Supplier Code of Conduct
1. Introduction and Purpose
Odyssey Interactive Limited, trading as “Interact”, referred to in this Code as “Odyssey” (“we”, “us”,”our”) is a United Kingdom-incorporated software company. Odyssey develops and provides an internet-based intranet platform and ancillary services to organisations globally. Odyssey is registered at 5th Floor, 24 Mount Street, Manchester, M2 3NX.
We are committed to operating responsibly and ethically, and we expect the same commitment from every supplier, contractor, subcontractor, and service provider (each a “Supplier”) that forms part of our supply chain or delivers services to Odyssey.
This Supplier Code of Conduct (the “Code”) sets out the minimum standards of conduct and compliance that Odyssey requires of all Suppliers. It covers ethical business practices, labour and human rights, health and safety, environmental responsibility, data protection, information security, and the ongoing governance of the supplier relationship.
This Code applies to all Suppliers providing goods or services to Odyssey, including its affiliates. Where a Supplier engages sub-suppliers or subcontractors in the performance of services for Odyssey, it must ensure that those parties are aware of, and operate in compliance with, the requirements of this Code.
2. Legal and Regulatory Compliance
Suppliers must conduct their business in compliance with all applicable laws and regulations in the jurisdictions in which they operate. Without limiting the generality of the foregoing, this includes but is not limited to:
- All applicable national and international laws governing trade, anti-corruption, competition, and financial crime;
- Applicable sanctions regimes, including those administered by HM Treasury, the Office of Financial Sanctions Implementation (OFSI), and the United Nations Security Council;
- Import and export control laws and regulations; and
- All applicable tax laws and reporting obligations.
Where a Supplier is uncertain whether a particular activity complies with applicable law, it must seek appropriate legal advice before proceeding.
3. Ethical Business Conduct
3.1 Anti-Bribery and Anti-Corruption
Suppliers must maintain a zero-tolerance approach to bribery and corruption in all forms, whether direct or indirect. Suppliers must:
- Not offer, pay, request, or accept any bribe, kickback, facilitation payment, or other improper financial or non-financial advantage in connection with business conducted with or on behalf of Odyssey;
- Comply with the Bribery Act 2010 (UK) and any other applicable anti-bribery and anti-corruption legislation;
- Maintain adequate procedures designed to prevent persons associated with the Supplier from engaging in bribery; and
- Ensure that gifts, hospitality, and entertainment given or received are reasonable, proportionate, transparent, and properly recorded.
3.2 Conflicts of Interest
Suppliers must avoid situations that give rise, or may be perceived to give rise, to a conflict of interest with Odyssey. Suppliers must promptly disclose to Odyssey any actual, potential, or perceived conflict of interest that arises during the course of the supplier relationship and must co-operate with Odyssey in managing any such conflict.
3.3 Fair Competition and Antitrust
Suppliers must comply with all applicable competition and antitrust laws. Suppliers must not engage in price-fixing, market-sharing, bid-rigging, or any other conduct that is anti-competitive or that restricts free and fair competition.
3.4 Financial Crime
Suppliers must not engage in, facilitate, or knowingly benefit from money laundering, tax evasion, fraud, or any other financial crime. Suppliers must have adequate controls in place to prevent their business from being used for financial crime purposes, in compliance with the Proceeds of Crime Act 2002, the Criminal Finances Act 2017 and any other applicable legislation.
3.5 Accurate Records and Reporting
Suppliers must maintain accurate and complete books, records, and accounts in accordance with applicable laws and generally accepted accounting standards. No false, misleading, or incomplete entries shall be made in any financial or business records in connection with services provided to Odyssey.
4. Labour Rights and Human Rights
4.1 Prohibition on Forced and Compulsory Labour
Suppliers must not use, benefit from, or knowingly facilitate forced labour, bonded labour, trafficked labour, prison labour (other than pursuant to a lawful programme of rehabilitation), or any other form of compulsory labour. Suppliers must comply with the Modern Slavery Act 2015 and must take reasonable steps to ensure that forced labour does not exist in their supply chains. Suppliers with an annual turnover exceeding £36 million must publish an annual Modern Slavery Act transparency statement.
In addition, Suppliers must ensure that all employment is freely chosen and that workers are free to leave their employment upon reasonable notice without penalty. Suppliers must not retain, withhold, or confiscate workers’ identity documents (including passports and identity cards), and must not require workers to pay recruitment fees or related costs in connection with their employment (the “employer pays” principle). Where it is discovered that workers have paid such fees, the Supplier must repay them in full.
4.2 Prohibition on Child Labour
Suppliers must not employ or engage children in any capacity that is unlawful or harmful to their health, safety, or development. The minimum age for employment must not be less than the age of completion of compulsory education and, in any event, must not be less than 15 years of age (or 14 years where an applicable International Labour Organisation exception applies). Suppliers must conduct appropriate due diligence to ensure that child labour does not occur in their supply chains.
4.3 Fair Treatment and Non-Discrimination
Suppliers must treat all workers with dignity and respect, and must not engage in or permit harassment, bullying, physical punishment, mental or physical coercion, or verbal abuse. Suppliers must not discriminate on the basis of age, disability, gender reassignment, marriage or civil partnership, pregnancy or maternity, race, religion or belief, sex, sexual orientation, or any other characteristic protected by applicable law. Suppliers must comply with the Equality Act 2010 (UK) and any equivalent applicable legislation in other jurisdictions.
4.4 Freedom of Association
Suppliers must respect the right of workers to freedom of association and collective bargaining in accordance with applicable law. Where law restricts such rights, Suppliers must allow workers to freely elect representatives and must not interfere with, obstruct, or penalise any worker for exercising lawful rights of representation.
4.5 Working Hours, Wages, and Conditions
Suppliers must comply with all applicable laws governing working hours, rest periods, wages, and other terms of employment or engagement. Suppliers must ensure that:
- Workers are paid at least the applicable minimum wage or living wage required by law;
- Workers receive all legally required benefits and entitlements;
- Working hours do not routinely exceed limits prescribed by applicable law;
- Workers are not required to work excessive overtime on a sustained basis; and
- Workers have access to a fair, confidential grievance mechanism through which they can raise concerns about their treatment or working conditions without fear of retaliation.
Suppliers are encouraged, though not required, to provide workers with access to a confidential hotline or independent reporting channel through which concerns can be raised anonymously.
5. Health, Safety, and Wellbeing
Suppliers must provide a safe and healthy working environment for all workers, whether in a physical workplace, when working remotely, or when providing services on Odyssey’s premises. Suppliers must:
- Comply with all applicable health and safety legislation, including but not limited to, the Health and Safety at Work etc. Act 1974 (UK) and equivalent legislation in other jurisdictions;
- Identify, assess, and take appropriate measures to mitigate health and safety risks in the workplace;
- Provide appropriate health and safety information, instruction, and training to workers;
- Maintain adequate health and safety management systems and processes proportionate to the size and nature of the Supplier’s business; and
- Report to Odyssey any accidents, incidents, or near-misses that occur on Odyssey’s premises or in connection with services provided to Odyssey.
Where a Supplier or its personnel are engaged on Odyssey’s premises, the Supplier must comply with Odyssey’s applicable health and safety policies and requirements as communicated from time to time.
6. Environmental Responsibility
Odyssey is committed to reducing its environmental impact and expects its Suppliers to share this commitment. Suppliers must:
- Comply with all applicable environmental laws and regulations, including those governing waste management, emissions, hazardous substances, and energy use;
- Take reasonable and proportionate steps to measure, reduce, and manage their environmental impact, including greenhouse gas emissions, energy consumption, water use, and waste generation;
- Implement appropriate environmental management practices proportionate to the size and nature of their operations;
- Not engage in the illegal trade in wildlife, timber, or other natural resources; and
- Where applicable, support the responsible sourcing of materials and seek to avoid the use of materials derived from conflict minerals as defined under applicable legislation, including but not limited to the EU Conflict Minerals Regulation.
Odyssey encourages Suppliers to set measurable environmental improvement goals and to work collaboratively with Odyssey towards shared environmental and sustainability goals. Suppliers with significant environmental impact may be asked to provide data on their environmental performance as part of ongoing supplier reviews.
7. Data Protection and Privacy
7.1 General Obligations
Where a Supplier processes personal data in connection with the supply of goods or services to Odyssey, the Supplier must comply with all applicable data protection legislation, including but not limited to:
- The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, where processing occurs in connection with activities in the United Kingdom;
- Regulation (EU) 2016/679 (EU GDPR), where processing occurs in connection with activities targeting individuals in the European Economic Area; and
- Any other applicable national data protection or privacy legislation in jurisdictions in which the Supplier operates.
7.2 Data Processing Agreements
Where a Supplier processes personal data on behalf of Odyssey as a data processor (as defined under applicable data protection law), the Supplier must execute a data processing agreement with Odyssey on request prior to commencing any such processing. Such agreement must comply with the requirements of Article 28 UK GDPR and/or Article 28 EU GDPR, as applicable, and must include appropriate technical and organisational security measures, provisions governing sub-processing, and mechanisms for the lawful transfer of personal data outside of the UK or EEA where relevant.
In addition, where requested by Odyssey, the Supplier must complete Odyssey’s GDPR/data protection assessment process to demonstrate that personal data is processed securely and in compliance with applicable data protection law. This assessment may be required prior to commencing processing and annually thereafter, in accordance with Odyssey’s supplier due diligence procedures.
The Supplier must notify Odyssey of its sub-processors and any intended changes to its sub-processors and, where the Supplier’s sub-processors process personal data on Odyssey’s behalf, must maintain and make available to Odyssey a current list of such sub-processors on request.
7.3 International Data Transfers
Where a Supplier transfers personal data originating from the UK or EEA to a third country, the Supplier must ensure that it has authority from Odyssey to do so and that such transfers are subject to an appropriate transfer mechanism recognised under applicable data protection law, including but not limited to UK International Data Transfer Agreements (IDTAs), the UK Addendum to EU Standard Contractual Clauses, or EU Standard Contractual Clauses as applicable.
7.4 Data Breach Notification
The supplier must notify Odyssey at security@interactsoftware.com without undue delay and, in any event, within 24 hours of becoming aware of any actual or suspected personal data breach involving data processed on behalf of Odyssey or relating to Odyssey’s personnel, customers, or users. Such notification must include sufficient information to enable Odyssey to meet its own reporting obligations under applicable data protection law.
8. Information Security
Given the nature of Odyssey’s business as a SaaS provider, information security is of paramount importance to us and to our customers. Suppliers must:
- Implement and maintain technical and organisational measures appropriate to the risk to protect the confidentiality, integrity, and availability of Odyssey’s information assets, systems, and data;
- Comply with Odyssey’s information security policies and requirements as communicated from time to time, where these apply to the Supplier’s activities;
- Not access, use, copy, disclose, or retain any Odyssey information, systems, or data except to the extent strictly necessary for the performance of the services and as authorised by Odyssey;
- Take appropriate steps to ensure that its personnel who have access to Odyssey’s systems or data understand and comply with applicable security requirements;
- Notify Odyssey promptly of any actual or suspected information security incident, cyber attack, or unauthorised access to Odyssey’s systems or data; and
- Where applicable, maintain ISO/IEC 27001 certification or an equivalent recognised information security management standard, or be able to demonstrate equivalent security controls.
Suppliers providing hosted or cloud-based services that integrate with Odyssey’s platform, or that process data on behalf of Odyssey’s customers, may be subject to additional security requirements set out in the applicable service agreement or data processing agreement.
9. Confidentiality and Intellectual Property
9.1 Confidentiality
Suppliers must maintain the confidentiality of all Odyssey information that is confidential or proprietary in nature, including but not limited to business plans, customer data, product roadmaps, commercial terms, technical architecture, and personnel information. Confidential information must only be used for the purpose for which it was disclosed and must not be shared with third parties without Odyssey’s prior written consent.
These obligations apply irrespective of whether the information is marked as confidential and continue after the termination of the supplier relationship.
9.2 Intellectual Property
Suppliers must not infringe the intellectual property rights of Odyssey or any third party in the course of providing services to Odyssey. Where a Supplier creates any intellectual property in connection with services provided to Odyssey, the ownership and licensing of such intellectual property shall be governed by the terms of the applicable service agreement. Suppliers must have appropriate licences in place for all third-party software, tools, and materials used in the performance of services.
10. Supply Chain Due Diligence
Suppliers are responsible for the standards and conduct of their own supply chains. Suppliers must:
- Conduct appropriate due diligence on their own suppliers and subcontractors to identify and manage risks of non-compliance with the standards set out in this Code;
- Flow down requirements equivalent to those set out in this Code to sub-suppliers and subcontractors engaged in the delivery of services to Odyssey and take reasonable steps to monitor compliance;
- Not engage any sub-supplier or subcontractor to perform material elements of services provided to Odyssey without Odyssey’s prior written consent, unless otherwise agreed in the applicable service agreement; and
- Promptly notify Odyssey if they become aware of any significant compliance failure within their supply chain that may affect services provided to Odyssey or that may create reputational, legal, or regulatory risk for Odyssey.
11. Reporting, Monitoring, and Audit
11.1 Reporting Concerns
Suppliers are encouraged to report any suspected or actual violations of this Code promptly to Odyssey. Reports may be made via the Supplier’s primary Odyssey contact, or by writing to legal@interactsoftware.com. Odyssey will treat reports with appropriate confidentiality and will not retaliate against any Supplier or individual who reports a concern in good faith.
11.2 Monitoring and Audit
Odyssey reserves the right to monitor Supplier compliance with this Code and, on reasonable notice, to carry out or commission audits of Supplier facilities, records, and practices relevant to compliance with this Code. Suppliers must co-operate with any such audit and must provide access to relevant documentation and personnel as reasonably requested.
11.3 Remediation
Where Odyssey identifies a potential non-compliance, Odyssey will ordinarily seek to work collaboratively with the Supplier to develop and implement a remediation plan within an agreed timeframe. The Supplier must co-operate with any such process in good faith. Where a Supplier fails to remediate a material non-compliance within a reasonable time, or where a non-compliance is sufficiently serious, Odyssey reserves the right to suspend or terminate the supplier relationship.
12. Consequences of Non-Compliance
Non-compliance with this Code may result in one or more of the following actions at Odyssey’s discretion:
- Issuance of a formal notice requiring the Supplier to remedy the non-compliance within a specified period;
- Suspension of orders, contracts, or payments pending investigation or remediation;
- Removal from Odyssey’s approved supplier list;
- Termination of the relevant contract or engagement in accordance with its terms; and/or
- Referral of the matter to relevant regulatory or law enforcement authorities where required or appropriate.
Odyssey’s exercise of rights under this clause is without prejudice to any other rights or remedies available to Odyssey under the relevant contract or at law.
13. Updates to this Code
Odyssey may update this Code from time to time to reflect changes in law, regulation, or business practice. The current version of this Code will be available on request from Odyssey’s procurement and legal teams. Suppliers are responsible for ensuring that they and their relevant personnel are aware of and comply with the current version of the Code.
Continued engagement with Odyssey following notification of any material update to this Code constitutes acceptance of the updated terms.
14. Contact and Queries
Any questions relating to the interpretation or application of this Code should be directed to legal@interactsoftware.com.
DOCUMENT INFORMATION
- Version: 1.0
- Date: August 2026
- Approved by: Legal & Compliance
- Summary of change: Initial version