ANTI-MONEY LAUNDERING POLICY

Version 1.0 as of December 15, 2025

Introduction

This Anti-Money Laundering (“AML”) Policy establishes the principles and procedures adopted by UP-X (hereinafter “the Company”, “We”, “Us”, or “Our”) to prevent the use of its services for money laundering, terrorist financing, or any other illicit activities. The Policy applies to all employees, contractors, and partners of the Company, and covers all business relationships and transactions carried out through the Platform.

The Company is committed to maintaining full compliance with the applicable laws and regulations, as well as with international best practices and standards, including those established by the Financial Action Task Force (FATF).

1. Purpose and Scope

This Policy defines measures to prevent, detect, and report money laundering and terrorist financing. It applies to:

All services and operations provided via the Platform;

All employees, contractors, and business partners;

All users interacting with the Company’s services.

It covers the entire user lifecycle, including onboarding, transactions, monitoring, reporting, and record-keeping.

2. Compliance with Applicable Law and International Standards

Our AML program ensures:

Full compliance with applicable legislation;

Adherence to FATF recommendations and international best practices;

Prevention and reporting of illicit activity in financial transactions.

3. About Money Laundering

Money laundering refers to the illegal process of transforming the proceeds of criminal activities into funds that appear to originate from legitimate sources. It typically involves the following three stages:

Placement. Introduction of illicit funds into the financial system, often through deposits, purchases of valuable assets, or other transactions designed to insert criminal proceeds into circulation.

Layering. Execution of complex financial movements to obscure the origin of the funds, including multiple transfers, currency exchanges, or cross-border transactions, creating a complicated trail that is difficult to trace.

Integration. Reintroduction of the laundered funds into the legitimate economy, where they can be used for investments, asset purchases, or other lawful activities without arousing suspicion.

These stages are deliberately designed to disguise the illegal origins of the funds, making it challenging for authorities to detect and prosecute those involved.

4. Definitions

For the purposes of this Policy, the following terms shall have the meanings set out below:

Money Laundering (ML) – The process of concealing the illicit origin of funds derived from criminal activities and integrating them into the legitimate financial system.

Terrorist Financing (TF) – The act of providing or collecting funds, by any means, directly or indirectly, with the intention that they be used to carry out terrorist acts or activities.

Customer – Any natural or legal person who uses or seeks to use the services of the Company.

Politically Exposed Person (PEP) – An individual who is or has been entrusted with prominent public functions, as well as their immediate family members and close associates.

Beneficial Owner – The natural person who ultimately owns or controls a customer, or on whose behalf a transaction is conducted.

Suspicious Activity – Any transaction or pattern of transactions that gives rise to a reasonable suspicion of money laundering, terrorist financing, or other criminal activity.

CDD (Customer Due Diligence) – The process of identifying and verifying the identity of a customer, assessing the nature and purpose of the business relationship, and conducting ongoing monitoring.

FATF – The Financial Action Task Force, an inter-governmental body that sets international standards for combating money laundering and terrorist financing.

5. Customer Due Diligence (CDD) and KYC

The Company implements robust Know Your Customer (KYC) procedures:

A. Identification and Verification

Initial Registration: Users provide personal information (full name, date of birth, address, nationality) and valid identification documents (passport, national ID, or driver’s license). Documents must be:

Color scans or photographs (not black-and-white);

Clear, high resolution, and unobstructed by glare or shadows;

Fully visible (all edges and corners shown).

Verification: Documents are checked via secure automated systems or third-party services.

Ongoing Monitoring: Updates to user profiles (e.g., address or name changes) trigger re-verification.

We can ask You provide additional Supporting Documents. When required, You must provide:

Proof of address (utility bill, bank statement, government letter issued within the last 3 months);

Proof of source of funds or source of wealth (salary slips, bank statements, tax returns, sale contracts, etc.).

To verify identity, we may request one or more of the following:

A live selfie holding the identification document;

A short video for liveness check;

A photo of the User holding the document and a handwritten note with the current date and the Company’s name.

Photographs must:

Be taken in good lighting;

Clearly show the User’s full face and the document details;

Match the appearance on the submitted ID.

B. Age Verification and Source of Funds

Users must verify their age to confirm legal eligibility; minors are prohibited.

Source of funds is assessed, especially for high-value transactions or high-risk users.

C. Risk-Based Approach and Enhanced Due Diligence (EDD)

Users are categorized as low, medium, or high risk based on profile, activity, and jurisdiction.

High-risk users, including PEPs, undergo Enhanced Due Diligence, including additional background checks and more frequent transaction monitoring.

6. Transaction Monitoring and Suspicious Activity

A. Monitoring

Transactions are monitored in real-time for unusual patterns, amounts, frequency, and geographic risk.

Automated systems flag potential suspicious transactions.

B. Detection and Reporting

Flagged transactions are reviewed manually by the compliance team.

Suspicious Activity Reports (SARs) are submitted to the relevant financial intelligence unit or regulatory authority as required by law.

Internal reporting protocols ensure employees escalate concerns promptly.

C. Cooperation with Authorities

The Company maintains open communication with the relevant authorities and other competent law enforcement agencies.

7. Record-Keeping and Risk Management

Retention Period:

The Company securely retains all records of customer identification data, verification results, transactional history, communication logs, and any Suspicious Activity Reports (SARs) for a minimum of five (5) years from the date of the transaction or closure of the Account, whichever is later, in accordance with applicable AML regulations.

Storage and Security:

All records are stored in encrypted databases with restricted access granted only to authorized personnel.

Physical copies, if maintained, are kept in secure, access-controlled facilities.

Backup systems ensure that no records are lost due to technical failures.

Risk Assessment Procedures:

Customer Risk: Users are periodically assessed based on geographic location, occupation, transaction patterns, and source of funds.

Transaction Risk: Unusual, complex, or high-value transactions are flagged and reviewed by the Compliance Officer.

Product/Service Risk: New products, payment methods, or features are reviewed for potential AML vulnerabilities before implementation.

Risk Re-Evaluation:

Risk ratings may be updated at any time based on new information, changes in user behavior, or alerts from regulatory bodies or law enforcement.

Compliance Oversight:

An appointed AML Compliance Officer (AMLCO) is responsible for:

Ensuring internal policies meet regulatory requirements;

Approving high-risk customers and transactions;

Overseeing the SAR process and liaising with authorities;

Conducting periodic reviews of AML controls and recommending improvements.

8. Training and Compliance

Mandatory Training:

All employees, particularly those in compliance, finance, operations, and customer support, must complete AML training upon hiring and participate in refresher training at least once per year.

Training Content Includes:

AML legal and regulatory requirements;

Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) procedures;

Recognizing and reporting suspicious transactions;

Data protection and secure handling of sensitive information.

Evaluation and Certification:

Employees must pass assessments after training to confirm their understanding of AML obligations. Records of training completion and test results are maintained for regulatory inspection.

Internal Audits:

The AMLCO conducts periodic internal reviews of compliance processes, KYC files, and SAR logs.

Any deficiencies identified are documented with corrective actions and deadlines.

Disciplinary Measures:

Breaches of AML policy, whether intentional or due to negligence, may result in:

Formal warnings;

Mandatory retraining;

Suspension or termination;

Reporting to regulatory or law enforcement authorities.

9. Policy Review and Updates

This AML Policy is reviewed regularly to ensure compliance with evolving laws, regulations, and international standards.

10. Contact Information

For questions or concerns regarding this AML Policy, contact our support team at support@xp5byq04u.life. Please reference this AML Policy in your communication to ensure accurate and timely response.