SPENDBASE CODE OF CONDUCT

Version 15 April 2026

1. Purpose and Scope

This Code of Conduct (the “Code”) sets mandatory standards for how Spendbase and its affiliates conduct business. It applies to all directors, officers, employees, and contractors (“Personnel”) across all products, functions, and jurisdictions.

Spendbase is committed to conducting its business with integrity, transparency, and accountability. This Code of Conduct reflects the standards that govern our decisions, operations, and relationships with customers, partners, and regulators.

The Code is binding. Compliance is a condition of engagement. Personnel must act within defined authority and comply with all applicable laws, regulations, contractual obligations, and internal policies. Where requirements differ, the stricter standard applies. No Personnel has authority to approve, direct, or permit conduct that breaches this Code.

The Code governs all business activities, including product development, customer interactions, financial operations, use of company systems, and third-party engagements. Company resources, including data and infrastructure, may be used only for authorized business purposes.

Personnel must exercise sound judgment. Any situation involving legal, regulatory, or reputational risk must be assessed and escalated before action is taken. Circumventing controls, acting outside approved processes, or relying on informal arrangements is not permitted.

Managers are responsible for ensuring the effective implementation of this Code within their teams. Failure to supervise, escalate, or address misconduct constitutes a breach.

Violations may result in disciplinary action, including termination, and may be reported to regulators or law enforcement where required.

Spendbase expects its partners, vendors, and other third parties acting on its behalf to adhere to standards consistent with this Code. Such requirements are implemented through contractual obligations and oversight. Customers are expected to comply with applicable terms governing the use of Spendbase products and services.

2. Governance and Accountability

Spendbase maintains a governance framework with defined authority, oversight, and independent control functions.

The Board oversees material risks and ensures the company operates within legal and regulatory boundaries. Senior management is responsible for implementation and for ensuring that commercial objectives do not override compliance obligations.

Legal and Compliance establish policies, monitor adherence, and investigate potential breaches. Their authority must not be bypassed or limited.

All Personnel are accountable for actions within their role and must act within delegated authority. Known issues must be escalated without delay. Failure to escalate or withholding information constitutes a breach. Accountability applies at all levels of the organization, regardless of seniority, function, or commercial responsibility.

Spendbase maintains a risk-based compliance program, including training, monitoring, and internal controls designed to ensure effective implementation of this Code.

3. Compliance with Laws and Regulatory Obligations

Spendbase conducts its business in accordance with applicable laws, regulations, and contractual obligations in each jurisdiction where it operates. Personnel must ensure that their activities comply with all requirements relevant to their role.

No product, service, or material change may be introduced without required internal approvals and, where applicable, regulatory assessment. Legal and Compliance must be engaged where activities involve regulatory interpretation, licensing considerations, or cross-border impact.

All communications, representations, and business practices must be accurate, complete, and not misleading. Personnel must not misrepresent products, capabilities, performance, or relationships with partners or regulators, or omit material information in a manner that creates a misleading impression.

Any interaction with regulators, supervisory authorities, or law enforcement must be coordinated through Legal or Compliance. Personnel are not permitted to respond independently unless authorized.

Where requirements are unclear or risks are identified, the matter must be escalated before action is taken.

Compliance obligations apply regardless of commercial priorities, timelines, or internal pressures.

4. Integrity of Operations and Internal Controls

Spendbase maintains systems and controls to ensure that all activities are authorized, properly executed, and capable of verification. Personnel must follow established processes and must not bypass, override, or otherwise undermine controls.

All transactions and business activities must be accurately recorded, supported by appropriate documentation, and completed through approved systems. Informal arrangements, side agreements, or off-system activity are not permitted.

Errors, discrepancies, or irregularities must be identified and escalated without delay. Concealment, mischaracterization, or delayed reporting of issues constitutes a breach.

Access to systems, data, and financial resources must be used strictly within assigned authority. Personnel must not act beyond delegated limits or use company assets for unauthorized purposes.

Managers are responsible for maintaining effective oversight, including appropriate segregation of duties and adherence to control processes within their teams.

5. Conflicts of Interest

Personnel must act in the best interests of Spendbase and must not allow personal interests to interfere with their professional responsibilities.

Any actual or potential conflict of interest must be disclosed before action is taken. This includes financial interests, outside business activities, personal relationships, or any situation that may influence, or appear to influence, objective decision-making.

Personnel must not use their position, access to information, or company resources for personal benefit or for the benefit of related parties. Participation in decisions where a conflict exists is not permitted unless formally reviewed and approved.

All conflicts must be managed in accordance with internal procedures. Failure to disclose or appropriately manage a conflict constitutes a breach of this Code. The same standard applies where a situation creates a reasonable appearance of compromised judgment, even if no improper conduct occurs. Conflicts must be managed proactively to preserve objectivity, independence, and trust in decision-making.

6. Anti-Corruption and Improper Conduct

Spendbase prohibits bribery, corruption, and any form of improper influence. Personnel must not directly or indirectly, including through third parties or intermediaries, offer, promise, give, request, or accept anything of value intended to obtain or retain business, secure an advantage, or influence a decision.

Gifts, hospitality, and entertainment must be reasonable, lawful, and proportionate, and must not influence, or appear to influence, business decisions. Any such benefit must comply with internal policies and approval requirements.

Interactions with government officials require heightened scrutiny. Any benefit offered or provided to a government official must be strictly lawful, transparently documented, and approved in advance.

Payments to third parties, including agents, consultants, or partners, must be legitimate, proportionate to services rendered, and properly documented. Commissions, success fees, or similar arrangements must not be used to conceal improper payments or circumvent applicable laws.

Personnel must not use third parties or intermediaries to bypass these requirements. Any request or situation that raises concerns must be escalated before action is taken.

All transactions must be accurately recorded. Concealment, mischaracterization, or off-record arrangements are prohibited and constitute a breach of this Code.

Spendbase applies a zero-tolerance approach to bribery and corruption and expects the same standard from all third parties acting on its behalf.

7. Data Protection. Confidentiality. Information Security

Spendbase requires strict protection of company, customer, and partner information. Personnel must process and safeguard information in accordance with applicable data protection laws and internal policies.

Access to information must be limited to what is necessary for the role. Data may be used only for authorized business purposes and must be handled through approved systems and tools. Use of personal devices, unapproved applications, or external channels to store or transmit company information is not permitted unless explicitly authorized.

Confidential information must not be disclosed to unauthorized persons, internally or externally. Unauthorized access, use, copying, transfer, or retention of confidential information is prohibited. This obligation continues after termination of employment or engagement.

Personnel must follow all information security requirements, including access controls, authentication measures, and incident reporting procedures. Any suspected data breach, unauthorized access, or loss of information must be reported immediately.

Failure to protect information, misuse of data, or circumvention of security controls constitutes a breach of this Code.

8. Fair Dealing and Communications

Personnel must act honestly and fairly in all business interactions. All communications, internal and external, must be accurate, complete, and not misleading.

Products and services must be presented based on actual capabilities. Personnel must not make statements or commitments that are unverified, exaggerated, or inconsistent with approved materials. Any representation regarding performance, features, or partnerships must be substantiated. Material limitations, conditions, or dependencies must not be omitted where omission would make a statement misleading.

Deceptive, unfair, or abusive practices are not permitted. This includes misrepresentation in sales, marketing, negotiations, or customer support.

Customer concerns and complaints must be handled promptly and in accordance with established procedures. Repeated issues or patterns indicating product, service, or control deficiencies must be escalated.

Professional conduct is required in all interactions. Communications must reflect appropriate judgment and must not create legal, regulatory, or reputational risk for Spendbase.

Personnel are expected to raise concerns when communications or practices may lead to a misleading or unfair outcome.

9. Human Rights and Workplace Conduct

Spendbase is committed to conducting its business in a manner that respects fundamental human rights and applicable labor standards.

Personnel must treat others with dignity and respect and must not engage in discrimination, harassment, retaliation, or any form of abusive conduct. Decisions related to employment, engagement, and collaboration must be based on objective and legitimate business criteria.

Spendbase does not tolerate forced labor, child labor, or any form of exploitation within its operations or through its third-party relationships.

Personnel are expected to raise concerns where workplace conduct or business practices do not meet these standards.

10. Third-Party Relationships

Spendbase engages third parties, including partners, vendors, and service providers, only through approved processes and subject to appropriate due diligence.

Personnel must ensure that third parties acting on behalf of Spendbase are selected on legitimate business criteria and can meet legal, regulatory, and operational requirements. Engagements must be governed by written agreements with appropriate controls, including compliance, data protection, and audit rights where applicable.

Third parties must not be used to circumvent legal or regulatory obligations or internal controls. Personnel remain responsible for activities performed on behalf of Spendbase.

Performance and conduct of third parties must be monitored. Any concerns, deficiencies, or potential breaches must be escalated without delay. Informal or unapproved engagements are not permitted. Due diligence must be risk-based and, where appropriate, refreshed during the relationship.

Delegation of work to third parties does not transfer accountability.

Third parties may be required to acknowledge and comply with this Code or equivalent standards as a condition of engagement.

11. Books, Records, and Internal Controls

Spendbase requires that all business activities be accurately recorded and supported by complete and reliable documentation. Records must reflect the true nature of transactions and must be maintained in accordance with applicable legal and regulatory requirements. Records must be sufficiently clear and complete to permit effective review, audit, and reconstruction of material decisions and transactions.

All transactions must be properly authorized and recorded in a timely manner through approved systems. Personnel must not create, alter, omit, or destroy records in a manner that misrepresents facts or circumvents controls.

Off-record arrangements, undisclosed accounts, or informal tracking of transactions are not permitted. All financial and operational activity must be transparent and capable of verification.

Personnel must comply with internal controls, including approval processes, segregation of duties, and audit requirements. Unauthorized overrides or manipulation of controls is prohibited.

All Personnel are required to cooperate fully with internal reviews, audits, and investigations, and to provide accurate and complete information.

12. Sanctions, Export Controls, and Restricted Activities

Spendbase complies with applicable economic sanctions, export control laws, and restrictions on prohibited or high-risk activities in all jurisdictions where it operates.

Personnel must not engage in or facilitate transactions or relationships involving sanctioned individuals, entities, jurisdictions, beneficial owners, or restricted goods or services. Screening, verification, and onboarding procedures must be followed at all times.

No product, service, or transaction may be structured to circumvent sanctions, export controls, or regulatory restrictions. Any attempt to disguise the true nature, parties, or destination of a transaction is prohibited.

Transactions involving cross-border elements, high-risk jurisdictions, or unusual structures must be assessed and, where required, escalated before execution.

Any potential match, concern, or uncertainty related to sanctions or restricted activities must be reported immediately. Proceeding without clearance is not permitted.

Spendbase applies a risk-based approach to identifying and managing sanctions and financial crime risks, including ongoing monitoring where applicable.

13. Reporting, Investigations, and Non-Retaliation

Personnel must promptly report any suspected or actual violation of this Code, applicable laws, or internal policies. Reports may be made confidentially and, where permitted by law, anonymously through the Code of Conduct Reporting Form or by email legal@test-partneway.prod.spendbase.co. Third parties may raise concerns through designated channels where applicable.

All reports must be made in good faith and based on reasonable grounds. Knowingly false or malicious reports are not permitted.

Personnel are required to cooperate fully with internal reviews and investigations, including preserving relevant information and providing complete and accurate responses. Interference with reporting or investigations is prohibited.

Retaliation against any individual who raises a concern or participates in an investigation is strictly prohibited and will result in disciplinary action.

Violations of this Code may result in disciplinary measures, including termination of employment or engagement, and may be reported to regulators or law enforcement where required. Disciplinary measures will be applied consistently, taking into account the nature of the breach, the surrounding facts, and the individual’s role and responsibility.

14. Acknowledgment and Compliance

Personnel are required to read, understand, and comply with this Code. Compliance is a condition of engagement.

Personnel may be required to confirm adherence periodically. Questions must be directed to Legal or Compliance before action is taken where uncertainty exists.

This Code may be updated from time to time. The most current version is binding. Spendbase may require periodic training, certifications, or acknowledgments to support effective implementation of this Code.

Table of contents