Our work helps clients make decisions about people and organisations. Those decisions can affect a person's livelihood, reputation, privacy and safety. The way we obtain information, assess it and communicate our findings must reflect that responsibility.
This Code sets out the standards expected of Bulca & Partners F.Z.E, its leadership, employees, contractors and anyone conducting research on its behalf. We expect clients to respect these boundaries. Commercial pressure, urgency and local custom do not justify departing from them.
Accept work for a legitimate purpose
Before accepting an engagement, we establish who is instructing us, the decision our work will support and how the findings are intended to be used. We agree the scope, methods, recipients and any limits on use. We consider the risks to the people involved as well as the risks to our client.
We decline work intended to facilitate intimidation, stalking, unlawful discrimination, political repression, retaliation against whistleblowers or other abuse. We do not accept a research brief merely to find damaging material about someone. A client's commercial interest alone does not justify an intrusive enquiry.
Where the purpose, authority or intended use is unclear, we pause and seek clarification. If we cannot resolve a material concern, we decline or end the engagement. We apply the same assessment when the scope or circumstances change.
Use lawful and proportionate methods
We obtain information through sources and methods we are entitled to use, including public records, licensed databases, authorised documents and lawful human enquiries. A record's availability online does not, by itself, establish that its collection or use is appropriate.
We do not use hacking, stolen credentials, impersonation, false pretences, covert surveillance, coercion or unauthorised access to private records. We do not commission another person to obtain information by a method we would prohibit ourselves. We do not solicit or purchase unlawfully obtained personal data or induce a breach of confidentiality.
Where the provenance or permitted use of material is doubtful, we restrict its handling and resolve the concern before relying on it. If a research method requires a licence or other authority, we proceed only when the necessary requirements are met.
Keep human enquiries within clear boundaries
Human enquiries require particular care because contact can expose a subject, source or confidential engagement. We agree their use within the scope and assess the likely consequences before approaching anyone.
Researchers must not misrepresent their identity or authority, pressure a source, or encourage disclosure of information the source is not entitled to share. Where we cannot explain an enquiry truthfully without compromising confidentiality or safety, we do not proceed with that approach.
We assess a source's opportunity to know, possible motives and reliability. An account from a human source is not presented as an established fact merely because it is detailed or confidently expressed. We protect source identities where appropriate without overstating the strength or verifiability of their evidence.
Let the evidence determine the conclusion
We distinguish verified facts, allegations, analytical judgments and unresolved questions. We check that information relates to the correct person or organisation, consider dates and context, and seek corroboration proportionate to the significance of a finding.
We do not treat political exposure as evidence of wrongdoing, a name match as a confirmed sanctions match, or an allegation as a conviction. We consider relevant dismissals, acquittals, corrections and other information that changes the meaning of an adverse record. Repetition of the same claim across several outlets is not independent corroboration.
Our reports identify material gaps, source limitations and uncertainty. A lack of adverse information is not a guarantee of integrity or the absence of risk. Findings are bounded by the scope, sources and date of the research.
Substantive reports receive review by someone other than their author before release. We do not invent sources, remove material qualifications or change findings to satisfy a preferred outcome. Fees must not depend on producing an adverse or favourable conclusion.
Respect privacy and human dignity
We collect and use personal information only for a defined, lawful purpose and limit it to what is necessary for that purpose. Sensitive information, criminal records and information about children require additional scrutiny and applicable safeguards.
We do not include intimate or irrelevant personal details merely because they are accessible. Information about relatives or associates must have a specific, documented relevance; association alone does not establish misconduct. Nationality, religion, ethnicity, gender and other personal characteristics are not substitutes for evidence of risk.
Employment vetting must be relevant to the role and conducted with documented candidate consent, as described in our service offering, alongside any other applicable requirements. We do not use the process to investigate unrelated aspects of a candidate's private life.
Protect confidential information
We restrict access to client instructions, research material and reports to authorised people with a legitimate need to know. We use appropriate safeguards for storage, access and transmission, and require equivalent care from service providers.
We establish the applicable basis and safeguards for processing and cross-border sharing before work begins. Retention must reflect a documented purpose, applicable obligations and agreed terms; records are not kept indefinitely simply because they may be useful. When retention is no longer justified, information is securely deleted or returned as appropriate, subject to lawful preservation requirements.
We do not reuse confidential information for unrelated engagements, personal advantage or publicity. Confidentiality continues after an engagement or working relationship ends. Any legally required disclosure is assessed and limited to what is required; we notify affected parties where lawful and appropriate.
Remain independent and reject improper influence
We identify and assess actual or potential conflicts before accepting work and throughout an engagement. These may arise from personal relationships, financial interests, previous assignments or competing instructions. We document safeguards and make appropriate disclosures without exposing another party's confidential information. If a conflict cannot be managed, we decline or withdraw.
We prohibit bribes, kickbacks and facilitation payments, whether offered directly or through an intermediary. Gifts, hospitality, donations or favours must never be used to obtain information or influence access, findings or decisions.
Legitimate registry fees and properly documented professional fees are distinguishable from improper payments. Researchers and correspondents must not be rewarded for producing a particular allegation or conclusion. We keep accurate records of fees, expenses and payments.
Apply the same standards to partners and technology
We assess the suitability of correspondents, researchers and other providers before entrusting them with work or information. Their instructions must define permitted methods, confidentiality requirements and escalation responsibilities. Further subcontracting requires our approval. Outsourcing does not remove our responsibility for the work.
Technology may assist retrieval, translation and organisation, but a human remains accountable for the assessment and report. Material machine-generated content must be checked against reliable sources. We do not use AI output as evidence in its own right.
Confidential or personal information may be entered only into tools approved for that use following an assessment of access, retention, security and provider reuse. We do not permit automated adverse conclusions without meaningful human review.
Comply with applicable restrictions and define the limits of our role
We assess applicable sanctions, anti-bribery, financial crime and trade restrictions affecting our own engagements, counterparties and payments. We do not assist clients in concealing prohibited dealings or evading legal restrictions. Where requirements are uncertain or conflict across jurisdictions, we seek qualified advice before proceeding.
Our research supports informed decisions; it does not guarantee an outcome or replace a client's legal, regulatory or decision-making responsibilities. Reports are supplied for the agreed purpose and recipients. Use outside that scope requires review and authorisation. Engagement through a law firm does not, by itself, establish legal privilege.
Raise concerns and correct mistakes
Anyone working on our behalf must promptly raise suspected misconduct, unsafe instructions, improper collection, data incidents or material inaccuracies. Clients, research subjects and other affected people may also raise a concern or request review of a factual error.
Concerns may be sent to info@bulcapartners.com, with “Code of Conduct” in the subject line. Please provide enough detail for us to assess the issue, but avoid sending sensitive supporting material until we agree an appropriate way to share it.
Concerns are handled discreetly and shared only as needed to assess and respond, subject to legal obligations. We do not promise absolute confidentiality or anonymity. We prohibit retaliation against anyone who raises a concern honestly or assists a review, even if the concern is not substantiated.
Reviews must be led by someone not implicated in the concern. We preserve relevant evidence, take proportionate protective action and correct material errors promptly. Where a correction affects a delivered report, we notify authorised recipients as appropriate. Requests concerning personal data are assessed under applicable requirements without automatically revealing confidential instructions, sources or third-party information.
Make the Code part of our work
Leadership is responsible for implementing this Code, ensuring that people understand it and reviewing it at least annually and after significant incidents or changes in our work. Everyone covered by the Code must acknowledge the standards relevant to their role and escalate uncertainty before proceeding.
Breaches may lead to corrective action, removal from an assignment, disciplinary action or termination of a relationship, consistent with applicable law and contractual terms. Reports to competent authorities are made where required or otherwise lawful and appropriate.
No deadline, instruction or commercial opportunity overrides these standards.