Declaration of Compliance

Effective Date: May 20, 2025

Cacao Financial Holdings Limited (Cayman Islands), operating through its subsidiary Ruvo Financial Inc. (Delaware, USA)

Ruvo's Declaration of Compliance in Brazil

Ruvo is an international platform operated by Cacao Financial Holdings Limited, registered in the Cayman Islands, and its subsidiary Ruvo Financial Inc., in the United States. The company does not have a legal entity or banking operation in Brazil.

Financial services offered to Brazilian users are exclusively provided by licensed partners:

  • Blindpay: Financial intermediary responsible for Pix ramps, virtual accounts, and fiduciary operations. Operates according to Central Bank Resolution nº 175/2024, with subcontracting of regulated institutions.
  • Crossmint: Provider of non-custodial wallets operating on public blockchain networks. Assets are exclusively controlled by users, without Ruvo's access.
  • Rain Cards: Issuance of virtual Visa cards based in the USA. Regulated according to PCI DSS requirements and licensed BIN sponsors.
  • Persona: Global identity verification provider, with sanctions lists, OCR, biometrics, and document validation in compliance with LGPD, FATF, and OFAC standards.

Ruvo fully complies with the following applicable Brazilian legislation:

  • • Law nº 13.709/2018 (LGPD - General Data Protection Law)
  • • Consumer Protection Code (Law nº 8.078/1990)
  • • Extraterritorial regulations related to digital advertising, data collection, and online service provision

Practices adopted for compliance:

  • • Privacy policy and terms in accessible Portuguese
  • • Customer service in Portuguese with a dedicated channel (email: ajuda@ruvo.com)
  • • Total transparency of fees and resources
  • • Express consent for data use and processing
  • • Anti-fraud monitoring, transaction logs, and mandatory KYC

Data Management and Exclusion

Ruvo is committed to providing users with total transparency and control over their personal data. This section describes the data processed and how users can manage it, in compliance with LGPD and global best practices.

What Data We Collect and Why

To provide secure and compliant services, we collect and process the following categories of data:

  • Identity Verification Data: Name, date of birth, government-issued ID (RG, CNH, or Passport), and biometric data (selfie) provided during KYC (Know Your Customer) verification via our partner Persona.
  • Contact Information: Email address and phone number for account communication and security.
  • Transactional Data: Details of your financial operations, including amounts, dates, and counterparties, as necessary for anti-money laundering (AML) monitoring.
  • Device and Usage Data: Information about the device you use to access Ruvo, such as IP address and browser type, to prevent fraud and improve our services.

How to Request Access to Your Data

You have the right to request a copy of the personal data we hold about you. To do so, please follow these steps:

  • 1. Send an Email: Draft an email to ajuda@ruvo.com from the email address associated with your Ruvo account.
  • 2. Use the Subject Line: 'Data Access Request'.
  • 3. Verify Your Identity: For your security, we may ask for additional information to confirm your identity before processing the request.
  • 4. Receive Your Data: We will provide a copy of your data in a portable, machine-readable format within 15 days, as mandated by the LGPD.

How to Request Exclusion of Your Data

You have the right to request the deletion of your account and personal data. Please note that due to regulatory obligations (such as anti-money laundering laws and tax regulations), we are required to retain certain transactional and identification data for a legally mandated period, even after your account is closed. This data will be securely stored and will not be used for any other purpose.

  • 1. Send an Email: Draft an email to ajuda@ruvo.com from the email address associated with your Ruvo account.
  • 2. Use the Subject Line: 'Data Deletion Request'.
  • 3. Confirmation: Our team will contact you to confirm your request and explain the implications, including the data that must be retained for legal reasons.
  • 4. Account Deletion: Upon confirmation, we will proceed with deleting your account and all personal data that is not subject to mandatory legal retention. You will receive a final confirmation once the process is complete.

Additional Support

If you need additional support, have regulatory questions, or wish to exercise your rights, please contact our compliance channel: ajuda@ruvo.com.