COMPLIANCE

SIPAY PLUS fosters a culture of compliance among its partners, staff, customers, suppliers, collaborators and other interested parties.

 

SIPAY has a Criminal Risk Management and Corporate Compliance System (Compliance), and it is essential to communicate to its partners, staff, collaborators, customers, suppliers and other interested parties the objective of ensuring professional and commercial performance in line with the company’s mission, vision, values and commitments, regulatory compliance and risk prevention.

A compliance system in line with SIPAY’s responsible ethical model

As part of the implementation of the Criminal Risk Management and Corporate Compliance System, the Sole Director of SIPAY has approved, as first-level internal compliance regulations, the Criminal Risk Prevention Policy and the Code of Conduct, which establish the guiding compliance principles that we wish to establish in relationships with all our partners, staff, collaborators, customers, suppliers and other interested parties.

Compliance Committee

In order to provide SIPAY with the mechanisms necessary to ensure compliance with regulations and self-regulation systems, respect for the commitments made, and the supervision and improvement of the criminal risk management and corporate compliance system, the Sole Director of SIPAY has appointed and empowered a Compliance Committee made up of internal experts and external advisors on regulatory requirements and their adaptation, on compliance risk management and the design of controls, action plans, self-assessments and verifications, in order to ensure the effective fulfilment of the company’s obligations and the prevention of risks.

Whistleblowing channel

At SIPAY we have zero tolerance for non-compliance with regulations, with our ethical principles and for malpractice.

 

SIPAY makes its Whistleblowing channel available to its members, collaborators, customers, suppliers and any interested party, to report on a confidential and even anonymous basis any suspicion or knowledge of conduct, actions or omissions that may constitute an infringement of European Union Law; a criminal or administrative offence, or any breach of the values, guidelines for action or rules of conduct set out in the Code of Conduct, in the Criminal Risk Prevention Policy and in SIPAY’s other internal regulations, committed by a member of SIPAY in the exercise of their duties at the company.

 

Consult our Prevention Policy HERE.

 

Consult our Code of Conduct HERE.

 

Access the management procedure of our Whistleblowing Channel HERE.

WHISTLEBLOWING CHANNEL

SIPAY is fully committed to the highest ethical and regulatory compliance standards in its relationships with all its partners, staff, collaborators, customers, suppliers and other interested parties in all the activities it carries out.

 

To ensure the maintenance of the Criminal Risk Management and regulatory compliance System, the Sole Director of SIPAY has appointed and empowered a Compliance Committee made up of internal experts who are constantly advised by specialists in corporate risk management, whose duties include the management of the Whistleblowing channel.

 

SIPAY makes its Whistleblowing channel available to its members and any interested party to report on a confidential and, where technically possible, anonymous basis, any suspicion or knowledge of conduct, actions or omissions committed by a member of SIPAY in the exercise of their duties that constitute:

  • an infringement of European Union Law (legal infringement);
  • a serious or very serious criminal or administrative offence:
  • any breach of the values, guidelines for action or rules of conduct set out in the Code of Conduct, in the Criminal Risk Prevention Policy and in SIPAY’s other internal regulations, including infringements relating to the prevention of money laundering and terrorist financing, where applicable.

The whistleblower may also request, through said form, an in-person meeting with the Compliance Committee for the purpose of making a report or complaint of those indicated above. In such a case, the Compliance Committee will summon them to said meeting within a maximum period of seven (7) working days. In the case of an in-person meeting, and after obtaining the express and informed consent of the whistleblower regarding the processing of their personal data, the conversation held will be documented in one of the following ways:

  • Recording of the conversation in a secure, durable and accessible format.
  • Complete and accurate transcription of the conversation held. In this case, the whistleblower will be offered the opportunity to check, rectify and accept, by means of their signature, the transcription of the conversation

Without constituting the preferred means for submitting reports, and as an alternative to this SIPAY Whistleblowing channel, reports may be submitted through the external reporting channels to the Independent Whistleblower Protection Authority, to the competent administrative authorities, where applicable, or to the institutions, bodies and agencies of the European Union.

 

All reports received will be entered into a reporting register, assigning each one a unique reference number by which it can be identified throughout its entire processing.

 

All reports may be anonymous, that is, identification of the person making the report is not mandatory but optional.

 

Please note that only in the event that the informant or whistleblower provides an address, email or secure location for the purpose of receiving notifications will they be sent an acknowledgement of receipt with a reference number for the report; SIPAY may request additional information if necessary and keep them informed of whether or not it is admitted for processing and of the corresponding resolution.

 

Reports will be assessed and investigated with the aim of resolving them within a period not exceeding three (3) months from receipt of the report, without prejudice to any additional periods that are legally applicable when the complexity of the facts so requires, in accordance with Law 2/2023.

 

SIPAY states that the Whistleblowing channel complies with the following principles and offers the following guarantees, the specific development of which can be consulted in the Whistleblowing Channel Management Procedure:

  • Maximum confidentiality.
  • Guarantee of the right of defence, presumption of innocence and right to honour.
  • Guarantee of the principle of evidence and adversarial proceedings.
  • Management of conflicts of interest.
  • Prohibition of retaliation, including threats and attempted retaliation.
  • Protection of personal data.

Submit a report:

Personal data is not mandatory. You can submit an anonymous report.

Basic data protection information: Controller: SIPAY PLUS, SL. Purpose: to process, investigate and/or resolve reports. They will only be handled by those who perform management functions for the Whistleblowing Channel at SIPAY in accordance with the Whistleblowing Channel Management Procedure, mainly the Compliance Committee. The utmost confidentiality and safekeeping is guaranteed under security measures appropriate to the type of data and to the risk of the information processed. Type of data: Identifying data and, depending on what the user states in the text of the report or attached files, other types of data may be included. Legal basis: Compliance with a legal obligation as provided for in Law 2/2023, of 20 February, regulating the protection of persons who report regulatory infringements and the fight against corruption, and SIPAY's legitimate interest in complying with the requirements regarding corporate risk prevention, especially those related to the possible criminal liability of the legal entity, pursuant to Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights. Recipients: Your data may be disclosed to third parties exclusively in the case of external legal advisors and to the judicial bodies and to the State Security Forces and Bodies or administrative authority, when necessary. Retention: the data will be kept in the Whistleblowing Channel system for the time strictly necessary to decide whether it is appropriate to initiate an investigation into the reported facts and, where applicable, while the process of investigating and resolving the submitted reports is carried out, and always for a maximum period of 3 months from the date the report is received. Exercise of rights: dpo@sipay.es enclosing a photocopy of your ID card or substitute identity document and indicating "Ref. Personal Data SIPAY Whistleblowing Channel" for the processing of said rights by the Compliance Committee. If the exercise of your rights is not attended to, you may file a complaint with the Spanish Data Protection Agency. More information: Privacy Policy.

The use of this form for commercial purposes is not authorized.