Introduction and Purpose
Welcome to the MinIO Supplier Code of Conduct! At MinIO, Inc. (collectively, with its affiliates “MinIO”, “we”, or “our”) we believe that great partnerships are built on trust, transparency, and shared values. We're a global company with a start-up heart, and we see our suppliers as an extension of our team, helping us deliver secure, innovative, and reliable solutions to our customers around the world.
This Supplier Code of Conduct (“Code”) sets out the standards we expect from all our suppliers, vendors, contractors, business partners and other third-party partners along with their employees, personnel, agents, and subcontractors (collectively, "Supplier(s)", “you” or “your”). It's designed to foster ethical, compliant, and responsible relationships, ensuring that together we uphold MinIO's culture of integrity, respect, and accountability. The Code applies to all aspects of Suppliers work with MinIO, wherever Supplier operates or conducts business with or on behalf of MinIO. We expect our Suppliers to share our commitment to doing the right thing, always. In all cases in which MinIO requirements are different from local legal requirements, Suppliers are required to meet the more stringent requirement.
If Supplier has questions or needs guidance, reach out to Compliance (compliance@minio.io) or Legal (legal@minio.io). We're here to support our Suppliers.
Our Values and Expectations
At MinIO, our values aren't just words, they're how we show up for each other and our partners every day. We expect our Suppliers to embrace and reflect these principles in all interactions with MinIO, its teams, and the wider community. In helping MinIO maintain our values, Supplier agrees to the following:
- Integrity: Do the right thing, even when it's hard. Be honest, keep your commitments, and act ethically in all business dealings.
- Respect: Treat everyone with dignity and kindness. We celebrate diversity and expect inclusive, fair treatment for all.
- Transparency: Communicate openly and honestly. Share information, flag concerns early, and avoid hidden agendas.
- Collaboration: Work together to solve problems, share ideas, and support each other's success. We're one team, moving forward.
- Accountability: Take responsibility for its actions and decisions. If something goes wrong, own it, fix it, and learn from it.
- Social Responsibility: Support human rights, fair labor, and environmental sustainability. Give back to itsour communities and help us build a better world.
We trust our Suppliers to use good judgment and uphold these values in every aspect of your work with MinIO.
Legal and Regulatory Compliance
We play on a global stage, and compliance is non-negotiable. Suppliers must comply with all applicable local laws, national and international laws, treaties, regulations, and international standards wherever operate, including, but not limited to:
- Anti-Corruption & Anti-Bribery: Never offer, give, solicit, or accept bribes or improper payments, directly or indirectly. This includes facilitation payments, kickbacks, or anything of value intended to influence business decisions.
- Export Controls & Sanctions: Follow all export, import, and economic sanctions laws. Do not engage with restricted parties or in prohibited transactions.
- Fair Competition: Compete honestly and avoid anti-competitive practices such as price-fixing, bid-rigging, or market allocation.
- Data Privacy & Security: Protect personal and confidential information in line with MinIO's Data Protection Policy, Information Security and Confidentiality Policy, and all relevant privacy laws.
- Labor & Employment: Adhere to all labor, wage, and working condition laws, and respect the rights of workers.
- Environmental Laws: Comply with all applicable environmental regulations and support MinIO's sustainability goals.
- Compliance Programs: Suppliers should establish robust compliance programs that include policies, procedures, training, and internal controls to support legal compliance. Regular monitoring and evaluation of compliance status are essential to ensure ongoing adherence to legal requirements.
- Cooperation: Suppliers must cooperate fully with regulatory authorities and any inquiry or audit authorized by MinIO by providing all necessary or requested documentation and access.
If Supplier becomes aware of any actual or suspected violation of law or this Code, report it promptly to MinIO Compliance or Legal. We encourage proactive communication, better to ask and clarify than risk a compliance issue. Retaliation for raising concerns in good faith is strictly prohibited.
By working together and holding ourselves to these standards, we protect our people, our customers, and our shared reputation.
Human Rights and Labor Standards
We believe that respecting human rights and upholding fair labor standards are fundamental to ethical business practices. All Suppliers must demonstrate an unwavering commitment to these principles, and this applies to all Supplier employees, including temporary, migrant, student, contract, direct employee, and any other type of employee.
Prohibition of Forced and Child Labor:
- Zero Tolerance: Suppliers must unequivocally reject the use of forced labor, bonded labor, indentured labor, prison labor, or child labor in any of their operations or supply chains.
- Freedom of Employment: All work must be voluntary, and workers must be free to leave employment after reasonable notice without penalty, retaliation, or forfeiture of wages or benefits.
- No Child Labor: Suppliers must comply with minimum age laws and applicable international standards. Ensure that no underage workers are employed and that its workers above the minimum age are protected from hazardous work.
- Verification Processes: Suppliers shall implement robust processes to verify the age and legal status of workers to prevent forced or child labor. This includes proper documentation, background checks where appropriate, and regular auditing.
- Awareness and Training: Suppliers shall educate and train staff, particularly those involved in recruitment and management, on the risks of forced and child labor and the methods to identify and prevent it.
Fair Working Conditions:
- Working Hours: Suppliers shall ensure that workers are not required to work excessive hours beyond legal limits and that they receive adequate rest periods. Monitor and manage working hours to prevent exhaustion and maintain worker well-being.
- Overtime Compensation: Suppliers shall compensate workers for overtime at rates defined by law or industry standards, whichever is higher. Overtime work should be voluntary except in emergency situations.
- Benefits and Compensation: Suppliers shall provide all legally mandated benefits, such as social security, health insurance, and paid leave. Ensure fair and competitive compensation.
- Transparency in Employment: Suppliers shall on or before onboarding, clearly communicate pay structure, benefits, deductions, and terms of employment to all workers. Provide employment contracts or agreements in a language workers understand.
Freedom of Association:
- Workers' Rights: Suppliers shall respect workers' rights to freely associate, join unions, seek representation, and engage in collective bargaining, consistent with applicable law and local practice.
- No Retaliation: Suppliers shall never retaliate. Workers must be able to exercise these rights without fear of retaliation, discrimination, or harassment.
Example:
If Supplier discovers that a subcontractor is requiring excessive overtime without proper compensation, or if workers are not free to leave their employment, immediately investigate and take corrective action. Report such issues to MinIO Compliance and work together to resolve them while protecting the affected workers.
Environmental Responsibility
We expect our Suppliers to share our commitment to environmental stewardship and sustainable business practices. Protecting our planet is everyone's responsibility, and together we can make a positive impact. In doing so, Suppliers should:
Environmental Management:
- Waste Management: Implement responsible waste management practices, including reduction, recycling, and proper disposal of waste, in accordance with legal requirements and best practices. Work to minimize waste generation and maximize resource efficiency.
- Hazardous Materials: Manage and handle hazardous materials responsibly, ensuring proper storage, labeling, transportation, and disposal in compliance with all applicable regulations. Maintain proper documentation and training for staff handling such materials.
- Resource Conservation: Work to minimize energy and water consumption, reduce greenhouse gas emissions, and use natural resources efficiently in its operations.
- Environmental Compliance: Comply with all applicable environmental laws and regulations, including those related to air quality, water protection, and soil contamination.
- Continuous Improvement: Regularly assess its environmental impact and implement improvements to reduce its footprint. Consider environmental factors in business decisions and operations.
Sustainability Partnerships:
- Green Practices: Where possible, adopt sustainable practices in its operations and encourage its own suppliers to do the same.
- Innovation: Look for opportunities to innovate and improve environmental performance in the products and services it provides to MinIO.
Example:
If Supplier facility generates electronic waste, ensure it's disposed of through certified e-waste recyclers rather than general waste streams. If Supplier uses chemicals in its manufacturing process, maintains proper safety data sheets, train workers on safe handling, and follow all disposal requirements.
Data Privacy and Information Security
Protecting data is everyone's job, including our Suppliers. We expect Suppliers to treat all personal, business, and confidential information it accesses through your work with MinIO as if it were your own: with care, respect, and in strict confidence.
- Follow the Rules: Comply with all applicable data privacy laws (like GDPR, CCPA, and others) and MinIO's Data Protection Policy, Information Security and Confidentiality Policy, and Data Retention and Disposal Policy. Only collect, use, or share data as needed for its work with MinIO, and never for unauthorized purposes.
- Safeguard Information: Suppliers shall implement strong security measures, think encryption, access controls, secure storage, and regular training for its teams. Limit access to sensitive data to only those who truly need it and keep records of who has access.
- Data Integrity: Suppliers shall ensure the integrity, confidentiality, and availability of data, including personal data, intellectual property, and other sensitive information. Implement appropriate backup and recovery procedures.
- Incident Response: Suppliers shall maintain an incident response plan and train its team on how to respond to security incidents or data breaches.
- Report Issues Fast: If Supplier reasonably suspects a data breach, loss, or unauthorized access affecting MinIO confidential information or data it should notify MinIO Compliance (compliance@minio.io) or Legal (legal@minio.io) promptly. Quick action helps us protect everyone involved and meet our legal obligations.
- Be Proactive: If Supplier is unsure about a data request or a security practice, ask before acting. We'd rather answer a "just checking" question than fix a preventable problem later.
Remember, Supplier’s commitment to data privacy and security helps keep our community safe and our reputation strong.
Intellectual Property Rights
Suppliers must protect and respect MinIO assets, software, technology, confidential information, proprietary information, customer information and intellectual property. Suppliers shall not misuse or infringe MinIO’s intellectual property rights, including but not limited to, invention, discovery, idea, original works of authorship, development, improvements, trade secret, concept, or other proprietary information or right.
Any known unauthorized use by a third party of trade secrets, brands, trademarks, logos, or any proprietary or private information belonging to MinIO must be immediately reported to MinIO by the Supplier.
Conflicts of Interest and Gifts
We count on our Suppliers to make decisions that are in MinIO's best interest, free from personal bias or outside influence.
- Avoid Conflicts: Don't let personal relationships, outside business interests, or financial incentives influence Supplier’s work with MinIO. If Supplier thinks there might be a conflict (or even the appearance of one), disclose it to its MinIO contact or Compliance right away. Transparency is key.
- Gifts & Entertainment: We know that small tokens of appreciation are part of doing business in many cultures. However, gifts, hospitality, or entertainment must never be used to gain an unfair advantage or influence a business decision. Supplier shall only offer or accept gifts that are modest, customary, and legal. When in doubt, disclose it, better safe than sorry.
- Third-Party Relationships: Supplier shall apply the substantially same standards and in no event less than what is mandated by applicable law to Supplier’s own suppliers, agents, and subcontractors. We expect everyone in our supply chain to act with integrity. By keeping things above board, we protect our partnership and maintain trust on all sides.
Supply Chain Responsibility
As a MinIO Supplier, you play a crucial role in our extended supply chain, and we expect you to uphold the same high standards throughout your own supplier network.
Sub-Supplier Management:
- Cascade Compliance: Ensure that all your subcontractors, sub-tier suppliers, agents, and business partners adhere to the principles set forth in this Code. The standards we expect from you must also apply to your supply chain.
- Due Diligence: Conduct thorough due diligence when selecting subcontractors and suppliers, ensuring alignment with MinIO's ethical, social, and legal standards. This includes assessing their labor practices, environmental impact, data security measures, and compliance programs.
- Ongoing Monitoring: Regularly monitor and audit your subcontractors' compliance with this Code and applicable laws. Address any violations promptly and work with them to implement corrective actions.
- Contractual Requirements: Include compliance with this Code as a requirement in all agreements with your subcontractors and suppliers. Make sure they understand and acknowledge their obligations.
- Transparency: Be prepared to provide MinIO with information about your key subcontractors and suppliers, including their locations, services provided, and compliance status.
Risk Management:
- Supply Chain Mapping: Maintain visibility into your supply chain to identify potential risks related to human rights, environmental impact, data security, and regulatory compliance.
- Corrective Action: When issues are identified in your supply chain, take prompt corrective action and work with affected parties to remediate problems. Report significant issues to MinIO.
Example:
If Supplier use a subcontractor for manufacturing components, verify that they comply with labor standards, environmental regulations, and data security requirements. Include Code compliance clauses in your contract with them and conduct regular assessments to ensure ongoing compliance.
Open and Honest Communication
Great partnerships thrive on open, respectful, and timely communication. We want Suppliers to feel comfortable sharing feedback, raising concerns, or asking questions, no matter how big or small.
- Speak Up: If Supplier sees something that doesn't feel right, whether it's a policy violation, unethical behavior, or a potential risk, let us know. Supplier can reach out to Compliance (compliance@minio.io) or Legal (legal@minio.io). We take all reports seriously and investigate promptly.
- No Retaliation: We will never tolerate retaliation against anyone who raises a concern in good faith. Your voice matters, and you're helping us build a better, safer company.
- Feedback Welcome: We value your insights. If you have ideas for improving our partnership or this Code, please share them. We're always looking to learn and grow together.
- Whistleblower Protections: We maintain robust whistleblower protections and encourage reporting of any violations of this Code, applicable laws, or unethical behavior.
Let's keep the conversation going, transparency and trust are the foundation of everything we do.
Workplace Conduct and Safety
A safe, respectful, and inclusive workplace is non-negotiable. We expect our Suppliers to foster environments where everyone can do their best work, free from harassment, discrimination, and violence.
- Respect and Inclusion: Supplier shall treat all individuals with fairness and respect, regardless of race, gender, age, religion, disability, sexual orientation, or any other protected characteristic. Embrace diversity and create space for every voice.
- No Harassment or Bullying: Supplier shall not tolerate any form of harassment, bullying, or abusive behavior. This applies to Supplier’s employees, contractors, and anyone Supplier interacts with on MinIO's behalf.
- Health and Safety: Supplier shall provide a safe and healthy work environment. Follow all applicable health and safety laws, and take proactive steps to prevent accidents and injuries. Maintain proper safety equipment, training, and procedures.
- Violence Prevention: Supplier shall maintain a zero-tolerance policy for workplace violence, threats, or intimidation. Ensure workers feel safe and protected in their work environment.
- Speak Up: Supplier should encourage their teams to report unsafe conditions or inappropriate behavior without fear of retaliation. Address issues promptly and transparently.
By prioritizing safety and respect, we create workplaces where everyone can thrive.
Business Continuity Plan
When it comes to assuring the availability of vital services for MinIO during an unexpected disaster event that could completely or partially impair the performance of services, MinIO expects its Suppliers to manage business continuity risk. MinIO therefore anticipates that its Suppliers will have strategies in place to ensure that their operations can continue with the least amount of disruption possible in the case of an emergency, crisis situation, natural disaster, or terrorist/security-related event.
Occupational Health and Safety
At MinIO we believe that our greatest asset is our people, and we are committed to the wellbeing of all our employees. Similarly, we expect Suppliers to prioritize the occupational health and safety of their employees and implement reasonable and effective occupational health and safety measures.
Suppliers must comply with all safety rules and practices, cooperate with authorities enforcing these rules and practices, and promptly report all accidents, injuries, and unsafe practices or conditions in accordance with law.
Suppliers are responsible for determining and evaluating any potential emergencies. Suppliers shall devise and put into action emergency plans and procedures that will minimize harm to life, environment, and property for each scenario.
Physical Access Control
Those Suppliers who access MinIO’s premises for performance of services must adhere to the security control system put in place by MinIO to ensure zero intrusion and the protection of MinIO and its customers’ and partners’ confidential information. The physical access credentials must only be used for their intended purpose and must not be exploited.
Monitoring, Audits, and Compliance
We're committed to continuous improvement and accountability, and we expect the same from our Suppliers which includes the following measures:
Audit Cooperation:
- Full Cooperation: Be prepared to participate in MinIO's monitoring and audit processes as needed. Suppliers are expected to provide their full cooperation in assessments or audits which may be conducted by MinIO from time to time, whether conducted by MinIO itself or through a third party. This may include providing documentation, access to relevant records, facilities, and personnel for site visits or interviews.
- Documentation: Maintain complete and accurate records related to compliance with this Code, including policies, procedures, training records, incident reports, and corrective action plans.
- Transparency: Address any findings or concerns openly and work with MinIO to resolve them quickly. Provide regular updates on corrective actions and improvements.
- Self-Assessment: Conduct regular self-assessments of your compliance with this Code and applicable laws. Identify areas for improvement and implement necessary changes proactively.
Continuous Improvement:
- Learning Culture: Use audit results and feedback as opportunities to strengthen your own processes and controls. Embrace a culture of continuous improvement and learning.
- Best Practices: Share best practices and lessons learned with MinIO and consider adopting industry-leading practices in your operations.
- Performance Metrics: Track and measure your performance against the requirements of this Code and work to continuously improve your compliance and ethical standards.
Your partnership in these efforts helps us maintain the highest standards and deliver on our commitments to customers, regulators, and each other.
Reporting and Remediation
If Supplier sees or suspects something that doesn't align with this Code, MinIO's policies, or the applicable law, speak up. We count on our Suppliers to help us maintain the highest standards of integrity and safety.
- How to Report: Supplier can report concerns, violations, or unethical behavior directly to its MinIO contact, Compliance (compliance@minio.io), or Legal (legal@minio.io). If you prefer, Supplier may report anonymously, just let us know your preference, and we'll do our best to respect your wishes within the law.
- What to Report: Anything that feels off, fraud, bribery, discrimination, data breaches, unsafe conditions, labor violations, environmental concerns, or any violation of MinIO's policies or this Code.
- Investigation Process: We take all reports seriously. MinIO will promptly investigate concerns, keep Supplier’s information as confidential as possible, and take appropriate action. We'll work with Supplier to understand the situation and develop effective remediation plans.
- Corrective Action: When violations are identified, we expect immediate corrective action and a plan to prevent recurrence.. Suppliers must produce all necessary evidence in such circumstances, operating in a transparent manner. If Suppliers are found to be violating the Code’s guidelines or requirements, corrective action plans may be suggested, which are to be established within a specified time frame and the progress of the same shall be monitored.
- No Retaliation: We strictly prohibit retaliation against anyone who raises a concern in good faith. Your courage in speaking up helps us all do better. Suppliers must also not retaliate against anybody who in good faith discloses a violation of this Code or assists in an investigation into any such violation or unlawful conduct. No person who reports a suspected breach in good faith shall be subject to discharge, demotion, suspension, threats, harassment, or any other form of discrimination by Suppliers, their employees or their agents or contractors.
- Breach: Any breach of this Code or failure to implement suitable corrective action plans may result in further action, including contract termination or loss of status as a Supplier.
Communication and Amendment
Suppliers are required by MinIO to keep a documented code of business behavior that is applicable to and binding on all of its employees, subcontractors, and agents. In order to avoid and identify illegal and unethical behavior, such policy should include requirements that are substantially similar to this Code as well as any applicable laws and regulations. If a situation arises where either this Code's requirements or Supplier’s own policy are not met, the Supplier shall promptly notify MinIO.
MinIO has the right to periodically update this Code to reflect changes in applicable laws or regulations or for any other cause or reason.
Conclusion and Acknowledgment
Thank you for partnering with MinIO and for your commitment to ethical, responsible business. By working together, we create value, build trust, and make a positive impact, locally and globally.
This Code represents our shared commitment to the highest standards of business conduct, human rights, environmental stewardship, data protection, and social responsibility. We trust Suppliers to uphold these principles and to help us build a supply chain that reflects our values and supports our mission.
We welcome your feedback on this Code and our partnership. If you have questions, suggestions, or concerns, reach out anytime to your MinIO contact, Compliance, or Legal. Together, we can continue to raise the bar for ethical business practices and create positive changes in our industry and communities.