# Bidali KYC & AML Policy

Last updated on February 27th, 2022

Bidali Inc. ( **"Bidali", "we", "us", "our", and Company**) has developed an Anti-Money Laundering and Anti-Terrorist Financing Policy ( **"AML Policy"**) to maintain compliance with applicable laws and regulations relating to anti-money laundering and terrorist financing. Our policies and procedures meet or exceed legislative requirements in Canada and reflect how we manage money laundering and terrorist financing risks posed to Bidali in order to provide a robust, compliant platform.

## The Proceeds of Crime and Terrorist Financing Act

In accordance with the legislative requirements set forth in the Proceeds of Crime (Money Laundering) and Terrorist Financing Act ( **"PCMLTFA"**), our Company is required to fulfill certain record keeping, identification, and reporting requirements. Our Company has chosen to implement and maintain a compliance regime which includes, but is not limited to:

- Establishing robust internal policies, procedures and controls that strive to combat any attempted use of Bidali's products or services for illegal or illicit purposes.
- Appointing a Chief Compliance Officer (“CCO”), responsible for the development, implementation, and oversight of Bidali's AML program.
- Executing Know Your Customer (“KYC”) procedures on all customers* to identify them as required by the PCMLTFA;
- Assessing our risks related to money laundering and terrorist financing;
- Following all applicable record retention requirements as required by the PCMLTFA;
- Monitoring transactions for potentially suspicious activities for the purposes of filing Suspicious Transaction Reports ("STR") or Attempted Suspicious Transaction Reports ("ASTR");
- Maintaining and providing written, ongoing compliance training for our employees;
- Regular reviews of our compliance regime to test its effectiveness related to money laundering and terrorist financing every two years.

> *A customer is defined as a person or entity that uses Bidali's payment products and services.

## Policies and Procedures

Bidali has adopted a risk-based regime approved by its board of directors. Bidali personnel and our board of directors recognize the importance of implementing and maintaining a sound AML Policy that meets or exceeds the requirements of all applicable laws and regulations. Bidali has implemented internal policies and procedures to achieve these requirements. The AML Policy is regularly reviewed and revised as necessary.

## Our Chief Compliance Officer

Under the PCMLTFA, Bidali has designated a Chief Compliance Officer ("CCO") responsible for the implementation and oversight of our compliance regime. Our CCO has the authority and resources to ensure ongoing compliance related to the identification and prevention of money laundering and terrorist financing. The CCO and their compliance team can be reached directly at [compliance@bidali.com](mailto:compliance@bidali.com).

## Ongoing Monitoring of Business Relationships

As per FINTRAC guidance, business relationships are established once a client has an account. At Bidali, an active account, and therefore a business relationship, is defined as when a customer conducts two or more commercial transactions within a 12 month period. Therefore, for business relationships, Bidali must:

- Determine the identity of the individual; or 
- Confirm the existence of a corporation or other entity.

Additionally, Bidali adheres to the following regulatory requirements:

- Risk-rating all business relationships and amending their risk-rating if the need arises;
- Conducting ongoing monitoring based on the risk-rating assigned to the customer;
- Keeping a record of measures taken to monitor the relationship and the information obtained.

If necessary, we may require customers to provide additional documentation to confirm the source of funds for the transaction.

Our system employs a combination of automated and manual monitoring procedures with an appropriate escalation process based on risk. Bidali's compliance staff will review any transactions that trigger a system alert to determine if they are within the customers’ stated activity.

## Know Your Customer Processes

Prior to a customer being able to perform a transaction, Bidali must identify the customer, known as Know Your Customer ("KYC"). Bidali requires all customers to be "verified" in the following circumstances:

- Prior to issuing closed loop prepaid stored value products (i.e., gift cards);
- When a business customer accepts more than $1,000 in cumulative payment processing volume;
- When a customer purchases gift cards equal to or greater than $9,500 in 24 hours;
- When a customer sends equal to or greater than $1,000 in a single transaction;
- When a customer has a Bidali Account balance equal to or greater than $10,000;

All transaction and account limits are in local fiat currency value. Bidali Accounts are presently available only to residents in certain countries. See our [Restricted Use Policy](/content/policies/restricted-use/index.html) for more details.

### Information that we may collect to verify and authenticate a customer or beneficial owner:

- Email address;
- Mobile phone number;
- Full legal name;
- Home Address (not a mailing address or P.O. Box);
- Date of birth ("DOB");
- IP Address;
- Unique device information;
- Proof of identity;
- Additional information or documentation at the discretion of our compliance team.

Individual customers may be verified by way of:

#### Single Process Identity Verification Method

Determining the identity of a customer by referring to a credit file or financial institution account established with a third party. Details provided must match the individual customer’s information.

#### Dual Process Identity Verification Method

Referring to information from reliable and independent sources submitted by the individual. Customers are asked to upload original electronic or paper documents. Such documents typically include:
- Government issued photo identification;
- Bank or credit card statement;
- Utility bill.

All files are submitted over encrypted channels and stored securely. Review our [Security Policy](/content/policies/security/index.html) for more information.

### Identifying Corporations and Other Entities

We must confirm the existence of a corporation or the entity's beneficial ownership.

#### Corporations

We confirm the existence of a corporation by collecting and verifying:
- Corporate Email address;
- Corporate phone number;
- Full Corporate legal name;
- Government registration number;
- Business Address;
- Proof of existence;
- Confirmed identity of all beneficial owners.

#### Partnerships, Cooperatives, Sole Proprietorships

We confirm the existence of such entities similarly but with different acceptable documentation like:
- Partnership agreement;
- Articles of association;
- Sole proprietorship registration.

### Not-for-profits and Charities

We confirm the existence of such entities similarly, but acceptable supporting documentation may include:
- Proof of charity or non-profit registration;
- Articles of association.

## Beneficial Ownership Records

We confirm and determine the accuracy of an entity's beneficial ownership through:

**If the entity is a corporation:**
- Directors and officers names and occupations;
- Individuals who own or control 25% or more of shares.

**If the entity is other than a corporation:**
- Individuals who own or control 25% or more of the entity.

### Keeping Client Identification Information Updated

Customers presenting an elevated risk are required to have their identification updated at least every two years, or sooner based on our risk evaluation.

## Reporting Requirements

Bidali complies with all reporting requirements under the PCMLTFA and regulations enforced by FINTRAC.

### Suspicious Transaction Reports

Our Company must report transactions or attempted transactions with reasonable grounds to suspect they relate to money laundering or terrorist activity without a monetary threshold.

### Terrorist Property Reporting and Sanctions Requirements

We must send a terrorist property report to FINTRAC immediately if:
- Knowing that a property is owned or controlled by a terrorist;
- Believing a property is owned or controlled by a listed person.

## Ongoing Monitoring of Business Relationships

We monitor for unusual activity and may report internally to our CCO if necessary.

## Policy Audits

Our CCO performs an annual audit of the AML Policy and presents results to the CEO and Board of Directors. Independent reviews occur at least every two years.

## Training

All employees and officers receive ongoing AML training, repeating it at least once every twelve months. Documentation related to training is maintained.
