A360 Social and Governance Policy

1. Our commitment

A360 DOO BEOGRAD (“A360”, “we”, “us” or “our”) is committed to respecting people, conducting business with integrity and maintaining governance appropriate to a specialist payment-software company. Trust in our work depends not only on reliable technology, but also on fair employment, responsible innovation, accountable decisions, effective risk management and transparent relationships with clients, partners and other stakeholders. Our objective is to create sustainable long-term value through capable people, ethical conduct, responsible technology, clear accountability and continuous improvement.

2. Purpose and scope

This public policy summarises A360’s principal social and governance commitments. It is intended for employees, candidates, clients, suppliers, business partners and the general public. It applies to activities under A360’s control and is supported by detailed internal policies, procedures, contracts, risk records and management-system controls. This policy does not replace applicable law, employment terms, client agreements or controlled internal documents. Where a stricter legal, contractual, regulatory or professional requirement applies, that requirement takes precedence. A360 seeks to apply recognised responsible-business principles in a manner proportionate to its size, activities, risk profile and influence.

3. Our social principles

  • Human rights and dignity: respect internationally recognised human rights and prohibit forced labour, child labour, human trafficking, harassment and degrading treatment.
  • Fair and inclusive employment: provide equal opportunity, objective employment decisions, lawful working conditions and a workplace free from discrimination and retaliation.
  • Health, safety and well-being: maintain safe working practices, reasonable work organisation and appropriate support for physical and mental well-being.
  • Skills and development: invest in professional competence, awareness, knowledge sharing and responsible career development.
  • Accessibility and inclusion: consider diverse users and accessibility in workplace practices, communications and product design where applicable.
  • Community and financial inclusion: recognise the role that secure and accessible digital payments can play in economic participation and resilient communities.

4. Our governance principles

  • Accountability and oversight: assign clear decision, risk and control ownership, with management challenge and independent assurance where appropriate.
  • Integrity and lawful conduct: prohibit bribery, corruption, fraud, conflicts of interest, retaliation and misleading or anti-competitive practices.
  • Risk-based governance: apply controls proportionate to material risks, including technology, privacy, security, resilience, suppliers and regulatory obligations.
  • Transparency and traceability: maintain reliable records of material decisions, approvals, incidents, audits, risks and corrective actions.
  • Responsible value chain: set proportionate ethical, social, security and governance expectations for relevant suppliers and partners.
  • Evidence-based improvement: use feedback, monitoring, audits, incidents and stakeholder expectations to improve performance and public reporting.

5. Human rights and fair employment

A360 respects fundamental human rights and seeks to align its practices, where relevant, with recognised principles such as the Universal Declaration of Human Rights, the International Labour Organization’s fundamental principles and the UN Guiding Principles on Business and Human Rights. This commitment is implemented through lawful recruitment, clear employment terms, confidentiality and security obligations, role-appropriate screening, fair treatment and controlled offboarding. A360 does not tolerate forced labour, child labour, human trafficking, retention of identity documents for coercive purposes or abusive employment practices. Working hours, compensation, leave and employment conditions are managed in accordance with applicable law and contractual commitments. Material concerns involving A360 or a relevant business partner may lead to review, remediation, contractual action or termination of the relationship.

6. Equality, inclusion and accessibility

Employment, assignment, development and progression decisions are based on lawful, objective and role-relevant criteria. Discrimination, harassment, bullying, threats and degrading behaviour are prohibited. A360 values different backgrounds, professional perspectives and cultures, and aims to provide an environment in which people can contribute, learn and raise concerns without fear of retaliation. Where appropriate to the product, service and client context, A360 considers usability and accessibility so that technology and communications can serve a diverse range of users. Accessibility requirements are addressed through stakeholder engagement, documented requirements, design, testing and continuous improvement rather than unsupported public claims.

7. Health, safety and well-being

  • Safe working conditions: follow applicable workplace health and safety requirements and report hazards, incidents or unsafe conditions promptly.
  • Preparedness and continuity: consider employee safety, availability and alternative working arrangements in continuity and incident-response planning.
  • Responsible work organisation: promote respectful management, clear priorities, reasonable workloads and communication when health or availability may affect performance.
  • Remote and hybrid work: apply appropriate security, privacy, communication and ergonomic practices outside A360 premises.

8. Learning and professional development

A360 provides role-appropriate training and awareness on professional conduct, information security, privacy, operational resilience, software quality and relevant regulatory obligations. Specialist roles receive additional training where needed. Completion and effectiveness may be recorded and reviewed, while personnel are encouraged to maintain competence and share knowledge responsibly.

9. Clients, communities and financial inclusion

A360 seeks long-term relationships based on trust, quality, transparency and mutual success. We protect confidential information, respect intellectual property and avoid commitments that cannot be responsibly fulfilled. Through secure, reliable and configurable payment technology, A360 aims to help clients provide efficient digital services and, where relevant, support broader access to the digital economy. Community or social-impact statements are made only where the contribution and evidence can be clearly demonstrated.

10. Governance and accountability

The Director and management are accountable for setting direction, approving key policies and ensuring that appropriate responsibilities and resources are assigned. Operational owners implement controls in their areas. Risk, compliance, information-security and other oversight functions provide advice, challenge and monitoring, while internal audit provides independent assurance where applicable. Material decisions are made by authorised persons, supported by relevant information and documented in proportion to risk. Governance arrangements include defined responsibilities, segregation of duties, escalation paths, meeting records, action tracking and periodic review of unresolved matters. Where the organisation’s size limits structural separation, documented compensating controls are used.

11. Ethics, integrity and fair business

  • Anti-bribery and anti-corruption: do not offer, request, authorise or accept improper benefits intended to influence a business or official decision.
  • Conflicts of interest: avoid, disclose and appropriately manage actual, potential or perceived conflicts between personal interests and A360 responsibilities.
  • Fair competition and dealing: communicate honestly and do not misuse confidential information, coordinate anti-competitive conduct or misrepresent products, capabilities or results.
  • Accurate records: maintain complete and reliable business, technical, financial and control records and never conceal or falsify material information.
  • Applicable restrictions: observe sanctions, export-control and financial-crime requirements where they apply to A360’s activities, clients, jurisdictions or partners.

12. Risk management, compliance and assurance

A360 applies structured processes to identify, assess, treat, monitor and report material risks. Particular attention is given to information security, privacy, operational resilience, software quality, regulated client environments and third parties. Controls are reviewed through management oversight, monitoring, testing, audit and corrective-action processes. A360 maintains policies supporting applicable laws, contracts, ISO management-system requirements and DORA-related obligations relevant to its activities. Nonconformities, incidents, audit findings and control gaps are assigned to responsible owners and tracked until remediated, otherwise resolved or formally accepted by authorised management.

13. Responsible technology and product stewardship

A360 integrates security, privacy, quality, resilience and human oversight into the software lifecycle. New technology and automation, including artificial intelligence, are assessed for business purpose, accuracy, security, privacy, intellectual property, bias, explainability and potential adverse impact before material use. Technology must support accountability and professional judgement, not weaken them. Product and service claims must be accurate and supportable. A360 seeks to design solutions that are reliable, maintainable, scalable and suitable for regulated payment environments, while clients retain responsibility for their own use, configuration, infrastructure and legal obligations as defined by contract.

14. Suppliers and business partners

A360 selects and manages relevant third parties using proportionate due diligence, contractual requirements and ongoing oversight. Assessment may cover competence, financial and operational reliability, information security, privacy, continuity, ethical conduct, human rights, labour practices, environmental responsibility and regulatory obligations. High-risk or material relationships may require additional evidence, monitoring or corrective action. Third-party access is authorised, limited, monitored and removed when no longer required. A360 expects relevant partners to prohibit bribery, forced or child labour, discrimination and retaliation, and to protect confidential information and personal data. Serious or unresolved breaches may result in suspension, remediation, contractual remedies or termination.

15. Data protection, security and operational resilience

Governance of information and technology is central to A360’s business. We apply secure development, controlled change, access management, information classification, logging, vulnerability management, incident response, backup and continuity practices proportionate to the systems and services involved. Personal data is processed lawfully and protected through appropriate technical and organisational measures. A360 maintains preparedness for disruptions affecting people, technology, suppliers or facilities. Incidents and exercises are documented, lessons are reviewed and corrective actions are tracked. Public statements regarding security, resilience or compliance are limited to information that can be responsibly disclosed and supported by evidence.

16. Speak up, grievances and non-retaliation

Employees, contractors, candidates, suppliers and other stakeholders are encouraged to seek guidance or report suspected misconduct, discrimination, human-rights concerns, conflicts of interest, fraud, security issues or material non-compliance. Concerns may be raised through a manager, the relevant internal function or another designated A360 channel. A360 does not tolerate retaliation against a person who raises a concern, requests guidance or participates in a review in good faith. Reports are handled as confidentially as reasonably possible, assessed objectively and reviewed by appropriately authorised persons. Outcomes may include remediation, disciplinary or contractual measures, control improvements, notification to affected parties or reporting to competent authorities where required. Deliberately false reports may themselves constitute misconduct.

17. Objectives, stakeholder engagement and transparency

A360 may establish social and governance objectives and indicators proportionate to material risks, stakeholder needs and available evidence. Examples include training completion, employee concerns and resolution, audit and corrective-action status, risk treatment, supplier reviews, access reviews, continuity exercises, policy acknowledgements and accessibility or quality improvements. Relevant stakeholder feedback from employees, clients, partners, auditors and other parties is considered in policy and control reviews. Public metrics, commitments and impact statements are issued only when their scope, methodology, reliability, limitations and approval are understood. A360 does not claim certifications, representation, diversity outcomes, community impact or ESG performance that it cannot substantiate.

18. Contact A360

Questions, suggestions or concerns regarding this Social and Governance Policy may be submitted to A360 using the contact details below. A360 DOO BEOGRAD Vladimira Popovića 6, sprat 5, stan A 504, 11070 Beograd, Serbia Email: office@a-360.net Website: www.a-360.net

19. Review and publication

This public policy is reviewed at least annually and may be updated earlier to reflect changes in law, stakeholder expectations, organisational arrangements, risk or business practices. The current approved version will be published on the A360 website. Version 1.1. Last updated: 5 August 2026.