Internal policies

Governance and compliance

This page consolidates the normative principles governing the conduct of GBS PRIVATE LTDA, its managers, employees, service providers and counterparties. The provisions set out here are mandatory.

Version 1.0 — effective from 31 July 2026.

1. Principles of conduct

The company conducts its activities in compliance with Brazilian law and with the law applicable in each market where an order is processed. No commercial target justifies breach of a legal rule, a contractual clause or an internal policy.

It is prohibited to offer, promise, give, solicit or receive any undue advantage, directly or indirectly, to or from a public or private agent, in any jurisdiction. It is prohibited to enter into business with a counterparty whose identity has not been verified or whose activity is not lawful. Conflicts of interest must be reported to management before the act is performed and recorded in writing.

The company's accounting and operational records must accurately reflect the nature, amount and date of each operation. Creating a false, incomplete or late record is prohibited.

2. Anti-money laundering and counter-terrorist financing

The company adopts controls designed to prevent its operations from being used to conceal or disguise the origin, nature, location, disposition or ownership of assets, rights or values derived from a criminal offence, and to prevent the financing of terrorism.

Permanent obligations include: identifying all counterparties before the relationship begins; understanding the nature and purpose of the commercial relationship; monitoring intermediated operations; and retaining records for the statutory period.

Situations requiring attention include, among others: an operation with no apparent economic or legal rationale; the splitting of amounts apparently intended to avoid control thresholds; repeated refusal to provide registration information; divergence between the counterparty's declared profile and the volume transacted; and payment instructions to a third party unrelated to the operation.

Identification of such a situation suspends processing of the order and triggers analysis by management, which decides on the continuation of the relationship and on any reporting due to the competent authorities under applicable law. Informing the counterparty that a report has been made to an authority is prohibited.

3. Know your customer and counterparty

No counterparty is admitted without prior registration. Registration comprises, as a minimum: the identification of the legal entity or individual; the incorporation or identity document; the address; the identification of representatives with contracting powers; and the identification of the ultimate beneficial owner where the counterparty is a legal entity.

The company screens counterparties against restrictive and sanctions lists applicable to the jurisdictions involved, before admission and periodically during the relationship. Refusal to provide a required document, submission of an inauthentic document or subsequent inclusion on a restrictive list results in immediate suspension of processing and assessment of termination of the relationship.

Registration data is reviewed whenever a material change is notified by the counterparty and, in any event, at intervals set by management. Records are retained for the statutory period counted from the end of the relationship.

[TO BE CONFIRMED: formal frequency of registration review and the name of the internal officer appointed by management to the compliance function.]

4. Personal data protection

The company processes personal data as controller or as processor, as the case may be, observing the principles of purpose, adequacy, necessity, transparency, security and accountability, under Brazilian Law No. 13,709/2018 (General Personal Data Protection Law) and the law applicable in the markets where it operates.

Personal data received from counterparties is used exclusively to perform the contracted service, to comply with a legal or regulatory obligation and for the regular exercise of rights. Access is restricted to persons whose role requires it. Transfer to third parties occurs only where necessary to perform the operation, subject to contractual obligations of confidentiality and equivalent security.

Security incidents that may entail relevant risk or damage to data subjects are reported to the competent authority and to the affected data subjects, within the periods and in the manner required by applicable law. Processing is detailed in the Privacy Policy.

5. Whistleblowing channel

The company maintains a channel for reports of breaches of law, contract or internal policies, including anonymous reports. The channel is available to employees, managers, counterparties and third parties.

Reports received are recorded and investigated by management. Any form of retaliation against a person reporting in good faith is prohibited, even where the investigation concludes that no irregularity occurred. The identity of the reporting person, where disclosed, is treated as confidential and revealed only by order of a competent authority.

[TO BE CONFIRMED: dedicated e-mail address or form for the whistleblowing channel and the internal response deadline, for publication in this section.]

6. Effectiveness and review

These provisions take effect on the date stated at the top of this page and remain in force until revised. Management reviews the content at least once a year and whenever there is a relevant legal or operational change. Each revision receives a new version number and a new effective date.