Deskpro Vendor Code of Conduct
Last Updated: 4 March 2026
This Vendor Code of Conduct (“Code”) applies only where incorporated by reference into a written agreement between Deskpro and a supplier, vendor, subcontractor, consultant, contractor, agency worker, or other third party (“Vendor”).
1. Introduction
Deskpro is committed to conducting business lawfully, ethically, and professionally. Vendors play an essential role in supporting Deskpro’s services, customers, and operations. This Code sets out the minimum standards of integrity, conduct, and legal compliance expected of Vendors and Vendor Personnel when providing services to Deskpro.
2. Scope and Applicability
This Code applies to:
- Vendors that provide products or services to Deskpro; and
- the Vendor’s owners, officers, directors, employees, consultants, affiliates, contractors, and subcontractors involved in providing such services
Vendor must ensure that Vendor Personnel are aware of and comply with this Code.
3. Compliance with Laws and Regulations
Vendor must comply with all applicable local, national, and international laws and regulations in connection with services provided to Deskpro.
Vendor must provide the cooperation, information, and assistance required for Deskpro to meet its legal, regulatory, and contractual obligations relating to the services performed by Vendor, including responding to regulatory inquiries, examinations, or supervisory requirements.
Where Vendor provides services that support Deskpro’s obligations to regulated customers (including financial institutions, healthcare providers, and public sector organisations), Vendor must also comply with legal, regulatory, and industry requirements that are inherent to the services being performed, to the extent those requirements would apply if Deskpro or its regulated customers were performing the services directly.
Vendor must ensure Vendor Personnel are trained on the legal and regulatory obligations relevant to the services they perform, prior to being granted access to Deskpro information or systems and at least annually thereafter.
If compliance with this Code would result in a violation of applicable law, Vendor must comply with the law and promptly notify Deskpro.
Vendor must cooperate with Deskpro in responding to lawful requests, regulatory inquiries, or supervisory requirements relating to services performed by Vendor.
4. Ethical Business Conduct
Vendor must conduct all business activities relating to Deskpro with integrity, transparency, and fairness. Vendor must establish, maintain, and enforce internal controls and procedures to prevent, detect, investigate, and remediate unethical, unlawful, or improper conduct in connection with services provided to Deskpro.
4.1 Anti-Bribery and Anti-Corruption
Vendor must not, directly or indirectly:
- offer, promise, give, solicit, or accept any payment, gift, hospitality, favour, or other advantage;
- make political or charitable contributions on behalf of Deskpro; or
- provide anything of value to any public official, customer, or third party,
where such action is intended to improperly influence a business decision or secure an improper advantage.
Vendor must:
- comply with all applicable anti-bribery and anti-corruption laws;
- maintain procedures to prevent bribery and corruption within its organisation; and
- promptly report any suspected bribery, corruption, or improper influence relating to Deskpro.
4.2 Gifts and Hospitality
Vendor must ensure that any gifts, hospitality, entertainment, travel, or business courtesies involving Deskpro personnel:
- are modest and customary for the relevant business context;
- are directly related to a legitimate business purpose;
- are transparent and accurately recorded in Vendor’s books and records; and
- are not offered, provided, or accepted in a manner that could be perceived as influencing a business decision.
Vendor must not offer:
- cash or cash equivalents;
- excessive, extravagant, or frequent hospitality;
- personal discounts not available to the general public; or
- gifts or benefits intended to bypass procurement, compliance, or approval processes.
4.3 Conflicts of Interest
Vendor must actively identify and disclose any actual, potential, or perceived conflict of interest that could impair objective decision-making in relation to Deskpro.
Conflicts may include, but are not limited to:
- personal or family relationships with Deskpro personnel;
- financial interests in Deskpro competitors, partners, or customers;
- outside employment or business activities that affect impartiality; or
- any situation where Vendor’s interests diverge from Deskpro’s interests.
Vendor must disclose such conflicts in writing and cooperate in implementing mitigation measures.
Failure to disclose a material conflict may constitute a breach of the parties’ agreement.
4.4 Fraud, Financial Crime, and Accurate Records
Vendor must not engage in fraud, embezzlement, falsification of records, money laundering, tax evasion facilitation, or any other financial crime in connection with services provided to Deskpro.
Vendor must:
- maintain accurate, complete, and truthful books and records;
- ensure invoices and billing are transparent and reflect actual services performed;
- not manipulate performance metrics, audit evidence, or compliance reporting; and
- retain records in accordance with applicable law and contractual requirements.
Vendor must promptly report any suspected fraudulent activity relating to Deskpro.
5. Confidentiality and Information Protection
Vendor must treat all Deskpro information as strictly confidential and must use it solely for authorised purposes under the parties’ agreement.
For the purposes of this Code, “Deskpro information” means any non-public information disclosed by or on behalf of Deskpro that is identified as confidential or that would reasonably be understood to be confidential given the nature of the information and the circumstances of disclosure, whether disclosed orally, visually, electronically, or in writing.
Deskpro information includes, without limitation:
- personal data, customer data, and system data;
- business plans, product plans, pricing, financial information, forecasts, and commercial strategy;
- information relating to Deskpro’s customers, suppliers, partners, and employees;
- technical information including designs, architectures, specifications, source code, system diagrams, and security controls;
- authentication credentials, access codes, passwords, encryption keys, and security tokens;
- non-public information relating to security incidents, vulnerabilities, incident response activity, or investigations;
- non-public regulatory or supervisory communications, requests, or examination materials;
- customer complaints and communications relating to Deskpro services; and
- all intellectual property rights in the foregoing.
Vendor must ensure that Deskpro information is:
- accessed only by authorised personnel on a strict need-to-know basis;
- protected against unauthorised access, disclosure, alteration, or destruction;
- not disclosed to any third party without Deskpro’s prior written authorisation (unless legally required); and
- not used for Vendor’s own benefit or competitive advantage.
Vendor must comply with Deskpro’s detailed requirements relating to information security and data protection, available at:
- www.deskpro.com/supplier-security-requirements
- www.deskpro.com/supplier-data-protection-requirements
Vendor must not use Deskpro information in any artificial intelligence, machine learning, or large language model tool (including for training, fine-tuning, prompt-based processing, or data enrichment) unless explicitly authorised in writing by Deskpro.
As between Deskpro and Vendor, Deskpro retains all right, title, and interest in and to Deskpro information. Vendor shall not assert, and hereby waives, any lien, security interest, retention right, or other encumbrance over Deskpro information, and shall not withhold Deskpro information as leverage in any dispute.
These obligations survive termination or expiration of the Vendor’s relationship with Deskpro for as long as the information remains confidential.
6. Workplace Standards, Human Rights, and Employment Practices
Vendor must provide a workplace environment that is lawful, safe, respectful, and free from harassment or discrimination.
Vendor must:
- comply with all applicable labour, employment, wage, and working-hour laws;
- prohibit discrimination based on legally protected characteristics;
- prohibit harassment, bullying, intimidation, retaliation, or threats;
- maintain policies and procedures addressing workplace misconduct and grievance reporting;
- prohibit forced labour, involuntary labour, human trafficking, and exploitative practices; and
- ensure workers meet minimum legal age requirements.
Vendor must provide working conditions that meet applicable health and safety standards and must implement measures designed to prevent workplace accidents and harm, including training and incident reporting processes appropriate to the work being performed.
Vendor is encouraged to maintain policies addressing diversity, equal opportunity, and inclusion within its organisation.
7. Reporting Concerns and Non-Retaliation
Vendor must establish mechanisms for employees or subcontractors to raise concerns regarding unethical, unlawful, or non-compliant behaviour.
Vendor must:
- promptly report to Deskpro any suspected violations of this Code that relate to services provided to Deskpro;
- cooperate in investigations relating to such concerns; and
- preserve relevant evidence where misconduct is suspected.
Reports relating to Deskpro may be made to: security@Deskpro.com
Vendor must not retaliate against any individual who raises a concern in good faith.
Retaliation itself may constitute a material breach of the parties’ agreement.
Vendor must promptly notify Deskpro (unless prohibited by law) regarding the receipt of any subpoena, regulatory request, law enforcement request, or media inquiry relating to Deskpro.
8. Subcontractors and Supply Chain Responsibility
Vendor must not engage any subcontractor, agent, affiliate, or third party to support services for Deskpro unless the engagement is permitted under the parties’ agreement and Vendor has completed the requirements in this Section.
Vendor must, before engagement and throughout the term of the subcontract:
- perform documented due diligence covering the subcontractor’s financial stability, information security controls, operational resilience/business continuity capability, and compliance capability relevant to the services being outsourced;
- obtain and review security and privacy assurance evidence appropriate to the risk (for example: ISO/IEC 27001 certificate, SOC 2 Type II report, independent audit report, penetration testing summary, security questionnaire, or equivalent evidence);
- enter into a written agreement with the subcontractor that imposes obligations for the relevant scope that are no less protective than:
- this Code; and
- where the subcontractor will access, process, store, transmit, or support Deskpro systems or Deskpro information, the Deskpro Vendor Security Requirements and Deskpro Vendor Data Protection Requirements; and
- ensure the subcontractor grants Deskpro (and, where applicable, Deskpro customers and their auditors/regulators) audit, information, and access rights that are no less protective than the rights Vendor grants under the Deskpro requirements for the relevant scope.
Vendor remains fully responsible for the acts and omissions of subcontractors and for subcontractor compliance with the above obligations.
Vendor must not assign personnel to Deskpro services where they have relevant disqualifying convictions relating to dishonesty or breach of trust, to the extent legally permissible.
Vendor must take corrective action and, where required by Deskpro, replace subcontractors or personnel if Vendor becomes aware of misconduct, non-compliance, or security/privacy risk in its supply chain relating to Deskpro services.
9. Environmental Responsibility
Vendor must comply with applicable environmental laws and regulations.
Vendor is encouraged to:
- operate in a manner that minimises environmental harm;
- use resources responsibly; and
- implement environmental management practices proportionate to the size and nature of its operations.
Vendor must not knowingly engage in activities that cause unlawful environmental damage in connection with services provided to Deskpro.
10. Insurance
Vendor must maintain, at its own expense and for the duration of the services, insurance coverage appropriate to the nature of the services provided to Deskpro and the risks associated with those services.
At a minimum, Vendor must maintain (where applicable to the services and Vendor’s operations):
- workers’ compensation or equivalent employer cover (where required by law);
- employer’s liability (where required by law);
- commercial general liability (or equivalent public liability cover); and
- professional liability / errors and omissions (where Vendor provides professional services, development, implementation, or support).
Where Vendor processes, stores, transmits, supports, or otherwise has access to Deskpro information, or provides technology services (including SaaS, hosting, software development, or managed services), Vendor must also maintain cyber / privacy and network security liability insurance (or equivalent coverage) that includes, as applicable:
- security incident/breach response costs (including investigation and notification);
- privacy liability and regulatory defence costs; and
- business interruption and restoration costs arising from a security incident, where such risks are relevant to the services.
Vendor must ensure that insurance limits, terms, and coverage are sufficient to cover liabilities that could arise from the services provided to Deskpro, taking into account the nature of the data accessed and the potential impact of a security incident.
Upon request, Vendor must provide Deskpro with certificates of insurance or other documentary evidence of coverage.
Where Vendor engages subcontractors to support services for Deskpro, Vendor must ensure that those subcontractors maintain insurance coverage appropriate to their scope of services and can provide evidence of coverage upon request.
Deskpro may specify additional insurance types or minimum coverage requirements for particular high-risk or regulated service scopes in a statement of work or written notice.
11. Cooperation with Audits, Investigations, and Regulatory / Customer Requests
Vendor must provide timely, accurate, and complete cooperation and assistance to Deskpro in connection with audits, assessments, investigations, examinations, and requests relating to the services provided to Deskpro, including:
- security, privacy, compliance, financial, operational, and technical audits;
- disaster recovery testing, vulnerability testing, and control validation activities;
- regulatory inquiries, examinations, supervisory requests, or enforcement investigations relating to Deskpro or Deskpro customers; and
- customer due diligence, assurance, or audit requests relating to outsourced or subcontracted services.
Such cooperation must include, where relevant to the services:
- providing documentation, policies, procedures, and written attestations;
- completing security, privacy, or compliance questionnaires;
- providing independent assurance reports (for example: ISO/IEC 27001 certificates, SOC 2 Type II reports, penetration testing summaries, or equivalent evidence);
- providing evidence of remediation for identified deficiencies;
- supporting incident investigations, including timelines, scope, root cause analysis, and corrective actions; and
- preserving relevant records, logs, and evidence where an investigation is ongoing.
Upon notice, Deskpro, Deskpro’s customers, and their authorised auditors or regulators may conduct technical, financial, operational, or security audits and testing of Vendor and its subcontractors relating to the services (including any service location used to provide the services), provided that such activity does not require access to unrelated customer environments or expose other customers’ confidential information.
Non-regulatory audits will not occur more than once per calendar year per service scope unless:
- a prior audit identified material findings;
- Vendor is in, or is alleged to be in, material breach of its obligations relating to the services; or
- an emergency situation or security event requires additional review.
Vendor must ensure subcontractors grant Deskpro, Deskpro customers, and relevant regulators audit, access, and information rights no less protective than those granted under this Section for the relevant scope.
If an audit identifies material deficiencies, Vendor must implement a remediation plan agreed with Deskpro and provide status updates until remediation is complete.
Vendor’s obligations under this Section survive termination of the Vendor’s relationship with Deskpro to the extent necessary to support audits, investigations, regulatory inquiries, and incident response relating to services performed during the term.
12. Updates to This Code
Deskpro may update this Code from time to time by publishing an updated version at this URL.
13. Enforcement
Failure to comply with this Code may constitute a material breach of the parties’ agreement and may result in remediation requirements, suspension of access, or termination.