Real Hotels Group
ENPT
An azulejo mural of commuters walking with briefcases and bags, in blues and greys on glazed tile.

Be Responsible

Governance

Operating responsibly also means operating transparently

Ethics, transparency and risk management are strategic pillars of the way we run the business. We are strengthening our internal control mechanisms, our whistleblowing channels and our training in ethical conduct, so as to act always to the highest standards of integrity.

This responsibility rests on a governance structure with responsibilities defined at each level, under review as part of the Belonging strategy.

In 2025 the Group kept in force the transversal Codes and Policies that frame how it operates, applicable to employees, suppliers and partners across the whole value chain, and presented on the pages that follow. The Human Resources policies are presented in the chapter devoted to the team.

ESG governance

Sustainability governance in 2025 and the model review under way.

In 2025 ultimate responsibility for managing non-financial impacts sat with one of the directors, whose role was to monitor the initiatives implemented and to inform the governing bodies. The ESG Committee met once in the year. The Board of Directors had three members, all male and over 50, all executive, with no independent directors. The Group’s executive leadership was exercised throughout 2025 by Eurico de Almeida. Mafalda Dias, who signs the opening message of this report, took office as Chief Executive Officer in 2026, a change after the reporting period which is therefore not reflected in the composition of the governing bodies described above.

With the Belonging strategy review, the Group is redefining its sustainability-governance model, including bodies, responsibilities and the frequency of oversight. How it works will be reported in the year it comes into force.

Policies and codes that govern our conduct

In 2025 the Group kept in force the set of Codes and Policies that frame how it operates: the Code of Conduct, which guides the behaviour of all employees; the Human Rights Policy, which formalises the commitment to internationally recognised principles and applies across the whole operation and value chain; the Responsible Purchasing Policy, which extends ESG criteria to supplier selection; the Plan for the Prevention of Corruption Risks and Related Offences (PPRCIC), monitored across every area of activity; and the privacy and data-protection policy. The RealAlign project, presented in the previous report as the digital infrastructure supporting the Responsible Purchasing Policy, completed its survey phase in early 2025 and was then suspended, having neither entered production nor produced results in the year; the resumption of one of its components, the automation of requisitions, is planned for 2026. Supplier assessment against ESG criteria began through a survey addressed to the main partners, whose results will guide the progressive widening of the process. Information on the Group's existing Policies is complemented in the section of this report dedicated to human-resources management.

The Code of Conduct is handed to every employee on hiring. The policies produced by the Human Resources area are communicated to the whole employee network when issued and are permanently available on the internal Real People platform, and they are also covered at the onboarding of new employees.

Two colleagues conferring over a tablet in a data centre, server racks lit behind them.

Ethics in action

Clear policies, accessible channels and effective accountability sustain the trust of our stakeholders.

Information security and data protection

The growing digitalisation of hotel operations makes information security and personal-data protection matters of risk management. The Group has a centrally managed information-security policy and carried out a security audit of its critical systems in 2025. Cybersecurity awareness reached all employees, through periodic communications and awareness actions, rather than structured training. There were 4 cybersecurity incidents, none of which resulted in a confirmed personal-data breach, and there were no notifications to the national data-protection authority. The Group has a designated Data Protection Officer. Investment in innovation, digital transformation and cybersecurity amounted to 0.186 M€, a figure also presented in the value-creation model (chapter “Belonging - Estratégia ESG”).

Compliance and anti-corruption

The Plan for the Prevention of Corruption Risks and Related Offences (PPRCIC) remained in force and monitored across every area of the Group’s activity throughout 2025, with the Code of Conduct continuing to frame the behaviour expected of all employees. In the year there were 1 confirmed case of corruption, 1 breach of the Code of Conduct and 1 infringement of relevant regulatory rules, with no conflict-of-interest situations identified. The corruption case was handled under the General Anti-Corruption Regime, with no risk of fines attached to it; its nature and the measures adopted are subject to confidentiality and are therefore not disclosed. There were no significant fines or sanctions unrelated to corruption. Ethics and anti-corruption training reached 2 employees, both in Shared Services, out of 986. Extending the training to the whole organisation, committed to in the previous report, remains a commitment.

Whistleblowing channel

The whistleblowing channel provided for in the Code of Conduct is available to employees, suppliers and partners and ensures the confidentiality and anonymity of whoever reports, the absence of retaliation and a defined process of triage, investigation and resolution of each submission. In 2025, 3 reports were received, none related to human rights, all investigated and closed, with an average handling time of 19 days. By allowing irregularities to be reported early, the channel makes it possible to deal internally with situations that might otherwise escalate into legal or reputational consequences.

Transparency and accountability

The Group commits to disclosing financial and non-financial information regularly, clearly and accessibly to employees, guests, partners and shareholders, among other parties.

This report was prepared with reference to the Global Reporting Initiative Standards and makes voluntary use of the basic module of the VSME framework, also responding to a set of indicators requested by FOREST, of Turismo de Portugal. The content index in the Dossier Técnico identifies, for each disclosure, where it sits in the report. Where information is not available or is not disclosed, that is flagged and explained in the index itself. The information was not subject to independent external assurance.

Hands typing on a laptop, with document panels drawn over the keyboard.
Four colleagues around a meeting table looking together at a laptop screen.