Bitrux.io
Anti-Money Laundering & Counter-Terrorist Financing Policy
1. Purposes and Basis

In view of the fact that money laundering undermines the development of digital asset trading, facilitates corruption, damages the legitimate rights and interests of users, and increases legal and operational risks for digital asset trading platforms, Bitrux formulates this policy in accordance with our User Agreement and relevant documentation to prevent money laundering and terrorist financing while ensuring full compliance with applicable regulations. By the nature of our business, Bitrux serves clients globally and adheres to international anti-money laundering standards. This policy outlines procedures to prevent money laundering, terrorist financing, and corruption. Bitrux is committed not merely to legal compliance, but to effectively minimizing the risk of criminal exploitation through implementation of the highest standards.


2. Scope of Application

This Policy applies to all users trading on Bitrux Platform. Users shall comply with anti-money laundering and anti-terrorist financing laws and regulations applicable in their jurisdiction. Where stricter requirements exist in a user's country or region, those requirements shall prevail.


3. Fight Against Money Laundering and Terrorist Financing

This refers to measures adopted pursuant to relevant laws and regulations to prevent money laundering activities carried out through the Platform for the purpose of concealing the source and nature of proceeds obtained through crimes including narcotics trafficking, organized crime, terrorism, smuggling, corruption, bribery, financial fraud, and other illegal activities.


4. Platform Rules and Regulations

Bitrux's anti-money laundering framework includes this Policy, relevant sections in the User Agreement, Guidelines for Large Transaction Management, and User Guidelines for Anti-Money Laundering and Terrorist Financing. In the event of conflicts between documents, specific guidelines shall prevail over general policies.


5. Basic Principles

The Platform monitors user risks according to the following principles:

(1) The principle of comprehensiveness. The Platform considers all risk factors that may indicate money laundering and monitors all users appropriately.

(2) The principle of prudence. Based on thorough user understanding, the Platform maintains robust identity authentication capabilities and monitors user risks prudently.

(3) The principle of sustainability. The Platform maintains continuous attention to user risks and responds based on actual circumstances.

(4) The principle of confidentiality. User identity information, transaction data, and risk levels are kept strictly confidential and disclosed only when required by law or regulatory authorities.

(5) The principle of hierarchical management. The Platform regularly reviews user information according to risk levels, with stricter scrutiny applied to higher-risk users.


6. Responsible Organization

The Platform operates anti-money laundering functions through a guidance group and an operational team, consisting of members from risk control and compliance departments.


7. Functions of Responsible Organization

The guidance group is responsible for planning, directing, and coordinating anti-money laundering affairs. Specific responsibilities include:

(1) to review and approve AML policies, work plans, and reports;

(2) to promulgate and update AML principles and rules;

(3) to review organizational structure and AML responsibilities;

(4) to design internal inspection and transaction control procedures;

(5) to study complex AML issues and develop solutions.

The operational team's responsibilities include:

(1) to implement AML rules and guidance group plans;

(2) to execute various assignments;

(3) to analyze and identify suspicious user identities and transactions;

(4) to assess and adjust user risk levels;

(5) to conduct due diligence and continuous supervision;

(6) to review transactions regularly;

(7) to report suspicious transactions to competent authorities;

(8) to assist investigations upon request from authorities.


8. Due Diligence

Following principles of diligence and Know Your Customer (KYC), the Platform conducts due diligence on all users. For high-risk users, enhanced due diligence is required.


9. Documents Required from Individual Users

Based on jurisdictional requirements, required information may vary. Individual users typically must provide:

(1) full legal name (first name and last name as shown on the identity document);

(2) date of birth;

(3) issuing country;

(4) government-issued identity document type — one of: National ID Card, Driving License, or Passport;

(5) identity document number;

(6) a clear digital photo of the front of the identity document;

(7) a clear digital photo of the back of the identity document;

(8) a selfie photograph clearly showing the applicant's face;

(9) contact information including telephone number and email address;

(10) other information or documents as requested.


10. Documents Required from Institutional Users

Institutional users shall submit:

(1) legal entity name;

(2) registered office address;

(3) contact information;

(4) articles of incorporation or association;

(5) equity structure and ownership description;

(6) legal representative information;

(7) legal representative's residence;

(8) legal representative's contact details;

(9) business license or registration certificate;

(10) authorization to open account;

(11) letter of authorization;

(12) valid ID or passport copy of legal representative;

(13) other information or documents upon request.


11. Document Languages

The Platform accepts documents in English. Documents in other languages must be translated by a qualified translator and properly notarized.


12. Document Photos

Submitted identity document photos must be original, unedited digital captures taken directly from the physical document. Scanned copies, photocopies, screenshots, or images edited with graphic software are not accepted. Photos must be in JPG or PNG format, must not exceed 2 MB each, and must clearly show the complete document without cropping, glare, or obstruction.


13. Photograph-Based Verification

Users must complete photograph-based identity verification by submitting a selfie photo that clearly and unambiguously shows the applicant's face. This selfie is reviewed alongside the submitted identity document photos to confirm that the applicant and the document holder are the same person. Photos that are blurry, partially obscured, edited, or otherwise non-compliant with the stated requirements will result in rejection of the verification application.


14. Identification of Beneficiaries and Controllers

The Platform identifies actual beneficial owners or controllers of accounts. For institutional users, shareholders holding more than 25% must provide materials and undergo identity verification.


15. Third-Party Identity Authentication

When using third-party authentication services, such institutions must:

(1) adopt necessary user identification and information storage measures in compliance with AML regulations;

(2) provide user information without legal or technical obstacles;

(3) enable timely access to user information and identity documents upon request.


16. Review of User Documents

The Platform verifies and records submitted information according to user identification procedures. When doubts arise regarding submitted information, the Platform may request additional documents or consult with relevant authorities.


17. Classification of Risk Levels

The Platform classifies users into three categories: low-risk, medium-risk, and high-risk, based on submitted materials, geographical location, industry involvement, shareholder background, and public figure status. The Platform reserves the right to adjust user risk classifications.


18. High-Risk Users

High-risk users include those with any of the following factors:

(1) users subject to or under criminal or administrative investigation;

(2) politically exposed persons (PEPs) or entities controlled by PEPs;

(3) users from high-risk jurisdictions;

(4) users identified as key suspicious accounts;

(5) users engaged in high-risk industries such as jewelry, precious metals, currency exchange, pawn services, money remittance, etc.;

(6) users engaging in intensive trading inconsistent with market conditions;

(7) users conducting unusual operations.


19. Low-Risk Users

Low-risk users include:

(1) financial institutions or reputable companies;

(2) natural persons properly verified with low money laundering risk;

(3) users reviewed and approved by risk control and compliance departments.


20. Medium-Risk Users

Medium-risk users are those not classified as high-risk or low-risk.


21. Risk Level Adjustment

The Platform maintains continuous monitoring of user identity and transaction status. Upon detecting changes, abnormalities, or suspicious information, the Platform will re-identify users and adjust risk levels accordingly. Adjustments may be made without providing reasons.


22. Monitoring High-Risk Users

The Platform conducts regular reviews of high-risk users to update identity information and ascertain funding sources, fund usage, financial standing, and business status. Risk levels may be lowered following comprehensive assessment if activity appears normal.


23. Continuous User Identification

The Platform maintains continuous identity verification throughout the business relationship. If user information expires without timely update and no justifiable reason is provided, services may be suspended.


24. User Re-Identification

The Platform may re-identify users under these circumstances:

(1) user requests to change name, identification type, ID number, or other key information;

(2) abnormal user conduct or trading patterns;

(3) user name matches known criminal suspects or sanctioned individuals;

(4) suspected money laundering or terrorist financing;

(5) inconsistencies in user information;

(6) doubts about authenticity, validity, or integrity of previously obtained information;

(7) other circumstances deemed necessary by the Platform.


25. Trading Limits

The Platform sets and adjusts maximum transaction and withdrawal amounts based on transaction security and operational conditions.


26. Suspicious Transaction Identification

The Platform monitors and verifies the following suspicious activities:

(1) dispersed transfers followed by collective withdrawals within short periods, or vice versa, inconsistent with user profile;

(2) dormant accounts suddenly reactivated with abnormal asset inflows and rapid withdrawals;

(3) multiple accounts opened or cancelled without justification, with large deposits or withdrawals before closure;

(4) suspicious large deposits or withdrawals in individual user accounts;

(5) excessively frequent trading inconsistent with market conditions;

(6) other suspicious trading patterns identified by the Platform.


27. Terrorist Financing Identification

When transactions or attempted transactions are suspected to relate to terrorism, terrorist organizations, or individuals engaged in terrorist financing, appropriate measures are adopted regardless of transaction amount.


28. Handling Suspicious Conduct

The Platform may suspend transactions, reject applications, reverse transactions, freeze accounts, or report to authorities when users:

(1) refuse to provide valid identification;

(2) refuse to update profile information without justification;

(3) provide information that remains doubtful despite verification;

(4) forge or alter identification documents;

(5) refuse to provide reasonable explanations for suspicious conduct or provide unjustifiable explanations.


29. Data Storage System

The Platform maintains a comprehensive system for storing user identity information and transaction records to facilitate AML investigation and regulatory oversight while preventing data loss, damage, or unauthorized disclosure.


30. Scope of Data Storage

Stored information includes user-provided identity information, identity verification data and records, transaction data, and information reflecting actual transaction circumstances.


31. Retention Periods

Data retention periods are as follows:

(1) user identity information: at least five years from the date business relationship ends;

(2) transaction records: at least five years from transaction date;

(3) information related to ongoing money laundering investigations: retained until investigation completion, even if minimum retention period expires.


32. Assistance to Authorities

When judicial, law enforcement, or competent authorities request assistance in investigations, the Platform cooperates and provides requested information and materials.


33. Confidentiality Requirements

Staff members accessing AML-related information must maintain strict confidentiality regarding user identity information, suspicious transactions, terrorist financing data, and other sensitive information. Such information may not be disclosed to unauthorized organizations, individuals, or unrelated staff members.


34. User Obligations

Users must:

(1) not lend account credentials to others;

(2) not rent or lend identity documents;

(3) not rent, lend, or disclose important personal information such as account details and passwords;

(4) actively cooperate with Platform identity verification procedures.


35. Reporting Suspicious Activity

Users may report suspected money laundering or terrorist financing activities to the Platform.


36. Interpretation

This Policy shall be interpreted by Bitrux.


37. Effective Date

This Policy is effective from the date of promulgation.