Policies
Policies
Filters
A Code of Conduct that is not read is not a Code of Conduct. This document is written in plain, direct language — with real scenarios and behaviour tables that employees can apply to everyday situations.
Eight principles, each with a Do/Don't behaviour table, a practical scenario card, and the rationale for why it matters. Covers: reporting channels with a five-route escalation table, consequences of breach, a related policies table linking to the full suite, and a versioned annual acknowledgement form. Written specifically for startups and growing businesses where cultural foundation matters most.
FAQS
Q Why does a startup need a Code of Conduct?
Culture is set in the first 20 people. What is tolerated in the early days becomes what is normal as the company grows — and by the time it is a problem, it is expensive and painful to change. A Code also has direct commercial value: investors expect to see one at due diligence, enterprise customers increasingly require it as a contracting condition, and it provides the documented basis for disciplinary action when conduct standards are breached.
Q How is this Code different from a generic template?
Most Codes are written in abstract principles that require translation into real decisions. This one is built around practical scenario cards — a situation, the right approach, and the wrong approach — and Do/Don't behaviour tables for each of the eight principles. The scenarios are specific: the Responsibility scenario addresses a health tech regulatory context; Fairness addresses a hiring bias situation; Excellence addresses quality compromise under deadline pressure. Real decisions, not aspirations.
Q Does the Code cover speaking up and whistleblowing?
Yes. Part 9 covers five reporting channels with a clear escalation table and a prominent 'No retaliation. Ever.' commitment. The Code states explicitly that anyone who raises a concern in good faith will not be subject to retaliation regardless of whether the concern is substantiated. It also links to the Whistleblowing & Protected Disclosure Policy for the formal process.
Q How does the annual acknowledgement work?
The Code includes a versioned annual acknowledgement form signed on joining and annually thereafter. It confirms the person has read and understood the Code and commits to comply. The version history table shows which version each person acknowledged and when — important for any subsequent disciplinary or legal proceedings.
Most confidentiality breaches happen because people do not understand what is confidential or how to protect it. This document fixes that — combining a readable policy with a legally robust integrated NDA.
Policy covers: what is (and is not) confidential information, positive obligations and prohibited activities, handling third-party information, confidentiality in the digital environment (including AI tools), breach reporting, and post-employment obligations. The integrated NDA covers 12 clauses including definitions, confidentiality obligations, standard of care, exceptions, return of information, duration, remedies, and whistleblowing carve-out. Trade secret protection jurisdiction flags for IE, UK, US, CA, and AU.
FAQS
Q Why does a startup need both a confidentiality policy and an NDA?
The policy sets out what is confidential, how to protect it, and what happens if it is breached — in accessible, readable language. The NDA is the legally binding contract that makes the policy enforceable. Having the policy without the NDA leaves obligations unenforceable in contract; having the NDA without the policy means people sign something they have not fully understood. This document combines both into one integrated instrument — the NDA incorporates the policy by reference.
Q Does the policy cover AI tools specifically?
Yes. A dedicated section on the digital environment prohibits entering Confidential Information into public AI tools — explaining that inputs may be used to train the model, cannot be recalled, and could be exposed to other users. It requires any AI tool used with Company data to be specifically approved with appropriate data processing agreements in place.
Q What are the post-employment obligations?
The confidentiality obligation survives employment indefinitely for information received during the engagement. On departure, Covered Persons must return or delete all Confidential Information and confirm deletion in writing. They may not use Confidential Information in a new role or disclose it to a new employer. A jurisdiction flag covers the enforceability of these obligations post-employment in IE, UK, US, CA, and AU — including the important distinction between trade secrets (protectable at common law) and other confidential information (which may require an express post-employment covenant).
Q Does the NDA contain a whistleblowing carve-out?
Yes — and this is legally required in most jurisdictions. Clause 9 of the NDA explicitly preserves the right to make a protected disclosure under applicable whistleblowing legislation, report a breach of law to a regulatory authority, or exercise any statutory right that cannot be excluded by agreement. Attempting to use an NDA to suppress a protected disclosure is not only unenforceable but may itself constitute a breach of whistleblower protection legislation.
Without a clear Acceptable Use Policy, there is no documented basis for disciplinary action when someone misuses Company systems — and the organization may have compromised its ability to monitor or access its own devices. This policy closes that gap.
Covers: scope (hardware, software, cloud, networks, BYOD), acceptable and unacceptable use, email standards and anti-spam obligations (PECR/CAN-SPAM/CASL/AU Spam Act), device security standards, monitoring obligations with a five-jurisdiction flag (GDPR/UK GDPR, ECPA, PIPEDA, Privacy Act), and breach consequences. Includes specific guidance on AI tools.
FAQS
Q Why does a small business need an Acceptable Use Policy?
Without a documented AUP, the organization has no contractual or policy basis for disciplinary action when someone misuses Company systems. It also creates risk around monitoring — accessing employee communications or logs without a prior communicated policy may be unlawful under GDPR, the Electronic Communications Privacy Act, or equivalent legislation. The AUP establishes the rules, communicates them, and creates the documented framework for both disciplinary action and lawful monitoring.
Q Does the policy cover personal device use (BYOD)?
Yes. The scope section explicitly addresses personally owned devices used for work. It sets out the conditions for permitted BYOD use, the security requirements that apply, the organization's right to require remote wipe of Company data from personal devices, and the employee's responsibility to maintain the device in a state that protects Company data.
Q What does the policy say about monitoring?
The monitoring section balances legitimate business interests with employee privacy rights. It states clearly what may be monitored, the purpose, and that monitoring is not continuous or individually targeted without cause. A five-jurisdiction flag covers GDPR (IE/UK), ECPA and state law (US), PIPEDA (CA), and the Privacy Act / Workplace Surveillance Act (AU) — because the legal requirements differ significantly.
Q Does this policy cover AI tools?
Yes. The unacceptable uses section prohibits entering Confidential Information into public AI tools. This provision works alongside the AI Usage Policy, which provides the full governance framework. For organisations wanting basic AI coverage in a single policy, the AUP provides the foundation; for comprehensive AI governance, the dedicated AI Usage Policy is recommended.
Data protection compliance is legally mandatory in Ireland and the UK and practically required in every jurisdiction where the Company operates. This policy gives organizations the documented foundation that GDPR and equivalent legislation demands.
Covers: the seven data protection principles, what personal data is held and why, lawful bases for processing (including the special category data warning), six individual rights with jurisdiction-specific response timelines, a five-step breach response process with notification windows (GDPR 72 hours, AU NDB 30 days, US state law timelines), and employee obligations. Jurisdiction flags for GDPR/UK GDPR, US (CCPA/CPRA, HIPAA), PIPEDA/Law 25, and Australian Privacy Principles.
FAQS
Q Is a written data protection policy legally required?
Under the GDPR (which applies in Ireland and to any company processing EU residents' personal data regardless of location), a documented policy is a core element of the accountability obligation under Article 5(2) and the record of processing activities required under Article 30. Its absence is itself an indicator of non-compliance. For UK employers, the UK GDPR imposes equivalent requirements.
Q What is the difference between a data protection policy and a privacy notice?
A data protection policy is an internal document covering how the organization handles personal data — the principles applied, lawful bases, individual rights, and employee obligations. A privacy notice is an external-facing document provided to individuals explaining how their data is used. Both are required under GDPR; this document covers the internal policy. Separate employee and customer privacy notices should be prepared for external publication.
Q What is a Subject Access Request and how long do we have to respond?
A SAR is a request from an individual to receive a copy of their personal data and information about how it is used. Response timelines: GDPR/UK GDPR — 1 calendar month (extendable to 3 for complex requests); PIPEDA (Canada) — 30 days; Australian Privacy Act — 30 days; CCPA (California) — 45 days. The policy sets out the SAR handling process and the limited grounds on which a request can be refused.
Q What does the 72-hour breach notification requirement mean?
Where a personal data breach creates a risk to individuals' rights and freedoms, GDPR requires notification to the supervisory authority within 72 hours of becoming aware — not from the breach itself. This requires a documented breach response process enabling rapid triage and notification. The policy includes a five-step breach response framework with specific timelines for each stage.
A written health and safety policy is legally required for most employers in Ireland, the UK, and equivalent jurisdictions. This policy meets that obligation and goes further — covering the specific challenges of remote and hybrid working environments.
Covers: responsibilities by role (Company, leadership, managers, employees), risk assessment for DSE, manual handling, fire, stress, and home working, home working self-assessment framework, incident reporting process with a five-jurisdiction statutory reporting obligations flag (HSA, RIDDOR, OSHA, provincial OH&S, WHS), and mental health and EAP provisions.
FAQS
Q Is a written H&S policy legally required for small businesses?
In Ireland, the Safety Statement is required for all employers — not just large ones. Employers with three or more employees must have a written Safety Statement under the Safety, Health and Welfare at Work Act 2005. In the UK, employers with five or more employees must have a written policy under the Health and Safety at Work etc. Act 1974. In Australia, a documented safety management system is required under the WHS Act 2011.
Q Does the policy cover employees who work from home?
Yes — with a dedicated section. The employer's duty of care extends to home working environments. The policy covers home workstation self-assessment (DSE risk assessment), ergonomic guidance, equipment provision where risks are identified, lone worker check-in protocols, and the mental health obligations specific to remote working contexts.
Q What does the incident reporting section require?
All incidents, near misses, and dangerous occurrences must be reported promptly regardless of severity. The framework distinguishes four levels with different reporting chains and timelines. A five-jurisdiction flag covers statutory reporting: RIDDOR (UK), HSA notification (Ireland), OSHA recording and reporting (US), provincial OH&S requirements (Canada), and WHS Act notification obligations (Australia).
Q What does the mental health section include?
EAP access, manager training obligations, workload monitoring as part of the 1:1 process, a culture of openness around stress and mental health, and the reasonable adjustment obligation for mental health conditions. It cross-references the Mental Health & Wellbeing Policy for the full framework.
Equal opportunities is both a legal obligation and a commercial necessity. This policy gives organizations a clear, accessible framework for what is prohibited and what is required.
Covers: protected characteristics in all five jurisdictions (including a detailed jurisdiction flag), the six types of prohibited conduct with definitions and examples, reasonable adjustments in recruitment, pay and promotion fairness, a gender pay gap reporting obligations flag by jurisdiction, and a four-route escalation table.
FAQS
Q What protected characteristics does this policy cover?
All five jurisdictions in full. Ireland (Employment Equality Acts): gender, civil status, family status, sexual orientation, religion, age, disability, race, Traveller community. UK (Equality Act 2010): age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, sexual orientation. US (Title VII/ADA/ADEA/GINA): race, colour, national origin, sex, religion, age (40+), disability, genetic information. Canadian Human Rights Act and Australian anti-discrimination legislation are also covered.
Q What is the difference between direct and indirect discrimination?
Direct discrimination is treating someone less favourably because of a protected characteristic — not interviewing a candidate because of their age, or paying a woman less for the same work. Indirect discrimination is applying a neutral provision that puts people with a protected characteristic at a disadvantage without objective justification — for example, requiring Saturday working in a way that disproportionately disadvantages employees of certain religions.
Q What should a manager do when they witness harassment?
The policy is explicit that silence is not neutral — it signals endorsement. Managers are required to address dismissive, undermining, or harassing behaviour immediately when they observe it, regardless of the seniority of the person engaging in it. The Code of Conduct includes a specific scenario on this with intervention language. Managers who witness harassment and do nothing may themselves face conduct consequences.
Q Does the policy cover pay and promotion decisions?
Yes — with a specific section on pay and promotion fairness. Pay decisions must be based on objective criteria, not protected characteristics. Promotion decisions must be based on demonstrated performance and capability against defined criteria. A five-jurisdiction gender pay gap reporting flag covers mandatory reporting obligations in Ireland (Gender Pay Gap Information Act 2021), UK (Equality Act regulations), and the comparable obligations in the US, Canada, and Australia.
Without a clear expense policy, claims become inconsistent and tax complications arise across jurisdictions. This policy gives organizations and their employees clarity on exactly what will and will not be reimbursed.
Covers: the seven principles of expense management, eight categories of reimbursable expenses, daily meal limits by jurisdiction (aligned with Revenue/HMRC/IRS/CRA/ATO rates), a comprehensive non-reimbursables list, and the five-step claim and approval process. Jurisdiction flags cover tax treatment for IE (Revenue civil service rates), UK (HMRC AMAPs), US (IRS accountable plan), CA (CRA rates), and AU (ATO tax determination rates).
FAQS
Q Why do businesses need a formal expenses policy?
Without a policy, expense claims become inconsistent (similar expenses treated differently depending on who is asking), create tax risk (reimbursements outside accountable plan rules can become taxable income), and invite abuse (without documented limits, individual judgment fills the gap unpredictably). A clear policy protects both the business and the employee.
Q What meal rates does the policy use?
The policy aligns meal limits to the statutory civil service rates in each jurisdiction — Revenue (Ireland), HMRC (UK), IRS (US), CRA (Canada), and ATO (Australia). Aligning to statutory rates ensures reimbursements within those limits are not treated as taxable benefits. Rates are referenced with a note to confirm current amounts annually as they are updated regularly.
Q Does the policy cover home office expenses?
Yes. A section covers home worker contributions: a one-time home office setup contribution (subject to a workstation assessment) and a monthly internet allowance. The policy also guides employees on claiming the home working tax relief available in each jurisdiction.
Q When does client entertainment need pre-approval?
Client entertainment up to a stated daily limit with a clear business purpose is permitted without pre-approval. Entertainment above a specified threshold requires manager approval before the event — not after. Cash or cash-equivalent gifts are never acceptable. The Anti-Bribery Policy sets the broader framework for when hospitality crosses into unacceptable territory.
Mental health is as important as physical health and carries the same legal obligations. This policy gives organizations a clear, humane framework for supporting employee mental health at every level.
Covers: five support resources (EAP, mental health first aiders, occupational health, manager conversations, formal HR), eight manager responsibilities including training and confidentiality, absence management and phased return, the duty to make reasonable adjustments for mental health conditions, and five active wellbeing practices (workload, meetings culture, annual leave, right to disconnect, recognition). Jurisdiction flags for disability protection under IE Employment Equality Acts, UK Equality Act 2010, US ADA, Canadian Human Rights Codes, and AU Disability Discrimination Act.
FAQS
Q What are the employer's legal obligations around mental health?
In Ireland, the Safety, Health and Welfare at Work Act 2005 extends the duty of care to psychological as well as physical safety. The UK Health and Safety at Work Act 1974 imposes an equivalent duty. In the US, the ADA requires reasonable accommodations for qualifying mental health conditions. In Canada, human rights codes in all provinces require accommodation of mental disability. In Australia, WHS legislation requires employers to manage psychosocial hazards in the same way as physical ones.
Q What is an EAP and do we need one?
An Employee Assistance Programme is a confidential support service providing employees and often their immediate family with access to counselling, legal advice, financial guidance, and wellbeing support — typically from a third-party provider, 24/7. While not legally mandatory in most jurisdictions, it is considered the baseline employer mental health provision and is referenced in health and safety codes of practice. The policy covers how to communicate EAP availability without stigma.
Q What should a manager do if they notice someone struggling?
The policy gives managers a clear framework: notice the early warning signals (changes in communication, energy, attendance, or engagement), create time for a private conversation, ask open questions about how the person is doing, listen without rushing to fix, and refer to HR, the EAP, or occupational health where professional support is needed. Managers are not expected to act as therapists — their role is to create the conditions for the person to access the right support.
Q What reasonable adjustments might a mental health condition require?
Adjustments are assessed individually — there is no standard menu. Examples include flexible working, adjusted performance targets during a difficult period, phased return from absence, reduction of specific stressors (travel, client-facing work, high-stakes deadlines), quiet workspace provision, or reallocation of specific tasks. The obligation is to consider and implement what is reasonably practicable given the role and the organisation's size and resources.
Parental leave law is among the most jurisdiction-specific in employment law. This policy covers all five jurisdictions in detail — giving organizations operating internationally a single document that meets statutory minimums everywhere.
Eight parts covering: policy principles, maternity and pregnancy-related leave (full five-jurisdiction table with statutory pay, enhanced pay, and notice requirements), parental and paternity leave, adoption leave, shared parental leave (with US/CA/AU position explained), flexible working statutory rights (including the EU Directive, UK Employment Relations (Flexible Working) Act 2023, US state laws, and AU Fair Work Act), return-to-work rights, and protection against detriment. Eight inline jurisdiction flags.
FAQS
Q Why does a multi-jurisdiction parental leave policy matter?
Parental leave entitlements are among the most jurisdiction-specific provisions in employment law. Statutory leave durations, pay rates, government funding models, and employer obligations differ materially between Ireland, the UK, the US, Canada, and Australia. A business with employees in multiple jurisdictions needs a single policy that meets statutory minimums in each, with entitlement tables clear enough that employees can understand what they are entitled to without researching the law themselves.
Q What are the maternity leave entitlements in each jurisdiction?
Ireland: 26 weeks ordinary plus 16 weeks additional leave; Maternity Benefit from DPER. UK: up to 52 weeks total; Statutory Maternity Pay for up to 39 weeks. US: 12 weeks under FMLA for qualifying employees; no federal paid maternity leave — state programs vary significantly. Canada: 15 weeks EI maternity benefit plus 35 or 61 weeks parental benefit. Australia: up to 12 months unpaid (NES) plus up to 20 weeks government Parental Leave Pay (increasing to 26 weeks by 2026).
Q Do employees have a legal right to request flexible working?
In the UK, all employees have a statutory right from day one of employment (Employment Relations (Flexible Working) Act 2023). In Ireland, the Work Life Balance Act 2023 gives parents and carers of children under 12 the right to request remote working. In Australia, the Fair Work Act provides a right to request for qualifying employees with disputes referable to the Fair Work Commission. In the US and Canada, there is no general federal statutory right — though the ADA may require it as a reasonable accommodation.
Q Is Shared Parental Leave available in all five jurisdictions?
No. Shared Parental Leave exists in its specific statutory form only in the UK (SPL framework) and Ireland (Parent's Benefit). In the US, each eligible parent has their own independent 12-week FMLA entitlement — there is no shared pool. In Canada, the EI parental benefit can be shared between parents in any combination they choose. In Australia, Flexible PPL provisions from 2023 allow more flexible use of the government-funded entitlement between parents.
Remote working creates obligations — and opportunities — that a standard employment contract does not address. This policy gives organizations and employees clarity on every aspect of the arrangement.
Covers: working arrangements and core hours, the working-from-another-country warning, equipment and connectivity responsibilities (Company vs employee), home working safety with DSE assessment, working time obligations jurisdiction flag (IE Working Time Act, UK WTR, FLSA, provincial rules, NES), expenses and allowances, and performance and visibility expectations. Five-jurisdiction flag on the statutory right to request remote/flexible working.
FAQS
Q Do employees have a legal right to request remote working?
It depends on the jurisdiction. UK: all employees have a statutory right to request flexible working from day one (Employment Relations (Flexible Working) Act 2023). Ireland: the Work Life Balance Act 2023 gives parents and carers of children under 12 the right to request. Australia: the Fair Work Act gives qualifying employees a right to request with disputes referable to the Fair Work Commission. US and Canada: no general federal statutory right, though state/provincial laws are developing and the ADA may require remote working as a reasonable accommodation.
Q What are the H&S obligations for remote workers?
The employer's duty of care extends to home working environments. The policy requires home workstation self-assessments for all regular home workers, ergonomic guidance and equipment provision where risks are identified, and the same working time protections (daily and weekly hour limits, rest breaks) that apply in the office. Lone worker check-in protocols are required where employees work in isolation for extended periods.
Q What are the risks of working from a different country?
Working from another country creates unexpected tax, employment law, immigration, and social security obligations. In some cases it creates permanent establishment risk — the business is deemed to be operating in the employee's country, triggering corporate tax obligations there. The policy prohibits working from a different country for more than a defined period without prior HR approval, and explicitly notes that not all international remote working arrangements are legally or practically feasible.
Q What expenses and allowances does the policy cover for home workers?
A one-time home office setup contribution for approved home workers following a workstation assessment; a monthly internet allowance contribution; and guidance on claiming the home working tax relief available in each jurisdiction. The policy also distinguishes what the Company provides (core hardware, software, VPN) from what the employee is responsible for (broadband connectivity, suitable desk and chair).
Social media is where most unintentional confidentiality breaches begin — and where employer brands are built or destroyed in minutes. This policy gives organizations a clear, proportionate framework for managing the risk without over-restricting legitimate activity.
Covers: Company account standards, personal account obligations (what employees must not do and best practice), the specific health tech context (regulatory and reputational risk of premature disclosure), a jurisdiction flag covering NLRA Section 7 concerted activity protections (US), the right to disconnect (IE), and the consequences of breach. Designed to work alongside the Confidentiality Policy.
FAQS
Q Does a social media policy restrict employees' freedom of speech?
A proportionate policy does not restrict lawful personal expression — it sets reasonable expectations about how Company confidential information, brand, and reputation are treated online. Employees retain full freedom to express personal views on matters unrelated to the Company. In the US, the NLRA Section 7 specifically protects employees' rights to discuss wages and working conditions online — the policy reflects this and does not attempt to prohibit concerted activity.
Q What should employees do if they see a concerning social media post about the Company?
Report it to the marketing function or HR immediately. The policy covers both proactive brand management and reactive issue handling — including data disclosure via social media, content that could constitute harassment of a colleague, and posts by employees that may breach the policy. Early reporting enables the organization to assess and respond before the situation escalates.
Q Does the policy cover AI-generated content posted on social media?
Yes. The general prohibition on disclosing Confidential Information applies to AI-generated content exactly as to human-authored content. An employee who prompts an AI tool with Company-specific information and posts the output on social media has breached both this policy and the Confidentiality Policy. The AI Usage Policy provides the full AI governance framework.
Q What are the consequences of a serious breach?
A serious breach — deliberate disclosure of unannounced product information, patient data, or commercially sensitive information — constitutes potential gross misconduct and can result in summary dismissal. In a health tech context, it may also engage regulatory notification obligations (FDA, MHRA, HSA) and create personal legal liability. The policy is explicit about these consequences.
The UK Bribery Act 2010 creates criminal liability for the Company if an employee or agent pays a bribe — even without the Company's knowledge — unless adequate procedures are in place. This policy constitutes those procedures.
Covers: the six prohibited acts, the UK Bribery Act s.7 adequate procedures defence, facilitation payments prohibition (with explicit naming and the reason it applies globally), a gifts and hospitality traffic-light table (acceptable/conditional/prohibited) with threshold guidance, the gifts register requirement, third-party due diligence checklist, and reporting obligations. Jurisdiction flags for IE (Criminal Justice (Corruption Offences) Act 2018), UK (Bribery Act 2010), US (FCPA), CA (CFPOA), and AU (Criminal Code Act 1995).
FAQS
Q Does the UK Bribery Act apply to companies not based in the UK?
Yes — and this is one of the most significant aspects of the Act. The section 7 corporate offence (failure to prevent bribery) applies to any company that carries on business or any part of its business in the UK, regardless of where it is incorporated or where the bribery occurred. An Irish, US, Canadian, or Australian company with UK employees, UK customers, or UK commercial activity is subject to the Act. The only defence is having adequate anti-bribery procedures in place. This policy constitutes those procedures.
Q What are facilitation payments and why are they prohibited?
A facilitation payment is a small unofficial payment to a government official to speed up a routine government action — expediting a licence, clearing customs, securing a utility connection. They are prohibited by this policy in all jurisdictions and all circumstances, including where they are customary in a particular country. They are a criminal offence under the UK Bribery Act and are broadly prohibited across all five jurisdictions covered by this suite.
Q What should an employee do if they are offered a bribe?
Refuse it. Note the offer in writing immediately — what was offered, by whom, in what context, and on what date. Report it to the legal function and their manager without delay. Do not attempt to investigate or negotiate. The policy is explicit: no employee will be penalized for refusing to pay or accept a bribe, even where the refusal results in the loss of a business opportunity.
Q What is the gifts register and who maintains it?
The gifts register records all gifts and hospitality given or received above the stated minimum threshold, within five business days. It must capture: date, description, estimated value, giver/recipient, business context, and whether approval was obtained. It is maintained by Finance, Legal, or Compliance (as appropriate) and reviewed by senior leadership quarterly. The policy requires the register to be maintained but does not provide its format — this is typically a shared spreadsheet or a field in the compliance management system.
An undisclosed conflict of interest is a breach of trust that can undermine every decision made during the period of non-disclosure. This policy gives organisations a clear, enforceable framework for managing conflicts before they cause harm.
Covers: what constitutes a conflict of interest (six categories with examples), the mandatory disclosure process (four numbered steps), how the Company responds (four severity levels from immaterial to serious), the conflicts register, and a five-field annual declaration form. Legal context flags for director fiduciary duties in IE, UK, US (Delaware), CA, and AU.
FAQS
Q What counts as a conflict of interest?
A conflict arises where a person's personal interests, relationships, or outside activities could influence — or could reasonably appear to influence — their decisions or actions at work. The policy covers six categories: financial interests in competitors, suppliers, or customers; outside employment or consultancy; personal relationships with colleagues or business partners that affect decisions; competing businesses; gifts and entertainment that could affect judgment; and personal benefit from Company decisions. The key test is not whether a conflict actually influenced a decision — it is whether it could reasonably appear to have done so.
Q Must board members and directors follow this policy?
Yes — and with heightened obligations. Directors owe fiduciary duties including the duty to avoid conflicts (Companies Act 2006 s.175 in the UK; Companies Act 2014 s.228 in Ireland). The policy requires board members and advisors to disclose conflicts to the Chair of the Board or Audit Committee and to recuse themselves from any discussion or decision where a conflict exists. Undisclosed conflicts by a director are a potential breach of fiduciary duty with civil and regulatory consequences.
Q What is the annual conflicts declaration?
A five-question form completed by all Covered Persons confirming either that no undisclosed conflicts exist or that all known conflicts have been previously disclosed. It covers financial interests, outside work, personal relationships, gifts and entertainment, and any other relevant circumstances. Filed with HR and reviewed by senior leadership. It is the mechanism that ensures the policy is not signed on joining and forgotten.
Q What happens when a disclosed conflict is serious?
The Company's response scales with severity. Immaterial conflicts are documented and reviewed annually. Material conflicts require exclusion from relevant decisions and appointment of an alternative decision-maker. Serious conflicts incompatible with the role may require divestment, resignation from an outside position, or in extreme cases consideration of the employment relationship. Undisclosed conflicts discovered after the fact are treated as potential gross misconduct.
A company that cannot hear difficult truths from within cannot correct them before they become crises. This policy gives employees a safe, confidential route to raise serious concerns — and gives the organisation a legally compliant framework for handling them.
Covers: what is covered (criminal activity, regulatory breach, safety, financial misconduct), five reporting channels with timelines, the five-step investigation process, a table of external regulatory bodies by jurisdiction (including FDA and TGA for health tech), and four protection commitments for reporters. Jurisdiction flags cover the Irish Protected Disclosures Act 2014/2022 (EU Directive transposition), UK PIDA, US Dodd-Frank/SOX/False Claims Act (with financial rewards), CA legislation, and AU Public Interest Disclosure Act and Corporations Act.
FAQS
Q What is a protected disclosure and who is protected?
A protected disclosure is a report of suspected wrongdoing — illegal activity, regulatory breach, health and safety risks, environmental damage, or financial misconduct — made by a worker who has a reasonable belief the information is true. In Ireland, the Protected Disclosures Act 2014 (as amended 2022) protects all workers including employees, contractors, agency workers, and volunteers against penalization for making a protected disclosure. Equivalent protection applies in the UK (PIDA 1998), the US (Dodd-Frank, SOX, False Claims Act, OSHA, and sector-specific statutes), Canada, and Australia.
Q Is a formal whistleblowing policy legally required?
In Ireland, organizations with 50 or more workers must establish formal internal reporting channels under the Protected Disclosures (Amendment) Act 2022, which transposes the EU Whistleblower Directive 2019/1937. This is a legal requirement for organizations of that size. In the UK, the FCA and other regulators require regulated firms to have whistleblowing procedures. In the US, the SEC requires public companies to have programs. Regardless of legal obligation, the absence of a clear policy significantly increases legal and reputational exposure.
Q What protections does the policy provide to reporters?
Four commitments: no retaliation for raising a concern in good faith regardless of whether the concern is substantiated; confidentiality of the reporter's identity to the extent possible; prior notification if identity disclosure becomes necessary (and why); and non-interference with any regulatory or tribunal proceedings that may follow. Retaliation against a whistleblower is treated as potential gross misconduct.
Q What external bodies can employees report to?
The policy includes a five-jurisdiction table of external regulatory bodies. For health tech specifically: FDA (US), TGA (Australia), MHRA (UK), HSA (Ireland) for product safety concerns; SEC/CFTC/SFO for financial misconduct; WRC/EEOC/Fair Work Ombudsman for employment concerns. Employees may report externally regardless of whether they have used internal channels first.
A patent that cannot be prosecuted because invention dates cannot be established by competent evidence is a patent right lost through administrative failure. This policy gives technology companies the record-keeping infrastructure their IP estate depends on.
Thirteen parts covering: ownership rules (UK Patents Act 1977 s.39, IE Patents Act 1992 s.16, US employed-to-invent doctrine and California §2870 limitation, CA and AU common law), disclosure obligations (six mandatory triggers, 30-day window), the four requirements for competent evidence of invention date (specificity, contemporaneousness, corroboration, integrity), the invention notebook standard, electronic records and metadata integrity, assignment requirements by jurisdiction, patent filing decisions, employee compensation (UK s.40/IE s.17 rights), post-employment obligations, Invention Disclosure Form, and Invention Notebook Record Sheet.
FAQS
Q Why do technology companies need a standalone inventions policy?
An employment contract may include a general IP assignment clause, but it rarely provides the record-keeping infrastructure required to protect patent rights. Patent rights can be lost through administrative failure: if an invention date cannot be established by competent evidence, a valid patent may be unenforceable. This policy provides both the legal framework (ownership rules, disclosure obligations, assignment requirements) and the practical record system (Invention Notebook standards, corroboration requirements, Invention Disclosure Form) that an IP estate depends on.
Q What is the corroboration requirement?
An invention record must be read, signed, and dated by at least one person who is not a co-inventor of the invention being recorded. The Corroborating Witness confirms they read and understood the record on the date they sign — they do not certify the inventive acts themselves. This requirement exists because an inventor's own testimony alone is insufficient to establish an invention date as a matter of law. The policy requires corroboration within five business days of each notebook entry.
Q Does this policy limit what employees can invent on their own time?
Yes — but within what the law permits. The policy establishes Company ownership of inventions made using Company resources, made within the scope of the employee's duties, or relating to the Company's actual or reasonably anticipated business. It includes an explicit carve-out for inventions outside these criteria — including a specific reference to California Labor Code §2870 and equivalent statutes that limit assignable inventions in other US states. Inventions made entirely on personal time without Company resources and unrelated to the Company's business remain the employee's property.
Q What does the Invention Disclosure Form require?
Six sections: inventor identification, a description of the invention (problem solved, inventive concept, best mode), dates of inventive activity (conception date, reduction to practice, earliest notebook reference), prior disclosure and prior art, Company resources and funding used, and declarations and signatures. The form is designed to capture the information needed for a patent filing decision and to create a contemporaneous record of the disclosure date.
Pay transparency is moving from progressive practice to legal obligation. The EU Pay Transparency Directive must be transposed by June 2026; US state laws are proliferating; Australia has prohibited pay secrecy clauses since 2023. This policy helps organizations stay ahead of the compliance curve.
Eight parts covering: the four transparency principles, salary range disclosure standards (what constitutes a compliant range, prohibition on asking about current salary, multi-jurisdiction disclosure requirements), employee rights to pay information, pay discussion rights, gender pay gap reporting obligations (five-jurisdiction table), pay equity audit (seven-step process), manager conversation scripts, and governance. Statutory requirements appendix covers all five jurisdictions across six dimensions. Designed to work alongside the Compensation Framework & Pay Banding Guide.
FAQS
Q Is pay transparency now legally required?
Increasingly yes. The EU Pay Transparency Directive (2023/970) must be transposed into national law by June 2026 — requiring salary ranges in job postings, employee rights to pay information, and joint pay assessments where a gender pay gap of 5%+ is identified. In the US, Colorado (2021), California (2023), New York State (2023), Washington (2023), Illinois (2025), and other states already require salary ranges in job postings. Australia prohibited pay secrecy clauses from January 2023. British Columbia, Canada, introduced salary range requirements in 2023.
Q Does pay transparency mean publishing everyone's individual salary?
No. Pay transparency means being clear about the salary range for a role (in job postings and to employees who ask), how pay decisions are made, and what the aggregated data shows including gender pay gap analysis. It does not require individual salary disclosure. This policy is built around band transparency — sharing the minimum, midpoint, and maximum for each level — which is the standard adopted by most transparent organizations and what the EU Directive actually requires.
Q Can we prohibit employees from discussing their pay?
No — not in most jurisdictions. In the US, the NLRA makes pay secrecy policies unlawful for non-managerial employees. In Australia, pay secrecy clauses are unenforceable since January 2023. The EU Pay Transparency Directive explicitly prohibits contractual terms requiring workers to keep their pay confidential. In the UK, pay secrecy clauses cannot prevent employees from making pay comparisons under the Equality Act 2010.
Q What are the manager conversation scripts in this policy?
Two detailed scripts: one for sharing the pay band with an employee for the first time, and one for when a salary increase request cannot be granted. Both use specific, honest language giving the employee real information — where they sit in the band, why, and what would need to change — rather than vague reassurances. A 'what managers must never say' callout names three specific phrases that destroy trust in pay conversations.
Most AI policies are either too restrictive to be followed or too vague to be useful. This one is built around practical tools — traffic-light use tables, a named tool register with approval status, and concrete verification standards — so employees can make real decisions about real situations.
Twelve parts covering: scope and definitions (AI tool, approved tool, consumer/public tool, high-risk AI use), the core accountability principle with a Do/Don't behaviour table, approved uses (10 categories), conditional uses (8 categories), prohibited uses (10 categories), data protection and confidentiality (GDPR/UK GDPR, HIPAA, PIPEDA/Law 25, Australian APPs), quality and verification standards by output type, IP and copyright (five-jurisdiction flag), disclosure standards, AI in employment decisions (EU AI Act Annex III high-risk classification, GDPR Article 22, US EEOC guidance, NYC Local Law 144, Australian general protections), the AI tool register with named examples, and governance. Regulatory context flag covers EU AI Act (in force August 2024), UK pro-innovation approach, US state AI legislation, Canada's AIDA, and Australian Voluntary AI Safety Standard.
FAQS
Q Does my business need an AI policy in addition to an Acceptable Use Policy?
If your employees are using AI tools — and they almost certainly are — then yes. A general AUP does not address the specific risks of generative AI: data leakage through public tools, quality and verification obligations, IP ownership of AI-generated outputs, or the EU AI Act's high-risk classification for HR AI systems. The AI Usage Policy provides the specific, practical framework that fills this gap.
Q What is the EU AI Act and does it affect HR?
The EU AI Act (in force August 2024) is the world's first comprehensive AI regulation. Critically for HR: AI systems used for recruitment, CV screening, interview assessment, performance monitoring, and employee evaluation are classified as high-risk under Annex III of the Act. From August 2026, employers using such systems must comply with conformity assessment, transparency, human oversight, and data governance requirements. This is a material compliance obligation for any organization using AI-assisted hiring or performance tools in the EU.
Q What is the traffic-light use table?
The policy includes three colour-coded tables: approved uses (10 categories in green), conditional uses requiring care or approval (8 categories in amber or blue), and prohibited uses (10 categories in red). Each row names a specific use case, the status, and the conditions or notes. An employee can find the answer to a real question — 'can I use this tool for this task?' — in under a minute without reading the whole policy.
Q What data must never be entered into a public AI tool?
Personal data about any individual, clinical or patient data, confidential business information (financial data, product roadmaps, customer lists), intellectual property (source code, algorithms), legal advice or privileged communications, and third-party NDA-protected information. Any of these categories entered into a public AI tool constitutes a confidentiality breach and, where personal data is involved, a potential data protection violation in all five jurisdictions.
Equity is one of the most powerful talent tools available to a startup — and one of the most frequently misunderstood. This policy explains the Company's equity arrangements in language every employee can understand.
Covers: what employees have been granted (options vs shares, the exercise price, vesting, the cliff), monthly vesting post-cliff, what happens on departure (good leaver, bad leaver, retirement), liquidity event scenarios (acquisition, IPO, secondary sale), and a five-jurisdiction tax treatment flag covering UK EMI (no income tax at exercise, CGT at disposal), IE KEEP (CGT only), US ISO/NSO (AMT and ordinary income implications), Canada (employment benefit deduction), and AU ESS start-up concessions.
FAQS
Q What is the difference between an option and a share?
An option gives the holder the right to buy shares at a fixed price in the future — but does not convey ownership until it is exercised. A share is actual ownership. Most startup programs use options rather than shares because they defer ownership (and the associated tax event) until exercise, which typically coincides with a liquidity event when cash to cover any tax is available. This policy explains both instruments in plain language that any employee can understand.
Q What does the four-year vesting schedule with one-year cliff mean?
Four-year vesting: options become exercisable gradually over 4 years. One-year cliff: no options vest in the first year. On the first anniversary of the grant (the cliff), 25% of the total grant vests in one event. After the cliff, the remaining 75% vests monthly over the following 36 months — 1/48th of the total grant per month. An employee who leaves before the cliff receives nothing. This protects the company from granting equity to employees who leave quickly.
Q What happens to options when someone leaves?
Good leavers (resignation in good standing, redundancy, retirement, disability, death) typically retain vested options and have a window (commonly 90 days) to exercise them; unvested options lapse. Bad leavers (dismissed for gross misconduct, breach of restrictive covenants) may lose some or all vested options at the Board's discretion. The policy covers good leaver, bad leaver, and retirement scenarios and directs employees to their grant agreement for the specific terms applicable to them.
Q When is equity taxed?
This varies significantly by jurisdiction and scheme. UK EMI: no income tax at exercise of qualifying options (granted at or above market value); CGT on disposal. Irish KEEP: no income tax, PRSI, or USC at exercise; CGT on disposal. US ISO: no income tax at exercise for qualifying options (AMT may apply); CGT on sale. US NSO: ordinary income tax at exercise. Canada: employment benefit taxed on exercise (with deduction where available). Australia ESS start-up concessions: tax deferred until disposal of shares. Independent tax advice is always recommended before exercising.
No results found
No results match your search. Try removing a few filters.