Anti-Money Laundering and Counter-Terrorism Financing Policy
Anti-Money Laundering and Counter-Terrorism Financing Policy
Policy Owner: Daniel Peixoto
Effective Date: Sep 24, 2026
Purpose
To prevent Straloo Tecnologia LTDA's business, accounts, products, and relationships from being used to launder money, to finance terrorism, or to finance the proliferation of weapons of mass destruction (PLD/FTP), and to define the controls through which the company identifies and escalates those risks.
Scope
This policy applies to all Straloo Tecnologia LTDA employees, contractors, consultants, temporary workers, interns, officers, and partners (sócios), and to all of the company's commercial relationships — customers, suppliers, subprocessors, partners, intermediaries, and investors — and to all funds the company receives or pays.
Regulatory position
Straloo Tecnologia LTDA is a digital health company. It is not a financial institution and is not a regulated obliged entity (pessoa obrigada) under article 9 of Lei 9.613/1998, and therefore has no standing COAF reporting or registration obligation in that capacity.
The prohibitions in Lei 9.613/1998 and Lei 12.683/2012 nevertheless apply to the company and to every person in scope of this policy, as do applicable sanctions regimes. The company therefore maintains the risk-based, proportionate controls set out below, and will report to the competent authorities where the law requires it or where the circumstances warrant it.
Should the company's activities change such that it becomes an obliged entity, this policy and its controls shall be revised before those activities begin.
Prohibited conduct
The following are strictly prohibited, with no exceptions:
- Concealing or disguising the nature, origin, location, disposition, movement, or ownership of assets derived directly or indirectly from a criminal offence.
- Receiving, holding, using, converting, transferring, or otherwise handling assets known or suspected to be the proceeds of crime.
- Providing, collecting, or making available funds or resources for terrorism, for a terrorist organisation or individual, or for the proliferation of weapons of mass destruction.
- Entering into or maintaining a relationship with a person or entity subject to applicable sanctions.
- Structuring, splitting, or otherwise arranging transactions to avoid a control, threshold, or reporting requirement.
- Assisting, facilitating, or counselling any of the above, or ignoring evidence of it.
Wilful blindness is not a defence. A person who suspects that a transaction or counterparty involves the proceeds of crime shall escalate rather than proceed.
Know your counterparty
Before entering a commercial relationship, and proportionate to its risk, the company shall establish and record:
- The counterparty's legal identity — corporate name, CNPJ or CPF, and address — verified against reliable documentation or an official register.
- Its ownership and control, including the ultimate beneficial owners holding 5% or more, and its legal representatives and administrators.
- The nature of its business and the economic rationale for the relationship.
- Whether the counterparty, its owners, or its representatives are Politically Exposed Persons, or are connected to one.
Counterparty information shall be refreshed periodically and whenever ownership, control, or the risk profile changes. The company shall not enter or maintain a relationship where the counterparty refuses to provide this information, where its ownership cannot be established, or where the stated business rationale is not credible.
This assessment is performed alongside the supplier and subprocessor evaluation required by the Third-Party Management Policy.
Sanctions and watchlist screening
Counterparties, their beneficial owners, and their legal representatives shall be screened against applicable sanctions and restricted-party lists before onboarding and periodically thereafter.
A confirmed match shall result in the relationship being declined or suspended, and shall be escalated immediately to the Policy Owner, who determines any reporting obligation. Personnel shall not notify the counterparty of the reason.
Politically Exposed Persons
A relationship involving a Politically Exposed Person, a person who has held relevant public office within the last five years, or a close family member or associate of either, shall be approved by the Policy Owner before it is entered, subject to enhanced scrutiny of the source of funds, and reviewed at least annually.
PEP status shall also be disclosed under the Conflict of Interest Policy.
Payments and funds
- Payments shall be made and received only through the company's own bank accounts, and only to and from accounts held in the counterparty's own name.
- The company does not accept payment in cash, in cryptocurrency, or from an unidentified third party.
- The company does not accept payment from, or make payment to, a jurisdiction unconnected to the counterparty's business without documented justification approved by the Policy Owner.
- Every payment shall be supported by a contract or invoice describing the goods or services actually provided, and recorded in accordance with the books-and-records requirements of the Anti-Corruption and Anti-Bribery Policy.
- Refunds and overpayments shall be returned to the originating account only.
Red flags
The following warrant escalation to the Policy Owner before proceeding:
- A counterparty that is reluctant to identify its beneficial owners, or whose ownership runs through opaque structures or jurisdictions with no connection to its business.
- Payment offered in cash, in cryptocurrency, from a third party, from multiple accounts, or from an unexpected jurisdiction.
- Overpayment followed by a request for a refund to a different account.
- A transaction with no apparent economic or lawful purpose, or one inconsistent with the counterparty's stated business.
- Unusual urgency, or pressure to bypass onboarding or approval steps.
- A counterparty appearing on a sanctions or restricted-party list, or adversely reported in credible media for financial crime.
- A request to split a payment, to invoice for something other than what was supplied, or to misdescribe the service.
Reporting and escalation
Any suspicion arising under this policy shall be reported immediately to the Policy Owner at daniel@straloo.com.br, or through the channels in the Whistleblower Policy, including the anonymous channel at https://forms.gle/y5PaTbs1ySW6FqXm8.
The Policy Owner assesses each report, determines whether the relationship or transaction must be suspended, and determines whether a report to COAF, the Polícia Federal, the Ministério Público, or another competent authority is required or appropriate. Where the company reports, it cooperates fully with the authority.
Personnel shall not disclose to the counterparty, or to anyone outside the escalation, that a suspicion has been raised or a report made.
Reports made in good faith are protected from retaliation under the Whistleblower Policy.
Records
Counterparty identification and verification records, screening results, escalations, and the rationale for decisions taken under this policy shall be retained for at least five years from the end of the relationship or the date of the transaction, whichever is later, and handled in accordance with the Data Management Policy.
Training and awareness
Personnel involved in onboarding counterparties, contracting, invoicing, or handling payments receive guidance on this policy on joining and periodically thereafter, as part of the awareness programme described in the Human Resource Security Policy.
Monitoring and review
Money laundering, terrorism financing, and proliferation financing risks are assessed within the process defined in the Risk Management Policy. This policy is reviewed at least annually, and whenever the company's activities, counterparties, or applicable law change materially.
Exceptions
Requests for an exception to this policy must be submitted to the IT Manager for approval.
No exception may be granted to the prohibitions in "Prohibited conduct" or to the sanctions screening requirement.
Violations & enforcement
Any known violations of this policy should be reported to the IT Manager, or through the channels in the Whistleblower Policy.
Violations of this policy can result in immediate withdrawal or suspension of system and network privileges and/or disciplinary action in accordance with company procedures up to and including termination of employment, termination of a commercial relationship, and referral to the competent authorities.
Version history
| Version | Date | Description | Author | Approver |
|---|---|---|---|---|
| 1.0 | Sep 24, 2026 | Version 1.0 | Daniel Peixoto | Daniel Peixoto |