SUBMISSION PROCEDURE FOR MANDATORY DOCUMENTS TO BE SENT TO CUSTOMERS

1. PURPOSE AND SCOPE

The purpose of this procedure is to set out the rules for the timely, complete and secure transmission of all documents that Whitebit Kripto Varlık Alım Satım Platformu A.Ş. ("Company") is obliged to send to customers within the framework of the relevant regulations of the Capital Markets Board. The Procedure covers account opening agreements, risk notification forms, service agreements, transaction summaries and receipts, information obligations and all other documents required to be sent by the Board.

2. COMPLIANCE WITH LEGISLATION

This procedure has been prepared in accordance with the "Communiqué on Establishment and Operating Principles of Crypto Asset Service Providers (III-35/B.1)", "Communiqué on Operating Procedures and Principles and Capital Adequacy of Crypto Asset Service Providers (III-35/B.2)", "Communiqué on Procedures and Principles Regarding Information Systems Management (VII-128.10)", Law No. 6698 on the Protection of Personal Data (KVKK) and other relevant secondary regulations.

3. DOCUMENT TYPES AND TRANSMISSION OBLIGATIONS

The Company defines the following types of documents that must be transmitted to customers in accordance with the Board regulations and establishes processes for the traceable transmission of these documents in its systems:

  • Client Agreements: Framework agreements, service agreements, account opening forms and identification documents that must be signed within the framework of crypto asset brokerage services.
  • Risk Notification Forms: Forms for informing customers about issues such as price volatility, custody risks, liquidity, counterparty risk of the crypto assets to be traded.
  • Information and Consent Documents: Disclosure texts, explicit consent forms, platform usage rules, fee and commission tariffs in accordance with the legislation regarding the products and services offered to the user.
  • Transaction Documents: Receipts, e-invoice and e-archive documents for each crypto asset transaction, fund transfer, withdrawal or deposit made by the Client.
  • Change Notifications: Sharing with the customer any changes made to the contract terms, fee/commission rates, terms of use or platform operation.
  • Regulatory Compliance Documents: Documents such as additional declaration forms, information update requests, risk classification assessments requested pursuant to Board regulations.

Each of these documents cannot be executed without the client's approval or notification, and the timing, content appropriateness and accessibility of the transmission are subject to supervision.

4. DOCUMENT SUBMISSION METHODS

The Company sends documents to customers using the following methods and creates proof of transmission for each method:

  • Electronic Notification / In-Platform Notification: Documents transmitted to customers based on the platform login via the user interface are recorded with the phrase "read/approved".
  • Notification by e-mail: Documents are sent to the customer's e-mail address registered in the system. Sending is tracked with SMTP logs, transmission status, opening information and error reports.
  • SMS Notification: Notification about critical changes or important documents can be made via SMS. SMS sending logs are stored with content and timestamp.
  • Sending with Wet Signature (In Mandatory Cases): Documents that require a physical signature by law are sent to the customer address by cargo/courier. Delivery receipts are archived.
  • e-Signature / Mobile Signature: Relevant system integrations are used for documents that need to be signed with RA approved e-signature or mobile signature infrastructure. The signature is stored together with the time stamp.

All delivery methods are supported by a systematic logging infrastructure that can confirm that the documents have reached the customer and that the content is complete.

5. VERIFICATION AND RECORDING OF DOCUMENT DELIVERY

The Company establishes the technical infrastructure that can prove that documents have been sent to and accessed by customers and records the process according to the following principles:

  • Read/Approved Records: For notifications made through the platform, the transaction time, user ID, IP address and device information are recorded together with details such as the time the customer viewed or approved the relevant document. These records are stored in association with the relevant document.
  • Transmission Logs: Transmission details of notifications made via e-mail, SMS or other communication channels are recorded in the system logs along with the time of transmission, address sent, server response and error/delivery information.
  • Signature Traces: For documents signed with methods such as e-signature, mobile signature or in-platform electronic approval; the signing timestamp, user information and hash value of the relevant document are recorded.
  • Physical Delivery Records: For documents sent physically in mandatory cases; cargo / courier delivery minutes, the name of the person receiving the delivery and the date of delivery are added to the Company's registration system.
  • Versioning: Each version of the documents sent is labeled and stored separately on the system. In particular, past versions of risk notifications and framework agreements are archived and kept accessible on a client basis.

All these records are kept in a secure, unalterable and accessible format for at least 10 years for use in Board audits, customer disputes or internal audit processes.

6. RISK WARNINGS AND THE PRINCIPLE OF TIMELY NOTIFICATION

The Company ensures timely and clear notification of risk notifications, operational changes and regulatory disclosures that it is obliged to inform customers about:

  • Documents are submitted through processes structured in such a way that the transaction cannot be initiated prior to the execution of the relevant transaction or without the client's consent.
  • Significant changes in legislation, contract or platform policy are communicated to clients at least 2 business days before they come into force.
  • If a new product/service is offered, the risk warning and terms of use to be offered to customers are communicated in advance and the service is not activated without explicit consent/approval.
  • All these notifications are time-stamped and recorded in the relevant internal systems.

7. INTERNAL AUDIT AND COMPLIANCE OVERSIGHT

The Company regularly evaluates the document submission processes carried out within the scope of this procedure within the framework of the internal audit mechanism:

  • Submitted documents, transmission logs, customer approval records and document versions are sampled at least once a year by the internal audit unit.
  • Corrective and preventive actions are planned and implemented for the findings of audits such as incomplete transmission, late notification, documents not reaching the customer.
  • If requested by the CMB, MASAK and other supervisory institutions, all log, approval and version records for each document sent are submitted in a timely and complete manner.

8. ENFORCEMENT

This procedure enters into force as of 25.03.2025. It has been approved by the board of directors and is mandatory for all units of the company. The procedure is reviewed at least once a year and revised in line with legislative changes, system updates or audit findings. The Procedure is binding for all units and service providers of the Company.