Introduction
The Know Your Customer (KYC) Policy governs identity verification, customer due diligence, and ongoing monitoring on the Xhjili Website. It implements applicable anti‑money laundering (AML) and counter‑terrorist financing (CTF) obligations and sets out the data collection, verification, and record‑keeping requirements applicable to all users and accounts.
Scope and Definitions
This Policy applies to all registered users and their activity on the Xhjili Website (the Platform). For clarity: "We" or "Our" refers to Xhjili; "Website" means the Xhjili platform; "Verification" means identity verification and documentation checks; "Source of Funds" means the origin of funds used to fund an account; "PEP" means Politically Exposed Person; "SAR" means Suspicious Activity Report.
Risk‑Based Approach
Xhjili applies a risk‑based framework aligned with FATF guidance to identify, assess, and mitigate ML/CTF risks associated with customers and transactions. The principal risk dimensions are:
- Country/Geography risk: jurisdiction of residence or operation, including high‑risk or offshore jurisdictions.
- Customer risk: indicators such as PEP status, sanctions exposure, adverse media, or unusual activity patterns.
- Transaction risk: magnitude, velocity, and instrument mix of deposits and withdrawals.
Customer Verification (KYC)
On onboarding and during ongoing relations, Xhjili conducts Standard Verification when risk indicators or activity warrant. Triggers for verification include:
- Cumulative deposits and withdrawals through the Platform reaching or exceeding €1,000 (or equivalent in another currency);
- Identification of significant ML/CTF risk or suspicious behavior;
- Behavioural indicators suggesting non‑compliance with Terms or illicit activity;
- Regulatory or internal policy requirements mandating verification.
Required documentation and data include:
- A clear copy or photograph of a government‑issued identification document showing the holder’s full name and photograph;
- A photograph of the payment instrument to be used for deposits, with the cardholder name matching the account holder; CVV and middle digits may be redacted, but the cardholder name must be legible;
- A photograph of the user holding the required documents when requested (verification selfie or live verification as required by the Platform);
- Proof of address (e.g., utility bill or bank statement issued within the last three months) showing the user’s name and residential address;
- Additional data as reasonably requested to verify the Source of Funds, in accordance with applicable law.
Verification decisions are communicated to the user. If verification is incomplete or delayed, deposit and withdrawal capabilities may be restricted pending completion. Refusal to provide required information may result in temporary or permanent account restriction or closure.
Enhanced Verification for PEPs and High‑Risk Jurisdictions
If a user is a Politically Exposed Person (PEP) or connected with a high‑risk jurisdiction, Xhjili applies Enhanced Due Diligence (EDD) in addition to Standard Verification. Additional measures may include:
- Comprehensive source of wealth and source of funds verification beyond routine documentation;
- Additional identity checks and risk profiling;
- Decision making involving senior management or the MLRO for final verification;
- Ongoing enhanced monitoring with increased review frequency.
Ongoing Monitoring
All user activity remains subject to ongoing monitoring for suspicious patterns and inconsistencies. The Platform actively reviews deposits, withdrawals, and linked payment instruments to ensure consistency with the user profile and declared activity. Indicators of suspicious activity include, but are not limited to:
- Unusual deposit patterns or funding from multiple instruments or devices;
- Discrepancies between geolocation data and declared residency or identity data;
- Use of multiple accounts or devices to evade verification or limits;
- Unwillingness to provide verification data or to engage with the Support Team.
Suspected cases are escalated to the anti‑fraud/AML function for assessment and potential further action in accordance with applicable law.
Transactions Monitoring and Payment Integrity
All transactions are subject to monitoring and reconciliation. The Platform enforces the following controls:
- Payments via cards must be initiated and funded by the account holder; third‑party payments are prohibited;
- Electronic wallets used for deposits must be linked to the registered account email;
- The Platform does not accept anonymous payments or funds from untraceable instruments (including anonymous cryptocurrencies or wallets);
- Deposited funds are generally returned to the original payment instrument where feasible; withdrawals are processed to the original funding source or an instrument verifiable as belonging to the user;
- Withdrawals are not made to a payment instrument where ownership cannot be reliably established.
Record Keeping, Data Retention and Privacy
Documents and data collected for Verification, as well as transaction records and supporting evidence, are stored and processed in compliance with applicable AML laws and data protection regulations. Retention periods align with the relevant jurisdiction’s legal requirements and the Platform’s Privacy Policy. Access to records is restricted to authorised personnel and regulatory authorities as required by law.
Reporting, Cooperation and Audit Trail
Where there are reasonable grounds to suspect money laundering or terrorist financing, the Platform reports to the designated Money Laundering Reporting Officer (MLRO) and, where required, to competent authorities. Employees must act promptly and maintain confidentiality; disclosure or tipping off to the subject of an investigation is prohibited. The MLRO coordinates internal and external reporting as permitted by law and maintains an auditable trail of actions taken.
Roles, Training and Compliance Governance
Senior management is accountable for policy governance and effectiveness. A designated MLRO is responsible for receiving disclosures, managing SARs, and coordinating regulatory reporting. All staff receive ongoing AML/CFT training, including customer due diligence (CDD), enhanced due diligence (EDD) for high‑risk clients, and procedures for reporting suspicious activity to the MLRO.
High‑Risk Jurisdictions and Sanctions
Customers connected with high‑risk jurisdictions or FATF‑designated high‑risk countries are subject to enhanced scrutiny or restricted access. The Platform may refuse service or apply additional due diligence as permitted by law. Use of funds from or a connection to sanctioned individuals or entities will be investigated and may be reported to authorities as required by law.
Amendments and Communications
The Platform may amend this Policy at any time. Material changes will be communicated through appropriate channels to registered users, and continued use of the Website after notification constitutes acceptance of the updated Policy.
Data Subject Rights and Information Security
Users retain rights under applicable data protection law, including access, correction, deletion, and restriction of processing, subject to regulatory requirements. Xhjili implements reasonable security measures to protect data from unauthorized access, loss, or alteration, consistent with industry standards and regulatory obligations.
