Legal
Bidali Compliance Program (KYC & AML)
Last updated
On this page
Bidali Inc. ("Bidali", "we", "us", "our", and Company) is a Canadian software company and gift card reseller based in Calgary, Alberta. Our customers buy closed-loop gift cards, prepaid Bidali One platform credit that can only be used to buy gift cards, and small-denomination prepaid cards supplied by a third-party platform. Bidali does not provide payment processing, money transmission, remittance, currency exchange or bill payment services, and does not hold customer funds in the manner of a bank account.
Gift cards and other prepaid products can still be misused for fraud, money laundering and terrorist financing. For that reason we voluntarily run a compliance program (the "Compliance Program") covering identity verification (Know Your Customer or "KYC"), anti-money laundering and anti-terrorist financing ("AML") controls, sanctions screening and fraud monitoring. This policy describes that program. Capitalized terms not defined here have the meaning given in our Terms of Use.
Our Compliance Program
Our Compliance Program includes, but is not limited to:
- Establishing robust internal policies, procedures and controls that strive to combat any attempted use of Bidali's products or services for illegal or illicit purposes;
- Designating a Compliance Officer, responsible for the development, implementation, and oversight of the Compliance Program;
- Executing Know Your Customer procedures to verify the identity of customers* in the circumstances described below;
- Assessing our risks as they relate to fraud, money laundering and terrorist financing;
- Keeping records of the information we collect and the steps we take, as described below;
- Screening customers against sanctions and terrorist lists;
- Monitoring transactions for fraud and for potentially suspicious and attempted suspicious activity;
- Maintaining and providing written, ongoing compliance training for our employees; and,
- Regular reviews of the Compliance Program to test its effectiveness.
*A customer is presently defined as a person or entity that uses Bidali's products and services.
Policies and Procedures
Bidali has adopted a risk-based Compliance Program approved by its board of directors. Bidali personnel and our board of directors recognize the importance of implementing and maintaining a sound Compliance Program. As such, our Company has implemented internal policies and procedures to carry it out. The Compliance Program is reviewed on a regular basis and, if necessary, revised as our products, our risks and applicable laws change.
Our Compliance Officer
Bidali has designated a Compliance Officer who is responsible for the implementation and oversight of the Compliance Program. Our Compliance Officer has the authority and the resources to oversee the identification and prevention of fraud, money laundering and terrorist financing in the jurisdictions that Bidali operates in. Our Compliance Officer and their team can be reached directly at compliance@bidali.com.
Ongoing Monitoring of Business Relationships
We treat a customer as having an ongoing business relationship with Bidali when they have an active account. At Bidali an active account, and therefore a business relationship, is defined as when a customer conducts two or more commercial transactions, with the exclusion of closed loop gift card purchases, within a 12 month period. For business relationships Bidali will:
- Determine the identity of the individual; or
- Confirm the existence of a corporation or other entity.
In addition, Bidali will:
- Risk-rate all business relationships and amend their risk-rating if the need arises;
- Conduct ongoing monitoring of the business relationship as determined by the risk-rating (high/low) assigned to the customer; and,
- Keep a record of the measures that we have taken to monitor the relationship and the information we obtained as a result.
If necessary, we may require our customers to provide additional documentation or information to confirm source of funds for the purpose of the transaction.
Our system employs a combination of automated and manual monitoring procedures with an appropriate escalation process based on risk. Bidali's compliance staff will review any transactions that trigger a system alert and determine if the activities are within the customers’ stated activity and/or normal usage behavior before being completed. In some cases, Bidali will require additional information from the customer such as source of income, proof of employment, proof of corporate registration, nature of the client's business, as well as review of customer’s transaction history.
Know Your Customer Processes
Bidali requires customers to be "verified" in the following circumstances:
- before a business customer can distribute gift cards, Bidali One Balance or other prepaid products to its customers, employees or other recipients;
- when a customer purchases or attempts to purchase a total monetary sum of gift cards or Bidali One Balance equal to or greater than $9,500 per 24 hours;
- when a customer sends equal to or greater than $1,000 in a single transaction or $9,500 per 24 hours in Bidali One Balance to another Bidali customer;
- when a customer has a Bidali One Balance equal or greater than $10,000; and
- at any other time our risk assessment of a customer, a payment method or a transaction calls for it.
All transaction and account limits are denoted in Canadian dollars or the equivalent value in another supported currency. Bidali Accounts are presently only made available to residents in certain countries in order to minimize the risk of money laundering and terrorist financing activities. Please see our Restricted Use Policy for more details.
Information that we may collect in order verify and authenticate a customer or beneficial owner:
- Email address;
- Mobile phone number;
- Full legal name;
- Home Address (not a mailing address or P.O. Box);
- Date of birth ("DOB");
- IP Address
- Unique device information
- Proof of identity (as outlined below);
- Additional information or documentation at the discretion of our compliance team.
Individual customers may be verified by way of:
Single Process Identity Verification Method
Using this method we determine the identity of a customer by referring to a credit file or financial institution account that has been established with a third party credit file provider or financial institution. To be verified, the details provided by the third party must match the name, date of birth and address provided by an individual customer, or match two trade lines within the credit file. If any of the information does not match, the individual will need to use another method to prove their identity.
Dual Process Identity Verification Method
This method involves referring to information from reliable and independent sources which can be submitted by the individual in original paper form or an un-altered electronic form. As part of the account sign up process, customers are asked to upload to our site the original electronic or paper documents they received or downloaded. All documents must be valid and unaltered in order to be acceptable. If any information has been redacted, it is not acceptable. Such documents typically include, but are not limited to:
- Government issued photo identification
- Bank or credit card statement
- Utility bill
All files are submitted over encrypted channels and stored encrypted in our data centres or with third party data processors. Refer to our Security Policy and our Privacy Policy for more information on the procedures we employ to keep your data safe.
Identifying Corporations and Other Entities
Since some of our customers may be corporate entities, non-profits, or charities, we confirm the existence of the entity, and the entity's beneficial ownership.
Corporations
We confirm the existence of a corporation as well as the corporation's name and address by collecting and verifying the following information:
- Corporate Email address;
- Corporate phone number;
- Full Corporate legal name;
- Operating name;
- Government registration number;
- Business Address (not a mailing address or P.O. Box);
- Proof of existence (as outlined below);
- Confirmed identity of all beneficial owners (as outlined below);
- Additional information or documentation at the discretion of our Compliance team.
We use one or more of the following documents to verify the business information collected:
- Proof of existence:
- Certificate of Corporate Status (if incorporated within the previous 12 months); or
- Notice of registration (either provincial/state or federal); or
- A letter or a notice of assessment from a municipal, provincial, state, territorial or federal government; or
- Corporation’s published annual report signed by an independent audit firm; or
- Trade name registration (if applicable)
- Proof of corporate address (utility bill, bank statement or any government record)
- Completed business account information (including the nature of business and estimated transaction volumes)
- Completed beneficial ownership information and identity verification for all beneficial owners of the organization (i.e. any actual person who owns or controls, directly or indirectly, 25% or more of the corporation’s shares).
Partnerships, Cooperatives, Sole Proprietorships
We confirm the existence of an entity other than a corporation in the same way we do corporations however, supporting documentation that is deemed acceptable is different. Acceptable supporting documentation may include, but is not limited to:
- a partnership agreement; or
- articles of association; or
- sole proprietorship registration; or
- any other similar record that confirms the entity's existence.
In confirming an entity’s existence, we must be able to refer to a paper or electronic record and retain a copy of it. Verbal confirmation is not sufficient. Electronic records must be from a public source and we record the type and source and the entity’s registration number. In addition, we also require complete beneficial ownership information and identity verification for all beneficial owners of the organization (i.e. any actual person who owns or controls, directly or indirectly, 25% or more of the entity's shares).
Not-for-profits and Charities
We confirm the existence of an entity other than a corporation in the same way we do corporations however, supporting documentation that is deemed acceptable for non-profits may differ. Acceptable supporting documentation may also include, but is not limited to:
- proof of charity or non-profit registration; or
- articles of association; or
- any other similar record that confirms the entity's existence.
If the entity is a not-for-profit organization, we also:
- Determine whether or not the entity is a registered charity for income tax purposes
- If that entity is not a registered charity, determine whether or not it solicits charitable financial donations from the public
- Obtain completed beneficial ownership information and identity verification for all beneficial owners of the organization (i.e. any actual person who owns or controls, directly or indirectly, 25% or more of the entity's shares or is a director of the non-profit).
Beneficial Ownership Records
In addition to confirming the existence of a corporation or other entity, we also determine and confirm the accuracy of the entity's beneficial ownership through the following:
If the entity is a corporation:
- The name and occupation of all directors and officers of the corporation; and
- The name, address and occupation of all individuals who directly or indirectly own or control 25% or more of the shares of the corporation.
If the entity is other than a corporation:
- The name, address and occupation of all individuals who directly or indirectly own or control 25% or more of the entity.
Keeping Client Identification Information Updated
Bidali customers who present an elevated risk have their identification information updated at least every two years, or sooner depending on our risk evaluation. Customers who present an elevated risk include (but are not limited to) Politically Exposed Persons ("PEPs") or individuals from certain countries we operate in. This is done by reviewing original identity or entity documents and recording the updated identification or information details for our files as appropriate.
Record Keeping
We keep records of the identification information we collect, the results of our verification and screening, customer transactions, and the monitoring, escalation and decisions described in this policy. These records are kept for at least five (5) years after the end of the business relationship, or longer where the law requires. See our Privacy Policy and Account Deletion Policy for how this affects requests to delete your data.
Sanctions Screening
We screen customers and, for entities, their beneficial owners against the sanctions and terrorist lists that apply in Canada, and against other lists we consider relevant to the markets we serve, such as those of the United States, the United Kingdom, the European Union and the United Nations. We also do not provide our Services in the countries listed in our Restricted Use Policy.
If we know or believe that a customer, or property involved in a transaction, is owned or controlled by or on behalf of a sanctioned person, a listed person or a terrorist group, we will refuse or stop the activity, freeze property where the law requires us to, and report it to the appropriate authorities where the law requires us to.
Suspicious Activity
If in the course of reviewing and monitoring, we identify unexplainable or unusual patterns or activity, or have reasonable grounds to suspect that a transaction or attempted transaction relates to fraud, money laundering, terrorist financing, sanctions evasion or other crime, we will work to obtain further information so that questions surrounding the activity are satisfactorily answered. The activity is escalated internally to our Compliance Officer, who keeps a record of every internal escalation and the decision taken.
We may delay, refuse or reverse a transaction, and suspend or close an account, while we review the activity or as a result of it. If Bidali cannot reach a clear understanding of the customer's identity, or the sources and movement of funds, it may result in their account being permanently closed. This will be followed by terminating the business relationship and blacklisting the account owner to prevent them from re-opening a new account.
Bidali cooperates with law enforcement and regulatory authorities, responds to valid legal requests, and makes reports to the appropriate authorities where the law requires.
Program Reviews
Internally our Compliance Officer is responsible for reviewing the Compliance Program at least annually and presenting the results to the CEO and the Bidali Board of Directors. The Compliance Program is updated on a regular basis as we develop new products and technologies and as laws and guidance evolve.
An independent review of the Compliance Program will occur a minimum of once every two years, performed by a qualified reviewer. The review will assess Bidali's internal controls, transactional systems and procedures. The findings from such review are sent directly to the CEO and Board of Directors.
Training
All Bidali employees and officers receive ongoing broad-based compliance training, as well as position-specific training. They must repeat this training at least once every twelve (12) months to ensure they are knowledgeable about our Compliance Program and pertinent laws. New employees receive training within thirty (30) days of their start date. All documentation related to compliance training including: materials, tests, results, attendance and date of completion are maintained. In addition, our compliance training program is updated as necessary to reflect current laws and guidance.
If you have any questions or concerns feel free to contact compliance@bidali.com.