Zyla Health Private Limited (“Zyla”) is committed to conducting its business ethically, responsibly and in compliance with applicable law.
This Code of Business Conduct for Suppliers (“Supplier Code”) sets out the standards expected from suppliers, vendors, contractors, service providers and other third parties providing goods or services to Zyla (“Suppliers”).
Suppliers are expected to comply with this Supplier Code, applicable law and any contractual obligations agreed with Zyla.
Suppliers shall conduct their business with honesty, integrity, fairness and transparency.
Suppliers shall comply with all applicable laws and regulations, including those relating to anti-bribery, anti-corruption, fraud, unfair business practices, labour and employment, human rights, environmental protection and other matters relevant to their activities.
Suppliers shall not directly or indirectly offer, promise, authorize, give, request or accept any bribe, kickback, improper payment or other unlawful advantage in connection with their relationship with Zyla.
Suppliers shall avoid any actual or potential conflict of interest that may improperly influence, or appear to influence, their business relationship with Zyla.
Suppliers shall promptly disclose to Zyla any relationship, financial interest or other circumstance that could reasonably create an actual or perceived conflict of interest.
This includes any close personal or family relationship between the Supplier, its owners, directors, employees or representatives and an employee, director or representative of Zyla who is involved in decisions relating to the Supplier.
Suppliers shall maintain appropriate policies, procedures, controls, management systems and trained personnel proportionate to the nature of the services they provide to Zyla.
Suppliers shall communicate applicable legal, ethical, confidentiality, security and compliance requirements to their employees, contractors and other personnel involved in providing services to Zyla.
Suppliers shall promptly notify Zyla of any material actual or suspected violation of applicable law relating to services provided to Zyla, and of any material regulatory investigation, enforcement action or proceeding that may reasonably affect the Supplier’s ability to provide such services.
Zyla may request reasonable information regarding a Supplier’s policies, controls, compliance framework or management of relevant risks.
Suppliers shall protect all confidential and proprietary information received from or relating to Zyla.
Confidential information may include business information, commercial information, intellectual property, technical information, security information, Patient information, Provider information, personal information, health-related information and any other information that is confidential by its nature or designated as confidential.
Suppliers shall access, use, process or disclose such information only:
a) to the extent necessary to perform authorized services for Zyla;
b) in accordance with applicable contractual obligations;
c) in accordance with Zyla’s documented instructions, where applicable; and
d) in accordance with applicable privacy, data protection and security laws.
Suppliers shall implement reasonable technical, organizational and security measures appropriate to the nature and sensitivity of the information they process.
If a Supplier becomes aware of any unauthorized access, disclosure, loss, misuse or security incident involving Zyla information, the Supplier shall notify Zyla promptly and cooperate with Zyla in investigating and addressing the incident.
If a Supplier receives confidential information in error, it shall promptly notify Zyla and shall not further access, use or disclose such information except as instructed by Zyla.
Where a Supplier processes personal information, health-related information or other protected data on behalf of Zyla, the Supplier shall comply with applicable data protection and information-security requirements and any contractual data-processing or security obligations agreed with Zyla.
Suppliers shall ensure that access to such information is limited to personnel who have a legitimate business need and who are subject to appropriate confidentiality obligations.
Suppliers shall not use Zyla data, Patient information or other information obtained through their relationship with Zyla for their own marketing, commercial, analytics, product-development or other independent purposes unless expressly authorized in writing by Zyla and permitted by applicable law.
Suppliers shall not subcontract or delegate any material part of the services provided to Zyla without Zyla’s prior written approval where such approval is required under the applicable agreement or where the subcontractor may access Zyla confidential information, systems, personal information or health-related information.
Where subcontracting is approved, the Supplier shall remain responsible for the acts and omissions of its subcontractors and shall ensure that such subcontractors are subject to obligations that are no less protective than those applicable to the Supplier.
Zyla may, where reasonably necessary and proportionate to the nature of the services or associated risk, request Suppliers to:
a) complete compliance or security assessments;
b) provide relevant policies, certifications, reports or other supporting information; or
c) participate in reasonable audits or evaluations relating to compliance with contractual, legal, confidentiality, data-protection, security or other applicable requirements.
Any such audit or evaluation shall be conducted reasonably, with due regard to the Supplier’s confidentiality, security and operational requirements and subject to applicable law.
Suppliers shall cooperate in good faith with reasonable remediation measures where material compliance gaps are identified.
Suppliers are expected to respect internationally recognized human rights and to maintain fair and lawful working conditions.
Suppliers should take reasonable steps, proportionate to the nature of their business, to identify and address material human rights, labour, environmental, ethical and compliance risks within their operations and relevant supply chains.
Suppliers should promptly report any suspected misconduct, breach of this Supplier Code or material compliance concern relating to their relationship with Zyla.
Concerns may be reported to:
Zyla Health Private Limited
Email: compliance@zyla.in
Zyla expects concerns to be raised in good faith and will handle reported concerns appropriately and in accordance with applicable law.
Where Zyla reasonably determines that a Supplier has materially failed to comply with this Supplier Code, applicable law or its contractual obligations, Zyla may require the Supplier to take appropriate corrective action.
Subject to applicable contractual rights and law, Zyla may suspend, restrict or terminate its relationship with a Supplier where the Supplier fails to address material compliance concerns, refuses to cooperate with reasonable compliance requirements or engages in serious misconduct.
This Supplier Code does not replace or amend any agreement entered into between Zyla and a Supplier. Where a Supplier agreement imposes more stringent obligations, the terms of that agreement shall apply.