QUALITY POLICY STATEMENT
Vermantia has developed and implements an Integrated Management System in accordance with the requirements of the ISO 9001:2015 standard with scope: «Design, Production and Support of Digital Audio / Visual Services Content and Applications for Lotteries, Gaming & Betting Operators».
The Management of the company is committed to adhere to the Integrated Management System with consistency and with the aim of providing products and services of consistent and recognized quality. This Company Policy Statement is a commitment to comply with national laws, EU and regulatory directives, the requirements of the standard and to continuously improve the effectiveness of the Integrated Management System. The company is committed to observe and fully implement the applicable legislation governing its operations.
For the effective implementation of the above, Vermantia establishes objective quality targets at all levels of its operations, the achievement of which are reviewed and evaluated by the Management, within the framework of the scheduled Reviews, of the Integrated Management System (IMS), with the ultimate goal of its continuous improvement.
The Management is committed to the continuous training of its employees for the continuous improvement of the Integrated Management System. The above policy applies to all activities of the company, is communicated, and made available both within the company and to stakeholders as appropriate and it is ensured that it is applied at all levels, with the main purpose of creating awareness of the Principles and Philosophy of the System.
The Company, through the unwavering commitment of the Management, to adherence to the principles set out in this Policy and, more generally, throughout the Company’s Integrated Management System (IMS), looks forward to the continuous and steady growth of its business activity, as a by-product of satisfying the requirements of its customers and continuously increasing the quality of the products and services provided by the Company.
Top Management
04/05/2026
Information Security Policy
Vermantia implements an Integrated Management System that complies with the Information
Security Management System ISO 27001:2022 standard and is committed to:
- Ensuring the confidentiality, integrity and availability of information processed, stored, transferred electronically or physically through the company’s staff and information systems.
- The timely and rapid identification and response to emergencies related to a breach (or possible breach) of the security of the company’s information.
- Ensuring the information security policy and the information security objectives are established and are compatible with the strategic direction of the company.
- The protection of the company’s investment in information and communication
- Compliance with the requirements of the applicable legislation in matters of personal data management, communications privacy, copyright, etc. in the area of its activities.
- The continuous improvement of the Integrated Management System.
- Define the business requirements regarding information systems availability.
- Define the interested parties and internal/external issues.
- The proper assessment and monitoring of Risks and Opportunities.
It is important for Vermantia to have the necessary resources to support the Integrated Management System and to provide the necessary knowledge to its staff in matters of information security, utilizing their skills and abilities.
Vermantia fully recognizes the objectives of the Integrated Management System and supports their implementation.
Top Management
04/05/2026
Whistleblowing Policy and Procedure for Submission and Management of Reports (Law 4990/2022) of the Company VERMANTIA PRODUCTIONS S.A.
Business Registry No. 69996303000
1. Introduction
The company under the name “VERMANTIA PRODUCTIONS S.A.” (hereinafter referred to as the “Company”), committed to complying with the requirements of the National and European Legislation on the Protection of Personal Data as well as with the provisions of Law 4990/2022 (Government Gazette A’ 210/ 11.11.2022) and the European Directive 2019/1937/ΕU on the Protection of Public Interest Witnesses, as applicable, and aiming at a transparent and responsible business environment and a high level of business ethics, has prepared the present Whistleblowing Policy regarding the procedure for the submission and management of reports (hereinafter referred to as the “Policy”).
This Policy aims to define the procedure for submitting, receiving and following up on reports-complaints, i.e. oral or written or via an electronic platform for the provision of information with the recipient being the Company and specifically the Person Responsible for Receiving and Monitoring Reports (hereinafter the “Y.P.P.A.“), regarding violations that fall within the scope of application of Law 4990/2022, as defined in paragraph 2.3 below (hereinafter the “Reports“). In addition, the purpose of this Policy is also to determine the procedure for submitting reports – complaints, i.e. oral or written or via an electronic platform for the provision of information with the recipient being the National Transparency Authority (EAD), regarding violations that fall within the scope of application of Law 4990/2022 (hereinafter the “External Reports“).
2. Scope of the Policy
2.1 This Policy applies to those employed by the Company and who have acquired, in the context of their employment, information regarding violations (as set out in point 2.3) and in particular:
(a) shareholders and all members of the Board of Directors,
(b) the Company’s personnel in general, regardless of the employment status to which such personnel are subject (including persons whose employment relationship has ended for any reason, as well as persons whose employment relationship has not yet begun, provided that the information regarding any violations was obtained during the recruitment process or at another stage of negotiation prior to the conclusion of an employment contract),
(c) suppliers in general and persons who provide services to the Company, as well as those working under the supervision and instructions of these (suppliers and/or consultants),
(d) as well as any other natural person falling within the scope of the relevant applicable EU and national legislation.
Furthermore, protection is also offered to third-party legal and natural persons who are associated with the above-mentioned persons and who may suffer retaliation in the work environment (e.g. colleagues or relatives of the persons who submit a Report).
2.2 Reports should always be made in good faith by the Reporter, subject to the Reporter’s honest and reasonable belief that (i) a violation, defined as an act or omission that is punishable under Union law or is contrary to the object or purpose of the rules of Union law, falling within the scope of Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 (L 305) and Law 4990/2022, has been committed or is likely to be committed, as well as (ii) other serious misconduct or matters have been committed or are likely to be committed, as set out below.
Persons falling within the scope of the Policy, in accordance with par. 2.1, are encouraged to submit Reports of criminal acts, suspected incidents of illegal conduct, incidents of mismanagement or serious misconduct and omissions in relation to the Company’s procedures (hereinafter the “Reporters or Reporting Person(s)“).
2.3 The Reports concern the following violations:
(a) acts involving elements of gross negligence, suspicion of fraud or corruption,
(b) violations in matters of network and information system security,
(c) serious misconduct, as well as material violations, which concern the provision of services by the Company in general,
(d) offering or accepting a bribe,
(e) theft, embezzlement, abuse, legalization of proceeds from criminal activities (“money laundering”), forgery, violation of confidentiality and personal data, violation of competition law, violations in accounting and control matters,
(f) intimidation, discriminatory treatment, threat, extortion, use of violence, insult, defamation, sexual harassment,
(g) misuse/embezzlement of Company assets and resources in general,
(h) violations of EU law in general in the areas of public procurement, product safety and conformity, transport safety, environmental protection, radiation protection, public health and consumer protection,
(i) violations related to the internal market (indicatively competition and state aid rules, rules on corporate taxation, etc.).
2.4 The following may not be the subject of a Report:
(a) any disagreement on issues concerning policies and decisions of the Company’s Management in general,
(b) personal issues and disagreements with colleagues or superiors,
(c) rumours.
3. Purpose and basic principles of the Policy
3.1 The establishment of this Policy aims to define the principles and framework under which the Company receives, processes and investigates named or anonymous Reports of misconduct, omissions or other criminal acts that have come to the attention of persons who fall, according to par. 2.1, within the scope of the Policy, thus encouraging them to make Reports, in the event that they become aware of illegal or unethical behavior within the Company.
A further purpose of this Policy is to ensure a comprehensive framework for the protection of persons who report violations of the provisions listed in the previous section, while aiming at protecting human dignity, respecting the personality rights of employees and creating a safe working environment with guarantees of transparency and lawful behavior.
3.2 In order to serve the above fundamental purpose, the Policy aims to create a reliable mechanism for:
(a) supporting and protecting against malicious acts the persons of paragraph 2.1 who in good faith make a Report on an issue that they consider to constitute a violation and is related to the operation of the Company according to paragraph 2.2,
(b) the effective management of Reports, providing guarantees that such Reports on possible violations are taken seriously and are confidential, to the extent that this does not contradict the applicable legislation,
(c) ensuring the exclusion of any form of retaliation against persons who submit any Report.
This Policy provides ways for such persons to express their concerns and receive information regarding the outcome of each investigation and creates a clear procedure for the submission and management of Reports with quick reflexes and clear roles.
3.3 The Policy is governed by the following fundamental principles:
(a) ensuring the collection and investigation of all evidence and information related to each Report submitted with the aim of providing a reasonably substantiated response,
(b) ensuring an environment of security and trust, to encourage the good faith submission of Reports on illegal acts or misconduct that come to the attention of the persons referred to in paragraph 2.1,
(c) ensuring the anonymity and protection of the personal data of the persons submitting Reports, without compromising the current position they hold in the Company or their future professional development (prohibition of acts of retaliation),
(d) treating Reports with impartiality, respect for general and specific principles and values, such as respect of personality rights, human dignity, trust, transparency, decency, honesty and professional conscientiousness.
In this context, the Company undertakes to: (i) investigate Reports diligently, within a reasonable time and without discrimination, (ii) respond attentively to each Report, demonstrating courtesy and understanding, (iii) make every effort and exhaust every possibility of immediate settlement of the Report and (iv) not to argue with or antagonize the person submitting the Report, (v) provide guidance on existing communication mechanisms on relevant issues.
4. Anonymity of the Reporting Person
4.1 The Company encourages, to the extent possible, named Reports, while anonymous Reports are also accepted in any case. It is noted, however, that anonymous Reports make the task of analytical investigation more difficult, due to the difficulty of acquiring information from an anonymous reporter and due to the difficulty of assessing the reliability of the Reports. Anonymous Reports are investigated by the Company considering, among other things, the seriousness of the issue and the likelihood of confirmation of the Report by independent and reliable sources.
4.2 Anonymous Reports submitted are examined depending on their degree of documentation and the possibility of identifying the illegal action they describe.
4.3 Any reference to sensitive personal data based on the applicable regulatory framework (e.g. data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, membership in a trade union, genetic and biometric data, health, sexual life, sexual orientation) must be avoided, unless it is directly related to the subject of the Report. Otherwise, the specific information will be deleted.
4.4 The Company is committed to maintaining the anonymity of the Reporting Person and to not taking any actions that may result in the disclosure of their identity. However, the disclosure of the Reporting Person’s identity may be required in the context of any judicial investigation of the case, subject to the conditions of article 14 of Law 4990/2022.
4.5 In the event that the disclosure of the identity of the Reporting Person is necessary in the context of any investigations by competent authorities or legal proceedings, then this will be carried out after the Company has informed the Reporting Person in writing about the reasons for disclosing their identity and other confidential information, unless such a notice undermines the investigations or legal proceedings. After the notice, the Reporting Person is entitled to submit written observations to the Company, which shall not be disclosed. Unjustified failure to provide such a notice by the Company constitutes a disciplinary offense of the Company personnel member who omitted it, while the Reporting Person is entitled to submit written observations to the competent authority regarding such disclosure. If the reasons included in the observations are not deemed sufficient, the disclosure of the identity and other confidential information of the Reporting Person is not prevented.
5. Protection of the Reporting Person and relevant provisions
5.1 From the moment it receives a Report, the Company’s Management is committed to protecting the Reporting Person from:
(a) any acts of “retaliation”, as defined in detail below in paragraph 5.3, regarding the position held in the Company and/or their future professional development,
(b) any other type of discrimination or any type of threat or adverse treatment,
(c) acts or behaviors of targeting/victimization on the part of the person responsible, as stated below, for the receipt and examination of the Report.
5.2 Personal data and any type of information that directly or indirectly leads to the identification of the Reporting Person are not disclosed to anyone other than the authorized members of the Company’s staff who are responsible for receiving or monitoring Reports, unless the Reporting Person provides their consent in advance and in writing.
For this purpose, the Company takes appropriate technical and organizational measures, such as pseudonymization techniques when monitoring the Report and communicating with the competent authorities.
5.3 “Retaliation” is defined as the negative consequences that the Reporting Person (and/or legal entities of their interests and/or third parties associated with them) may experience, from anyone (members of the management, superiors, colleagues, partners, external consultants, suppliers, customers), due to the submission of a Report or their participation in an investigation into a submitted Report. Indicatively, possible acts of retaliation include: (i) termination, dismissal or other equivalent measures, (ii) workplace harassment (mobbing), (iii) adverse treatment, (iv) assignment of excessive duties, (v) removal of duties without justification and replacement with new duties, omission or deprivation of promotion, change of place of work, change of schedule, (vi) obstruction of the exercise of labor rights (participation in training, taking leave, developing union action, etc.), (vii) reprimand, imposition of disciplinary or other measure, (viii) inclusion in a list of undesirables (“blacklist”). In the event of retaliation in the workplace, the victim reports the incident to the Human Resources Department, which immediately proceeds to investigate the issue, informing them of the progress of the process, in order to normalize the employee’s working environment again. In this process, the presumption of innocence of both the complainant and the person who is the object of the complaint is taken into account in order to protect all those involved and ensure the necessary objectivity and impartiality. If the Company confirms any of the aforementioned situations that constitutes vindictive behavior in response a Report, such retaliation is invalid and has no legal effect.
5.4 In any case, Reporting Persons are subject to the measures and protection provided in detail in the applicable regulatory framework (indicatively articles 18 to 22 of Law 4990/2022).
5.5 If the Reporting Person is proven to knowingly submit a false or malicious Report, or to knowingly abuse this Policy or make false public disclosures, they will not be protected against retaliation and may be subject to measures being taken by the Company against them, in accordance with the provisions of Law 4990/2022 with consequences regarding their employment relationship, such as, among others, the early termination of their employment contract, as well as the imposition of a fine and imprisonment of at least two (2) years, depending on the case, in accordance with article 23 par. 3 of Law 4990/2022.
5.6 The persons affected by the Report (hereinafter referred to as the “Reportees”) have the right to be informed of the misconduct for which they are accused, of the persons who have access to the data included in the Report in the context of its examination, as well as the right to be called to a defence. However, if there is a serious risk that the above information will hinder the investigation of the case and the collection of the necessary evidence, the notice of the Reportees may be postponed until such risk ceases to exist. If the Report ultimately proves to be unfounded, the Reportee is not informed of the Report against them, for reasons of protecting the working environment within the Company, unless the Reportee exercises the right to access their personal data or there is a relevant legal obligation.
6. Procedure for submitting Reports
6.1 In order to facilitate the investigation and their proper evaluation, Reports must include, indicatively and not exhaustively, the following:
(a) the events that gave rise to the Reporting Person’s concern/suspicion, with reference to the names of the persons involved, dates, documents and locations, and
(b) the reason that led to the submission of the Report.
In no case is the Report expected to prove the Reporting Person’s possible concerns/suspicions regarding the reported violation, however, it is encouraged to provide all available information, in order to facilitate the Company’s investigation of the case.
6.2 Reports can be submitted electronically by email to the email address yppa-anafores@vermantia.com or by completing the appropriate form posted by the Company on its website (Annex hereto) or by sending the appropriate form to the address of the registered office of VERMANTIA PRODUCTIONS S.A. (STELIOU KARAGIORGI 4. HERAKLION ATTICA P.C. 14121) for the attention of the Person Responsible for Receiving and Monitoring Reports (Y.P.P.A), with the indication “Confidential”.
6.3 Any expression of protest, dissatisfaction and/or complaint, which is not submitted through this procedure, is not recognized and is not treated by the Company as a Report and is not covered by the provisions and regulations of this Policy.
6.4 YPPA shall treat all written Reports as confidential and shall be bound, both upon receipt and upon monitoring the progress of the Reports, by an obligation to maintain the confidentiality of the information contained therein.
6.5 Those affected have the opportunity to submit an External Report directly to the National Transparency Authority (hereinafter the “EAD”). The External Report is submitted in writing or via an electronic platform, accessible to people with disabilities, and in particular:
- Electronically: by email to kataggelies@aead.gr or by completing the corresponding Report form: https://aead.gr/submit-complaint/
- By post: by sending it to the postal address of the EAD: Lenorman 195 & Amfiaraou, PC 104 42, Athens.
- In person (or through a legally authorized representative) by submitting the External Report to the EAD premises: Lenorman 195 & Amfiaraou, PC 104 42, Athens.
7. Management of Reports
7.1 All Reports are investigated seriously and in accordance with this Policy and the law.
For the management of Reports as well as for any issue falling under this Policy, YPPA shall act as a reporting person to whom Reports are addressed.
7.2 YPPA shall maintain a file, which contains the following information for each Report:
(a) number, subject, category and origin,
(b) information regarding the investigation of each Report and
(c) the final result of the investigation and the actions that have been implemented in its context.
The file shall be kept either in electronic or paper form, with the necessary security specifications and shall include all Reports received by YPPA, as well as the documents related to each of them, from the time of their submission.
7.3 The file shall be kept for a minimum period of five (5) years from the date each item came into the possession of YPPA, otherwise for a reasonable period of time and in any case, for the entire period until the completion of the investigation or any legal proceedings. All Reports shall be stored appropriately and only the competent persons shall have access to them.
7.4 The Company’s YPPA:
(a) must perform their duties with integrity, objectivity, impartiality, transparency and social responsibility, respect and observe the rules of confidentiality and secrecy for matters that they became aware of during the exercise of their duties and refrain from handling specific cases, declaring conflict of interest, if there is such a situation,
(b) receives Reports regarding violations that fall within the scope of this Policy, monitors their development and maintains communication with the Reporting Person and, if necessary, requests further information from them,
(c) immediately informs, within seven (7) working days, the Reporting Person of the receipt of the Report, providing a relevant confirmation of receipt (paper or electronic),
(d) evaluates, initially, the seriousness and credibility of the Report and reports within five (5) days to the CEO, who then informs the Board of Directors, if this, in his judgment, is justified by the content of the Report,
(e) following the notice to the CEO, a three-member ad hoc Report Management Committee (hereinafter the “EDA”) is established by the YPPA, consisting of a manager (preferably related to the department where the violation is identified), the YPPA and a member (even external) appointed by the CEO. A person named in the Report, either as a perpetrator, an accomplice, or a witness, does not participate in the EDA. The YPPA may maintain communication with the Reporting Person throughout the investigation, request clarifications or additional information or their assistance. The EDA examines the reported incidents with discretion and confidentiality, without becoming aware of the identity of the Reporting Person. Access by third parties to the Report data is limited, i.e. the Report and the critical facts it presents are disclosed to the required extent and only to the persons deemed necessary for the conduct of the investigation, who are previously bound, also by their duties, to observe the rules of confidentiality and secrecy. Participants in any way in the investigation (other employees who are called upon to contribute due to their position, duties and knowledge) must cooperate harmoniously and substantially with the aim of resolving the reported incident. At the end of the investigation, which may not exceed thirty (30) days, the EDA shall make a recommendation to the company’s management, in order to close the case (if it is determined that the Report is essentially unfounded) or to take appropriate internal corrective measures or to take legal action before the competent authorities. Any delay in the investigation must be adequately justified. The measures may include (but are not limited to): (a) additional training of employees and associates, (b) establishment of new internal control safeguards, (c) amendments to existing policies and procedures, (d) disciplinary sanctions including permanent removal/dismissal, (e) legal action.
All departments of the Company must provide all possible and necessary assistance and support during the investigation of the Reports,
(f) terminates the procedure by archiving the Report, if it is incomprehensible or is submitted abusively or does not contain incidents of violations that fall within the scope of application of Law 4990/2022 or there are no serious indications of such a violation and communicates the relevant decision to the Reporting Person, who, if they consider that the Report was not dealt with effectively, may resubmit it to the EAD, which, as an external channel, exercises the responsibilities of article 12 of Law 4990/2022,
(g) ensures the protection of the confidentiality of the identity of the Reporting Person and any third party named in the Report, preventing access to it by unauthorized persons,
(h) provides information to the Reporting Person on the actions taken within a reasonable period of time, which does not exceed three (3) months from the acknowledgement of receipt of the Report, or if no acknowledgement has been sent to the Reporting Person, three (3) months from the end of seven (7) working days from the submission of the Report,
(i) provides clear and easily accessible information on the procedures under which Reports can be submitted to the EAD and, where appropriate, to public bodies or institutions and other bodies or organizations of the European Union,
(k) plans and coordinates training activities on ethics and integrity, participates in the formulation of internal policies to strengthen integrity and transparency in the Company.
7.5 In the event that the Report relates to a person involved in the investigation process, the latter must abstain from examining the Report and will be replaced by another person.
7.6 The term of office of the Y.P.P.A. lasts at least one (1) calendar year, but may be terminated earlier for cause. If the Y.P.P.A. performs other duties, the Company must ensure that the exercise of these duties does not affect their independence and does not lead to a conflict of interest in relation to their above duties. For example, the Company must accept a request from the YPPA to abstain from their other duties in specific cases, provided that the YPPA declares their impediment to the Company’s management and invokes a case of conflict of interest.
8. Obligations
8.1 The managers and Directors of the individual departments and divisions of the Company are required to:
(a) inform their subordinates, by planning and coordinating training activities regarding this Policy and the relevant procedures, under the clear and complete guidance of the YPPA,
(b) encourage their subordinates to adopt a positive and open mindset, so that they feel that they can express their concerns without hesitation and fear and
(c) implement the provisions and regulations of this Policy, as well as the decisions of the competent corporate bodies for the handling and management of Reports.
8.2 Persons who fall within the scope of the Policy, in accordance with par. 2.1, must:
(a) be aware of the existence of this Policy and the relevant procedures it establishes,
(b) when submitting a Report, do so in good faith and with supporting evidence and declare the existence of any direct personal interest related to the matter,
(c) request from the YPPA, any information or clarification regarding the application of this Policy, as well as the framework of their rights and protection measures.
9. Personal data
9.1 Any processing of personal data that takes place under this Policy is carried out in accordance with the national and European legislation in force at any time, with the aim of fulfilling the obligation to establish reporting channels and take the necessary measures each time. The personal data of all those involved are protected and are subject to processing for the sole purpose of verifying the validity or otherwise of a specific Report and investigating it.
9.2 Access to the data included in the Reports may only be provided to the persons included in them (Reporting Person and Reportee), the persons involved in the management and investigation of the incident in question, the witnesses and anyone with a legitimate interest. The Company takes all necessary technical and organizational measures to protect the relevant personal data.
The extent of access granted to the applicant is decided on a case-by-case basis by the YPPA and varies depending on the status of the applicant and the seriousness of the case. When access is granted, the details of the Reporting Person and witnesses are withheld, unless they have given their express consent, as well as if it is proven that the Report was malicious.
9.3 Data subjects will have all the rights provided for by Applicable Law:
- right of access to personal data concerning them,
- right to request the amendment of incorrect, inaccurate or incomplete personal data relating to themselves,
iii. right to request the deletion of their personal data, in the cases provided for by applicable law (right to erasure),
- right to request the restriction of their personal data, in the cases provided for by applicable law,
- right to object to the processing of their personal data, in the cases provided for by applicable law,
- right to submit a Report to the Hellenic Data Protection Authority (HDPA) at the following contact details: Address: 1-3 Kifissias Ave., 115 23 Athens, Greece Telephone: +30-210 6475600 Fax: +30-210 6475628 Email: complaints@dpa.gr
9.4 In accordance with Law 4990/2022, and in particular article 15, the controller (in this case the Company), by way of derogation from point A of paragraph 1 of article 5, articles 12 and 13, paragraphs 1 to 4 of article 14 and article 34 of the General Data Protection Regulation, does not provide relevant information on the processing of personal data to the Reportee and to any third party in their capacity as a data subject named in the Report or the personal data resulting from monitoring measures and in particular for the source of origin according to point (f) of paragraph 2 of Article 14 of the General Data Protection Regulation, pursuant to paragraph 5 of Article 14 of the General Data Protection Regulation, in conjunction with Article 23 of the General Data Protection Regulation, for as long as required and if deemed necessary for the purpose of preventing and addressing attempts to obstruct the Report, obstruct, cancel or delay monitoring measures, in particular with regard to investigations, or attempts to identify the reporting persons, as well as for their protection against retaliation.
The Company may not satisfy the rights provided for in Articles 15 to 22 of the General Data Protection Regulation, when they are exercised by the aforementioned and third parties named in the Report, or resulted from monitoring measures in accordance with the above.
9.5 In cases of restriction of the rights of the data subjects provided for above, the Company shall take all necessary technical and organizational measures to protect the rights and freedoms of the persons. When the Company refuses to satisfy the rights, without informing about the reason for the restriction, the data subject is entitled to file a complaint with the Hellenic Data Protection Authority (HDPA), which may investigate the existence of the conditions for the restriction of the rights and inform the subject accordingly, provided that such information is not detrimental to the fulfillment of these purposes.
The Company, in the event of a personal data breach, does not proceed to a notification, pursuant to paragraph 1 of article 34 of the General Data Protection Regulation, of the data subject, if such notification may be detrimental to the intended purposes of this Policy and informs the Data Protection Authority accordingly, which may, after investigating the validity of the reasons invoked, request the notification to be made, if it deems that the conditions for the omission of the notification are not met.
9.6 All Personal Data are kept exclusively and are not transferred outside the EU.
9.7 In any case, the Company takes all necessary technical and organizational measures to protect personal data. In particular, as mentioned above, the electronic address for submitting Reports is confidential, is operating strictly within the Company and the appropriate technical and organizational measures are observed, in accordance with Article 32 of the General Data Protection Regulation, in order to ensure the anonymity and security of Personal Data from loss, destruction, unauthorized access or any form of unlawful processing. The Company takes appropriate technical and organizational measures, in accordance with the General Data Protection Regulation, and with regard to Reports made via e-mail, such as limiting access only to the YPPA.
9.8 The Personal Data included in the Report and the completion of the investigation with archiving of the incident are deleted within three (3) months from the completion of the investigation. An exception is any legal proceedings (against the Reportee or the Reporting Person), in which case the Personal Data will be retained until the completion of the legal/judicial/disciplinary proceedings initiated by the Company, the Reporting Person or the Reportee.
10. Monitoring – Review of the Policy
10.1 For issues and procedures not regulated in this policy, the provisions of Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 (L 305) and Law 4990/2022 on the protection of persons reporting breaches of EU law apply.
10.2 This Policy may be amended in accordance with the applicable legislation or the needs of the Company.
10.3 Under the responsibility of the YPPA, the Policy is communicated to employees and posted on the Company’s website.
11. Effective Date of the Policy
This procedure is new, does not replace an older one and is valid as of the 8th of July, 2026.