Anti-Bribery & Anti-Corruption Policy
Last updated: [TBD] · This is a working draft pending legal review.
1. Purpose and commitment
Coded B.V. ("Coded", "we", "us", "our") conducts its business honestly and ethically. We have a zero-tolerance approach to bribery and corruption in any form, and we are committed to acting professionally, fairly, and with integrity in all of our business dealings and relationships, wherever we operate.
This Anti-Bribery & Anti-Corruption Policy (the "Policy") sets out our position, the standards we require of everyone who works for or with us, and the consequences of breaching it. Bribery and corruption are criminal offences in the Netherlands and in most countries in which we, our merchants, and our partners operate. They expose individuals and Coded to prosecution, fines, debarment, and serious reputational harm. We will not tolerate them.
Coded operates a commerce platform internationally and is not an EU-only business. Accordingly, this Policy is drafted to meet a high international standard rather than the minimum required by any single jurisdiction.
2. About Coded and the platform context
Coded B.V. is a private limited company (besloten vennootschap) registered in the Netherlands. Coded Holding B.V. is its parent company.
- Registered office: De Taling 15, 2761 SL Zevenhuizen, The Netherlands
- Chamber of Commerce (KVK) number: 42027097
- VAT number: NL869368795B01
Coded provides storefront and hosting infrastructure together with payment facilitation. Each merchant operates their own branded online shop and is the seller and trader of record for sales made through that shop; Coded is a hosting and intermediary service provider, not an online marketplace and not the seller of the merchant's goods. Within our product, a merchant's account is an "Organization", a seller is a "merchant", and the shops and other things a merchant creates are referred to with the umbrella term "projects". Built-in payments are facilitated through third-party payment providers (Stripe and Mollie), and built-in fulfilment is performed by third parties. We charge a 0% platform fee on a merchant's payment transactions.
This context matters for corruption risk. Our highest-exposure relationships are with the third parties in our value chain — payment providers, fulfilment and logistics partners, suppliers of the curated catalog, resellers and affiliates, professional advisers, and any public officials or regulators we interact with across multiple jurisdictions.
3. Scope
This Policy applies to all persons and entities working for or on behalf of Coded in any capacity, including:
- directors, officers, and employees of Coded B.V. and Coded Holding B.V., at all levels;
- contractors, contracted development personnel, temporary and agency staff, interns, and secondees;
- agents, intermediaries, introducers, consultants, and other representatives;
- affiliates and entities within the Coded group;
- suppliers, fulfilment and logistics partners, resellers, and other business partners acting on our behalf or in connection with our business.
In this Policy, the people in the first three bullet points are referred to as "personnel". Third parties acting on our behalf are expected to comply with the principles of this Policy, and the relevant standards will be reflected in our contracts and onboarding with them.
This Policy is not exhaustive guidance on every situation. Where you are unsure whether something is permitted, you must seek guidance before acting (see Section 13).
4. Legal framework
We comply with the anti-bribery and anti-corruption laws of the jurisdictions in which we operate. This Policy is grounded in, and is intended to meet, the following key standards. Where these standards differ, we apply the strictest.
- Netherlands — Wetboek van Strafrecht. Dutch criminal law prohibits both active and passive bribery of public officials and in the private (commercial) sector. This includes the bribery of public officials (including foreign and international officials) and commercial bribery offences directed at the corruption of employees and agents acting in breach of their duties (including the offences addressed in articles 177 and 328ter of the Dutch Criminal Code). Dutch law is the governing law of this Policy.
- United Kingdom — Bribery Act 2010. One of the strictest anti-corruption regimes in the world, with extraterritorial reach. It creates offences of offering, promising, or giving a bribe; requesting, agreeing to receive, or accepting a bribe; bribery of foreign public officials; and — critically — the section 7 corporate offence of "failure to prevent bribery", under which a commercial organisation can be liable for a bribe paid by an associated person anywhere in the world, subject only to the defence of having adequate procedures in place. The UK Act recognises no de-minimis threshold and provides no exemption for facilitation payments. We treat these principles as our global baseline.
- OECD Convention on Combating Bribery of Foreign Public Officials in International Business Transactions. The international standard, implemented by the Netherlands and many of our markets, targeting the bribery of foreign public officials to obtain or retain business.
- United States — Foreign Corrupt Practices Act (FCPA). We maintain awareness of the FCPA's anti-bribery and books-and-records / internal-controls provisions, which can have extraterritorial reach. Because some of our partners (for example payment providers) and counterparties have US nexus, we conduct ourselves so as to avoid conduct that could engage the FCPA.
We also expect compliance with the local anti-corruption laws of any country where we, or those acting for us, do business. Nothing in this Policy overrides a mandatory provision of applicable local law that is stricter than this Policy.
5. What is bribery and corruption
Corruption is the abuse of entrusted power or position for private gain.
A bribe is a financial or other advantage offered, promised, given, requested, agreed to be received, or accepted to induce or reward the improper performance of a function or activity, or to influence a decision improperly. A bribe does not have to be cash and does not have to actually change hands — an offer or a promise is enough. The advantage can be indirect (for example, given to a family member, a charity, or a third party at the recipient's request).
Examples of what this Policy prohibits include:
- Bribery of public officials — giving or offering anything of value to a government official, regulator, state-owned-enterprise employee, political party, or candidate to obtain or retain business or any improper advantage. This includes foreign officials.
- Commercial (private-sector) bribery — giving or offering an advantage to an employee, agent, partner, or counterparty so that they act improperly or in breach of their duty (for example, to steer a contract, leak confidential information, or overlook a problem).
- Receiving bribes — requesting, agreeing to receive, or accepting any advantage as an inducement or reward for performing your role improperly.
- Kickbacks — returning a portion of a payment, fee, or other benefit, or arranging a side payment, in exchange for awarding or retaining business.
- Bribery through third parties — using an agent, intermediary, consultant, partner, reseller, or other person to give or receive a bribe on our behalf or for our benefit. You are responsible for the conduct of those you engage.
6. Facilitation payments and kickbacks
Facilitation payments are small, typically unofficial payments made to secure or speed up a routine government action to which the payer is already entitled (for example, processing a permit or clearing goods). Although tolerated in some places and under some regimes, facilitation payments are illegal in the Netherlands, illegal under the UK Bribery Act (which has no facilitation-payment exemption), and inconsistent with our values.
Coded prohibits facilitation payments and kickbacks of any kind, in any amount, anywhere. There is no monetary threshold below which they are acceptable. The only exception is a payment made under genuine duress where there is an imminent threat to a person's life, liberty, or safety — in which case the affected person's safety comes first, and the payment must be reported to Legal as soon as it is safe to do so and accurately recorded.
7. Gifts and hospitality
This Policy does not prohibit normal and appropriate gifts and hospitality (given or received) that build legitimate business relationships, provided they meet all of the following conditions. A gift or hospitality is acceptable only if it is:
- not made with the intention of influencing a third party to obtain or retain business or a business advantage, or to reward improper conduct, and not given in the expectation that anything will be provided in return;
- not made, requested, or accepted in secret;
- given openly, in our name, and not to or from a person's private address;
- reasonable, proportionate, and infrequent in the circumstances, and of a type and value that is appropriate, customary, and lawful in the relevant market;
- compliant with applicable local law and with the recipient organisation's own rules;
- not cash or a cash equivalent (such as a gift card, voucher, loan, or security).
7.1 Public officials
Particular caution applies to public officials. Many governments forbid their officials from accepting any gift or hospitality. Personnel must not offer or give gifts or hospitality to public officials without prior written approval from Legal, however modest.
7.2 Thresholds, approval, and recording
Coded will maintain monetary thresholds above which a gift or item of hospitality (whether offered, given, requested, or received) requires prior written approval, and a register in which such gifts and hospitality are recorded. When in doubt about whether something is appropriate, do not proceed — seek approval first.
<!-- OPEN ITEM: set concrete approval thresholds (e.g. per-item and aggregate annual values per counterparty) and confirm the gifts & hospitality register owner before publication. -->8. Conflicts of interest
A conflict of interest arises where personnel have a personal, financial, family, or other interest that could improperly influence — or could reasonably be perceived to influence — their judgement or actions on behalf of Coded. Conflicts of interest are closely linked to corruption risk.
Personnel must:
- avoid situations that create, or appear to create, a conflict between their personal interests and the interests of Coded;
- promptly and fully disclose to their manager or to Legal any actual, potential, or perceived conflict — for example, a personal or family relationship with a supplier, partner, candidate, or counterparty; an outside financial interest in a counterparty; or an outside role that could compete or interfere;
- not participate in decisions (such as awarding contracts, selecting suppliers, or hiring) where they have an undisclosed conflict;
- follow any mitigation or recusal measures Coded puts in place once a conflict is disclosed.
Disclosing a conflict is not, in itself, a breach of this Policy. Concealing one is.
9. Third-party and partner due diligence
Third parties acting on our behalf are a primary source of bribery risk, and a corrupt act by an associated person can expose Coded to liability — including under the UK Bribery Act section 7 corporate offence. We therefore apply risk-based due diligence to relevant third parties, including agents, intermediaries, introducers, consultants, resellers, affiliates, suppliers, and fulfilment and logistics partners.
Our intended due-diligence measures include:
- Risk screening before engagement — assessing the third party by role, country and sector corruption-risk indicators, level of interaction with public officials, and ownership/control (including screening for sanctions and, where relevant, politically exposed persons, coordinated with our Sanctions Policy and AML Policy).
- Integrity verification — proportionate checks on the third party's identity, beneficial ownership, reputation, and references before onboarding higher-risk relationships.
- Contractual safeguards — requiring relevant third parties to commit, by contract or by acceptance of our standards, to comply with anti-bribery laws and the principles of this Policy, to keep accurate records, to permit reasonable audit, and to allow termination for breach.
- No improper payment structures — refusing arrangements that lack a genuine commercial rationale, involve disproportionate fees or commissions, request payment to third parties or unusual jurisdictions, or otherwise bear the hallmarks of a channel for a bribe.
- Ongoing monitoring — periodic review of higher-risk relationships and re-screening where circumstances change.
As a first-pass position, we are transparent that several of these measures are being established and matured rather than fully operational. We will not represent them as more developed than they are.
10. Books, records, and internal controls
Hidden funds and inaccurate records are how bribery is concealed. Accurate accounting is therefore a control, not just an obligation.
- All accounts, invoices, expense claims, and other records and documents relating to dealings with third parties — including payments, gifts, hospitality, fees, and commissions — must be prepared and maintained accurately, completely, and in reasonable detail. They must fairly reflect the transactions to which they relate.
- No account, fund, or asset may be established or maintained off the books for any purpose.
- No false, misleading, incomplete, or artificial entry may be made, and no payment may be made or approved with the understanding that any part of it is for a purpose other than that described in the supporting documents.
- Personnel must claim expenses relating to gifts, hospitality, or payments to third parties strictly in accordance with our expenses procedures and must record the reason for the expenditure.
These requirements reflect the books-and-records and internal-controls expectations of the FCPA and good governance generally.
11. Training and awareness
Coded will provide anti-bribery and anti-corruption awareness appropriate to each person's role and risk exposure, with enhanced training for personnel in higher-risk functions such as partner and supplier management, procurement, payments, and any role that interacts with public officials. New personnel will be made aware of this Policy as part of onboarding, and we will promote awareness of how to raise concerns. Maintaining adequate, proportionate procedures — including training — is a deliberate part of our defence against the failure-to-prevent risk described in Section 4.
12. Reporting concerns and whistleblowing
It is everyone's responsibility to prevent, detect, and report bribery and corruption. You must report as soon as possible if you are offered a bribe, are asked to make one, suspect that bribery or corruption has occurred or may occur, or believe a breach of this Policy has happened or may happen.
- Internal route: raise the concern with your manager or directly with Legal at legal@coded.eu.
- Confidential / external concerns: concerns may also be raised confidentially — and where available anonymously — by contacting report@coded.co or legal@coded.eu. We protect anyone who reports a concern in good faith against retaliation.
- Abuse or illegal conduct via the platform can be reported at report@coded.co.
Coded will not tolerate any retaliation, dismissal, disciplinary action, threat, or other unfavourable treatment against anyone who, in good faith, raises a concern, reports suspected bribery or corruption, refuses to take part in it, or declines to pay a bribe — even if it results in Coded losing business. Anyone who engages in retaliation will be subject to disciplinary action. A report made in good faith will not be penalised even if it turns out to be mistaken.
13. Guidance — if you are unsure
You must avoid any activity that might lead to, or suggest, a breach of this Policy. As a guide, be cautious if you ever feel that an offer, request, or payment is excessive, secret, lacks a genuine commercial reason, is routed unusually, is conditioned on a decision in our or the other party's favour, or would embarrass Coded if it became public. If you are unsure whether something is acceptable, do not proceed — seek guidance from Legal at legal@coded.eu first.
14. Consequences of breach
Compliance with this Policy is a condition of working for and with Coded.
- For personnel: any breach of this Policy will be treated as a serious matter and may result in disciplinary action up to and including termination of employment or engagement, and, where contracts permit, recovery of losses. Conduct may also be reported to the relevant authorities.
- For third parties, suppliers, and partners: breach may result in suspension or termination of the relationship and of any related agreements, and may be reported to the relevant authorities.
- Criminal and personal liability: bribery and corruption are crimes. Individuals who pay or accept bribes can face imprisonment and unlimited fines under the laws referenced in Section 4; organisations can face substantial fines, confiscation, debarment from public contracts, and reputational damage. These consequences apply regardless of any disciplinary action Coded takes.
15. Responsibility, monitoring, and review
The board of Coded B.V. has overall responsibility for ensuring this Policy complies with our legal and ethical obligations and that those under our control comply with it. Day-to-day implementation and the handling of queries and reports are delegated to Legal. Management at all levels is responsible for ensuring that those reporting to them understand and comply with this Policy.
We will monitor the effectiveness of this Policy and our anti-bribery controls and will review them regularly, and at least annually, updating this Policy in response to changes in our business, our risk profile, or the law. This Policy does not form part of any employment contract and may be amended at any time.
16. Governing law and jurisdiction
This Policy, and any dispute or claim arising out of or in connection with it, is governed by the laws of the Netherlands, and the courts of Amsterdam shall have jurisdiction. This choice does not override any mandatory provision of the law of a person's or entity's own jurisdiction that applies regardless of this choice, and nothing in this Policy limits obligations arising under applicable local anti-corruption law — including, where they apply, the UK Bribery Act 2010, the US FCPA, and the laws implementing the OECD Anti-Bribery Convention.
Contact
Questions about this Policy, requests for guidance or approval, and reports of suspected bribery or corruption can be directed to:
- Legal / policy and approvals: legal@coded.eu
- Abuse / illegal-content & reports: report@coded.co
- Postal: Coded B.V., De Taling 15, 2761 SL Zevenhuizen, The Netherlands
Confidential and, where available, anonymous concerns may also be raised via report@coded.co or legal@coded.eu. We do not tolerate retaliation against anyone who raises a concern in good faith.
<!-- OPEN ITEMS FOR COUNSEL: - Confirm precise citations and current wording for Dutch Wetboek van Strafrecht arts. 177 (active bribery of public officials), 178, 363/364 (passive), and 328ter (private/commercial bribery), and whether to cite the specific articles in the published text or describe them generically. - Verify the UK Bribery Act 2010 framing — ss.1, 2, 6, and the s.7 corporate "failure to prevent" offence with the "adequate procedures" defence — and confirm whether Coded has a UK nexus that engages s.7; align procedures to the MoJ "adequate procedures" six principles if so. - Confirm FCPA applicability/nexus (US issuer, domestic concern, or territorial conduct via partners such as Stripe) and whether the books-and-records / internal-controls framing should be strengthened. - Set concrete gifts & hospitality monetary thresholds (per-item, aggregate, public-official rules) and name the register owner; decide approval workflow. - Decide whether to publish a separate standalone Whistleblowing Policy / Speak-Up channel and finalise the cross-link; confirm EU Whistleblower Directive / Dutch Wet bescherming klokkenluiders applicability and the protected-channel mechanics. - Confirm whether a separate internal Code of Conduct and Supplier Code of Conduct exist or are in progress; align references and avoid overstatement. - Confirm board governance: which board (Coded B.V. and/or Coded Holding B.V.) owns the Policy and the named policy owner/signatory. - Confirm whether this Policy is internal-facing only, partner/supplier-facing, or both, and adjust tone/distribution accordingly. - Fill placeholders: 42027097, NL869368795B01, De Taling 15, 2761 SL Zevenhuizen, The Netherlands, 11 June 2026. -->