On this page
Brasil Terras Raras
English

Governance policies

BTR governance is designed to evolve progressively and in proportion to operational complexity, risk, and growth.

Scope, conduct, and technical independence

The policies apply to management, employees, service providers, consultants, partners, and third parties acting on behalf of BTR or maintaining a relevant relationship with its activities.

Conduct must observe legality, integrity, accountability, transparency, technical rigor, respect for people, and long-term interests. Those responsible for technical analyses must have autonomy to issue favorable or unfavorable conclusions regardless of commercial or financial interests.

  • Strategic, technical, commercial, corporate, financial, and personal information must be protected and accessed only by authorized people.
  • Discrimination, harassment, intimidation, and conduct incompatible with a respectful professional environment are not tolerated.
  • Hypotheses, targets, anomalies, and preliminary results must not be communicated as discoveries, resources, or reserves without appropriate technical support.

Anti-corruption, conflicts, and related parties

BTR establishes zero tolerance for corruption, bribery, fraud, and undue advantage. Payments, engagements, and reimbursements must have a legitimate purpose, adequate documentation, and correspondence with real obligations. Gifts, hospitality, travel, sponsorships, or benefits may occur only when reasonable, transparent, and free of any expectation of improper consideration.

Actual or potential conflicts must be disclosed before they influence a decision. When necessary, the affected person must step away from the analysis, negotiation, or approval. Related-party transactions must have an economic rationale, documentation, and justifiable conditions, preserving process independence and the company's interests.

Proportionate risk management

Risk management considers likelihood, potential impact, mitigation capacity, and the relationship between assumed risk and expected value. For material exposures, the guideline is to record origin, possible impacts, prevention or mitigation measures, and the owner responsible for monitoring.

The structure should grow with the materiality of exposures, avoiding both absent controls and structures incompatible with the company's stage.

  • Strategic, technological, regulatory, legal, land, and environmental risks.
  • Technical, operational, financial, and reputational risks.
  • Artificial-intelligence, data-quality and availability, information-security, privacy, supplier, and third-party risks.

Responsible disclosure and non-retaliation

All disclosed information must accurately reflect the effective stage of the company, its technologies, research, analyses, and projects. Communications must distinguish proven information, third-party data, internal analyses, hypotheses, estimates, projections, initiatives under development, and long-term objectives.

Public information found to be incorrect, incomplete, or materially outdated should be assessed for correction, supplementation, or updating. BTR encourages responsible good-faith reporting of violations, provides for confidential and impartial treatment, and does not allow retaliation against anyone who reports suspected misconduct in good faith.

Information security, privacy, and LGPD

Data, systems, models, code, credentials, and strategic information are treated as essential assets. Security guidelines follow confidentiality, integrity, availability, and need-to-know access, with controls proportional to the criticality of each information asset or system.

Personal-data processing must have a legitimate, defined purpose, be limited to what is necessary, and follow applicable law. Data subjects may exercise rights provided by the LGPD through company channels, and new systems and processes should incorporate privacy, security, and access control by design.

  • Access and permission management, multi-factor authentication, and credential policies.
  • Encryption, backups, access logs, monitoring, and system segregation.
  • Updates, recovery, and incident-response procedures.
  • Retention, sharing, updating, and disposal proportional to purpose and legal requirements.

Data governance and responsible AI

Data should have identifiable origin, quality, traceability, legality, versioning, and reproducibility. Public, governmental, academic, orbital, private, licensed, proprietary, and field sources must be used according to their licenses and restrictions.

Artificial intelligence complements technical analysis and human oversight. Models should pursue traceability, explainability, data quality, validation, security, version history, error analysis, and specialist review.

Procurement, remuneration, and policy review

Purchasing and engagements should consider need, quality, technical capacity, deadlines, cost, security, and integrity. Material engagements should have a defined scope, documented terms, and assessment proportionate to materiality and risk.

Remuneration may combine fixed, variable, and long-term incentive components without pressuring technical conclusions to depend on positive outcomes. Evidence quality, integrity, and reliability prevail over commercial expectations.

Policies may be reviewed as activities, regulation, expansion, and risks evolve. New procedures, approval authorities, controls, and governance bodies should track BTR's operational complexity.