Crypto-Currency Policy

3-102-949565 SOCIEDAD DE RESPONSABILIDAD LIMITADA | Last updated: 2026-06-17

The English version prevails.

This Crypto-Currency Policy sets out the framework for accepting, processing, monitoring and risk-managing cryptocurrency transactions by 3-102-949565 SOCIEDAD DE RESPONSABILIDAD LIMITADA (the "Company"). It supplements the Terms and Conditions, Payments Policy and AML/KYC Policy.

1. Purpose and Scope

1.1 The purpose of this Policy is to ensure that cryptocurrency transactions are handled in a controlled, transparent and compliant manner, while mitigating money laundering, terrorist financing, sanctions, technology and operational risks.

1.2 The Company does not operate as a cryptocurrency exchange, broker, peer-to-peer trading platform or custodial wallet provider. Cryptocurrency functionality is facilitated through licensed and regulated third-party payment service providers (PSPs), where available.

1.3 Cryptocurrency is treated as a high-risk payment method and is subject to Enhanced Due Diligence where required by the AML/KYC Policy.

2. Definitions

Cryptocurrency means a digital representation of value secured by cryptography and recorded on a distributed ledger. PSP means a third-party payment service provider authorised or otherwise permitted to process cryptocurrency transactions. AML/CFT means anti-money laundering and counter-terrorist financing. EDD means enhanced due diligence. SAR/SMR means suspicious activity report or suspicious matter report to the relevant authority.

3. Transaction Channels

3.1 Deposits. Customers may initiate deposits through approved cryptocurrency PSPs. Deposits are credited only after the required blockchain confirmations, PSP screening and Company compliance checks are completed.

3.2 Withdrawals. Customers may request withdrawals in supported cryptocurrencies. Before execution, the request is checked against account KYC/EDD status, transaction history and blockchain analytics results. Withdrawals are executed through the PSP.

3.3 The Company may refuse, delay, return, freeze or block any cryptocurrency transaction in accordance with the AML/KYC Policy, Payments Policy, sanctions requirements, PSP requirements or regulatory direction.

4. Third-Party Providers and Internal Controls

4.1 The Company partners only with cryptocurrency PSPs assessed as suitable for the transaction type and risk profile. Due diligence is conducted at onboarding and at least annually, covering licensing/registration status, AML/CFT controls, blockchain analytics capability, cybersecurity, incident response and business continuity.

4.2 API integrations with PSPs are secured by encryption and subject to periodic testing. Access to crypto-related systems is controlled through multi-factor authentication, role-based access and logging.

4.3 Daily reconciliation is conducted between PSP transaction logs and internal financial records. Material discrepancies are escalated to Finance and Compliance.

4.4 Periodic reports on crypto transaction volumes, trends, incidents and risks are provided to senior management or the Board and to regulators upon request.

5. Accepted Cryptocurrencies

5.1 The Company maintains a conservative approach to accepted cryptocurrencies, balancing customer demand with AML/CFT and operational risk. Approved cryptocurrencies are: USDT, USDC, BTC, ETH, SOL, LTC, TRX, TON, BNB, XRP, CSC, ADA, BCH, CORE, DOGE, DOT, NOT, LINK, DAI, AVAX, POL, SHIB, SUI, XLM, DASH.

5.2 The Company may add, suspend or remove supported cryptocurrencies based on PSP availability, blockchain analytics coverage, sanctions exposure, liquidity, regulatory requirements, cyber risk or AML/CFT risk.

6. Prohibited Jurisdictions and EDD Jurisdictions

6.1 The Company does not accept cryptocurrency transactions from customers located in jurisdictions subject to international sanctions, TGC restricted jurisdictions, jurisdictions where online gambling or crypto transactions are prohibited, or jurisdictions otherwise restricted by the Company.

6.2 The current Tobique Restricted Jurisdictions are: Afghanistan, Canadian Province of New Brunswick, China, Cuba, Central African Republic, Democratic Republic of Congo, Haiti, Iran, Iraq, Israel, Libya, Myanmar, North Korea, Russia, Somalia, South Sudan, Syria, United Kingdom, United States of America, Yemen, Venezuela.

6.3 The Company also applies additional restrictions based on its risk appetite, payment-provider limitations, game-provider restrictions, legal risk and operational controls. These additional restrictions do not by themselves classify the jurisdiction as Tobique-banned or AML high-risk: Armenia, Azerbaijan, Belarus, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, Australia, Belgium, Canada (Ontario), Croatia, Denmark, France, Georgia, Guinea Bissau, Jamaica, Lebanon, Netherlands, Nicaragua, Pakistan, Panama, Philippines, Poland, Portugal, Spain, Switzerland, Turkey, Ukraine, Zimbabwe.

6.4 Where a jurisdiction is not restricted but is listed by Tobique as requiring Enhanced Due Diligence, crypto services may be provided only after EDD at first deposit and subject to enhanced transaction monitoring. Current Tobique EDD jurisdictions include: Albania, Barbados, Bulgaria, Burkina Faso, Burundi, Chad, Comoros, Cameroon, Cayman Islands, Croatia, Equatorial Guinea, Gibraltar, Jamaica, Jordan, Lebanon, Mali, Mozambique, Nicaragua, Nigeria, Pakistan, Palestinian Territory, Panama, Philippines, Senegal, South Africa, Tanzania, Tajikistan, Turkey, Turkmenistan, Uganda, United Arab Emirates, Ukraine, Vietnam, Zimbabwe. The Compliance function must update this list promptly if Tobique amends its assessment.

7. Prohibited Activities

7.1 Company-level prohibitions. The Company does not operate as an exchange or broker, issue tokens or ICOs, provide custodial wallet services or hold private keys on behalf of customers, engage in proprietary crypto trading or arbitrage, or participate in DeFi lending, staking, yield farming or liquidity provision.

7.2 Customer-level prohibitions. Customers must not use mixers, tumblers, chain-hopping, privacy-enhancing tools or other techniques designed to obscure origin, destination or ownership. Transactions involving sanctioned wallets, blacklisted wallets, darknet markets, ransomware, fraud, illicit enterprises or restricted jurisdictions are prohibited.

7.3 Violations may result in automatic blocking, Account freeze, EDD, SAR/SMR filing, permanent Account closure and referral to law enforcement or regulators.

8. Risk Controls

8.1 Customer risk controls include KYC verification, sanctions/PEP/adverse media screening, source-of-funds and source-of-wealth checks, risk rating, senior management approval for high-risk cases and ongoing monitoring.

8.2 Transaction risk controls include blockchain analytics, wallet risk scoring, wallet attribution, exposure to high-risk services, sanctions and blacklist checks, transaction velocity rules, structuring checks and review of consistency with the customer profile.

8.3 Automated alerts are suspended pending Compliance review. Confirmed suspicious cases are escalated to the AMLCO/MLRO and reported under the AML/KYC Policy.

8.4 Technology risk controls include secure integrations, encryption in transit and at rest, MFA, RBAC, vulnerability scanning, penetration testing, intrusion detection, daily backups and incident response procedures.

9. Blocking, Freezing and Customer Communication

9.1 Crypto deposits or withdrawals may be automatically blocked where screening identifies sanctions exposure, blacklisted wallets, illicit typologies, restricted jurisdictions or other high-risk indicators.

9.2 Funds may be temporarily frozen while Compliance investigates. During a freeze, the customer may be unable to withdraw or transfer funds and may be asked for additional information, transaction explanation or SOF/SOW documentation.

9.3 Customers may be informed that an Account or transaction is under review unless doing so would breach tipping-off rules or compromise an investigation.

10. Record Keeping, Training and Reporting

10.1 The Company retains records of crypto transactions, wallet addresses, timestamps, amounts, blockchain analytics reports, wallet risk scores, customer KYC/EDD, investigation notes, escalations and SAR/SMR decisions for at least five years or longer where required.

10.2 Staff involved in crypto onboarding, payments, compliance, finance, IT or customer support receive role-based training on cryptocurrency risks, typologies, monitoring tools, escalation and reporting obligations, with annual refreshers.

10.3 Suspicious crypto activity is reported in accordance with the AML/KYC Policy, including TGC reporting timelines and any FIU reporting obligation.

Review Cryptocurrency Transaction Rules at Winari Casino Canada