LEGAL / ETHICS AND COMPLIANCE

Code of Conduct and Business Ethics

Integrity. Confidentiality. Responsible innovation.

VERSION
1.0
EFFECTIVE DATE
4 August 2026
DOCUMENT OWNER
Partners of AP Digital Solutions GbR
CONTACT
info@apdigitalsolutions.eu

Public and internal standard

PURPOSE OF THIS CODE

This Code establishes the minimum standards of lawful, ethical and professional conduct expected from every person acting for or on behalf of AP Digital. It protects our customers, their people and data, our business partners, and the trust on which our services depend.

Our commitment

AP Digital Solutions helps organisations organise sensitive digital assets and prepare documentation for complex regulatory obligations. Our work may involve workforce compensation information, confidential product and security information, and materials intended for regulators, worker representatives, auditors or senior management. Trust, accuracy and discretion are therefore not optional; they are essential to every engagement.

We conduct business lawfully, fairly and transparently. We do not obtain work, influence decisions or solve commercial problems by compromising our integrity. We expect the same standard from everyone who represents us and from third parties engaged to support our services.

The Partners are accountable for setting the tone, providing suitable resources and responding appropriately when concerns are raised. Every Covered Person is personally responsible for understanding this Code, exercising sound judgement and speaking up when something appears wrong.

THE PRACTICAL RULE

When in doubt: stop, protect the information, ask for guidance and document the decision. Never proceed merely because a deadline, customer request or commercial opportunity makes the issue inconvenient.

Document information

Applies toPartners, employees, temporary staff, interns, contractors, consultants and anyone else acting for or on behalf of AP Digital. Suppliers and other business partners are covered where this Code is incorporated into their agreement or otherwise accepted.
Territorial scopeAll AP Digital activities, wherever performed, subject to mandatory local law.
Relationship to other rulesThis Code supplements applicable law, contracts, the Terms and Conditions, Privacy Notice, data processing terms, security requirements and any role-specific procedures.
Reporting contactA Partner, the relevant manager, or info@apdigitalsolutions.eu with the subject line "CONFIDENTIAL - CODE OF CONDUCT REPORT".
Review cycleAt least annually and sooner following a material change in law, services, risk profile or organisational structure.
ApprovalApproved by the Partners of AP Digital Solutions GbR.
HOW TO USE THIS CODE

The Code cannot anticipate every situation. Read the relevant section, apply the decision guide in Appendix 1, and seek guidance before acting where the legal, ethical, security or reputational position is unclear.

1

Purpose, scope and legal effect

1.1 Purpose

This Code sets the minimum standards of conduct for AP Digital Solutions GbR ("AP Digital", "we", "us" or "our"). It is intended to prevent misconduct, support consistent decision-making and demonstrate our commitment to responsible business conduct.

The Code is risk-based. Particular care is required because our services may involve personal data, pay and employment information, cybersecurity and vulnerability information, regulatory deadlines, automated analysis and deliverables on which customers may rely for important decisions.

1.2 Who must comply

This Code applies to all "Covered Persons":

  • the partners of AP Digital;
  • employees, temporary agency workers, interns and trainees;
  • independent contractors, consultants and secondees acting for AP Digital; and
  • any other individual authorised to represent AP Digital or access its systems, customer data or confidential information.

Suppliers, subprocessors and other business partners are required to comply with the relevant provisions where this Code is incorporated into their contract, where they have expressly accepted it, or where equivalent standards are imposed through contractual obligations.

1.3 Legal effect and hierarchy

This Code supplements, and does not replace, applicable law, an employment or services contract, an accepted customer Order, a data processing agreement, confidentiality obligations, information-security requirements or other binding policy. Where several standards apply, Covered Persons must comply with the stricter standard unless doing so would breach mandatory law.

Nothing in this Code is intended to remove or restrict statutory rights, contractual rights, protected disclosures, rights of employee representatives, collective bargaining rights or applicable co-determination rights. Where implementation requires consultation or agreement with a works council or other employee representative body, AP Digital will comply with those requirements.

This Code does not create enforceable rights for customers, suppliers or other third parties unless a contract expressly provides otherwise. It does not guarantee continued employment or engagement and does not alter any legally applicable termination rights or procedures.

1.4 Definitions

TERMMEANING
AP Digital InformationInformation owned, controlled or processed by AP Digital, including customer information, internal business information, credentials, software, templates, methodologies and records.
Customer DataData, documents and other materials supplied by or on behalf of a customer or generated from those materials in performing the services.
Confidential InformationAny non-public information that is confidential by nature, designation, agreement or circumstance, including personal data, trade secrets, pricing, security information, source code and customer deliverables.
Personal DataInformation relating to an identified or identifiable natural person, as defined by applicable data protection law.
AI SystemA machine-based system within the meaning of applicable AI law, including generative AI, machine-learning, classification, prediction, recommendation and decision-support tools.
Public OfficialAny official, employee, representative or agent of a government, public authority, state-owned or controlled entity, regulator, court, public international organisation or political party, including candidates for public office.
2

Core principles and responsibilities

2.1 Our core principles

PRINCIPLEWHAT IT REQUIRES
Lawfulness and integrityWe comply with applicable law, contractual commitments and legitimate instructions. We do not conceal, misrepresent or circumvent requirements.
Respect and fairnessWe treat people with dignity, make decisions using objective criteria and do not tolerate discrimination, harassment, exploitation or retaliation.
Confidentiality and securityWe protect customer information, personal data, trade secrets and systems using need-to-know access and appropriate technical and organisational measures.
Competence and accuracyWe perform work within our competence, use reliable sources and methods, check material outputs and communicate assumptions, limitations and uncertainty.
Independence and transparencyWe disclose conflicts, resist improper influence and ensure that records, marketing claims and regulatory deliverables are accurate and not misleading.
Accountability and speaking upWe document material decisions, correct errors promptly and report suspected misconduct, security incidents and legal or ethical concerns without delay.

2.2 Responsibilities of the Partners

  • approve and model this Code and ensure that commercial pressure does not override legal, ethical, security or professional standards;
  • allocate appropriate resources for privacy, information security, quality assurance, responsible AI and compliance;
  • ensure concerns are assessed by an appropriately independent and competent person;
  • take proportionate corrective and disciplinary action where misconduct is substantiated; and
  • review material incidents and implement lessons learned.

2.3 Responsibilities of managers and engagement leads

  • explain relevant requirements to team members and contractors;
  • confirm that people are competent, authorised and appropriately supervised;
  • plan adequate time for review, security and regulatory deadlines;
  • respond promptly to questions and escalate matters outside their authority; and
  • never instruct, pressure or reward anyone to breach this Code.

2.4 Responsibilities of every Covered Person

  • read, understand and comply with this Code and applicable role-specific procedures;
  • complete required training and maintain appropriate professional competence;
  • protect information and credentials entrusted to them;
  • challenge or stop work that appears unlawful, unsafe, inaccurate or misleading;
  • report concerns and cooperate honestly with reviews and investigations; and
  • seek guidance before acting where the correct course is uncertain.
3

Lawful, ethical and professional conduct

3.1 Compliance with law and legitimate instructions

Covered Persons must comply with the laws and regulatory requirements applicable to their work, including data protection, cybersecurity, AI, anti-corruption, competition, employment, intellectual property, sanctions, tax, accounting and consumer or business communications rules where relevant.

No person may use an intermediary, automated tool, supplier, affiliate or customer instruction to do indirectly what AP Digital or the individual is prohibited from doing directly. A customer request does not justify unlawful or unethical conduct.

3.2 Authority and approvals

Only authorised persons may bind AP Digital, sign contracts, approve expenditure, make regulatory submissions, engage suppliers, issue public statements, access customer environments or represent that AP Digital has reached a legal or professional conclusion. Approval limits and segregation-of-duties requirements must be respected.

3.3 Professional boundaries

AP Digital is a digital asset management and compliance-support provider. It must not hold itself out as a court, regulator, notified body, certification body or conformity-assessment body. It must not hold itself out as a law firm or provide legal services unless and to the extent that the relevant service is lawfully permitted and performed by an appropriately authorised person.

Any statement that a deliverable is "legally vetted" must be accurate, supported by an appropriately qualified review within a documented scope, and accompanied by any material assumptions or limitations. It must not imply a guarantee of compliance, litigation outcome, regulator acceptance or legal privilege.

3.4 Dealings with authorities

Communications with regulators, courts, public authorities and external reporting bodies must be accurate, complete within the stated scope and authorised. No Covered Person may obstruct an investigation, conceal relevant information, create a false record or destroy material subject to a preservation obligation.

Nothing in this section requires AP Digital or any individual to waive legal privilege, confidentiality rights, procedural rights or other lawful protections. Requests from authorities must be escalated promptly to a Partner and, where appropriate, independent legal counsel.

4

Respect, equality, human rights and safety

4.1 Dignity, equal treatment and inclusion

AP Digital provides a working environment based on dignity, professionalism and equal opportunity. Employment, work allocation, compensation, development and other decisions must be based on objective, role-related criteria and applicable law.

Discrimination, harassment, sexual harassment, bullying, victimisation and retaliation are prohibited. This includes conduct based on race or ethnic origin, nationality, sex, pregnancy or maternity, gender identity, religion or belief, disability, age, sexual orientation, marital or family status, social origin, political opinion, trade-union activity, health status or any other protected characteristic under applicable law.

Harassment can occur verbally, physically, visually or digitally and can arise in offices, remote work, customer locations, messaging platforms, social events or business travel. Intent is not required where conduct has the prohibited effect under applicable law.

4.2 Equal pay and pay transparency

AP Digital supports equal pay for equal work or work of equal value and the use of objective, gender-neutral criteria in pay-setting and progression. Covered Persons must not retaliate against anyone for lawfully seeking pay information, discussing remuneration, exercising equal-pay rights or participating in a pay-transparency process.

Customer workforce data must never be used to stereotype individuals, infer unrelated protected characteristics, or recommend individual employment action outside the agreed and lawful service scope.

4.3 Human rights and fair working conditions

AP Digital does not tolerate forced labour, child labour, human trafficking, slavery, abusive working conditions or interference with lawful freedom of association and collective representation. We expect relevant suppliers and contractors to uphold equivalent standards.

Working time, remuneration, leave and other conditions must comply with applicable law and contractual commitments. No one may be pressured to work in a way that creates an unreasonable risk to health, safety, data security or quality.

4.4 Health, safety and reasonable support

Covered Persons must follow workplace, travel and remote-working safety requirements, report hazards and take reasonable care of themselves and others. AP Digital will consider reasonable adjustments or accommodations required by applicable law and will handle related information confidentially.

5

Conflicts of interest

5.1 General rule

A conflict of interest exists where personal, family, financial, professional or other interests could influence, or reasonably appear to influence, a person's judgement or duties to AP Digital or a customer. The appearance of a conflict can be as damaging as an actual conflict.

Covered Persons must disclose an actual, potential or perceived conflict promptly to a Partner and must not participate in the relevant decision or activity until the conflict has been assessed and a written mitigation or approval has been issued.

5.2 Examples requiring disclosure

  • a financial interest in, or close personal relationship with, a customer, supplier, competitor, candidate or person involved in a decision;
  • outside employment, consulting, directorships or business activities that compete with AP Digital, use its resources or impair performance;
  • selecting, supervising or approving payments to a business owned or controlled by a family member or close associate;
  • accepting benefits, opportunities or information obtained through an AP Digital role for personal gain;
  • working for two customers whose interests create a material conflict or risk to confidentiality; and
  • participating in pay, recruitment, performance or disciplinary decisions involving a close personal relationship.

5.3 Managing conflicts

Mitigation may include disclosure to an affected customer, recusal, independent review, information barriers, reassignment, restrictions on access, disposal of an interest or declining the engagement. A conflict may not be approved where it would breach law, professional duties, confidentiality or customer trust.

6

Anti-bribery, gifts and hospitality

6.1 Zero tolerance for bribery and corruption

AP Digital prohibits bribery and corruption in both the public and private sectors. No Covered Person may directly or indirectly offer, promise, give, request, agree to receive or accept anything of value to obtain an improper advantage, influence a decision, reward improper conduct or cause another person to breach a duty.

Kickbacks, secret commissions and facilitation payments are prohibited. A request for such a payment must be refused and reported immediately, except where a payment is made under an immediate and credible threat to personal safety; any such incident must be reported as soon as it is safe to do so.

6.2 Gifts and hospitality

Gifts and hospitality may be offered or accepted only where they are lawful, modest, occasional, transparent, for a legitimate business purpose and permitted by both organisations. They must not influence, or appear to influence, an award, renewal, tender, regulatory interaction, payment, employment decision or other business judgement.

ALWAYSNEVER
Confirm the recipient's rules; obtain written Partner approval for anything involving a Public Official, tender or active decision; record the true purpose and value; decline or return anything inappropriate.Cash or cash equivalents; personal discounts not generally available; lavish or repeated entertainment; gifts during a tender or approval process; benefits routed through relatives, charities or intermediaries to disguise their purpose.

6.3 Donations, sponsorship and political activity

Charitable donations and sponsorships made in AP Digital's name require written Partner approval, due diligence and accurate records. They must not be used to obtain business or channel value to a decision-maker. Political donations, lobbying or political endorsements in AP Digital's name are prohibited unless expressly approved following legal review.

Personal political activity must be clearly separated from AP Digital, must not use AP Digital resources without permission and must not imply company endorsement.

6.4 Third-party intermediaries

Agents, introducers, consultants and other intermediaries must be selected for legitimate business reasons, subject to proportionate due diligence, engaged under a written agreement and paid reasonable, transparent compensation for documented services. Unusual payment routes, success fees or requests for secrecy must be escalated.

7

Fair competition and market conduct

7.1 Competition law

AP Digital competes independently and fairly. Covered Persons must not agree, coordinate or exchange competitively sensitive information with competitors in a way that restricts competition. Prohibited conduct includes price fixing, bid rigging, customer or market allocation, output restrictions and agreements not to hire or solicit workers where unlawful.

Competitively sensitive information includes future pricing, margins, costs, strategic plans, customer-specific terms, capacity, tender intentions and non-public compensation strategies. If such a topic arises in a meeting or communication with a competitor, object, leave where appropriate, ensure the objection is recorded and report the incident.

7.2 Fair dealing

We do not obtain competitor or customer information through deception, unauthorised access, inducement to breach confidentiality or misuse of a former employer's information. Market comparisons and benchmarking must use lawful sources and appropriate aggregation or anonymisation.

Statements about competitors, customers and third parties must be accurate, relevant and professionally expressed. We do not make false, misleading or disparaging claims.

7.3 Procurement and tenders

Tender and procurement processes must be conducted honestly. Covered Persons must not collude, submit cover bids, manipulate specifications, conceal conflicts or obtain confidential tender information improperly. Commitments must be realistic and must reflect AP Digital's actual capabilities and approvals.

8

Financial integrity, fraud and records

8.1 Accurate books, records and billing

All business records must be accurate, complete, timely and sufficiently detailed to explain the transaction or decision. This includes proposals, contracts, invoices, time records, expenses, calculations, regulatory deliverables, approvals, customer instructions, security logs and accounting records.

No Covered Person may create or approve a false, misleading, incomplete or backdated record; hide liabilities or side arrangements; establish an off-book account; split transactions to avoid approval; or bill for work, expenses or deliverables not properly incurred or provided.

8.2 Fraud, theft and misuse

Fraud, theft, embezzlement, forgery, misappropriation, misuse of customer or company assets and deliberate manipulation of data or reports are prohibited. Suspected fraud or a material accounting irregularity must be reported immediately to a Partner who is not implicated.

8.3 Tax and payments

AP Digital complies with applicable tax, invoicing and record-keeping obligations. Covered Persons must not facilitate tax evasion, disguise the true party to a transaction, accept or make payments through unexplained third parties, or use cash, cryptocurrency or unusual jurisdictions to avoid controls without documented approval and lawful justification.

8.4 Retention and legal holds

Records must be retained and securely deleted in accordance with applicable law, contractual obligations and AP Digital's retention requirements. Routine deletion must stop where a document, dataset or communication may be relevant to litigation, an investigation, an audit, a regulatory request or another preservation instruction.

9

Data protection and privacy

9.1 Privacy principles

Personal data must be processed lawfully, fairly and transparently; collected for specified purposes; limited to what is necessary; kept accurate; retained no longer than required; and protected by appropriate security. Covered Persons must be able to explain why personal data are needed, the role in which AP Digital processes them and the approved system in which they are stored.

9.2 Controller and processor roles

Where AP Digital acts as controller, processing must have an identified legal basis and comply with the applicable privacy notice. Where AP Digital acts as processor, Customer Data may be processed only on the customer's documented instructions and within the applicable data processing agreement, except where law requires otherwise.

Customer personal data must not be reused for AP Digital's own unrelated purposes, sold, disclosed for advertising, combined across customers for identifiable benchmarking, or used to train a shared or general-purpose AI model unless the customer has expressly authorised the processing and all legal and contractual requirements have been satisfied.

9.3 Data minimisation and sensitive information

Only data reasonably necessary for the agreed service may be requested or accessed. Names and direct identifiers should be replaced with pseudonymous identifiers where they are not required. Special-category data, criminal-conviction data, private contact details, national identifiers, bank details and other highly sensitive data must not be collected unless specifically necessary, authorised and protected by additional controls.

9.4 Access, sharing and transfers

Access must be limited to authorised persons with a need to know. Personal data may be shared only with approved recipients under an appropriate legal and contractual basis. International transfers and remote access from another country require an approved transfer mechanism and any supplementary safeguards identified by the privacy review.

9.5 Privacy by design and individual rights

New services, tools, vendors, integrations, forms and AI uses involving personal data must be assessed before deployment. Data protection impact assessment screening must be completed where the processing may create high risk. Requests from individuals, regulators or customers concerning personal data must be forwarded promptly to the designated person and must not be answered informally without authority.

9.6 Personal data breaches

Any actual or suspected loss, unauthorised access, disclosure, alteration, deletion, misdirection or unavailability of personal data must be reported immediately through the incident process. Do not delay reporting while investigating, and do not contact affected individuals, regulators or customers unless authorised.

DATA HANDLING RULE

Do not download customer workforce or security data to a personal device, personal email account, unapproved cloud service, removable media or public AI tool. Use only the approved customer or AP Digital environment.

10

Confidentiality and trade secrets

10.1 Duty of confidentiality

Covered Persons must protect Confidential Information belonging to AP Digital, customers, suppliers, workers and other third parties. Information may be used only for the authorised purpose, disclosed only to approved recipients with a need to know and handled in accordance with contractual and security requirements.

The duty continues after employment, engagement or the customer relationship ends. Information must be returned, securely deleted or retained only as lawfully required. Access does not create a right to keep copies or use the information for personal benefit, future employment, publication or another customer.

10.2 Reasonable protective measures

  • classify and label information where appropriate;
  • use approved secure sharing channels and encryption;
  • verify recipients before sending and use the minimum necessary distribution list;
  • avoid discussing confidential matters in public places or with unauthorised colleagues, friends or family;
  • secure screens, papers and devices when unattended and dispose of material securely;
  • apply information barriers where conflicts or customer restrictions require them; and
  • report accidental disclosure or misdirection immediately.

10.3 Protected disclosures and lawful rights

Confidentiality obligations do not prohibit a lawful protected disclosure, reporting suspected wrongdoing to a competent authority, obtaining independent legal advice, cooperating with law enforcement, exercising employee-representation rights or making another disclosure protected by applicable law. Only information reasonably necessary for the protected purpose should be disclosed.

11

Information security and cyber resilience

11.1 Security is everyone's responsibility

Covered Persons must follow AP Digital and customer security requirements and apply a level of care appropriate to the sensitivity of the information. Security controls must not be disabled, bypassed or weakened for convenience, speed or customer pressure.

11.2 Minimum security behaviours

  • use unique credentials, an approved password manager and multi-factor authentication where available;
  • never share accounts, passwords, recovery codes or access tokens;
  • use only approved, managed and encrypted devices and software for AP Digital work;
  • install updates promptly and do not disable endpoint protection, logging or screen locks;
  • verify unusual payment, credential, file-sharing and access requests through a separate channel;
  • use approved secure connections and take additional care on public or shared networks;
  • do not install unapproved software, browser extensions, integrations or remote-access tools;
  • follow least-privilege access and remove access promptly when no longer required; and
  • securely dispose of devices and media using an approved process.

11.3 Security incidents and vulnerabilities

Lost devices, suspected phishing, malware, credential compromise, unauthorised access, misdirected information, abnormal system behaviour, service outages and other suspected incidents must be reported immediately. Preserve relevant evidence and follow instructions; do not independently notify customers, regulators, vendors or the public unless authorised.

Security testing, vulnerability scanning, penetration testing and attempts to access systems beyond granted permissions are prohibited without written authorisation and a defined scope. Vulnerability information received in connection with Cyber Resilience Act services must be strictly need-to-know and must not be disclosed prematurely or used for trading, exploitation or publicity.

11.4 Customer environments and remote work

Customer environments may be accessed only for the agreed purpose, through approved methods and within granted permissions. Customer information must not be copied into AP Digital systems unless authorised. Remote work must preserve confidentiality, prevent unauthorised viewing or listening, and use secure storage and communications.

12

Responsible AI and automated tools

12.1 Approved and accountable use

AI Systems may be used only for an approved business purpose, within the user's competence and subject to the risk, privacy, security, intellectual-property and contractual controls appropriate to the use case. AP Digital will maintain suitable AI literacy and role-specific guidance for persons using or overseeing AI Systems.

An AI System does not replace professional judgement or accountability. The person using the output remains responsible for checking its accuracy, relevance, legality and suitability before it is relied on, shared or incorporated into a deliverable.

12.2 Prohibited uses

Covered Persons must not use AI Systems for unlawful manipulation, prohibited discrimination, social scoring, unlawful biometric categorisation, deceptive impersonation, unauthorised surveillance or any other prohibited practice under applicable law. AI must not be used to infer sensitive personal characteristics from customer pay or workforce data unless the processing is expressly lawful, necessary, authorised and subject to appropriate safeguards.

AP Digital must not make employment, compensation, promotion, disciplinary or dismissal decisions about an individual solely through automated processing where this would produce legal or similarly significant effects. Customer-facing analysis must not be presented as an automated employment decision or instruction.

12.3 Customer and confidential data

Customer Data, personal data, trade secrets, source code, vulnerability information and confidential documents must not be entered into a public, consumer or otherwise unapproved AI service. Use of a third-party AI provider requires prior vendor, privacy, security, transfer, intellectual-property and contractual review, together with any required customer approval.

12.4 Human oversight, quality and transparency

  • define the purpose, users, data, output and human decision-maker;
  • test material outputs for accuracy, bias, robustness and foreseeable misuse;
  • maintain sufficient records of the tool, version, input controls, review and material corrections;
  • provide meaningful human review before external use or a material decision;
  • identify AI-generated or materially AI-assisted content where law, contract or context requires disclosure;
  • monitor incidents, material performance changes and vendor changes; and
  • stop use and escalate where the system behaves unexpectedly, creates material bias, leaks information or cannot be adequately supervised.

12.5 Intellectual property and authenticity

AI use must respect copyright, database rights, trade secrets, licence terms and attribution requirements. Covered Persons must not present AI-generated material as independently verified expert work, fabricate sources or citations, or use synthetic evidence, signatures or identities deceptively.

13

Integrity of regulatory and compliance services

13.1 Scope and customer responsibility

Every engagement must have a documented scope, customer, jurisdiction, deliverables, assumptions, responsibilities, data requirements, review process and timetable. Work outside scope requires appropriate approval and, where material, a written change to the engagement.

AP Digital supports customers with data handling, analysis, documentation and regulatory preparation. The customer remains responsible for its legal obligations, factual submissions, employment and product decisions, internal approvals, regulator communications and independent legal advice unless an Order expressly and lawfully states otherwise.

13.2 Competence and current requirements

Work must be assigned to persons with suitable knowledge and supervision. Material legal or regulatory assumptions must be checked against reliable, current and jurisdiction-specific sources. Where national implementation, guidance or reporting formats are incomplete or uncertain, that uncertainty must be stated and the customer must be advised to obtain appropriate legal advice.

13.3 Data quality and methodology

  • record the source, version and date of material inputs;
  • validate completeness, format and obvious inconsistencies before analysis;
  • document calculation rules, categorisation logic, exclusions, assumptions and manual adjustments;
  • use reproducible methods and preserve a suitable audit trail;
  • do not alter data, categories, thresholds or presentation to conceal an adverse result or create a preferred outcome;
  • distinguish customer-provided facts from AP Digital analysis and recommendations; and
  • escalate material data gaps or suspected falsification rather than filling them with unsupported assumptions.

13.4 Review and approval

Material deliverables must receive a documented review proportionate to their risk. Reports intended for a regulator, worker representative, board, audit committee or notified body, or carrying a statement of legal review, require an independent second-person review before release. The reviewer must have sufficient competence and must not merely confirm formatting.

Errors discovered after delivery must be escalated promptly. AP Digital must assess impact, preserve the original record, issue a corrected version where appropriate and communicate clearly with the customer. Errors must not be silently overwritten or concealed.

13.5 Regulatory submissions and communications

AP Digital may prepare submission-ready materials but must not file, certify or communicate in the customer's name without clear written authority. Before any authorised submission, the customer must approve the relevant factual content and AP Digital must confirm that the approved version is the version submitted.

Regulatory deadlines, including urgent cybersecurity and vulnerability reporting deadlines, must be recorded, monitored and escalated. No person may delay escalation because facts are incomplete; preliminary reporting requirements may need to be met while an investigation continues.

13.6 Independence, worker rights and no retaliation

Analysis must remain objective and must not be adjusted to satisfy a commercial preference. Covered Persons must respect lawful information, consultation and participation rights of workers and their representatives. AP Digital will not assist a customer to retaliate against an individual for raising an equal-pay, cybersecurity, privacy, compliance or whistleblowing concern.

SERVICE INTEGRITY RULE

Never label a report "compliant", "certified", "court-ready", "submission-ready" or "legally vetted" unless the statement is accurate for the agreed scope, supported by the required review and does not imply a guarantee that AP Digital cannot lawfully or professionally give.

14

Intellectual property and use of assets

14.1 AP Digital assets

Systems, devices, accounts, methodologies, templates, brands, domains, software, source code, prompts, documentation and other AP Digital assets may be used only for authorised purposes and with reasonable care. Access must be returned or disabled when it is no longer required.

Limited personal use of communication or device resources is permitted only where it is lawful, reasonable, secure, does not interfere with work and is not prohibited by a customer or system-specific rule. AP Digital resources must never be used for unlawful, discriminatory, abusive, deceptive or commercial side activities.

14.2 Third-party rights and licences

Covered Persons must respect copyright, database rights, patents, trademarks, trade secrets, software licences, open-source obligations and contractual restrictions. Unlicensed software, copied subscription credentials, pirated content and unauthorised reuse of customer or competitor materials are prohibited.

Open-source and third-party components may be used only after confirming that the licence, security, attribution and source-disclosure obligations are compatible with the intended use and customer commitments.

14.3 Work created for AP Digital

Intellectual property created in the course of employment or engagement must be handled in accordance with applicable law and the relevant contract. Covered Persons must execute reasonable documents required to confirm ownership or licensing and must disclose third-party materials incorporated into work product.

15

Sanctions, export controls and financial crime

15.1 Sanctions and restricted parties

AP Digital complies with applicable economic and trade sanctions. No Covered Person may provide funds, services, software, technical information or other economic resources to a sanctioned person, entity, territory or prohibited activity, or participate in an arrangement intended to circumvent a restriction.

Customer, supplier and payment due diligence must be proportionate to risk. Matches, ownership concerns, unusual jurisdictions or requests to omit identifying information must be escalated before work or payment proceeds.

15.2 Export controls

Software, encryption, technical documentation, cybersecurity information and remote access may be subject to export-control restrictions. Cross-border transfers must not occur until any required classification, authorisation or restriction has been assessed.

15.3 Money laundering and suspicious arrangements

AP Digital does not accept or facilitate funds that appear to be proceeds of crime or intended to disguise beneficial ownership, destination or purpose. Suspicious payment patterns, unexplained third-party payers, overpayments, refund requests to a different account and requests for false invoice descriptions must be refused or paused and reported.

16

Communications, marketing and public statements

16.1 Accurate and responsible communications

Website content, proposals, presentations, case studies, social-media posts and other communications must be accurate, supportable, current and not misleading by statement or omission. Legal requirements, deadlines, thresholds and enforcement mechanisms must be described with appropriate jurisdictional qualifications.

AP Digital must not guarantee compliance, regulator acceptance, litigation success, certification or a particular business outcome. Claims about security, hosting location, encryption, AI capabilities, legal review, customer numbers, experience or qualifications must reflect actual and verifiable practice.

16.2 Customer and third-party references

Customer names, logos, testimonials, quotations, project details and results may be used only with appropriate written permission and in accordance with confidentiality and data protection requirements. Data must be aggregated or anonymised before publication where required, and re-identification risk must be assessed.

16.3 Media, social media and personal views

Only authorised persons may speak to the media, issue press statements or respond publicly on behalf of AP Digital. Personal communications must not disclose Confidential Information or imply AP Digital endorsement. Covered Persons should make clear when views are personal where confusion could reasonably arise.

16.4 Records and informal messaging

Business communications must use approved channels. Material decisions, customer instructions and approvals made through calls or informal messaging must be recorded in the appropriate business record. Messages must remain professional and capable of lawful disclosure.

17

Environment and responsible business

17.1 Environmental responsibility

AP Digital seeks to reduce avoidable environmental impact through efficient use of energy, devices, storage, paper, travel and other resources. Electronic equipment and media must be reused, recycled or securely disposed of through approved channels.

Environmental claims must be accurate, specific and supportable. Covered Persons must not make vague or misleading claims about sustainability, carbon impact or environmental benefits.

17.2 Responsible digital operations

Data retention, cloud use and computationally intensive tools should be proportionate to business and legal needs. Responsible digital operations include deleting redundant data securely, selecting appropriately efficient services and avoiding unnecessary duplication of large datasets.

18

Third parties and suppliers

18.1 Due diligence and selection

Third parties must be selected on objective criteria, including competence, integrity, security, privacy, conflicts, financial reliability, sanctions risk and ability to meet contractual requirements. Personal relationships or improper benefits must not influence selection.

18.2 Written terms and controls

Before access to AP Digital or Customer Data is granted, the third party must have an appropriate written agreement covering scope, confidentiality, data protection, information security, intellectual property, subcontracting, incident notification, deletion or return, audit or assurance rights and termination where relevant.

A third party must not be used to avoid a restriction that applies to AP Digital. Covered Persons who manage a supplier remain responsible for proportionate oversight, documented performance review and escalation of material issues.

18.3 Expected supplier standards

  • comply with applicable law and act honestly;
  • prohibit bribery, fraud, retaliation, discrimination, forced labour and child labour;
  • protect personal data, confidential information and systems;
  • respect intellectual property and competition law;
  • maintain accurate records and disclose conflicts;
  • report security incidents and serious misconduct promptly; and
  • cooperate with reasonable due diligence and remediation.

Material or repeated non-compliance may result in corrective measures, suspension of access, withholding of approval, termination or reporting to authorities, subject to contract and law.

19

Speaking up and reporting concerns

19.1 Duty to raise concerns

Covered Persons should raise a concern whenever they reasonably suspect a breach of law, this Code, a contract, a security requirement or a professional obligation, or where conduct creates a material risk to a person, customer, regulator or AP Digital. Proof is not required before reporting, and a concern should not be investigated privately in a way that could compromise evidence or confidentiality.

19.2 Internal reporting options

CHANNELHOW TO USE IT
A PartnerContact any Partner directly. Where a Partner may be implicated, report to another Partner or use an external channel.
Manager or engagement leadRaise operational, conduct, quality or security concerns with the relevant manager, unless that person is implicated or cannot act independently.
Confidential emailEmail info@apdigitalsolutions.eu with the subject line "CONFIDENTIAL - CODE OF CONDUCT REPORT". Access to the report should be restricted to a designated Partner.
Emergency or security incidentUse the applicable incident or emergency process immediately. Where personal safety is at risk, contact emergency services first.

19.3 External reporting and protected disclosures

Internal reporting is encouraged because it may allow AP Digital to address an issue quickly, but it is not mandatory where the law protects external reporting. A person may contact a competent external reporting office, regulator, law-enforcement authority, data protection authority, legal adviser, employee representative or other protected recipient in accordance with applicable law.

These internal reporting options do not purport to replace a formal statutory internal reporting office where AP Digital is legally required to establish one. Any such office will operate under the applicable statutory procedure and confidentiality requirements.

19.4 Anonymous reports and information to provide

Anonymous concerns will be considered to the extent reasonably possible, although anonymity can limit follow-up. A report should, where available, describe what happened, when and where it occurred, who was involved, the risk or impact, relevant records and whether urgent protective action is required. Reporters should preserve information lawfully and avoid unnecessary disclosure of personal or confidential data.

20

Investigations, non-retaliation and consequences

20.1 Fair and proportionate review

Reports will be assessed promptly, impartially and proportionately by a person with appropriate competence and independence. AP Digital will protect confidentiality to the extent reasonably possible and legally permitted, while recognising that information may need to be disclosed to investigate, protect rights, take corrective action or comply with law.

Persons involved in a review must cooperate honestly, preserve relevant information, keep the matter appropriately confidential and avoid interfering with witnesses or evidence. A person whose conduct is under review should be treated fairly and given an appropriate opportunity to respond before a final adverse finding, subject to urgent protective measures and applicable law.

20.2 Non-retaliation

Retaliation is prohibited against a person who in good faith raises a concern, seeks guidance, refuses to participate in suspected misconduct, assists an investigation or makes a protected disclosure. Prohibited retaliation includes dismissal, demotion, loss of work, threats, harassment, exclusion, adverse references, unjustified changes to duties or any other disadvantage connected with the protected activity.

A report is made in good faith where the person had reasonable grounds to believe the information was true at the time, even if the concern is not substantiated. Knowingly false or malicious allegations, deliberate evidence fabrication or misuse of the reporting process may lead to proportionate action, but an honest mistake will not.

20.3 Consequences and remediation

A substantiated breach may result in coaching, additional controls, training, correction of records, removal of access, reassignment, a warning, termination of employment or engagement, contractual remedies, recovery of loss, or referral to a regulator or law-enforcement authority. Any measure will be proportionate and subject to applicable law, contract, due process and employee-representation rights.

AP Digital will also consider root causes, customer notification, affected-person support, control improvements, disciplinary consistency and whether prior decisions or deliverables must be corrected.

21

Governance, training, exceptions and review

21.1 Ownership and oversight

The Partners own this Code and are responsible for its implementation. They may designate specific responsibilities for privacy, security, AI, quality, finance, supplier oversight and investigations, but remain accountable for ensuring appropriate governance.

21.2 Training and awareness

Covered Persons must complete induction and refresher training appropriate to their role and risk exposure. Training should cover at least confidentiality, data protection, information security, responsible AI, anti-bribery, conflicts, equal treatment, quality and reporting concerns. Additional training is required before a person performs a higher-risk activity without supervision.

21.3 Monitoring and assurance

AP Digital may monitor compliance through access reviews, quality checks, security logging, supplier assurance, policy attestations, audits and incident reviews, subject to applicable privacy, employment and co-determination law. Monitoring must be proportionate, transparent where required and used only for legitimate purposes.

21.4 Exceptions

An exception to an internal control may be granted only in writing by an authorised Partner, for a documented reason, for a defined period and with appropriate compensating measures. No exception may authorise a breach of law, contractual duty, protected right, confidentiality, data protection or a prohibition on bribery, fraud, retaliation or deliberate misrepresentation.

21.5 Review and changes

This Code will be reviewed at least annually and may be updated when laws, services, technology or risks change. Material changes affecting employment conditions or employee monitoring will be implemented subject to applicable consultation and co-determination requirements. The current approved version should be made reasonably accessible to Covered Persons and relevant business partners.

21.6 Questions

Questions about this Code or the appropriate course of action should be directed to a Partner or to info@apdigitalsolutions.eu. Seeking guidance is encouraged and will not be treated as an admission of wrongdoing.

Appendix 1 - Decision guide

Before acting on a material issue, ask the following questions. A "no", "not sure" or "I do not want this documented" answer means stop and seek guidance.

STEPQUESTION
1Is it lawful and within AP Digital's authority?
2Is it consistent with this Code, the customer agreement and applicable policies?
3Am I using accurate information, an appropriate method and the required review?
4Does it protect personal data, confidential information, systems and affected individuals?
5Would I be comfortable explaining the decision to the customer, a regulator, a colleague or on the public record?
6Have I disclosed conflicts, obtained approvals and documented the material reasoning?
STOP - CHECK - ASK - REPORT

Do not let urgency, seniority, revenue, customer pressure or sunk cost prevent escalation. It is better to pause a task than to conceal or compound a legal, security or ethical problem.

Examples of warning signs

  • "Do not put this in writing."
  • "Everyone in the market does it."
  • "The customer told us to, so it is their responsibility."
  • "Change the categories so the result looks better."
  • "Upload the file to a free AI tool; we need the answer now."
  • "Use my personal account because the approved system is slow."
  • "Invoice another entity or describe the service differently."
  • "We can call it certified or legally compliant even though the review is not complete."

Appendix 2 - Selected legal and policy context

This non-exhaustive list identifies key legal areas reflected in the Code. The laws applicable to a particular activity depend on the facts, jurisdiction and date. References include amendments, implementing laws, regulatory guidance and successor legislation where applicable.

AREAKEY FRAMEWORKS
Data protection and digital privacyRegulation (EU) 2016/679 (GDPR); German Federal Data Protection Act (BDSG); Telecommunications Digital Services Data Protection Act (TDDDG); applicable UK GDPR and national privacy law where relevant.
Artificial intelligenceRegulation (EU) 2024/1689 (AI Act), including AI literacy, prohibited practices, risk management, transparency and human-oversight requirements applicable to the relevant role and use case.
Pay transparency and equalityDirective (EU) 2023/970 and national implementing laws; German General Equal Treatment Act (AGG); applicable equal-pay and employment laws.
Cybersecurity and product complianceRegulation (EU) 2024/2847 (Cyber Resilience Act); applicable national cybersecurity, incident-reporting, product-safety and security requirements.
Whistleblower protectionGerman Whistleblower Protection Act (Hinweisgeberschutzgesetz - HinSchG), Directive (EU) 2019/1937 and other applicable protected-disclosure laws.
Legal-services boundariesGerman Legal Services Act (Rechtsdienstleistungsgesetz - RDG) and applicable professional and authorisation rules.
Anti-bribery, fraud and financial integrityGerman Criminal Code, including public-sector and commercial bribery offences; applicable anti-corruption, fraud, tax, accounting and anti-money-laundering laws; relevant foreign anti-bribery laws where they apply.
CompetitionArticles 101 and 102 TFEU; German Act against Restraints of Competition (GWB); applicable procurement and unfair-commercial-practices rules.
Confidentiality and intellectual propertyGerman Trade Secrets Act (GeschGehG); copyright, database, trademark, patent, software-licensing and contractual confidentiality law.
Sanctions and export controlsEU and national restrictive-measures regimes, export-control law and applicable rules concerning software, encryption, technical data and cross-border services.
Employment, human rights and safetyApplicable employment, working-time, occupational health and safety, collective-representation, non-discrimination, modern-slavery and human-rights requirements.

This Appendix is an internal orientation aid and is not a substitute for legal advice on a specific matter.

Appendix 3 - Acknowledgement

This acknowledgement may be used where AP Digital requires an individual or business partner to confirm receipt of the Code. For a supplier or other third party, the Code becomes contractually binding only to the extent stated in the applicable agreement or acceptance document.

ACKNOWLEDGEMENT OF RECEIPT AND COMMITMENT

I confirm that I have received and read the AP Digital Solutions Code of Conduct and Business Ethics, Version 1.0, effective 4 August 2026.

I understand the standards relevant to my role and agree to comply with them to the extent applicable to my employment, engagement or contract. I will seek guidance and report suspected breaches or material risks through an appropriate channel.

I understand that this acknowledgement does not waive statutory, contractual, collective, whistleblowing or employee-representation rights and does not create rights for third parties beyond any express contract.

Capacity (tick one): [ ] Partner / employee [ ] Contractor / consultant [ ] Supplier / business partner

______________________________________________

Name

______________________________________________

Role and organisation

______________________________________________

Signature

______________________________________________

Date

AP Digital Solutions GbR
Schulte Strasse 25
57076 Siegen
Germany
info@apdigitalsolutions.eu
apdigitalsolutions.eu