CONFLICT OF INTEREST POLICY

1. INTRODUCTION

1.1. Purpose

This policy has been prepared within the scope of the activities carried out by Whitebit Kripto Varlık Alım Satım Platformu A.Ş. ("Company") as a crypto asset service provider. The purpose of the policy is to ensure the protection of customer interests and the observance of market integrity by identifying conflicts of interest that may arise between the Company and its customers, related parties and third parties in advance, taking the necessary administrative and operational measures to prevent them, and managing the situations that cannot be prevented in line with the principle of transparency.

1.2. Scope

The Policy covers all employees, management bodies, shareholders, affiliates, subsidiaries and all real and legal persons directly or indirectly related to the Company. Although the policy provisions are not directly integrated into customer agreements, it sets out the basic principles for the ethical, fair, transparent and fully compliant execution of the services provided by the Company.

2. DEFINITIONS

Some concepts and terms used within the scope of this policy are defined below in order to ensure uniformity in practice, to prevent misunderstandings and to ensure that conflicts of interest can be managed effectively. These definitions shall be used in the same scope and meaning throughout the policy. In this context, in this Policy:

  • Company: Whitebit Crypto Asset Trading Platform Joint Stock Company.
  • Conflict of Interest: Any situation in which the personal, commercial or financial interests of the Company, its employees, directors, partners or related persons may conflict with the interests of clients, the Company's obligation to provide impartial services or market integrity.
  • Related Person: The Company's shareholders, members of the Board of Directors, executives, employees and their spouses, first degree relatives and real or legal persons directly or indirectly controlled or influenced by these persons.
  • Client: Natural and legal persons who benefit from the Company's crypto asset trading, custody, listing or similar services.
  • Compliance Unit: This is the unit that fulfills the Company's internal control, regulatory compliance and risk monitoring duties. This unit is responsible for identifying potential conflicts of interest, evaluating notifications and coordinating management processes.
  • Information Barrier (Chinese Wall): Refers to the physical, technical and organizational measures implemented to limit access to sensitive and internal information within the company, preventing the transfer of information between units.
  • Inside Information: This refers to information that has not yet been disclosed to the public, is of financial or strategic value and, if disclosed, could affect investors' decisions. Misuse of inside information is a serious violation that may result in a conflict of interest.
  • Information Security Management System ("ISMS"): It is the system that covers the administrative, technical and physical security measures and processes related to these measures implemented by the Company to protect information assets and ensure information security. The confidentiality, integrity and accessibility of customer information is guaranteed by this system.
  • Declaration of Interest: This is a corporate declaration in which employees and related persons declare in writing their potential interests in persons, institutions or transactions that may have a direct or indirect interest in the Company and update them when necessary.

3. PURPOSE AND SCOPE

3.1. General Purpose

This document has been prepared to ensure that conflicts of interest that may arise within the scope of the activities carried out by the Company are identified, prevented and managed effectively. The Company adopts a fair, honest and transparent approach in all areas where it provides services and considers protecting customer interests and market integrity as its fundamental responsibility.

3.2. Service Coverage

The Policy covers all services such as trading, custody, transfer, listing, listing, supporting issuance processes of crypto assets and all kinds of conflict of interest risks that may arise during the provision of these services. In addition, all corporate processes that may have a direct impact such as decision making, guidance, evaluation, transaction execution are also evaluated within this scope.

3.3. Personnel Coverage

The obligations are not limited to employees and managers, but also include board members, consultants, partners, agents, external service providers, subcontractors and all third parties acting on behalf of the Company. Every person and entity in direct or indirect contact with the customer is responsible for acting in accordance with the principles in this framework.

3.4. Principles and Updates

The principles set forth serve to ensure impartiality in service quality, trust in customer relations and integrity across the sector, as well as compliance with capital markets legislation. The scope may be reviewed over time and updated when necessary, depending on changes that may occur in the field of activity, organizational structure or service types.

4. IDENTIFICATION OF POTENTIAL CONFLICTS OF INTEREST

4.1. Basic Evaluation Criteria

The Company considers the digital, fast-paced and technology-based nature of its business when assessing potential conflicts of interest. The Company recognizes that it and its associated persons:

  • The customer will realize a financial gain or avoid a financial loss,
  • The customer will benefit directly or indirectly from the services or activities provided, even if the customer does not have an interest,
  • A customer or group of customers will benefit as a result of favoring one customer or group of customers over another customer or group of customers,
  • That during the provision of services, other persons, institutions or applications other than the customer will benefit financially from other persons, institutions or applications other than standard fees and commissions,

situations as a minimum assessment criterion. This assessment is made separately for each type of service, business model, business partnership, use of technology and personnel practices.

4.2. Examples of Possible Conflicts of Interest in Crypto Asset Services

4.2.1. Conflict Scenarios

Situations that may lead to conflicts of interest during the Company's activities can be defined through, but not limited to, the following examples:

  • Listing or recommending crypto assets belonging to its own portfolio or related persons in violation of the principle of impartiality,
  • Order routing, prioritization (front-running, self-dealing, etc.) on the trading platform to the benefit of the Company or its related parties,
  • In the case of investing in crypto projects planned to be listed or providing technical or strategic consultancy to these projects, trading by persons who have access to this information,
  • When the company provides liquidity to the market from its own wallets or bots and trades in a way that conflicts with user orders,
  • The Company's partners, directors or employees have a personal investment position in crypto assets listed or traded on the Platform,
  • Acting with loyalty rather than impartiality when receiving services from a third-party wallet provider, custodian, clearing house or blockchain infrastructure provider with which the company is associated,
  • Algorithms routing customer orders prioritize certain trading pairs or high-fee trades in order to increase the Company's revenue,
  • Providing target-based bonuses to employees in order to increase transaction volume and therefore unnecessarily incentivizing transactions,
  • Company employees trying to gain personal gain by establishing a direct or indirect interest relationship with customers,
  • The application of preferential trading conditions granted to certain customers to the detriment of other users,
  • The company trades or leaks non-public information about cryptoassets,
  • Non-standard earnings of the Company due to the relationship between the Company and the exchange, market maker or wallet provider used for the service provided to the client,
  • Keeping clients' crypto assets and the Company's own portfolio assets in the same wallets, trading without segregation, or subjecting proof-of-reserve obligations to a relationship of interest.

The examples listed above are derived from various scenarios inherent in the services provided by the Company, and it is essential that conflict of interest risks are not limited to the examples listed here and are monitored dynamically according to the nature of the services. Each potential conflict of interest situation detected is examined by the Compliance Unit and taken under control through administrative processes.

In such cases, customers are informed in a clear and timely manner about the unbundling principles, risks and the possibility of conflict of interest; no transaction is carried out without the informed consent of the customer. Preventive measures such as task rotation, temporary limitation of authority or change of duty are taken for personnel working in units with high risk of conflict of interest. When necessary, the activities of employees are subjected to internal audit and compliance controls at more frequent intervals. In cases where a risk of conflict of interest is identified, preventive administrative measures such as duty rotation, restriction of authority or temporary change of duty of the relevant personnel are applied. The implementation of these measures and the evaluation of their effectiveness are carried out in cooperation with the Compliance Unit and the Human Resources Unit.

4.2.3. Evaluation Timeline

Each potential conflict of interest situation detected is evaluated by the Compliance Unit within 30 (thirty) days at the latest following the detection and necessary actions are taken.

5. DETECTION, PREVENTION AND MANAGEMENT MEASURES

The Company has adopted a comprehensive corporate and operational framework to identify, prevent and effectively manage potential conflicts of interest. In this context, it is essential to recognize risks before they arise, to eliminate them through preventive controls and to manage emerging situations transparently.

5.1. GENERAL PRINCIPLES

Providing fair, equal and impartial service to customers is one of the fundamental principles of the Company. All employees are obliged to notify their immediate managers and the Compliance Unit without delay if they encounter any situation that may pose a risk of conflict of interest while performing their duties. Prior to the commencement of service provision, potential relationships of interest and conflict of interest risks are clearly and comprehensibly disclosed to customers. It is essential to obtain written consent from customers for transactions that may be subject to conflict of interest. The relevant service is not provided without the written consent of the customer. In addition, in activities involving the risk of conflict of interest, individual areas of responsibility are clearly defined and structured in line with the principles of separation of duties and supervision.

5.2. MANAGING INFORMATION FLOW

Controlled management of information flow is of great importance in minimizing the risk of conflict of interest. The Company has established infrastructure and procedures within the framework of ISO 27001 Information Security Management System ("ISMS") standards to ensure information security. Access to internal information is granted only to personnel authorized by their job descriptions. Accordingly, sensitive data sharing between units is restricted and information barriers, also known as "Chinese Walls", are created to ensure that only authorized and relevant personnel can access the information. Authorizations to access internal information are limited in line with job descriptions. Personal or financial information of customers is shared with third parties only in line with legal obligations or with the explicit consent of the relevant person. In all these processes, information security is ensured through an Information Security Management System that complies with national regulations and international standards.

5.3. SUPERVISION AND REMUNERATION OF EMPLOYEES

5.3.1. Supervision Framework

The Company has an effective supervision and remuneration system to ensure that employees avoid behaviors that may create conflicts of interest while performing their duties. The Company encourages its employees to act within the framework of their professional and ethical responsibilities, while at the same time ensuring that they fulfill their duties in an objective, impartial and honest manner.

5.3.2. Employee Obligations

All employees are obliged to avoid conflicts of interest, to carry out their duties in accordance with the principle of impartiality and to adhere to the Company's code of ethics. These obligations are conveyed to employees through the orientation process at the time of recruitment and periodically reinforced through trainings. Employees are obliged to immediately notify their managers and the Compliance Unit in writing if they identify any potential conflict of interest that may be related to their duties. Such notifications are evaluated on the basis of confidentiality and do not result in any consequences against the employee.

5.3.3. Performance Evaluation Systems

The Company has designed its employee performance evaluation and reward systems in a way that does not encourage conflicts of interest. Performance-based bonus systems are determined by considering not only quantitative but also qualitative criteria. For example:

  • Customer satisfaction,
  • Internal control and compliance with legislation,
  • Commitment to ethical rules,
  • Effective management of risk in the area of responsibility,
  • Transparent reporting and internal audit collaboration,
  • Transaction practices free from conflicts of interest

are among the determining factors in the evaluation processes. No employee is compensated for listing a specific crypto asset, promoting specific trading pairs or increasing trading volume.

5.3.4. High-Risk Units

In addition, employees working in units where the risk of conflict of interest is higher (e.g. listing committee, market making, order routing unit) shall be subject to strict supervision and internal control mechanisms. The duties and authority definitions of these employees are structured in a way to prevent conflicts of interest. Where necessary, measures such as rotation, reassignment or temporary limitation of authority may be taken to prevent conflicts of interest.

5.3.5. Off-Duty Activities

The Company also monitors the off-duty commercial activities of its employees and conducts a regular declaration and approval process for situations that may create conflicts of interest. In this context:

  • Don't work for another company,
  • Participation in crypto asset projects,
  • Activities such as personal trading with assets traded in the company's client portfolio,

must be declared in advance and approved by the Compliance Unit. The Compliance Unit regularly monitors whether the approved activities increase the risk of conflict of interest and may decide to limit or stop the relevant activity if deemed necessary. Employees are obliged to submit an updated declaration immediately when there is a change in the activities that may create a conflict of interest. Declared off-duty activities are reviewed by the Compliance Unit at least once a year and their timeliness is evaluated in terms of conflict of interest risk. If the off-duty activity declarations are outdated, the relevant person is informed and ensured to update them. Administrative action may be taken against the personnel who do not update them according to internal procedures.

5.3.6. Client Relationships

Finally, employees' relationships with clients are also monitored for conflict of interest risk. It is strictly forbidden to provide direct investment advice to the client, to establish a personal relationship or to exert a directive influence on transactions. Such behavior is subject to disciplinary provisions and may result in sanctions ranging from suspension to termination of employment, if necessary.

The Company acts with the awareness that conflicts of interest may arise not only at the level of employees, but also at the level of the company's partners, managers and "related persons" who are directly or indirectly linked to these persons. In this context, the actions and positions of all related persons who shape the corporate decision-making processes of the company or who are in strategic interaction with the company, which may create conflicts of interest, are meticulously monitored, audited and limited when deemed necessary.

5.4.2. Audit Processes

In this respect, the Company regularly audits the processes in which related persons are involved in the capacity of duty, title or shareholder in order to determine whether they pose a potential conflict of interest risk. In particular, the following situations are evaluated within this scope:

  • Board or committee members are also involved in organizations that issue, store, list or provide consultancy services for crypto assets,
  • Related persons establishing direct commercial relations with the Company or receiving services from the Company,
  • Related persons simultaneously trading on the Company's trading platform or assuming positions related to listed assets,
  • Participation of related persons in the governance processes within the Company in a way that directly or indirectly affects decision-making mechanisms.

5.4.3. Conflict Resolution

In such cases, the Company shall implement arrangements to ensure that the related person withdraws from the transaction, decision or voting processes, does not intervene in the relevant processes or is monitored by an independent internal control mechanism. If deemed necessary, in order to eliminate the conflict of interest, the transaction with the person or unit in question is avoided or the transaction is carried out under the supervision of a third independent party.

5.4.4. Annual Declarations

In order to ensure the sustainability of this control mechanism regarding related parties, the Company adopts an annual declaration obligation and periodically requests declarations of interest, duty and stakeholder relations reports from related parties. Thus, potential conflicts of interest are recorded before they arise and proactive measures are taken by evaluating them before the Board of Directors.

5.4.5. Service Provider Relationships

The Company assesses the risk of conflict of interest for employees or managers who are in direct relationship with the partners or managers of cloud providers, infrastructure, API or technology companies from which it outsources services; in such cases, it reorganizes the internal governance structure, approval processes and data access. These processes also clearly define data protection measures and security obligations for relevant suppliers to ensure the security of customer data.

5.5. PROCEDURES TO BE FOLLOWED IN CASE CONFLICT OF INTEREST CANNOT BE AVOIDED

5.5.1. Transparency Principle

In cases where a conflict of interest cannot be completely prevented despite all measures taken, the Company undertakes to manage the relevant process in accordance with the principle of transparency and by considering the interests of the customer. Within this framework, before any service or transaction that may be subject to a conflict of interest is performed, the client is provided with clear, understandable and timely information about the nature, source and potential effects of the conflict. The information is provided in writing or through a permanent data storage device, and the service to be provided is initiated only after this information is provided in accordance with the explicit consent to be obtained from the customer.

This information process is carried out not only as a formality to fulfill legal obligations but also to enable the client to make an informed, free and healthy decision. The Company reserves the right to refrain from providing the relevant service if the customer does not give explicit consent or if the potential conflict of interest is likely to have unreasonable consequences to the detriment of the customer. In such a case, the decision on whether the service relationship will continue or not is made based on the assessment to be made by the Compliance Unit. The Company reserves the right to suspend or terminate the relevant service if the Company concludes that the conflict of interest cannot be managed in the best interest of the client.

5.5.3. Additional Controls

In some special cases, additional controls may be applied to effectively manage the conflict of interest. These controls may include methods such as involving an impartial third party in decision-making processes, performing the relevant transaction by an independent unit, or temporarily removing the personnel subject to the conflict of interest from decision-making processes. When necessary, the relevant service may be stopped completely or alternative solutions to eliminate the conflict of interest may be developed and presented to the customer.

5.5.4. Action Plans

An action plan is prepared within 30 (thirty) days at the latest for the conflict of interest risks identified as a result of the assessment made by the Compliance Unit. The implementation of the action plans is audited by the senior management within 90 (ninety) days at the latest and the results are recorded. If deemed necessary, additional measures are taken or the process is restructured.

6. DISCLOSURE OF CONFLICT OF INTEREST AND THE PRINCIPLE OF TRANSPARENCY

6.1. Market Advice Disclosure

When the Company makes statements that constitute general market advice, information or commentary, it shall clearly and understandably inform clients of any direct or indirect interest relationships that may affect the objectivity of these statements. In particular, if the Company or its related parties have an interest in the crypto assets traded or planned to be traded, these relations of interest shall be disclosed to the clients in a timely and complete manner.

6.2. Service Provision Transparency

In cases where conflicts of interest cannot always be completely eliminated due to market dynamics, the relevant customer is adequately informed and necessary explanations are provided before the Company starts service provision. In cases where the conflict of interest is at a level that cannot be managed, the Company reserves the right to stop service provision or not to carry out activities. This approach is adopted in line with the principles of transparency and protection of customer interests.

6.3. Audit Trails and Reporting

The Company keeps and periodically monitors audit trails of all transactions and user activities, particularly transactions subject to conflicts of interest, for at least 10 years. Elements such as transaction time, transaction type, related person and transaction result are recorded in audit trails. An automatic warning mechanism is activated in abnormal situations. Serious anomalies, information security violations or significant events that may be subject to conflict of interest are immediately notified to senior management through the Compliance Unit and to the CMB when necessary. Notified conflict of interest incidents and the measures taken are presented to the Board of Directors at least once a year by preparing an annual report on conflicts of interest.

7. PROTECTION OF PERSONAL DATA AND INFORMATION SECURITY

7.1. Data Protection Framework

Within the framework of the Personal Data Protection Law No. 6698 ("KVKK"), the Company accepts the secure processing, storage and protection of personal data of customers as a fundamental obligation. This data is processed only to the extent required by legal obligations, approvals given within the scope of explicit consent and service provision. The principle of minimum data and the rule of proportionality are observed in the processing of personal data. The Company implements multi-layered measures to ensure information security. In this context, personnel authorizations are meticulously made; physical and digital security systems are actively operated; data is protected by encryption, regularly backed up and all accesses are recorded. Within the scope of the Information Security Policy, the security of the systems is continuously monitored by performing periodic audits and tests. All employees have been informed about data security and personal data processing processes and authorized about their responsibilities.

7.2. Information Security Officer

The Company has appointed an "Information Security Officer" with more than 5 years of experience in information security. This person is responsible for control and reporting activities related to information systems security. Information systems are subjected to independent penetration testing and internal control processes at least once a year. Test results are reported to senior management and the Board. The Information Security Officer works independently from operational units and operates in compliance with CMB regulations and TÜBİTAK Information Security criteria.

7.3. Annual Security Assessment

At the end of each year, a comprehensive Information Security Situation Assessment Report on the general security status of information systems and identified risks is prepared and submitted to senior management.

8. EDUCATION AND AWARENESS

The Company conducts regular training programs to raise the awareness of all employees regarding internal policies and practices for the prevention and effective management of conflicts of interest. In this context, all employees receive training on conflict of interest risk, preventive measures, internal audit practices and ethical rules at least once a year. Training contents are periodically updated in line with the current legislation in force and the Company's internal policies. Participation in trainings is recorded and participation rates and training results are monitored by the Compliance Unit. Compensatory trainings are organized for employees who cannot attend.

9. REVIEW OF THE POLICY

9.1. Annual Review

This policy is reviewed at least once a year by the Compliance Unit and the relevant internal control functions. After assessing the applicability, currency and compliance with the legislation, revisions deemed necessary are prepared and submitted to the Board of Directors for approval. When necessary, periodic reviews may also be carried out within the framework of extraordinary developments or legislative changes.

9.2. Action Plans

An action plan is prepared within maximum 30 days for the deficiencies identified as a result of the assessment made by the Compliance Unit and the implementation of this plan is audited by the senior management within 90 days.

9.3. Policy Updates

Updates to the Policy shall be notified in writing or electronically to all relevant employees and other stakeholders where deemed necessary by the Company. The final version of the updated policy may be made public by publishing it on the Company's website or other communication channels.

10. ENFORCEMENT

This policy was approved by the Company's Board of Directors on 02/06/2025 and entered into force. The provisions of the Policy are binding for all employees, managers and related parties of the Company. The updated version is publicly published on the Company's website when necessary and made available to all relevant stakeholders.