Code of Conduct and Information Security Policy

REICOR, Inc. dba PeopleKind HR

Revised: September 28, 2026

1. Purpose and Scope

This Code of Conduct and Information Security Policy establishes ethical, workplace, privacy, payment-security, and legal-compliance expectations for REICOR, Inc. dba PeopleKind HR (the “Company”). It applies to employees and, where relevant to their services and contractual obligations, temporary staff, contractors, consultants, and other individuals acting on the Company’s behalf.

This Policy is intended to operate together with the Company’s Privacy Policy, employee policies, information-security procedures, payment-processor requirements, and applicable federal, California, and City of Los Angeles requirements. Where a separate policy or law provides greater protection or a more specific requirement, that requirement controls.

2. Compliance with Laws and Company Standards

Personnel must comply with applicable laws and Company policies concerning employment, workplace safety, discrimination and harassment, privacy and security, customer records, intellectual property, records retention, payments, and ethical business practices. Questions about legal or ethical obligations should be raised promptly with management or Human Resources.

This Code is not a substitute for legally required workplace postings, notices, training, wage-and-hour practices, or other separate compliance documents.

3. Ethical Conduct and Conflicts of Interest

Personnel must act honestly, fairly, professionally, and in the Company’s legitimate interests; accurately represent services and transactions; protect Company and client assets; avoid bribery, kickbacks, fraud, and improper inducements; disclose actual or potential conflicts of interest; and not misuse confidential information or Company opportunities for personal benefit.

4. Respectful Workplace; Equal Employment Opportunity

The Company is committed to a professional workplace free from unlawful discrimination, harassment, and retaliation. Prohibited conduct includes discrimination or harassment based on any characteristic protected by applicable federal, California, or local law. This protection applies to conduct in person and in work-related electronic or virtual communications.

Personnel must not retaliate against an employee, applicant, contractor, or other protected person for reporting discrimination, harassment, suspected legal violations, safety concerns, privacy or security incidents, payment concerns, or other misconduct; requesting an accommodation; participating in an investigation; or otherwise engaging in legally protected activity.

The Company will provide legally required harassment-prevention information and training when applicable. Complaints will be addressed promptly and fairly, with confidentiality maintained to the extent reasonably possible and consistent with an effective investigation and applicable law.

5. Reporting Concerns and Investigations

Concerns may be reported to a supervisor, Human Resources, or another manager with authority to investigate or correct the issue. A person is not required to report a concern first to an individual who is involved in the alleged misconduct. Reports may be made without fear of retaliation.

The Company will evaluate reports and use a fair, timely, and impartial process appropriate to the circumstances. Personnel must cooperate honestly in investigations and must not destroy, alter, conceal, or fabricate relevant records. Corrective action may be taken when warranted, up to and including termination of employment or engagement, consistent with applicable law.

6. Whistleblower Rights

Nothing in this Policy prohibits or restricts an employee from reporting suspected violations of law to a government or law-enforcement agency, providing information to a person with authority over the employee or an employee with authority to investigate or correct a violation, participating in a government investigation or hearing, or refusing to participate in conduct that would violate applicable law. The Company prohibits retaliation for protected whistleblowing activity.

7. Privacy, Confidentiality, and Customer Information

Personnel must collect, access, use, disclose, transmit, retain, and dispose of personal information only for authorized business purposes and in accordance with the Company’s Privacy Policy and applicable law. Access must be limited to personnel with a legitimate business need.

Personal information may include customer or client contact information, transaction and service records, membership information, event registration information, communications, login or device information, and financial information associated with credit-card or ACH payments. Confidential information also includes Company proprietary information, client materials, credentials, security information, and nonpublic business records.

Personnel must not disclose confidential or personal information to unauthorized individuals, place sensitive data in unapproved systems, send it through unauthorized channels, or retain copies for personal use. Customer records containing personal information that are no longer required to be retained must be securely disposed of in accordance with Company procedures and applicable law.

8. Reasonable Security and Cybersecurity Responsibilities

The Company maintains reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information it handles. The Company’s website hosting and cybersecurity controls and its cybersecurity insurance complement, but do not replace, individual security responsibilities.

Personnel must protect passwords and authentication factors; use unique Company-authorized credentials; follow access-control requirements; keep systems and software reasonably current; use Company-approved devices, networks, storage, and applications for sensitive information; guard against phishing, malware, social engineering, and unauthorized access; lock or secure unattended devices; and immediately report suspected compromise, lost devices, unauthorized access, or accidental disclosure.

Personal information disclosed under contract to nonaffiliated service providers must be handled through approved vendors and agreements that address appropriate protection of the information where legally required.

9. Payment Card Security and PCI DSS

Payment-card information must be handled in accordance with the Company’s payment-processing arrangements and applicable Payment Card Industry Data Security Standard (PCI DSS) requirements. Personnel must use only Company-approved payment channels and processor interfaces.

Personnel must not request or transmit complete card information through ordinary email, text message, chat, shared documents, notes, or other unapproved channels. Access to payment account data must be restricted to authorized personnel with a business need. Sensitive authentication data, including card verification codes, must not be retained after authorization where prohibited by PCI DSS or processor requirements.

Personnel must not bypass payment-security controls, share credentials, disable protections, or store payment data in systems not specifically approved for that purpose. Any suspected payment-card compromise must be reported immediately so the Company can take required containment, processor, acquirer, card-brand, insurance, and legal-response steps.

The Company will complete the PCI DSS validation or compliance documentation required by its acquiring bank, payment brand, or payment-processing partner for the Company’s merchant environment. The processor or acquirer may impose requirements beyond this Code.

10. ACH and Bank Account Information

ACH transactions and bank-account information must be handled only through Company-approved payment systems and in accordance with applicable processor, financial-institution, and ACH Network requirements. Personnel must obtain and retain transaction authorization as required by the applicable payment process and must not initiate unauthorized or deceptive ACH transactions.

Bank-account information must be protected against unauthorized access or disclosure. Where applicable ACH rules require electronically stored account numbers to be rendered unreadable, the Company will use an approved method or processor-hosted solution. Personnel must not copy bank-account information into unapproved systems, email, chat, or local files.

11. Incident and Data-Breach Response

Personnel must immediately report any suspected loss, theft, unauthorized acquisition, access, use, disclosure, modification, or destruction of personal, payment, credential, or confidential information. Personnel must preserve relevant evidence, follow Company incident-response instructions, and must not independently contact affected individuals, payment brands, processors, media, or regulators unless authorized.

The Company will assess incidents and provide legally required notifications. California law imposes security-breach notification duties when specified personal information is acquired, or reasonably believed acquired, by an unauthorized person, subject to statutory requirements and exceptions.

12. Electronic Systems and Acceptable Use

Company systems, devices, networks, accounts, and software are primarily for authorized business purposes. Limited personal use may be permitted when it does not interfere with work, violate law or policy, create security risk, or impose material cost. Personnel must not install unauthorized software, defeat security controls, access data without authorization, or use Company resources for unlawful activity.

To the extent permitted by applicable law and Company notice, Company systems and Company-owned information may be accessed, reviewed, preserved, or monitored for security, compliance, investigation, maintenance, and legitimate business purposes. This provision does not restrict legally protected communications or activities.

13. Records, Intellectual Property, and Legal Holds

Business and transaction records must be accurate, complete, and not falsified. Personnel must follow applicable retention and secure-disposal requirements. Records subject to litigation holds, investigations, audits, payment disputes, or other preservation obligations must not be destroyed or altered.

Personnel must respect copyright, trademark, trade-secret, license, and other intellectual-property rights. Company or client proprietary information may be used only for authorized purposes.

14. Workplace Safety and Substance Misuse

Personnel must follow applicable safety requirements and promptly report hazards, injuries, threats, or unsafe conditions. Unlawful possession, distribution, or sale of controlled substances in the workplace or while performing Company business is prohibited. Alcohol or other substance use must not impair safe or effective performance or violate applicable Company policy or law.

15. Los Angeles and California Workplace Compliance

The Company will comply with applicable California and City of Los Angeles wage, hour, paid-sick-leave, workplace-rights, fair-chance, scheduling, safety, posting, and notice requirements based on the Company’s workforce, location, and activities. Personnel responsible for payroll, hiring, scheduling, or workplace postings must follow the current requirements applicable to their functions.

Certain Los Angeles requirements apply only to covered employers or industries. For example, the City’s Fair Work Week Ordinance applies to covered retail employers meeting its stated size and geographic criteria. The Company will apply such requirements only when the applicable coverage conditions are met.

16. Third-Party, Vendor, and Client Relationships

Personnel must conduct business with customers, clients, vendors, payment processors, contractors, and government officials honestly and fairly. Vendors handling personal or payment information must be engaged through approved processes. Personnel must not misrepresent the Company’s security, privacy, insurance, PCI DSS, ACH, or legal-compliance status to a customer, processor, bank, insurer, or vendor.

17. Political and Civic Activity

Personal political and civic activities must be conducted on personal time and with personal resources unless otherwise authorized and lawful. Personnel must not imply Company sponsorship or endorsement without authorization. Nothing in this section is intended to restrict rights protected by applicable law.

18. Discipline and Non-Retaliation

Violations of this Policy may result in corrective or disciplinary action, up to and including termination of employment or engagement, consistent with applicable law and contractual rights. Good-faith reporting of suspected misconduct is protected. Knowingly making false statements or intentionally falsifying investigation evidence may itself violate this Policy.

19. Acknowledgment and Updates

Personnel covered by this Policy are expected to read, understand, and comply with it and applicable supporting policies. The Company may revise this Policy as laws, payment requirements, technology, or business practices change and will provide notice as appropriate.

Questions about this Policy may be directed to Human Resources or Company management. Privacy questions may be directed to info@peoplekind-hr.com.

20. Compliance Items Maintained Separately

This Code does not replace required stand-alone materials. The Company should separately maintain and distribute or post, as applicable: its Privacy Policy; California and Los Angeles workplace postings and notices; a compliant discrimination, harassment, and retaliation prevention policy and complaint process; required harassment-prevention training records; payment-processor merchant agreements; PCI DSS validation documentation applicable to the merchant environment; ACH authorization and processor procedures; written incident-response and breach-notification procedures; and applicable record-retention and secure-disposal procedures.

Code of Conduct and Information Security Policy