Privacy policy

Processing of personal data

This Privacy Policy contains information governing the processing of personal data of users (hereinafter referred to as the “User”) who access and use the following websites owned by Milor S.p.A. or its subsidiaries, specifically:

Purposes of data processing

Data provided by the User upon registration on the Site or for the Site’s newsletter, as well as when submitting any order, will be used for purposes strictly related to the objective specified at the time of data collection and/or for the purposes outlined in this Privacy Policy. More specifically, this includes sending the newsletter and/or fulfilling the order request and all associated services, such as payment and delivery. Furthermore, the User's personal data may be used by the Data Controller and by third parties authorized by the Controller to comply with any accounting and tax obligations related to the purchase of Products and to complete all activities strictly linked and preparatory to managing the relationship between the Site and the Customer.

Processing methods

All collected User data will be processed exclusively and with due care by individuals specifically assigned to this task and appropriately trained in the matter. The purposes of the processing are those for which the data were collected, primarily using electronic and computer-based tools.

Nature of data acquisition

The personal data requested by the Data Controller while browsing the Site may be mandatory or optional. Failure by the User to provide mandatory data will result in the inability to fulfill the purpose for which the data was requested. Conversely, providing optional data is entirely at the User's discretion; the User may choose whether or not to provide it. In such cases, a refusal entails no consequences regarding the fulfillment of the purposes indicated at the time of the request. The User is also responsible for keeping such data up to date, thereby enabling the Data Controller to provide services effectively and efficiently without delays, errors, or additional costs resulting from a failure to update the data. In particular, the Data Controller collects data that you voluntarily provide via a collection form on the Site, including socio-professional information (such as your profile, surname, first name(s), gender, date of birth, referrer and/or delivery address, and profession).

Communication of data

The disclosure of the User's personal data to third parties is subject to compliance with statutory limits and the purposes declared and outlined in point 1. The third parties involved fall into the following categories: 1. entities responsible for warehousing, packaging, shipping, delivery, and product returns; 2. entities appointed by the Data Controller to handle the administrative, contractual, accounting, and legal management of the Site's activities; 3. credit institutions, insurance companies, and companies responsible for managing payments (including electronic payments); 4. entities responsible for managing and maintaining the Site and all its functions; 5. any other parties granted access to the data by the Data Controller, in compliance with applicable laws or regulations; 6. companies affiliated or related to our Company, as well as offices associated with our Company. Finally, the User's personal data may be used for contests and/or prize draws, and for sending advertising and promotional material regarding the Site and the Data Controller's partners, solely subject to the User's explicit and voluntary consent.

Consent to processing

In cases where data processing requires the User's explicit and voluntary consent, such consent will be obtained specifically, with a clear explanation of the individual purposes being pursued. It should be noted that Article 6 of the GDPR provides for instances where data processing does not require the User's express authorization—such as, for example, for the fulfillment of legal or contractual obligations undertaken towards the User.

Rights of the data subject

The User has the right to request confirmation of the existence of personal data concerning them at any time, pursuant to Articles 12 et seq. of the GDPR. In accordance with the Personal Data Regulation, you specifically benefit from the following rights: a. access (Article 15 of the GDPR), b. rectification (Article 16 of the GDPR), c. erasure (Article 17 of the GDPR), d. restriction of processing (Article 18 of the GDPR), e. portability (Article 20 of the GDPR), f. objection (Articles 21 and 22 of the GDPR), g. post-mortem directives (Law No. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties);

Access rights

You have the right to obtain confirmation from the Data Controller as to whether or not personal data concerning you are being processed and, where that is the case, access to such data and the following information: 1. the purposes of the processing; 2. the categories of data; 3. the recipients or categories of recipients to whom the data have been or will be disclosed; 4. where possible, the envisaged retention period for the data or, where not possible, the criteria used to determine such period; 5. the existence of the right to request from the Data Controller the rectification or erasure of data, or a restriction on the processing of your data, or the right to object to such processing; 6. where the data are not collected from you, any available information regarding their source; 7. where data are transferred to a third country or an international organization, the right to be informed of the appropriate safeguards relating to such transfer.

Rights of rectification

You have the right to obtain from the Data Controller, as soon as possible, the rectification of inaccurate data concerning you. You also have the right to request that incomplete data be completed, including by means of a supplementary statement.

Right to erasure

You have the right to obtain from the Data Controller the erasure of data concerning you as soon as possible if one of the following grounds applies: a. the data are no longer necessary in relation to the purposes for which they were collected or otherwise processed by the Data Controller; b. you have withdrawn your consent to the processing of such data and there is no other legal basis for the processing; c. you exercise your right to object under the conditions set out below; d. there are no overriding legitimate grounds for the processing; e. the data have been processed unlawfully; f. the data must be erased to comply with a legal obligation; g. the data were provided by a child.

Right to restriction

You have the right to obtain from the Data Controller a restriction on the processing of your data based on any of the following grounds: a. the Data Controller is verifying the accuracy of the data following your contestation of their accuracy; b. the processing is unlawful and you oppose the erasure of the data, requesting instead a restriction on their use; c. the Data Controller no longer needs the data for the purposes of processing, but they are still required for the establishment, exercise, and/or defense of legal claims; d. you have objected to the processing under the conditions set out below, and the Data Controller is verifying whether the legitimate grounds pursued override the grounds you have put forward.

Right to data portability

You have the right to receive the data concerning you from the Data Controller in a structured, commonly used, and machine-readable format when: 1. the data processing is based on consent or a contract, and 2. the processing is carried out by automated means. When exercising your right to data portability, you have the right to have the data transmitted directly by the Data Controller to a data processor designated by you, where technically feasible.

Right to object

You have the right to object at any time, on grounds relating to your particular situation, to the processing of data concerning you based on the Data Controller’s legitimate interest; in such a case, the data will no longer be processed unless the Controller demonstrates compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or retains the data for the establishment, exercise, or defense of legal claims. When data is processed for direct marketing purposes, you may object to such processing at any time. Finally, the User has the right to object, in whole or in part on legitimate grounds, to the processing of personal data concerning them—even if relevant to the purpose of collection—as well as to the processing of personal data concerning them for the purpose of sending advertising material or direct sales, or for carrying out market research or commercial communication.

To exercise these rights, the User may contact the following: Tony S.r.l. - Via Carducci 32, 2012 Milan - email: privacy@milor.it

Data Controller

The Data Controller for the personal data of Users visiting the Site is Milor S.p.A. – Via dei Gracchi 35, 20146 Milan. To exercise their rights or for further information regarding data processing, Users may contact the Data Controller at the following address: Milor S.p.A. – Via dei Gracchi 35, 20146 Milan – email: privacy@milor.it.

Data retention period

Your Personal Data is actively retained for a period of three (3) years following your last activity on the Site or via electronic communication (such as an email); once this period has elapsed, your profile is deemed “inactive” and will be automatically deactivated. You will therefore need to create a new profile for any future Orders. Personal Data associated with an Order is retained for a period of three (3) years from the date of the Order. This data remains accessible to both you and us—particularly following the creation of your account—to ensure a complete history of your Orders is available to both parties. We may delete this data at any time upon your request. However, upon the expiration of the aforementioned periods—or, where applicable, following your request for deletion—your Personal Data may be subject to intermediate archiving in order to comply with our legal, accounting, and tax obligations.

Social networks

The Site is present on social networks. For further information regarding the protection of your data while browsing these social networks, please consult their respective privacy policies.

Protection of minors

Unless otherwise specifically stated, the Site’s services are intended for a general audience. We recognize a special obligation to protect personal information obtained from young children. Therefore, for children under the age of 16 to register for any service, we require the child to provide the email address or other contact information of a parent or guardian; the Data Controller will then contact that person to provide information and to allow them to confirm, modify, or refuse their child's registration. The Data Controller reserves the right to request written proof of parental or guardian authorization at any time. Until the parent or guardian responds to the Data Controller’s email in accordance with the provided instructions, the child's use of the services may be restricted.

Cookie policy

Cookie

A “cookie” is a connection marker—specifically a text file—that may be stored, subject to your choices, in a dedicated area of ​​your device’s hard drive when you visit the Site. A cookie allows the entity issuing it to identify the device on which it is stored for the duration of the cookie’s validity or storage period; consequently, it must be treated as Personal Data. When you connect to our Site, we may—depending on your choices—install various cookies on your device that enable us to recognize your device’s browser for the duration of the relevant cookie’s validity. No personal user data is collected by the Site in this regard. Cookies are not used to transmit personal information, nor are so-called persistent cookies of any kind—or user tracking systems—employed. The use of so-called session cookies (which are not permanently stored on the user’s computer and disappear when the browser is closed) is strictly limited to the transmission of session identifiers (consisting of random numbers generated by the server) necessary to enable secure and efficient site navigation. The session cookies used on this site avoid the need for other IT techniques that could potentially compromise user browsing privacy and do not allow for the collection of personal data that could identify the user.

Third-party cookies

The site uses third-party cookies (both temporary and permanent) solely for anonymous purposes, enabling the data controller to utilize web analytics services provided by third parties. These cookies collect and record information about the pages visited on the site anonymously; they do not identify the visitor and are not combined with any other information. Such data is used exclusively to track and examine user activity on the site and to compile statistics based on anonymously collected and aggregated data. Specifically, users are informed that the web analytics service used by the data controller—which issues cookies—is "Google Analytics," described below. Google Analytics is a web analytics service provided by Google, Inc. ("Google") that uses "cookies"—text files placed on the user's computer—to allow the visited website to analyze how users interact with the site. The information generated by the cookie regarding the user's use of the website (including their IP address) is transmitted to and stored on Google's servers in the United States. Google uses this information to track and examine the user's use of the website, compile reports on website activity for site operators, and provide other services related to website activity and Internet usage. Google may also transfer this information to third parties where required by law or where such third parties process the information on Google's behalf. Google will not associate the user's IP address with any other data held by Google. Users may refuse the use of cookies at any time by selecting the appropriate settings on their browser. By using this Site, the User consents to the processing of their data by Google in the manner and for the purposes set out above. To consult Google's privacy policy regarding the Google Analytics service, please visit the website http://www.google.com/intl/en/analytics/privacyoverview.html.

Code of Ethics

Guiding principles

The Code of Ethics serves as an organization’s "identity card"; it outlines the conduct guidelines that should shape the behavior of its members and acts as the primary vehicle for fostering an ethical culture within the company. The adoption of Codes of Ethics has become increasingly widespread in recent years, driven in part by specific legal provisions—particularly at the international level—that have prompted companies and other organizations to implement them. Due to market globalization, there is a growing global need to integrate and explicitly articulate ethical and social principles within economic models. These principles must allow profit and value-creation objectives to coexist with respect for the needs and interests of all stakeholders involved in business activities—whether in domestic and international dealings or within the corporate environment itself. This need arises because the expectations and interests of various stakeholders (shareholders, employees, suppliers, customers, business partners, etc.)—while legitimate—may conflict, and because there is often a risk that actual conduct may fail to align with proclaimed principles. In Italy, the importance of adopting a Code of Ethics is further underscored by the legal framework establishing specific corporate liability for crimes committed, as set forth in Legislative Decree no. 231 of June 8, 2001. 231. Against this backdrop, the companies comprising the Milor Group (the “Group”) have consistently committed to applying rigorous principles in the conduct of their various activities. They have always been characterized by the seriousness, reliability, and professionalism of their management, employees, and collaborators, thereby establishing a solid reputation that is recognized internationally. In pursuit of continuous improvement, Milor has deemed it appropriate to adopt and issue this Code of Ethics. This Code articulates the corporate principles and values ​​the Group has long upheld and outlines rules of conduct—compliance with which is essential for all those acting in the name of or on behalf of Group companies—to maintain and enhance the smooth operation and reliability of business processes, as well as the Group’s overall image. All individuals subject to this Code of Ethics must align their operations and conduct with these principles and standards, both in internal professional dealings and in relationships with parties external to the Group.

The Group's mission

The Group recognizes the importance of ethical and social responsibility in the conduct of its business and corporate activities and is committed to respecting the legitimate interests of shareholders, directors, employees, collaborators, customers, suppliers, and business partners.

Addressees and scope of application of the Code

The core values ​​and rules of conduct set out in the Code of Ethics are binding on all Group companies, their Directors, Employees, and third parties acting in the Group’s interest in any capacity; the latter category includes agents, technical support providers, suppliers, distributors, developers, consultants, and collaborators in general (hereinafter referred to as "Collaborators"). In particular, Directors are required to be guided by these values ​​and rules of conduct when setting corporate objectives for Group companies, proposing investments, and implementing projects, as well as in any decision or action regarding the management of the businesses. Employees holding executive positions, when carrying out management activities for Group companies, must be guided by these same values ​​and rules of conduct—both within the Group (thereby strengthening cohesion and a spirit of mutual cooperation) and in their dealings with third parties who come into contact with the Group. All Employees are required to adhere to the principles and rules of conduct contained in the Code of Ethics, as well as to company procedures, regulations, and policies, in the performance of their duties and responsibilities. Furthermore, all Employees are required to ensure that independent third-party Collaborators acting in the Group’s interest in any capacity also comply with the principles and rules set forth in this Code of Ethics. They undertake to inform Collaborators of the content of this Code of Ethics and to instruct them to comply with the rules contained therein. Group Collaborators are required to align their conduct with the provisions of the Code and with company procedures and regulations.

Reference values

Compliance with Laws and Regulations: The Group’s companies recognize compliance with the laws and regulations in force in all countries where they operate as a fundamental principle. Directors, employees, and collaborators involved in the Group’s business activities are therefore required to carry out their duties with the utmost transparency and in strict compliance with the laws and regulations applicable to the location and time of their operations. They commit to acquiring the best possible understanding of the regulations applicable to their activities and the responsibilities arising from any violation thereof. Under no circumstances may the pursuit of the Group’s interests justify conduct that does not comply with laws and regulations. Integrity: Moral integrity is a constant obligation for all those working in the name of and/or on behalf of the Group’s companies. All recipients of this Code of Ethics are required to pursue objectives with honesty, fairness, and responsibility, and to maintain conduct characterized by respect for rules, laws, and professional ethics. Transparency and Completeness of Information: The Group’s companies promote transparency in communications, formal agreements, and the criteria underlying their conduct, in order to enable the parties involved to make autonomous and informed decisions.

Rules of conduct

Milor’s Code of Ethics applies to all companies within the Group, as well as their directors, employees, and collaborators—regardless of specific organizational, production, or commercial structures—and sets forth rules of conduct that all such parties are required to observe. Directors, executives, employees, and collaborators maintaining contractual relationships of any kind with the Group are required to observe and ensure compliance with these principles within the scope of their respective duties and responsibilities, and to cooperate in establishing appropriate procedures to safeguard the Group’s interests.

Human Resource Management

In compliance with the principles set out above, the Group recognizes its human resources as an essential asset for competing successfully in the marketplace and achieving its corporate objectives, as well as the importance of establishing relationships based on loyalty and mutual trust.

The Group companies shall ensure that the selection, hiring, classification, and career development of employees, as well as the engagement of employees and collaborators in any capacity, are based exclusively on objective assessments of the professional and personal qualifications required for the performance of the relevant duties, as well as on demonstrated competence in carrying out those duties.

The Group companies shall reject any discriminatory conduct relating to access to employment, job classification, assignment of duties, career progression, or the allocation of responsibilities.

Recruitment and Management of Human Resources

In light of the above, the Company's recruitment, remuneration, and training policies for employees and collaborators shall be based on professionalism, integrity, competence, and merit.

In particular, the relevant functions shall ensure that:

  • recruited personnel correspond to the profiles genuinely required by the Company's operational needs, avoiding any form of favoritism or preferential treatment, while ensuring equal opportunities and prohibiting discrimination based on candidates' private lives or personal opinions;
  • employees and collaborators are treated fairly and consistently, preventing favoritism, abuse, and discrimination based on gender, race, religion, political affiliation, trade union membership, language, age, disability, or any other protected characteristic;
  • fairness of treatment and equal opportunities are guaranteed in the assignment of roles and responsibilities, considering internal mobility across different positions as a means of fostering professional development.

Professional Development and Training

The Group companies are committed to supporting the training and professional development of their employees and collaborators by periodically offering opportunities for mutual exchange of knowledge and work experience, as well as other training initiatives, with the aim of promoting continuous learning and enabling individuals to develop their professional skills within the Group.

Accordingly, Managers and Heads of Department are expected to devote the utmost attention to enhancing and developing the professionalism of their colleagues and collaborators by creating the conditions necessary for the growth of their skills and the realization of their full potential.

In particular, the relevant functions shall ensure that:

  • the conditions necessary to develop each individual's skills, abilities, and talents are maintained, in accordance with the Company's equal opportunity policies;
  • systems for evaluating conduct, competencies, knowledge, and potential are maintained on the basis of transparency and merit;
  • individuals are given the opportunity to express their individuality at work, recognizing diversity and each person's unique qualities as an essential contribution to the Group's growth;
  • conditions are maintained that enable everyone to perform their role effectively, promote the continuous improvement of professional competencies, and foster teamwork in support of the Company's objectives;
  • training programmes are designed, assessed, and developed with due consideration for individual learning needs.

Working Environment

All employees and collaborators shall be treated in strict compliance with the principles set forth in this Code of Ethics and within a working environment that promotes open communication and cooperation among colleagues, managers, and subordinates, with the shared objective of strengthening the Group and fostering a sense of belonging.

In particular, the Company's governing bodies, managers, employees, and collaborators acting in any capacity on behalf of the Group companies shall:

  • conduct their interpersonal and professional relationships with fairness, integrity, loyalty, and mutual respect;
  • promote and uphold respect for the dignity and individuality of every colleague and collaborator as a fundamental element in creating a workplace founded on mutual trust and the contribution of each individual;
  • strive to create a working environment that guarantees all persons interacting with the Group companies, in any capacity, conditions that respect personal dignity and in which individual characteristics cannot give rise to discrimination or undue influence;
  • endeavour to create a working environment that is stimulating and rewarding, thereby encouraging the development of each individual's potential.

Financial, administrative, and accounting management

Ensuring the utmost accounting transparency for every company within the Group is a priority for the Group itself, at all times and under all circumstances. The sourcing and disbursement of financial resources, as well as their administration and control, must always comply with the Group’s approval and authorization procedures. Directors, employees, collaborators, and all parties maintaining a relationship with the Group in any capacity must conduct themselves with strict propriety, transparency, and a spirit of cooperation—in compliance with legal regulations and corporate procedures—during all activities related to the preparation of financial statements and other corporate disclosures. In particular, the following obligations apply: – everyone is required to strictly observe established procedures and to cooperate fully to ensure that business transactions are accurately and promptly reflected in the company’s accounts; – within their respective areas of competence and function, everyone must adhere to the strictest principles of transparency, propriety, and truthfulness when preparing accounting documents and data, as well as any records related to administration; – in the case of financial or asset-related items based on valuations, the corresponding accounting entry must be made by clearly explaining, in the relevant documentation, the criteria used to determine the asset's value; – documentation supporting every accounting transaction must be adequate, truthful, clear, and complete; ...must be kept on record in a manner that allows for the verification—at any time—of the transaction’s characteristics and rationale, as well as the precise identification of the individuals who authorized, executed, recorded, and verified the transaction at its various stages; responsibilities must be clearly defined and understood within the organization; – the corresponding accounting entry must clearly, completely, and accurately reflect the details contained in the supporting documentation; – the supporting documentation must be readily retrievable and filed according to appropriate criteria that facilitate easy consultation by both internal bodies and external entities authorized to conduct audits.

Receiving stolen goods and money laundering

Integrity of financial flows: Any transaction that could entail even the slightest risk of involving the Company in the receipt of stolen goods, money laundering, or the use of assets or funds of illicit origin is strictly prohibited. Financial flows must be managed in a way that ensures complete transaction traceability and the retention of appropriate documentation, always within the scope of each individual's assigned responsibilities. To this end, the following principles regarding documentation and record-keeping must be observed: – all payments and other transfers made by or to the Company must be accurately and fully recorded in the corporate accounting systems; – all payments must be made only to parties and for activities that have been contractually formalized and/or authorized by the Company. The Company implements necessary controls to verify the authenticity of cash received and used in the course of business operations. Recipients are required to exercise the utmost diligence and care when handling cash to ensure that no counterfeit money is accepted or spent. The Company is committed to ensuring that the gold used to manufacture its jewelry products does not originate from geographic regions involved in armed conflicts driven by economic interests regarding the control of precious metal extraction. Furthermore, it confirms its commitment to the responsible sourcing of gold. To this end, we are committed to ensuring compliance with the Dodd-Frank Act and to purchasing gold exclusively from banks, bullion dealers, or refineries that are included on the LBMA Good Delivery List or certified by the Responsible Jewellery Council (RJC).

Privacy protection

In compliance with applicable laws, the Group’s companies are committed to protecting the privacy of information regarding the private lives and opinions of their employees and all those who interact with the Group. Employees and collaborators acting in the name of or on behalf of the Group’s companies are required to process personal data in strict compliance with applicable privacy laws and in accordance with the directives issued to them. In particular, they are obliged to: – acquire and process only the data necessary for and directly related to their duties; – respect the confidential and private nature of the information; – acquire and process data for specific, explicit, and legitimate purposes; – acquire and process data that is pertinent, accurate, complete, and not excessive in relation to the purposes for which it was collected and subsequently processed, ensuring it is kept up to date; – store such data in a manner that prevents unauthorized third parties from accessing it; – communicate and disclose data only within the framework of established procedures or with the prior authorization of the designated managers; – retain data in a form that allows for the identification of the data subject for a period no longer than necessary for the purposes for which it was collected and subsequently processed. Management, employees, and collaborators responsible for processing personal data must adopt all appropriate measures to prevent risks such as the destruction or loss (including accidental loss) of said data, unauthorized access, or processing that is not permitted or does not align with the purposes of collection; these measures are identified and periodically updated within the Group’s companies.

Safety protection

In accordance with the aforementioned values, the Group recognizes human resources as an essential asset. The Group’s companies aim to maintain the highest standards of health and safety and to ensure necessary preventive measures against workplace accidents and illnesses. Everyone must contribute to maintaining a healthy and safe working environment and ensuring the safety of their colleagues and collaborators. Each corporate function must make every effort to remain fully informed—within its area of ​​responsibility—of the rights and obligations incumbent upon the Group arising from laws, contracts, or dealings with public authorities, and must not engage in any conduct that could in any way harm the Group’s interests. All employees and collaborators working on behalf of or in the name of the Group’s companies are strictly prohibited from disclosing non-public information to third parties regarding projects, acquisitions, mergers, commercial strategies, or—more generally—any information concerning the Group’s companies that has come to their knowledge, or the disclosure of which could in any way prejudice the Group’s interests. Each individual is responsible for safeguarding, preserving, and protecting the Group’s assets and resources entrusted to them in the course of their work, and is obliged to use them properly and appropriately, preventing any misuse.

Protection of corporate assets

To safeguard the integrity of the company's assets, it is strictly prohibited—except in cases permitted by law—to: return capital contributions in any form or release shareholders from the obligation to make them; distribute profits that have not actually been realized or that are required by law to be allocated to reserves (or to reserves that are legally non-distributable), or to purchase or subscribe to shares or equity interests; carry out reductions of share capital, mergers, or demergers in violation of regulations designed to protect creditors; fictitiously subscribe to or increase share capital; or satisfy shareholders' claims to the detriment of company creditors in the event of liquidation.

Relations with public administration

This context encompasses all relationships—related to the activities of the Group’s companies—maintained with public officials or persons charged with a public service who act on behalf of public administration bodies, national or foreign legislative bodies, Community institutions, or public organizations of any foreign state.

Supplier and customer relations

Directors, employees, and collaborators of the Group companies shall ensure equal opportunities in the selection of suppliers, taking into account their suitability and compatibility with the Group's size and operational requirements.

In particular, the relevant functions responsible for selecting independent third parties, including consultants, agents, and suppliers of goods, products, and services, shall ensure that:

  • suppliers are selected on the basis of objective criteria and assessments (such as quality, value for money, price, capability, efficiency, and similar factors) aimed at protecting the Group's commercial and industrial interests and, in any event, creating added value for the Group;
  • suppliers are selected according to standards of reliability and integrity, taking into account the need to ensure compliance with the Group's core values, the principles of conduct set out in this Code of Ethics, and the Group's internal procedures. Such relationships shall be formalized in writing and in accordance with the Group's organizational and reporting structure;
  • suppliers are informed of the Group's policies and that contracts include specific clauses requiring compliance with this Code of Ethics.

The relevant functions shall also ensure that suppliers are continuously engaged and encouraged to adopt a proactive and responsible approach, particularly with regard to transparency, communication, compliance with applicable laws and regulations, and awareness of the social and ethical risks and opportunities arising from their activities.

Relationships with Customers

In their dealings with customers, whether public or private, directors, employees, and collaborators of the Group companies shall:

  • establish and maintain long-term relationships based on efficiency, cooperation, and courtesy;
  • operate in compliance with applicable laws and regulations and require their strict observance;
  • ensure that any statements, declarations, and certifications provided to customers are accurate and truthful;
  • honour all commitments and obligations undertaken towards customers;
  • provide accurate, complete, truthful, and timely information to enable customers to make informed decisions.

In business relationships with suppliers and customers, the Group's corporate policies shall be observed, and all dealings shall be conducted with the utmost fairness and integrity, particularly in the negotiation and execution of contracts, while avoiding any actual or potential conflict of interest.

Without prejudice to the provisions set out in the section "Relations with the Public Administration," directors, employees, and collaborators are prohibited, in their business relationships with suppliers and customers, from offering or accepting gifts, gratuities, hospitality, or other courtesies, whether directly or indirectly, unless these are of such modest nature that they cannot compromise the Group's reputation or reasonably be interpreted as intended to obtain preferential treatment beyond that permitted by legitimate market practices.

In any event, any gifts, courtesies, or hospitality that fall outside ordinary business practices shall be appropriately documented and reported to the relevant manager, who shall assess their appropriateness.

Any employee or collaborator who receives gifts or preferential treatment from suppliers or customers exceeding normal standards of business courtesy shall immediately inform his or her line manager. Following the necessary assessments by the competent management, the relevant Group company, through the appropriate functions, shall inform the donor of the Group's policy governing gifts, hospitality, and similar benefits.

Compliance with competition regulations

The Group’s companies are committed to ensuring maximum market competitiveness; consequently, their commercial policy must be guided by compliance with regulations governing competition, both domestically and internationally. All recipients of this Code of Ethics must keep themselves constantly updated on applicable regulations and consult their line manager before entering into any agreement or understanding that could potentially result in unlawful competition.

Prevention of conflicts of interest

Senior management, employees, and collaborators acting in the name and on behalf of the Group’s companies are required to act in a manner that avoids situations conflicting with the Group's own interests. By way of example and without limitation, the following constitute conflicts of interest: exploiting one’s functional position to pursue interests that conflict with those of company colleagues; using information acquired during the performance of work duties for personal gain or for the benefit of third parties, or in any way contrary to the Group's interests; the employee’s participation—whether open or concealed—in the activities of suppliers, clients, or competitors; and engaging in work activities of any kind for clients, suppliers, competitors, and/or third parties that conflict with the Group's interests. In particular, regarding employees, the acceptance of any professional engagement offered by third parties must be discussed in advance with their direct supervisor and the Human Resources Director of Milor S.p.A. to ensure there are no incompatibilities or situations that could prove detrimental. Everyone has a duty to promptly report to the relevant management any situation that might be considered—even potentially—detrimental to the Group's rights and interests, so that management may take the necessary protective measures with equal promptness.

Relations with supervisory bodies

Relations with bodies responsible for statutory oversight or audit functions, as well as relations with audit firms, must be characterized by the utmost propriety, transparency, and cooperation, in full compliance with applicable laws and regulations. In particular, auditors—whether internal or external—must have free access to the data, documents, and information necessary to perform their duties. It is strictly prohibited to impede or obstruct the oversight or audit activities legally assigned to shareholders, other corporate bodies, or the audit firm. These same obligations apply to relations with the Supervisory Body; within the scope of the responsibilities set out in the respective Organization and Management Models voluntarily adopted by Group companies pursuant to Legislative Decree no. 231 of June 8, 2001 ("Regulations on the administrative liability of legal entities, companies, and associations, including those without legal personality, pursuant to Art. 11 of Law no. 300 of September 29, 2000"), this body is tasked with monitoring compliance with existing preventive and control systems and assessing their actual adequacy, particularly in areas where potential crime risks associated with the activities performed have been identified (Ref. Code of Ethics and Organizational Models pursuant to Legislative Decree 231/2001).

Code of Ethics and Organizational Models (pursuant to Legislative Decree 231/2001)

Within the framework of the Group companies' internal control systems, this Code of Ethics forms an integral part of the Organization and Management Models voluntarily adopted by said companies. While respecting their full autonomy and respective commercial and/or operational characteristics, Group companies that adopt Organization and Management Models in compliance with the principles set forth in Legislative Decree no. 231/2001 (and subsequent amendments and/or supplements) are required to conduct risk assessments to identify areas where offenses could be committed and to establish prevention and control systems in accordance with the provisions of the decree itself.

Supervisory Body

The Group’s companies appoint a Supervisory Body (OdV) endowed with autonomous powers of initiative and oversight, tasked with: – monitoring the functioning of and compliance with the Code of Ethics and corporate procedures, particularly in areas where crime risks under Legislative Decree 231/2001 associated with the activities performed have been identified—for this purpose, the Body is free to access all sources of corporate information, review documents, and consult data; – receiving and/or reporting any violations of the Code of Ethics; – proposing updates to the Code of Ethics and internal protocols to ensure alignment with the law; – verifying, monitoring, and evaluating instances of non-compliance with the standards set forth in the Code of Ethics and reporting such matters to the relevant functions for the application of appropriate sanctions, in accordance with laws, regulations, and National Collective Labour Agreements (CCNL).

Reports to the Supervisory Body

Group companies are required to establish appropriate communication channels enabling anyone who becomes aware of conduct within the Group contrary to the principles and rules of conduct set out in this Code to report such matters freely, directly, and confidentially to their line manager and to the Supervisory Body (where appointed). Information obtained by the Supervisory Body and the relevant departments for the purpose of conducting necessary investigations must be handled in a manner that guarantees: – the confidentiality and anonymity of the whistleblower; – protection of the whistleblower against any form of retaliation, penalization, or discrimination, subject to legal obligations and the protection of the rights of Group companies or of individuals accused erroneously and/or in bad faith.

Violation of the Code and remedial system

Adherence to the principles and rules of the Code of Ethics is considered an essential part of the contractual obligations of Employees. Violations of the Code of Ethics may constitute a breach of the primary obligations of the employment relationship or a disciplinary offense—entailing all legal consequences, including those regarding the continuation of employment—and may give rise to liability for damages resulting from such violations. Adherence to the Code of Ethics is considered an essential part of the contractual obligations undertaken by non-subordinate collaborators and/or parties maintaining business relationships with the Group. Violations of the Code of Ethics may constitute a breach of contractual obligations—entailing all legal consequences, including the termination of the contract and/or engagement—and may give rise to liability for damages resulting from such violations. Violations by members of the Board of Directors and the Board of Statutory Auditors are subject to all applicable legal provisions, including the resulting remedies and sanctions. The Group companies undertake to provide for and impose—consistently, impartially, and uniformly—sanctions that are proportionate to the specific violations of the Code and compliant with applicable regulations governing employment relationships.

Dissemination of the Code of Ethics

The Group’s companies are committed to disseminating the Code of Ethics among its recipients and to promoting and giving significant prominence—within their internal communications—to matters concerning professional ethics, conduct, and the prevention of irregularities. All recipients of this Code of Ethics are therefore required to be familiar with its content and to observe—and ensure compliance with—the principles and rules of conduct set forth therein.