Policies & compliance
The corporate policies and published statements our customers ask us for, in one place — and what else we can send you on request.
Last updated 30 July 2026
Why these are published
We sell to NHS trusts, public bodies and businesses that buy through a formal procurement process. That process asks for the same set of documents every time — a modern slavery statement, a carbon reduction plan, a social value commitment, an equality policy, an accessibility statement — and asks for them as published pages rather than as attachments to an email.
So they are published. Most of them are not legally required of a company our size, and we would rather say that plainly than imply otherwise. They are here because they are useful to the people evaluating us, and because writing them down is how a small company avoids only thinking about these things the week a bid is due.
Published policies
- Modern Slavery StatementOur supply chain, where the risk in it actually sits, and what we do about it. Published voluntarily — we are below the s.54 threshold.
- Carbon Reduction PlanOur emissions baseline, reduction targets and route to Net Zero, in the format PPN 06/21 and the NHS Net Zero Supplier Roadmap require.
- Social Value StatementWhat a company of our size can genuinely commit to under the Social Value Model, mapped to its themes rather than to a wish list.
- Equality, Diversity & Inclusion PolicyHow we recruit, employ and work, and how someone raises it with us when we fall short of this.
- Accessibility StatementThis website and — the part that matters to a public sector buyer — the applications built on the platform.
Related documents already on the site
- Security & complianceHosting, encryption, access control, penetration testing, backups and our certification position.
- GDPR & data protectionOur role as a processor, the data processing agreement, sub-processors, UK data residency and breach notification.
- Privacy policyWhat we collect as a controller for this website and for sales enquiries.
- Terms of useThe terms covering this website. Subscriptions and bespoke projects have their own signed agreements.
Available on request
Not everything a procurement exercise asks for belongs on a public web page. The following are current and we will send them to a named buyer, usually the same day:
- Certificates — Cyber Essentials, and our latest NHS Data Security & Protection Toolkit submission.
- Insurance certificates — professional indemnity, public liability, employers' liability and cyber, with cover levels and renewal dates.
- Our data processing agreement and current sub-processor list.
- Business continuity and disaster recovery arrangements, including recovery time and recovery point objectives.
- Health & safety policy, anti-bribery policy and whistleblowing procedure.
- The most recent independent penetration test summary, under NDA.
- ISO 27001 Annex A control mapping.
Email info@activemanage.co.uk and tell us which framework or questionnaire you are working to. We would rather answer the actual question than send a folder of PDFs.
Who is responsible
Every policy in this section is owned by TODO_RESPONSIBLE_DIRECTOR, who is the point of escalation if you think we are not living up to one of them. Reviews are annual unless the policy itself says otherwise, and each document carries the date it was last reviewed.
ActiveManage Ltd, company number 10448163, registered in England and Wales. Registered office: ActiveManage Ltd., Enterprise Centre, David Lane, Basford, Nottingham, NG6 0JU. Email info@activemanage.co.uk.