top of page

Code of Conduct

ETHICS,
INTEGRITY, AND LEGAL COMPLIANCE

1. Integrity, Honesty, and Accountability

1.1 Acting with Integrity

  • All personnel shall act truthfully at all times, including in circumstances where doing so may be professionally inconvenient.

  • Half-truths, procedural shortcuts, and the deferral of necessary corrective action ("we will address it later") are not permitted.

  • No employee, contractor, consultant, or partner shall mislead clients, partners, or colleagues, whether by omission or otherwise.

1.2 Accountability for Actions

  • Each individual bears personal responsibility for their own decisions, results, and errors.

  • Where an error occurs, it must be reported immediately, corrected, and formally documented.

  • Assigning blame to others, concealing issues, or delaying disclosure constitutes a breach of this Code.

1.3 Conflicts of Interest

  • Any personal, financial, or external relationship that may reasonably influence an individual’s professional judgment must be disclosed to management without delay.

  • No employee may engage in external business activity that competes with COGITANS, or make use of Company resources for such activity, without prior written approval from management.

2. Confidentiality and Data Protection

2.1 Confidential Information

  • Project data, architectural diagrams, technical documentation, pricing information, correspondence, internal processes, and client details constitute confidential information of the Company.

  • Disclosure of such information outside approved channels (including email, ClickUp, Google Workspace, Command, and encrypted storage systems) is strictly prohibited.

2.2 GDPR and Personal Data

  • All personnel shall comply fully with the General Data Protection Regulation (GDPR) and the Company’s internal data protection policies.

  • Access to personal data shall be limited strictly to what is necessary and processed solely for clearly defined and legitimate purposes.

  • The downloading, exporting, or transferring of data to private devices without prior authorisation is prohibited.

2.3 Secure Communication

  • Internal communications shall be conducted exclusively through approved platforms (Slack, Microsoft Teams, or WhatsApp, as designated by Company policy).

  • Sensitive information shall under no circumstances be transmitted through insecure or unapproved channels.

  • Screenshots depicting system configurations, credentials, or client deployments shall not be shared publicly under any circumstances.

3. Compliance and Legal Responsibility

3.1 Compliance with Laws

  • All personnel are required to comply with all applicable Slovak, European Union, and international laws relevant to their duties, including but not limited to cybersecurity regulations, export controls, and technology licensing requirements.

3.2 Anti-Corruption and Fair Business Conduct

  • The offering or acceptance of bribes, gifts intended to influence decision-making, or any form of hidden advantage is strictly prohibited.

  • Business hospitality is permitted only where it is reasonable, transparent, and approved in advance by management.

3.3 Standards and Certifications

  • All work performed shall conform to the requirements of ISO 27001, ISO 9001, and ISO 20000-1, together with the Company’s internal standard operating procedures.

  • Failure to complete required documentation constitutes a breach of process under this Code.

OPERATIONAL CONDUCT AND SECURITY STANDARDS

4. Security Obligations

COGITANS operates within a security-sensitive industry. Compliance with the following security obligations is mandatory and non-negotiable.

4.1 Authentication and Access

  • Multi-factor authentication (MFA) is mandatory across all Company systems.

  • Passwords must comply with the Company’s internal security standards; the reuse of passwords across systems is prohibited.

  • Access to systems and data shall be granted strictly on the principle of least privilege — limited to what is necessary for the performance of an individual’s duties.

4.2 Company Devices and Equipment

  • Company laptops, mobile devices, SIM cards, and equipment must be safeguarded against loss or theft at all times.

  • The installation of unapproved software on Company devices is prohibited.

  • Remote access to Company systems is permitted only through approved VPN connections or other designated secure channels.

4.3 Handling of Sensitive Systems

  • Camera networks, access control credentials, server configurations, and cloud administration dashboards must be handled with the utmost care.

  • Workstations must be locked or logged out whenever left unattended.

  • Laptops and Company devices must never be left unattended at client sites, airports, or in vehicles.

4.4 Incident Reporting

  • Any suspicious activity, system anomaly, or potential security incident must be reported immediately to the Chief Technology Officer (CTO) or the designated Security Officer.

  • No incident shall be considered too minor to report.

5. Professional Conduct and Workplace Behaviour

5.1 Respect

  • Discrimination, harassment, insults, or degrading remarks of any kind will not be tolerated under any circumstances.

  • All colleagues shall be treated with respect irrespective of nationality, gender, religion, or background.

5.2 Communication

  • All personnel are expected to communicate clearly, concisely, and respectfully at all times.

  • Escalation of disputes shall follow the Company’s established hierarchy; shouting or emotionally charged conflict is not acceptable.

  • The spreading of gossip or misinformation undermines trust within the organisation and is prohibited.

5.3 Conduct at Client Sites

  • Employees represent COGITANS at all times while on client premises.

  • Personnel must be punctual, adequately prepared, appropriately attired, and professional in conduct.

  • Personnel shall not make disparaging remarks about competitors or clients under any circumstances.

6. Quality, Delivery Standards, and Work Discipline

6.1 Work Standards

  • All work delivered must be accurate, complete, and fully documented.

  • Internal templates and structural standards must be followed when preparing technical material.

  • Expedient solutions ("quick fixes") that introduce long-term risk are not permitted.

6.2 Time Management

  • Personnel must be punctual for meetings, site visits, installations, and handovers.

  • Any anticipated delay must be communicated at the earliest opportunity, and not at the last moment.

6.3 Project Documentation

  • Every project must maintain up-to-date documentation, including diagrams, device inventories, configuration records, change logs, and records of customer communication.

  • Work is considered incomplete in the absence of the required documentation.

7. Use of Company Property and Resources

7.1 Responsible Use

  • Company devices and software are to be used exclusively for work purposes, unless otherwise explicitly authorised.

  • Cryptocurrency mining, the use of pirated software, torrenting, and unapproved experimentation on Company systems are strictly prohibited.

7.2 Physical Assets

  • Tools used during installations must be returned in proper working condition.

  • Any damage to Company property must be reported immediately and must not be concealed.

7.3 Expenses

  • Company expenses must be justified, reasonable, and approved in advance.

  • Supporting receipts must be provided for all claimed expenses.

8. Remote Work and Flexibility

8.1 Expectations

  • Personnel must be available during agreed working hours.

  • Regular progress updates must be provided.

  • Personnel must maintain a working environment suitable for handling calls and technical work in a professional manner.

8.2 Performance Measurement

  • The Company measures output rather than hours worked; agreed deadlines nonetheless remain non-negotiable.

9. Health, Safety, and On-Site Protocols

9.1 Personal Safety

  • All personnel must comply with applicable safety guidelines on construction sites, rooftops, industrial premises, and warehouses.

  • Personal protective equipment (helmet, vest, harness) must be worn where required.

9.2 Vehicle Safety

  • Company vehicles must be operated responsibly and in accordance with applicable traffic regulations.

  • The consumption of alcohol or drugs during working hours, or prior to operating a vehicle, is strictly prohibited.

10. Representation of COGITANS in Public and Online

10.1 Social Media

  • Client names, photographs, or project details must not be published on personal or public social media accounts.

  • The Company brand must not be associated with political statements or arguments.

  • Personal opinions must not be presented in a manner suggesting they represent an official Company position.

10.2 Public Statements

  • Any communication with media or external entities on behalf of the Company requires prior approval from management.

  • Official communications shall be issued exclusively through designated Company spokespersons.

ENFORCEMENT, REPORTING, AND ACCEPTANCE

11. Zero-Tolerance Violations

The following conduct constitutes grounds for immediate disciplinary action, including termination of contract, without prior warning:

  • Fraud, theft, or misuse of Company assets;

  • Data leakage or unauthorised sharing of data;

  • Security breaches resulting from negligence;

  • Harassment or discrimination;

  • Substance abuse during working hours;

  • Intentional provision of misinformation to clients or colleagues.

12. Reporting Mechanisms

12.1 Reporting Channels

Concerns regarding, or violations of, this Code may be reported through any of the following channels:

  • Direct Manager

  • Chief Technology Officer (CTO) / Chief Information Security Officer (CISO)

  • Chief Executive Officer (CEO)

12.2 Protection for Whistleblowers

  • The Company shall not retaliate against any individual who reports concerns in good faith.

  • Retaliation against a whistleblower constitutes a serious violation of this Code and will be treated accordingly.

13. Acceptance of the Code

Every employee, contractor, consultant, and partner is required to confirm in writing that they have read, understood, and agree to comply with this Code of Conduct in its entirety. Non-compliance with the provisions of this Code carries disciplinary consequences, up to and including termination of contract.

bottom of page