itegGO logo

Compliance

Compliance, Integrity and Good Governance

Corporate Compliance Program

itegGO Consulting

Compliance

Transparency and Integrity

Anyone who becomes aware of or suspects any violation, illegal activity, inappropriate behavior, or similar issue may report it not only to the Corporate Compliance Officer but also through the following available channels.

DIGITAL PLATFORM
All communications will be treated with the strictest confidentiality.
https://cobrais.integrityline.com
TELEPHONE HOTLINE
- Spain: +34 910 477 636 9756
- Mexico: +52 5 571 002 193

During the call you will be asked to provide the service code 9756.
POSTAL MAIL
Grupo IMESAPI
Calle Vía de los Poblados, 9-11
Trianón Business Park – Building C
28033 Madrid, Spain.

Attention: Corporate Compliance Officer.

These channels may be used both to report any breach of applicable laws and/or internal regulations and to request guidance regarding issues that may arise during the organization's activities. Confidentiality is guaranteed at all times, as well as protection against retaliation for submitting a report.

Corporate Compliance Program

The organization is firmly committed to complying with the highest standards of corporate ethics. Since March 30, 2017, it has maintained a Corporate Compliance Program that is periodically reviewed by highly respected external advisors. The program includes an organized set of measures designed to establish an environment for the prevention, detection, and proactive management of risks. It focuses particularly on preventing criminal offenses and violations of competition law, among other matters, ensuring the highest level of integrity in all business practices.

The company adheres to the VINCI standards, which define the principles shared by all employees and business partners. These core values are set out in the following five reference documents:

    • The Code of Ethics and Conduct, which establishes the principles of business ethics that must be applied in different circumstances and in every country where the company operates.
    • It is used together with the Anti-Corruption Code of Conduct, which includes rules aimed at preventing all forms of corruption by identifying risks in business processes and defining the behaviors that must be avoided.
    • The Human Rights Guide, which summarizes potential risks and their implications for businesses while defining a common set of guidelines for addressing human rights issues.
    • These guidelines are based on the principles of the Universal Declaration of Human Rights (UDHR), the eight fundamental conventions of the International Labour Organization (ILO), and the OECD Guidelines for Multinational Enterprises. They also include the Statement on Essential and Fundamental Actions in Occupational Health and Safety, reflecting the shared commitment to achieving the goal of "Zero Accidents". This declaration results from constructive and ongoing social dialogue. As part of a policy of continuous improvement, it affirms that progress can only be achieved with the participation of all employees by promoting a strong safety culture.
    • The Environmental Guidelines, which provide a framework designed to minimize the risks and environmental impacts of business activities. All companies must follow these guidelines to continuously improve and adapt their actions and procedures in order to protect and preserve the environment wherever they operate. Each subsidiary is responsible for ensuring that its business partners make similar efforts throughout the entire life cycle of every project.

    The Corporate Compliance Program consists of the following documents:

    VINCI Standards

    COBRA S.C.E. Protocols

    • Framework Protocol
    • Regulatory Compliance Protocol
    • Protocol for Reporting Alleged Irregularities
    • Corporate Defense Procedure Activation Protocol
    • Protocol on Compliance Training for Professionals
    • Charter of the Compliance Body – Protocol defining the profile, experience, and organizational position of the Compliance Body, the Corporate Compliance Officer, and the Corporate Compliance Delegate.
    • Essential Policies Protocol
    • Catalogue of Prohibited Conduct and Expected Standards of Behavior
    • Code of Conduct for Business Partners
    • Competition Law Compliance Protocol
    • Management of Relationships with Public Authorities and Civil Servants
    • Facilitation Payments
    • Sustainability Policy

    COBRA S.C.E. Internal Regulations

    Crime Prevention Plan and IMESAPI Group Policies

    • Regulatory Compliance, Anti-Bribery and Competition Law Compliance Policy
    • Anti-Money Laundering and Counter-Terrorist Financing Policy
    • Anti-Corruption Policy
    • Professional Hospitality and Gifts Policy
    • Industrial and Intellectual Property Rights Protection Policy
    • Data Protection and Confidential & Sensitive Information Handling Policy
    • Human Rights Due Diligence Policy
    • Workplace Harassment Prevention, Detection and Response Protocol
    • Protocol for the Prevention, Detection and Response to Sexual Harassment and Gender-Based Harassment within IMESAPI S.A.


    Any individual who, in good faith, submits a report through these channels will be protected against any form of discrimination, retaliation, or penalty resulting from such communication. False or malicious reports will be subject to disciplinary measures in accordance with applicable internal procedures, collective agreements, and legal regulations. The confidentiality of the whistleblower's identity is guaranteed. The identity of the reporting person will not be disclosed to third parties, the reported person, or members of management unless disclosure is required for the purposes of a subsequent investigation or judicial proceeding arising from the Compliance Management System investigation. In accordance with the applicable Personal Data Protection regulations, personal data collected through this Ethics Channel will be processed by the IMESAPI Group solely for the purpose of managing reports and inquiries, in accordance with the Corporate Compliance Program and internal regulations. The legal basis for this processing is the data subject's consent, granted by voluntarily submitting the information. Personal data will be retained for the duration of the investigation and, unless erasure is requested, for the legally established limitation periods applicable in each case. Where necessary for the purposes of the investigation, the information received may be shared with the relevant companies within the IMESAPI Group. Information about IMESAPI Group companies is available through official corporate registers. Data subjects may exercise their rights of access, rectification, erasure, portability, restriction of processing, or objection at any time by sending a written request to:

    Grupo IMESAPI
    Calle Vía de los Poblados, 9-11
    Parque Empresarial Trianón – Building C
    28033 Madrid, Spain.