Compliance & Whistleblower Channel

Introduction

BIO OIL GROUP is committed to integrity, transparency and lawful conduct across all business areas. To ensure that violations, misconduct and concerns can be reported confidentially, BIO OIL GROUP operates an anonymous whistleblower channel in line with the EU Whistleblower Directive (2019/1937), the German Whistleblower Protection Act (HinSchG) and the Austrian Whistleblower Protection Act (HSchG). Whistleblowers enjoy comprehensive protection from retaliation.

Who can report and what can be reported

The channel is open to all current and former employees, applicants, suppliers, customers, business partners and other third parties who have obtained relevant information in the context of their professional activities. Reports may concern in particular:

  • Discrimination, harassment or workplace bullying
  • Corruption, bribery, conflicts of interest or money laundering
  • Violations of occupational safety, health or environmental protection rules
  • Breaches of data protection, IT security or confidentiality
  • Accounting fraud, embezzlement or other financial irregularities
  • Violations of supply chain, human rights or sustainability obligations
  • Other material breaches of laws, regulations or our Code of Conduct

Protection of the whistleblower

BIO OIL GROUP guarantees comprehensive protection to all whistleblowers acting in good faith. Specifically, this means:

  • Strict confidentiality of every incoming report
  • Prohibition of any retaliation (dismissal, transfer, harassment, career obstruction, etc.)
  • Independent handling by a dedicated compliance function
  • Reversal of the burden of proof in suspected retaliation cases: the company must prove that any disadvantage is unrelated to the report
  • Abusive reports are reviewed but will not be used against the whistleblower unless the whistleblower acts unlawfully

Anonymity of this channel

This channel is designed so that a report can be submitted fully anonymously. What we ensure:

  • No storage of your IP address or other connection data
  • No cookies or browser fingerprinting on this page
  • No database storage of your report — your message is forwarded exclusively by encrypted e-mail to our compliance function
  • No automated content analysis by third parties (AI spam filters, etc.)
  • You may voluntarily provide a contact e-mail if you wish to receive follow-up questions or feedback — otherwise your report stays fully anonymous
  • Note: if you do not provide a means of contact, an acknowledgement or feedback cannot technically be sent to you

Procedure after receipt of a report

Incoming reports are handled exclusively by a small, trained group within the compliance function. The procedure follows statutory requirements:

  • If you provided a means of contact: acknowledgement of receipt within seven days
  • Review of the report for substance and plausibility
  • Where necessary, confidential follow-up questions via the channel you provided
  • Initiation of appropriate follow-up measures (internal investigation, remediation, referral to external bodies)
  • Feedback on the outcome within three months, provided a means of contact was given
  • Documentation of the case in line with statutory retention periods, while preserving confidentiality

External reporting bodies

You are always entitled to report violations directly to external reporting bodies, such as the Federal Office of Justice (Germany), the Federal Bureau of Anti-Corruption (Austria), or the competent authorities of any EU Member State. Internal reporting beforehand is not required; we nevertheless recommend it to enable rapid remediation.

Submit a report

Please describe the matter as concretely as possible. Include dates, persons involved (if known), locations and any supporting evidence available to you. The more precise your report, the better we can respond.

Minimum 50, maximum 5000 characters.

Only fill in if you would like a response. Anonymous disposable addresses (ProtonMail, Tutanota, etc.) are explicitly allowed.

We store no IP address, no cookies and no database records. Your report is forwarded only by e-mail to the compliance function.

For questions about this channel or the procedure, please contact our compliance function at: compliance@bio-oil.biz