Kende semba na makambo ya ntina
Parousia Group

Mibeko

Koloba polele

Whistleblowing policy

What can be reported, to whom it is sent, what the group does and by when, and the protection the law gives to the person who reports.

Ezali na botali ya bayebi ya mibekoMokanda oyo ekomami mpe ebimisami polele, kasi conseil ya administration to bayebi ya mibeko ya etuluku bandimi yango naino te. Ezali ya nsuka te.
Minoko oyo ezali na bokonziMokanda oyo ezali na bokonzi na Lingelesi mpe na Falanse. Emonisami awa na Lingelesi mpo version oyo batali ezali naino te na monoko oyo — bobongoli ya masini ya mokanda oyo ezali na nguya ya mobeko elingaki kozala mabe koleka liyebisi oyo.

Purpose and who is protected

This policy applies to Parousia Group, to the regional holding companies — Parousia West Africa, Parousia East Africa, Parousia Europe, Parousia America, Parousia Middle East — to Echad Technologies in Singapore, and to the six solutions the group operates. It is applied in every entity, whether or not the fifty-worker threshold of Article 8(3) of Directive (EU) 2019/1937 is reached in that entity. The Legal Department owns this policy and operates the internal reporting channel described below.

Protection does not depend on holding an employment contract. Following Article 4 of the Directive, it covers a person who acquires information on a breach in a work-related context, which includes:

  • Workers, whatever the form or duration of the contract, and persons working under the supervision and direction of contractors, subcontractors and suppliers.
  • Self-employed persons, consultants and freelancers engaged by an entity of the group.
  • Shareholders and members of an administrative, management or supervisory body, including non-executive members.
  • Volunteers and trainees, whether paid or unpaid.
  • Persons whose work relationship has ended, and candidates whose information was acquired during recruitment or other pre-contractual negotiations.
  • Facilitators who assist a reporting person, colleagues and relatives who could suffer retaliation in a work-related context, and legal entities that the reporting person owns, works for, or is otherwise connected with in that context.
Proof is not requiredArticle 6(1)(a) of the Directive sets the standard: protection is owed to a person who had reasonable grounds to believe, at the time of reporting, that the information was true and fell within the scope of the policy. A report made on reasonable grounds keeps its protection even where the investigation concludes that no breach occurred. A report its author knows to be false when making it is not protected.

What can be reported

Article 2 of the Directive sets a material scope that the group applies in full and extends to its own standards. A report is in scope where it concerns an act or omission that is unlawful, that defeats the object or purpose of the rules concerned, or that the group has prohibited in its own policies.

  • Bribery, corruption, facilitation payments, kickbacks and influence peddling, including conduct caught by the UK Bribery Act 2010 or the US Foreign Corrupt Practices Act.
  • Fraud, theft, misappropriation of assets, false invoicing, and any misstatement or falsification of accounting records.
  • Public procurement irregularities, bid rigging, and breaches of competition or State aid rules.
  • Money laundering, terrorist financing, and breaches of sanctions or export control rules.
  • Forced labour, child labour, human trafficking or debt bondage in the operations of the group or in its supply chains — see the modern slavery statement for the diligence that surrounds this.
  • Breaches of personal data protection, misuse of personal data, and incidents affecting the security of network and information systems.
  • Conduct that endangers health and safety, consumer protection, food or product safety, transport safety, public health, or the environment.
  • Conflicts of interest that are concealed, undeclared benefits, and abuse of a position for private gain.
  • Retaliation, or the threat of retaliation, against a person who has reported or intends to report.
  • Any attempt to conceal, destroy or alter evidence of the above, and any instruction to do so.

Where a report concerns conduct covered by the anti-bribery and anti-corruption policy, the Legal Department informs the Compliance Department, which holds the registers and the diligence records that policy requires. The transfer does not alter the deadlines, the confidentiality or the protection set out below.

What belongs to another route

The matters below have their own procedure and are handled under it. A request sent to the reporting channel that belongs to one of those procedures is redirected to it after an assessment of admissibility, and the person who sent it is informed of the redirection.

  • An individual contractual dispute — an unpaid invoice, a contested delivery, a disagreement over the terms of a supplier or client contract — is handled under the dispute resolution clause of that contract.
  • An individual employment grievance — pay, appraisal, working time, a management decision affecting one person — is handled under the grievance procedure of the employing entity, with Human Resources.
  • A customer complaint about one of the six solutions is handled by the operator of that solution.
  • A request to exercise data protection rights — access, rectification, erasure, objection — is addressed to the Data Protection Office at contact@parousiagroup.com.
  • An accessibility barrier on the group websites is handled under the accessibility statement.
  • A security vulnerability in the group websites is handled under the coordinated vulnerability disclosure policy, which sets its own timetable and its own protection for the researcher.
  • A press enquiry is addressed to press@parousiagroup.com.

A matter that begins under one of those procedures falls within this policy from the moment it reveals a breach listed in the preceding section. Where a report is admissible in part, the admissible part is handled under this policy and the remainder is redirected, and the reporting person is told which part is handled where.

How to report internally

The internal channel is written and is operated by the Legal Department. A report is made in either of the two forms set out below, and both are received by the members of that department designated to receive and follow up reports.

Where to send a reportBy email to contact@parousiagroup.com, with REPORT as the first word of the subject line, for the attention of the Legal Department. By post to Parousia Group, 157 avenue du Livre, Kinshasa – Gombe, Democratic Republic of the Congo, in a sealed envelope marked CONFIDENTIAL — REPORT, for the attention of the Legal Department. A report states what happened, when and where it happened, who was involved and how the reporting person knows, and encloses any document lawfully held. A report that lacks detail is received and assessed on the same terms.

A report is routed to the designated members of the Legal Department without being read for any other purpose, and access to it is restricted to those members from receipt. The confidentiality of the identity of the reporting person is protected on the terms set out below, and a breach of that confidentiality by a member of staff is a disciplinary matter. The group switchboard is not a reporting channel.

A report may also be made orally at a physical meeting, which the group arranges within a reasonable time of a request made through either written route, as Article 9(2) of the Directive requires. The meeting is documented either by a recording made with the consent of the reporting person, or by a written minute of the conversation; in both cases the reporting person may check, rectify and sign the record, and receives a copy.

Anonymous reports are accepted and are acted on. Without a means of reaching the reporting person, the group cannot acknowledge receipt, cannot put a question that the investigation may require, and cannot give feedback; a pseudonymous mailbox controlled by the reporting person alone preserves those steps. A person who reported anonymously and is subsequently identified keeps the full protection of the Directive under Article 6(3).

What happens next, and by when

A report is recorded by the Legal Department on receipt, assessed for admissibility, and where admissible investigated by a person or unit independent of the facts and of the persons concerned. Diligent follow-up means that the group establishes the facts, ends the breach where one is found, and states what it has done. Where a report concerns a member of the Legal Department or a member of a governing body, the file is transferred to the board’s ethics and compliance committee, and where every possible recipient is concerned the reporting person is told so and directed to the external channels described below.

Deadlines that apply to a report, and what each one rests on
StageDeadlineBasis
Acknowledgement of receiptSeven days from receiptDirective (EU) 2019/1937, Article 9(1)(b)
Statement of whether the report is admissible and is being followed upThirty days from the acknowledgementGroup commitment
Feedback on the action envisaged or taken, and the grounds for itThree months from the acknowledgement, or from the expiry of the seven-day period where no acknowledgement was sentDirective (EU) 2019/1937, Article 9(1)(f)
Interim feedback where the investigation runs longer than three monthsEvery three months until the file is closedGroup commitment
Notice before the identity of the reporting person is disclosed where a legal obligation requires itBefore the disclosure, in writing, with reasons — unless the notice would jeopardise the related investigation or judicial proceedingsDirective (EU) 2019/1937, Article 16(3)
Physical meeting following a request to report orallyWithin a reasonable time of the requestDirective (EU) 2019/1937, Article 9(2)

Confidentiality of identity

Article 16(1) of the Directive requires that the identity of the reporting person is not disclosed, without that person’s explicit consent, to anyone beyond the staff authorised to receive and follow up reports. The same protection covers any third party named in a report and the person the report is about. Access to a report file is restricted to the designated members of the Legal Department and to those the investigation makes it necessary to involve, and the restriction is applied to the file itself.

There is one exception, and it is narrow: disclosure is possible where it is a necessary and proportionate obligation imposed by law in the context of an investigation by a national authority or of judicial proceedings, including to safeguard the rights of defence of the person concerned. In that case the group informs the reporting person in writing before the disclosure and explains the reasons, unless that information would jeopardise the investigation or the proceedings.

  • The group does not seek to identify the author of an anonymous report, and does not use message headers, access logs or document metadata for that purpose.
  • The group does not ask a reporting person to justify why they reported, or to disclose how they came by the information, beyond what the investigation of the facts requires.
  • The group does not tell the person a report is about who reported it.
  • A breach of this confidentiality duty by a member of staff is a disciplinary matter, and Article 23(1)(c) of the Directive requires that it be penalised.

Retaliation is prohibited, and presumed

Article 19 of the Directive prohibits retaliation, including the threat of it and the attempt at it, against a person protected by this policy. The prohibition is not limited to dismissal and covers each of the measures listed below.

  • Suspension, dismissal, or the equivalent measure for a self-employed person or a supplier.
  • Demotion, withholding of promotion, transfer of duties, change of place of work, reduction in wages, or change in working hours.
  • Withholding of training, a negative performance assessment or employment reference.
  • A disciplinary measure, reprimand or other penalty, including a financial one.
  • Coercion, intimidation, harassment or ostracism.
  • Discrimination, or unfavourable and unfair treatment.
  • Failure to convert a temporary contract into a permanent one where the worker had legitimate expectations of it, and non-renewal or early termination of a temporary contract.
  • Harm to reputation, particularly on social media, and blacklisting on an informal or formal sector-wide basis.
  • Early termination or cancellation of a contract for goods or services, cancellation of a licence or permit, and referral for psychiatric or medical treatment.
The burden of proof is reversedUnder Article 21(5) of the Directive, where a person who reported suffers a detriment and brings proceedings about it, the detriment is presumed to have been made in retaliation for the report. It is then for the person who took the measure to prove that it was based on duly justified grounds. Article 21(2) provides that a reporting person incurs no liability for acquiring or accessing the information reported, where that acquisition or access did not constitute a self-standing criminal offence; Article 21(7) limits liability for defamation, breach of copyright, breach of secrecy and breach of data protection rules where reporting was necessary to reveal the breach. Article 24 makes any waiver of these rights void: no employment contract, confidentiality clause, settlement agreement or supplier term of the group is applied to prevent a report or to penalise one.

The group adds one operational rule to the legal one. Where a decision affecting the employment, engagement or contract of a person known to have reported is proposed, Human Resources and the Legal Department review it against the report before it takes effect, and the grounds are recorded in writing. The review does not exempt that person from ordinary management decisions; it establishes the grounds of a measure at the time it is taken.

Reporting outside the group

Internal reporting is not a precondition. Article 10 of the Directive gives a right to report directly to a competent external authority, and the group does not treat the exercise of that right as a breach of any duty of loyalty, confidentiality or contract. The internal channel is offered in addition to the external channels, and does not condition access to them.

  • In the European Union: the authority designated by the Member State under Article 11 of the Directive, and where relevant the Union institutions, bodies, offices and agencies named in Article 10, including the European Anti-Fraud Office and the European Public Prosecutor Office.
  • In the United Kingdom: the employer, or a prescribed person listed in the Public Interest Disclosure (Prescribed Persons) Order 2014, under section 43F of the Employment Rights Act 1996. The Public Interest Disclosure Act 1998 inserted that Part IVA into the 1996 Act; a qualifying disclosure under section 43B must be made in the reasonable belief that it is in the public interest, and sections 47B and 103A give the remedies for detriment and for dismissal.
  • In the United States: the Securities and Exchange Commission under Section 21F of the Securities Exchange Act, the Occupational Safety and Health Administration for a complaint under section 806 of the Sarbanes-Oxley Act, and the Department of Justice.
  • Elsewhere the group operates: the competent authority of that jurisdiction — for example the Agence de prévention et de lutte contre la corruption in the Democratic Republic of the Congo, the Ethics and Anti-Corruption Commission in Kenya, the Economic and Financial Crimes Commission in Nigeria, and the Corrupt Practices Investigation Bureau in Singapore.
No clause of the group stands between a person and a regulatorNo confidentiality agreement, employment contract, settlement, severance or supplier term of any entity of the group restricts a person from communicating directly with a competent authority about a possible breach, and none requires prior notice to the group or its permission. This states expressly what SEC Rule 21F-17(a) requires of any such agreement and what Article 24 of the Directive makes void in any event, and it applies whether or not the authority concerned is a securities regulator. Nothing in this policy limits an award a person may be eligible to receive under Section 21F of the Securities Exchange Act.

Public disclosure — to the press or otherwise to the public — is protected under Article 15 of the Directive where the person first reported externally, or internally and then externally, and no appropriate action was taken within the applicable timeframe; or where the person has reasonable grounds to believe that the breach may constitute an imminent or manifest danger to the public interest, or that external reporting carries a risk of retaliation or offers little prospect of the breach being effectively addressed. Where those conditions are met, the group brings no proceedings against the person who made the disclosure and supports none.

Personal data and records

A report is a processing of personal data. Processing is limited to what the handling of the report requires. Personal data that are manifestly not relevant to the handling of a report are not collected, and where they are collected accidentally they are deleted without undue delay, as Article 17 of the Directive and Article 5(1)(c) of the GDPR require. The Data Protection Office is consulted on the processing described in this section and on any change to it.

What is kept for a report, why, on what basis and for how long
RecordPurposeLegal basisRetention
The report and its attachmentsAssessing admissibility, investigating, ending the breachGDPR Article 6(1)(c) where the channel is a legal obligation; Article 6(1)(f) elsewhere, the interest being the detection of breachesWhile the file is open, then five years from closure, unless proceedings or a legal retention duty require longer
Identity and contact details of the reporting person, where givenAcknowledging receipt, asking questions, giving feedback, protecting against retaliationSame, with the confidentiality duty of Article 16 of the DirectiveSame, held separately from the file with access restricted to the designated members of the Legal Department
Recording or written minute of an oral reportEstablishing what was said, and allowing the reporting person to correct itConsent for a recording, Article 18(2) of the DirectiveSame as the file
Special category data, where a report unavoidably contains themInvestigating the facts reportedGDPR Article 9(2)(f) or 9(2)(g), depending on the matterSame as the file, with access further restricted
Register of reports without identifying data — date, subject matter, outcomeOversight of the channel, reporting to the governing body, publication of aggregate figuresGDPR Article 6(1)(f)Ten years
Personal data manifestly not relevant to the handling of the reportNoneNoneDeleted without undue delay

The rights of access, rectification, erasure and objection apply to a report file, and so does one restriction: the right of access does not extend to obtaining the identity of the reporting person, because Article 16 of the Directive protects it and Article 23 of the GDPR allows that restriction. In the Democratic Republic of the Congo, where the group has its registered office, the processing of personal data is governed by Ordonnance-loi n° 23/010 du 13 mars 2023 portant code du numérique. Requests and questions on the processing described here are addressed to the Data Protection Office at contact@parousiagroup.com.

The person a report is about

Article 22 of the Directive protects the person concerned by a report as well. That person keeps the presumption of innocence, the right to an effective remedy, the right to a fair trial and the rights of defence, including the right to be heard and to access the file. The identity of a person concerned is protected for as long as the investigation is ongoing, on the same terms as that of the reporting person.

The group takes no measure against a person on the basis of an unverified allegation. A report that its author knew to be false when making it is not protected: Article 23(2) of the Directive requires that such conduct be penalised, and the group treats it as a disciplinary matter and, where the law allows, as a matter for the courts. The distinction between a mistaken report and a false one rests on the standard of reasonable grounds set out in the first section of this policy.

Governance and review of this policy

The Legal Department owns this policy, operates the reporting channel, designates the members of the department who receive and follow up reports, and keeps the register of reports described above. The Compliance Department is informed where the facts fall under the anti-bribery and anti-corruption policy; Human Resources is involved where a measure affecting the employment of a protected person is proposed; the Data Protection Office is consulted on the processing of the data held in a report file.

The Legal Department reports to the board’s ethics and compliance committee on the operation of the channel, on the basis of the register kept without identifying data. It reviews this policy at least once a year, and whenever the law applicable in a country where the group operates, the organisation of the channel or a finding made under this policy requires an amendment. The version in force is the one published on this site, and the date it was last reviewed is carried at the head of this document.

The deadlines, the duty of confidentiality and the prohibition of retaliation set out above are obligations of law and of this policy, and they apply to every report from the day it is received.

Moboko ya mibeko

  • Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law
  • Regulation (EU) 2016/679 (GDPR), Articles 5, 6, 9, 15 and 23
  • Public Interest Disclosure Act 1998 (UK), inserting Part IVA into the Employment Rights Act 1996
  • Employment Rights Act 1996 (UK), sections 43B, 43C, 43F, 47B and 103A
  • Public Interest Disclosure (Prescribed Persons) Order 2014 (SI 2014/2418)
  • Dodd-Frank Wall Street Reform and Consumer Protection Act 2010, section 922 — Securities Exchange Act section 21F (15 U.S.C. 78u-6)
  • SEC Rule 21F-17(a) (17 C.F.R. 240.21F-17)
  • Sarbanes-Oxley Act of 2002, section 806 (18 U.S.C. 1514A)
  • Loi n° 2016-1691 du 9 décembre 2016 (Sapin II), modifiée par la loi n° 2022-401 du 21 mars 2022
  • Hinweisgeberschutzgesetz of 31 May 2023 (Germany)
  • Ordonnance-loi n° 23/010 du 13 mars 2023 portant code du numérique (DRC)
  • UK Bribery Act 2010
  • Foreign Corrupt Practices Act (15 U.S.C. 78dd-1 et seq.)
  • United Nations Convention against Corruption (2003)