Các chính sách

TẬP ĐOÀN TRANSFI
CHÍNH SÁCH QUYỀN RIÊNG TƯ TOÀN CẦU

Cập nhật lần cuối: Tháng 10 năm 2024

LIÊN HỆ VỚI CHÚNG TÔI
Nếu bạn có bất kỳ câu hỏi nào về Chính sách quyền riêng tư này, bạn có thể liên hệ với chúng tôi:
Qua email: compliance@transfi.com

1. Mục tiêu của Chính sách quyền riêng tư của TransFi là gì?

“TransFi” đề cập đến Trans-Fi Inc. cùng các đơn vị liên kết và công ty con trên toàn thế giới, bao gồm Trans-Fi UAB và NEOMONEY INC. (gọi chung là “Tập đoàn TransFi”, “TransFi”, “chúng tôi”). 

TransFi có thể chia sẻ dữ liệu cá nhân của bạn với các đơn vị khác (công ty con và đơn vị liên kết) và sử dụng dữ liệu đó theo Chính sách quyền riêng tư này.

Mục tiêu của chính sách quyền riêng tư của TransFi (tất cả các công ty con và đơn vị liên kết) (“Chính sách quyền riêng tư”) là cam kết bảo vệ quyền riêng tư của bạn. Vui lòng đọc kỹ vì chính sách này có hiệu lực pháp lý khi bạn chọn sử dụng Dịch vụ của chúng tôi. Vì mục đích của các quy định bảo vệ dữ liệu liên quan, TransFi có thể đóng vai trò là “bên kiểm soát dữ liệu”, “bên xử lý dữ liệu” hoặc cả hai đối với thông tin của bạn.

Chính sách quyền riêng tư này mô tả cách chúng tôi thu thập, sử dụng, xử lý và trong một số điều kiện nhất định, tiết lộ dữ liệu cá nhân của bạn khi bạn truy cập Dịch vụ của chúng tôi, bao gồm nội dung của chúng tôi trên Trang web tại www.transfi.com hoặc bất kỳ trang web, trang, tính năng hoặc nội dung nào khác mà chúng tôi sở hữu hoặc vận hành, bao gồm nền tảng giao dịch thanh toán TransFi (gọi chung là “Trang web”), hoặc bất kỳ tiện ích, giao diện lập trình ứng dụng (“API”) của TransFi hoặc các ứng dụng của bên thứ ba dựa trên API đó, các sản phẩm (Thanh toán, Thu tiền và Ramp) và các dịch vụ liên quan (gọi chung sau đây là “Dịch vụ”).

Chính sách quyền riêng tư này cũng giải thích các bước chúng tôi đã thực hiện để bảo mật thông tin cá nhân của bạn. Cuối cùng, Chính sách quyền riêng tư này giải thích các tùy chọn của bạn liên quan đến việc thu thập, sử dụng và tiết lộ thông tin cá nhân của bạn. Bằng cách truy cập Trang web, bạn chấp nhận các thực tiễn được mô tả trong Chính sách quyền riêng tư này đối với Trang web. Nếu bạn không thừa nhận và chấp nhận Chính sách quyền riêng tư này, bạn không được sử dụng Dịch vụ.  

Nếu bạn có bất kỳ câu hỏi nào về chính sách này, vui lòng gửi đến compliance@transfi.com.

2. Chúng tôi thu thập những thông tin cá nhân nào từ bạn?

Thông tin cá nhân có nghĩa là bất kỳ dữ liệu nào liên quan đến một cá nhân đang sống có thể được xác định từ dữ liệu đó, hoặc từ dữ liệu đó và các thông tin khác mà TransFi (hoặc đại diện, nhà cung cấp dịch vụ của TransFi) đang sở hữu hoặc có khả năng sở hữu. Ngoài thông tin, khái niệm này còn bao gồm bất kỳ ý kiến nào về một cá nhân và bất kỳ chỉ dấu nào về ý định của TransFi hoặc bất kỳ người nào khác đối với một cá nhân. Định nghĩa về thông tin cá nhân phụ thuộc vào luật liên quan áp dụng cho vị trí thực tế của bạn. Dữ liệu mà TransFi có thể thu thập và sử dụng về bạn được mô tả dưới đây trong các phần 2.1-2.3 của Chính sách quyền riêng tư này. 

TransFi thu thập thông tin về bạn từ nhiều nguồn khác nhau. “Bạn” có thể là cá nhân hoặc pháp nhân ký kết thỏa thuận dịch vụ kinh doanh với TransFi và/hoặc thiết lập tài khoản người dùng với TransFi và sử dụng các Dịch vụ được cung cấp hoặc thông qua Trang web hoặc API của chúng tôi (“Người dùng”), một pháp nhân/doanh nghiệp được xác định theo các yêu cầu nhận dạng về chống rửa tiền (“AML”) hoặc chống tài trợ khủng bố (“CTF”) theo quy định địa phương, được TransFi xác minh, sử dụng Dịch vụ của chúng tôi để thu tiền, thực hiện thanh toán hoặc tạo điều kiện cho các giao dịch chuyển tiền xuyên biên giới (“Khách hàng”), một pháp nhân có mối quan hệ hợp đồng với Khách hàng của TransFi và có thể phải tuân theo các yêu cầu nhận dạng AML/CTF, được xác minh bởi TransFi hoặc Khách hàng (“Đơn vị thương mại”), một pháp nhân là khách hàng của Đơn vị thương mại và có thể phải tuân theo các yêu cầu nhận dạng AML/CTF, được xác minh bởi TransFi hoặc Đơn vị thương mại (“Đơn vị thương mại phụ”), hoặc các cá nhân hay pháp nhân là người dùng cuối của các Đơn vị thương mại tương tác với các Dịch vụ được cung cấp (“Người dùng cuối”). Bạn cũng có thể là người nhận/người thụ hưởng một trong các Dịch vụ của chúng tôi, hoặc khách truy cập Trang web của chúng tôi hoặc dịch vụ khác có liên kết đến API và Dịch vụ của chúng tôi. Nếu Bạn là Đơn vị thương mại, Đơn vị thương mại phụ hoặc Người dùng cuối, việc bạn sử dụng Dịch vụ sẽ được điều chỉnh bởi thỏa thuận hiện hành giữa TransFi và Khách hàng liên quan.

2.1 Thông tin bạn cung cấp cho chúng tôi

Điều này bao gồm thông tin bạn cung cấp cho chúng tôi để thiết lập tài khoản và truy cập Dịch vụ của chúng tôi. Thông tin này hoặc là bắt buộc theo luật (ví dụ: để xác minh danh tính của bạn), hoặc cần thiết để cung cấp các Dịch vụ được yêu cầu (ví dụ: bạn sẽ cần cung cấp số tài khoản ngân hàng nếu muốn liên kết tài khoản đó với TransFi), hoặc có liên quan đến các lợi ích hợp pháp của chúng tôi được mô tả chi tiết hơn dưới đây.

Tính chất của các Dịch vụ mà bạn đang sử dụng hoặc tương tác sẽ quyết định loại thông tin cá nhân mà chúng tôi có thể yêu cầu, nhưng có thể bao gồm:

  • Thông tin định danh cá nhân: họ tên đầy đủ, ngày tháng năm sinh, tuổi, quốc tịch, quốc gia cư trú, chi tiết giấy tờ tùy thân do chính phủ cấp (bao gồm số ID, loại ID, ngày cấp và ngày hết hạn), mã số an sinh xã hội, mã số thuế, thông tin đăng nhập tài khoản, vị trí địa lý, chi tiết thiết bị duy nhất, thông tin mạng hoặc địa chỉ giao thức internet, địa chỉ ví, giới tính, chữ ký, hóa đơn tiện ích, ảnh chụp, số điện thoại, địa chỉ nhà riêng, email và/hoặc bất kỳ thông tin nào khác được coi là cần thiết để tuân thủ các nghĩa vụ pháp lý của chúng tôi theo luật và quy định hiện hành;
  • Giấy tờ tùy thân chính thức: giấy tờ tùy thân do cơ quan chính phủ cấp như hộ chiếu, thị thực hoặc căn cước công dân, thẻ ID tiểu bang, bằng lái xe và/hoặc bất kỳ thông tin nào khác được coi là cần thiết để tuân thủ các nghĩa vụ pháp lý của chúng tôi theo luật và quy định hiện hành;
  • Thông tin Tài chính: thông tin tài khoản ngân hàng, thông tin thẻ thanh toán, mã số thuế (“TIN”), lịch sử giao dịch, dữ liệu giao dịch. Đối với chi tiết giao dịch, chúng tôi lưu trữ chi tiết đơn hàng, số tài khoản ngân hàng của Người dùng, tên tài khoản ngân hàng và thông tin thẻ, bao gồm tên chủ thẻ, số thẻ, CVV và ngày hết hạn. Vì chúng tôi được chứng nhận theo Tiêu chuẩn Bảo mật Dữ liệu Ngành Thẻ Thanh toán (“PCI DSS”), chúng tôi có thể lưu trữ thông tin này một cách an toàn để đáp ứng các nghĩa vụ tuân thủ và đảm bảo bảo mật dữ liệu. Mặc dù chúng tôi không lưu trữ thông tin đăng nhập tài khoản Người dùng TransFi của bạn, chúng tôi xử lý và lưu trữ thông tin thẻ một cách an toàn theo tiêu chuẩn PCI DSS. Thông tin thẻ thanh toán cũng có thể được xử lý thông qua hệ thống của chúng tôi trong quá trình giao dịch bởi các nhà cung cấp dịch vụ bên thứ ba an toàn. 
  • Thông tin Giao dịch: thông tin về các giao dịch bạn thực hiện liên quan đến Dịch vụ của chúng tôi, chẳng hạn như tên người nhận, tên của bạn, số tiền và/hoặc dấu thời gian, mục đích giao dịch, khu vực pháp lý của giao dịch; 
  • Thông tin Xác minh: để xác thực danh tính của bạn, bao gồm thông tin để kiểm tra gian lận và các thông tin khác mà bạn cung cấp, bao gồm hình ảnh của chính bạn và kiểm tra tính sống động;
  • Thông tin Việc làm: Địa điểm văn phòng, chức danh công việc và/hoặc mô tả vai trò; hoặc
  • Thư từ: Phản hồi khảo sát, thông tin cung cấp cho đội ngũ hỗ trợ hoặc đội ngũ nghiên cứu Người dùng của chúng tôi.

Nếu bạn là một công ty, chúng tôi có thể yêu cầu thông tin như mã số thuế doanh nghiệp (hoặc số tương đương do chính phủ cấp), bằng chứng thành lập hợp pháp (ví dụ: Điều lệ công ty) và thông tin nhận dạng cá nhân của tất cả các chủ sở hữu hưởng lợi chính cho mục đích Tìm hiểu Doanh nghiệp của bạn (“KYB”).

Nếu bạn không cung cấp cho chúng tôi thông tin dưới đây, chúng tôi có thể không cung cấp được Dịch vụ cho bạn, hoặc việc sử dụng Dịch vụ của bạn có thể bị hạn chế. 

Ngoài thông tin bạn cung cấp cho chúng tôi liên quan đến việc sử dụng Dịch vụ, bạn cũng có thể chọn gửi thông tin cho chúng tôi qua các kênh khác, bao gồm cả thông tin liên quan đến mối quan hệ kinh doanh hiện tại hoặc tiềm năng với TransFi.

2.2 Thông tin chúng tôi thu thập tự động hoặc tạo ra về bạn

Điều này bao gồm thông tin chúng tôi thu thập tự động, chẳng hạn như bất cứ khi nào bạn tương tác với Trang web hoặc sử dụng Dịch vụ của chúng tôi. Liên quan đến việc bạn sử dụng Dịch vụ của chúng tôi, chúng tôi có thể tự động thu thập các thông tin sau:

  • Chi tiết về các giao dịch bạn thực hiện khi sử dụng Dịch vụ của chúng tôi, bao gồm vị trí địa lý nơi giao dịch bắt nguồn;
  • Thông tin kỹ thuật, bao gồm địa chỉ giao thức Internet (“IP”) được sử dụng để kết nối máy tính của bạn với Internet, thông tin đăng nhập, tên, loại và phiên bản trình duyệt, cài đặt múi giờ, các loại và phiên bản trình duyệt plug-in, hệ điều hành, chi tiết vị trí địa lý/theo dõi và nền tảng, chi tiết thiết bị;
  • Thông tin về lượt truy cập của bạn, bao gồm dữ liệu xác thực, câu hỏi bảo mật, luồng nhấp chuột đầy đủ của Bộ định vị Tài nguyên Thống nhất (“URL”) đến, thông qua và từ Trang web hoặc ứng dụng di động của chúng tôi (bao gồm ngày và giờ); các sản phẩm bạn đã xem hoặc tìm kiếm; thời gian phản hồi của trang, lỗi tải xuống, thời lượng truy cập vào một số trang nhất định, thông tin tương tác trên trang (như cuộn, nhấp chuột và di chuột), và các phương thức được sử dụng để rời khỏi trang cũng như bất kỳ email nào được sử dụng để liên hệ với chúng tôi.
  • Cookie và các Công nghệ khác. Giống như nhiều trang web khác, Trang web của chúng tôi sử dụng cookie, Dịch vụ dựa trên vị trí và web beacon (còn được gọi là công nghệ clear GIF hoặc “thẻ hành động”) để tăng tốc độ điều hướng trên Trang web, nhận diện bạn và quyền truy cập của bạn, cũng như theo dõi việc sử dụng của bạn. Vui lòng đọc Chính sách Cookie để biết thêm thông tin.

2.3 Thông tin thu thập từ bên thứ ba

Chúng tôi có thể nhận thông tin về bạn nếu bạn truy cập hoặc sử dụng Trang web hoặc Dịch vụ của chúng tôi. Điều này bao gồm thông tin chúng tôi có thể thu thập về bạn từ các nguồn bên thứ ba. Các loại bên thứ ba chính mà chúng tôi nhận thông tin cá nhân của bạn từ đó là:

  • Các cơ sở dữ liệu công khai, các đối tác xác minh danh tính để xác thực danh tính của bạn theo quy định của pháp luật hiện hành. Các đối tác xác minh danh tính sử dụng kết hợp hồ sơ chính phủ và thông tin công khai về bạn để xác minh danh tính của bạn. Thông tin này có thể bao gồm tên, địa chỉ, chức danh công việc, hồ sơ việc làm công khai, tình trạng trong bất kỳ danh sách trừng phạt nào do các cơ quan công quyền duy trì và các dữ liệu liên quan khác;
  • Dữ liệu blockchain để đảm bảo các bên sử dụng Dịch vụ của chúng tôi không tham gia vào các hoạt động bất hợp pháp hoặc bị cấm, các khu vực pháp lý bị trừng phạt, dark net, lạm dụng trẻ em, v.v. và để phân tích xu hướng giao dịch cho mục đích nghiên cứu và phát triển bằng cách sàng lọc địa chỉ ví để xác định nguồn tiền;
  • Các đối tác tiếp thị & đại lý bán lại để chúng tôi có thể hiểu rõ hơn về các Dịch vụ nào có thể khiến bạn quan tâm;
  • Các ngân hàng/nhà cung cấp dịch vụ tài chính mà bạn sử dụng để chuyển tiền cho chúng tôi sẽ cung cấp cho chúng tôi thông tin cá nhân cơ bản của bạn, chẳng hạn như tên và địa chỉ, cũng như thông tin tài chính của bạn như chi tiết tài khoản ngân hàng;
  • Các đối tác kinh doanh có thể cung cấp cho chúng tôi tên và địa chỉ của bạn, cũng như thông tin tài chính, chẳng hạn như thông tin thanh toán bằng thẻ; và
  • Các mạng quảng cáo, nhà cung cấp dịch vụ phân tích và nhà cung cấp thông tin tìm kiếm có thể cung cấp cho chúng tôi thông tin đã được ẩn danh về bạn, chẳng hạn như xác nhận cách bạn tìm thấy Trang web của chúng tôi.

3. Chúng tôi sử dụng thông tin cá nhân của bạn như thế nào?

Chúng tôi có thể sử dụng thông tin của bạn theo những cách và cho các mục đích sau:

(a) Sử dụng Nội bộ: Chúng tôi sử dụng thông tin cá nhân của bạn để cung cấp Dịch vụ cho bạn. Chúng tôi có thể sử dụng thông tin cá nhân của bạn để cải thiện nội dung và bố cục Trang web của chúng tôi, cũng như cải thiện các nỗ lực tiếp thị. Ngoài ra, chúng tôi sử dụng thông tin của bạn để đảm bảo sự an toàn, bảo mật và tính toàn vẹn của Dịch vụ bằng cách bảo vệ chống lại các hoạt động gian lận, trái phép hoặc bất hợp pháp; giám sát danh tính và quyền truy cập dịch vụ; và giải quyết các rủi ro bảo mật.

(b) Liên lạc với Bạn: Theo tùy chọn của bạn và tuân thủ luật pháp hiện hành, chúng tôi có thể gửi cho bạn các thông tin tiếp thị để thông báo về các sự kiện, cung cấp các nội dung tiếp thị mục tiêu và chia sẻ các ưu đãi khuyến mãi. Điều này có thể bao gồm việc gửi thông báo cho bạn qua email hoặc thông báo trên ứng dụng di động về Dịch vụ, tính năng, chương trình khuyến mãi, khảo sát, tin tức, cập nhật và sự kiện của chúng tôi, quản lý việc bạn tham gia các chương trình khuyến mãi và sự kiện, cung cấp tiếp thị mục tiêu và xác định thông tin chung về hành vi sử dụng của khách truy cập trên Trang web. Hoạt động tiếp thị của chúng tôi sẽ được thực hiện theo tùy chọn quảng cáo và tiếp thị của bạn cũng như theo quy định của pháp luật hiện hành. Chúng tôi yêu cầu một số thông tin nhất định, chẳng hạn như thông tin nhận dạng, thông tin liên hệ và chi tiết thanh toán để cung cấp và duy trì Dịch vụ của mình. Nếu bạn là Người dùng hoặc Khách hàng mới, chúng tôi sẽ chỉ liên hệ với bạn qua phương tiện điện tử cho mục đích tiếp thị nếu bạn đã đồng ý với việc liên lạc đó. Nếu bạn không muốn chúng tôi gửi thông tin tiếp thị, vui lòng truy cập cài đặt tài khoản của bạn để từ chối hoặc gửi yêu cầu qua compliance@transfi.com.

Chúng tôi có thể gửi cho bạn các bản cập nhật dịch vụ liên quan đến thông tin hành chính hoặc tài khoản, các vấn đề bảo mật hoặc thông tin khác liên quan đến giao dịch. Những thông báo này rất quan trọng để chia sẻ các diễn biến liên quan đến tài khoản của bạn có thể ảnh hưởng đến cách bạn sử dụng Dịch vụ của chúng tôi. Bạn không thể từ chối nhận các thông báo dịch vụ quan trọng.

Chúng tôi cũng xử lý thông tin cá nhân của bạn khi bạn liên hệ với chúng tôi để giải quyết bất kỳ câu hỏi, tranh chấp, thu phí hoặc để khắc phục sự cố. Nếu không xử lý thông tin cá nhân của bạn cho các mục đích này, chúng tôi không thể phản hồi các yêu cầu của bạn và đảm bảo bạn sử dụng Dịch vụ không bị gián đoạn.

(c) Tuân thủ Pháp lý và Quy định: TransFi bắt buộc phải xử lý thông tin cá nhân của bạn để tuân thủ các luật về AML/CTF (chống rửa tiền/chống tài trợ khủng bố) và luật an ninh, điều này có thể bao gồm việc thu thập, sử dụng và lưu trữ thông tin của bạn theo những cách nhất định. Ví dụ, chúng tôi phải xác định và xác minh khách hàng sử dụng Dịch vụ của mình, bao gồm việc thu thập ảnh giấy tờ tùy thân và sử dụng các nhà cung cấp dịch vụ bên thứ ba để đối chiếu thông tin cá nhân của bạn với các cơ sở dữ liệu và hồ sơ công khai. Khi bạn muốn liên kết tài khoản ngân hàng với tài khoản TransFi của mình, chúng tôi có thể yêu cầu thêm thông tin để xác minh danh tính hoặc địa chỉ của bạn và quản lý rủi ro theo quy định của pháp luật hiện hành. Ngoài ra, chúng tôi có thể tiết lộ thông tin cá nhân để phản hồi các yêu cầu từ cơ quan thực thi pháp luật, trát tòa, lệnh của tòa án hoặc theo yêu cầu khác của pháp luật, và khi cần thiết để bảo vệ các quyền hợp pháp của chúng tôi, thực thi các thỏa thuận hoặc ngăn chặn gian lận và lạm dụng Dịch vụ của chúng tôi. Điều này bao gồm các nỗ lực giảm thiểu việc tài khoản bị xâm phạm hoặc mất tiền, điều tra các khiếu nại, yêu cầu bồi thường và/hoặc tranh chấp, cũng như tuân thủ các yêu cầu/truy vấn về quy định hoặc pháp lý.

(d) Sử dụng Bên ngoài: Chúng tôi tiết lộ thông tin cho các nhà cung cấp dịch vụ của mình để giúp họ thực hiện Dịch vụ thay mặt bạn. Ví dụ, để tạo điều kiện thuận lợi cho việc mua và lưu ký tài sản kỹ thuật số, chúng tôi chia sẻ một số thông tin nhất định với các bên thứ ba, chẳng hạn như tên, địa chỉ email, địa chỉ thực, số an sinh xã hội, ngày sinh, giấy tờ tùy thân do chính phủ cấp và số lượng tài sản kỹ thuật số đang được mua. Ngoài ra, các loại dữ liệu chúng tôi thu thập và chia sẻ với các bên thứ ba đã được mô tả ở trên trong phần thông tin bạn cung cấp cho chúng tôi, bao gồm ngày sinh, quốc gia cư trú, tên, họ, số ID, loại ID, ngày cấp ID và ngày hết hạn ID, số tài khoản ngân hàng, tên tài khoản ngân hàng và thông tin thẻ của bạn, bao gồm tên trên thẻ, số thẻ, mã CVV và ngày hết hạn.

Chúng tôi có thể chia sẻ thông tin phi cá nhân (chẳng hạn như số lượng khách truy cập hàng ngày vào Trang web của chúng tôi hoặc quy mô đơn hàng được đặt vào một ngày nhất định) với các bên thứ ba. Thông tin này không trực tiếp xác định danh tính cá nhân của bạn hoặc bất kỳ Người dùng nào. Để tránh hiểu lầm, bất kỳ địa chỉ IP hoặc thiết bị hay mã định danh nào khác mà chúng tôi thu thập đều có thể được chia sẻ với một hoặc nhiều bên thứ ba.

(e) Lợi ích Kinh doanh Hợp pháp của Chúng tôi: Đôi khi, việc xử lý thông tin cá nhân của bạn là cần thiết cho các lợi ích kinh doanh hợp pháp của chúng tôi, chẳng hạn như:

  • kiểm soát chất lượng và đào tạo nhân viên;
  • để tăng cường bảo mật, giám sát và xác minh danh tính hoặc quyền truy cập dịch vụ, đồng thời chống thư rác hoặc các phần mềm độc hại hay rủi ro bảo mật khác;
  • phục vụ mục đích nghiên cứu và phát triển;
  • để nâng cao trải nghiệm của bạn đối với Dịch vụ và Trang web của chúng tôi; 
  • để tạo điều kiện cho các hoạt động mua lại, sáp nhập hoặc giao dịch doanh nghiệp;

để thực hiện các hoạt động nội bộ cần thiết nhằm cung cấp Dịch vụ của chúng tôi, bao gồm khắc phục lỗi phần mềm và các vấn đề vận hành.

4. Chúng tôi tiết lộ thông tin cá nhân nào cho bên thứ ba?

Chúng tôi chỉ cho phép những người cần truy cập để thực hiện công việc của họ mới được tiếp cận thông tin cá nhân của bạn và chỉ chia sẻ thông tin đó với các bên thứ ba có mục đích hợp pháp khi truy cập. TransFi sẽ không bao giờ bán hoặc cho thuê thông tin cá nhân của bạn cho bên thứ ba mà không có sự đồng ý rõ ràng của bạn. Chúng tôi sẽ chỉ chia sẻ thông tin cá nhân của bạn với các bên thứ ba được chọn, bao gồm:

  • Các dịch vụ xác minh danh tính để ngăn chặn gian lận. Điều này cho phép TransFi xác nhận danh tính của bạn bằng cách so sánh thông tin bạn cung cấp cho chúng tôi với hồ sơ công khai và các cơ sở dữ liệu của bên thứ ba khác;
  • Các tổ chức tài chính mà chúng tôi hợp tác để xử lý các khoản thanh toán mà bạn đã ủy quyền;
  • Các đơn vị liên kết, đối tác kinh doanh, nhà cung cấp và nhà thầu phụ để thực hiện và hoàn thành bất kỳ hợp đồng nào mà chúng tôi ký kết với họ hoặc với bạn;
  • Các nhà cung cấp dịch vụ phân tích và công cụ tìm kiếm hỗ trợ chúng tôi trong việc cải thiện và tối ưu hóa Trang web của mình;
  • Các công ty hoặc bên thứ ba khác liên quan đến việc chuyển nhượng doanh nghiệp hoặc thủ tục phá sản;
  • Các công ty hoặc đơn vị khác mua lại tài sản của TransFi;
  • Cơ quan thực thi pháp luật, cơ quan quản lý hoặc bất kỳ bên thứ ba nào khác khi chúng tôi buộc phải làm như vậy theo luật hiện hành hoặc nếu chúng tôi tin tưởng một cách thiện chí rằng việc sử dụng đó là cần thiết một cách hợp lý, bao gồm để bảo vệ quyền lợi, tài sản hoặc sự an toàn của TransFi, khách hàng của TransFi, bên thứ ba hoặc công chúng; tuân thủ các nghĩa vụ hoặc yêu cầu pháp lý; thực thi các điều khoản và thỏa thuận khác của chúng tôi; hoặc phát hiện hay giải quyết các vấn đề về bảo mật, gian lận hoặc kỹ thuật; và
  • Nếu bạn ủy quyền cho một hoặc nhiều ứng dụng bên thứ ba truy cập vào Dịch vụ của chúng tôi, thì thông tin bạn đã cung cấp cho TransFi có thể được chia sẻ với các bên thứ ba đó. Một kết nối mà bạn ủy quyền hoặc kích hoạt giữa tài khoản TransFi của bạn và một tài khoản, công cụ thanh toán hoặc nền tảng không thuộc TransFi được coi là “kết nối tài khoản”. Trừ khi bạn cung cấp thêm quyền, TransFi sẽ không ủy quyền cho các bên thứ ba này sử dụng thông tin này cho bất kỳ mục đích nào khác ngoài việc hỗ trợ các giao dịch của bạn bằng Dịch vụ của chúng tôi. Xin lưu ý rằng các bên thứ ba mà bạn tương tác sẽ có chính sách bảo mật riêng và TransFi không chịu trách nhiệm về hoạt động hoặc việc sử dụng dữ liệu mà họ thu thập.

Các ví dụ về kết nối tài khoản bao gồm:

  • Người bán: Nếu bạn sử dụng tài khoản TransFi của mình để thực hiện giao dịch với một người bán bên thứ ba, người bán đó có thể cung cấp dữ liệu về bạn và giao dịch của bạn cho chúng tôi.
  • Các nhà cung cấp dịch vụ tài chính của bạn: Ví dụ, nếu bạn gửi tiền cho chúng tôi từ tài khoản ngân hàng của mình, ngân hàng của bạn sẽ cung cấp cho chúng tôi thông tin nhận dạng cùng với thông tin về tài khoản của bạn để hoàn tất giao dịch.

Bạn xác nhận và đồng ý rằng TransFi có thể tiếp tục sử dụng và tiết lộ dữ liệu cá nhân của bạn trong một khoảng thời gian hợp lý sau khi mối quan hệ giữa bạn và TransFi chấm dứt vì một hoặc nhiều mục đích sau đây: 

  • để cho phép TransFi hoàn thành các nghĩa vụ còn tồn đọng đối với bạn theo bất kỳ thỏa thuận nào, nếu có; 
  • để cho phép TransFi thực thi các quyền của mình theo bất kỳ thỏa thuận nào, nếu có; 
  • cho bất kỳ mục đích nào mà bạn đã cung cấp sự đồng ý bằng văn bản; 
  • theo yêu cầu của luật pháp hiện hành; và theo lệnh của tòa án có thẩm quyền.

5. Liên kết đến các trang web khác

Trang web của chúng tôi có thể chứa các liên kết đến những trang web khác để thuận tiện cho bạn hoặc cung cấp thông tin. Các trang web này được vận hành bởi những đơn vị không liên kết với TransFi, và chúng tôi không kiểm soát, xác nhận hoặc chịu trách nhiệm về nội dung hay các chính sách bảo mật của họ. Mỗi trang web được liên kết có thể có các điều khoản sử dụng và chính sách bảo mật riêng, có thể khác với chúng tôi. Chúng tôi khuyến khích bạn xem xét các chính sách này bất cứ khi nào bạn truy cập trang web của bên thứ ba, vì TransFi không chịu trách nhiệm về các hoạt động hoặc chính sách của những trang web bên ngoài này.

6. Chúng tôi bảo vệ và lưu trữ thông tin cá nhân như thế nào?

TransFi thực hiện và duy trì các biện pháp hợp lý để bảo vệ thông tin cá nhân của bạn. Các tệp của bạn được bảo vệ bằng các biện pháp an toàn tùy theo mức độ nhạy cảm của thông tin liên quan. Các biện pháp kiểm soát hợp lý (chẳng hạn như hạn chế quyền truy cập) được áp dụng trên các hệ thống máy tính của chúng tôi.

TransFi là một doanh nghiệp quốc tế với hoạt động tại nhiều quốc gia. Điều này có nghĩa là chúng tôi có thể chuyển dữ liệu đến các địa điểm bên ngoài quốc gia của bạn. Khi chúng tôi chuyển thông tin cá nhân của bạn sang quốc gia khác, chúng tôi sẽ đảm bảo rằng mọi hoạt động chuyển thông tin cá nhân của bạn đều tuân thủ luật bảo vệ dữ liệu hiện hành.

Chúng tôi có thể lưu trữ và xử lý toàn bộ hoặc một phần thông tin cá nhân và giao dịch của bạn, bao gồm một số thông tin thanh toán nhất định, chẳng hạn như số tài khoản ngân hàng và/hoặc số định tuyến đã được mã hóa của bạn. Chúng tôi bảo vệ thông tin cá nhân của bạn bằng cách duy trì các biện pháp bảo vệ vật lý, điện tử và quy trình tuân thủ các luật và quy định hiện hành.

Là một điều kiện làm việc, nhân viên của TransFi bắt buộc phải tuân thủ tất cả các luật và quy định hiện hành, bao gồm cả luật bảo vệ dữ liệu. Quyền truy cập vào thông tin cá nhân nhạy cảm chỉ giới hạn cho những nhân viên cần thiết để thực hiện vai trò của họ. Việc sử dụng hoặc tiết lộ trái phép thông tin khách hàng bảo mật bởi nhân viên TransFi đều bị nghiêm cấm và có thể dẫn đến các biện pháp kỷ luật.

Cuối cùng, chúng tôi dựa vào các nhà cung cấp dịch vụ bên thứ ba để đảm bảo an ninh vật lý cho một số phần cứng máy tính của chúng tôi. Chúng tôi yêu cầu các nhà cung cấp dịch vụ bên thứ ba đó tuân thủ các biện pháp và thực tiễn bảo mật hợp lý về mặt thương mại. Ví dụ: khi bạn truy cập Trang web của chúng tôi, bạn đang truy cập các máy chủ được giữ trong môi trường an toàn. Mặc dù chúng tôi thực hiện các biện pháp phòng ngừa theo tiêu chuẩn ngành để bảo vệ thông tin cá nhân và bảo mật tài khoản của bạn, không có hệ thống nào có thể hoàn toàn an toàn. Do đó, bạn chấp nhận rủi ro về các vi phạm tiềm ẩn và hậu quả của chúng. Để bảo vệ tài khoản của mình, vui lòng bảo mật thông tin đăng nhập, chọn mật khẩu phức tạp khi đăng ký, bật các tính năng bảo mật nâng cao như xác thực hai yếu tố và không bao giờ chia sẻ thông tin đăng nhập tài khoản của bạn với bên thứ ba.

Nếu chúng tôi ẩn danh hóa thông tin cá nhân của bạn để thông tin đó không còn có thể liên kết với bạn, thì thông tin đó sẽ không còn được coi là thông tin cá nhân nữa và chúng tôi có thể sử dụng thông tin đó mà không cần thông báo thêm cho bạn.

Chúng tôi không cố ý thu thập thông tin cá nhân từ bất kỳ người nào dưới 18 tuổi. Nếu nghi ngờ Người dùng gửi thông tin cá nhân dưới 18 tuổi, TransFi sẽ yêu cầu Người dùng đó đóng tài khoản và sẽ không cho phép Người dùng tiếp tục sử dụng Dịch vụ của chúng tôi. Chúng tôi cũng sẽ thực hiện các bước để xóa thông tin đó sớm nhất có thể. 

 Chúng tôi lưu giữ thông tin cá nhân trong thời gian cần thiết một cách hợp lý để hoàn thành các mục đích dự kiến và đáp ứng các nghĩa vụ hợp đồng và pháp lý của chúng tôi. Địa chỉ email và số điện thoại được lưu trữ cho đến khi Người dùng sử dụng Dịch vụ TransFi, và dữ liệu được lưu giữ trong năm năm sau khi Người dùng hủy đăng ký hoặc xóa tài khoản. Thông tin sẽ bị xóa hoặc hủy nhận dạng khi không còn cần thiết, trừ khi luật pháp yêu cầu lưu giữ lâu hơn. TransFi lưu giữ một số thông tin nhất định theo các quy định về AML/CTF và giữ dữ liệu trong thời hạn năm năm. Nếu chúng tôi không thể xóa hoặc hủy nhận dạng hoàn toàn thông tin, chúng tôi sẽ thực hiện các biện pháp hợp lý để ngăn chặn việc xử lý thêm.

7. Chúng tôi có thực hiện lập hồ sơ và ra quyết định tự động không?

Chúng tôi có thể sử dụng một số dữ liệu của bạn để tùy chỉnh Dịch vụ và thông tin mà chúng tôi cung cấp cho bạn, cũng như để đáp ứng nhu cầu của bạn - chẳng hạn như quốc gia cư trú và lịch sử giao dịch. Ví dụ: nếu bạn thường xuyên chuyển tiền từ loại tiền tệ này sang loại tiền tệ khác, chúng tôi có thể sử dụng thông tin này để thông báo cho bạn về các bản cập nhật sản phẩm hoặc tính năng mới có thể hữu ích cho bạn. Khi thực hiện việc này, chúng tôi thực hiện mọi biện pháp cần thiết để đảm bảo quyền riêng tư và bảo mật của bạn được bảo vệ - và chúng tôi chỉ sử dụng dữ liệu đã được giả danh hóa bất cứ khi nào có thể. Hoạt động này không gây ra bất kỳ hiệu lực pháp lý nào đối với bạn.  

8. Các quyền về quyền riêng tư và truy cập thông tin của bạn là gì?

Tùy thuộc vào luật hiện hành tại nơi bạn cư trú, bạn có thể thực hiện một số quyền liên quan đến thông tin cá nhân của mình. Các quyền này bao gồm:

  • quyền nhận thông tin liên quan đến việc xử lý thông tin cá nhân của bạn và quyền truy cập vào thông tin cá nhân mà chúng tôi lưu giữ về bạn;
  • quyền rút lại sự đồng ý đối với việc xử lý thông tin cá nhân của bạn vào bất kỳ lúc nào. Tuy nhiên, xin lưu ý rằng chúng tôi vẫn có thể có quyền xử lý thông tin cá nhân của bạn nếu chúng tôi có lý do chính đáng khác để làm như vậy (ví dụ: chúng tôi có thể cần lưu giữ thông tin cá nhân để tuân thủ nghĩa vụ pháp lý);
  • trong một số trường hợp, quyền nhận một số thông tin cá nhân ở định dạng có cấu trúc, thông dụng và có thể đọc được bằng máy và/hoặc yêu cầu chúng tôi truyền dữ liệu đó cho bên thứ ba nếu khả thi về mặt kỹ thuật. Xin lưu ý rằng quyền này chỉ áp dụng cho thông tin cá nhân mà bạn đã cung cấp trực tiếp cho TransFi;
  • quyền yêu cầu chúng tôi chỉnh sửa thông tin cá nhân của bạn nếu thông tin đó không chính xác hoặc không đầy đủ;
  • quyền yêu cầu chúng tôi xóa thông tin cá nhân của bạn trong một số trường hợp nhất định. Xin lưu ý rằng có thể có những trường hợp bạn yêu cầu chúng tôi xóa thông tin cá nhân, nhưng chúng tôi vẫn có quyền lưu giữ thông tin đó theo quy định của pháp luật;
  • quyền phản đối hoặc yêu cầu chúng tôi hạn chế xử lý thông tin cá nhân của bạn trong một số trường hợp nhất định. Tuy nhiên, có thể có những trường hợp bạn phản đối hoặc yêu cầu chúng tôi hạn chế xử lý thông tin cá nhân, nhưng chúng tôi vẫn có quyền từ chối yêu cầu đó theo quy định của pháp luật;
  • quyền khiếu nại với cơ quan quản lý bảo vệ dữ liệu có liên quan nếu bạn cho rằng bất kỳ quyền nào của mình đã bị chúng tôi xâm phạm; và
  • quyền chuyển dữ liệu cá nhân của bạn giữa các bên kiểm soát dữ liệu, ví dụ như chuyển chi tiết tài khoản của bạn từ nền tảng trực tuyến này sang nền tảng khác.

Các Dịch vụ của chúng tôi đôi khi có thể chứa các liên kết đến và đi từ các trang web của đối tác, nhà quảng cáo và đơn vị liên kết của chúng tôi. Nếu bạn truy cập vào bất kỳ trang web nào trong số này thông qua liên kết, vui lòng lưu ý rằng các trang web đó có chính sách quyền riêng tư riêng và chúng tôi không chịu trách nhiệm về các chính sách đó. Vui lòng kiểm tra các chính sách này trước khi bạn gửi bất kỳ dữ liệu cá nhân nào cho các trang web đó. Thông tin thêm về các quyền của bạn có thể được lấy bằng cách liên hệ với cơ quan giám sát bảo vệ dữ liệu tại khu vực pháp lý của bạn.

Tùy thuộc vào luật hiện hành, bạn có thể có quyền truy cập vào thông tin mà chúng tôi lưu giữ về bạn. Quyền truy cập của bạn có thể được thực hiện theo quy định của pháp luật về bảo vệ dữ liệu có liên quan.

9. Chính sách Quyền riêng tư được cập nhật bao lâu một lần?

Chúng tôi có thể cập nhật Chính sách Quyền riêng tư này theo thời gian mà không cần thông báo trước cho bạn để phản ánh những thay đổi trong hoạt động thông tin của chúng tôi, và mọi sửa đổi như vậy sẽ áp dụng cho thông tin đã thu thập và sẽ được thu thập. Việc bạn tiếp tục sử dụng Trang web hoặc bất kỳ Dịch vụ nào của chúng tôi sau khi có bất kỳ thay đổi nào đối với Chính sách Quyền riêng tư này đồng nghĩa với việc bạn đồng ý với các điều khoản của Chính sách Quyền riêng tư đã sửa đổi. 

Vui lòng xem lại Chính sách Quyền riêng tư này định kỳ, đặc biệt là trước khi bạn cung cấp dữ liệu cá nhân cho chúng tôi. Nếu chúng tôi thực hiện các thay đổi quan trọng đối với Chính sách Quyền riêng tư này, chúng tôi sẽ thông báo cho bạn tại đây, qua email hoặc thông qua thông báo trên trang chủ của Trang web chúng tôi. Ngày cập nhật cuối cùng của Chính sách Quyền riêng tư được ghi ở đầu tài liệu này.

10. Làm thế nào để liên hệ với chúng tôi nếu có thắc mắc về quyền riêng tư?

Nếu bạn có bất kỳ câu hỏi nào về Chính sách Quyền riêng tư này, vui lòng liên hệ với chúng tôi qua địa chỉ compliance@transfi.com hoặc gửi thư qua đường bưu điện đến đơn vị liên quan dưới đây:

Trans-Fi UAB

Lvivo str. 21A, Vilnius LT-09313, Lithuania

NEOMONEY INC. 

325 Front Street West, tầng 2 

Toronto, ON M5V2Y1

Canada

TransFi AML KYC Policy

Last updated: August 2026

Table of Contents

Section 1: Version Control
Section 2: Document Overview
2.1 Objectives & Goals
2.2 Program Ownership
2.3 Stakeholders
Section 3: Introduction
3.1 Business Model Overview
3.2 Simple Flow of Funds
Section 4: Regulatory Overview
4.1 Definitions:
4.1.1 Money Laundering
4.1.2 Terrorist Financing
4.1.3 Money Service Business
4.1.4 FINTRAC
4.1.5 Financial Action Task Force (FATF)
4.1.6 Business Relationship
4.1.7 Tipping Off
4.1.8 24 Hour Rule
4.1.9 Ministerial Directives
4.1.10 Politically Exposed Persons & HIOs
4.2 Canadian Money Service Business Requirements
4.2.1 FINTRAC MSB Registration
4.2.2 Revenue Québec MSB Registration
4.2.3 FINTRAC Travel Rule
4.2.4 Sanctions Requirements
4.2.5 Ministerial Directives
4.3 Non-Compliance
Section 5: TransFi Canada's Compliance Program
5.1 Appointment of a Compliance Officer
5.2 Risk-Based Approach
5.3 Customer Due Diligence
5.4 Sanction and Applicant Screening
5.5 Client Risk Rating and Classification
Section 6: Enhanced Due Diligence (EDD)
6.1 Enhanced Measures
Section 7: Reporting Requirements
7.1 MSB Reporting Requirements Overview
Section 8: Identifying Suspicious Activity & Investigations
8.1 Investigation Framework
8.1.1 Investigation Outcomes
Section 9: Compliance Monitoring
9.1 Client Maintenance Reviews
9.2 Transaction Monitoring
Section 10: Record Keeping
Section 11: AML Staff Training Plan

Section 12: Two Year Effectiveness Review
Section 13: Voluntary Self-Declaration of Non-Compliance (VSDONC)
Section 14: Law Enforcement Requests
14.1 Notification
14.2 Review
14.3 Investigation
14.4 Response
14.5 Actions
Section 15: Country Acceptance Policy
15.1 Banned Countries
15.2 Restricted Countries
15.3 Onboarding Exceptions
Section 16: Prohibited Industries
16.1 Restricted Industries
16.2 Onboarding Exceptions
Section 17: Policy Review Schedule

Section 1: Version Control

Version Reviewer Date Description
1.0 Payaswani Shukla 04/1/2024 Creation of Policy
2.0 CAMLO 10/8/2024 Revamp & Update.
2.1 CAMLO 23/02/2025 Country and Industry updates.
2.2 CAMLO 10/10/2025 Country and Industry updates.
2.3 Payaswani Shukla 14/11/2025 UBO Ownership percentage updated
2.4 Payaswani Shukla 19/2/2026 Prohibited business list updated
2.5 Payaswani Shukla 07/4/2026 Updated sections as per review findings
2.6 Payaswani Shukla 01/5/2026 Updated Address
2.7 Payaswani Shukla 15/7/2026 Updated Prohibited Country
2.8 Payaswani Shukla 24/7/2026 Updated KYC description

Section 2: Document Overview

2.1 Objectives & Goals

TransFi Canada's AML policy and associated internal controls are designed to outline the regulations and requirements outlined in the Proceeds of Crime, Money Laundering and Terrorist Financing Act (PCMLTFA) and associated regulations and to ensure a culture of compliance, guide daily operational compliance functions, assesses and mitigate risk, and summarize TransFi Canada's overall compliance regime.

2.2 Program Ownership

Designation Name Email
Primary Head of Compliance Payaswani Shukla payaswani@transfi.com
Reviewed By CAMLO Justin Leegsma Compliance@transfi.com

2.3 Stakeholders

Stakeholders in this process include:

  • Executives
  • Legal Counsel
  • Operational Staff
  • Brokers & Counterparties
  • Merchants
  • Consumers
  • Agents and Mandataries

Section 3: Introduction

3.1 Business Model Overview

TransFi Canada, doing business as TransFi Canada, is an Ontario corporation with physical operations at 325 Front Street West 2nd floor, Toronto, ON M5V2Y1 offering money services within North American markets. TransFi Canada is a Money Service Business (MSB) with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) with the registration number M24519990 for the following Money Service designations:

  • Payment Service Provider
  • Virtual Currency Dealing
  • Money Transmission
  • Foreign Exchange Dealing

TransFi Canada offers the following services related to these designations:

  • Cross-border remittance transactions to business entities only.
  • Cross-border remittance transactions to individual and entity clients.
  • Cross-border remittance transactions for high net wealth individuals to business entities only.
  • Cross-border remittance transactions for high net wealth individuals to individual and entity clients.
  • Invoice payment services.
  • Payment process services enabling e-commerce Merchants to accept Canadian domestic banking rails such as Interac E-Transfer services.
  • Foreign Exchange services enabling clients to exchange various currencies at favorable rates.

TransFi Canada does not deal with cash, cheques, money orders, or other payment instruments not listed in the flow of funds below.

3.2 Simple Flow of Funds

Payout — CAD to fiat and Fiat to CAD

Typical Product Journey

  1. A Client seeking to use TransFi Canada's services signs up on TransFi Canada and after completion of KYC/KYB procedures and other compliance checks as well as after agreeing to the Business Services Agreement of TransFi Canada, gets onboarded.
  2. Client signs up a Merchant that they want to offer TransFi Canada's product. The Merchant gets onboarded post KYB and other compliance checks and after agreeing to TransFi Canada's Payments T&Cs.
  3. The Client/Merchant can then select the option to "Add Contact" (a new payee/counterparty). The Client/Merchant can select the contact type (business v individual), country/region, name, email ID and other details.
       
    a) For fiat payouts: The Client/Merchant can add the payee/counterparty's bank account details.

    b) For CAD payouts: The Client/Merchant can add the payee/counterparty's CAD bank account details.

  4. The Client/Merchant can then select the option to make a payment to the payee/counterparty. The Client/Merchant is asked to provide the payment purpose and to confirm the fiat currency/stablecoin in which they will send TransFi the money (Payin currency), against which the payout would be initiated.
  5. Once the Client/Merchant selects the payin currency and the payout currency and required payout amount, the next step depends on whether the payin is done in CAD or fiat:
       
    a) For CAD Payin — The Client/Merchant can choose which payment method they want to send CAD in like interac, domestic wire or billpay (any such CAD payments would be made to TransFi Canada account/sub-account with TransFi Canada LLPs that processes the fiat currency) and they will be displayed how much CAD they would need to send, in order to initiate payout of the required amount. TransFi Canada will display the price of the transaction on the TransFi Canada Pay dashboard. This price will be displayed for a maximum of 5 minutes during which the Client/Merchant is able to accept it. If accepted during the aforementioned period, the Client/Merchant is required to send the required amount of CAD using the method selected, after which, the order to send payout will be considered final and TransFi Canada will execute the order.

    b) For Fiat payin — The Client/Merchant can choose which fiat currency they would want to prefund their balance with (any such fiat payments would be made to TransFi Canada account/sub-account with TransFi Canada LLPs that processes the fiat currency) and they will be displayed how much fiat they would need to send, in order to initiate payout of the required amount. TransFi Canada will display the price of the transaction on the TransFi Canada Pay dashboard. This price will be displayed for a maximum of 5 minutes during which the Client/Merchant is able to accept it. If accepted during the aforementioned period, the Client/Merchant is required to send the required amount of fiat using the method selected, after which, the order to send payout will be considered final. TransFi Canada shows the updated account balance real-time in the Client/Merchant's account on the TransFi Canada Pay product.
  1. Upon receipt of such transfer by TransFi Canada, the corresponding payout to the designated counterparty shall be initiated automatically.
  2. TransFi Canada processes the transaction the same day either real time or within a few hours depending on terms signed up with the Client/Merchant.
  3. The transaction details are then shown to the Client/Merchant and processing done
       
    a) For fiat payouts: The transaction details shown are the status of transaction, amount of fiat the payee/counterparty will receive, and any fees the Client/Merchant will pay in connection with the transaction.

    b) For CAD payouts: The transaction details shown are the status of transaction, the amount of CAD the payee/counterparty will receive and any fees the Client/Merchant will pay in connection with the transaction.
  1. The transaction is subjected to transaction monitoring, fraud and other compliance checks.
  2. The Client/Merchant can monitor the status of all settled and unsettled payouts on the TransFi Canada Pay dashboard.
  3. Funds in local currency with local partners/bank are then, later on, converted to stablecoins offline, net of any payouts, by TransFi Canada's treasury and vice versa.

Section 4: Regulatory Overview

Money service businesses are subject to the regulations under Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and associated regulations. As a money service business, TransFi Canada is required to:

  • Identify clients according to MSB Guidelines;
  • Report eligible transactions;
  • Facilitate an independent review of the company's compliance program every two years at minimum;
  • Conduct AML/CTF staff training;
  • Implement a written compliance program; and
  • Implement a risk-based approach for service delivery.

TransFi Canada has implemented a compliance program to meet the requirements designated by FINTRAC.

At any time, TransFi Canada is subject to audits of this program by FINTRAC and other regulatory bodies.

4.1 Definitions

4.1.1 Money Laundering

Money laundering is the process of taking money obtained through illicit means and disguising the source to make it appear legitimate. Money laundering typically takes places in three stages:

  • Placement – initial deposit of proceeds of crime into the financial system, placement may or may not include the predicate offence from which illicit funds were derived.
  • Layering – conducting multiple transactions and/or transfers to convert illicit funds to another form and obfuscate the true source/original placement.
  • Integration – withdrawal or conversion of the funds to a "clean" form. Money laundering may, or may not be, accompanied by a predicate criminal offence.
4.1.2 Terrorist Financing

Terrorist financing is the process of moving funds in relation to terrorist activities. The source of funds may come from legitimate sources and does not always involve additional illicit activity or money laundering. Terrorist financing is defined as the collection, provision or receipt of money or other property for the purpose of it being used, or in the knowledge that it is intended to be used to:

  • To commit particularly serious crimes as referred to in section 74 of the PCMLTFA (every person or entity that knowingly contravenes any of the sections, subsections or the regulations listed, is guilty of an offence.)
  • By a person or persons forming an association that commit such crime as referred to in section 3 of the PCMLTFA or is guilty of attempt, preparation, conspiracy or complicity in such crime, or
  • For such travel as referred to in Criminal Responsibility for Public Provocation, Recruitment and Training concerning Terrorist Offences and other Particularly Serious Crimes.
4.1.3 Money Service Business

A person or entity with a presence in Canada engaged in providing at least one of the following services:

  • Dealing in virtual currencies,
  • Foreign exchange dealing;
  • Remitting funds or transmitting funds by any means or through any person, entity or electronic funds transfer network,
  • Issuing or redeeming money orders, traveler's cheques or other similar negotiable instruments except for cheques payable to a named person or entity, or
  • Crowd-funding platform services.

Money services businesses (MSBs) must fulfill specific obligations as required by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and associated Regulations, to help combat money laundering and terrorist activity financing in Canada and abroad.

4.1.4 FINTRAC

The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) is Canada's Financial Intelligence Unit (FIU) agency that regulates Money Service Businesses and money service activities. FINTRAC issues requirements and guidance for the obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and associated acts.

4.1.5 Financial Action Task Force (FATF)

The Financial Action Task Force (FATF) is an international and intergovernmental organization that aims to develop and promote policies focused on combating money laundering, terrorist financing, and other related threats to the integrity of the international financial system. FATF sets standards and provides recommendations that member countries are expected to implement. The organization's work includes monitoring the progress of member countries implementing these standards, reviewing measures taken, and promoting effective legislative, regulatory, and operational measures. FATF's recommendations are widely recognized as the global standard for compliance best practices in relation to anti-money laundering and counter-terrorist financing.

4.1.6 Business Relationship

The relationship established between a Money Service Business and its Clients for financial transaction services. Money Service Business enter a business relationship under the following two conditions:

  • A Client's identity is verified a second time within a 5-year period. This equates to a Client transacting equal to or greater than CAD 1,000 on two separate occasions.
  • Engaging in a written service agreement with a Client for services related to financial transactions.

Business relationships carry verification and record keeping obligations to meet regulatory requirements and combat money laundering activity within Canada.

4.1.7 Tipping Off

In Canada, tipping off offenses under anti-money laundering regulations refer to the illegal act of informing a person or entity that they are the subject of a suspicious transaction report or an ongoing investigation by authorities. This is prohibited because it can compromise the investigation and allow the suspect to alter their behavior, destroy evidence, or flee. Violations of this rule can result in significant penalties, including fines and imprisonment.

4.1.8 24 Hour Rule

The 24-hour rule in Canadian regulations mandates that MSBs aggregate multiple transactions conducted by or on behalf of the same individual or entity within a 24-hour period when determining whether they meet the reporting thresholds for large cash transactions or electronic funds transfers. This means if the total amount of transactions reaches or exceeds $10,000 in a single day from the same individual or entity.

4.1.9 Ministerial Directives

Ministerial Directives are issued by the Minister of Finance of Canada to safeguard Canada's financial system. Measures are enacted to counter threats from foreign jurisdictions or entities that are identified to pose a significant risk for enabling money laundering and terrorist financing activities. The directives mandate reporting entities to implement countermeasures on transactions originating from or directed to designated foreign jurisdictions or entities.

4.1.10 Politically Exposed Persons & HIOs

FINTRAC divides PEPs into two categories: Foreign and Domestic.

Foreign Politically Exposed Person (Foreign PEP)

A foreign PEP is an individual who holds or has held one of the following offices or positions in or on behalf of a foreign state:

  • Head of state or head of government
  • Member of the executive council of government or member of a legislature
  • Deputy minister or equivalent rank
  • Ambassador, or attaché or counsellor of an ambassador
  • Military officer with a rank of general or above
  • President of a state-owned company or a state-owned bank
  • Head of a government agency
  • Judge of a supreme court, constitutional court, or other court of last resort
  • Leader or president of a political party represented in a legislature

Important Note: According to FINTRAC, once an individual is determined to be a foreign PEP, they remain a foreign PEP forever (even after death). All Foreign PEPs are automatically classified as High Risk

Domestic Politically Exposed Person (Domestic PEP)

A domestic PEP is a person who currently holds, or has held within the last 5 years, a specific office or position in or on behalf of the Canadian federal government, a provincial (or territorial) government, or a municipal government:

  • Governor General, lieutenant governor, or head of government
  • Member of the Senate or House of Commons, or member of the legislature of a province
  • Deputy minister or equivalent rank
  • Ambassador, or attaché or counsellor of an ambassador
  • Military officer with a rank of general or above
  • President of a corporation that is wholly owned directly by the Crown in right of Canada or a province
  • Head of a government agency
  • Judge of an appellate court in a province, the Federal Court of Appeal, or the Supreme Court of Canada
  • Leader or president of a political party represented in a legislature
  • Mayor, reeve, or other similar chief officer of a municipal or local government

Important Note: An individual ceases to be a domestic PEP 5 years after they have left office (or upon death).

Head of an International Organization (HIO)

A HIO is an individual who currently holds, or has held within the last 5 years, the office or position of head of an international organization. To qualify, the organization must be:

  • An international organization established by the governments of states (e.g., the United Nations, NATO, the World Bank).
  • An institution established by an international organization (e.g., the World Health Organization).

Important Note: Similar to domestic PEPs, a person ceases to be an HIO 5 years after they leave the position (or upon death).

Family Members and Close Associates

Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), reporting entities must also apply measures to the family members and close associates of PEPs and HIOs, as their proximity makes them vulnerable to being used for illicit financial activities.

Family Members are strictly defined as:

  • Spouse or common-law partner
  • Biological or adoptive children
  • Mother or father
  • Mother or father of the spouse or common-law partner (mother-in-law or father-in-law)
  • Children of the mother or father (siblings or half-siblings)

Close Associates are individuals who are reasonably known to be closely connected to the PEP or HIO. This can include:

  • Business partners or individuals who beneficially own/control a business with the PEP/HIO
  • Individuals in a romantic relationship with the PEP/HIO
  • Prominent members of the same political party, union, or board
  • Individuals closely carrying out charitable works with the PEP/HIO
  • Individuals jointly listed on policies or involved in financial transactions with the PEP/HIO
4.1.11 Proliferation Financing

Proliferation financing refers to the act of providing funds or financial services that contribute, in whole or in part, to the development, production, acquisition, possession, transfer, or deployment of chemical, biological, radiological, or nuclear (CBRN) weapons and their means of delivery, in contravention of international law.

Proliferation financing is distinct from terrorist financing in that the funds may originate from entirely legitimate sources and may not involve conventional money laundering activity. The complexity of proliferation financing schemes means that transactions may appear commercially legitimate on the surface, with common typologies including:

  • Front companies and intermediaries used to obscure the true end-use or end-user of goods or funds
  • Trade-based concealment through misrepresentation of the nature, quantity, or value of goods in international trade documentation
  • Correspondent and nested relationships exploited to move funds across jurisdictions without triggering scrutiny
  • Shell companies and complex ownership structures used to distance the ultimate beneficiary from the transaction

Regulatory Basis

As a Money Service Business registered with FINTRAC, TransFi Canada is subject to the United Nations Act and the Special Economic Measures Act, both of which give effect to United Nations Security Council Resolutions (UNSCRs) targeting proliferation financing, including Resolutions 1540, 1718, 1737, 1747, 1803, 1929, and 2231. Compliance with these resolutions and associated Canadian sanctions regulations is mandatory.

FINTRAC's guidance on money laundering and terrorist financing risk assessment requires reporting entities to assess their exposure to proliferation financing as part of their enterprise-wide risk assessment (EWRA). TransFi Canada incorporates proliferation financing risk into its EWRA and reviews this assessment at least annually.

TransFi Canada's Obligations

TransFi Canada must:

  • Screen all clients, beneficial owners, directors, and counterparties against UN Security Council consolidated sanctions lists and Canadian autonomous sanctions lists for proliferation-related designations, in addition to standard sanctions screening conducted through SumSub and Accend
  • Apply enhanced scrutiny to transactions involving dual-use goods, technology sectors, or jurisdictions associated with CBRN proliferation risk, including those subject to Ministerial Directives (currently DPRK, Iran, and Russia)
  • Treat any transaction where there are reasonable grounds to suspect a link to proliferation financing as a Suspicious Transaction Report (STR) obligation under the PCMLTFA, regardless of the transaction value
  • Maintain records of all proliferation financing-related screening, reviews, and escalations for a minimum of five years

Risk Indicators

The following indicators may suggest exposure to proliferation financing risk and must be escalated to the Compliance Officer:

  • Clients or counterparties operating in, or transacting with, jurisdictions subject to UN or Canadian proliferation-related sanctions
  • Transactions involving technology companies, logistics providers, or trading entities in high-risk jurisdictions without a clear commercial rationale
  • Complex or opaque ownership structures where the ultimate beneficial owner cannot be confirmed and the client operates in a sector with dual-use potential
  • Payments to or from entities that appear on, or are associated with entities on, the UN 1267/1989/2253 ISIL and Al-Qaida Sanctions List or any UNSCR-related consolidated list
  • Requests to structure transactions in a manner that obscures the origin, destination, or purpose of funds in the context of international trade

Where proliferation financing is suspected, the CAMLO must be notified immediately. An STR must be filed with FINTRAC and, where the activity may involve UN-listed entities or sanctioned property, a Listed Person or Entity Property Report must also be submitted to FINTRAC, CSIS, and the RCMP.

4.2 Canadian Money Service Business Requirements

4.2.1 FINTRAC MSB Registration

Money Service Business (MSB)s must register with Financial Transactions and Reports Analysis Centre of Canada (FINTRAC), Canada's Financial Intelligence Unit (FIU) and maintain an active registration while offering money services including:

  • Remain active while offering money services;
  • List the appropriate money service designations;
  • Be current with director, officer, ownership and associated financial institutions;
  • Respond to clarification requests in the prescribed form and manner;
  • Renew the registration before the expiry date; and
  • Notify FINTRAC within 30 days if money service activities cease to offer.
4.2.2 Revenue Québec MSB Registration

Revenue Québec is the regulatory body maintaining the province's MSBs in licensing and compliance. The Quebec MSB Act defines MSBs more broadly than the Canadian federal definition and includes provincial licensing and registration requirements. TransFi Canada does not operate in Québec or service Québec customers and is not required to register as an MSB with Revenue Quebec.

4.2.3 FINTRAC Travel Rule

FINTRAC has implemented the travel rule requirements for virtual currency transfers that require documentation and retention of specific information associated with these transfer activities.

4.2.3.1 VC Travel Rule

Travel rule information records must be kept by TransFi Canada when sending VC transfers and take reasonable measures to ensure Travel Rule information is included when receiving virtual currency. Travel rule information must be retained and included in applicable FINTRAC reports:

  • Name, address and account/reference number of the person or entity that requested the transfer (originator information); and
  • Name, address and account/reference (if any) of the beneficiary.

Travel rule information is obtained through onboarding, due diligence and compliance monitoring practices.

Note:If TransFi Canada is unable to obtain required Travel Rule information despite "reasonable measures," the transaction must be reviewed by the Compliance Officer to determine if it should be rejected, held, or reported as suspicious.

4.2.4 Sanctions Requirements

Sanctions are measures or actions taken against a target to influence behavior, policy, or actions. These measures typically have three components:

  1. an economic action;
  2. the identification of a target (such as a country, an individual, an entity or a specific function); and
  3. the intended influence on the target's actions.

Sanctions can restrict trade, financial transactions, diplomatic relations, and movement. They may be implemented and enforced either specifically or generally. The Government of Canada imposes economic sanctions under three federal statutes and acts related to trade measures and restrictions:

  • The Criminal Code
  • United Nations Act
  • Justice for Victims of Corrupt Foreign Officials Act
  • Special Economic Measures Act
  • OFAC
  • HM treasury list
  • The State Department Foreign Terrorist Organizations List and Non-Proliferation List
  • US DOJ (FBI, DEA, US Marshals, and others)
  • Freezing Assets of Corrupt Foreign Officials Act

Canadian sanction laws prohibit Money Service Businesses engaging with designated persons, jurisdictions, and specific sectors. Compliance with sanctions law is mandatory and requires screening, monitoring, and reporting to meet obligations. Obligations for Canadian individuals and businesses remain under subsection 83.1(1) Criminal Code (R.S.C., 1985, c. C-46). Canadian sanctions laws impose strict liability for direct and indirect dealings with sanctioned persons or organizations. These laws also require TransFi Canada to comply with asset-freezing obligations to prevent sanctioned parties from accessing financial or material resources. TransFi Canada is dedicated to adhering to all applicable Canadian laws and regulations concerning sanctions evasion. Sanctions evasion occurs when individuals or entities attempt to circumvent restrictions imposed under Canadian laws. Common methods include structuring transactions through intermediaries or high-risk jurisdictions or obscuring the identity of sanctioned parties. Any suspected evasion activities must be promptly reported to the Compliance Officer for investigation and reporting to FINTRAC through suspicious transaction reports (STRs) and relevant authorities, such as the RCMP and CSIS.

4.2.5 Ministerial Directives

Ministerial Directives and transaction restrictions are issued by the Minister of Finance that mandate reporting entities to implement countermeasures for transactions originating from, or destined for, specific foreign jurisdictions or entities that are considered to present high risks for facilitating money laundering and terrorist financing. These measures allow the Minister of Finance to take steps to protect Canada's financial system and support MSBs in combating money laundering and terrorist financing through money service activities. Each directive outlines countermeasures to either enhance or expand upon current obligations that exist under existing obligations for Money Service Businesses. The directives specify the effective date and will remain active until they are officially revoked, suspended, or amended. Current Ministerial Directives issued by Canada as of July 31, 2024 include:

  • February 24, 2024: Russia
  • July 25, 2020: Islamic Republic of Iran (updated February 24, 2024)
  • December 9, 2017: Democratic People's Republic of Korea (DPRK)

Compliance with Ministerial Directives and transaction restrictions is mandatory. FINTRAC monitors and assesses compliance with AML directives under the PCMLTFA and may examine records or inquire into the business activities of entities covered under the Act. Compliance activities, such as on-site or desk-based examinations, may now include reviewing adherence to Ministerial Directives. TransFi Canada does not allow individuals, entities or transactions linked to countries subject to Ministerial Directives under any circumstances.

4.3 Non-Compliance

Compliance with FINTRAC regulations is mandatory. Failure to adhere to regulations and legislation may lead to severe criminal or administrative penalties. Monetary penalties for non-compliance are related to the following activities:

  • Failure to report a suspicious transaction;
  • Reporting information that demonstrated non-compliant activity, entities, individuals, relationships, jurisdictions, or flow-of-funds; and
  • Reporting information that is non-compliant or inaccurate which enhances the efficiency of FINTRAC's analysis.

Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), criminal penalties criterion are defined as:

  • General offences, including the failure to register as a money services business, to verify client's identity, and to keep prescribed records;
  • Reporting offences for suspicious transactions;
  • Reporting offences for electronic funds transfers, large cash transactions, large virtual currency transactions, and casino disbursements; and
  • Money services business registration information offences for providing false or misleading statements or information to FINTRAC.

FINTRAC Registration Maintenance

TransFi Canada shall ensure its registration with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) remains accurate and current. The Compliance Officer is mandated to update FINTRAC registration information within 30 days of any change to the entity's status, ownership, or operations.

Section 5: TransFi Canada's Compliance Program

TransFi Canada is committed to mitigating money laundering and illicit activity associated with provided services, follows the measures required by the PCMLTFA, governed by an established written compliance program implementing a risk-based approach to prevent money laundering, and will provide reasonable assistance to law enforcement and regulatory bodies in the event of an audit or law enforcement request.

The following measures have been implemented into this compliance program to meet regulatory requirements in Canada:

  • Appointment of a dedicated, knowledgeable Compliance Officer responsible for overseeing AML/ATF program to ensure compliance with all applicable laws and regulations.
  • Maintaining a risk-based approach management program that assesses inherent risk, mitigation efforts, and the resulting residual risk factors as they relate to service delivery.
  • Conducting annual AML/ATF staff training pertaining to Canadian regulations that is documented with written testing components to assess company-wide understanding of regulatory obligations.
  • Implementation of a written compliance program outlining company policies to meet reporting, record keeping, and customer identification obligations that is approved by senior management.
  • Scheduled independent reviews of the compliance program to assess the efficacy and relevance of the compliance regime that are conducted every two years.
  • The first independent effectiveness review commencement date is 26/01/2026 scheduled to take place two years after obtaining registration approval from FINTRAC on 26/01/2024.
  • The Board of Directors holds ultimate accountability for the AML/CTF program. Their responsibilities include:
    • Approval of the AML/CTF Policy and Risk Assessment.
    • Appointment of a qualified Compliance Officer.
    • Ensuring adequate resources are allocated to financial crime prevention.
    • Reviewing the results of biennial effectiveness reviews and ensuring timely remediation of gaps.

5.1 Appointment of a Compliance Officer

A Compliance Officer is responsible for implementing and managing day-to-day compliance and anti-money laundering activities of money service business operations. The Compliance Officer reports directly to the Board of Directors and is independent from all other departments/divisions.

Duties and responsibilities of the Compliance Officer include:

  • Develop and maintain written compliance policies and procedures.
  • Develop and maintain an enterprise-wide risk assessment (EWRA) to outline inherent risk and identify mitigation measures to support residual risk management and guide day to day operations.
  • Review and evaluate external partnerships with vendors, acquirers, and other parties to ensure that they align with overall risk appetite.
  • Monitoring regulatory changes and adjusting or modifying risk management policies to ensure the compliance program remains compliant.
  • Facilitate AML staff training to be conducted once per year at minimum.
  • Coordinating independent effectiveness reviews of the compliance program every two years at minimum.
  • Act as the point of contact for law enforcement, regulatory bodies, and other external parties.
  • Reporting semi-annually to the CEO and Board of Directors on compliance activities and the status of the compliance regime.

5.2 Risk-Based Approach

Implementing a risk-based approach can contribute to preventing money laundering before it occurs. An RBA (Risk-Based Approach) is a tool utilized to assess risk associated with service delivery and to applying control measure to mitigate these risks where possible:

  • Inherent risk exists before the implementation of controls or mitigation measures.
  • Residual risk remains after controls or mitigation measures have been implemented to reduce the likelihood of Money Laundering, Terrorist Financing or an illicit activity event occurring.

An Enterprise-Wide Risk Assessment (EWRA) must be maintained at all times to guide a risk-based approach and evaluate money laundering and terrorist financing risks related to services, clients, geographic regions, operations, and regulatory risks. The assessment will be reviewed and updated at least annually to reflect new and emerging risks, legislative changes, and updates made to the business model and services. Implementation of new technologies, products, and services must first undergo assessment for money laundering and terrorist financing risks before it is implemented in operations and be maintained in the documented risk assessment to ensure proper risk assessment and mitigation.

Risk management measures are assessed to strike a balance between TransFi Canada's ability to operate efficiently and meet FINTRAC's risk assessment guidelines. Results of overall risk assessments are used to ensure the quality of adapted risk-based measures, including:

  • Customer due diligence procedures and processes;
  • Ongoing follow-up;
  • Transaction monitoring;
  • Internal checks;
  • Resource allocation and to guide staff AML training.

TransFi Canada presents a low overall residual risk and does not tolerate residual high-risk ratings in any category. Mitigation measures have been implemented to reduce inherent high risks intrinsically associated with services by outlining proactive compliance protocols tailored to business specific risk factors.

Client Risk-Rating Methodology

Clients are assigned a risk rating (Low, Medium, or High) based on a weighted scoring matrix. This methodology evaluates:

  • Geography: Residency in high-risk jurisdictions.
  • Products: High-velocity or anonymous-leaning services.
  • Delivery Channel: Non-face-to-face vs. in-person.
  • Entity Type: Complexity of ownership structure.
  • Behavioral Patterns: Deviations from expected activity.

Beneficial Ownership and Discrepancy Reporting

  • Effective October 1, 2025, entities regulated by FINTRAC must report any material discrepancies found between beneficial ownership information obtained and the individuals with significant control (ISC) listed in Corporations Canada's database. This reporting obligation applies when a reporting entity determines that an active corporation governed by the Canada Business Corporations Act (CBCA) presents a high risk of involvement in money laundering or terrorist activity financing.
  • All reporting entities, excluding title insurers, are required to take reasonable steps to verify the accuracy of beneficial ownership information both at initial acquisition and during ongoing monitoring of business relationships. Should a reporting entity assess a CBCA corporation as high risk for money laundering or terrorist activity financing, it must consult Corporations Canada's database and compare its collected beneficial ownership data with ISC records to identify any material discrepancies.
  • For CBCA corporations not deemed high risk, reporting entities may voluntarily submit a Beneficial Ownership Discrepancy Report to Corporations Canada if a material discrepancy is identified.
  • TransFi must report any material discrepancy to Corporations Canada within 30 days of identification. Reporting is not required if the discrepancy is resolved within 30 days of being identified.

Termination of Business Relationships

The "Business Relationship" and all associated ongoing/enhanced monitoring conclude only when:

  • The account/service agreement is formally closed.
  • TransFi ceases to provide any MSB-specific services to the client.
  • The final transactional "cool-down" period (as defined in the Risk Assessment) has elapsed.

An independent Enterprise-Wide Risk Assessment (EWRA) document is maintained and is utilized to guide this AML Policy. The most current and detailed EWRA can be found in TransFi Canada Business Wide Risk Assessment.

5.3 Customer Due Diligence

Verifying client identity is required through FINTRAC's acceptable methods of verifying used to identity a person or entity. Client information and documentation is used to confirm existence and associated risk. Customer Due Diligence applies to all clients regardless of application method, if a client cannot be identified, they will not be approved for services.

The Company is a B2B2C business and shall provide Services to Business. The end users can be both natural persons and legal entities. The Company provides services primarily to the business who are Customers-Clients, Merchants, and end users. Both the Merchants and the End Users receive Services and both these subjects are considered as Customers of the Company, who shall be identified accordingly. TransFi's current product suite is described below. All of these products are available as both a solution and as a single Application Programming Interface ("API") and provide a dashboard or other solution for monitoring transactions and orders:

  • Payins: Enabling our Clients/their Merchants to collect payments in fiat currency (e.g. the US Dollar or Euro) or stablecoins from their counterparties (both businesses or individuals) by sending a payment link and settling in stablecoins or fiat, as desired, with ease from anywhere across the world.
  • Payouts: Enabling our Clients/their Merchants to pay their employees, vendors, freelancers, and trade partners globally in fiat or stablecoins across the world by exchanging crypto-assets for fiat (stablecoin-to-fiat) or exchanging fiat for crypto-assets (fiat-to-stablecoin) or crypto-assets for crypto-assets (crypto-to-stablecoin).

Ramp:Enabling our Clients to offer the exchange of fiat to crypto-assets (fiat-to-crypto "onramp") and the exchange of crypto-assets to fiat (crypto-to-fiat "offramp") to their Merchants and/or End Users.

KYC — Individuals

We have tiered based KYC structure, namely,

  • Basic KYC
  • Standard KYC
  • Enhanced KYC
Basic KYC Standard KYC Enhanced KYC
First name, last name, DOB/email ID, country of citizenship, address, crypto wallet address (crypto), phone (optional) First name, last name, email ID, country of citizenship, address, ID number, phone (optional) Proof of source of funds, Proof of address
ID document ID document Proof of source of funds, Proof of address

Product-Specific Controls: The KYC requirements outlined above represent the minimum standard. Depending on the product or service being used and the associated risk, the Company may request additional information, documentation as deemed necessary.

Individual Verification

The Customer (natural person) identification and ID document validity verification shall be performed following these steps:

5.4 Registration

The Customer shall enter First name, Last name, Date of Birth, Email, the country of citizenship on the web page dedicated to onboarding;

5.5 Identification

The Company applies remote identification – via real-time selfie and ID document photo (video) transmission. Namely: In case of a photo transmission:

A. The Customer shall take a photo of his / her ID document. 

Only the following ID documents can be accepted for Customer due diligence purposes. The Company shall accept only those ID documents that are valid and only if there are no circumstances showing possible forgery of the ID document:

  • Passports,
  • National ID cards,
  • Any other acceptable ID allowed by regulation

The collected ID document shall contain the following information about the Customer:

  • Name(s);
  • Surname(s);
  • ID number
  • Photo;
  • Citizenship

Individuals are required to provide the following information to aid in identity verification, client due diligence, reporting and record keeping requirements:

  • Full name;
  • Date of birth;
  • Email;
  • Phone number;
  • Address; and
  • Occupation.

TransFi Canada utilizes FINTRAC's Government Issued Photo Identification Method to verify individual applicants, ultimate beneficial owners (UBO), and authorized signatories of entity applicants. Under this method, the provided government issued ID documents must meet the following criteria:

  • Be genuine and have the characteristics of an original and credible document that is unaltered;
  • Not be invalid due to a name change or similar occurrence;
  • Must be up to date and not past expiry at the time of verification;
  • Be issued by a federal or national government;
  • List the individuals full name;
  • Have a unique identification number;
  • Include a photo of the individual; and
  • Match the name and likeness of the individual applicant.

Applicants are onboarded through non-face to face interactions and are not physically present during authentication; therefore, additional measures must be taken during verification. The following measures are acceptable for non-face-to-face ID verification:

  • Liveness selfie verification.

Individuals under the age of 18 years are not onboarded for individual services under any circumstances. Additionally, individuals over 70 years are not onboarded for any services under any circumstances.

5.5.1 Entity Verification

The Confirmation of Existence method is utilized to verify all entities under current operational practices. Entities include Corporations, Partnerships. In all cases the existence of an entity must be confirmed to be authentic, valid, and current. Certain entity structures carry increased risk for money laundering and terrorist activity and require additional measures to verify such as Charities and Trusts. Document requirements to support confirmation of existence include:

  • Being genuine and have the characteristics of an original and credible document that is unaltered;
  • Not be invalid due to a name change or similar occurrence;
  • Be issued by or registered with a federal, national, or state registry;
  • List the entity registered name;
  • Contain the entity's address; and
  • List the names of the Directors for the entity (if applicable).

The following documents for business entity verification are considered acceptable:

  • Certificate of Incorporation (COI);
  • Articles of Association/ Company Bylaws;
  • Self certified Shareholder Register;
  • Proof of address
  • Self certified Director's Register

Charities, Non-Government Organizations and Trusts present a heightened risk for Money Laundering, Terrorist Financing, and illicit activity due to the intrinsic structure. Entities under this category will automatically be categorized as high risk and undergo Enhanced Due Diligence with approval from TransFi Canada's Compliance Officer required before being approved to transact. When publicly available, the existence of an entity is confirmed and referenced against the provided documentation via the issuing corporate registry. Publicly available information is used to record and document additional information regarding the entity.

TransFi Canada does not onboard:

  • Known beneficiaries of Corruption or Illegal Activities;
  • Shell companies/shell banks;
  • Unregulated casinos or gambling companies;
  • Incomplete or failed KYB (Know your business);
  • Unlicensed money transmitters / payments / financial services companies; and
  • Customers with bearer shares in the ownership structure.
  • Marijuana/cannabis;
  • Guns, Arms and ammunition;
  • Precious metals;
  • Cash Intensive Businesses;
  • Adult content or Pornography;
5.5.1.1 Beneficial Ownership Requirements

Beneficial Ownership information must collect for all business entities. Beneficial ownership varies based on a business entity structure and can include:

  • All individuals who own or control, directly or indirectly, 20% or more of the business entity.

The following information must be collected regarding beneficial owners and directors of a business entity:

  • Full legal name (no initials, short forms or abbreviations);
  • Full home address (post office boxes, business offices and general delivery addresses are not acceptable for this purpose);
  • The role and/or ownership stake in the organization; and
  • UBO's KYC
5.5.2 Indirect Beneficial Ownership

Indirect beneficial ownership is when the ultimate beneficial ownership stake is through an intermediary entity or through a chain of ownership entities, rather than holding it directly through individual shareholders. All shareholder business entities will be verified under the entity verification requirements outlined in this policy until Ultimate Beneficial Individual Owners of 20% or more are identified and verified pursuant to this policy.

5.5.3 Third Party Determination

A third party refers to an individual or entity that directs another person or entity to perform a transaction or activity on their behalf. In this context, the third party is the instructing party and is understood to be acting "on behalf of" someone else. TransFi Canada must take reasonable measures to determine whether a third party is involved in a transaction. Indicators that may suggest third-party involvement include:

  • An unusual or inconsistent source of funds relative to the client's profile
  • The client demonstrates limited knowledge of the transaction details
  • Instructions for the transaction are being provided by someone other than the client

If a third party is identified, the following information must be documented in the client's profile:

  • If the third party is an individual: their full name, address, date of birth, and occupation
  • If the third party is a corporation or entity: their name, address, nature of business, registration number, and jurisdiction of issue
  • The nature of the relationship between the third party and the client

Third parties are not permitted to conduct transactions through TransFi Canada's services under any circumstances. Where third-party involvement is identified or suspected, the matter must be escalated to the Compliance Officer for review and a determination made as to whether a Suspicious Transaction Report is required.

5.5.4 Risk-Based Due Diligence for Licensed and High-Profile Customers

In the onboarding of a customer that meets the following criteria, the organization shall apply a risk-based approach to due diligence:

  • Licensed Status: The customer, if applicable, must hold a valid and active license from a recognized regulatory authority.
  • Established Market Presence: The customer must be a well-known entity in the market, with a proven track record of compliance and stability.
  • Risk-Based Due Diligence Steps:
       
          Open-Source Research: Conduct comprehensive searches of public internet sources to verify the customer reputation and operational history.
  • Public and Government Databases: Cross-check the customer credentials, including license validity, through official public records and government databases.
  • Verification of Licensing: Ensure that all licenses are current and in good standing.

5.6 Sanction and Applicant Screening

Applicants are screened against numerous sanctions and screening watch lists through third party compliance tools SumSub and Accend which utilizes over 1700 global databases to screen for exposures related to sanctions, PEPs, HIOs and watch lists. Individuals, Business Entities, Ultimate Beneficial Owners, Directors and other authorized signatories are screened prior to transacting and set to continuous monitoring where new listings publications are referenced against internal client lists where new alerts and associations trigger an email notification to the Chief Compliance Officer for manual review. Sanctioned individuals and entities will not be permitted to transaction through offered services under any circumstances. Sanctions associations identified during onboarding or through client monitoring procedures must result in submission of a Suspicious Transaction report to FINTRAC, at minimum.

If sanctioned funds are believed to be in TransFi Canada's possession at any time, the Chief Compliance Officer, Senior Management and General Counsel must be contacted immediately as funds seizures obligations may apply. TransFi Canada does not onboard sanctioned individuals or business entities, under any circumstances. PEPs and HIOs are only onboarded on a case by case basis, after Enhanced due Diligence and with the approval of the Compliance Officer. TransFi Canada does not have any PEP or HIO clients currently.

5.7 Client Risk Rating and Classification

Applicant and Client Risk Assessments are utilized to support compliance monitoring, suspicious transaction monitoring and investigations, and the overall understanding of the active Business Relationships to aid in day-to-day operations and risk mitigation processes.

Risk factors that must be considered while assessing Individuals must include the following considerations and minimum:

  • Services Provided;
  • Service delivery channel;
  • Payment methods;
  • Demographic;
  • Occupation; and
  • Jurisdiction.

Risk factors that must be considered while assessing Business Entities must include the following considerations and minimum:

  • Services provided;
  • Service delivery channel;
  • Business structure;
  • Nature of business; and
  • Jurisdiction.

Clients are divided into three categories during risk assessment evaluation and are assigned to low, medium, and high categories each with specific parameters surrounding onboarding requirements and compliance monitoring procedures related to transaction monitoring and Client maintenance schedules and practices.

Low Risk:Profile presents an overall low risk for money laundering for all identified risk factors with no presence of high-risk or eliminating factors governed by this policy. Low risk Clients are subject to standard transaction monitoring procedures, and a client maintenance reassessment every 36 months to update client information, assess for newly presented risks, and ensure verification documents are kept up to date.

Medium Risk:Profile presents an overall medium risk for money laundering for all identified risk factors with presence of increased risk factors such as vulnerable demographics or nature of business with no presence of high-risk or eliminating factors governed by this policy. Medium risk Clients are subject to standard transaction monitoring procedures, and a client maintenance reassessment every 24 months to update client information, assess for newly presented risks, and ensure verification documents are kept up to date.

High Risk:High risk classifications are subject to Enhanced Due Diligence, increased monitoring, and schedule reassessment to monitor and mitigate risk associated with this classification category. High risk classifications may be triggered by a single factor, such as a presence or association with a high-risk jurisdiction or entities, adverse media, or business entity structure. Multiple, high-risk factors can also accumulate to lead to high-risk rating. High risk Clients are subject to increased transaction monitoring procedures, and a client maintenance reassessment every 12 months to update client information, assess for newly presented risks, and ensure verification documents are kept up to date.

Reputed Customers:Profile presents an established, verifiable, and favorable standing that warrants recognition as a low-risk, trusted relationship. These are typically well-known, publicly listed, regulated, or otherwise reputable entities (e.g., publicly traded companies, regulated financial institutions, government bodies, or long-standing clients with a demonstrated history of compliant activity and transparent ownership structures) with no presence of high-risk, adverse media, or eliminating factors governed by this policy. Reputed Customers benefit from a verified track record, strong public reputation, and transparent beneficial ownership. Such Clients are subject to standard transaction monitoring procedures, and a client maintenance reassessment every 36 months to update client information, assess for newly presented risks, and ensure verification documents are kept up to date.

Applicants and clients deemed to present unacceptable risk are declined or offboarded for services due to the presence of factors that are outside of the TransFi Canada's risk appetite. All assessments of this nature must be escalated to the Chief Compliance Officer for review and determination whether an Attempted Suspicious Transaction Report (ASTR) or a Suspicious Transaction Report (STR) will be filed with FINTRAC.

Customer Identification Triggers

Identification requirements are triggered by specific Money Services Business (MSB) activities, including:

  • Issuing or redeeming money orders/traveller's checks of $3,000 or more.(not applicable on Transfi Canada)
  • Foreign exchange transactions of $3,000 or more.
  • The opening of a service agreement or business relationship.
  • Any instance of suspicious activity, regardless of dollar value.

Address Verification Standards

TransFi Canada must obtain the full mailing address for all customers.

Note:The use of a Post Office (PO) box or "general delivery" address is strictly prohibited as a primary residence/place of business address.

Corporate and Entity Verification

For all corporate clients, TransFi shall ensure that the name, address, and directors' names collected during onboarding are fully consistent with the official government documents used to verify the corporation's existence (e.g., Articles of Incorporation).

Non-Profit Organizations (NPO) and Charities

During onboarding, staff must confirm if an entity is an NPO.

  • Documentation: While the question may be asked verbally, the answer must be recorded in the client file.
  • Registered Charities: If the entity is an NPO, staff must determine if it is a registered charity in Canada. If so, the Charitable Registration Number must be collected and documented.

Beneficial Ownership Unavailability

TransFi Canada may, under exceptional circumstances, onboard customers whose beneficial ownership cannot be confirmed provided that:

  1. The customer is automatically classified as High Risk.
  2. All "reasonable efforts" to confirm beneficial ownership are documented.
  3. TransFi takes reasonable steps to verify the identity of the Chief Executive Officer (CEO) or the person fulfilling that equivalent role.
  4. It will be reviewed by the Compliance Officer.

Trust Organizations

When identifying trusts, TransFi must collect the full name (no initials or abbreviations), role (full description), and full physical address (no PO boxes) for:

  • All Trustees.
  • All known Beneficiaries.
  • Non-Compliance Rule: Any trust failing to provide this complete information must be classified as High Risk.

Customer Identification Triggers (FINTRAC)

Applicable MSB triggers per FINTRAC's guidance, including:

  • virtual currency transactions of $10,000 or more (as a separate identification trigger, distinct from the LVCTR threshold),
  • Foreign exchange transactions of $3,000 or more, and
  • any suspicious activity regardless of value.
  • When a client transacts at $1,000 or more on a second occasion within five years, that independently triggers identification (confirming a business relationship)

Section 6: Enhanced Due Diligence (EDD)

An Enhanced Due Diligence assessment aims to confirm the legitimacy and further verify an individual, business entity, or source of funds. TransFi Canada's Compliance may apply enhanced due diligence efforts at any stage of a client relationship and for a number of reasons including but not limited to:

  • Individuals of a vulnerable or high-risk demographic.
  • Associations with banned or high-risk industries or clients base for business entities.
  • Associations with banned or high-risk jurisdictions.
  • Transaction patterns or volumes that are outside of established client profiles.
  • Data inconsistencies or missing information.
  • Additional due diligence required to mitigate various red flags at the description of the Compliance Analyst conducting the assessment.

The following customer types are subjected to Enhanced due diligence:

  • Custodial crypto / digital assets services
  • Other crypto / digital assets services that are non-custodial
  • Money services / Payments / other financial services
  • Licensed Gambling services
  • Any customer with a politically exposed beneficial owner

6.1 Enhanced Measures

6.1.1 Elevated Verification

Individual or Business Entity verification includes obtaining more information or documents to confirm the legitimacy of a business entity or individual. This can include obtaining a second Government issued Photo ID, a business plan, certificate of good standing, or licensing and AML Policy, if applicable.

6.1.2 Source of Funds/Wealth

Obtaining documents from the applicant/Client regarding the source of funds or wealth from their client in the form of the most recent three months of unredacted bank statements or audited corporate financials. Acceptable sources of funds:

  • Salary /Business income;
  • Pension releases;
  • Personal savings from legal sources;
  • Share sales and dividends;
  • Property sales;
  • Inheritances and gifts allowed by law;
  • Tax return receipts and other incomes from government;
6.1.3 Online Source Intelligence

Using public databases and search engines to confirm or obtain new information. Confirmation of entity registration or license verification with registration authorities where possible. Searching for social media accounts, highlighting search phrases to include "Scam", "Fraud", "Theft", "Criminal" "Court" and "Warning". Searching addresses and locations in google maps street view to assess whether the location matched the information for the applicant/Client.

6.1.4 PEP specific EDD measures

Source of wealth must be established within 30 days of the business relationship being formed. Source of funds and source of wealth must be obtained for any virtual currency transaction of $100,000 or more. Senior management must review all VC transactions of $100,000 or more involving a PEP before they are carried out or within a reasonable period after.

Section 7: Reporting Requirements

Compliance with reporting obligations is mandatory. Qualified transactions to FINTRAC and other agencies as required. Each report has specific conditions for which types of transactions must be reported and a specific timeline within which a report must be submitted to FINTRAC. FINTRAC reports are submitted electronically through the FINTRAC Web Reporting System (FWR) or FINTRAC Reporting Ingest API. Listed Person or Entity Property Reports are submitted online or offline and through Forms available for download online. Additionally an STR must be filled with FINTRAC through conventional methods. Reports must also be submitted to the Canadian Security Intelligence Service (CSIS) by fax at 613-369-2303 and the Royal Canadian Mounted Police (RCMP) by fax at 613-825-7030. Additionally an STR must be filled with FINTRAC through conventional methods. Tipping off a client associated with a report may be perceived as interfering with a possible investigation. This restriction applies regardless of whether the investigation is active. To avoid inadvertently tipping off a client, all requests for information to support reporting submissions must follow procedures outlined in this policy or be approved by the Chief Compliance Officer. Volume based reports subject to FINTRAC's 24-hour rule are confined to a static 24 hour period that matches any calendar day from 0:00 to 23:59. Multiple transactions from a single Client outside of this timeframe will not be considered for volume based reporting under FINTRAC's 24 hour rule.

7.1 MSB Reporting Requirements Overview

Report Type Information Timeline
Large Cash Transaction Report (LCTR) Upon receipt of Cash (paper or coin money) from a single client in an amount greater than or equivalent to $10,000 CAD in a single transaction or multiple transactions within a 24 hour period. 15 calendar days
Large Virtual Currency Transactions Report (LVCTR) Upon receipt of virtual currency from a single client or commission payment in an amount greater than or equivalent to $10,000 CAD in a single transaction or multiple transactions within a static 24 hour period. 5 working days
Suspicious Transaction Report (STR) In the event that there is reasonable grounds to suspect suspicion related to money laundering has occurred for completed transactions.

Automatic High Risk: Any client for whom an STR is filed will be re-classified as High Risk.

Subsequent Reporting: Once an STR is filed, all subsequent suspicious transactions for that client must continue to be reported.

Correction Timeline: Any requested changes to a filed STR must be submitted within 20 days of the request.

Non-Reported Unusual Activity: Transactions identified as "unusual" but not escalated to an STR must be documented with a clear rationale explaining why they were deemed not suspicious.

Note: An STR remains reportable even when an LVCTR has been filed for the same transaction
As soon as practicable, no longer than 30 days.
Attempted Suspicious Transaction Report (ASTR) In the event that there is reasonable grounds to suspect suspicion related to money laundering for without the occurrence of a transaction. As soon as practicable, no longer than 30 days.
Listed Person or Entity Property Report In the event the company identifies funds or property that is affiliated with terrorist activity (either an individual or an organization) a Listed Person or Entity Property Report report must be filed immediately with FINTRAC and additionally with CSIS and RCMP. Immediately.

Electronic Funds Transfer Reports (EFTRs)EFTRs are not applicable to TransFi Canada services and will not be filed as TransFi Canada does not accept Cash.

Large Cash Transaction Reports (LCTRs)Large Cash Transaction Reports are not applicable to TransFi Canada services and will not be filed as TransFi Canada does not accept Cash.

Large Virtual Currency Transaction Reports (LVCTRs)As a Money Service Business Dealing in Virtual Currency, TransFi Canada is required to file Large Virtual Currency Transaction Reports (LVCTRs) when Virtual Currency is received from a client or in the form of a commission payment equal to or in excess of $10,000 CAD in a single transaction or multiple transactions within a single calendar day. TransFi Canada must use the Canadian dollar exchange rate established at the time of the virtual currency transaction to determine whether the reporting threshold is met. Due to the fluctuating value of virtual currencies, this rate will vary based on a per trade basis.

Suspicious Transactions & Attempted Suspicious TransactionsThe threshold to report a suspicious transaction or attempted suspicious transaction is reasonable grounds to suspect that a money laundering or terrorist financing offence might have occurred. Reasonable grounds to suspect does not require confirmation of details to prove that an offence has occurred, however, the suspicion needs to be reasonable and unbiased and have considered; facts, context and risk indicators supporting suspicion. Suspicious reports must be filed when measures and investigation have been conducted with outcomes that reach the reasonable grounds to suspect threshold at minimum. Suspicious Transaction Reports must be treated as a priority as they are complex and must include clear, simple and concise language outlining grounds for suspicion including with the facts, context, and indicators that allowed you to reach reasonable grounds for suspicion.

Listed Person or Entity Property ReportsListed Person or Entity Property Reports are submitted offline and exclusively through fax or paper mail with Paper Report Forms available for download online. Additionally an STR must be filled with FINTRAC through conventional methods. Reports must also be submitted to the Canadian Security Intelligence Service (CSIS) by fax at 613-369-2303 and the Royal Canadian Mounted Police (RCMP) by fax at 613-825-7030. Additionally an STR must be filled with FINTRAC through conventional methods. The Chief Compliance officer must escalate activity related to Listed Person or Entity Property to senior management and General Counsel immediately.

Section 8: Identifying Suspicious Activity & Investigations

Identifying suspicious transactions begins with screening and identifying any transactions that appear unusual based on risk flags and detection measures, assessing the facts and context surrounding these transactions and linking any indicators of money laundering or terrorist financing to your evaluation. Examples of red flags for suspicion include but are not limited to:

  • Transaction volumes and frequency outside of the established client profile.
  • Client opens multiple accounts.
  • Customers that frequently change their credentials, including email addresses, IP addresses, or financial information.
  • Structuring transactions in small amounts and under the record-keeping or reporting thresholds.
  • Making multiple high-value transactions that are not in line with the expected activity for that client.
  • Frequent transfers occurring in a certain period of time to the same virtual asset account either by more than one person, from the same location, or concerning large amounts.
  • Fraud or risk alert triggers through automated transaction review software.

Grounds for suspicion must be outlined in an investigation report outlining how the facts, context, and indicators resulted in the conclusion:

  • "Fact" refers to an objective detail or event such as the red flag or trigger that led to the investigation, a fact cannot be an opinion.
  • "Context" provides clarity on the circumstances surrounding a transaction, including details regarding the client profile, client financial background and the investigation steps taken to determine suspicion.

Transactions alone may not seem suspicious, however, context can outline the conditions that support suspicious activity. Established Client profiles, including assigned risk ratings, must be assessed and leveraged during the investigation to identify indicators specific to the Client. The Chief Compliance Officer must review and approve all suspicious activity investigations prior to filing an STR with FINTRAC to ensure the reasonable grounds to suspect threshold has been met and adequate facts, context and indicators are included in the investigation.

8.1 Investigation Framework

The standard investigation process includes the following measures:

Transaction Reviews:Analysis of client's last 90 days transactional data assessing volume, frequency, beneficiary information and account data.

Sanctions Screening and Review:Screening business entities, directors, UBOs, and authorized users against sanctions lists and comprehensive review of related compliance requirements are conducted at the time of onboarding as well as on an ongoing basis

OSINT Investigation:Open-source intelligence (OSINT) gathering to gather relevant information including examination of social media profiles and associated websites for additional context.

Enhanced due diligence:Obtaining further information from the client to support verification through a Request for Information (RFI) process adhering to the terms outlined in this policy and only with the approval of the Chief Compliance Officer. Requests must be reasonable and avoid any instances of "tipping off".

8.1.1 Investigation Outcomes
  • No Further Action: Red flags and suspicions dismissed, no further issues or concerns are identified.
  • Flagged for Further Monitoring and Due Diligence: Requires increased monitoring, additional due diligence, and a new client risk assessment.
  • Client Relationship Terminated: Decision to cease business relations with the client.
  • Suspicious Transaction Report (STR) Filed: Suspicious activities suspected, reporting to regulatory authorities is required.

Section 9: Compliance Monitoring

TransFi Canada conducts ongoing compliance monitoring to evaluate Business Relationships and risks through Client maintenance reviews, and through transaction monitoring to identify and report any suspicious activity. The primary focus and scope of compliance monitoring is determined by the risks identified in the enterprise wide risk assessment, company AML policies, and established procedures.

9.1 Client Maintenance Reviews

Client Maintenance reviews are a key function of the Client Management framework. Review frequency is governed by established client risk profiles or triggered by various factors including but not limited to:

  • The presence of unusual transactional activity.
  • Client communications of a suspicious nature.
  • Changes in an established Client profile such as occupation, nature of business, or company structure.
  • An escalation from an external partner, regulator or law enforcement agency.
  • Identification of new risks related to Client profiles or services offered.

Client profiles must be maintained, valid, accurate, and complete throughout the Business Relationship. This involves sourcing updated Client documents and information surrounding the intended use of services.

9.2 Transaction Monitoring

Transaction Monitoring is focused on all transactions on behalf of Clients, commissions, or referral payment transactions to support money service offerings. Transaction reviews facilitate reporting obligations and identify transactions that meet the parameters for volume based reporting. These reviews also assist with suspicious activity monitoring under general guideline identifiers that include:

  • Transactions with no apparent economic or business purpose.
  • Rapid movement of funds between accounts.
  • Transactions involving high-risk individuals or entities.
  • Transactions conducted with repetitive patterns.
  • Transactions that are inconsistent with the Client's established profile.

High Risk Clients are subject to increased transaction monitoring which include a higher sensitivity threshold with increased considerations on identified red flags. TransFi Canada's IT systems have pre-programmed notifications and triggers that notify the compliance team of unusual activity related to Fiat transactions. Reviews of high volume/high velocity transfers are conducted bi-weekly to support client monitoring and reporting initiatives. TransFi Canada's transaction reviews are conducted manually by the compliance to identify reportable transactions and to review to identify money laundering red-flags and transactions that deviate from what is expected with established client profiles.

Know Your Transaction - KYT

TransFi has a robust inhouse Transaction Monitoring (TM) program as a rules engine designed to identify and report unusual or suspicious transaction activity. These rules applies to both fiat transactions and crypto transactions, leveraging a mix of automated and manual processes to ensure comprehensive monitoring and compliance.

Fiat TM Program

TransFi employs real-time and post-transaction monitoring to analyze fiat transactions, focusing on the following aspects: Transactions that exceed predefined thresholds are flagged for manual review and subjected to due diligence. Transactions originating from or destined for prohibited jurisdictions are automatically rejected and reported in Suspicious Transaction Reports (STRs). We have TM rules which indicates suspicious patterns. Below are the example of such rules:

  • More than 3 transaction within 5 minutes
  • More than 5 transactions attempted in one hour
  • More than 10 transactions attempted in 24 hours
  • Transaction value is 5x or more than the average of the last 10 transaction
  • Transactions deviating from expected behavior or declared activity are scrutinized, with appropriate action taken as necessary.

Crypto TM Program

For cryptocurrency transactions, we have implemented additional measures tailored to the unique risks of virtual assets: Wallets are analyzed based on the source of funds and sanctions screening through our blockchain monitoring partner Chainalysis. Wallets flagged as high-risk result in rejection of transactions. Transactions involving virtual currencies are monitored for compliance with international sanctions. Suspicious activity is flagged for further investigation. Similar to fiat, unusual patterns in crypto transactions trigger additional review to assess potential risks.

Section 10: Record Keeping

To facilitate information requests, and to be aligned with compliance best practices, records must be maintained in an organized and accessible format and be retained for a minimum of 5 years after the date the record was created. Access to records maintained on company servers is granted on an as-needed basis and is accessible only through two factor authentication. In the event of a FINTRAC request for information, the request must be fulfilled within 30 calendar days. Documents to meet record keeping requirements with the information supported in this policy include, but are not limited to:

  • Copies of every report submitted to FINTRAC.
  • Records relating to transactions over $1000.00 CAD or equivalent conducted by TransFi Canada.
  • Records related to Government Issued Photo ID verification.
  • Business relationship records outlining services and client profiles and risk rating used to anticipate transactions and activity used to support suspicion identification.
  • Records related to compliance onboarding and monitoring policies, procedures, and methodology.
  • Entity verification and Beneficial Ownership records.
  • Records of any verifications, transactions
  • Sanctions and PEP screening records.
  • Record requirements related to measures implemented by Ministerial Directives.
  • Copies of Independent reviews, FINTRAC Exams, and Law Enforcement Requests.

Access to Record Keeping must be protected, granted on a need to know basis, and accessed through company databases with Two Factor Authentication enabled at all times.

Section 11: AML Staff Training Plan

Employees, directors, agents or mandataries, or other persons authorized to act on the company's behalf must complete mandatory written and ongoing AML compliance training. A documented training program for ongoing AML compliance training must be maintained with a defined methodology on training delivery. Training must include:

  • Money Laundering and Terrorist Financing definitions.
  • Background information on money laundering and terrorist financing such as definitions and activity models.
  • Company vulnerabilities to Money Laundering and Terrorist Financing.
  • Responsibilities under PCMLTFA and associated regulations.
  • Compliance policies and procedures aligned with PCMLTFA.
  • Reporting requirements and transaction limits.
  • Identification and reporting of suspicious activities.
  • Handling suspicious activities or transactions.
  • Roles and responsibilities of employees in detecting and deterring illicit activities.

TransFi Canada's Chief Compliance Officer will maintain the annual training plan, track the completion of all training and implement additional training sessions if compliance issues arise. This includes documenting the steps taken to ensure appropriate training is conducted and is relevant to employee roles on an ongoing basis. This includes:

  • Training recipients
       
          Front line staff or staff involved in client transaction activities.
  • Staff involved in handling of cash, funds or virtual currency in any way.
  • Staff responsible for implementing or overseeing the compliance program.
  • Outline of the topics covered in the training program with sources to the training material addressing these topics.
  • May include self-directed learning, information sessions, face-to-face meetings, conferences, and on the job training where instruction is provided.
  • Tailored to the size, structure and money laundering and terrorist financing risk of the company.

Relevant new hires must receive training within 60 days of beginning their position. Anyone that is on a leave of absence that causes them to miss regularly scheduled training will complete training within 30 days of their return to work. A record of all training materials must be maintained at all times and include the training source materials, the date of the training, a list of attendees, and the topics covered to support training management and demonstrate that the training is being conducted on an ongoing basis.

Section 12: Two Year Effectiveness Review

A two-year effectiveness review supports an independent evaluation of the company's written and operational compliance program with higher-risk business areas receiving focused attention during the review. This to test the effectiveness of the program, identify any instances of non-compliance, and identify areas for improvement based on regulation or compliance best practices. An independent review supports preparation for a FINTRAC Exam, determines if operational practices reflect the TransFi Canada's written compliance program, and examines the effectiveness of TransFi Canada's enterprise-wide risk assessment and mitigation measures.

Independent effectiveness reviews must begin no later than two years from the start of any previous reviews or initial MSB registration. TransFi Canada's independent effectiveness reviews must be completed by a compliance professional with knowledge and experience in the PCMLTFA and Canadian regulations. The review must include at minimum:

  • Start date, completion date, and audit period utilized during the review.
  • Interviews with compliance staff to ensure adequate knowledge of the established compliance program and applicable regulations.
  • Interviews with compliance staff.
  • Customer Identification Testing.
  • Transaction and Reporting Testing.
  • AML Policy and procedure assessment.
  • TransFi Canada's EWRA assessment.

The Chief Compliance Officer must review and report on the external review to management within 30 days of completion, detail any deficiencies, and any remediations required in a remediation plan including set timelines for implementation. The Chief Compliance officer must determine whether a Voluntary Self-Declaration of Non-Compliance (VSDONC) should be submitted to FINTRAC based on the findings of the review.

Section 13: Voluntary Self-Declaration of Non-Compliance (VSDONC)

FINTRAC promotes a regulatory approach that is based on the promotion of compliance and not to penalize reporting entities with fines and penalties. Unreported transactions may hold value for FINTRAC and law enforcement, and must be reported even when missed, late, or uncovered during a scheduled or independent effectiveness review.

Submitting a VSDONC, an entity officially acknowledges compliance obligation short-comings and lists implemented measures to regain compliance. FINTRAC will work with a reporting entity to guide and correct instances of non-compliance without proposing administrative penalties, if:

  • The voluntarily declared non-compliance issues are not a repeated instance of a previous, voluntarily disclosed issue.
  • The VSDONC submission is after a reporting entity has been notified of a FINTRAC Examination.

Voluntary self-declarations of non-compliance must be sent to: VSDONC.ADVNC@fintrac-canafe.gc.ca and include:

  • TransFi Canada's MSB details and contact details for submitting the report.
  • The number of reports impacted, type, and the time period during which the issues occurred, as well as the reason why the reports were not submitted, were late, or incorrect.
  • The period of time during which the instances of non-compliance unrelated to reporting occurred and the reason for occurrence.
  • A detailed plan to resolve the issues and submit all outstanding reports, including measures and timelines for corrective action.

Personal information regarding instances of non-compliance must be protected and not included in VSDONC reports or submission email. If private information is pertinent to the investigation, FINTRAC will provide secure information sources.

Section 14: Law Enforcement Requests

Supporting law enforcement is a key factor in mitigating money laundering, terrorist financing, fraud, and illegal activity where possible. Validly served requests for Client information and assistance must be handled with priority. Requests from individual users or requests from law enforcement without a formal legal document detailing the requested information will not be accommodated.

Law Enforcement requests must follow a structured process including multiple stakeholders to establish validity, formulate a timely and detailed response, and report and document the request for internal and external management.

14.1 Notification

The Chief Compliance officer remains the primary point of contact for all Law Enforcement requests. Upon receipt of any requests, the Chief Compliance Officer must notify Senior Management and General Counsel with all provided documentation. Access to this information and details therein must remain confidential and on a need to know basis.

14.2 Review

Chief Compliance officer and General Counsel must review the Law Enforcement Request to ensure that it originates from a real law enforcement agency and that it is a formal legal request, such as a subpoena or search warrant.

14.3 Investigation

The Chief Compliance Officer must conduct an investigation on the Client(s) and information with priority pursuant to the established investigation protocols directed by this policy. Additional information that must be included in these investigations include:

  • The date the request was received;
  • The type of formal legal document received;
  • The name, department and information from which the request was received;
  • Specifics of the Client details and/or transactional information requested;
  • Timelines which the requested information must be delivered; and
  • Any required data or documents to support the requested deliverables.

Copies of investigations must be provided to Senior Management and General Counsel for review prior to any formal response. General Counsel must verify that the details in the investigation are required by the formal requests, and that the obligations outlined in the request are met. General Counsel must provide any investigation amendments or deviations from Law Enforcement Request Policy in written format to the Chief Compliance Officer and Senior Management for review and implementation.

14.4 Response

All external response communications must be approved by TransFi Canada's General Counsel. Law Enforcement responses must include a cover letter outlining the requested information, parameters of the request, a summary of the investigation, and list the records to be provided. Responses must be sent through official company channels, be factual, and delivered before the due date outlined in the formal law enforcement request document.

14.5 Actions

The Chief Compliance Officer must submit a Suspicious Activity Report (SAR) to FINTRAC under suspicion of "Reasonable Grounds to Suspect.". Accounts posing any identified risk of illegal activity, money laundering, reputational harm, or other risks that may cause harm to the company are reviewed for closure. TransFi Canada will follow law enforcement recommendations for account closures. All records of law enforcement requests, investigations, responses and internal and external communications surrounding the request will be maintained for a minimum of 5 years after the submission of the response.

Section 15: Country Acceptance Policy

This Country Acceptance Policy aims to provide a comprehensive delineation of acceptable jurisdictions for services. This framework ensures clarity and adherence to regulatory standards across operations and promotes a robust and compliant approach to jurisdictional considerations for Client Intake and Client Monitoring procedures. For the purposes of this policy, "location" is defined broadly to ensure a risk-based approach is applied during the Client boarding process. It encompasses any world area, country, region, state, or similar where a significant aspect of business operations is situated. Such aspects may include office locations, the residence of a majority owner, fulfillment or shipping warehouses, bank accounts, suppliers, home addresses, countries of identity document issuance, IP addresses, email domains, and other relevant factors. The policy outlines various types of location risks that are considered critical:

  • Tax Evasion: Jurisdictions that maintain outdated or poor legislation and banking secrecy laws that facilitate tax crimes and the illicit flight of capital.
  • Money Laundering: Jurisdictions that fail to comply with international standards for financial reporting and transparency. Money laundering risks often intersect with predicate offenses such as drug trafficking, human trafficking, and war plunder.
  • Terrorist Financing: Payments associated with terrorist financing may or may not involve money laundering. These transactions typically involve the movement of funds intended to directly or indirectly support terrorist groups.
  • Source Countries: Certain countries or jurisdictions serve as source countries for narcotics or trafficked humans. Due to the prevalence of predicate offenses in these locations, they pose heightened risks for money laundering and are treated accordingly.
  • Countries or Territories in Conflict: Regions experiencing armed conflict are particularly susceptible to predicate offenses such as human trafficking, money laundering, corruption, and others.

15.1 Banned Countries

The following countries subject to current sanctions imposed by Canada, that are outside of TransFi Canada's risk appetite include:

  • Cuba
  • Iran
  • North Korea (DPRK)
  • Syria
  • Crimea, Donetsk & Luhansk (Ukraine regions)
  • Russia
  • Belarus
  • Venezuela
  • Myanmar (Burma)
  • Nicaragua
  • Iraq
  • Lebanon
  • Libya
  • Somalia
  • Sudan
  • South Sudan
  • Yemen
  • Mali
  • Central African Republic
  • Democratic Republic of the Congo
  • Afghanistan
  • Haiti
  • Zimbabwe
  • Tunisia
  • Eritrea
  • Guinea-Bissau

15.2 Restricted Countries

The following countries and jurisdictions require enhanced due diligence prior to boarding: Algeria, Bulgaria, Burkina Faso, China, Cameroon, Comoros, Ivory Coast, Kenya, Lao People's Democratic Republic, Monaco, Mozambique, Namibia, Nepal, Sri Lanka, South Africa, Tanzania, Trinidad and Tobago, Uganda, and Vietnam,

15.3 Onboarding Exceptions

Exceptions apply solely to Clients domiciled in restricted locations, contingent on the implementation of enhanced due diligence and robust fraud/risk controls. Under no circumstances will Clients located in banned countries be considered for onboarding. The review process for restricted countries must undergo rigorous review verification that goods/services are fulfilled.

  • Detailed reporting of beneficial ownership.
  • Increased entity verification.
  • Confirmation that owners are not politically exposed persons (PEPs) or listed on watch lists.
  • Accurate reporting of business income to tax authorities.

Exceptions are evaluated individually and must be approved by TransFi Canada's Chief Compliance Officer. A risk-based approach is used to determine location risk, considering that clients may have multiple locations, such as corporate addresses, physical addresses, bank account locations, fulfillment warehouses, and home addresses. The highest risk location among these is used to score the Client's overall location risk. For Clients located in restricted countries and operating within high-risk industries or offering high-risk products, service will be denied

Section 16: Prohibited Industries

Adult content, airlines; collection agencies; marijuana dispensaries; CBD oil and related products; cash advances or cash gifting; charities; check cashing; cruises; debt consolidation; drug paraphernalia; firearms; fulfillment centers; government grant assistance; mail order brides; medical benefits or discounts; mortgage modification or reduction; multi-level marketing schemes; payday lending; replica or counterfeit goods; precious metal dealers; guns, arms, and ammunition; bearer share ownership companies; unlicensed MSBs, unlicensed gambling, shell banks, and timeshares. TransFi Canada does not onboard:

  • Known beneficiaries of Corruption or Illegal Activities;
  • Shell companies/shell banks;
  • Unregulated casinos or gambling companies;
  • Incomplete or failed KYB (Know your business);
  • Unlicensed money transmitters / payments / financial services companies; and
  • Customers with bearer shares in the ownership structure.
  • Marijuana/cannabis;
  • Guns, Arms and ammunition;
  • Precious metals;
  • Cash Intensive Businesses;
  • Adult content or Pornography;

Clients with multiple products or services may be approved with enhanced due diligence and only with the Chief Compliance Officer's approval.

16.1 Restricted Industries

Restricted industries are only onboarded when accompanied by enhanced due diligence. In some cases, additional controls, such as transaction or volume restrictions with heightened transaction monitoring, may be implemented as necessary and determined by the Chief Compliance Officer. Clients in restricted categories often pose higher risks due to extended fulfillment times, advance payments, or frequent customer complaints and disputes. This includes clients trading in products subject to frequent or pending regulation changes by national health, safety, or regulatory bodies. The following business types are subject to increased scrutiny; educational programs, modeling agencies, money services businesses, pharmaceuticals, gaming, betting, and wagers, gemstones, vape supplies, pawnbrokers, ticket brokers, travel agents and clubs, used car dealerships, and vitamins and herbal remedies.

16.2 Onboarding Exceptions

Exceptions to client onboarding apply only to those trading in restricted industries and only after the completion of due diligence and fraud/risk controls. Clients involved in prohibited products will not be considered for onboarding under any circumstances. Exceptions are evaluated on a case-by-case basis and upon the written approval of the Chief Compliance Officer.

Section 17: Policy Review Schedule

TransFi Canada must update this AML ATF Policy upon any material change in services or regulatory requirements affecting business operations. In addition, a scheduled annual review must be conducted to measure policy adherence in day-to-day operations.

17.1 Next Scheduled Update

July 1st, 2027

Authorized Signatory

Raj Kamal