Operations & Compliance

Operations & Compliance Policy

Detailed regulations on operational processes, legal compliance and asset management.

Last updated: January 4, 2026

Operations and compliance policies ensure all Xylentis activities are conducted efficiently, transparently and in full compliance with legal regulations. All employees are responsible for understanding and correctly implementing these regulations.

Legal Compliance

Commitment to legal compliance

Labor Law: Full compliance with Vietnamese Labor Code on employment contracts, working hours, rest periods, social insurance.

Data Protection: Correctly implement Decree 13/2023/ND-CP on personal data protection and GDPR, CCPA regulations when serving international customers.

Intellectual Property: Respect third-party copyrights, trademarks, patents. Do not use intellectual property without permission.

Anti-Corruption: Zero-tolerance policy for bribery and corruption in any form.

Tax and Accounting: Honest financial reporting, full and timely tax payments.

Project Management

Project management processes and methods

Agile/Scrum Methodology: Flexibly apply Agile for software projects with short Sprints (1-2 weeks), Daily Standups, Sprint Reviews.

Progress Reporting: Regularly update project status through management systems (Jira, Linear, Notion) and periodic reporting meetings.

Risk Management: Identify, assess and plan responses to potential project risks.

Change Control: All project scope changes must go through approved Change Request processes.

Quality Acceptance: Rigorous testing (QA/QC) process before handover.

Company Asset Use

Equipment and software regulations

Company equipment (laptop, phone, monitor): Use for work purposes, handle carefully, report immediately if damaged or lost.

Licensed Software: Only use company-licensed software, do not install cracked/pirated software.

Access Accounts: Do not share login information, enable 2FA for all accounts.

Return Upon Departure: Return all equipment in full, delete personal data on the last working day.

Personal Use: Limit personal use of company equipment. Do not store inappropriate content.

Internal Communication

Communication regulations within the organization

Official Channels: Use company email, Slack/Teams for work communication.

Effective Meetings: Have clear agenda, time limits, take meeting notes and action items.

Timely Response: Reply to emails, messages within 24 business hours.

Information Security: Do not discuss confidential information in public or through unsecured channels.

Feedback Culture: Encourage constructive feedback, respect different opinions.

Compliance Checklist

  • Read and signed commitment to comply with company policies.
  • Completed information security training course.
  • Enabled 2-step authentication for all work accounts.
  • Using company-provided password manager.
  • Know how to report security incidents/violations.

Contact Compliance

For legal compliance questions, please contact the Compliance department.

[email protected]
Operations & Compliance Policy | Xylentis | Xylentis