Compliance Policy

Last updated: June 15, 2026

Overview

Bruxus is committed to operating with integrity, transparency, and in full compliance with all applicable laws and regulations. This Compliance Policy establishes the framework for our compliance program.

Regulatory Framework

Bruxus complies with the following regulatory requirements:

  • GDPR — General Data Protection Regulation (EU)
  • LGPD — Lei Geral de Proteção de Dados (Brazil)
  • CCPA/CPRA — California Consumer Privacy Act (USA)
  • COPPA — Children’s Online Privacy Protection Act (USA)
  • ADA/WCAG — Accessibility standards
  • PCI DSS — Payment Card Industry Data Security Standard (where applicable)

Compliance Program

Governance

Our Compliance Committee, comprising legal, security, and executive leadership, oversees the compliance program and meets quarterly to review policies and incidents.

Policies & Procedures

We maintain written policies covering:

  • Data protection and privacy
  • Information security
  • Acceptable use
  • Anti-corruption and anti-bribery
  • Conflict of interest
  • Export controls and sanctions
  • Whistleblower protection

Training

All employees complete annual compliance training covering:

  • Data protection principles
  • Security awareness
  • Anti-corruption practices
  • Code of conduct

Monitoring & Auditing

  • Regular internal audits of compliance controls
  • Third-party compliance assessments
  • Automated monitoring for policy violations
  • Annual SOC 2 Type II audit

Reporting Violations

Employees, partners, and users can report compliance concerns through:

Non-Retaliation

Bruxus prohibits retaliation against any individual who reports a compliance concern in good faith or participates in an investigation.

Enforcement

Violations of this policy may result in disciplinary action, up to and including termination of employment or business relationship.

Contact

For compliance-related inquiries, contact compliance@bruxus.com.