LEGAL
KYC, AML/CFT and Compliance Policy.
Wibx · Last updated: September 24, 2026
Guidelines adopted by Wibx for identifying, validating and monitoring platform users, focused on security, transparency, traceability and regulatory compliance.
WIBX · KYC · AML/CFT · Compliance
01
Purpose
This KYC, AML/CFT and Compliance Policy establishes the guidelines adopted by Wibx for identifying, validating and monitoring platform users, with the objective of promoting a secure, transparent environment aligned with good practices for fraud prevention, anti-money laundering and counter-terrorism financing.
Wibx adopts mechanisms proportional to its operating model and to the utility nature of the Wibx token, seeking to ensure traceability, integrity and regulatory compliance in its operations.
02
Scope
This policy applies to users, partners, participants and internal processes related to identity validation, compliance and Wibx token movement.
- All users of the Wibx platform.
- Commercial partners.
- Campaign participants.
- Operations involving movement of the Wibx token.
- Internal processes related to identity validation and compliance.
03
KYC (“Know Your Customer”) guidelines
Wibx performs identity verification procedures before releasing rewards and before any balance movement (exchange, gift or sending to an external address), under item 3.4 of the Terms of Use.
The validation process may include document, registration, anti-fraud and additional security checks when considered necessary.
- Submission of a valid official photo ID.
- Facial image, liveness check and authentication video.
- Ownership validation.
- Identity confirmation.
- Anti-fraud analysis of behavior, addresses and network.
- Registration verification.
- Additional security mechanisms when considered necessary.
- Teenagers between 14 and 18: verification done with the legal guardian, who assists and authorizes the registration.
04
Accepted documents
Valid official documents may be accepted, provided they are compatible with the data provided by the user and with applicable law.
- National Driver’s License (CNH).
- National Identity Card (RG).
- Passport.
- Equivalent documents permitted by applicable law.
- Legal entities: CNPJ card, articles of association or bylaws (latest amendment or consolidated), head office address and documents of the legal representative, a valid public power of attorney being accepted.
- Wibx may refuse documents that are illegible, expired, adulterated, inconsistent or incompatible with the data provided by the user.
05
Video authentication process
As an additional security and fraud-prevention measure, Wibx may request an authentication video from the user.
- Visual identification of the user.
- Display of the document used.
- Statement of ownership and authorization for validation.
- Confirmation of the request date.
- The video audio only records the spoken declaration of ownership; it is not used as voice biometrics.
- This procedure aims to reinforce registration authenticity, reduce risks of false identity, protect users and partners and ensure future audit capability.
06
Anti-Money Laundering and Counter-Terrorism Financing (AML/CFT)
Wibx adopts measures compatible with good practices for anti-money laundering and counter-terrorism financing.
Whenever necessary, Wibx may request additional information, suspend movements, block or reverse movements in case of fraud or proven operational error, block accounts, deny access to the platform and cooperate with competent authorities.
- User identification.
- Record retention.
- Analysis of suspicious behavior.
- No reward released and no balance movement before registration validation.
- Per-period limits, published on the Platform, for gifts between users and for sending to an external address.
- Sending to an external address only to an address owned by the user, verified before delivery, made by WibxCo in its own name.
- Wibx received from an external address is transferred to WibxCo in exchange for program balance; other tokens sent create no credit and no obligation.
- Monitoring of movements.
- Internal compliance mechanisms.
07
Risk-based approach
Wibx adopts an approach proportional to risk (“risk-based approach”) and may apply additional validations according to the operating context and identified signals.
- User operational profile.
- Movement volume.
- Behavioral patterns.
- Fraud indicators.
- Legal or regulatory requirements.
08
Record retention
KYC and movement records are kept securely for 5 (five) years from account closure or completion of the movement, whichever is later, under art. 10 of Law 9,613/1998, a period that may be extended by order of a competent authority.
- Compliance with legal obligations.
- Audits.
- Fraud prevention.
- Dispute resolution.
- Cooperation with competent authorities.
09
Information security
Wibx adopts technical and organizational measures aimed at protecting collected information, compatible with the size and nature of the operation.
- Access control.
- Secure storage.
- Internal monitoring.
- Protection against unauthorized access.
- Digital security mechanisms compatible with the size of the operation.
10
Cooperation with authorities
Wibx may cooperate with judicial, regulatory or administrative authorities whenever there is a legal obligation, an order from a competent authority or a need to protect the platform, its users and partners.
11
Policy updates
This policy may be changed periodically to reflect operational improvements, regulatory changes, evolution of compliance practices and updates to security mechanisms.
The most recent version will remain available through Wibx’s official channels.
12
Contact
Questions related to this policy may be sent to the support center (atendimento@wibx.io) or the DPO (encarregadodedados@wibx.io).