Policy 24 Financial Authority Expenses and Fraud Prevention
Owner Finance with management approval | Applies to all spending and financial records | Access internal
Authority and separation of duties
Written management delegations identify who may prepare, check and approve payments, refunds, discounts, purchases and account changes. Unless expressly delegated, only the authorised management signatory may commit funds or release payments. Preparing a report or maintaining a ledger does not confer banking authority. Nobody may approve their own expense, pay increase or related-party transaction without independent review.
For Ataraxy's operating model, Finance tracks receivables, writer and vendor balances, project profitability and financial exceptions. HR maintains authorised personnel and payroll changes. Management retains payment authority unless formally delegated. Each team must see only the information needed to perform its part.
Invoices receivables and payables
Record each order's agreed value, approved changes, invoices, payments, outstanding amount and source evidence. Match receipts to the correct client and project. Report overdue balances to the designated account owner; Finance must not send threats, waive balances or suspend services without authority. Writer and contractor ledgers must show accepted work, agreed rates, invoices, payments and disputed items separately.
Reconcile bank and payment-provider records regularly against the ledger. Do not mark an invoice paid solely on an unverified screenshot. Keep credits, refunds and write-offs traceable. Project profit reports must state the cost basis and distinguish collected cash from booked revenue.
Payment and account-change controls
Verify new or changed bank details through an independently known contact method, especially where a request arrives by email or message. Use approved beneficiary records and keep evidence of approval. Unexpected urgency, secrecy or instructions to bypass checks must be escalated. Restrict OTPs, banking credentials and payment-provider access to authorised people.
Expenses gifts and fraud
Expenses require a business purpose, appropriate approval and valid evidence. Lost receipts require an explanation and permitted alternative evidence, not fabrication. Split purchases to evade limits, personal expenses disguised as business costs, kickbacks and undisclosed commissions are prohibited. Related-party purchases must be disclosed and assessed for fairness.
Suspected fraud is reported through Policy 09 and, if systems or data are involved, Policy 20. Preserve records and avoid confronting suspects in a way that destroys evidence. Finance maintains a weekly exceptions summary and periodic reconciliation record. Tax treatment and statutory record retention require qualified review.
Policy 25 Sales Marketing and Client Communication
Owner Sales and Marketing with Operations | Applies to outreach proposals and client contact | Access internal
Authority and accurate representation
Use approved service descriptions, portfolio material and pricing. Sales may not promise delivery dates, integrations, security certifications, guaranteed revenue, rankings, grades or regulatory approval without a documented and supportable basis. Operations must confirm scope, capacity and technical feasibility before a binding commitment. Discounts, credits and unusual terms require written management approval within the authorised delegation.
Lead collection and outreach
Record the source and permitted use of lead information. Public availability of a phone number does not automatically establish permission for every marketing channel. Check applicable outreach laws, platform rules and client-country requirements before campaigns. Do not buy or use unlawfully obtained lists, impersonate people, evade platform restrictions or continue contacting people who have validly opted out.
Messages must identify the business accurately, describe the offer honestly and provide a practical opt-out where required. Maintain a suppression list with limited access so opt-outs are respected across campaigns. Contact frequency and automation must follow the approved campaign plan. Do not expose recipients by placing unrelated client addresses in a visible group email.
Proposals and approvals
Every proposal identifies deliverables, assumptions, exclusions, client responsibilities, timeline dependencies, price, payment stages and validity. Record what the client accepted. Oral discussions and messaging approvals that materially affect scope should be summarised in the project record and confirmed by an authorised representative. Only authorised personnel may sign agreements.
Communication and escalation
Keep client communication courteous and factual, including when payments are overdue or criticism is unfair. Do not threaten public exposure, delete client data, insult clients or announce service termination without the approved contractual process. Escalate complaints, unrealistic deadlines, scope disputes and security questions to the correct owner. Personnel must not accept private side payments or divert opportunities to personal accounts.
Reporting
Record leads, source, stage, next action and genuine outcomes in the CRM. Do not inflate calls, conversions or revenue. Marketing results should distinguish estimates, actual sales and attribution uncertainty. Review campaigns for accuracy, consent or other lawful basis, opt-outs and use of approved assets before release.
Policy 26 Client Delivery Quality Assurance and Change Control
Owner Operations and project leads | Applies to all client deliverables | Access internal
Project initiation
No project should proceed beyond an approved preliminary stage without a written scope, responsible owner, deliverables, price, assumptions, client dependencies and acceptance criteria. Identify who can approve work for each party. Record required content, access, licences, data, integrations and review deadlines. Work involving production systems requires an access and rollback plan.
Planning and execution
Break work into reviewable milestones and assign owners. Track progress, risks, decisions and blockers in the approved project system. Escalate likely delays before a deadline is missed, with the cause, impact and recovery options. Do not quietly reduce scope or quality to appear on schedule. Client-supplied information should be checked for completeness and obvious issues within the agreed scope.
Quality checks
Review software for agreed functionality, access control, security, usability, mobile behaviour and relevant compatibility. Verify content for accuracy, originality, permissions and client instructions. For consequential changes, another competent person should review where practicable. Record test evidence and known limitations. Security-sensitive changes require proportionate checks before release, including secret scanning and permission review where appropriate.
Change requests and revisions
A change request describes the requested addition or alteration, effect on fees and timing, dependencies and approval. Obtain authorisation before doing chargeable extra work unless a documented emergency exception applies. Correcting a failure to meet the agreed scope is not automatically a billable change. Distinguish included revision rounds from new requirements without using vague wording to evade responsibility.
Acceptance deployment and closure
Provide the client with the deliverable, relevant instructions and a reasonable review opportunity under the agreement. Record specific acceptance or rejection against agreed criteria. Silence counts as acceptance only if a lawful, clearly agreed mechanism applies. Deployment requires the designated approval, backup where appropriate and a rollback method. Close the project with source and credential handover as agreed, outstanding-issue records, support terms and data disposition. A closed task board does not override unresolved contractual obligations.
Policy 27 Content Writing Originality and Editorial Standards
Owner content lead and Operations | Applies to writers editors and content contractors | Access internal
Brief and permitted scope
Every assignment should state audience, purpose, length, style, sources, deadline, permitted AI use, revision terms and delivery format. Writers must clarify ambiguous instructions before producing work. Content must be lawful and must not impersonate a real person, fabricate credentials or misrepresent evidence. Educational support must respect the relevant institution's rules and must not involve falsified observations, invented data, fabricated citations or prohibited submission under another person's identity.
Originality and sources
Produce original wording except for properly permitted and attributed quotations. Do not copy another client's work, purchase unlicensed text, or use paraphrasing to conceal infringement. Keep a proportionate source record. Verify that cited materials exist and support the claims made. Distinguish fact, opinion, estimate and unverified client-provided information. A plagiarism checker or AI detector is an aid, not proof of authorship or accuracy.
AI and factual review
Follow Policy 18 and the client agreement. Human editors remain responsible for facts, tone, references and suitability. Do not upload confidential briefs into an unapproved tool. Claims about medicine, law, finance or other regulated matters require appropriately qualified review where necessary; a writer must not invent professional approval. Do not promise a particular detector result, grade, publication decision or commercial outcome.
Editing and revisions
Check spelling, grammar, consistency, formatting and compliance with the brief. Preserve revision history and respond to feedback professionally. A material factual or confidentiality error must be escalated promptly even if discovered after delivery. Corrections to non-compliant work and additional client scope should be handled according to the agreed revision terms and Policy 26.
Confidentiality ownership and portfolios
Keep each client's material separate. Unpublished manuscripts, personal stories, business documents and research records may be highly confidential. Secure permissions for images, quotations and other third-party assets. Ownership and reuse rights follow the signed agreement. Writers may not resell commissioned work or display it as a sample without authorisation. The content lead records final review, delivery and any material limitations communicated to the client.
Policy 28 Conflicts of Interest Gifts and Outside Work
Owner HR and management | Applies to all personnel | Access staff portal
Disclosure
Disclose circumstances that could improperly influence a business decision or interfere with duties. Examples include a financial interest in a supplier, a relative seeking a contract, private work for a company client, receipt of commissions, or participation in a competing bid. A disclosed conflict is not automatically misconduct; failure to disclose or misuse of authority may be.
Outside work
Personnel may undertake lawful outside activities subject to valid contractual obligations, working-time and conflict rules. Approval is required where the activity involves a company client, competitor, confidential information, company assets or overlapping committed working hours. Ataraxy does not claim ownership of all personal time or unrelated personal creative work. HR must assess requests reasonably and document specific restrictions.
Client relationships and competing interests
Do not divert company leads, solicit private payments from assigned clients or use non-public pricing and contact information for personal advantage. If a client offers direct work or employment, disclose the situation so the relevant agreements can be reviewed. Any post-engagement non-solicitation or non-compete term requires separate legal review and a valid agreement; this policy does not create a blanket ban on future work.
Gifts and hospitality
Cash, cash equivalents, kickbacks and gifts intended to influence a decision are prohibited. Modest legitimate hospitality or gifts require written management approval before acceptance unless a documented delegation expressly permits them. Disclose the provider, value, purpose and any pending business decision. Gifts involving public officials require specific legal review. Return or surrender inappropriate gifts in a documented manner.
Managing a conflict
Management may require recusal, independent approval, restricted access or a revised assignment. Record the decision, responsible reviewer and review date. Related-party transactions require independent scrutiny. Personnel must report pressure to conceal a conflict, and good-faith disclosure must not itself attract retaliation. Decisions affecting senior management should be reviewed by an appropriate independent adviser or authority.
Policy 29 Social Media Portfolio and Brand Use
Owner Marketing and Operations | Applies to all personnel and authorised promoters | Access internal
Official communication
Only authorised people may publish from company accounts or speak on behalf of Ataraxy. Maintain company-controlled ownership, recovery information and access records for social channels, advertising accounts and business listings. Credentials must be stored securely and removed promptly when responsibilities change. Agencies or interns receive limited permissions rather than unrestricted ownership.
Client approval and work samples
Before publishing a client name, logo, testimonial, screenshot, case study or project result, confirm the contract permits it and obtain any necessary written approval. Approval for one item or channel does not automatically cover all future use. Remove personal data, credentials, financial details and confidential metadata. Check whether a screenshot reveals information through tabs, notifications or background content.
Portfolio material must accurately describe Ataraxy's contribution. Do not imply that the company built, owns or is endorsed by a product merely because it completed a small component. Do not invent testimonials, ratings, partnerships, awards or client outcomes. Employees and interns need the same permission before using work in personal portfolios or university presentations.
Personal accounts
Personnel should make clear when expressing personal views and must not disclose protected information or falsely claim company authority. This policy does not prohibit lawful criticism, protected discussions of working conditions, reporting wrongdoing or seeking advice. Harassment, unlawful threats and deliberate disclosure are handled under the relevant policy regardless of the platform used.
Corrections and exit
Report accidental publication or account compromise immediately. Marketing coordinates corrections and preserves evidence where needed. Do not delete a disputed post solely to hide misconduct; containment and evidence preservation should be coordinated. At exit, transfer company assets and remove permissions while respecting personal accounts. The brand asset register records authorised logos, templates, domains and approved public claims.
Policy 30 Vendor Freelancer and Subcontractor Management
Owner Operations with Finance and Security | Applies to external suppliers and engagements | Access internal
Selection and approval
Choose suppliers according to competence, capacity, price, reliability, security and conflicts of interest. Assess the level of review according to the risk: a provider with production access requires more scrutiny than a supplier of ordinary office items. Verify identity and payment details proportionately. Disclose relationships and obtain the required spending approval before committing work.
Written terms
Before access or delivery begins, agree scope, milestones, acceptance, fees, tax responsibilities, confidentiality, intellectual-property rights, security, subcontracting, incident reporting and termination. Use a data-processing agreement where appropriate. Calling a person a contractor does not settle employment classification; HR must review arrangements resembling employment.
Client permission and access
Confirm whether the client permits subcontracting and whether named-provider approval, country restrictions or data-transfer safeguards apply. The company must not secretly substitute an unapproved freelancer on restricted work. Grant the minimum necessary access with an expiry and named sponsor. Vendors may not share credentials, delegate to further parties or reuse client data without approval.
Delivery and payments
The project owner checks work against the agreed criteria and records acceptance, defects and revisions. Finance matches invoices to agreed work and approval. Do not withhold undisputed amounts merely because another project is in dispute unless the contract and law permit it. Changes and additional fees need written authorisation. The company remains accountable to clients for obligations it has accepted; subcontracting is not a blanket disclaimer.
Review and exit
Review significant suppliers periodically and after incidents or ownership/service changes. Track expiring licences, data access and renewal dates. At exit, revoke access, obtain deliverables, return or delete data as agreed and preserve required records. Maintain evidence of deletion where material. Report vendor incidents under Policy 20 and reassess whether ongoing access is appropriate.