Code of conduct
Code of Conduct
1. Purpose
This Code of Conduct sets out the principles and expectations for everyone working on behalf of Purde Software. It helps ensure that we act with integrity, professionalism, and respect in every interaction with customers, suppliers, and each other.
2. Scope
This Code applies to the owner, all contractors, and any individual performing work on behalf of Purde Software, in every business interaction — including communication on Atlassian Marketplace channels, service desk, public Bitbucket repositories, email, and customer-facing meetings.
3. Proportionality
Purde Software is a two-person, part-time business. The expectations below are proportionate to that scale and rely on personal accountability and mutual review, not on a separate compliance function. Where industry codes (for example, the Atlassian Partner Code of Conduct) apply to our activities, we follow them in addition to this Code.
4. Core principles
4.1 Integrity, honesty, and fair dealing
Communicate truthfully and transparently in marketing, sales, support, and contractual dealings.
Do not misrepresent the capabilities, performance, or status of our products or services.
Compete on the merits of our work; do not disparage competitors unfairly.
4.2 Respect, diversity, and non-discrimination
Treat colleagues, customers, suppliers, and community members with courtesy and fairness.
Discrimination, harassment, bullying, or intimidation on any ground — including those protected by the German Allgemeines Gleichbehandlungsgesetz (AGG): race, ethnic origin, gender, religion or belief, disability, age, or sexual identity — is not tolerated.
Value diverse backgrounds, perspectives, and experience in everyone we work with.
4.3 Anti-bribery, gifts, and conflicts of interest
We do not offer, give, accept, or solicit bribes, kickbacks, or other improper payments or benefits, whether directly or through third parties, in any form.
Reasonable, infrequent business courtesies (modest meals, branded items, conference invitations) are acceptable; anything beyond that is declined or escalated.
Disclose any personal, family, or financial interest that could influence — or appear to influence — a business decision, so that a conflict-free path can be agreed.
4.4 Confidentiality, intellectual property, and trade secrets
Protect non-public information of customers, suppliers, and Purde Software at all times. Do not disclose it without proper authorization, and apply the protections expected under the German Geschäftsgeheimnisgesetz (GeschGehG).
Respect the intellectual property of others: use third-party code, content, fonts, images, and trademarks only with a valid licence.
Comply with open-source licence obligations for every dependency we use; do not strip notices, do not commingle incompatibly licensed code.
4.5 Privacy and data protection
Process personal data only in accordance with the Privacy Policy, the Data Processing Agreement, and applicable law (in particular the GDPR and the German BDSG).
Apply data minimization in everything we build and operate.
4.6 Security and quality
Follow the Cybersecurity Policy: secure coding, access control, MFA, secrets management, dependency scanning, vulnerability reporting.
Aim for high quality in every deliverable; respond to bug reports promptly within the SLA.
4.7 Lawful and ethical business conduct
Comply with all applicable laws, regulations, and contractual obligations.
Do not engage in anti-competitive behaviour, money laundering, tax evasion, or fraud.
Comply with applicable EU and German trade-control rules, including sanctions and export controls; we do not knowingly supply our apps or services to sanctioned individuals, entities, or destinations.
4.8 Human rights and labour standards
We respect internationally recognized human rights, including the principles of the UN Guiding Principles on Business and Human Rights and the ILO core labour standards.
We do not use, tolerate, or knowingly contribute to forced labour, child labour, human trafficking, or unsafe working conditions, and we expect the same from our suppliers — consistent with the cascading expectations of the German Lieferkettensorgfaltspflichtengesetz (LkSG) where it applies to our customers.
We comply with applicable wage, working-time, and labour laws (including the German Mindestlohngesetz).
4.9 Responsible use of AI and third-party tools
AI features in our products (currently the optional OpenAI-powered answer support in Smart Questions and Answers) are opt-in, transparent to administrators, and documented in the Privacy Policy.
When we use AI tools for our own work (for example, coding assistants), we do not submit confidential customer data to public or unlicensed AI services, we review AI-generated output before use, and we remain responsible for the quality and licensing of what we ship.
We do not use AI to autonomously make decisions that have legal or similarly significant effects on individuals.
5. Individual responsibilities
Compliance. Read, understand, and follow this Code and the other documents linked under "Related documents."
Conflict-of-interest disclosure. Promptly disclose actual or apparent conflicts to the responsible person (§7).
Reporting. Promptly report any suspected violation of this Code, of applicable law, or of our policies through the channels in §7.
Training and awareness. Stay current on security and privacy topics through the arrangements described in Cybersecurity Policy §13.
Acknowledgement. Each contributor confirms in writing that they have read and will follow this Code at the start of their engagement, and again after any material update.
6. Responsible person and contact
The responsible person for matters under this Code is Andreas Purde (owner). For privacy-related matters, the same contact applies — Purde Software is not required to appoint a Data Protection Officer under Art. 37 GDPR or §38 BDSG; see Privacy Policy §2.3.
Contact channels:
Service Desk (preferred): https://purde-software.atlassian.net/servicedesk/customer/portal/2
Email: support@purde.de
Postal: Purde Software, Max-Friedlaender-Bogen 17, 80339 München, Germany
7. Reporting concerns and whistleblower protection
Concerns about possible violations of this Code, of applicable law, or of our policies can be raised through any of the channels listed in §6. Reports may be submitted by name or anonymously.
All reports are treated confidentially, to the extent permitted by law, and investigated promptly and proportionately.
Non-retaliation. In line with the principles of the EU Whistleblower Protection Directive (2019/1937) and the German Hinweisgeberschutzgesetz (HinSchG), no one will face dismissal, withdrawal of work, harassment, or any other detriment for raising a concern in good faith — regardless of whether the concern is ultimately substantiated.
8. Investigation and consequences of violations
Reports are investigated by the responsible person (or, where the responsible person is the subject of the concern, by the second contributor) in a manner proportionate to the seriousness of the matter. Substantiated violations may result in corrective measures appropriate to the relationship, including but not limited to remedial training, written warnings, suspension of access, termination of the engagement or contract, and — where applicable — reporting to authorities.
9. Related documents
10. Version history
Version | Date | Changes |
|---|---|---|
1.0 | up to May 31, 2026 | Earlier versions. |
2.0 | May 31, 2026 | Restructured for procurement readability. Corrected "Data Protection Officer" reference to align with Privacy Policy v2 (no DPO required). Added proportionality clause. Expanded principles: anti-bribery and conflicts of interest; non-discrimination with explicit AGG grounds; intellectual property and open-source licence compliance; sanctions and export controls; human rights and labour standards (referencing LkSG cascade); responsible use of AI and third-party tools. Added acknowledgement requirement, whistleblower-protection reference (HinSchG / EU Directive 2019/1937), and consequences-of-violations section. Added related-documents and version-history sections. |