PROCEDURE FOR MONEY TRANSFER TRANSACTIONS FROM AND TO THE CUSTOMER
1. PURPOSE
This procedure has been prepared to ensure that all deposits and withdrawals made by Whitebit Kripto Varlık Alım Satım Platformu A.Ş. (hereinafter referred to as the "Company") are carried out in accordance with the law, financial security principles, transparency principles and technological infrastructure requirements. It is aimed to carry out the money transfer processes used in customer transactions in accordance with the information systems management, storage and access standards determined by the regulatory authorities in a manner that is open to both internal control and external audit.
2. SCOPE
This procedure covers all customer fiat money transfer transactions at the Company. Deposits made by the client to the Company system and withdrawals made by the Company to the client are considered within this scope. Crypto asset purchase, sale and transfer transactions are excluded from this procedure and are detailed in separate procedures.
3. DEFINITIONS
The key terms used in this procedure document are defined below:
- Customer: Refers to natural or legal persons who have opened an account with the Company and whose identity verification (KYC) process has been completed.
- Money Transfers: All inflow and outflow transactions in fiat currency made by or for the customer.
- Customer Account: A bank account belonging to the Client, opened in his/her name and verified in the Company's system.
- Company Account: This is a special account opened by the company at banks and used only for customer money transfers, allocated from the company's own funds.
- Segregated Account: This is a bank account or group of accounts where customer assets are kept separate from company assets in accounting and operational terms and money transfers belonging to the customer are monitored.
- Suspicious Transaction: Transactions that are defined in MASAK regulations and have unusual characteristics and may pose risks such as laundering proceeds of crime or financing terrorism.
- Risk Scoring System: A systematic structure in which transactions are automatically analyzed and classified according to parameters such as customer behavior, transaction amount, frequency and country risk.
4. GENERAL PRINCIPLES REGARDING MONEY TRANSFER
4.1. Account Verification
All money transfer transactions carried out within the Company are carried out only through bank accounts belonging to the customer and previously verified through the identity verification process. Transfers from or to bank accounts belonging to third parties will not be processed, even if they are associated with the client. No transaction will be accepted unless it has been verified that the customer is the registered account holder in the banking system.
4.2. Segregation of Assets
In order to ensure that money transfers transmitted by the Client are not mixed with the Company's own assets, all bank accounts used shall be notified to the bank, clearly stating that they carry the assets of the client, and this notification shall be supported by written confirmation. If this notification is not confirmed by the bank within fifteen business days, the Company shall terminate its business with the relevant bank and immediately transfer the customer assets to a segregated account opened in another bank.
4.3. No Encumbrance on Customer Accounts
No pledge, blockage or similar restriction may be applied in favor of the Company on any account held in the name of the customer with the Company. These accounts cannot be attached for any receivables, including public debts, and cannot be included in the bankruptcy estate. Likewise, Company assets cannot be subject to such transactions due to customer debts.
4.4. Audit Trails
Audit trails for all money transfer transactions are systematically created, and each step from the beginning to the end of the transaction is recorded with a time stamp. These records are kept in a format open to independent information systems audit.
5. MONEY TRANSFER PROCESSES FROM THE CUSTOMER
5.1. Source of Funds
All deposits from the customer can only be made from bank accounts opened in the customer's own name and defined in the system. In this context, the sender name, IBAN and description information received from the bank before the transaction is automatically analyzed by the system and compared with the customer's registered information.
5.2. Transaction Rejection Criteria
If the name-surname or trade name of the person making the transfer does not match the customer information registered in the system, the transaction is automatically rejected. Likewise, money inflows with an empty description field, which cannot be associated and originating from risky countries are specially evaluated.
5.3. Risk Assessment and Blocking
Each deposit transaction is subjected to the risk scoring algorithm defined in the system based on the transaction amount, transaction frequency and information in the description field. Transfers that exceed the thresholds set in the system, show suspicious patterns or are linked to previous similar transactions are automatically blocked and directed to the review of the Compliance Unit.
5.4. Third-Party Transfers
For transfers from third parties, in addition to automatic rejection by the system, the relevant transaction information is recorded by creating an audit trail. These transactions are periodically reported by the Internal Control Unit.
5.5. Resolution for Rejected Transactions
If deemed necessary, the transaction is rejected, returned to the sender, the customer is informed and a suspicious transaction notification is made to MASAK. The entire process is time-stamped and archived for at least ten years.
6. MONEY TRANSFER PROCESSES TO THE CUSTOMER
6.1. Destination of Funds
Money transfers to the Client may only be made to the Client's bank account registered in his/her name and verified as part of the KYC process. Withdrawal requests are received through the Company's digital user interface and the transaction is automatically passed through the system control module.
6.2. Withdrawal Request Review
The amount of the trade request is compared with the past trade volume and frequency. In case of requests with high amounts, unusual frequency or incomplete explanations, the system issues a warning and the transaction is directed to the manual evaluation of the Compliance Unit. If deemed necessary, additional documents or explanations may be requested from the client.
6.3. Execution of Approved Requests
Approved requests are executed only through bank accounts reserved for customers. These accounts are kept accounting and operationally separate from company assets. Banks used for transfers must have the infrastructure to directly distinguish customer accounts. Log data of all transactions are stored in the system with a time stamp.
7. RISK ANALYSIS, MONITORING AND SUSPICIOUS TRANSACTION REPORTING
7.1. Two-Stage Risk Analysis
All transactions related to money transfers are subject to a two-stage risk analysis, pre- and post-transaction. At the first stage, the transaction is classified by analyzing the transaction amount, frequency, sender country, PEP status and other behavioral indicators. The system generates a time-stamped risk score for each transaction, which determines the priority of the transaction for processing.
7.2. High-Risk Transactions
The second stage analysis examines possible chain links and unusual movements in the customer portfolio after the transaction has occurred. Transactions identified as "high" risk in both stages are blocked and resolved only with the express approval of the Compliance Unit.
7.3. MASAK Reporting
In accordance with the procedures stipulated by MASAK, each transaction that falls within the definition of suspicious transaction shall be reported to MASAK within the framework of the Company's internal notification procedures without delay and within 10 business days at the latest; however, immediately in cases of suspicion of laundering proceeds of crime or financing of terrorism.
8. RECORDING, STORAGE AND REPORTING
8.1. Data Storage
For each money transfer transaction; transaction date and time, customer information, IBAN, explanation text, transaction result, risk score and log records and documents transmitted by the customer, if any, are stored digitally and unalterably.
8.2. Accessibility and Confidentiality
These records are kept open to access only by authorized personnel within the framework of the Personal Data Protection Law No. 6698 and can be submitted upon request by the CMB, MASAK and independent auditors.
8.3. Data Preservation
Records are preserved in an accessible format for a minimum of ten years with backup infrastructures kept in different geographical locations. The retention system is structured in a way that prevents data loss and is suitable for legal audit.
8.4. Retention Period and Security
The retention period is at least eight years as per legal obligation. It is also essential that the recording system has a time-stamped, multi-factor access controlled and highly secure log infrastructure.
9. TRAINING, SUPERVISION AND CONTINUOUS UPDATING
9.1. Employee Training
In order to effectively implement this procedure, all employees in charge of money transfer processes within the Company are provided with comprehensive training at least once a year. Training contents are renewed every period in line with legislative changes and suspicious transaction updates.
9.2. Internal Audit and Procedure Review
The Company's Internal Audit and Compliance Unit audits the level of implementation of the procedure at least once a year, and initiates corrective action for any deficiencies identified in implementation. The content of the procedure is immediately reviewed, updated and put into effect with the approval of the management for each change in the legislation.
9.3. Training Records
Training contents are prepared by the Compliance Unit and carried out together with the Human Resources Department. Training participation and success are logged and stored in digital systems.
10. BUSINESS CONTINUITY AND TURNAROUND PLANS
In order to ensure the continuity of money transfer transactions, the Company has predefined alternative transaction channels and recovery plans to be activated in case of system failures or extraordinary circumstances. Backup of critical systems is carried out in different geographical regions. In case of system interruptions, customers are notified instantly.
11. ENFORCEMENT
This procedure entered into force with the decision of the Board of Directors dated 25.03.2025. It is reviewed by the Compliance Unit at least once a year and, if necessary, updated and re-enacted.