Important Legal Notice
This document describes SmartPayFX's internal compliance standards and customer-facing compliance principles. It does not itself constitute a statement that SmartPayFX holds any particular licence, regulatory approval, statutory classification or supervisory status unless such status has been formally granted and separately disclosed.
The legal and regulatory obligations applicable to SmartPayFX may depend on its exact business model, licences, registrations, payment arrangements, counterparties and services. SmartPayFX should obtain qualified Tanzanian legal and regulatory advice before relying on this Policy as its final statutory compliance manual.
Contents
- 1. Purpose
- 2. Scope
- 3. Legal & Regulatory Framework
- 4. Core Compliance Principles
- 5. Compliance Governance
- 6. AML, CFT & KYC
- 7. Consumer Protection
- 8. Exchange Rate Transparency
- 9. Data Protection & Privacy
- 10. Cybersecurity
- 11. Fraud Prevention
- 12. Transaction Integrity
- 13. Digital Asset Compliance
- 14. Third-Party Compliance
- 15. Record Keeping
- 16. Complaints & Disputes
- 17. Conflicts of Interest
- 18. Staff Conduct & Training
- 19. Compliance Incidents
- 20. Regulatory Cooperation
- 21. User Responsibilities
- 22. Policy Enforcement
- 23. Monitoring & Review
- 24. Contact
1. Purpose
SmartPayFX is committed to conducting its activities in a lawful, fair, transparent and responsible manner. The purpose of this Compliance Policy is to establish a framework for managing legal, regulatory, operational, financial-crime, customer-protection, data-protection and technology risks.
This Policy is intended to help protect SmartPayFX users, personnel, business partners, payment infrastructure and the integrity of the services offered through SmartPayFX.
2. Scope
This Policy applies, where relevant, to:
- SmartPayFX management, employees, contractors and authorised personnel.
- Users of SmartPayFX products and services.
- Deposits and withdrawals involving supported trading platforms.
- Transactions involving Deriv USD wallets and supported mobile money services.
- Supported trading platforms including Deriv, Weltrade, HFM and Exness.
- Supported mobile money services including M-Pesa, Airtel Money, Mixx by Yas and Halopesa.
- Buying and selling supported digital currencies such as USDT and Bitcoin (BTC).
- APIs, payment partners, financial institutions and other third-party service providers used by SmartPayFX.
3. Legal & Regulatory Framework
SmartPayFX seeks to conduct its operations consistently with laws and regulatory requirements applicable to its activities in Tanzania and any other jurisdiction in which services are lawfully provided.
Relevant legal and regulatory areas may include, where applicable:
- Anti-money laundering, counter-terrorist financing and proliferation-financing requirements.
- National payment-system laws, regulations and supervisory requirements.
- Financial consumer-protection requirements.
- Personal data protection and privacy requirements.
- Electronic transactions, cybersecurity and fraud-prevention requirements.
- Foreign-exchange requirements.
- Tax, accounting, corporate and record-retention requirements.
- Requirements applicable to virtual assets or digital currencies.
Where applicable law imposes a higher standard than this Policy, the applicable legal requirement takes precedence.
4. Core Compliance Principles
SmartPayFX's compliance approach is guided by the following principles:
- Lawfulness: services should be operated in accordance with applicable law.
- Transparency: users should receive clear information about transactions, rates, relevant fees and service conditions.
- Fair Treatment: users should be treated consistently and without deceptive or unfair practices.
- Security: reasonable technical and organisational safeguards should protect systems and customer information.
- Accountability: compliance responsibilities should be clearly assigned and documented.
- Risk-Based Controls: stronger controls may be applied where a customer, transaction or service presents greater risk.
- Traceability: transactions and material compliance actions should be appropriately recorded.
- Continuous Improvement: controls should be reviewed as laws, risks, technology and services evolve.
5. Compliance Governance & Internal Controls
SmartPayFX aims to maintain internal governance arrangements proportionate to the nature and scale of its operations.
These arrangements may include:
- Clear allocation of compliance responsibilities.
- Defined approval levels for sensitive operational and financial actions.
- Role-based staff permissions and access controls.
- Audit logs for significant administrative and transactional activities.
- Internal escalation procedures for unusual activity and compliance concerns.
- Periodic review of policies, procedures and operational controls.
- Segregation of duties where appropriate to reduce fraud and operational risk.
6. AML, CFT & Know Your Customer Compliance
SmartPayFX maintains AML/KYC controls intended to reduce the risk of its services being used for money laundering, terrorist financing, proliferation financing, fraud, sanctions evasion or other unlawful activity.
Controls may include:
- Customer identification and verification.
- Enhanced due diligence for higher-risk relationships.
- Source-of-funds or source-of-wealth checks where appropriate.
- Transaction monitoring.
- PEP and sanctions screening where legally required or risk-appropriate.
- Review and escalation of unusual or suspicious activity.
- Record keeping and regulatory reporting where legally required.
Detailed requirements are set out in the separate SmartPayFX AML & KYC Policy.
7. Financial Consumer Protection
SmartPayFX aims to treat customers fairly and provide sufficient information for users to make informed transaction decisions.
Consumer-protection principles include:
- Clear disclosure of transaction information before confirmation.
- Transparent presentation of applicable exchange rates.
- Clear transaction status information.
- Reasonable protection of customer information.
- Fair and professional customer support.
- Accessible complaints and dispute-handling channels.
- Avoidance of misleading, deceptive or unfair marketing practices.
8. Exchange Rate Transparency & Rate Lock
SmartPayFX displays the applicable exchange rate to the user before a transaction is initiated.
Once the user confirms and initiates a transaction, the displayed exchange rate is locked for that transaction. The transaction will be completed using the same rate shown and accepted at the beginning of the transaction.
Subsequent market-rate movements do not change the exchange rate already confirmed for that transaction.
If the transaction is cancelled, rejected, expires, fails or must be initiated again, a new rate may be displayed and applied to the new transaction.
9. Data Protection & Privacy Compliance
SmartPayFX may collect and process personal data required for account management, transaction processing, customer support, fraud prevention, KYC/AML, security and legal compliance.
SmartPayFX aims to process personal information lawfully, fairly and transparently and to maintain appropriate technical and organisational safeguards.
Data-protection controls may include:
- Collecting only data reasonably required for identified purposes.
- Keeping personal information accurate and appropriately updated.
- Restricting employee access according to operational need.
- Protecting personal data from unauthorised access, loss, destruction or disclosure.
- Retaining personal data only for legitimate business or legal purposes.
- Managing disclosures and international data transfers in accordance with applicable requirements.
- Handling data-subject requests and personal-data incidents through defined procedures.
SmartPayFX should maintain a separate Privacy Policy or Privacy Notice describing customer-facing data-processing practices.
10. Cybersecurity & Access Control
SmartPayFX aims to maintain security controls proportionate to the sensitivity of its systems, data and payment operations.
Controls may include:
- Secure authentication and password controls.
- Multi-factor authentication for sensitive administrative access where appropriate.
- Role-based permissions.
- Encryption and secure communication protocols where appropriate.
- Security logging and monitoring.
- Protection against unauthorised administrative changes.
- Backup and recovery procedures.
- Security patching and vulnerability management.
- Incident response procedures.
11. Fraud Prevention & Detection
SmartPayFX may use automated and manual controls to detect and prevent fraudulent activity.
Examples of activity that may trigger review include:
- False or manipulated payment information.
- Duplicate or previously used payment references.
- Unauthorised account access.
- Identity inconsistencies.
- Account takeover or impersonation attempts.
- Unusual transaction frequency or transaction patterns.
- Use of payment methods not reasonably connected to the verified user.
12. Transaction Integrity & Operational Controls
SmartPayFX aims to maintain transaction controls that reduce errors, duplicate processing, unauthorised transactions and manipulation of payment records.
Operational controls may include:
- Unique transaction identifiers.
- Transaction status tracking.
- Duplicate-reference detection.
- Verification of payment information before settlement where applicable.
- Audit logs for important transaction events.
- Administrative approval controls for sensitive actions.
- Reconciliation of payment and transaction records.
13. Digital Asset Compliance
SmartPayFX may support selected digital currencies, including USDT and Bitcoin (BTC).
Because digital assets can present elevated operational, fraud, AML, cybersecurity and regulatory risks, additional controls may be applied to digital-asset transactions.
These may include:
- Wallet-address and network verification.
- Transaction-risk review.
- Source or destination information requests.
- Blockchain transaction review using available tools where appropriate.
- Enhanced verification for higher-risk transactions.
- Restrictions on transactions that present unacceptable legal or financial-crime risk.
Availability of digital-asset services remains subject to applicable law and SmartPayFX risk controls.
14. Third-Party & Service Provider Compliance
SmartPayFX may depend on mobile money providers, banks, trading platforms, API providers, cloud infrastructure, telecommunications providers and other external service providers.
Where appropriate, SmartPayFX may assess third parties based on operational reliability, security, legal risk, compliance requirements and suitability for the service provided.
Third-party relationships do not remove SmartPayFX's responsibility to maintain reasonable internal controls for activities under its own control.
15. Record Keeping & Audit Trail
SmartPayFX may retain transaction records, KYC records, customer communications, system logs, compliance reviews and other records required for business, security, fraud-prevention, audit, dispute-resolution or legal purposes.
Records should be complete enough to support transaction reconstruction, internal review, customer complaints and lawful requests from competent authorities where applicable.
Retention periods will be determined by applicable law, regulatory requirements and legitimate business needs.
16. Customer Complaints & Dispute Handling
SmartPayFX aims to provide users with accessible channels for reporting transaction problems, service complaints, suspected fraud and other concerns.
Complaint-handling procedures should include:
- Recording the complaint and relevant transaction information.
- Acknowledging and reviewing the complaint within a reasonable period.
- Investigating available payment, system and transaction records.
- Communicating the outcome or status to the customer where permitted.
- Escalating unresolved or higher-risk matters internally.
- Maintaining records of complaints and resolutions.
17. Conflicts of Interest
SmartPayFX personnel should avoid situations in which personal interests improperly influence business decisions, transaction handling, customer treatment or access to confidential information.
Actual or potential conflicts of interest should be disclosed and managed through appropriate internal procedures.
18. Staff Conduct, Confidentiality & Training
Personnel with access to SmartPayFX systems, customer information or transaction operations are expected to act professionally, ethically and in accordance with internal policies.
Personnel should:
- Protect confidential customer and business information.
- Use system access only for authorised business purposes.
- Report suspected fraud, security issues or compliance breaches.
- Avoid unauthorised alteration of transaction records.
- Complete relevant compliance and security training where required.
19. Compliance Breaches & Incident Management
Suspected compliance breaches, fraud incidents, data breaches, security incidents or material operational failures should be identified, documented, escalated and investigated according to their severity.
SmartPayFX may take corrective measures including access restriction, account review, process changes, security remediation, staff disciplinary action, customer notification or regulatory reporting where legally required.
21. User Compliance Responsibilities
Users are expected to:
- Provide accurate and current account and identity information.
- Use only payment methods and accounts they are authorised to use.
- Review transaction information before confirming payment.
- Respond to legitimate KYC or compliance requests.
- Use SmartPayFX only for lawful purposes.
- Protect their login credentials and verification information.
- Promptly report suspected unauthorised activity.
- Avoid attempting to bypass transaction, verification or security controls.
22. Policy Enforcement
SmartPayFX may, subject to applicable law and contractual obligations, take proportionate action where a user, transaction or account presents a compliance, security, fraud or legal risk.
Actions may include:
- Requesting additional information or documentation.
- Placing a transaction under review.
- Delaying or rejecting a transaction.
- Restricting certain account functions.
- Temporarily suspending or terminating access to services.
- Preserving relevant records.
- Making legally required reports or disclosures to competent authorities.
23. Compliance Monitoring & Policy Review
SmartPayFX may periodically review its compliance framework to reflect changes in law, regulation, technology, fraud patterns, business activities, payment methods, third-party services and operational risks.
Policies, procedures, system controls and staff responsibilities may be updated where weaknesses, new risks or regulatory changes are identified.
Updated customer-facing versions of this Compliance Policy may be published on the SmartPayFX website.
Relationship with Other SmartPayFX Policies
This Compliance Policy should be read together with, where applicable:
- SmartPayFX AML & KYC Policy.
- SmartPayFX Risk Disclosure.
- SmartPayFX Privacy Policy.
- SmartPayFX Terms & Conditions.
- SmartPayFX Refund or Transaction Resolution Policy.
- Any transaction-specific disclosures presented to the user.
24. Contact SmartPayFX
If you have questions about this Compliance Policy, a transaction, account verification or a compliance request, contact SmartPayFX Support.
Website: smartpayfx.org
WhatsApp Support: 0773001444