Custody Policy
Version 1.0 - October 2024
1. Purpose, Scope and Applicability
The aim of this Custody Policy (“the Policy”) is to regulate the provision of custody and administration of crypto-assets on behalf of clients services (“the Custody Services”) by Zillion Bits Ltd. (“ZBX” or “the Company”).
The provisions of this Policy have been designed in a manner that ensures clear disclosure of the rights and responsibilities of ZBX and its clients as the effective protection of ZBX clients’ rights.
2. Register of Positions
ZBX shall keep a register of positions, opened in the name of each client, corresponding to each client’s rights to the crypto-assets.
Where relevant, ZBX shall record any movements following instructions from its clients as soon as possible in that register. Any other event likely to create or modify the rights of a client to crypto-assets shall also be immediately recorded in the clients’ register of positions.
3. Segregation of Client Crypto-Assets
ZBX shall segregate holdings of crypto-assets on behalf of its clients from its own holdings and ensure that the means of access to crypto-assets of its clients is clearly identified as such. ZBX shall also ensure that, on the distributed ledger, its clients’ crypto-assets are held separately from its own crypto-assets.
The crypto-assets held in custody shall be segregated from ZBX’s estate in the interest of its clients both operationally and legally, so that ZBX’s creditors have no recourse to crypto-assets held in custody by ZBX, in particular in the event of insolvency. Client funds shall never be converted to on-balance sheet assets of ZBX.
ZBX shall not outsource the custody and administration of crypto-assets on behalf of clients to third parties.
4. Reconciliation of Client Funds
ZBX shall reconcile, on a monthly basis, the amount of clients’ crypto-assets actually held by ZBX with its clients’ records.
If applicable, ZBX shall also reconcile, on a monthly basis, the balance on each client’s fiat funds account as recorded by ZBX with the balance as set out in the statement issued by the credit institution with whom ZBX has deposited clients’ fiat money in accordance with the applicable regulations.
Where ZBX discovers discrepancies after carrying out the above reconciliations, it will:
- immediately apply measures to remedy such discrepancies; and
- maintain a record of such discrepancies and the measures taken to remedy the differences.
5. Account Statements
ZBX shall provide its clients with a statement of position of the crypto-assets recorded in the name of those clients at least once every three months and at the request of the client concerned.
The statement of position shall be made in an electronic format and shall identify the crypto-assets concerned, their balance, their value and the transfer of crypto-assets made during the period concerned.
6. Fiat Funds
ZBX does not provide custody of customers’ fiat funds. Instead, the customers’ fiat funds shall be deposited with a credit institution duly licensed within the EU/EEA or jurisdictions with comparable standards of financial regulations.
The fiat funds shall be placed with a credit institution by the end of the business day following the day on which they were received and shall be held in an account separately identifiable from any accounts used to hold funds belonging to ZBX.
When selecting credit institutions to deposit clients’ fiat funds ZBX shall carry out a risk assessment while taking into account the following factors:
- regulatory status and authorisations obtained;
- jurisdiction of incorporation and related geographical risks;
- financial stability, credit and settlement risks;
- AML/CFT and prevention of financial crime compliance;
- operational resilience and information security;
- reputation and legal standing; and
- concentration and diversification risks, if applicable
Such assessments shall be kept up to date and reviewed at least annually.
7. Liability to Clients
ZBX shall minimise the risk of a loss of clients’ crypto-assets or the rights related to those crypto-assets or the means of access to the crypto-assets due to fraud, cyber threats or negligence.
ZBX shall only be liable to its clients for the loss of any crypto-assets or the means of access to the crypto-assets as a result of an incident that is fully attributable to ZBX. Unless otherwise prescribed by the applicable regulations, the liability of ZBX shall be capped at the market value of the crypto-assets that were lost, at the time the loss occurred.
Incidents not attributable to ZBX shall include any event that occurred independently of the provision of the relevant service, or independently of the operations of ZBX, such as but not limited to problems inherent in the operation of the distributed ledger that ZBX does not control.
Where applicable, ZBX shall facilitate the clients’ access to the rights attached to the crypto-assets. If requested by the client, ZBX shall return crypto-assets held on behalf of its clients, or the means of access, as soon as possible to those clients.
Where there are changes to the underlying distributed ledger technology or any other event likely to create or modify a client’s rights, the client shall be entitled to any crypto-assets or any rights newly created on the basis and to the extent of the client’s positions at the time of the occurrence of that change or event, except when the agreement signed between the client and ZBX prior to that change or event expressly provides otherwise.
ZBX shall provide its clients as soon as possible with any information about operations on crypto-assets that require a response from those clients.
8. Cybersecurity Considerations
ZBX shall implement a robust cybersecurity risk management framework to adequately protect all information assets and ICT assets, including custody technological solutions, from risks including unauthorised access or usage.
ZBX will implement the following key measures as part of its cybersecurity risk management framework:
- establish the risk tolerance for ICT risk;
- conduct regular ICT risk assessments to identify vulnerabilities and prioritize mitigation efforts;
- implement relevant multi-layered security measures, such as encryption, access controls, and intrusion detection systems;
- identify and manage key dependencies on third-party ICT service providers;
- perform testing of the ICT plans and measures, as well as the effectiveness of the controls implemented;
- ensure the continuity of critical and important functions, through business continuity plans and response and recovery measures; and
- provide ongoing ICT security awareness training to employees to minimize the risk of human error and unauthorized access.
Comments
0 comments
Article is closed for comments.