Internal document

code of Conduct

This Code defines the standards of conduct expected of employees, service providers, suppliers, partners and anyone acting on behalf of PangeaPay. It's not just a list of rules: it's the way we decide when no one is looking.

Last updated: April 2026

1. Purpose

PangeaPay was created to give financial freedom to Brazilian people and companies with a fair exchange rate, without bureaucracy and without unnecessary intermediaries. This purpose only works if customer trust and respect for the legal framework come before everything else.

This Code exists to make clear what we expect from those who work with us, in any role.

2. Who needs to follow

This Code applies to all PangeaPay employees (CLT, PJ, interns, temporary employees), advisors, directors and service providers who act on behalf of the company. We also expect partners and suppliers to adopt compatible standards in their relationships with us.

3. Values ​​that guide conduct

Five things we don't negotiate:

  • Customer first — difficult decisions are resolved by asking what is best for the customer.
  • Radical transparency — honest communication, public post-mortem when something goes wrong, without making up numbers.
  • Regulatory discipline — we operate within the law, even when it is slower or more expensive.
  • Technical excellence — quality of the code, operation and product always matters.
  • Unconditional respect — no one here is less important than anyone else.

4. Professional conduct

We expect professionalism, honesty and responsibility in every interaction. Comply with the agreement, communicate changes in advance, admit mistakes and offer solutions.

Drinking, illicit drugs or any behavior that impairs judgment and safety has no place during working hours or on behalf of the company.

5. Conflicts of interest

Conflicts of interest occur when personal interests (financial, family, emotional) can influence professional decisions. Whenever there is doubt, state it. Declaring is not a problem, hiding is.

Examples: hiring a relative or close friend as a supplier; invest in a competitor, partner or counterparty company; receive a gift of relevant value from a supplier; have external activity that competes with PangeaPay.

6. Anti-corruption and anti-bribery

We do not offer, promise, authorize or accept undue advantage, direct or indirect, to a public agent, private agent or any third party for the purpose of obtaining or maintaining business. We comply with the Anti-Corruption Law (Law 12,846/13) and international good practices such as FCPA and UK Bribery Act.

Symbolic gifts of moderate value, in the context of legitimate courtesy, are permitted. If in doubt, consult the Compliance Officer before accepting or offering.

7. Confidentiality and data protection

PangeaPay's customer information, financial, strategic, operational and technical data are confidential. Do not share outside the company or with colleagues who do not have a legitimate need for access.

We process personal data in accordance with the LGPD (Law 13,709/18). Access to customer data is restricted to the minimum necessary, recorded in the audit log and audited periodically.

The obligation of confidentiality remains after the termination of the relationship with the company.

8. Diversity, respect and safe environment

We do not tolerate discrimination based on race, color, ethnicity, origin, gender, sexual orientation, gender identity, age, religion, disability, social status or any other characteristic protected by law.

Moral harassment, sexual harassment, bullying, intimidation or any form of violence are absolutely unacceptable and entail serious sanctions, including dismissal for just cause.

We have built an environment where disagreement is welcome, as long as it is respectful.

9. Information security

Follow internal information security policies: password manager, multi-factor authentication, device encryption and principle of least privilege. Never share credentials. Immediately report any suspected incident, such as phishing, lost device or improper access, to the security team.

Critical: No single person can move customer bookings. Sensitive operations require multiple approvers and immutable logging.

10. Use of company resources

Company tools, equipment, data and time must be used for professional purposes. Occasional and reasonable personal use is tolerated, as long as it does not harm work or operational safety.

We do not use PangeaPay resources for partisan political activity, personal trading of crypto assets based on privileged information, or for any illicit purpose.

11. Relationship with partners and suppliers

We select partners and suppliers based on technical, commercial and ethical criteria. We expect them to adopt integrity standards compatible with ours. We contract with transparency, avoid exclusivities that limit healthy competition and require compliance with labor, tax and regulatory obligations.

12. External communication and social media

Only authorized spokespersons can speak on behalf of PangeaPay to the press, regulators and the market. On personal social networks, make it clear that your opinions are yours and do not represent the company. Do not comment on the roadmap, non-public financial numbers or strategy on external channels.

13. Reporting channel

If you see or suspect a violation of this Code, the law or internal policies, report it. Reports can be anonymous and are treated confidentially.

Available channels: email compliance@pangeapay.org, internal ombudsman or any leadership you trust. We do not tolerate reprisals against anyone who reports in good faith.

14. Consequences of non-compliance

Violations of this Code may result in warning, suspension, dismissal for just cause, termination of a contract with a supplier or partner and civil and criminal liability, depending on the severity. Sanctions are proportional to the impact and recurrence.

15. Questions

If you have doubts about what is the right thing to do in a specific situation, ask first. Look for your leadership or the Compliance Officer. In sensitive cases, write to compliance@pangeapay.org.

Do you want to report something?

Reporting channel.

Reports can be anonymous. We do not tolerate reprisals against anyone who reports in good faith.

compliance@pangeapay.org