CORTRIUM
CODE OF CONDUCT
Ethical, responsible and compliant conduct for Cortrium and its business partners
1. Purpose and principles
Cortrium is a Danish medical device and healthcare service company that develops reusable Holter monitoring solutions, associated software and professional ECG analysis services.
Through innovative digital healthcare solutions, Cortrium supports healthcare professionals in diagnosing and managing cardiac conditions while maintaining the highest standards of patient safety, quality and regulatory compliance.
This Business Code of Conduct describes the ethical, social, environmental, quality and compliance principles that guide Cortrium and establishes expectations for persons and organizations acting for on behalf of, or in the value chain of Cortrium.
The Code supports Cortrium’s Quality Management System, Sustainability Policy, Carbon Reduction Plan and commitment to lawful, ethical and responsible business conduct. It does not replace applicable laws, contracts, quality agreements, employment terms, professional duties or controlled procedures. Where another requirement is stricter, the stricter requirement applies.
Core principle
Patient safety, product quality, intended use, clinical performance, usability, cybersecurity and regulatory compliance are primary requirements. No commercial, operational or sustainability objective may override these obligations.
2. Scope and application
This Code contains two connected parts:
- Part A applies to Cortrium employees, Executive Management, temporary workers, consultants, contractors and other people acting for or on behalf of Cortrium.
- Part B establishes additional expectations for suppliers, contract manufacturers, service providers, logistics partners, distributors, agents and other business partners.
Business partners are expected to communicate relevant requirements to their employees, subcontractors and upstream suppliers where appropriate. Requirements are applied proportionately, taking account of role, size, location, risk, criticality and potential impact on patient safety, product quality, human rights, the environment, information security and regulatory compliance.
PART A — EXPECTATIONS FOR CORTRIUM PERSONNEL
3. Core expectations
- Act honestly, responsibly and in compliance with applicable laws, regulations and Cortrium procedures.
- Protect patients, users, customers, colleagues, business partners and Cortrium’s reputation.
- Make decisions using objective evidence, appropriate risk management and the long-term interests of patients and Cortrium.
- Treat people fairly, respectfully and without discrimination, harassment or retaliation.
- Raise concerns promptly and cooperate with investigations, corrective actions and continual improvement.
4. Patient safety, quality and regulatory compliance
Everyone must follow applicable quality procedures, maintain complete and accurate records, complete required training, report quality or safety concerns, and support timely investigation of complaints, incidents, nonconformities and regulatory issues.
Environmental improvements and cost, schedule or commercial considerations must not compromise patient safety, intended use, device performance, usability, cybersecurity, product quality, risk acceptability or regulatory compliance.
5. Integrity and ethical business conduct
5.1 Anti-bribery and corruption
Cortrium does not tolerate bribery, corruption, facilitation payments, kickbacks or any improper advantage. Gifts, hospitality, sponsorships, donations and interactions with healthcare professionals, public officials and public institutions must comply with applicable law and Cortrium’s Anti-Bribery and Anti-Corruption Policy.
5.2 Conflicts of interest
Personal, financial or other interests that could influence, or appear to influence, business decisions must be disclosed promptly. Cortrium positions, confidential information and company property must not be used for improper personal benefit.
5.3 Fair competition and accurate communication
Cortrium competes fairly and does not engage in misleading, deceptive, collusive or anti-competitive conduct. Product, clinical, regulatory, environmental and sustainability statements must be accurate, evidence-based and approved through applicable processes.
6. Confidentiality, privacy and information security
Confidential, personal, clinical, technical and commercial information must be protected against unauthorized access, use, disclosure, alteration or loss. Information may be accessed and shared only for legitimate business purposes and in accordance with data-protection, confidentiality, cybersecurity and information-security requirements.
Suspected data breaches, cybersecurity incidents or loss of information assets must be reported immediately through the applicable process.
7. Respectful workplace and human rights
- Respect internationally recognized human rights and prohibit forced labour, modern slavery, human trafficking and child labour.
- Provide equal opportunity and prohibit discrimination, harassment, bullying, threats and retaliation.
- Support a safe and healthy working environment and comply with workplace health and safety requirements.
- Respect freedom of association and lawful employee representation.
- Maintain fair employment practices and provide role-appropriate training and development.
8. Environmental responsibility
Cortrium personnel are expected to support the Sustainability Policy, Carbon Reduction Plan and applicable environmental procedures. This includes responsible use of resources, waste segregation, shipment consolidation, digital-first working, responsible travel and consideration of environmental impacts in purchasing, product and operational decisions.
Sustainability decisions shall be evidence-based and proportionate. Environmental improvements must not compromise patient safety, intended use, device performance, usability, cybersecurity, product quality or regulatory compliance.
9. Responsible use of company assets and records
Cortrium assets, systems, funds, equipment, data and intellectual property must be used responsibly, securely and primarily for legitimate business purposes. Records must be complete, accurate, traceable and retained in accordance with applicable procedures.
PART B — ADDITIONAL EXPECTATIONS FOR BUSINESS PARTNERS
10. Legal and regulatory compliance
Business partners shall comply with applicable laws, regulations, permits, licences, contractual obligations and recognized industry requirements in the countries where they operate and where goods or services are supplied.
Partners supporting regulated medical-device activities shall comply with applicable quality, traceability, change-control, record-retention, validation, contamination-control and regulatory requirements communicated by Cortrium.
11. Patient safety, product quality and business continuity
- Maintain appropriate quality-management controls and provide conforming goods and services.
- Notify Cortrium promptly of actual or potential quality, safety, cybersecurity, supply, compliance or continuity issues.
- Obtain required approval before making changes that may affect product quality, safety, performance, materials, manufacturing location, suppliers or regulatory compliance.
- Maintain business-continuity, disaster-recovery and incident-response arrangements proportionate to the supplied goods or services.
- Cooperate with audits, investigations, corrective actions, complaints and regulatory activities where relevant.
12. Business ethics and fair dealing
- Do not offer, promise, authorize, request or accept bribes, kickbacks, facilitation payments or improper advantages.
- Disclose actual or potential conflicts of interest that could affect the relationship with Cortrium.
- Compete fairly and comply with applicable competition, sanctions, export-control, customs and trade laws.
- Maintain complete and accurate business, quality and financial records.
13. Human rights, labour standards and health and safety
- Prohibit forced labour, bonded labour, prison labour, human trafficking, modern slavery and child labour.
- Provide fair wages, benefits and working hours in accordance with applicable law.
- Respect freedom of association and lawful collective representation.
- Prevent discrimination, harassment, abuse, intimidation and retaliation.
- Provide accessible grievance mechanisms and protect persons who raise concerns in good faith.
- Provide a safe and healthy workplace, assess occupational risks and maintain appropriate emergency-preparedness and incident-reporting arrangements.
14. Environmental responsibility and climate information
- Comply with applicable environmental laws, permits and reporting obligations.
- Identify and manage material environmental impacts, including energy, greenhouse gas emissions, water, waste, hazardous substances, pollution and biodiversity where relevant.
- Seek continual improvement in resource efficiency, emissions reduction, waste prevention, reuse and recycling.
- Provide environmental, carbon, energy, waste, transport or product-footprint information when reasonably requested and available.
- Maintain environmental policies, objectives or management systems proportionate to the nature and significance of operations.
- Avoid unsupported environmental claims and ensure supplied data are accurate, current and transparent about boundaries, assumptions and limitations.
15. Materials, chemicals and responsible sourcing
- Comply with applicable substance and product requirements, including REACH, RoHS and other requirements communicated by Cortrium.
- Maintain material and substance information sufficient to support regulatory compliance and change control.
- Support responsible sourcing of minerals and provide current conflict-minerals or extended-minerals reporting where applicable.
- Notify Cortrium of substances of very high concern, restricted substances, exemptions or material changes that could affect compliance.
- Support responsible packaging and end-of-life management without compromising product protection, quality or regulatory compliance.
16. Information security, privacy and confidentiality
- Protect Cortrium, customer, patient, employee and business information against unauthorized access, disclosure, alteration, loss or misuse.
- Process personal data only for authorized purposes and in accordance with applicable data-protection law and contractual requirements.
- Maintain appropriate cybersecurity, access-control, incident-response, backup and recovery measures.
- Notify Cortrium promptly of actual or suspected information-security, privacy or cybersecurity incidents affecting Cortrium data, systems, products or services.
17. Subcontractors and supply-chain due diligence
Business partners remain responsible for the activities of subcontractors and upstream suppliers used to fulfil Cortrium requirements. They shall conduct proportionate due diligence and communicate applicable quality, ethical, human-rights, environmental, security and regulatory expectations throughout the relevant supply chain.
18. Evidence, assessment and corrective action
Cortrium may request proportionate evidence of compliance, including policies, certifications, questionnaires, sustainability reports, greenhouse gas information, modern-slavery controls, conflict-minerals reports, REACH/RoHS declarations, audit reports or corrective-action records.
Compliance may be assessed through document review, supplier evaluation, meetings, questionnaires or audits. Where a gap is identified, the business partner is expected to investigate the cause and implement proportionate corrective action within an agreed timeframe. Serious repeated or uncorrected violations may result in escalation, increased oversight, suspension, termination of the business relationship or notification to relevant authorities.
PART C — SPEAKING UP, GOVERNANCE AND REVIEW
19. Reporting concerns and non-retaliation
Anyone who becomes aware of suspected misconduct, unlawful behavior, quality or safety concerns, conflicts of interest, security incidents or violations of this Code is expected to report the concern promptly and in good faith.
19.1 Cortrium employees
Employees may report concerns to a manager, HR, QA/RA or Executive Management, or by email to [email protected] in Danish or English. The designated whistleblower unit consists of the QA and Data Protection Officer roles. Reports submitted through the whistleblower channel are treated confidentially, and Cortrium prohibits retaliation against anyone who raises a genuine concern or participates in an investigation in good faith.
Cortrium’s current whistleblower process does not provide a dedicated anonymous reporting platform. The reporter’s identity or identifying information is restricted to the whistleblower unit except where limited disclosure is necessary to assess or investigate the concern.
19.2 Business partners and external persons
Business partners and other external persons should report concerns to their normal Cortrium contact, QA/RA or Executive Management unless Cortrium communicates a dedicated external reporting route. Where the concern involves the normal Cortrium contact, it should be escalated directly to QA/RA or Executive Management. Reports should contain sufficient factual information to support proportionate assessment while avoiding unnecessary disclosure of personal or confidential information.
20. Responsibilities and consequences
All covered people and organizations are responsible for understanding and following the parts of this Code that apply to them. Managers and business owners are expected to lead by example, create an environment where concerns can be raised and ensure appropriate follow-up.
Violations may result in corrective or disciplinary action, termination of employment or engagement, suspension or termination of a business relationship, notification to authorities, recovery of losses or other appropriate action.
21. Governance, acknowledgement and review
Executive Management owns this document. QA/RA and relevant functions support implementation, training, supplier communication, investigation and periodic review. Cortrium may require acknowledgement of this document through employment processes, contracts, purchase terms, supplier onboarding or separate confirmation.
This document shall be reviewed at least every two years and following significant legal, organizational, regulatory, risk or business changes.
22. Internal supporting policies
To further support the Cotrium Code of conduct, the below policies are a part of the overarching policy portfolio that Cortrium uses to govern the company.
- Quality Policy and Quality Management System documentation
- Anti-Bribery and Anti-Corruption Policy
- Information Security Policy and data-protection procedures
- Modern Slavery
- Sustainability Policy and Sustainability Management Procedure
- Carbon Reduction Plan
- Whistleblower Policy
- Applicable supplier-quality agreements, specifications and purchasing requirements
- Applicable REACH, RoHS and responsible-minerals requirements
- Applicable information-security and data-processing agreements