Organizational, Management, and Control Model (adopted pursuant to Legislative Decree No. 231/2001)
Document approved by the Board of Directors by resolution dated 27 November 2023
Rev.1 – Change of company name – approved by the Board of Directors by resolution dated 20 December 2024.
Rev. 2 - Update - approved by the Board of Directors by resolution dated 04 September 2026
1 INTRODUCTION
HIVE S.r.l. (hereinafter also referred to as “the Company” or “the Entity”) is a company within the Assist Group that specializes in the design and implementation of integrated digital ecosystems, thereby fostering harmony and interconnection among people, businesses, technologies, and services. Specifically, within these ecosystems—created through the use of technology and the development of proprietary software and algorithms—Hive promotes and markets products and services related to domestic and international tourism offerings, catering to both tourism businesses and private individuals. Through its core business operations, the Company aims to provide all types of audiences with integrated solutions and systems tailored to each client; by organizing and managing tourism flows—both domestic and international—it delivers solutions that are coherent and adaptive.
2 PURPOSE OF THE MODEL
Through this document describing the Organization, Management, and Control Model adopted by the Company pursuant to Legislative Decree no. 231 of June 8, 2001 (hereinafter, “Legislative Decree 231/2001” or the “Decree”), the Entity intends to pursue the following objectives:
- to comply with regulations regarding the administrative liability of entities by analysing potential risks of illicit conduct relevant under Legislative Decree 231/2001, and by enhancing and integrating the associated control measures designed to prevent such conduct;
- to increasingly promote and foster an ethical culture based on integrity and transparency in the conduct of its business activities;
- to ensure that all individuals acting on behalf of the Company within the scope of sensitive activities are aware that any violation of the provisions set forth herein may result in disciplinary and/or contractual consequences, as well as criminal and administrative sanctions applicable to them personally;
- to reiterate that such forms of illicit conduct are strongly condemned, as they contravene not only legal provisions but also the ethical principles the Company intends to uphold in the conduct of its business;
- to enable the Company—through the monitoring of high-risk business areas—to intervene promptly to prevent or counter the commission of such offenses and to sanction conduct that violates the law and corporate rules. The Organization, Management, and Control Model (hereinafter also referred to as the “Model”) therefore represents a coherent set of principles, procedures, and provisions that affect the Company’s internal operations and its external interactions, and govern the diligent management of a control system for sensitive activities, aimed at preventing the commission or attempted commission of the offenses referred to in Legislative Decree 231/2001.
The approval of this Model and its constituent elements is the exclusive prerogative and responsibility of the Company’s Board of Directors.
3 RECIPIENTS OF THE MODEL
The rules and provisions contained in this Model apply to, and must be observed by, those who perform - whether formally or in practice - management, administration, executive, or control functions within the Entity; by employees; and by collaborators, consultants, and, generally, all third parties acting on behalf of the Company within the scope of activities identified as "at risk."
The "Recipients" of this Model are therefore:
- holders of formal positions (involving the management, administration, and control of the Entity or one of its organizational units) falling within the definition of "senior management";
- individuals exercising such functions, even without formal designation;
- all personnel of the Entity, regardless of the type of contractual relationship (including interns, fixed-term collaborators, and project-based collaborators);
- freelance professionals formally integrated into the workforce;
- members of the Control Body, where appointed;
- all parties who, despite not belonging to the Company, maintain professional, commercial, and/or financial relationships of any nature with it;
- anyone acting in the name and on behalf of the Entity under its direction and supervision, regardless of the existence of an employment relationship of subordination.
The Company requires external collaborators, consultants, suppliers, freelance professionals, and other contractual counterparties in general to comply with the provisions of the Decree and the ethical principles adopted by the Company; this is achieved through the signing of specific contractual clauses ensuring a commitment to observe the regulations set forth in Legislative Decree 231/2001 and the principles contained in the adopted Code of Ethics.
4 STRUCTURE OF THE MODEL
The structure of the Model consists of:
- the Company’s Code of Ethics, which defines the general ethical values and principles that corporate bodies and their members, as well as the Entity’s employees, collaborators, and consultants, must observe in the conduct of their activities, in order to prevent illicit conduct or behavior inconsistent with corporate standards;
- a document describing the “Organization, Management, and Control Model,” divided into:
i. General Part, which describes the contents of the Decree and provides a summary of the Company’s organization, the methods for identifying risks and analyzing control measures, the appointment and functions of the Supervisory Body, references to the disciplinary system, communication and training activities regarding the Model, and the procedures for updating the Model itself;
ii. Special Part, which describes—for each business process potentially subject to “231 risk”—the relevant types of offenses, illustrative examples of how such offenses might occur, the behavioral principles to be observed, and the control measures to be implemented for risk prevention.
The Catalogue of offenses pursuant to Legislative Decree no. 231/2001 (Annex 1) also constitutes an integral part of this document.
5 CODE OF ETHICS OF HIVE S.R.L.
The Code of Ethics of HIVE S.r.l. constitutes a primary regulatory source within the framework of the Organization, Management, and Control Model pursuant to Legislative Decree 231/2001; therefore, the principles, values, and rules of conduct set forth therein must be considered an integral and essential part of the protocols, standards, and procedures applicable to each of the Entity’s operational areas.
The Code of Ethics applies to the Company’s governing bodies and their members, employees, collaborators, medical staff, consultants, suppliers, and any other party acting in the name of or on behalf of the Entity.
Any failure to comply with the principles and rules of conduct contained in the Code and the Model must be promptly reported to the Supervisory Body and entails the application of applicable disciplinary sanctions, without prejudice to any further civil, criminal, or administrative measures.
6 REGULATORY FRAMEWORK
6.1 The administrative liability regime applicable to legal entities
Legislative Decree no. 231/2001, enacted pursuant to the authority granted to the Government by Article 11 of Law no. 300 of September 29, 2000, governs the “liability of entities for administrative offenses arising from crimes.”
This regime applies to entities possessing legal personality, as well as to companies and associations that do not possess legal personality.
Legislative Decree no. 231/2001 originated from certain international and European Union conventions ratified by Italy, which mandate the establishment of forms of liability for collective entities regarding specific types of offenses.
Under the regime introduced by Legislative Decree no. 231/2001, an Entity (hereinafter also referred to as a “company”) may be held “liable” for certain crimes committed or attempted—in the interest or for the benefit of the company itself—by:
- persons in senior positions—namely, those who perform representative, administrative, or managerial functions for the company or for an organizational unit thereof possessing financial and functional autonomy, as well as those who exercise management and control over the same, including on a de facto basis;
- persons subject to the direction or supervision of persons in senior positions.
As regards the concept of “interest,” this arises whenever the illicit conduct is carried out with the sole intention of securing a benefit for the company, regardless of whether that objective was actually achieved.
Similarly, liability attaches to the company whenever the perpetrator of the offense—even without acting with the aim of benefiting the entity—nevertheless secures an “advantage” for the legal person, whether of an economic nature or otherwise.
The company’s administrative liability is independent of the criminal liability of the natural person who committed the offense and exists alongside it.
6.2 Offense Categories Provided by the Decree
The Decree pertains only to specific types of criminal offenses explicitly referenced by the Decree itself. For ease of presentation, these offense categories can be grouped as follows:
- crimes against the Public Administration (Arts. 24 and 25 of Legislative Decree 231/2001) ;
- cybercrimes and illicit data processing (Art. 24-bis of Legislative Decree 231/2001);
- organized crime offenses (Art. 24-ter of Legislative Decree 231/2001);
- crimes involving the counterfeiting of currency, public credit instruments, revenue stamps, and identification instruments or marks (Art. 25-bis of Legislative Decree 231/2001);
- crimes against industry and commerce (Art. 25-bis.1 of Legislative Decree 231/2001);
- corporate crimes (Art. 25-ter of Legislative Decree 231/2001);
- crimes committed for the purpose of terrorism or subversion of the democratic order (Art. 25-quater of Legislative Decree 231/2001);
- crimes involving female genital mutilation practices (Art. 25-quater.1 of Legislative Decree 231/2001);
- crimes against the individual (Art. 25-quinquies of Legislative Decree 231/2001);
- market abuse offenses (Art. 25-sexies of Legislative Decree 231/2001);
- crimes of manslaughter and serious or very serious negligent bodily harm committed in violation of accident prevention regulations and occupational health and safety laws (Art. 25-septies of Legislative Decree 231/2001);
- transnational crimes (Art. 10 of Law no. 146 of 16 March 2006, on the “ratification and implementation of the United Nations Convention and Protocols against Transnational Organized Crime, adopted by the General Assembly on 15 November 2000 and 31 May 2001”);
- crimes of receiving stolen goods, money laundering, and the use of money, assets, or benefits of illicit origin, as well as self-laundering (Art. 25-octies of Legislative Decree 231/2001);
- crimes involving non-cash payment instruments and the fraudulent transfer of assets (Art. 25-octies.1 of Legislative Decree 231/2001);
- crimes involving the violation of European Union restrictive measures (Art. 25-octies.2 of Legislative Decree 231/2001);
- crimes involving copyright infringement (Art. 25-novies of Legislative Decree 231/2001);
- the crime of “inducing a person not to make statements or to make false statements to the judicial authority” (Art. 25-decies of Legislative Decree 231/2001);
- environmental crimes (Art. 25-undecies of Legislative Decree 231/2001);
- the crime of “employing third-country nationals whose stay is irregular” (Art. 25-duodecies of Legislative Decree 231/2001);
- crimes of racism and xenophobia (Art. 25-terdecies of Legislative Decree 231/2001); - offenses involving fraud in sporting competitions, unauthorized operation of gaming or betting activities, and gambling conducted using prohibited devices (Art. 25-quaterdecies, Legislative Decree 231/2001);
- tax offenses (Art. 25-quinquiesdecies, Legislative Decree 231/2001);
- smuggling offenses (Art. 25-sexiesdecies, Legislative Decree 231/2001);
- offenses against cultural heritage and the landscape (Arts. 25-septiesdecies and 25-duodevicies, Legislative Decree 231/2001);
- crimes against animals (Art. 25-undevicies, Legislative Decree 231/2001).
Please refer to Annex 1 (Catalogue of offences pursuant to Legislative Decree no. 231/2001) of this document for a detailed description of the offences provided for by the Decree and its subsequent amendments and supplements.
6.3 Sanctions provided for by the Decree
Should the Company be held liable under the Decree as a result of the commission or attempted commission of the aforementioned offenses, the following sanctions apply:
- a pecuniary penalty, calculated using a quota-based system; the number and amount of these quotas are determined by the court within statutory limits, taking into account the gravity of the offense, the degree of liability, the entity’s economic and financial standing, and the actions taken to eliminate or mitigate the consequences of the offense and to prevent the commission of further unlawful acts.
However, it should be noted that in specific cases provided for by law, the pecuniary penalty may be determined based on a specific percentage—prescribed for each offense—of the entity’s total global turnover for the financial year preceding the commission of the offense or, if lower, the financial year preceding the imposition of the penalty. Where it is not possible to ascertain the entity’s total global turnover, the pecuniary penalty is applied in the amount established for the specific offense;
- disqualifying sanctions, which in turn may consist of:
▪ disqualification from carrying on business activities;
▪ suspension or revocation of authorizations, licenses, or concessions instrumental to the commission of the offense;
▪ a ban on contracting with public administration bodies;
▪ exclusion from incentives, financing, grants, or subsidies, and the potential revocation of those already granted;
▪ a ban on advertising goods or services;confisca del prezzo o del profitto del reato;
- - publication of the judgment in one or more newspapers.
6.4 Exemption Conditions: Organizational, Management and Control Models
A distinctive feature of Legislative Decree 231/2001 is that it assigns an "exonerating" effect to a company’s organizational, management, and control models.
Indeed, the entity is not held liable for crimes committed in its interest or to its advantage by individuals in senior positions if it proves that:
- the governing body adopted and effectively implemented organizational, management, and control models capable of preventing the crimes covered by the decree;
- the task of supervising the functioning of and compliance with the models, as well as ensuring their updating, was entrusted to a "body" endowed with autonomous powers of initiative and control;
- the individuals committed the crime by fraudulently circumventing the organizational models;
- the crime was committed without any omission or insufficiency of supervision on the part of said body.
Conversely, in the case of a crime committed by individuals subject to the direction or supervision of others, the entity is held liable if the commission of the crime was made possible by a breach of the direction or supervision obligations that the entity is required to observe.
The administrative liability of entities is excluded in any event—pursuant to an express statutory provision (Art. 5, paragraph 2, of Legislative Decree 231/2001)—if senior management and/or their subordinates acted in their own exclusive interest or in the exclusive interest of third parties.
7 ORGANIZATION OF THE COMPANY
7.1 Organizational Structure of the Entity
HIVE S.r.l., registered in the ordinary section of the Register of Companies, is part of the Assist Group; 95% of its share capital is held by the parent company, Assist Group S.r.l.
HIVE S.r.l. (hereinafter also referred to as “the Company” or “the Entity”) is an Assist Group company specializing in the design and implementation of integrated digital ecosystems, thereby fostering harmony and interconnection among people, businesses, technologies, and services. Specifically, within these ecosystems—created through the use of technology and the development of proprietary software and algorithms—Hive promotes and markets products and services related to domestic and international tourism offerings, catering to both tourism businesses and private individuals. Through its core business operations, the Company aims to provide all types of audiences with integrated systems and solutions tailored to each client; it delivers coherent, adaptive solutions by organizing and managing flows related to domestic and international tourism.
The recipients of the Company’s services are entities operating within the domestic tourism sector. These include public bodies and institutions (Ministries, Regions, Provinces, Municipalities, associations, tourism promotion agencies, etc.) as well as private individuals and/or legal entities.
Under a service agreement entered into with its parent company, Assist Group S.r.l., HIVE S.r.l. relies on the latter for support and assistance regarding legal and corporate services.
Furthermore, under service agreements entered into with VIDIERRE S.r.l.—another company within the Group—the Company also relies on the latter for support and assistance regarding IT services.
Finally, Hive S.r.l. Under contracts entered into with Assist Future S.r.l.—also a member of the Group—the Company avails itself of the latter’s assistance and consultancy services, including operational support, for the conception and implementation of strategic communication plans.
The corporate structure features a Board of Directors, from among whose members a Chairman has been elected.
The Company is represented by the Chairman of the Board of Directors and by the Vice Chairman—who has been appointed Chief Executive Officer—within the limits of the powers delegated to them.
7.2 Governance and Internal Control Tools of the Entity
The main governance and internal control mechanisms adopted by the Entity can be summarized as follows:
- the Company’s Articles of Association, which, in compliance with applicable laws, contain various provisions regarding corporate governance designed to ensure the proper conduct of management activities;
- the corporate organizational chart, representing the Entity’s organizational structure;
- powers of attorney granted by the Board of Directors and/or via notarial deed;
- internal organizational documentation;
- the Code of Ethics, which sets out the guidelines and ethical and professional conduct principles adopted by the Entity, requiring compliance from all parties involved in its activities.
Furthermore, this document defines the behavioral guidelines and principles aimed at preventing the offenses referred to in Legislative Decree 231/2001; it must therefore be considered an integral part of this Model and a fundamental tool for achieving the Model’s objectives.
7.3 Development of the Organization, Management and Control Model
The process of developing the Model was carried out through the project phases described below.
1. Identification of the activities and processes where conditions, opportunities, and/or means for committing the offenses covered by the Decree could potentially arise (“sensitive activities”), as well as the corporate areas/functions involved in carrying out such activities.
2. Analysis of sensitive activities and processes, identifying existing organizational and control mechanisms or those requiring adjustment. The control system is examined by considering the following standard preventive safeguards:
- existence of a system of powers and authorization levels consistent with assigned organizational responsibilities and relevant regulatory provisions;
- adherence to the principle of segregation of duties;
- existence of formalized rules (e.g., policies and procedures);
- existence of adequate specific control mechanisms;
- traceability of activities and controls;
with the aim of assessing their ability to prevent or detect risk situations relevant to the Decree.
3. Identification of necessary improvement actions (Gap Analysis) in the event of any deficiencies in the Internal Control System.
4. Preparation of the Organization, Management, and Control Model pursuant to Legislative Decree 231/2001, structured in compliance with the guidelines issued by Confindustria and based on the findings of the risk area mapping exercise.
7.4 Mapping of Risk Areas
The “sensitive activities” identified during the Model development process are as follows:
1. Personnel selection, hiring, and management
2. Administrative personnel management
3. Management of incentive systems, staff development, and performance evaluation
4. Management of training activities
5. Management of benefits and company-provided equipment
6. Management of relations with trade unions
7. Management of employee gifts
Special Part Reference A – Human Resources Management
8. Management of the procurement of goods, services, and consultancy
Special Part Reference B – Supply management
9. Management of relations with public authorities (including during inspection visits)
10. Management of public or subsidized funding
Special Part Reference C – Management of Relations with the Public Administration
11. Bookkeeping and preparation of financial statements
12. Tax management
13. Management of relations with shareholders and control bodies
14. Management of intercompany relations (including service contract arrangements with Group companies)
15. Legal and corporate affairs management
16. Cash flow and financial management
17. Management of expense claims and representation expenses
Special Part Reference D – Administration, Finance, and Control
18. Management of information systems
Special Part Reference E – Information Systems Management
19. Management of communications and marketing
20. Management of events/trade fairs and sponsorships
21. Management of gifts and giveaways
Special Part Reference F – Marketing, Events, and Sponsorships
22. Management of sales activities (including participation in public tenders)
Special Part Reference G – Commercial businesses
23. Management of occupational health and safety obligations
24. Management of environmental compliance obligations
Special Part Reference H – Management of occupational health and safety and environmental compliance obligations
Some of the sensitive activities identified above in the “Special Sections” may be carried out by corporate functions belonging to other Group companies, pursuant to intercompany agreements.
In the performance of these intercompany arrangements, the service-providing company must:
- adhere to the ethical and behavioural principles defined uniformly at the Group level and adopted by each Group company through the implementation of the Code of Ethics;
- in accordance with the provisions of said Code of Ethics, apply an internal control system designed to prevent the commission of offenses covered by the Decree;
- commit to complying with the Company’s Model (with particular regard to the behavioural and control principles applicable to the sensitive activity performed on the Company’s behalf).
7.5 Updating the Model
The Board of Directors resolves on the updating and adjustment of the Model in response to changes and/or additions that may become necessary due to, for example:
- significant changes in the Entity’s organizational structure or operations;
- significant violations of the Model, findings from reviews of its effectiveness, or publicly known experiences within the sector;
- specific events (e.g., legislative changes, requests from the Board of Directors, etc.) requiring the extension of the Model’s scope to new risk categories.
The Model shall undergo a periodic review process conducted by the Board of Directors and the Supervisory Body to ensure the dynamic continuity of its functions in light of evolving needs.
In any event, any occurrences necessitating a modification or update of the Model must be reported in writing by the Supervisory Body to the Board of Directors, so that the latter may adopt the relevant resolutions.
Modifications to corporate policies and procedures required for the implementation of the Model are carried out by the Entity’s relevant departments. The Supervisory Body is kept constantly informed regarding the updating and implementation of new operating procedures and has the right to express its opinion on proposed modifications.
8 SUPERVISORY BODY
Entrusting the tasks of monitoring the functioning and observance of the Model—as well as ensuring its updating—to a body within the Entity endowed with autonomous powers of initiative and control, together with the proper and effective performance of such tasks, constitutes an essential prerequisite for exemption from the liability provided for by Legislative Decree 231/2001.
The key requirements for the Supervisory Body (hereinafter also referred to as the "Supervisory Body")—as proposed in the Guidelines issued by Confindustria and endorsed by the courts in various published rulings—can be identified as follows:
- autonomy and independence;
- professional expertise;
- continuity of action.
The autonomy and independence of the Supervisory Body entail the freedom to initiate monitoring activities without any form of interference or influence from any representative of the legal entity—and, in particular, from the administrative body.
The requirement of professional expertise translates into the Supervisory Body’s technical capacity to perform its functions regarding the monitoring of the Model, as well as the qualities necessary to ensure the Model remains dynamic by submitting proposals for updates to senior management.
Finally, regarding continuity of action, the Supervisory Body must constantly monitor compliance with the Model, verify its actual operation and effectiveness, promote its continuous updating, and serve as a constant point of contact for anyone performing work for the Company.
Legislative Decree 231/2001 does not provide specific guidelines regarding the composition of the Supervisory Body. In the absence of such guidelines, the Company has opted for a solution that—taking into account the objectives pursued by the law and the principles derived from published case law—ensures the effectiveness of the controls overseen by the Supervisory Body, commensurate with the Company’s size and organizational complexity.
The Company has opted for a single-member Supervisory Body; this decision was approved by the Board of Directors at the same time the Model was adopted.
8.1 Establishment and appointment of the Supervisory Body
The Company’s Supervisory Body is established by a resolution of the Board of Directors. The Supervisory Body holds office for a term of three years and is eligible for re-election.
The Supervisory Body’s term of office expires at the end of the period established upon its appointment; however, it continues to perform its functions on an interim basis until a new Supervisory Body is appointed, which must take place at the earliest possible meeting of the Board of Directors.
If the Supervisory Body ceases to hold office during its term, the Board of Directors shall appoint a replacement by means of a resolution.
The remuneration of the Supervisory Body is determined by the Board of Directors.
Appointment to the Supervisory Body is conditional upon meeting the requisite eligibility criteria.
In particular, upon appointment, the party designated to serve as the Supervisory Body must provide a declaration attesting to the absence of grounds for ineligibility, such as—by way of example:
- conflicts of interest—including potential ones—with the Company that would compromise the independence required for the role and duties of the Supervisory Body. Examples of conflicts of interest include:
▪ maintaining significant business relationships with the Company, its parent company, or companies controlled by or affiliated with it (excluding an employment relationship);
▪ maintaining significant business relationships with the Chairman or with directors holding delegated powers (executive directors);
▪ having a relationship with, or being a member of the immediate family of, the Chairman or executive directors (with "immediate family" defined as a spouse from whom one is not legally separated, and relatives and in-laws up to the third degree);
▪ holding a direct (or indirect) equity interest in the Company of such magnitude as to allow for the exercise of significant influence over the Company;
- having held administrative roles—during the three financial years prior to the appointment as the Supervisory Body or the establishment of a consultancy/collaboration relationship with said Body—in enterprises subject to bankruptcy, compulsory administrative liquidation, or other insolvency proceedings;
- being subject to a temporary ban or suspension from holding public office or from holding executive positions in legal entities and enterprises;
- being subject to any of the grounds for ineligibility or disqualification set forth in Article 2382 of the Civil Code;
- being subject to preventive measures pursuant to Law no. 1423 of December 27, 1956, or Law no. 575 of May 31, 1965 (and subsequent amendments and additions), without prejudice to the effects of rehabilitation;
- conviction, in Italy or abroad, even if the judgment has not yet become final and even if the sentence is conditionally suspended, or a judgment applying a penalty upon the request of the parties pursuant to Art. 444 of the Code of Criminal Procedure (the so-called “plea bargain”), without prejudice to the effects of rehabilitation, for the offenses referred to in Legislative Decree 231/2001 or offenses otherwise affecting professional integrity;
- conviction—even if the judgment has not yet become final, even if the sentence is conditionally suspended, or resulting from a judgment applying a penalty upon the parties' request pursuant to Art. 444 of the Code of Criminal Procedure (plea bargain), subject to the effects of rehabilitation—to:
▪ a custodial sentence of not less than one year for one of the offenses provided for by Royal Decree no. 267 of March 16, 1942;
▪ a custodial sentence of not less than one year for one of the crimes provided for by regulations governing banking, financial, securities, and insurance activities, or by regulations concerning markets, securities, and payment instruments;
▪ a custodial sentence of not less than one year for a crime against the Public Administration, public faith, property, or the public economy, or for a tax-related offense;
▪ a term of imprisonment of not less than one year for any intentional crime;
▪ a penalty for one of the crimes provided for in Title XI of Book V of the Civil Code, as reformulated by Legislative Decree no. 61/2002.
Should any of the aforementioned grounds for ineligibility arise regarding an appointed individual, that person shall automatically forfeit their office.
Where Company employees serve as members of the Supervisory Body, the termination of their employment relationship entails the forfeiture of that office.
In carrying out its assigned duties, the Supervisory Body may—under its direct supervision and responsibility—draw upon the collaboration of all Company or Group functions and units, or external consultants, leveraging their respective expertise and professional skills. This authority enables the Supervisory Body to ensure a high level of professionalism and the necessary continuity of action.
To this end, the Board of Directors may allocate a budget to the Supervisory Body, taking into account requests submitted formally by the latter to the Board.
The budget allocation enables the Supervisory Body to operate autonomously and with the appropriate resources to effectively perform the duties assigned to it under this Model, in accordance with Legislative Decree no. 231/2001. If necessary, the Supervisory Body may request that the Board of Directors authorize additional funds, provided that an appropriate subsequent accounting of such expenditure is submitted.
To ensure the necessary stability for the Supervisory Body, the revocation of its powers and the reassignment of such powers to another party may occur only for just cause—including reasons related to the Company’s organizational restructuring—by means of a specific resolution of the Board of Directors.
In this regard, "just cause" for the revocation of the powers associated with the role of Supervisory Body may be understood to include, by way of example only:
- a final conviction of the Company pursuant to the Decree, or a plea-bargain judgment that has become final, where the records reveal "failure to supervise or insufficient supervision" on the part of the Supervisory Body, as provided for in Art. 6, paragraph 1, letter d) of the Decree;
- a conviction or plea-bargain judgment issued against the Supervisory Body for having committed any of the crimes or administrative offenses provided for by the Decree (or crimes/administrative offenses of a similar nature);
- violation of the confidentiality obligations binding upon the Supervisory Body;
- failure to attend more than two consecutive meetings without a valid reason;
- gross negligence in the performance of its duties, such as, for example, failure to prepare the semi-annual report to the Board of Directors regarding the activities performed;
- the assignment of operational functions and responsibilities within the corporate organization that are incompatible with the requirements of "autonomy and independence" and "continuity of action" inherent to the Supervisory Body.
In cases of particular gravity, the Board of Directors may, in any event, order the suspension of the Supervisory Body’s powers and the appointment of an interim Supervisory Body.
8.2 Functions and Powers of the Supervisory Body
The Supervisory Body is granted the powers of initiative and control necessary to ensure effective and efficient oversight of the functioning of and compliance with the Model, in accordance with Article 6 of Legislative Decree 231/2001.
In particular, the Supervisory Body is required to monitor:
- the actual adequacy and effectiveness of the Model in preventing the commission of the offenses to which Legislative Decree 231/2001 applies, taking into account the Company’s size and its organizational and operational complexity;
- the continued adequacy and effectiveness of the Model over time;
- compliance with the Model’s provisions by the Recipients, identifying any violations and proposing appropriate corrective and/or disciplinary measures to the competent corporate bodies;
- the updating of the Model whenever adjustments are required due to changes in corporate or regulatory conditions, proposing such adjustments to the competent corporate bodies and verifying their implementation.
To carry out and exercise its functions, the Supervisory Body is assigned the following tasks and powers:
- to access all Company facilities and all corporate documentation relevant to verifying the adequacy of and compliance with the Model;
- to conduct periodic, targeted spot checks on specific high-risk activities/operations and on compliance with the control and conduct safeguards adopted and referenced in the Model and corporate procedures;
- to promote the updating of the risk mapping in the event of significant organizational changes or an expansion of the types of offenses covered by Legislative Decree 231/2001; - coordinate with the relevant corporate functions to assess the adequacy of the adopted internal regulatory framework and define proposals for adjustment and improvement (internal rules, procedures, operational and control methods), subsequently verifying their implementation;
monitor information and training initiatives aimed at disseminating knowledge and understanding of the Model within the company;
- request information deemed relevant for verifying the adequacy and effectiveness of the Model from company managers, particularly those operating in areas with potential crime risk;
- collect reports from any Recipient of the Model regarding: i) potential issues with the measures provided for by the Model; ii) violations thereof; iii) any situation that might expose the Entity to the risk of a crime;
- periodically report to the Director and the relevant functions any violations of the control measures set out in the Model and/or company procedures, or any deficiencies identified during audits, so that they may implement the necessary corrective actions, involving the Board of Directors where required;
- monitor the consistent application of sanctions provided for by internal regulations in cases of violations of the Model, without prejudice to the authority of the management body to impose such sanctions;
- identify any behavioral deviations that may emerge from the analysis of information flows and reports submitted by the Model’s Recipients.
Training activities regarding Decree 231 and the contents of the adopted Organizational Model are promoted and supervised by the Company’s Supervisory Body, which may avail itself of the operational support of relevant company functions or external consultants.
The Supervisory Body requests an annual budget for its exclusive use in carrying out its activities.
The Supervisory Body is bound by confidentiality obligations regarding all information acquired in the course of performing its duties.
Such information may be disclosed only to the parties and in the manner prescribed by this Model.
8.3 Reporting obligations to the Supervisory Body
To carry out its duties of monitoring the effectiveness of the Model and assessing its adequacy, the Supervisory Body must be promptly informed by the Model’s Addressees of any events that could give rise to the Company’s liability under Legislative Decree 231/2001; it must also receive further information useful for evaluating the actual implementation and dissemination of the Model itself.
Indeed, pursuant to Art. 6 of Legislative Decree 231/2001, the Model must provide for “information obligations towards the body responsible for supervising the functioning of and compliance with the models” (para. 2, letter d). Accordingly, information flows to the Supervisory Body may be “ad hoc/event-based” or “periodic.”
With specific reference to the so-called “periodic information flows,” each function within the Entity is required to communicate the following information to the Supervisory Body on an annual basis:
- measures and/or information originating from judicial police bodies or any other authority indicating the conduct of investigations or criminal proceedings—including those against unknown persons—concerning matters of interest and/or matters that may involve the Entity (whether or not related to Legislative Decree 231/2001);
- measures and/or information regarding the existence of significant administrative or civil proceedings arising from requests or initiatives by public authorities;
- any legal document or summons to testify involving individuals belonging to the Entity or collaborating with it;
- requests for legal assistance submitted by employees upon the initiation of criminal or civil proceedings against them (not limited to offenses covered by Legislative Decree 231/2001); - information regarding any inspection visits conducted by public administration officials and reported by all company areas/functions;
- details concerning disciplinary proceedings conducted and any sanctions imposed, or the dismissal of such proceedings, including the relevant grounds;
- communications regarding organizational and corporate changes;
- anomalies or critical issues encountered by those responsible during the performance of activities deemed sensitive for the purposes of Legislative Decree 231/2001.
Furthermore, the aforementioned Entity Functions—as the parties responsible for the full and correct adoption of corporate rules designed to mitigate risks identified within their respective areas of competence—are required to periodically transmit to the Supervisory Body the data and information necessary for the latter to carry out its monitoring functions.
Finally, all Recipients of this Model are required to promptly report the following information to the Supervisory Body (so-called “ad hoc/event-based reporting”):
- the commission, attempted commission, or reasonable risk of commission of the offenses set forth in the Decree;
- any alleged violations of the behavioural and operational guidelines defined in the Code of Ethics, the Model, and/or the company’s regulatory and procedural framework, of which they have become aware, either directly or indirectly;
- in any event, any act, fact, event, or omission detected or observed during the performance of assigned responsibilities and tasks that presents a potential issue regarding compliance with the provisions of the Decree.
The general and specific information described above must be sent to the Supervisory Body in writing via the dedicated email address: odv@hivenetwork.it.
All information or reports provided for herein are stored by the Supervisory Body in a dedicated, confidential archive (whether electronic or paper-based).
8.4 Reporting by the Supervisory Body to other corporate bodies
To ensure its full autonomy and independence in the performance of its duties, the Supervisory Body reports directly to the Entity’s Board of Directors.
In particular, the Supervisory Body prepares and submits the following to the Board of Directors:
- an annual report on the activities performed;
- a notification regarding matters within its remit whenever confirmed violations of the Model occur that involve the alleged commission of offenses.
The Supervisory Body also has the right to request a hearing with the Board of Directors should it deem it necessary.
Likewise, the Board of Directors has the right to summon the Supervisory Body whenever it deems it appropriate.
The annual report addresses the following aspects:
- checks and verifications carried out by the Supervisory Body and their outcomes;
- any critical issues that have emerged;
- the implementation status of any corrective or improvement measures regarding the Model;
- any legislative changes or organizational modifications requiring updates to risk identification or amendments to the Model;
- any disciplinary sanctions imposed by the competent bodies following violations of the Model;
- any reports received from internal and external parties during the period regarding alleged violations of the Model or the Code of Conduct;
- the activity plan for the following six-month period;
- other information deemed significant.
The Supervisory Body may initiate coordination meetings with various corporate bodies, including the Control Body.
Meetings with the corporate bodies to which the Supervisory Body reports must be documented.
The Supervisory Body is responsible for archiving the relevant documentation.
8.5 Reporting of unlawful conduct (so-called whistleblowing)
In accordance with Art. 6, paragraph 2-bis, of Legislative Decree 231/2001—as amended by Legislative Decree 24/2023, which implements EU Directive 2019/1937—the Model provides for the establishment of an internal channel enabling employees, consultants, collaborators, and any other party interacting with the Company to report irregularities of which they become aware in the course of their duties. It also establishes a prohibition against discriminatory acts and a disciplinary system designed to sanction non-compliance with the provisions of the Model itself.
Therefore, in compliance with Legislative Decree 24/2023 and Legislative Decree 231/2001, the Company has implemented a system allowing its personnel and all third parties acting on its behalf to submit reports—in the interest of the public or the integrity of the entity—regarding violations or suspected violations of the Code of Ethics and the Model, as well as illicit conduct relevant under Legislative Decree 231/2001. Such reports must be submitted in accordance with the requirements and channels set out in the "Whistleblowing Procedure," ensuring that they are substantiated and based on precise, consistent factual elements.
To this end, the Company has established an internal reporting channel via a dedicated IT platform. This platform enables the whistleblower to submit a report while guaranteeing the confidentiality of the whistleblower’s identity, the identities of the individuals involved or mentioned in the report, and the content of the report and related documentation. The management of reports is entrusted to the Supervisory Body, which is responsible for verifying their validity and conducting the necessary analysis and in-depth review of the reports received.
Reports received by other corporate functions or the Company’s control bodies must be forwarded without delay to the Supervisory Body via the designated channels, in order to safeguard the confidentiality and reputation of the individuals named in the reports and to ensure the effectiveness of the investigations.
Upon receipt of a report, the Supervisory Body issues an acknowledgment to the reporting party and conducts an initial preliminary analysis. If information emerges—or can reasonably be inferred—that is useful and sufficient to assess the validity of the report, the Supervisory Body initiates the subsequent investigative phase. Conversely, if the assessment yields no grounds for further action, the Supervisory Body closes the file, providing the relevant reasons and informing the reporting party of the outcome.
During the investigation, the Supervisory Body may avail itself of the support of relevant corporate functions and, where necessary, external consultants; it may also request additional information from the whistleblower and gather information from the parties involved in the report, while respecting rights of defense and applicable personal data protection regulations.
If, following the investigation, the report is found to be substantiated, the Supervisory Body identifies the provisions alleged to have been violated and provides its assessment regarding the established evidence, the nature of the violation, and its severity in relation to the principles and provisions of the "Model 231" and the Code of Ethics.
The Supervisory Body acts to protect whistleblowers against any form of retaliation, discrimination, penalization, or any consequence arising from the disclosure of the report itself, while also ensuring the confidentiality of their identity (subject to legal obligations) and the confidentiality of the reported party. The personal data of the whistleblower, the reported party, and all individuals involved in the report are processed in compliance with applicable personal data protection regulations, specifically Regulation (EU) 2016/679 ("GDPR") and Legislative Decree no. 196/2003.
These protections apply not only to the Company’s employees but also to all parties involved in the proceedings in any capacity (e.g., self-employed workers, consultants, suppliers, interns, volunteers, etc.), as well as to so-called "facilitators" (i.e., individuals who may have assisted the whistleblower during the process of reporting the misconduct within the work context), third parties connected to the whistleblower (e.g., colleagues and family members), and entities owned by the whistleblower. Finally, conduct subject to sanctions—in accordance with the provisions of the Disciplinary and Sanctioning System (see Chapter 9)—includes both the violation of measures established by the Company to protect the whistleblower and related parties, and the submission, with willful intent or gross negligence, of reports that prove to be unfounded.
9 DISCIPLINARY AND SANCTION SYSTEM
9.1 Purpose of the System
Establishing a system of sanctions applicable in the event of a violation of the provisions of this Model is a necessary condition for ensuring the effective implementation of the Model itself, as well as an essential prerequisite for the Company to benefit from the exemption from administrative liability.
The application of disciplinary sanctions is independent of the outcome of any criminal proceedings, as the rules of conduct and internal procedures are binding on both Senior Management and Subordinate Personnel, regardless of whether the conduct in question actually results in the commission of a crime.
The Company’s exercise of its disciplinary authority must adhere to the following principles:
- proportionality: the sanction must be commensurate with the severity of the alleged violation;
- due process (right to be heard): ensuring the involvement of the individual concerned and providing them with the opportunity to present justifications in defense of their conduct.
Violations of the rules and requirements set forth in the Model—including the rules of conduct contained in the Code of Ethics—are assessed for the purpose of applying disciplinary sanctions; such sanctions are to be implemented in accordance with applicable laws and the relevant provisions of the Collective Bargaining Agreements governing the specific category of personnel involved.
It is further noted that the Disciplinary and Sanctioning System of this Model also applies in cases involving violations of the protective measures for whistleblowers and their associates, and against individuals who submit unfounded reports with willful intent or gross negligence, as well as, more generally, in cases of non-compliance with the whistleblowing provisions set forth in Legislative Decree no. 24/2023 of 10 March 2023, entitled “Implementation of EU Directive No. 2019/1937 on the protection of persons who report breaches of Union law and containing provisions regarding the protection of persons who report breaches of national legal provisions,” and the Company’s Whistleblowing Procedure.
9.2 General criteria for the imposition of sanctions
The sanctioning system varies based on:
- the category of recipients pursuant to Art. 2095 of the Civil Code, as well as the nature—whether independent or quasi-subordinate—of the relationship between the person committing the violation and the Company;
- the severity of the violation and the role and responsibility of the person committing it, taking into account the following general criteria:
▪ the subjective element of the conduct (willful intent or negligence—the latter involving imprudence, carelessness, or lack of professional skill, also considering the foreseeability of the event);
▪ the significance of the obligations violated;
▪ the severity of the risk exposure caused;
▪ the extent of any damage caused to the Company resulting from the application of sanctions provided for by the Decree and subsequent amendments and additions;
▪ the functional position and level of responsibility and autonomy of the individuals involved in the events constituting the infringement;
▪ the presence of aggravating or mitigating circumstances;
▪ any history of repeat offenses;
▪ any shared responsibility with other parties who contributed to the infringement.
Therefore, regarding the Recipients, in the event of a confirmed infringement, the Company—based on the corporate position held by the individual responsible for the relevant act or omission—shall:
- apply to its employees the disciplinary sanctions set forth in paragraphs 9.3 and 9.4, in compliance with legal provisions, the applicable National Collective Labour Agreement (CCNL), and the Code of Ethics;
- take measures against members of the Board of Directors deemed most appropriate given the severity of the infringements committed, as further specified below in paragraph 9.5.
Furthermore, the Company shall adopt measures regarding third parties as further specified in paragraph 9.6.
The aforementioned measures are adopted pursuant to law and/or contract, in accordance with the framework set out in this Model 231.
9.3 Sanctions against employees (non-executives)
The specific rules of conduct set forth in this Model constitute "instructions regarding the execution and regulation of work issued by the employer" which, pursuant to Article 2104 of the Civil Code, every employee is required to observe; failure by the employee to comply with the Model therefore constitutes a breach of contract, for which the employer may impose the disciplinary sanctions provided for by law and by the applicable Collective Bargaining Agreement.
Should a violation of the Model attributable to the Employee be established, and taking into account the provisions of Art. 7 of Law 300/1970 and the relevant Collective Bargaining Agreement
, the following disciplinary measures may be applied:
- Verbal warning;
- Written warning;
- Fine not exceeding the equivalent of three hours' pay;
- Suspension from work and pay for a period not exceeding 10 actual working days;
- Individual dismissal.
The procedure for formally notifying the employee of the charges shall be initiated promptly, no later than 10 days after the employer becomes aware of the facts and/or breaches relevant for disciplinary purposes.
No disciplinary measure may be imposed until five days have elapsed following the formal notification of charges; during this period, the employee may submit a written defense and justification or request a hearing to present their defense, potentially with the assistance of a representative from the trade union to which they belong or have authorized to act on their behalf. The imposition of the measure shall be communicated in writing.
An employee wishing to challenge an imposed disciplinary measure may avail themselves of the conciliation procedures set forth in Art. 7 of Law 300/1970 or those provided for in the relevant Collective Bargaining Agreement.
Sanctions are imposed in accordance with the authority assigned within the Company. Every act relating to the disciplinary proceeding must be communicated to the Supervisory Body for the assessments and monitoring falling within its remit.
9.4 Sanctions against Executives
In the event of a confirmed failure by an Executive to comply with the provisions of the Model, or if it is proven that an Executive permitted subordinates to engage in conduct constituting a violation of the Model, the Company will assess the most appropriate measures—taking into account the severity of the Executive's conduct, the applicable collective bargaining agreement, and relevant legal provisions—including termination of the employment relationship.
9.5 Sanctions against Directors
In the event that conduct sanctionable under the Model is committed by one or more members of the Board of Directors, the Supervisory Body shall promptly inform the entire Board of Directors so that it—excluding the director involved—may take and/or initiate the most appropriate and suitable measures, commensurate with the severity of the detected violation and in accordance with the powers provided for by applicable regulations and the Company’s Articles of Association.
Any member(s) of the Company’s Board of Directors alleged to have committed the violation shall have the right to promptly present their defense before the aforementioned measures are imposed .
9.6 Sanctions against third parties
Any conduct by third parties maintaining contractual relationships with the Company (e.g., suppliers, consultants, collaborators, etc.) that contravenes Legislative Decree 231/2001, the ethical principles adopted by the Company, or—for those acting in the name and on behalf of the Company—the provisions of this Model (to the extent applicable given the activities performed under the mandate received from the Company) and any specific procedures and/or requirements applicable to them, shall be subject to sanctions as stipulated in the specific clauses included in the relevant contracts or letters of engagement.
Such conduct may be deemed a breach of contractual obligations and may result in the termination of the contract by the Company.
10 COMMUNICATION AND TRAINING
The Company promotes the widest possible dissemination and understanding of the Model and encourages compliance with it through publications, communications, training activities, and any other means deemed suitable for this purpose, including through annual training plans tailored to the roles and responsibilities of the various recipients.
Training initiatives are generally organized and managed by the relevant internal departments. The training programs and the content of the information materials prepared by said departments are shared with the Supervisory Body.