Whistleblowing

Reporting Irregularities
RIV-Digital S.r.l. has activated an internal reporting channel (whistleblowing) through which employees, collaborators, suppliers, and anyone who maintains a professional relationship with the Company can report, in a secure and confidential manner, unlawful conduct, violations of regulations (in particular Regulation (EU) 2023/1114 – MiCAR and Legislative Decree 24/2023) or company policies.

Who can report

The channel is accessible to:

  • employees, collaborators, and consultants, regardless of the type of contract;
  • members of the administrative and control bodies;
  • former employees and collaborators, for facts known during the relationship;
  • candidates during the selection phase, for facts learned during the pre-contractual phase;
  • suppliers, subcontractors, partners, and other external parties operating on behalf of or under the supervision of RIV-Digital.

What can be reported

Any violation — even if only suspected — of laws, regulations, or company policies. By way of example: MiCAR or anti-money laundering regulation violations, improper use of data or ICT infrastructure, undeclared conflicts of interest, fraud or embezzlement, data manipulation, discriminatory or intimidating conduct, failure to report suspicious transactions.

The following are not subject to the channel: individual contractual or salary claims, personal disputes with colleagues or superiors, general requests for information.

Internal channels

Reports can be submitted in one of the following ways, at the whistleblower’s choice, including anonymously:

  • Dedicated email: whistleblowing@riv-digital.it — accessible exclusively to the Legal & Compliance Function.
  • Ordinary mail: sealed envelope marked “Confidential – Whistleblowing report”, addressed to RIV-Digital S.r.l., Legal & Compliance Function, Via Luigi Dalla Via 3b, 36015 Schio (VI), Italy.
  • Confidential interview: upon request, in person or remotely, with the Legal & Compliance Function, in a private setting and with confidential recording.
  • Channel Manager: Legal & Compliance Function — Avv. Alessandro Negri della Torre.

External channels

The whistleblower also has the right to use external channels, particularly when: the internal channel is not active or has not provided feedback within the terms, there is a well-founded fear of retaliation or impartial treatment, or there is an imminent danger to the public interest.

How we handle your report

  • Acknowledgment of receipt: within 7 days of receipt, with an acknowledgment of receipt (if the channel used allows it).
  • Investigation: confidential, conducted by the Legal & Compliance Function with the possible involvement of external experts, in compliance with due process.
  • Feedback to the whistleblower: within 3 months of the acknowledgment of receipt or, in its absence, within 3 months of the expiry of the 7 days from the submission of the report.
  • Retention: documentation is archived for at least 5 years in segregated and encrypted environments.

Your protections

  • Absolute confidentiality regarding the identity of the whistleblower, the persons involved, and the information received — need to know principle.
  • Anonymity permitted: you can choose not to provide your identification data.
  • Prohibition of retaliation: no discriminatory, disciplinary, demotion, exclusion, or reputational measures can be taken against those who report in good faith. The burden of proving that any unfavorable measures are not retaliatory in nature lies with the Company (reversal of the burden of proof pursuant to the Legislative Decree). 24/2023).
  • Extended protection for facilitators, family members, colleagues, and legal entities linked to the whistleblower.
  • Sanctions for those who make intentionally false or defamatory reports, and protection also for the subjects possibly reported.

Processing of personal data

The data collected as part of the report are processed by RIV-Digital S.r.l., the data controller, solely for the purposes of managing the report, in accordance with Reg. (EU) 2016/679 (GDPR) and the Legislative Decree. 24/2023. Access is limited only to authorized subjects of the Legal & Compliance Function. Data subject rights can be exercised by writing to privacy@riv-digital.it.

Regulatory references: Legislative Decree March 10, 2023, no. 24 (implementation of EU Directive 2019/1937 on whistleblowing); Art. 116 of Regulation (EU) 2023/1114 (MiCAR); Reg. (EU) 2016/679 (GDPR).

RIV-Digital S.r.l.
Sede legale: Via Luigi Dalla Via 3 B, 36015, Schio
Registro delle Imprese di Vicenza – REA VI-414981
Codice Fiscale/P. IVA: 05421350280
Capitale sociale: € 300.000,00 interamente versato
LEI: 815600DCB0E8882D2314

RIV-Digital S.r.l. — Authorized by CONSOB as a crypto-asset service provider (Resolution no. 24030 of June 10, 2026).

Activity subject to the supervision of CONSOB (Italian Companies and Exchange Commission), Via G. B. Martini 3, 00198 Rome – www.consob.it.

© Copyright 2026 RIV-Digital S.r.l. All Rights Reserved.