Version 4.0 | As of 22 July 2026
1 Preamble
SprintEins GmbH (hereinafter referred to as “SprintEins”) develops and operates software-based solutions used by businesses across a wide range of industries. Our clients entrust us with sensitive data, business-critical processes, and confidential business and trade information. This trust places an obligation on us, and on all those acting in our name or on our behalf, to handle such data and information with due care.
Compliance with applicable laws and regulations, adherence to contractual obligations, and equal commitment to environmental, social and economic responsibility are fundamental principles of SprintEins’ corporate governance.
This Supplier Code of Conduct therefore extends beyond mere compliance with laws and regulations. In addition to mutual trust, adherence to the principles set out below in this Supplier Code of Conduct is essential to any business relationship with SprintEins. SprintEins’ business partners are natural or legal persons who provide goods or services without being employees of SprintEins or affiliated companies of SprintEins.
This Supplier Code of Conduct forms an integral part of all contracts entered into with SprintEins and is legally binding on suppliers.
2 Information Security
Information security is of central importance to SprintEins. We expect all suppliers to implement appropriate and demonstrable measures to protect information.
2.1 General Requirements
Suppliers must operate an Information Security Management System (ISMS) or be able to demonstrate equivalent controls that reflect the current state of the art. The following frameworks are recognised in particular as reference standards:
- ISO/IEC 27001 (preferred certification standard)
- VDA ISA
- TISAX (for suppliers operating in the automotive sector)
- BSI IT-Grundschutz
- the NIS2 Directive and the German NIS2 Implementation Act (NIS2UmsuCG)
2.2 Access and Authorisation Control
- Access to SprintEins systems, data or infrastructure must be restricted to the minimum necessary, in accordance with the principle of least privilege.
- All access must be protected by multi-factor authentication (MFA), where technically feasible.
- Credentials must not be shared or stored in unencrypted form.
- Employees of a supplier who leave the organisation must be removed from all SprintEins systems without undue delay.
2.3 Data Storage and Transmission
- SprintEins data, and data belonging to its clients, may only be stored in agreed systems and in agreed regions or countries.
- As a general rule, data must be transmitted in encrypted form (TLS 1.2 or higher).
- Local storage on personal devices is prohibited unless expressly authorised, at minimum in text form (e.g. by email).
2.4 Secure Software Development
Suppliers developing software on behalf of SprintEins undertake to comply with recognised development standards, in particular:
- the OWASP Top 10 as the minimum benchmark for application security
- regular code reviews and static code analysis
- the use only of up-to-date, patched dependencies as part of proper dependency management
- no hard-coded credentials or secrets in source code or repositories
2.5 Security Incidents and Reporting Obligations
In the event of a security incident that may affect the systems or data of either SprintEins or our clients, SprintEins must be informed without undue delay upon becoming aware of the incident, at minimum in text form, via isb@sprinteins.com. The notification must include the following information:
- the nature and scope of the incident
- the systems and data affected
- any countermeasures already initiated
- the supplier’s point of contact
2.6 Endpoint Security
- All endpoint devices used for activities carried out on behalf of SprintEins must be fully encrypted (e.g. BitLocker or FileVault).
- A current antivirus and/or EDR solution is mandatory.
- Security updates for the operating systems and applications in use must be applied and installed as quickly as possible.
3 Data Protection
Suppliers that process personal data or other data in the course of their activities for SprintEins must comply in full with all applicable data protection and statutory requirements.
3.1 General Protection of Data and Security-Relevant Information
The supplier undertakes to treat as confidential, and to process solely for the contractually agreed purposes, all information and data made accessible or provided to it in connection with its contractual relationship with SprintEins, in particular personal data, security-relevant information, product data, and related service data within the meaning of the EU Data Act.
The supplier shall implement appropriate technical and organisational measures reflecting the current state of the art in order to protect the confidentiality, integrity, availability and resilience of the relevant systems and data.
Disclosure to third parties or subcontractors shall be permitted only insofar as it is necessary for performance of the contract, legally permissible, and subject to equivalent confidentiality and protection obligations.
Personal data may be processed only in accordance with the General Data Protection Regulation; any processing or disclosure shall take place only where an appropriate legal basis exists.
Where data must be made available under the Data Act, the rights of the data holder to protect trade secrets and security-relevant information shall remain unaffected; however, protective measures and any restrictions on data provision must not unreasonably impair the statutory right of access to data.
The supplier shall ensure that its employees, and any subcontractors engaged with the consent of SprintEins, are bound by corresponding obligations and shall, upon request, provide evidence of compliance with these obligations.
Upon termination of the collaboration, or upon request, the relevant data and documents must, unless statutory retention obligations apply, be returned, deleted or blocked without undue delay.
3.2 GDPR Compliance in Relation to the Protection of Personal Data
- Personal data may be processed only on the basis of an appropriate legal ground pursuant to Article 6(1) GDPR.
- Data subject rights (including access, erasure and rectification) must be supported.
- Technical and organisational measures (TOMs) in accordance with Article 32 GDPR must be implemented and, upon request, demonstrated.
3.3 Processing on Behalf of SprintEins
Suppliers that process personal data on behalf of SprintEins shall act as processors within the meaning of Article 28 GDPR. Before any such processing begins, a data processing agreement (DPA) must be concluded with SprintEins.
3.4 Transfers to Third Countries
The transfer of personal data to countries outside the European Union, the European Economic Area (EEA), the United Kingdom or Switzerland shall be permitted only where an adequate level of data protection is ensured in the country concerned, for example by means of an adequacy decision or the execution of applicable Standard Contractual Clauses. SprintEins must be informed sufficiently in advance, at minimum by email.
4 Confidentiality
All information obtained in the course of the contractual relationship concerning SprintEins, its clients, products, processes and technologies shall be treated by the supplier as confidential in accordance with the following provisions:
- Confidential information may be disclosed only to persons who have a strict need to know it for the performance of their duties.
- Confidential documents must be kept securely and protected against access by third parties and, upon termination of the collaboration, must be returned in full or demonstrably destroyed, unless the supplier is subject to a time-limited statutory retention obligation. For the avoidance of doubt, the supplier shall have no right of retention in this respect.
- The obligation of confidentiality shall continue beyond the termination of the contractual relationship.
The obligation of confidentiality shall not apply where:
- the information was independently developed by the supplier as recipient, without reference to the information obtained from SprintEins;
- the information was already known to the supplier at the time it was disclosed by SprintEins;
- the supplier lawfully obtained the information from a third party after disclosure by SprintEins, without any breach of a duty of confidentiality;
- the information was already in the public domain at the time of disclosure by SprintEins or subsequently enters the public domain other than through a breach of this obligation;
- the supplier has been expressly authorised in advance by SprintEins, at minimum in text form, to make the relevant disclosure;
- the supplier is required to disclose the information by law or by order of a public authority. In such case, the supplier shall, to the extent legally permissible, inform the disclosing party in advance, at minimum in text form, of the intended disclosure and shall take all lawful and necessary steps to limit the scope of disclosure as far as possible;
- the information is lawfully used for a report to an internal or external reporting office in accordance with the German Whistleblower Protection Act (HinSchG), or disclosure of the information is otherwise permitted under HinSchG;
- one of the exceptions under section 5 of the German Trade Secrets Act (GeschGehG) applies.
5 Compliance & Legal Requirements
5.1 Statutory Requirements
Suppliers undertake to comply in full with all applicable statutory and regulatory requirements in the countries in which they operate in accordance with the contractual arrangements. This includes, in particular:
- employment and social legislation;
- export control and sanctions laws; and
- tax and commercial law.
5.2 Anti-Corruption and Conflicts of Interest
General requirements applicable to suppliers in this context are as follows:
- Bribery, corruption, money laundering and improper influence are prohibited in all forms.
- Conflicts of interest must be disclosed to SprintEins without undue delay.
- Gifts and benefits offered to SprintEins employees must not exceed a token value.
- Suppliers must establish effective internal measures for the prevention and reporting of fraud, money laundering and embezzlement.
SprintEins has zero tolerance for corruption. The supplier undertakes to comply with the prohibition of all forms of corruption, bribery, embezzlement and extortion. At a minimum, the supplier is required to comply with the statutory provisions applicable in this respect.
The supplier must refrain from unlawfully requesting, accepting, offering or granting an advantage for itself, for an individual, for a company or for a public official in order to influence a business decision or a decision in the public sector, including the securing of expedited performance. This also applies to benefits such as gifts, hospitality and invitations to events. The supplier is likewise required to comply with all applicable legal requirements relating to donations and sponsorship.
The supplier must maintain appropriate systems to ensure compliance with its obligations under this section 5.2, to identify breaches and to prevent such breaches from occurring.
5.3 Competition Law
Agreements or arrangements that restrict competition are prohibited. Suppliers must act in accordance with all applicable competition and antitrust laws.
In the conduct of its business, the supplier shall observe the principles of fair and free competition.
The supplier undertakes to comply with the applicable antitrust and competition laws. It must refrain from entering into agreements or engaging in conduct which has the object or effect of restricting free competition. In particular, the supplier shall comply with the prohibition on exchanging confidential competition-sensitive information with competitors, entering into price-fixing arrangements with them, or coordinating any allocation of markets or customers that distorts competition.
Furthermore, the supplier must not dictate to its customers the prices they charge to their own customers. The supplier’s customers must remain free to determine the terms and pricing of their own sales.
The supplier must comply with the prohibition on unfair commercial practices. In particular, it must refrain from using aggressive commercial practices that improperly impair the freedom of decision of its contractual partners.
The supplier must also refrain from making disparaging or derogatory statements about competitors and their products, and from engaging in misleading commercial practices, including, for example, by making misleading statements in advertising.
The supplier must also conduct itself fairly in its advertising and is under an obligation to ensure that all statements made in that context, particularly in relation to the products and services it offers, are truthful.
5.4 Artificial Intelligence
The supplier shall ensure compliance with all applicable laws and regulations in the development or use of artificial intelligence. In doing so, the supplier must ensure that the use of artificial intelligence is transparent, responsible and subject to appropriate human oversight.
5.5 Protection of Intellectual Property
The supplier shall comply with all relevant national and international laws governing the protection of intellectual property and other proprietary rights. This applies in particular to copyright, designs, trade marks and patents.
In addition, the supplier shall ensure that it holds all necessary rights of use in order to prevent infringements of intellectual property rights and the misappropriation of third-party intellectual work, including plagiarism.
5.6 International Trade
SprintEins’ contractual partners must comply with all national and international trade regulations, customs rules, export control requirements and embargo provisions in order to ensure that all applicable national and international sanctions and trade embargoes are observed. Where necessary, appropriate measures must be taken to prevent sanctions breaches.
5.7 Anti-Money Laundering
As a contractual partner of SprintEins, the supplier must ensure compliance with all relevant statutory requirements relating to the prevention of money laundering.
6 Sustainability and Social Responsibility
SprintEins is committed to responsible corporate conduct and expects its suppliers to demonstrate a high level of commitment to environmental protection and sustainable business practices.
SprintEins’ contractual partners undertake to comply with all applicable national laws, regulations and standards relating to environmental protection. In addition, contractual partners commit to conserving resources wherever possible and to minimising environmental impacts and risks.
This includes establishing and continuously developing their own production processes and facilities in order to ensure that environmental impacts — for example those arising from energy and water consumption, wastewater, improper land use, air, noise and odour emissions, waste, and hazardous substances — are identified and systematically addressed.
6.1 Environment
- Compliance with all applicable environmental laws and regulations;
- Responsible use of resources and the reduction of emissions and waste wherever economically reasonable;
- Preferred use of certified data centres (e.g. ISO 50001, Green IT).
6.2 Social Standards
Suppliers undertake to comply with the ILO Core Labour Standards as well as the following minimum standards:
6.2.1 Prohibition of Child Labour
- Suppliers must comply with the ILO conventions on minimum age and on the protection of young workers under the age of 18.
- The age of employees must be verified and documented at the time of recruitment on the basis of a valid identity document.
6.2.2 Prohibition of Forced Labour
- All employment must be voluntary. Coercion, threats or intimidation are prohibited.
- Employees must be free to terminate an existing employment relationship subject to the applicable statutory notice periods.
6.2.3 Freedom of Association and Fair Remuneration
- The right of employees to associate freely, to join trade unions and to participate in collective bargaining must be respected to the extent permitted by law.
- All employees must receive fair and transparent remuneration at least equal to the statutory minimum wage.
- Working hours and working conditions must comply with all applicable legal requirements.
6.2.4 Non-Discrimination and Prohibition of Harassment
- Discrimination on grounds of ethnic origin, sex, religion, belief, disability, age, sexual orientation or any other protected characteristic is prohibited.
- Harassment in any form — whether verbal, physical or otherwise — will not be tolerated.
- Suppliers must ensure that employees are able to report breaches internally without fear of disadvantage.
7 Subcontractors
Suppliers wishing to outsource parts of their services to subcontractors are required to:
- inform SprintEins in good time in advance, in accordance with the contractual arrangements, of the engagement of subcontractors and obtain SprintEins’ consent at minimum in text form, unless the engagement of the relevant subcontractor has already been agreed; and
- remain responsible, as SprintEins’ direct contractual partner, for ensuring that any appointed subcontractors comply with this Supplier Code of Conduct.
8 Obligation to Provide Evidence by Self-Disclosure and Certificates
Suppliers are required, upon request by SprintEins, to provide up-to-date evidence of compliance with this Supplier Code of Conduct. Acceptable forms of evidence include:
- current certifications (ISO 27001, TISAX, SOC 2, etc.);
- completed self-assessment questionnaires; and
- security reports or summaries of penetration tests.
9 Amendments to the Supplier Code of Conduct / Contact Details
9.1 Version Control
SprintEins reserves the right to further develop and update this Supplier Code of Conduct on a regular basis, for example in the event of relevant legislative changes or other material amendments. Suppliers will be informed in advance of any new provisions and material changes. The current version is available at all times at
https://sprinteins.com/en/suppliers-code-of-conduct.
9.2 Contact Details
If the supplier has any questions regarding this Supplier Code of Conduct or wishes to report any breaches, it may contact SprintEins via the following channels:
- E-mail: isb@sprinteins.com
- Web: www.sprinteins.com
10 Whistleblowing System
Suppliers and their employees may report breaches of this Supplier – Code of Conduct or other misconduct anonymously via SprintEins’ whistleblowing system:
Report a concern: https://report.proliance360.com/sprinteins-gmbh
The system is open to external whistleblowers and ensures confidential handling in accordance with the requirements of the German Whistleblower Protection Act (HinSchG).
11 Supplier Declaration and Acceptance of the Supplier Code of Conduct / Compliance with Obligations and Legal Consequences
11.1 Legally Binding Effect
By signing a contract with SprintEins or by providing express confirmation, the supplier declares its acceptance of the provisions of this Supplier Code of Conduct. The supplier undertakes to comply with all requirements and obligations set out herein when supplying products or providing services to SprintEins.
The supplier further undertakes to communicate the contents of this Supplier Code of Conduct in an understandable manner to its employees, agents and subcontractors whose involvement has been approved by SprintEins, and to take all reasonable steps to ensure that they likewise comply with the obligations and requirements of this Supplier Code of Conduct or with equivalent standards.
In the event of any conflict between this Supplier Code of Conduct and specific agreements such as an NDA (Non-Disclosure Agreement), a data processing agreement or a subcontractor agreement, the provisions of such specific agreements shall prevail.
11.2 Supplier Due Diligence Obligations
The supplier must, in an appropriate manner, identify and minimise risks of breaches of this Supplier Code of Conduct within its own business operations and among its direct suppliers.
For this purpose, the supplier must establish an appropriate and effective risk management system and designate a person responsible for its oversight. The supplier must carry out a risk analysis in order to identify risks within its own business operations and among its direct suppliers. Where risks are identified, the supplier must without undue delay take appropriate preventive measures within its own business operations and in relation to its direct suppliers.
If the supplier becomes aware that a breach of this Supplier Code of Conduct has occurred or is imminent within its own business operations or at a direct supplier, the supplier must without undue delay take suitable remedial action to prevent the breach, bring it to an end or minimise the extent of the infringement. If remedial action at a direct supplier is not possible, a corrective action plan with a specific timetable must be drawn up and implemented.
By establishing an appropriate internal complaints procedure, the supplier must ensure that individuals are able to report, confidentially and without suffering any personal disadvantage, risks of breaches of, or actual breaches of, this Supplier Code of Conduct, whether such breaches concern the supplier itself or its direct or indirect suppliers.
The supplier must carry out or review the above risk analysis, as well as the effectiveness of its preventive or remedial measures and its complaints procedure, once a year and on an ad hoc basis where circumstances so require, and must inform SprintEins accordingly. The supplier must continuously document compliance with the above obligations internally and retain such documentation for at least seven years.
11.3 Supplier Reporting and other Cooperation Obligations
If the supplier becomes aware of facts giving rise to a suspicion of a breach of this Supplier Code of Conduct, it shall notify SprintEins without undue delay in text form.
Such notification must be made to SprintEins’ internal reporting office established for this purpose, either by telephone on +49 711 67418279 or by email to isb@sprinteins.com.
If the supplier is prevented from making such a notification or providing other information for reasons of data protection or the protection of trade secrets, it may make such disclosure conditional upon SprintEins first providing a confidentiality and non-disclosure undertaking.
The preceding paragraph shall apply equally in the event of a suspected or established breach by the supplier’s subcontractors.
11.4 Audits
Irrespective of whether any suspicion or established breach exists, the supplier agrees that SprintEins may verify compliance with this Supplier Code of Conduct by means of appropriate, necessary and proportionate measures, including in particular inspection of the documentation referred to in section 11.2 (preventive measures arising from risk assessments), obtaining self-assessments, interviewing employees, or carrying out on-site inspections (together referred to below as “Audits”); no prior notice of such Audits shall be required.
In the course of such Audits, the supplier shall provide information to SprintEins or to third parties commissioned by SprintEins for this purpose (the “Auditors”) and shall, upon request, grant access to the necessary documents; section 11.3 paragraph 1 sentence 1 shall apply accordingly.
The preceding paragraph shall apply mutatis mutandis to Audits at the supplier’s direct suppliers. At SprintEins’ request, the supplier must facilitate such Audits and ensure that it is granted the rights required for this purpose vis-à-vis its suppliers.
11.5 Consequences of Breaches
If the supplier breaches this Supplier Code of Conduct through an act or omission, SprintEins shall request in text form that the supplier amend its conduct within a reasonable period so that the breach of this Supplier Code of Conduct is ceased and/or remedied (formal warning).
If the supplier fails to amend its conduct within the period specified, SprintEins may terminate, with immediate effect and without notice, any contractual relationship affected by such conduct.
No notice period or formal warning shall be required if the supplier has seriously and definitively refused to amend its conduct, if such amendment is impossible due to the nature of the breach, or if special circumstances exist which, having regard to the interests of both parties, make the setting of a notice period or the issuing of a formal warning unreasonable, for example in the case of a repeated or serious breach.
Any further rights of SprintEins, in particular any potential claim for damages, shall remain unaffected.
This Code is not intended to be exhaustive. It does not replace individual contractual agreements but supplements them.