Anti-corruption framework

The Group operates an anti-corruption framework aligned with ISO 37001 principles. The policy applies to all employees, contractors, consultants, agents, distributors, resellers, and joint venture partners. Gifts and hospitality are subject to a written threshold; political donations are prohibited; facilitation payments are prohibited.

Public-sector tenders are responded to under specific compliance protocols. Conflicts of interest are declared in writing under a quarterly compliance affirmation by senior staff.

Anti-corruption policy

Whistleblowing

ERAM operates an independent confidential whistleblowing channel for employees, contractors, suppliers, customers, and third parties. The channel accepts reports in Albanian, Serbian, and English. Investigations are conducted under a documented procedure with retaliation expressly prohibited and contractually enforceable.

The channel is consistent with the EU Whistleblower Directive (EU 2019/1937) and is being aligned with Kosovo Law 06/L-085 on the Protection of Whistleblowers as transposed.

Whistleblowing policy

Data protection

ERAM processes personal data under the General Data Protection Regulation (Regulation EU 2016/679 — GDPR) and Kosovo Law 06/L-082 on Personal Data Protection. A Data Protection Officer is designated and reachable directly via the address published on the data protection page. Data-subject rights requests (access, rectification, erasure, portability, restriction, objection) are handled under a documented procedure.

Data protection policy

Financial integrity

ERAM Group is subject to an annual independent financial audit by a recognised audit firm. The audited financial statements are filed with the Kosovo Business Registration Agency under company-law disclosure requirements and are available to banking partners under standard non-disclosure terms.

Governance

The Board comprises the founder-CEO, non-executive directors, and an independent chair. The Audit and Risk Committee meets quarterly. Quarterly compliance affirmations are submitted by senior staff. Material changes to the Group's risk profile are reported to the Board within five working days.