Last Updated: 27 April 2026
If you have any questions about this Privacy Policy, you can contact us:
By email: compliance@transfi.com
“TransFi” refers to Trans-Fi Inc. and its affiliates and subsidiaries worldwide as mentioned under Annexure A and as amended from time to time (collectively “TransFi Group”, “TransFi”, “we”, “us” or “our”).
TransFi may share your personal data with its other entities (subsidiaries and affiliates) and use it in accordance with this Privacy Policy.
The objective of TransFi’s (all subsidiaries and affiliates) privacy policy (the “Privacy Policy”) is to commit to protecting your privacy. Please read this carefully as this policy is legally binding when you choose to use our Services. For the purpose of the relevant data protection regulations, TransFi may act as either the “data controller”, “data processor” or both of your information.
This Privacy Policy describes how we collect, use, handle and, under certain conditions, disclose your personal data, when you access our Services, which include our content on the Website located at www.transfi.com or any other websites, pages, features, or content we own or operate, including the TransFi payments transaction platform (collectively, the “Website(s)”), or any TransFi widget, application programming interface (“API”) or third party applications relying on such an API, products (Payouts, Collections and Ramp) and related services (referred to collectively hereinafter as “Services”).
This Privacy Policy also explains the steps we have taken to secure your personal information. Finally, this Privacy Policy explains your options regarding the collection, use and disclosure of your personal information. By visiting the Website, you accept the practices described in this Privacy Policy for the Website. If you do not acknowledge and accept this Privacy Policy, you may not use the Services.
If you have any questions about this policy, please send them to compliance@transfi.com
Personal information means any data which relates to a living individual who can be identified from that data, or from that data and other information, which is in the possession of, or is likely to come into the possession of, TransFi (or its representatives or service providers). In addition to information, it includes any expression of opinion about an individual and any indication of the intentions of TransFi or any other person in respect of an individual. The definition of personal information depends on the relevant law applicable for your physical location. The data TransFi may collect and use about you is described below in sections 2.1–2.3 of this Privacy Policy.
TransFi obtains information about you from various sources. “You” may be an individual or legal entity entering into a business services agreement with TransFi and/or setting up a user account with TransFi and using the Services provided or through our Website or API (“User”), a legal entity/business identified under anti money laundering (“AML”) or counter terrorist financing (“CTF”) identification requirements as per local regulations, verified by TransFi, that uses our Services to collect payments, make payouts, or facilitate cross-border transfers (“Client”), a legal entity that has a contractual relationship with a TransFi Client and may be subject to AML/CTF identification requirements, verified either by TransFi or the Client (“Merchant”), a legal entity that is a client of a Merchant and may be subject to AML/CTF identification requirements, verified either by TransFi or the Merchant (“Sub-Merchant”), or individuals or legal entities that are the end users of Merchants who interact with the Services provided (“End User”). You may also be a recipient/beneficiary of one of our Services, or a visitor to our Website or other service that links to our API and Services. If You are a Merchant, a Sub-Merchant, or End User, your use of the Services will be governed by the applicable agreement between TransFi and the relevant Client.
This includes information you provide to us in order to establish an account and access our Services. This information is either required by law (e.g. to verify your identity), necessary to provide the requested Services (e.g. you will need to provide your bank account number if you would like to link that account to TransFi), or is relevant for our legitimate interests described in greater detail below.
The nature of the Services you are using or interacting with will determine the kind of personal information we might ask for, but may include:
If you are a company, we may request information such as your employer Identification number (or comparable number issued by a government), proof of legal formation (e.g. Articles of Incorporation) and personal identification information for all material beneficial owners for Know Your Business (“KYB”) purposes.
If you do not provide us with the information below, we may not be able to provide the Services to you, or your use of the Services may be restricted.
In addition to the information you provide to us in connection with your use of the Services, you may also choose to submit information to us via other channels, including in connection with an actual or potential business relationship with TransFi.
This includes information we collect automatically, such as whenever you interact with our Website or use our Services. With regard to your use of our Services we may automatically collect the following information:
We may receive information about you if you visit or use our Website or use our Services. This includes information we may obtain about you from third-party sources. The main types of third parties we receive your personal information from are:
We may use your information in the following ways and for the following purposes:
We use your personal information to provide you with our Services. We may use your personal information to improve our Website’s content and layout, and improve our marketing efforts. Additionally, we use your information to ensure the safety, security, and integrity of our Services by protecting against fraudulent, unauthorised, or illegal activity; monitoring identity and service access; and addressing security risks.
According to your preferences and in compliance with applicable law, we may send you marketing communications to inform you about events, to deliver targeted marketing and to share promotional offers. This may involve sending you communications via emails or mobile application notifications about our Services, features, promotions, surveys, news, updates, and events, managing your participation in promotions and events, delivering targeted marketing, and determining general information about visitors’ usage behaviour on the Website. Our marketing will be conducted in accordance with your advertising and marketing preferences and as permitted by applicable law. We require certain information, such as your identification, contact, and payment details, to provide and maintain our Services. If you are a new User or Client, we will contact you by electronic means for marketing purposes only if you have consented to such communication. If you do not want us to send you marketing communications, please go to your account settings to opt out or submit a request via compliance@transfi.com.
We may send you service updates regarding administrative or account-related information, security issues, or other transaction-related information. These communications are important to share developments relating to your account that may affect how you can use our Services. You cannot opt out of receiving critical service communications.
We also process your personal information when you contact us to resolve any questions, disputes, collect fees, or to troubleshoot problems. Without processing your personal information for such purposes, we cannot respond to your requests and ensure your uninterrupted use of the Services.
TransFi is required to process your personal information in compliance with AML/CTF, and security laws, which may include the collection, use, and storage of your information in certain ways. For example, we must identify and verify customers using our Services, including collecting photo identification and using third-party service providers to compare your personal information against databases and public records. When you seek to link a bank account to your TransFi account, we may request additional information to verify your identity or address and manage risk, as required by applicable law. Additionally, we may disclose personal information in response to requests from law enforcement, subpoenas, court orders, or as otherwise required by law, and where necessary to protect our legal rights, enforce agreements, or prevent fraud and abuse of our Services. This includes efforts to mitigate account compromise or loss of funds, investigate complaints, claims and/or disputes, and comply with regulatory or legal requests/inquiries.
We disclose information to our service providers to help enable them to perform Services on your behalf. For example, to facilitate the purchase and custody of digital assets, we share certain information with third parties, such as your name, email address, physical address, social security number, date of birth, government-issued identification and the amount of digital assets being purchased. Further, the types of data we collect and share with third parties are described above in the information you provide to us, which includes your date of birth, country of residence, first name, last name, ID number, ID type, ID issue date, and ID expiry date, your bank account number, bank account name, and card information, including the name on the card, card number, CVV, and expiration date.
We may share non-personal information (such as the number of daily visitors to our Website or the size of an order placed on a certain date) with third parties. This information does not directly personally identify you or any User. For the avoidance of doubt, any IP addresses or a device or other identifier we collect may be shared with one or more third parties.
Sometimes the processing of your personal information is necessary for our legitimate business interests, such as:
We allow your personal information to be accessed only by those who require access to perform their work and share it only with third parties who have a legitimate purpose for accessing it. TransFi will never sell or rent your personal information to third parties without your explicit consent. We will only share your personal information with selected third parties including:
If you use your TransFi account to conduct a transaction with a third-party merchant, the merchant may provide data about you and your transaction to us.
For example, if you send us funds from your bank account, your bank will provide us with identifying information in addition to information about your account in order to complete the transaction.
You acknowledge and agree that TransFi may continue to use and disclose your personal data for a reasonable period following the termination of the relationship between you and TransFi for one or more of the following purposes:
Our Website may contain links to other websites for your convenience or information. These websites are operated by entities unaffiliated with TransFi, and we do not control, endorse, or take responsibility for their content or privacy practices. Each linked website may have its own terms of use and privacy policies, which may differ from ours. We encourage you to review these policies whenever you visit third-party websites, as TransFi is not responsible for the practices or policies of these external sites.
TransFi implements and maintains reasonable measures to protect your personal information. Your files are protected with safeguards according to the sensitivity of the relevant information. Reasonable controls (such as restricted access) are placed on our computer systems.
TransFi is an international business with operations in multiple countries. This means we may transfer to locations outside of your country. When we transfer your personal information to another country, we will ensure that any transfer of your personal information is compliant with applicable data protection law.
We may store and process all or part of your personal and transactional information, including certain payment information, such as your encrypted bank account and/or routing numbers. We protect your personal information by maintaining physical, electronic, and procedural safeguards in compliance with the applicable laws and regulations.
As a condition of employment, TransFi’s employees are required to follow all applicable laws and regulations, including in relation to data protection law. Access to sensitive personal information is limited to those employees who need it to perform their roles. Unauthorized use or disclosure of confidential customer information by a TransFi employee is prohibited and may result in disciplinary measures.
Finally, we rely on third-party service providers for the physical security of some of our computer hardware. We require those third-party service providers to comply with commercially reasonable security practices and measures. For example, when you visit our Website, you access servers that are kept in a secure environment. While we take industry-standard precautions to safeguard your personal information and secure your account, no system can be completely secure. As such, you assume the risk of potential breaches and their consequences. To protect your account, please safeguard your credentials, choose a complex password when registering, enable advanced security features like two-factor authentication, and never share your account credentials with third parties.
If we anonymize your personal information so that it can no longer be associated with you, it will no longer be considered personal information, and we can use it without further notice to you.
We do not knowingly request to collect personal information from any person under the age of 18. If a User submitting personal information is suspected of being younger than 18 years of age, TransFi will require the User to close his or her account and will not allow the User to continue using our Services. We will also take steps to delete the information as soon as possible.
We retain personal information as long as reasonably necessary to fulfil its intended purposes and meet our contractual and legal obligations. Email addresses and phone numbers are stored until the User uses the TransFi Services, and data is retained for five years once the User unsubscribes or removes themselves. Information will be deleted or de-identified when no longer needed, unless longer retention is required by law. TransFi retains certain information under AML/CTF regulations and holds data for a period of five years. If we cannot fully delete or de-identify information, we will take reasonable measures to prevent further processing.
We may use some instances of your data in order to customise our Services and the information we provide to you, and to address your needs — such as your country of address and transaction history. For example, if you frequently send funds from one particular currency to another, we may use this information to inform you of new product updates or features that may be useful for you. When we do this, we take all necessary measures to ensure that your privacy and security are protected — and we only use pseudonymised data wherever possible. This activity has no legal effect on you.
Depending on applicable law of where you reside, you may be able to assert certain rights related to your personal information. These rights include:
Our Services may, from time to time, contain links to and from the websites of our partners, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility for them. Please check these policies before you submit any personal data to these websites.
Further information about your rights may be obtained by contacting the supervisory data protection authority located in your jurisdiction.
Subject to applicable laws, you may have the right to access information we hold about you. Your right of access can be exercised in accordance with the relevant data protection legislation.
We may update this Privacy Policy from time to time and without prior notice to you to reflect changes in our information practices, and any such amendments shall apply to information already collected and to be collected. Your continued use of our Website or any of our Services after any changes to this Privacy Policy indicates your agreement with the terms of the revised Privacy Policy.
Please review this Privacy Policy periodically and especially before you provide personal data to us. If we make material changes to this Privacy Policy, we will notify you here, by email or by means of a notice on the home page of our Website. The date of the last update of the Privacy Policy is indicated at the top of this document.
If you have any questions about this Privacy Policy, please contact us at compliance@transfi.com
This list is indicative only and may be updated without notice
Last updated: August 2026
TransFi Canada's AML policy and associated internal controls are designed to outline the regulations and requirements outlined in the Proceeds of Crime, Money Laundering and Terrorist Financing Act (PCMLTFA) and associated regulations and to ensure a culture of compliance, guide daily operational compliance functions, assesses and mitigate risk, and summarize TransFi Canada's overall compliance regime.
Stakeholders in this process include:
TransFi Canada, doing business as TransFi Canada, is an Ontario corporation with physical operations at 325 Front Street West 2nd floor, Toronto, ON M5V2Y1 offering money services within North American markets. TransFi Canada is a Money Service Business (MSB) with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) with the registration number M24519990 for the following Money Service designations:
TransFi Canada offers the following services related to these designations:
TransFi Canada does not deal with cash, cheques, money orders, or other payment instruments not listed in the flow of funds below.
Payout — CAD to fiat and Fiat to CAD
Typical Product Journey
Money service businesses are subject to the regulations under Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and associated regulations. As a money service business, TransFi Canada is required to:
TransFi Canada has implemented a compliance program to meet the requirements designated by FINTRAC.
At any time, TransFi Canada is subject to audits of this program by FINTRAC and other regulatory bodies.
Money laundering is the process of taking money obtained through illicit means and disguising the source to make it appear legitimate. Money laundering typically takes places in three stages:
Terrorist financing is the process of moving funds in relation to terrorist activities. The source of funds may come from legitimate sources and does not always involve additional illicit activity or money laundering. Terrorist financing is defined as the collection, provision or receipt of money or other property for the purpose of it being used, or in the knowledge that it is intended to be used to:
A person or entity with a presence in Canada engaged in providing at least one of the following services:
Money services businesses (MSBs) must fulfill specific obligations as required by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and associated Regulations, to help combat money laundering and terrorist activity financing in Canada and abroad.
The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) is Canada's Financial Intelligence Unit (FIU) agency that regulates Money Service Businesses and money service activities. FINTRAC issues requirements and guidance for the obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and associated acts.
The Financial Action Task Force (FATF) is an international and intergovernmental organization that aims to develop and promote policies focused on combating money laundering, terrorist financing, and other related threats to the integrity of the international financial system. FATF sets standards and provides recommendations that member countries are expected to implement. The organization's work includes monitoring the progress of member countries implementing these standards, reviewing measures taken, and promoting effective legislative, regulatory, and operational measures. FATF's recommendations are widely recognized as the global standard for compliance best practices in relation to anti-money laundering and counter-terrorist financing.
The relationship established between a Money Service Business and its Clients for financial transaction services. Money Service Business enter a business relationship under the following two conditions:
Business relationships carry verification and record keeping obligations to meet regulatory requirements and combat money laundering activity within Canada.
In Canada, tipping off offenses under anti-money laundering regulations refer to the illegal act of informing a person or entity that they are the subject of a suspicious transaction report or an ongoing investigation by authorities. This is prohibited because it can compromise the investigation and allow the suspect to alter their behavior, destroy evidence, or flee. Violations of this rule can result in significant penalties, including fines and imprisonment.
The 24-hour rule in Canadian regulations mandates that MSBs aggregate multiple transactions conducted by or on behalf of the same individual or entity within a 24-hour period when determining whether they meet the reporting thresholds for large cash transactions or electronic funds transfers. This means if the total amount of transactions reaches or exceeds $10,000 in a single day from the same individual or entity.
Ministerial Directives are issued by the Minister of Finance of Canada to safeguard Canada's financial system. Measures are enacted to counter threats from foreign jurisdictions or entities that are identified to pose a significant risk for enabling money laundering and terrorist financing activities. The directives mandate reporting entities to implement countermeasures on transactions originating from or directed to designated foreign jurisdictions or entities.
FINTRAC divides PEPs into two categories: Foreign and Domestic.
Foreign Politically Exposed Person (Foreign PEP)
A foreign PEP is an individual who holds or has held one of the following offices or positions in or on behalf of a foreign state:
Important Note: According to FINTRAC, once an individual is determined to be a foreign PEP, they remain a foreign PEP forever (even after death). All Foreign PEPs are automatically classified as High Risk
Domestic Politically Exposed Person (Domestic PEP)
A domestic PEP is a person who currently holds, or has held within the last 5 years, a specific office or position in or on behalf of the Canadian federal government, a provincial (or territorial) government, or a municipal government:
Important Note: An individual ceases to be a domestic PEP 5 years after they have left office (or upon death).
Head of an International Organization (HIO)
A HIO is an individual who currently holds, or has held within the last 5 years, the office or position of head of an international organization. To qualify, the organization must be:
Important Note: Similar to domestic PEPs, a person ceases to be an HIO 5 years after they leave the position (or upon death).
Family Members and Close Associates
Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), reporting entities must also apply measures to the family members and close associates of PEPs and HIOs, as their proximity makes them vulnerable to being used for illicit financial activities.
Family Members are strictly defined as:
Close Associates are individuals who are reasonably known to be closely connected to the PEP or HIO. This can include:
Proliferation financing refers to the act of providing funds or financial services that contribute, in whole or in part, to the development, production, acquisition, possession, transfer, or deployment of chemical, biological, radiological, or nuclear (CBRN) weapons and their means of delivery, in contravention of international law.
Proliferation financing is distinct from terrorist financing in that the funds may originate from entirely legitimate sources and may not involve conventional money laundering activity. The complexity of proliferation financing schemes means that transactions may appear commercially legitimate on the surface, with common typologies including:
Regulatory Basis
As a Money Service Business registered with FINTRAC, TransFi Canada is subject to the United Nations Act and the Special Economic Measures Act, both of which give effect to United Nations Security Council Resolutions (UNSCRs) targeting proliferation financing, including Resolutions 1540, 1718, 1737, 1747, 1803, 1929, and 2231. Compliance with these resolutions and associated Canadian sanctions regulations is mandatory.
FINTRAC's guidance on money laundering and terrorist financing risk assessment requires reporting entities to assess their exposure to proliferation financing as part of their enterprise-wide risk assessment (EWRA). TransFi Canada incorporates proliferation financing risk into its EWRA and reviews this assessment at least annually.
TransFi Canada's Obligations
TransFi Canada must:
Risk Indicators
The following indicators may suggest exposure to proliferation financing risk and must be escalated to the Compliance Officer:
Where proliferation financing is suspected, the CAMLO must be notified immediately. An STR must be filed with FINTRAC and, where the activity may involve UN-listed entities or sanctioned property, a Listed Person or Entity Property Report must also be submitted to FINTRAC, CSIS, and the RCMP.
Money Service Business (MSB)s must register with Financial Transactions and Reports Analysis Centre of Canada (FINTRAC), Canada's Financial Intelligence Unit (FIU) and maintain an active registration while offering money services including:
Revenue Québec is the regulatory body maintaining the province's MSBs in licensing and compliance. The Quebec MSB Act defines MSBs more broadly than the Canadian federal definition and includes provincial licensing and registration requirements. TransFi Canada does not operate in Québec or service Québec customers and is not required to register as an MSB with Revenue Quebec.
FINTRAC has implemented the travel rule requirements for virtual currency transfers that require documentation and retention of specific information associated with these transfer activities.
Travel rule information records must be kept by TransFi Canada when sending VC transfers and take reasonable measures to ensure Travel Rule information is included when receiving virtual currency. Travel rule information must be retained and included in applicable FINTRAC reports:
Travel rule information is obtained through onboarding, due diligence and compliance monitoring practices.
Note:If TransFi Canada is unable to obtain required Travel Rule information despite "reasonable measures," the transaction must be reviewed by the Compliance Officer to determine if it should be rejected, held, or reported as suspicious.
Sanctions are measures or actions taken against a target to influence behavior, policy, or actions. These measures typically have three components:
Sanctions can restrict trade, financial transactions, diplomatic relations, and movement. They may be implemented and enforced either specifically or generally. The Government of Canada imposes economic sanctions under three federal statutes and acts related to trade measures and restrictions:
Canadian sanction laws prohibit Money Service Businesses engaging with designated persons, jurisdictions, and specific sectors. Compliance with sanctions law is mandatory and requires screening, monitoring, and reporting to meet obligations. Obligations for Canadian individuals and businesses remain under subsection 83.1(1) Criminal Code (R.S.C., 1985, c. C-46). Canadian sanctions laws impose strict liability for direct and indirect dealings with sanctioned persons or organizations. These laws also require TransFi Canada to comply with asset-freezing obligations to prevent sanctioned parties from accessing financial or material resources. TransFi Canada is dedicated to adhering to all applicable Canadian laws and regulations concerning sanctions evasion. Sanctions evasion occurs when individuals or entities attempt to circumvent restrictions imposed under Canadian laws. Common methods include structuring transactions through intermediaries or high-risk jurisdictions or obscuring the identity of sanctioned parties. Any suspected evasion activities must be promptly reported to the Compliance Officer for investigation and reporting to FINTRAC through suspicious transaction reports (STRs) and relevant authorities, such as the RCMP and CSIS.
Ministerial Directives and transaction restrictions are issued by the Minister of Finance that mandate reporting entities to implement countermeasures for transactions originating from, or destined for, specific foreign jurisdictions or entities that are considered to present high risks for facilitating money laundering and terrorist financing. These measures allow the Minister of Finance to take steps to protect Canada's financial system and support MSBs in combating money laundering and terrorist financing through money service activities. Each directive outlines countermeasures to either enhance or expand upon current obligations that exist under existing obligations for Money Service Businesses. The directives specify the effective date and will remain active until they are officially revoked, suspended, or amended. Current Ministerial Directives issued by Canada as of July 31, 2024 include:
Compliance with Ministerial Directives and transaction restrictions is mandatory. FINTRAC monitors and assesses compliance with AML directives under the PCMLTFA and may examine records or inquire into the business activities of entities covered under the Act. Compliance activities, such as on-site or desk-based examinations, may now include reviewing adherence to Ministerial Directives. TransFi Canada does not allow individuals, entities or transactions linked to countries subject to Ministerial Directives under any circumstances.
Compliance with FINTRAC regulations is mandatory. Failure to adhere to regulations and legislation may lead to severe criminal or administrative penalties. Monetary penalties for non-compliance are related to the following activities:
Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), criminal penalties criterion are defined as:
FINTRAC Registration Maintenance
TransFi Canada shall ensure its registration with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) remains accurate and current. The Compliance Officer is mandated to update FINTRAC registration information within 30 days of any change to the entity's status, ownership, or operations.
TransFi Canada is committed to mitigating money laundering and illicit activity associated with provided services, follows the measures required by the PCMLTFA, governed by an established written compliance program implementing a risk-based approach to prevent money laundering, and will provide reasonable assistance to law enforcement and regulatory bodies in the event of an audit or law enforcement request.
The following measures have been implemented into this compliance program to meet regulatory requirements in Canada:
A Compliance Officer is responsible for implementing and managing day-to-day compliance and anti-money laundering activities of money service business operations. The Compliance Officer reports directly to the Board of Directors and is independent from all other departments/divisions.
Duties and responsibilities of the Compliance Officer include:
Implementing a risk-based approach can contribute to preventing money laundering before it occurs. An RBA (Risk-Based Approach) is a tool utilized to assess risk associated with service delivery and to applying control measure to mitigate these risks where possible:
An Enterprise-Wide Risk Assessment (EWRA) must be maintained at all times to guide a risk-based approach and evaluate money laundering and terrorist financing risks related to services, clients, geographic regions, operations, and regulatory risks. The assessment will be reviewed and updated at least annually to reflect new and emerging risks, legislative changes, and updates made to the business model and services. Implementation of new technologies, products, and services must first undergo assessment for money laundering and terrorist financing risks before it is implemented in operations and be maintained in the documented risk assessment to ensure proper risk assessment and mitigation.
Risk management measures are assessed to strike a balance between TransFi Canada's ability to operate efficiently and meet FINTRAC's risk assessment guidelines. Results of overall risk assessments are used to ensure the quality of adapted risk-based measures, including:
TransFi Canada presents a low overall residual risk and does not tolerate residual high-risk ratings in any category. Mitigation measures have been implemented to reduce inherent high risks intrinsically associated with services by outlining proactive compliance protocols tailored to business specific risk factors.
Client Risk-Rating Methodology
Clients are assigned a risk rating (Low, Medium, or High) based on a weighted scoring matrix. This methodology evaluates:
Beneficial Ownership and Discrepancy Reporting
Termination of Business Relationships
The "Business Relationship" and all associated ongoing/enhanced monitoring conclude only when:
An independent Enterprise-Wide Risk Assessment (EWRA) document is maintained and is utilized to guide this AML Policy. The most current and detailed EWRA can be found in TransFi Canada Business Wide Risk Assessment.
Verifying client identity is required through FINTRAC's acceptable methods of verifying used to identity a person or entity. Client information and documentation is used to confirm existence and associated risk. Customer Due Diligence applies to all clients regardless of application method, if a client cannot be identified, they will not be approved for services.
The Company is a B2B2C business and shall provide Services to Business. The end users can be both natural persons and legal entities. The Company provides services primarily to the business who are Customers-Clients, Merchants, and end users. Both the Merchants and the End Users receive Services and both these subjects are considered as Customers of the Company, who shall be identified accordingly. TransFi's current product suite is described below. All of these products are available as both a solution and as a single Application Programming Interface ("API") and provide a dashboard or other solution for monitoring transactions and orders:
Ramp:Enabling our Clients to offer the exchange of fiat to crypto-assets (fiat-to-crypto "onramp") and the exchange of crypto-assets to fiat (crypto-to-fiat "offramp") to their Merchants and/or End Users.
KYC — Individuals
We have tiered based KYC structure, namely,
Product-Specific Controls: The KYC requirements outlined above represent the minimum standard. Depending on the product or service being used and the associated risk, the Company may request additional information, documentation as deemed necessary.
Individual Verification
The Customer (natural person) identification and ID document validity verification shall be performed following these steps:
The Customer shall enter First name, Last name, Date of Birth, Email, the country of citizenship on the web page dedicated to onboarding;
The Company applies remote identification – via real-time selfie and ID document photo (video) transmission. Namely: In case of a photo transmission:
A. The Customer shall take a photo of his / her ID document.
Only the following ID documents can be accepted for Customer due diligence purposes. The Company shall accept only those ID documents that are valid and only if there are no circumstances showing possible forgery of the ID document:
The collected ID document shall contain the following information about the Customer:
Individuals are required to provide the following information to aid in identity verification, client due diligence, reporting and record keeping requirements:
TransFi Canada utilizes FINTRAC's Government Issued Photo Identification Method to verify individual applicants, ultimate beneficial owners (UBO), and authorized signatories of entity applicants. Under this method, the provided government issued ID documents must meet the following criteria:
Applicants are onboarded through non-face to face interactions and are not physically present during authentication; therefore, additional measures must be taken during verification. The following measures are acceptable for non-face-to-face ID verification:
Individuals under the age of 18 years are not onboarded for individual services under any circumstances. Additionally, individuals over 70 years are not onboarded for any services under any circumstances.
The Confirmation of Existence method is utilized to verify all entities under current operational practices. Entities include Corporations, Partnerships. In all cases the existence of an entity must be confirmed to be authentic, valid, and current. Certain entity structures carry increased risk for money laundering and terrorist activity and require additional measures to verify such as Charities and Trusts. Document requirements to support confirmation of existence include:
The following documents for business entity verification are considered acceptable:
Charities, Non-Government Organizations and Trusts present a heightened risk for Money Laundering, Terrorist Financing, and illicit activity due to the intrinsic structure. Entities under this category will automatically be categorized as high risk and undergo Enhanced Due Diligence with approval from TransFi Canada's Compliance Officer required before being approved to transact. When publicly available, the existence of an entity is confirmed and referenced against the provided documentation via the issuing corporate registry. Publicly available information is used to record and document additional information regarding the entity.
TransFi Canada does not onboard:
Beneficial Ownership information must collect for all business entities. Beneficial ownership varies based on a business entity structure and can include:
The following information must be collected regarding beneficial owners and directors of a business entity:
Indirect beneficial ownership is when the ultimate beneficial ownership stake is through an intermediary entity or through a chain of ownership entities, rather than holding it directly through individual shareholders. All shareholder business entities will be verified under the entity verification requirements outlined in this policy until Ultimate Beneficial Individual Owners of 20% or more are identified and verified pursuant to this policy.
A third party refers to an individual or entity that directs another person or entity to perform a transaction or activity on their behalf. In this context, the third party is the instructing party and is understood to be acting "on behalf of" someone else. TransFi Canada must take reasonable measures to determine whether a third party is involved in a transaction. Indicators that may suggest third-party involvement include:
If a third party is identified, the following information must be documented in the client's profile:
Third parties are not permitted to conduct transactions through TransFi Canada's services under any circumstances. Where third-party involvement is identified or suspected, the matter must be escalated to the Compliance Officer for review and a determination made as to whether a Suspicious Transaction Report is required.
In the onboarding of a customer that meets the following criteria, the organization shall apply a risk-based approach to due diligence:
Applicants are screened against numerous sanctions and screening watch lists through third party compliance tools SumSub and Accend which utilizes over 1700 global databases to screen for exposures related to sanctions, PEPs, HIOs and watch lists. Individuals, Business Entities, Ultimate Beneficial Owners, Directors and other authorized signatories are screened prior to transacting and set to continuous monitoring where new listings publications are referenced against internal client lists where new alerts and associations trigger an email notification to the Chief Compliance Officer for manual review. Sanctioned individuals and entities will not be permitted to transaction through offered services under any circumstances. Sanctions associations identified during onboarding or through client monitoring procedures must result in submission of a Suspicious Transaction report to FINTRAC, at minimum.
If sanctioned funds are believed to be in TransFi Canada's possession at any time, the Chief Compliance Officer, Senior Management and General Counsel must be contacted immediately as funds seizures obligations may apply. TransFi Canada does not onboard sanctioned individuals or business entities, under any circumstances. PEPs and HIOs are only onboarded on a case by case basis, after Enhanced due Diligence and with the approval of the Compliance Officer. TransFi Canada does not have any PEP or HIO clients currently.
Applicant and Client Risk Assessments are utilized to support compliance monitoring, suspicious transaction monitoring and investigations, and the overall understanding of the active Business Relationships to aid in day-to-day operations and risk mitigation processes.
Risk factors that must be considered while assessing Individuals must include the following considerations and minimum:
Risk factors that must be considered while assessing Business Entities must include the following considerations and minimum:
Clients are divided into three categories during risk assessment evaluation and are assigned to low, medium, and high categories each with specific parameters surrounding onboarding requirements and compliance monitoring procedures related to transaction monitoring and Client maintenance schedules and practices.
Low Risk:Profile presents an overall low risk for money laundering for all identified risk factors with no presence of high-risk or eliminating factors governed by this policy. Low risk Clients are subject to standard transaction monitoring procedures, and a client maintenance reassessment every 36 months to update client information, assess for newly presented risks, and ensure verification documents are kept up to date.
Medium Risk:Profile presents an overall medium risk for money laundering for all identified risk factors with presence of increased risk factors such as vulnerable demographics or nature of business with no presence of high-risk or eliminating factors governed by this policy. Medium risk Clients are subject to standard transaction monitoring procedures, and a client maintenance reassessment every 24 months to update client information, assess for newly presented risks, and ensure verification documents are kept up to date.
High Risk:High risk classifications are subject to Enhanced Due Diligence, increased monitoring, and schedule reassessment to monitor and mitigate risk associated with this classification category. High risk classifications may be triggered by a single factor, such as a presence or association with a high-risk jurisdiction or entities, adverse media, or business entity structure. Multiple, high-risk factors can also accumulate to lead to high-risk rating. High risk Clients are subject to increased transaction monitoring procedures, and a client maintenance reassessment every 12 months to update client information, assess for newly presented risks, and ensure verification documents are kept up to date.
Reputed Customers:Profile presents an established, verifiable, and favorable standing that warrants recognition as a low-risk, trusted relationship. These are typically well-known, publicly listed, regulated, or otherwise reputable entities (e.g., publicly traded companies, regulated financial institutions, government bodies, or long-standing clients with a demonstrated history of compliant activity and transparent ownership structures) with no presence of high-risk, adverse media, or eliminating factors governed by this policy. Reputed Customers benefit from a verified track record, strong public reputation, and transparent beneficial ownership. Such Clients are subject to standard transaction monitoring procedures, and a client maintenance reassessment every 36 months to update client information, assess for newly presented risks, and ensure verification documents are kept up to date.
Applicants and clients deemed to present unacceptable risk are declined or offboarded for services due to the presence of factors that are outside of the TransFi Canada's risk appetite. All assessments of this nature must be escalated to the Chief Compliance Officer for review and determination whether an Attempted Suspicious Transaction Report (ASTR) or a Suspicious Transaction Report (STR) will be filed with FINTRAC.
Customer Identification Triggers
Identification requirements are triggered by specific Money Services Business (MSB) activities, including:
Address Verification Standards
TransFi Canada must obtain the full mailing address for all customers.
Note:The use of a Post Office (PO) box or "general delivery" address is strictly prohibited as a primary residence/place of business address.
Corporate and Entity Verification
For all corporate clients, TransFi shall ensure that the name, address, and directors' names collected during onboarding are fully consistent with the official government documents used to verify the corporation's existence (e.g., Articles of Incorporation).
Non-Profit Organizations (NPO) and Charities
During onboarding, staff must confirm if an entity is an NPO.
Beneficial Ownership Unavailability
TransFi Canada may, under exceptional circumstances, onboard customers whose beneficial ownership cannot be confirmed provided that:
Trust Organizations
When identifying trusts, TransFi must collect the full name (no initials or abbreviations), role (full description), and full physical address (no PO boxes) for:
Customer Identification Triggers (FINTRAC)
Applicable MSB triggers per FINTRAC's guidance, including:
An Enhanced Due Diligence assessment aims to confirm the legitimacy and further verify an individual, business entity, or source of funds. TransFi Canada's Compliance may apply enhanced due diligence efforts at any stage of a client relationship and for a number of reasons including but not limited to:
The following customer types are subjected to Enhanced due diligence:
Individual or Business Entity verification includes obtaining more information or documents to confirm the legitimacy of a business entity or individual. This can include obtaining a second Government issued Photo ID, a business plan, certificate of good standing, or licensing and AML Policy, if applicable.
Obtaining documents from the applicant/Client regarding the source of funds or wealth from their client in the form of the most recent three months of unredacted bank statements or audited corporate financials. Acceptable sources of funds:
Using public databases and search engines to confirm or obtain new information. Confirmation of entity registration or license verification with registration authorities where possible. Searching for social media accounts, highlighting search phrases to include "Scam", "Fraud", "Theft", "Criminal" "Court" and "Warning". Searching addresses and locations in google maps street view to assess whether the location matched the information for the applicant/Client.
Source of wealth must be established within 30 days of the business relationship being formed. Source of funds and source of wealth must be obtained for any virtual currency transaction of $100,000 or more. Senior management must review all VC transactions of $100,000 or more involving a PEP before they are carried out or within a reasonable period after.
Compliance with reporting obligations is mandatory. Qualified transactions to FINTRAC and other agencies as required. Each report has specific conditions for which types of transactions must be reported and a specific timeline within which a report must be submitted to FINTRAC. FINTRAC reports are submitted electronically through the FINTRAC Web Reporting System (FWR) or FINTRAC Reporting Ingest API. Listed Person or Entity Property Reports are submitted online or offline and through Forms available for download online. Additionally an STR must be filled with FINTRAC through conventional methods. Reports must also be submitted to the Canadian Security Intelligence Service (CSIS) by fax at 613-369-2303 and the Royal Canadian Mounted Police (RCMP) by fax at 613-825-7030. Additionally an STR must be filled with FINTRAC through conventional methods. Tipping off a client associated with a report may be perceived as interfering with a possible investigation. This restriction applies regardless of whether the investigation is active. To avoid inadvertently tipping off a client, all requests for information to support reporting submissions must follow procedures outlined in this policy or be approved by the Chief Compliance Officer. Volume based reports subject to FINTRAC's 24-hour rule are confined to a static 24 hour period that matches any calendar day from 0:00 to 23:59. Multiple transactions from a single Client outside of this timeframe will not be considered for volume based reporting under FINTRAC's 24 hour rule.
Electronic Funds Transfer Reports (EFTRs)EFTRs are not applicable to TransFi Canada services and will not be filed as TransFi Canada does not accept Cash.
Large Cash Transaction Reports (LCTRs)Large Cash Transaction Reports are not applicable to TransFi Canada services and will not be filed as TransFi Canada does not accept Cash.
Large Virtual Currency Transaction Reports (LVCTRs)As a Money Service Business Dealing in Virtual Currency, TransFi Canada is required to file Large Virtual Currency Transaction Reports (LVCTRs) when Virtual Currency is received from a client or in the form of a commission payment equal to or in excess of $10,000 CAD in a single transaction or multiple transactions within a single calendar day. TransFi Canada must use the Canadian dollar exchange rate established at the time of the virtual currency transaction to determine whether the reporting threshold is met. Due to the fluctuating value of virtual currencies, this rate will vary based on a per trade basis.
Suspicious Transactions & Attempted Suspicious TransactionsThe threshold to report a suspicious transaction or attempted suspicious transaction is reasonable grounds to suspect that a money laundering or terrorist financing offence might have occurred. Reasonable grounds to suspect does not require confirmation of details to prove that an offence has occurred, however, the suspicion needs to be reasonable and unbiased and have considered; facts, context and risk indicators supporting suspicion. Suspicious reports must be filed when measures and investigation have been conducted with outcomes that reach the reasonable grounds to suspect threshold at minimum. Suspicious Transaction Reports must be treated as a priority as they are complex and must include clear, simple and concise language outlining grounds for suspicion including with the facts, context, and indicators that allowed you to reach reasonable grounds for suspicion.
Listed Person or Entity Property ReportsListed Person or Entity Property Reports are submitted offline and exclusively through fax or paper mail with Paper Report Forms available for download online. Additionally an STR must be filled with FINTRAC through conventional methods. Reports must also be submitted to the Canadian Security Intelligence Service (CSIS) by fax at 613-369-2303 and the Royal Canadian Mounted Police (RCMP) by fax at 613-825-7030. Additionally an STR must be filled with FINTRAC through conventional methods. The Chief Compliance officer must escalate activity related to Listed Person or Entity Property to senior management and General Counsel immediately.
Identifying suspicious transactions begins with screening and identifying any transactions that appear unusual based on risk flags and detection measures, assessing the facts and context surrounding these transactions and linking any indicators of money laundering or terrorist financing to your evaluation. Examples of red flags for suspicion include but are not limited to:
Grounds for suspicion must be outlined in an investigation report outlining how the facts, context, and indicators resulted in the conclusion:
Transactions alone may not seem suspicious, however, context can outline the conditions that support suspicious activity. Established Client profiles, including assigned risk ratings, must be assessed and leveraged during the investigation to identify indicators specific to the Client. The Chief Compliance Officer must review and approve all suspicious activity investigations prior to filing an STR with FINTRAC to ensure the reasonable grounds to suspect threshold has been met and adequate facts, context and indicators are included in the investigation.
The standard investigation process includes the following measures:
Transaction Reviews:Analysis of client's last 90 days transactional data assessing volume, frequency, beneficiary information and account data.
Sanctions Screening and Review:Screening business entities, directors, UBOs, and authorized users against sanctions lists and comprehensive review of related compliance requirements are conducted at the time of onboarding as well as on an ongoing basis
OSINT Investigation:Open-source intelligence (OSINT) gathering to gather relevant information including examination of social media profiles and associated websites for additional context.
Enhanced due diligence:Obtaining further information from the client to support verification through a Request for Information (RFI) process adhering to the terms outlined in this policy and only with the approval of the Chief Compliance Officer. Requests must be reasonable and avoid any instances of "tipping off".
TransFi Canada conducts ongoing compliance monitoring to evaluate Business Relationships and risks through Client maintenance reviews, and through transaction monitoring to identify and report any suspicious activity. The primary focus and scope of compliance monitoring is determined by the risks identified in the enterprise wide risk assessment, company AML policies, and established procedures.
Client Maintenance reviews are a key function of the Client Management framework. Review frequency is governed by established client risk profiles or triggered by various factors including but not limited to:
Client profiles must be maintained, valid, accurate, and complete throughout the Business Relationship. This involves sourcing updated Client documents and information surrounding the intended use of services.
Transaction Monitoring is focused on all transactions on behalf of Clients, commissions, or referral payment transactions to support money service offerings. Transaction reviews facilitate reporting obligations and identify transactions that meet the parameters for volume based reporting. These reviews also assist with suspicious activity monitoring under general guideline identifiers that include:
High Risk Clients are subject to increased transaction monitoring which include a higher sensitivity threshold with increased considerations on identified red flags. TransFi Canada's IT systems have pre-programmed notifications and triggers that notify the compliance team of unusual activity related to Fiat transactions. Reviews of high volume/high velocity transfers are conducted bi-weekly to support client monitoring and reporting initiatives. TransFi Canada's transaction reviews are conducted manually by the compliance to identify reportable transactions and to review to identify money laundering red-flags and transactions that deviate from what is expected with established client profiles.
Know Your Transaction - KYT
TransFi has a robust inhouse Transaction Monitoring (TM) program as a rules engine designed to identify and report unusual or suspicious transaction activity. These rules applies to both fiat transactions and crypto transactions, leveraging a mix of automated and manual processes to ensure comprehensive monitoring and compliance.
Fiat TM Program
TransFi employs real-time and post-transaction monitoring to analyze fiat transactions, focusing on the following aspects: Transactions that exceed predefined thresholds are flagged for manual review and subjected to due diligence. Transactions originating from or destined for prohibited jurisdictions are automatically rejected and reported in Suspicious Transaction Reports (STRs). We have TM rules which indicates suspicious patterns. Below are the example of such rules:
Crypto TM Program
For cryptocurrency transactions, we have implemented additional measures tailored to the unique risks of virtual assets: Wallets are analyzed based on the source of funds and sanctions screening through our blockchain monitoring partner Chainalysis. Wallets flagged as high-risk result in rejection of transactions. Transactions involving virtual currencies are monitored for compliance with international sanctions. Suspicious activity is flagged for further investigation. Similar to fiat, unusual patterns in crypto transactions trigger additional review to assess potential risks.
To facilitate information requests, and to be aligned with compliance best practices, records must be maintained in an organized and accessible format and be retained for a minimum of 5 years after the date the record was created. Access to records maintained on company servers is granted on an as-needed basis and is accessible only through two factor authentication. In the event of a FINTRAC request for information, the request must be fulfilled within 30 calendar days. Documents to meet record keeping requirements with the information supported in this policy include, but are not limited to:
Access to Record Keeping must be protected, granted on a need to know basis, and accessed through company databases with Two Factor Authentication enabled at all times.
Employees, directors, agents or mandataries, or other persons authorized to act on the company's behalf must complete mandatory written and ongoing AML compliance training. A documented training program for ongoing AML compliance training must be maintained with a defined methodology on training delivery. Training must include:
TransFi Canada's Chief Compliance Officer will maintain the annual training plan, track the completion of all training and implement additional training sessions if compliance issues arise. This includes documenting the steps taken to ensure appropriate training is conducted and is relevant to employee roles on an ongoing basis. This includes:
Relevant new hires must receive training within 60 days of beginning their position. Anyone that is on a leave of absence that causes them to miss regularly scheduled training will complete training within 30 days of their return to work. A record of all training materials must be maintained at all times and include the training source materials, the date of the training, a list of attendees, and the topics covered to support training management and demonstrate that the training is being conducted on an ongoing basis.
A two-year effectiveness review supports an independent evaluation of the company's written and operational compliance program with higher-risk business areas receiving focused attention during the review. This to test the effectiveness of the program, identify any instances of non-compliance, and identify areas for improvement based on regulation or compliance best practices. An independent review supports preparation for a FINTRAC Exam, determines if operational practices reflect the TransFi Canada's written compliance program, and examines the effectiveness of TransFi Canada's enterprise-wide risk assessment and mitigation measures.
Independent effectiveness reviews must begin no later than two years from the start of any previous reviews or initial MSB registration. TransFi Canada's independent effectiveness reviews must be completed by a compliance professional with knowledge and experience in the PCMLTFA and Canadian regulations. The review must include at minimum:
The Chief Compliance Officer must review and report on the external review to management within 30 days of completion, detail any deficiencies, and any remediations required in a remediation plan including set timelines for implementation. The Chief Compliance officer must determine whether a Voluntary Self-Declaration of Non-Compliance (VSDONC) should be submitted to FINTRAC based on the findings of the review.
FINTRAC promotes a regulatory approach that is based on the promotion of compliance and not to penalize reporting entities with fines and penalties. Unreported transactions may hold value for FINTRAC and law enforcement, and must be reported even when missed, late, or uncovered during a scheduled or independent effectiveness review.
Submitting a VSDONC, an entity officially acknowledges compliance obligation short-comings and lists implemented measures to regain compliance. FINTRAC will work with a reporting entity to guide and correct instances of non-compliance without proposing administrative penalties, if:
Voluntary self-declarations of non-compliance must be sent to: VSDONC.ADVNC@fintrac-canafe.gc.ca and include:
Personal information regarding instances of non-compliance must be protected and not included in VSDONC reports or submission email. If private information is pertinent to the investigation, FINTRAC will provide secure information sources.
Supporting law enforcement is a key factor in mitigating money laundering, terrorist financing, fraud, and illegal activity where possible. Validly served requests for Client information and assistance must be handled with priority. Requests from individual users or requests from law enforcement without a formal legal document detailing the requested information will not be accommodated.
Law Enforcement requests must follow a structured process including multiple stakeholders to establish validity, formulate a timely and detailed response, and report and document the request for internal and external management.
The Chief Compliance officer remains the primary point of contact for all Law Enforcement requests. Upon receipt of any requests, the Chief Compliance Officer must notify Senior Management and General Counsel with all provided documentation. Access to this information and details therein must remain confidential and on a need to know basis.
Chief Compliance officer and General Counsel must review the Law Enforcement Request to ensure that it originates from a real law enforcement agency and that it is a formal legal request, such as a subpoena or search warrant.
The Chief Compliance Officer must conduct an investigation on the Client(s) and information with priority pursuant to the established investigation protocols directed by this policy. Additional information that must be included in these investigations include:
Copies of investigations must be provided to Senior Management and General Counsel for review prior to any formal response. General Counsel must verify that the details in the investigation are required by the formal requests, and that the obligations outlined in the request are met. General Counsel must provide any investigation amendments or deviations from Law Enforcement Request Policy in written format to the Chief Compliance Officer and Senior Management for review and implementation.
All external response communications must be approved by TransFi Canada's General Counsel. Law Enforcement responses must include a cover letter outlining the requested information, parameters of the request, a summary of the investigation, and list the records to be provided. Responses must be sent through official company channels, be factual, and delivered before the due date outlined in the formal law enforcement request document.
The Chief Compliance Officer must submit a Suspicious Activity Report (SAR) to FINTRAC under suspicion of "Reasonable Grounds to Suspect.". Accounts posing any identified risk of illegal activity, money laundering, reputational harm, or other risks that may cause harm to the company are reviewed for closure. TransFi Canada will follow law enforcement recommendations for account closures. All records of law enforcement requests, investigations, responses and internal and external communications surrounding the request will be maintained for a minimum of 5 years after the submission of the response.
This Country Acceptance Policy aims to provide a comprehensive delineation of acceptable jurisdictions for services. This framework ensures clarity and adherence to regulatory standards across operations and promotes a robust and compliant approach to jurisdictional considerations for Client Intake and Client Monitoring procedures. For the purposes of this policy, "location" is defined broadly to ensure a risk-based approach is applied during the Client boarding process. It encompasses any world area, country, region, state, or similar where a significant aspect of business operations is situated. Such aspects may include office locations, the residence of a majority owner, fulfillment or shipping warehouses, bank accounts, suppliers, home addresses, countries of identity document issuance, IP addresses, email domains, and other relevant factors. The policy outlines various types of location risks that are considered critical:
The following countries subject to current sanctions imposed by Canada, that are outside of TransFi Canada's risk appetite include:
The following countries and jurisdictions require enhanced due diligence prior to boarding: Algeria, Bulgaria, Burkina Faso, China, Cameroon, Comoros, Ivory Coast, Kenya, Lao People's Democratic Republic, Monaco, Mozambique, Namibia, Nepal, Sri Lanka, South Africa, Tanzania, Trinidad and Tobago, Uganda, and Vietnam,
Exceptions apply solely to Clients domiciled in restricted locations, contingent on the implementation of enhanced due diligence and robust fraud/risk controls. Under no circumstances will Clients located in banned countries be considered for onboarding. The review process for restricted countries must undergo rigorous review verification that goods/services are fulfilled.
Exceptions are evaluated individually and must be approved by TransFi Canada's Chief Compliance Officer. A risk-based approach is used to determine location risk, considering that clients may have multiple locations, such as corporate addresses, physical addresses, bank account locations, fulfillment warehouses, and home addresses. The highest risk location among these is used to score the Client's overall location risk. For Clients located in restricted countries and operating within high-risk industries or offering high-risk products, service will be denied
Adult content, airlines; collection agencies; marijuana dispensaries; CBD oil and related products; cash advances or cash gifting; charities; check cashing; cruises; debt consolidation; drug paraphernalia; firearms; fulfillment centers; government grant assistance; mail order brides; medical benefits or discounts; mortgage modification or reduction; multi-level marketing schemes; payday lending; replica or counterfeit goods; precious metal dealers; guns, arms, and ammunition; bearer share ownership companies; unlicensed MSBs, unlicensed gambling, shell banks, and timeshares. TransFi Canada does not onboard:
Clients with multiple products or services may be approved with enhanced due diligence and only with the Chief Compliance Officer's approval.
Restricted industries are only onboarded when accompanied by enhanced due diligence. In some cases, additional controls, such as transaction or volume restrictions with heightened transaction monitoring, may be implemented as necessary and determined by the Chief Compliance Officer. Clients in restricted categories often pose higher risks due to extended fulfillment times, advance payments, or frequent customer complaints and disputes. This includes clients trading in products subject to frequent or pending regulation changes by national health, safety, or regulatory bodies. The following business types are subject to increased scrutiny; educational programs, modeling agencies, money services businesses, pharmaceuticals, gaming, betting, and wagers, gemstones, vape supplies, pawnbrokers, ticket brokers, travel agents and clubs, used car dealerships, and vitamins and herbal remedies.
Exceptions to client onboarding apply only to those trading in restricted industries and only after the completion of due diligence and fraud/risk controls. Clients involved in prohibited products will not be considered for onboarding under any circumstances. Exceptions are evaluated on a case-by-case basis and upon the written approval of the Chief Compliance Officer.
TransFi Canada must update this AML ATF Policy upon any material change in services or regulatory requirements affecting business operations. In addition, a scheduled annual review must be conducted to measure policy adherence in day-to-day operations.
July 1st, 2027

Authorized Signatory
Raj Kamal