1.Purpose and scope
- Clause 1.1. This Anti-Money-Laundering and Know-Your-Customer Policy (the “Policy”) sets out how [JustPoker Operating Company Ltd.] (“JustPoker”, “we”) prevents its services from being used to launder the proceeds of crime, to finance terrorism or to evade sanctions. It is a public summary of the internal procedures required by our licence from [Licensing Authority] and by the anti-money-laundering legislation of [Jurisdiction of Incorporation].
- Clause 1.2. The Policy applies to every customer, every transaction and every member of staff. It applies in demo mode as well as to real-money play, because the account, identity and conduct controls it describes are the same in both.
- Clause 1.3. Nothing in this Policy limits our discretion to refuse, delay or reverse a transaction, to request further information, or to close an account where we consider that a money-laundering, terrorist-financing or sanctions risk exists.
2.Governance and responsibilities
- Clause 2.1. Our board has appointed a Money Laundering Reporting Officer (MLRO) with sufficient seniority, independence and resources to oversee this Policy, and a deputy to act in the MLRO's absence. The MLRO is responsible for receiving internal reports of suspicious activity, deciding whether an external report must be made, liaising with the financial-intelligence unit and the Regulator, and reporting to the board at least annually on the effectiveness of our controls.
- Clause 2.2. The compliance function maintains the detailed procedures that implement this Policy, sets and reviews risk thresholds, and monitors alerts. Product and engineering teams may not release a change to account, banking or game functionality without a compliance review.
- Clause 2.3. This Policy is reviewed at least once a year and whenever there is a material change in the law, in guidance from the Regulator, in our products, or in the risks we identify.
3.Risk-based approach
- Clause 3.1. We apply a risk-based approach: the intensity of our checks is proportionate to the risk presented by each customer, product, transaction and delivery channel. We maintain a written business-wide risk assessment that identifies these risks and the controls that mitigate them.
- Clause 3.2. Each customer is assigned a risk rating of low, medium or high at onboarding and the rating is refreshed continuously by our monitoring. Factors that increase risk include, among others:
- residence in or connections to a jurisdiction identified as high-risk or subject to sanctions;
- status as a politically exposed person (PEP), or as a family member or close associate of one;
- deposit volume, velocity or value that is inconsistent with the customer's known profile;
- use of wallets that blockchain analysis links to mixers, darknet markets, ransomware, sanctioned addresses, stolen funds or unlicensed exchanges;
- minimal or unusual gameplay relative to deposits (indicative of using the account as a pass-through);
- requests to withdraw to an address different from the one used to deposit;
- inconsistent, reluctant or false answers to due-diligence questions;
- device, network or behavioural signals shared with other accounts.
- Clause 3.3. Cryptocurrency as a delivery channel is treated as inherently higher risk than card or bank payments because of its pseudonymity and cross-border nature. Our crypto-specific controls are set out in section 9.
4.Customer due diligence
- Clause 4.1. Customer due diligence (CDD) means identifying the customer, verifying that identity using reliable independent sources, understanding the purpose and intended nature of the relationship, and — where the customer acts for someone else — identifying the beneficial owner. We accept only natural persons acting on their own behalf; accounts opened for a business, a trust or another person are refused.
- Clause 4.2. We carry out CDD when an account is opened, before the first withdrawal, when the cumulative deposits of a customer reach the threshold set by law or by our risk assessment (currently the equivalent of EUR 2,000 in a rolling 30-day period, or a lower threshold where risk indicators exist), whenever we suspect money laundering or terrorist financing, and whenever we doubt the accuracy of information previously obtained.
- Clause 4.3. Where CDD cannot be completed we do not open the account, do not process the transaction, restrict or close the account, and consider whether a suspicious-activity report is required.
5.Verification levels
Our verification programme has three levels. Your current level and any outstanding requirement are shown on the Verification page of your account.
| Level | When | What we collect and check | What it unlocks |
|---|---|---|---|
| Level 1 Registration | At sign-up | Email address (validated), username, date of birth, country of residence, acceptance of terms and your confirmation of age and self-exclusion status. Checked for duplicate accounts; screening against restricted-jurisdiction rules and our internal exclusion list applies from real-money launch. Status: unverified. | Account access, demo play, and — at launch — deposits and real-money play within limits. |
| Level 2 Identity | Before the first withdrawal, on reaching the CDD deposit threshold, or on request | A government-issued photo identity document (passport, national identity card or driving licence; both sides where applicable) and a proof of address dated within the last three months. Documents are checked for authenticity and consistency with the Level 1 details and screened under section 7. Review target: 24 hours. Status: pending → verified or rejected. | Withdrawals; higher deposit limits. |
| Level 3 Source of funds | Where enhanced due diligence applies (section 6) | Evidence of source of funds and, where appropriate, source of wealth: for example payslips or tax returns, bank or exchange statements showing the purchase of the cryptocurrency deposited, proof of ownership of the depositing wallet (signed message or micro-transaction), and an explanation of the intended level of play. A compliance officer reviews the file and documents the decision. | Continued play and withdrawals above the enhanced-due-diligence thresholds. |
- Clause 5.1. Documents must be genuine, unexpired, in colour, fully legible and show all four corners. We may ask for a selfie holding the document or a short live video, and may use an independent verification provider to check document security features and match the photograph.
- Clause 5.2. A rejected submission can be resubmitted with corrected documents. Repeated submission of altered or fraudulent documents results in account closure and, where appropriate, a report to the authorities.
6.Enhanced due diligence
- Clause 6.1. Enhanced due diligence (EDD) is applied to every customer rated high risk and in every case the law requires it, including: PEPs and their family members and close associates; customers connected to high-risk third countries; customers whose cumulative deposits, withdrawals or wagering exceed our EDD thresholds; and any relationship in which we have identified unusual or suspicious patterns.
- Clause 6.2. EDD measures include Level 3 verification, senior-management approval to open or continue the relationship, more frequent and more detailed transaction monitoring, verification of the source of the specific funds deposited, and a documented rationale for the decision reached.
- Clause 6.3. While EDD is outstanding we may suspend deposits, play and withdrawals. If satisfactory evidence is not provided within a reasonable time — normally 30 days — the account is closed and verified funds are returned to their source, unless we are prohibited from doing so.
7.Sanctions and PEP screening
- Clause 7.1. Every customer is screened at registration, at each verification level and thereafter continuously against applicable sanctions lists (including those of the United Nations, the European Union, the United Kingdom and the United States Office of Foreign Assets Control), against lists of politically exposed persons, and against adverse-media sources. Deposit and withdrawal addresses are screened against sanctioned-address lists.
- Clause 7.2. A confirmed sanctions match results in the immediate freezing of the account and its funds and a report to the competent authority. We do not process transactions with sanctioned persons, entities or addresses, and we do not accept customers from comprehensively sanctioned territories.
- Clause 7.3. Potential matches are reviewed by a compliance officer, who discounts false positives on documented grounds before any restriction is lifted.
8.Ongoing monitoring
- Clause 8.1. We monitor accounts and transactions on an ongoing basis to ensure that activity is consistent with what we know about the customer, their risk rating and their source of funds. Monitoring combines automated rules with human review; every credit and debit passes through a single immutable ledger, and every hand is recorded with its seeds and result, which gives our analysts a complete audit trail.
- Clause 8.2. Examples of behaviour that generates an alert: deposits followed by withdrawal with little or no play; structuring of deposits just below thresholds; a sudden increase in stakes or volume; deposits from many unrelated wallets; withdrawal requests to new addresses shortly after deposit; play patterns consistent with chip dumping or collusion; and any activity matching a known money-laundering typology for online gambling.
- Clause 8.3. Alerts are triaged within one business day. Outcomes are documented and may include a request for information, a change of risk rating, application of EDD, restriction of the account, or an internal report to the MLRO.
- Clause 8.4. Customer information is refreshed periodically according to risk — at least every three years for low-risk customers, annually for medium risk and at least every six months for high-risk customers — and whenever a trigger event occurs.
9.Cryptocurrency-specific controls
- Clause 9.1. Blockchain analysis. Every deposit is screened with a blockchain-analytics provider before it is credited. The screening traces the funds through preceding transactions and assigns a risk score. Funds with exposure to sanctioned addresses, darknet markets, ransomware, theft, terrorist financing, or unlicensed or high-risk services are held pending review and may be returned to source or frozen and reported.
- Clause 9.2. No mixers or privacy tools. We do not accept deposits that have passed through mixing, tumbling or coin-join services, or that originate from privacy-focused protocols designed to obscure the source of funds. We do not support privacy coins. Attempting to deposit such funds is a breach of our Terms of Service.
- Clause 9.3. Closed-loop withdrawals. Withdrawals are paid, wherever the network allows it, to the same wallet from which the customer deposited. A withdrawal to a different address requires proof that the customer controls it and is subject to additional review. We do not pay withdrawals to third parties, to exchange accounts not held in the customer's name, or to addresses that fail screening.
- Clause 9.4. Supported assets and confirmations. We accept only the assets and networks listed in the cashier and credit a deposit only after the number of confirmations we specify for that asset, which limits exposure to chain reorganisations and double-spend attempts. Deposits are converted to USD at the time of crediting and the applied rate is recorded.
- Clause 9.5. Travel-rule compliance. Where a deposit or withdrawal involves a regulated virtual-asset service provider, we exchange the originator and beneficiary information required by the FATF “travel rule” through a compliant messaging protocol.
- Clause 9.6. Wallet ownership. At Level 3 we may require proof that the customer controls a wallet, by signing a message with the wallet's key or by sending a micro-transaction of a specified amount.
10.Record keeping
- Clause 10.1. We keep, for at least five years after the end of the business relationship or the date of the transaction (whichever is later): copies of, or references to, the evidence of identity obtained; details of every deposit, withdrawal, stake and payout in our ledger; blockchain transaction identifiers and screening results; risk assessments and the reasoning behind due-diligence decisions; internal and external suspicious-activity reports; and training records.
- Clause 10.2. Records are stored securely with access restricted to authorised staff, and are made available to the Regulator, the financial-intelligence unit and law enforcement on lawful request. Retention may be extended where required by an authority or an ongoing investigation. Our Privacy Policy explains how this interacts with your data-protection rights.
11.Reporting
- Clause 11.1. Any member of staff who knows, suspects or has reasonable grounds to suspect that a customer is engaged in money laundering or terrorist financing must report it to the MLRO without delay through our internal reporting channel. Failure to report is a disciplinary matter.
- Clause 11.2. The MLRO evaluates each internal report and, where the legal test is met, files a suspicious-activity or suspicious-transaction report with the financial-intelligence unit of [Jurisdiction of Incorporation] and notifies the Regulator where its rules require. Where the law requires consent before a transaction proceeds, we will not process it until consent is obtained or the statutory period expires.
- Clause 11.3. Tipping off is prohibited. We will not tell a customer that a report has been made or that an investigation is under way. Delays to withdrawals that arise from this process are explained only in general terms.
- Clause 11.4. We cooperate fully with the Regulator, financial-intelligence units, law-enforcement agencies and courts, and respond to production orders and information requests within the time they specify.
12.Training and audit
- Clause 12.1. All staff complete anti-money-laundering, counter-terrorist-financing and sanctions training on joining and at least annually thereafter. Staff in customer support, payments, compliance and engineering receive additional role-specific training covering the typologies relevant to online gambling and cryptocurrency. Training records are kept for five years.
- Clause 12.2. From real-money launch the effectiveness of this Policy will be tested by an independent audit function at least annually and the findings reported to the board. Material deficiencies are remediated under a tracked action plan and, where required, notified to the Regulator.
13.What this means for you
- Clause 13.1. In practice, this Policy means that we may ask you for documents or information at any time; that withdrawals are not processed until you have completed Level 2 verification; that you should deposit and withdraw using wallets you personally control; that you should never use a mixing service or deposit funds belonging to someone else; and that a delay to a transaction is sometimes required by law and cannot be explained in detail.
- Clause 13.2. The faster you respond to a request for information, the faster we can complete our review. You can see what is outstanding at any time on the Verification page.
14.Contact
- Clause 14.1. Questions about this Policy or about a verification request: compliance@justpoker.example. Help with uploading documents: support@justpoker.example or the contact form. Regulator details are on the Licensing page.