← Back to Policies

Whistleblower Policy

Whistleblower Policy

Policy Owner: Daniel Peixoto
Effective Date: Sep 24, 2026

Purpose

To encourage and enable employees, contractors, and third parties to raise serious concerns internally so that Straloo Tecnologia LTDA can address and correct inappropriate conduct and actions before they cause harm to individuals, customers, or the company.

This policy formalizes the reporting channels available for those concerns — including an anonymous channel — and establishes the company's commitment that no one who reports in good faith will suffer retaliation.

Scope

This policy applies to all Straloo Tecnologia LTDA employees, contractors, consultants, temporary workers, interns, and other personnel, as well as to customers, suppliers, and any other third party wishing to raise a concern about the company.

It covers concerns of any kind about conduct that is illegal, unethical, or in violation of company policy. Concerns that are purely technical security events or incidents should additionally be reported through the channels in the Incident Response Plan so that they enter the incident response process.

What to report

It is the responsibility of all personnel to report concerns about violations of our Code of Conduct or suspected violations of the laws or regulations that govern our operations.

Reportable concerns include, but are not limited to:

  • Fraud, theft, bribery, corruption, or misuse of company or customer funds or assets.
  • Falsification, alteration, or destruction of company records, contracts, financial statements, or audit evidence.
  • Discrimination, harassment, retaliation, or other violations of the Code of Conduct.
  • Breaches of information security or data privacy obligations, including mishandling of personal or health data, and misrepresentation of the company's security or compliance posture.
  • Deliberate circumvention of security controls, or pressure on personnel to circumvent them.
  • Conflicts of interest that are undisclosed or improperly managed.
  • Any danger to the health or safety of an individual.
  • Concealment of any of the above.

Reports should be made in good faith. A report made in good faith is one the reporter reasonably believes to be true at the time it is made; a report does not need to be proven correct to be protected under this policy. Knowingly making a false or malicious report is itself a violation of this policy.

Reporting channels

Concerns may be raised through any of the following channels. Reporters may choose whichever channel they are most comfortable with, and are not required to raise the concern with their manager first.

ChannelHow to use itAnonymous
Direct to leadershipNotify any member of Straloo Tecnologia LTDA leadership in person or in writingNo
Emaildaniel@straloo.com.brNo
Anonymous whistleblower formhttps://forms.gle/y5PaTbs1ySW6FqXm8Yes

The anonymous whistleblower form is linked from our website and is available to personnel and to external parties. It does not collect the submitter's identity, email address, or IP address, and the company does not attempt to determine the identity of an anonymous reporter.

Reports should act as a good witness: include specific details of what was observed or discovered, the people and systems involved, the dates and times, and any supporting evidence. Anonymous reporters are encouraged to provide enough detail for the concern to be investigated without follow-up questions, since the company will have no way to contact them.

Confidentiality

The identity of a reporter who identifies themselves will be treated as confidential and shared only with those who need it to investigate or resolve the concern, or where disclosure is required by law or by a regulator.

Reports and investigation records are treated as confidential information and are handled in accordance with the Data Management Policy.

Non-retaliation

It is contrary to our values for anyone to retaliate against any person who in good faith reports an ethics violation, or a suspected violation of law or regulation, such as a complaint of discrimination, suspected fraud, or a suspected violation of any regulation.

The same protection extends to anyone who participates in the investigation of a report, including as a witness.

Retaliation includes dismissal, demotion, suspension, loss of benefits, reassignment, reduction in wages or hours, negative performance evaluation, exclusion, threats, and intimidation, whether carried out by a manager, a peer, or anyone acting on their behalf.

Anyone who retaliates against a person who has reported a concern in good faith is subject to discipline up to and including termination of employment or contract. Anyone who believes they have suffered retaliation should report it through the channels above; a retaliation complaint is itself a reportable concern under this policy.

Handling and investigation

The Policy Owner is responsible for receiving reports, for maintaining the anonymous channel, and for ensuring each report is handled under this policy.

  1. Acknowledge. Reports that include contact details are acknowledged within five business days. Anonymous reports cannot be acknowledged and proceed directly to triage.
  2. Triage. The Policy Owner assesses the nature and seriousness of the concern and determines whether it must also be handled as a security or privacy incident under the Incident Response Plan, or as a personnel matter under the Human Resource Security Policy.
  3. Assign. An investigator with no conflict of interest in the matter is assigned. Where the concern involves the Policy Owner, or where an independent review is otherwise warranted, the investigation is escalated to the company's leadership excluding the person concerned, and external counsel may be engaged.
  4. Investigate. The investigator gathers and preserves evidence, interviews relevant parties, and documents findings. Anyone subject to an allegation is given a fair opportunity to respond before conclusions are reached.
  5. Resolve. Substantiated concerns result in corrective action, which may include disciplinary action up to and including termination, changes to controls or processes, contractual action against a third party, and notification to customers, regulators, or law enforcement where required.
  6. Close and report back. The outcome is recorded and, where the reporter is identifiable, they are informed that the matter has been concluded to the extent that confidentiality and legal constraints permit.

Records and review

Records of reports, investigations, and outcomes are retained for the period defined in the Data Management Policy retention matrix and are stored with access restricted to those involved in handling them.

The Policy Owner reports a summary of the volume and nature of reports, and any resulting corrective actions, to leadership at least annually. This policy and the operation of the reporting channels are reviewed at least annually.

Exceptions

Requests for an exception to this policy must be submitted to the IT Manager for approval.

No exception may remove or restrict a person's access to the reporting channels described in this policy, or limit the non-retaliation protections above.

Violations & enforcement

Any known violations of this policy should be reported to the IT Manager.

Violations of this policy can result in immediate withdrawal or suspension of system and network privileges and/or disciplinary action in accordance with company procedures up to and including termination of employment.

Version history

VersionDateDescriptionAuthorApprover
1.0Sep 24, 2026Version 1.0Daniel PeixotoDaniel Peixoto