+
SmartPayFX Governance & Compliance

Compliance Policy

This Compliance Policy sets out the principles and controls SmartPayFX uses to promote lawful, transparent, secure and responsible operation of its digital payment services, supported trading-platform transactions, mobile money services and supported digital currency activities.

Effective Date: 27 August 2026 Website: smartpayfx.org Applies to: SmartPayFX operations, personnel, users and supported services

Important Legal Notice

This document describes SmartPayFX's internal compliance standards and customer-facing compliance principles. It does not itself constitute a statement that SmartPayFX holds any particular licence, regulatory approval, statutory classification or supervisory status unless such status has been formally granted and separately disclosed.

The legal and regulatory obligations applicable to SmartPayFX may depend on its exact business model, licences, registrations, payment arrangements, counterparties and services. SmartPayFX should obtain qualified Tanzanian legal and regulatory advice before relying on this Policy as its final statutory compliance manual.

Contents

1. Purpose

SmartPayFX is committed to conducting its activities in a lawful, fair, transparent and responsible manner. The purpose of this Compliance Policy is to establish a framework for managing legal, regulatory, operational, financial-crime, customer-protection, data-protection and technology risks.

This Policy is intended to help protect SmartPayFX users, personnel, business partners, payment infrastructure and the integrity of the services offered through SmartPayFX.

2. Scope

This Policy applies, where relevant, to:

3. Legal & Regulatory Framework

SmartPayFX seeks to conduct its operations consistently with laws and regulatory requirements applicable to its activities in Tanzania and any other jurisdiction in which services are lawfully provided.

Relevant legal and regulatory areas may include, where applicable:

Where applicable law imposes a higher standard than this Policy, the applicable legal requirement takes precedence.

4. Core Compliance Principles

SmartPayFX's compliance approach is guided by the following principles:

5. Compliance Governance & Internal Controls

SmartPayFX aims to maintain internal governance arrangements proportionate to the nature and scale of its operations.

These arrangements may include:

6. AML, CFT & Know Your Customer Compliance

SmartPayFX maintains AML/KYC controls intended to reduce the risk of its services being used for money laundering, terrorist financing, proliferation financing, fraud, sanctions evasion or other unlawful activity.

Controls may include:

Detailed requirements are set out in the separate SmartPayFX AML & KYC Policy.

7. Financial Consumer Protection

SmartPayFX aims to treat customers fairly and provide sufficient information for users to make informed transaction decisions.

Consumer-protection principles include:

8. Exchange Rate Transparency & Rate Lock

SmartPayFX displays the applicable exchange rate to the user before a transaction is initiated.

Once the user confirms and initiates a transaction, the displayed exchange rate is locked for that transaction. The transaction will be completed using the same rate shown and accepted at the beginning of the transaction.

Subsequent market-rate movements do not change the exchange rate already confirmed for that transaction.

If the transaction is cancelled, rejected, expires, fails or must be initiated again, a new rate may be displayed and applied to the new transaction.

9. Data Protection & Privacy Compliance

SmartPayFX may collect and process personal data required for account management, transaction processing, customer support, fraud prevention, KYC/AML, security and legal compliance.

SmartPayFX aims to process personal information lawfully, fairly and transparently and to maintain appropriate technical and organisational safeguards.

Data-protection controls may include:

SmartPayFX should maintain a separate Privacy Policy or Privacy Notice describing customer-facing data-processing practices.

10. Cybersecurity & Access Control

SmartPayFX aims to maintain security controls proportionate to the sensitivity of its systems, data and payment operations.

Controls may include:

11. Fraud Prevention & Detection

SmartPayFX may use automated and manual controls to detect and prevent fraudulent activity.

Examples of activity that may trigger review include:

12. Transaction Integrity & Operational Controls

SmartPayFX aims to maintain transaction controls that reduce errors, duplicate processing, unauthorised transactions and manipulation of payment records.

Operational controls may include:

13. Digital Asset Compliance

SmartPayFX may support selected digital currencies, including USDT and Bitcoin (BTC).

Because digital assets can present elevated operational, fraud, AML, cybersecurity and regulatory risks, additional controls may be applied to digital-asset transactions.

These may include:

Availability of digital-asset services remains subject to applicable law and SmartPayFX risk controls.

14. Third-Party & Service Provider Compliance

SmartPayFX may depend on mobile money providers, banks, trading platforms, API providers, cloud infrastructure, telecommunications providers and other external service providers.

Where appropriate, SmartPayFX may assess third parties based on operational reliability, security, legal risk, compliance requirements and suitability for the service provided.

Third-party relationships do not remove SmartPayFX's responsibility to maintain reasonable internal controls for activities under its own control.

15. Record Keeping & Audit Trail

SmartPayFX may retain transaction records, KYC records, customer communications, system logs, compliance reviews and other records required for business, security, fraud-prevention, audit, dispute-resolution or legal purposes.

Records should be complete enough to support transaction reconstruction, internal review, customer complaints and lawful requests from competent authorities where applicable.

Retention periods will be determined by applicable law, regulatory requirements and legitimate business needs.

16. Customer Complaints & Dispute Handling

SmartPayFX aims to provide users with accessible channels for reporting transaction problems, service complaints, suspected fraud and other concerns.

Complaint-handling procedures should include:

17. Conflicts of Interest

SmartPayFX personnel should avoid situations in which personal interests improperly influence business decisions, transaction handling, customer treatment or access to confidential information.

Actual or potential conflicts of interest should be disclosed and managed through appropriate internal procedures.

18. Staff Conduct, Confidentiality & Training

Personnel with access to SmartPayFX systems, customer information or transaction operations are expected to act professionally, ethically and in accordance with internal policies.

Personnel should:

19. Compliance Breaches & Incident Management

Suspected compliance breaches, fraud incidents, data breaches, security incidents or material operational failures should be identified, documented, escalated and investigated according to their severity.

SmartPayFX may take corrective measures including access restriction, account review, process changes, security remediation, staff disciplinary action, customer notification or regulatory reporting where legally required.

20. Cooperation with Competent Authorities

SmartPayFX may cooperate with courts, law-enforcement agencies, financial-intelligence authorities, data-protection authorities, financial regulators and other legally competent bodies when required by applicable law.

This may include preserving records, providing information pursuant to valid legal requests, restricting transactions where required, or submitting reports where SmartPayFX has a legal obligation to do so.

21. User Compliance Responsibilities

Users are expected to:

22. Policy Enforcement

SmartPayFX may, subject to applicable law and contractual obligations, take proportionate action where a user, transaction or account presents a compliance, security, fraud or legal risk.

Actions may include:

23. Compliance Monitoring & Policy Review

SmartPayFX may periodically review its compliance framework to reflect changes in law, regulation, technology, fraud patterns, business activities, payment methods, third-party services and operational risks.

Policies, procedures, system controls and staff responsibilities may be updated where weaknesses, new risks or regulatory changes are identified.

Updated customer-facing versions of this Compliance Policy may be published on the SmartPayFX website.

Relationship with Other SmartPayFX Policies

This Compliance Policy should be read together with, where applicable:

24. Contact SmartPayFX

If you have questions about this Compliance Policy, a transaction, account verification or a compliance request, contact SmartPayFX Support.

Website: smartpayfx.org

WhatsApp Support: 0773001444