Legal & Compliance
Code of Conduct & Sanctions Compliance
Note: This translation is for informational purposes only. The German version shall be solely legally binding. Deutsch →
As a German company with a Europe-wide customer base, Baduno GmbH commits to legally compliant and ethical business conduct. This Code of Conduct applies equally to management, employees, and our freelance auditor network.
This page provides general information about our practices and the legal situation. It does not constitute legal advice; only the contract documents and the German version of these pages are binding.
Legal Compliance & Integrity
We adhere to applicable law – without exception and without exploiting gray areas. We reject corruption, bribery, and improper granting of advantages; invitations and gifts remain within socially acceptable limits. Conflicts of interest are disclosed by those involved before decisions are made.
Sanctions & Export Control
We comply with the sanctions regimes of the European Union and the Federal Republic of Germany. We do not maintain business relationships with sanctioned persons or entities, review our contractual partners when there is reasonable cause, and do not provide any services that would violate sanctions or export control regulations. Our target market is the member states of the EU.
Anti-Money Laundering & Payment Integrity
We process payments exclusively through regulated payment service providers and business accounts; we do not accept cash payments. Unusual payment requests – third parties as payers, conspicuous denominations, overpayments with a request for a refund – we reject and clarify them before the start of services.
Fairness Towards Employees & Network
Fair, contractually clear fees for auditors, punctual payment, confidentiality protection in both directions, and respect regardless of origin, language or religion are basic conditions of our collaboration. We do not tolerate discrimination or harassment.
Report violations
Anyone who observes a violation of this code can report it via the channels described on the whistleblower page – confidentially if desired. Reports made in good faith never lead to disadvantages for the reporting person.
Common misunderstandings
A common misconception is that sanctions screening only takes place for new customers or at the start of a contract. In fact, we also carry out checks during an ongoing business relationship when a specific reason arises – for example, unusual payment patterns or new information. Another misconception is that small gifts or invitations are generally acceptable. Our code of conduct only permits these within a socially appropriate framework – for instance, a moderate business lunch. Regular gifts or expensive tokens that could be perceived as influence are not allowed. There is also a belief that the strict prohibition of cash payments is relaxed for private customers or very small amounts. This is not the case: we generally do not accept cash payments, regardless of the amount or reason. Finally, some think that EU sanctions lists are only relevant for countries outside the EU. However, these lists also include sanctioned individuals within the EU, and we screen all contractual partners without geographical restriction. These clarifications help to avoid false expectations and to better understand our compliance practices.
What this means for customers in practice
For our customers, the principles described have a number of specific consequences. When you work with us, you should expect that before we commence services, we will collect your name and, if necessary, other identification data (such as date of birth or registration entry). We compare this data against sanctions lists – a purely technical process that is usually completed within a few minutes. You will not be separately informed unless your name results in a hit.
Furthermore, we only accept payments from your own business account. If a third party wishes to pay on your behalf, we ask you to arrange the payment yourself or to coordinate with us in advance – however, in practice we usually decline such requests. Overpayments followed by requests for a refund are also not processed. If, in the context of a project, you provide us with information about your own customers or partners (for example, for a localized compliance document), we will treat it confidentially and use it only for the agreed purpose.
These measures serve solely to ensure legal compliance and protect all parties involved. We strive to keep the processes as straightforward as possible without compromising due diligence. If you have any questions about the specific requirements in your case, your contact person will be happy to assist you.
Step-by-step practical example
To make our compliance practice more tangible, a typical process illustrates how we proceed with a new business relationship. Suppose a potential customer from France wants to use our localization services. Step 1: Before concluding the contract, we collect basic identification data – usually the company name, legal form, VAT ID, and the name of the legal representative. Step 2: We compare this data with the common sanctions lists (EU, UN, BaFin). This process is automated and usually takes only a few minutes. If there is no match, we proceed with Step 3: We check whether the desired service – for example, a website localization from German to French – falls under export control regulations. Since it is a service without technology transfer, this is not the case here. Step 4: We ask the customer to make the payment from their own business account. When the payment is received, the service is provided. If the customer were to have a third party pay or offer a cash payment, this would immediately lead to a more in-depth review. Also, if the customer's name matched a sanctions list, we would have to reject the business relationship. This example shows how systematic and efficient our checks are.
Internal process at our company
Compliance with the Code of Conduct at Baduno GmbH is not only monitored by management but integrated into daily work processes. Every new employee and every new freelance reviewer receives a short version of the code at the start of the collaboration and confirms receipt in writing. When accepting an order, the project manager is obliged to verify the customer's identity before starting the service and to perform a sanctions list check. This is documented in our CRM system. For unusual payment requests – for example, if a third party wants to pay or there is an overpayment – an escalation process is in place: the responsible clerk forwards the case to the compliance officers, who review and decide on the matter. Approval is only granted if the payment request clearly does not indicate money laundering or sanctions evasion. In addition, we conduct an annual internal compliance training covering current sanctions regimes, typical risks, and reporting channels. Our reviewer network is informed of relevant changes via a circular. In the event of a specific trigger – such as a new EU sanctions regulation – ad-hoc notification occurs. These internal processes ensure that all parties apply the same standards at all times.
Terms explained in plain language
Our Code of Conduct contains several legal terms that are not always self-explanatory for customers and partners. Below we explain the most important ones.
Socially acceptable framework: This term describes benefits or invitations that are considered customary and appropriate in business and do not create the impression of improper influence. Example: a business lunch following a customer meeting where costs remain moderate (approx. 30 euros per person) is socially acceptable. However, regular dinners at luxurious restaurants or covering travel expenses would no longer be socially acceptable.
Sanctions lists: These are publicly accessible directories listing individuals, organizations, or countries against which the EU or Germany has imposed economic sanctions. The best-known include the EU Council's consolidated list and the sanctions list of the Federal Financial Supervisory Authority (BaFin). A hit on such a list generally means that no business relationship may be entered into or continued.
Export controls: This refers to national and EU-wide regulations restricting the export of certain goods, software, or technologies. For our services in the area of website localization, this plays virtually no role, as they are pure language services that are not subject to export controls. Nevertheless, we check this on a case-by-case basis to ensure that we do not provide any prohibited services.
Practical example step by step
Imagine a new customer from France commissions us to localize their website. For you as a customer, the process is as follows: First, we collect your name and company details – such as the SIRET number or commercial register. We compare this information against the current EU sanctions lists, which is automated and takes place within a few minutes. A hit is extremely rare; if one occurs, we will contact you for clarification. In parallel, we check whether your country or industry is subject to special export controls – for companies within the EU, this is usually unproblematic.
In the next step, we agree on payment terms: You will receive an invoice to your business account, which you transfer from that same account. We reject cash payments or payments by third parties, even for small amounts. Should one of our freelance auditors accidentally request an unusual payment, our internal control kicks in: Our Compliance team would stop the process and clarify it with all parties involved. The entire process is designed so that you, as a legitimate customer, do not notice anything – it runs in the background without delay.
Internal process at Baduno
When an internal compliance review is pending at our company, it goes through several stages. First, the responsible employee identifies a specific trigger—such as a new customer order, an unusual payment request, or a change in the business relationship. The relevant data is then automatically checked against the sanctions lists of the EU and the Federal Office for Economic Affairs and Export Control. This comparison is performed using certified software and is documented. In the event of a hit, the case is immediately escalated to management; in practice, a false positive is possible, which we then clarify through personal identification.
In parallel, we check whether the requested service itself falls under export control regulations—for example, software with encryption components. For pure website localization projects, this is rarely the case, but we still check it for all orders. After approval by the compliance department, the order is processed normally. All checks are recorded in an audit-proof log. The goal is to identify legal risks early without unnecessarily burdening ongoing operations.
Terms explained in plain language
To better understand our compliance principles, we explain key terms: By "sanctions lists" we mean the official lists of the European Union that name individuals, companies, and organizations subject to economic or financial measures. A hit on these lists does not automatically indicate a criminal offense, but rather that we are legally obliged not to conduct business. "Export control" refers to checks on whether a product or service may be delivered to certain countries or recipients. For our localization services, this is usually only relevant for encryption technology or when customers are based in third countries.
"Anti-money laundering prevention" includes measures such as identity verification of business partners, monitoring unusual payment flows, and the obligation to report suspicious transactions. We ourselves are not directly required to file these reports, as we are not a financial institution, but we reject suspicious transactions. "Socially adequate framework" is a legal term meaning that minor courtesies such as a coffee or a simple business meal are permissible if they do not create an appearance of corruption. In cases of uncertainty, we always opt for the restrictive approach.
Interaction with our other policies
This Code of Conduct is not an isolated document but part of a comprehensive compliance framework at Baduno GmbH. It establishes the fundamental ethical and legal principles and is supplemented by more specific guidelines. For example, the Code works closely with our Data Protection Policy, which governs the handling of personal data. When conducting a sanctions check, we request your name and, if applicable, your date of birth – a process carried out in accordance with the principles of data minimization and purpose limitation. Our IT Security Policy ensures that this data is protected during transmission and storage. The Policy on Gifts and Invitations specifies what is considered socially acceptable under the Code. The Whistleblower Policy, described on the separate whistleblower page, also complements the Code by detailing the reporting channel for violations. In summary: The Code sets out the values, while the other policies translate these into concrete instructions for daily work. This creates a consistent system that promotes legal compliance, integrity, and transparency equally. For you as a customer, this means that your data and payments are handled according to uniform, high standards.
Further Common Misunderstandings
In addition to the misunderstandings already explained, we encounter other assumptions in practice that we would like to clarify here. A common misconception is that sanctions checks are only carried out above a certain revenue or transaction volume. In fact, we check all business partners without any financial thresholds – even the placement of a small translation order triggers a check. Another misunderstanding concerns the reporting of violations: some believe that a report is only useful if you already have concrete evidence. However, our whistleblower system is specifically designed for suspicion – we also welcome reports of unconfirmed observations, which we then investigate internally. Finally, it is often assumed that the rules on gifts and invitations only apply to direct contact with customers. In fact, they apply to all external third parties, including potential new customers, service providers, and auditors. Even an invitation to a business meal with a prospect who is not yet a customer must be socially acceptable. These clarifications are intended to ensure that our compliance practices are correctly understood.
What Happens in the Event of a Sanctions Hit?
A sanction hit occurs when the name of a business partner or a person involved in the transaction matches an entry on a valid sanctions list. Internally, this triggers a standardized process, which we describe transparently here. First, the hit is manually validated by our compliance team, as it may be a case of name similarity without further matches. We check date of birth, address, and other available identification details. If the hit is confirmed, the business relationship is immediately halted: we carry out no further orders and accept no further payments. The process is documented and, if legally required, reported to the competent authority. If it is a false alarm, the review is concluded as negative and the business process continues immediately. You will only be informed of the result if it affects the cooperation, i.e., in the case of a confirmed hit or if we require additional information. This process ensures that we fulfill our legal obligations without unnecessarily burdening business relationships.
Status of this information: July 2026 – we update upon changes in the legal situation or our procedures.