Zowin card game

Anti-Money Laundering and Customer Due Diligence Policy

1. Policy Purpose and Regulatory Position

This Anti-Money Laundering and Customer Due Diligence Policy (“Policy”) establishes the framework applied by Mobile Incorporated Limited (the “Company”, “we”, “us”, or “our”) to prevent the misuse of its services for money laundering, terrorist financing, fraud, or any other financial crime.

The Company operates under a B2C Gaming Service Licence issued by the Malta Gaming Authority (MGA) and is subject to Maltese Anti-Money Laundering and Counter-Terrorist Financing legislation as a designated subject person.

The Company adopts a risk-based compliance model intended to identify, mitigate, and report financial crime risks across all customer relationships and transactional activity.

This Policy applies to all customers using the Company’s gaming and betting services.

2. Onboarding Controls and Customer Verification

2.1 Standard Customer Due Diligence

At onboarding, or where required during the business relationship, the Company applies Customer Due Diligence (CDD) measures to verify identity and establish customer legitimacy.

These measures include:

  • Collection of valid government-issued photographic identification
  • Verification of full name, date of birth, and residential address
  • Confirmation that the customer is at least 18 years of age
  • Validation through trusted electronic or manual verification sources

The Company may restrict account access until satisfactory verification is completed.

2.2 Enhanced Due Diligence Requirements

Where elevated risk indicators are present, Enhanced Due Diligence (EDD) measures are applied.

This may occur in cases involving:

  • High-risk customer classification
  • Politically Exposed Persons (PEPs)
  • Unusual transaction behaviour or elevated volumes
  • Unclear or unverifiable source of funds or wealth
  • High-risk jurisdictions or geographic exposure

EDD may include:

  • Requesting additional supporting documentation
  • Independent verification of identity and financial information
  • Source of funds or wealth validation
  • Senior Management review and approval prior to continuation

3. Source of Funds and Financial Transparency

The Company may request documentation to verify the legitimacy of funds used on the platform.

Acceptable evidence may include:

  • Bank statements
  • Employment confirmation or salary records
  • Business ownership documentation
  • Asset disposal or sale agreements

Pending satisfactory review, the Company reserves the right to restrict deposits, gameplay, or withdrawals.

4. Transaction Monitoring and Behavioural Analysis

The Company operates ongoing monitoring systems designed to detect suspicious or unusual activity.

Monitoring focuses on identifying:

  • Irregular deposit and withdrawal patterns
  • Rapid movement of funds without gaming activity
  • Structuring or fragmentation of transactions
  • Behaviour inconsistent with known customer profile

Alerts generated through monitoring systems are reviewed by trained compliance personnel.

Where concerns arise, the Company may:

  • Request further verification or documentation
  • Apply temporary restrictions on account activity
  • Escalate internally for compliance review
  • File a Suspicious Activity Report (SAR) with the FIAU where appropriate

5. Sanctions Screening and PEP Identification

All customers are screened against relevant international and domestic databases, including:

  • European Union sanctions lists
  • United Nations sanctions lists
  • Applicable national sanctions regimes
  • Politically Exposed Person (PEP) databases

Screening occurs at onboarding and is repeated periodically throughout the business relationship.

6. Reporting Duties and Legal Obligations

Where the Company knows, suspects, or has reasonable grounds to suspect money laundering or terrorist financing activity, a Suspicious Activity Report (SAR) is submitted to the Financial Intelligence Analysis Unit (FIAU) in accordance with Maltese legislation.

The Company strictly prohibits any form of tipping-off to customers or third parties regarding investigations or reporting.

The Company fully cooperates with:

  • The FIAU
  • The Malta Gaming Authority (MGA)
  • Law enforcement authorities

7. Record Retention Requirements

The Company maintains comprehensive AML records, including:

  • Identity verification documents
  • Transaction histories
  • Risk scoring and assessments
  • Compliance and SAR documentation

All records are retained for a minimum of five (5) years following the end of the business relationship or the last customer transaction, whichever is later.

8. Risk-Based Monitoring and Ongoing Assessment

The Company applies a continuous risk-based approach to customer monitoring.

Risk classification considers:

  • Geographic exposure
  • Transaction behaviour and financial patterns
  • Account activity and usage trends
  • Additional behavioural risk indicators

Customers assessed as higher risk are subject to enhanced monitoring and more frequent review.

The Company produces internal risk and compliance reports as required under regulatory obligations, including submissions to the MGA where applicable.

9. Customer Responsibilities

Customers are required to:

  • Provide accurate, complete, and truthful personal information during registration
  • Maintain up-to-date account details at all times
  • Provide requested documentation for verification purposes promptly

Failure to comply with AML/KYC requirements may result in:

  • Suspension of account access
  • Restriction of deposits or withdrawals
  • Account termination in line with regulatory requirements

10. Governance Structure and Training

The Company maintains a structured AML governance framework including:

  • Appointment of a Money Laundering Reporting Officer (MLRO)
  • Internal AML/CTF policies and documented procedures
  • Defined escalation and approval workflows
  • Regular employee training on AML and CTF obligations

The effectiveness of the AML framework is subject to periodic internal review and compliance assessment.

11. Data Protection and Information Handling

All personal and financial data collected for AML/KYC purposes is processed in accordance with applicable data protection legislation, including GDPR and relevant regulatory standards.

The Company ensures:

  • Secure storage and controlled access to data
  • Processing limited to authorised personnel and regulatory purposes
  • Compliance with confidentiality and security obligations
  • Proper retention and disposal procedures in line with legal requirements

All AML/KYC-related records are retained for at least five (5) years following termination of the business relationship or last transaction.

12. Withdrawal Controls and €2,000 Verification Threshold

Withdrawals are subject to compliance checks and identity verification requirements as part of the Company’s AML and fraud prevention controls.

The Company applies enhanced verification where a customer’s cumulative deposits exceed €2,000.

This threshold may be calculated using either:

  • a daily aggregated calculation, including all deposits made by the customer since the establishment of the business relationship; or
  • a rolling 180-day (one hundred and eighty days) assessment period, aggregating all deposits within that timeframe

Where this threshold is reached, the Company may require additional identity verification prior to processing withdrawals.

Failure to complete verification may result in delays, suspension, or restriction of withdrawal processing.

13. Policy Maintenance and Amendments

This Policy may be updated from time to time to reflect changes in legal, regulatory, or operational requirements.

The most recent version will always prevail and will be made available through the Company’s official communication channels or website.