Purpose

Represent Bitkaya’s approved Employee Handbook as the BCMS policy object governing employee conduct, ethics, anti-bribery, whistleblowing, training and disciplinary standards for all personnel.

Policy Statement

Bitkaya requires all employees, officers, directors, contractors, consultants, agents and third parties acting on behalf of the company to act with integrity, fairness and accountability in the delivery of virtual asset services. This handbook defines the behavioural, ethical and compliance expectations that every employee must follow.

Scope

This policy applies to all employees, officers, directors, contractors, consultants, agents, joint ventures, and any third parties acting on behalf of Bitkaya, regardless of their location.

1. Introduction

At Bitkaya, our people are at the heart of everything we do. We operate in the digital asset industry, which is fast-moving, innovative, and highly regulated. To succeed in this environment, we must always act with integrity, responsibility, and accountability.

This handbook is here to:

  • Explain how we are expected to behave at work and when representing the company.
  • Show our commitment to clients, regulators, and each other.
  • Provide clear policies on anti-bribery, whistleblowing, and ethics that apply to everyone.

By following this handbook, you help keep Bitkaya a trusted and respected company in the global digital asset market.

2. Employee Responsibilities

At Bitkaya, every employee plays an important role in keeping the company ethical, compliant, and safe. These responsibilities are not optional, they are part of your job and help protect our clients, the company, and the integrity of the financial system.

2.1 Read and Understand Policies

  • Every employee is expected to read this handbook carefully and stay up to date with company policies.
  • Policies may be updated when regulations change; employees will be notified and must review updates promptly.
  • If anything is unclear, it is your responsibility to ask your manager, HR, or Compliance for clarification.

2.2 Complete Training

  • Mandatory training includes: Anti-Money Laundering/Counter-Terrorist Financing (AML/CFT), Anti-Bribery and Corruption (ABC), Cybersecurity Awareness, and Code of Ethics.
  • Training ensures you recognize risks such as fraud, insider trading, or cyber threats.
  • All employees must complete training on time and refresh it annually or as required.

2.3 Act Honestly

  • Always act in good faith, fairly, and transparently, both inside and outside the company.
  • Do not engage in deceptive practices, misuse company resources, or misrepresent facts.
  • Remember that you represent Bitkaya in all professional interactions, including with clients, partners, regulators, and the public.

2.4 Protect Assets and Data

  • Client money and digital assets must be handled with the highest level of care.
  • Never use client funds for company operations or personal benefit.
  • Safeguard sensitive information by following data security protocols, encryption rules, and access controls.
  • Immediately report any loss, theft, or breach involving assets or data.

2.5 Speak Up

  • If you see or suspect misconduct, such as fraud, bribery, insider trading, or unsafe practices, you must report it through the Whistleblower Policy.
  • You are protected from retaliation when raising concerns in good faith.
  • Speaking up ensures issues are addressed before they become bigger problems.

2.6 Avoid Conflicts of Interest

  • Do not let personal, financial, or outside business interests interfere with your role at Bitkaya.
  • Examples of conflicts include:
    • Trading digital assets using inside knowledge.
    • Having a financial interest in a supplier, vendor, or competitor.
    • Accepting gifts or favors that could influence decisions.
  • If a conflict arises, you must disclose it immediately to Compliance or HR for proper management.

2.7 Support Reviews and Audits

  • Regulators, auditors, and internal teams regularly review how Bitkaya operates.
  • Employees must cooperate fully, providing accurate and complete information when requested.
  • Attempts to withhold, alter, or falsify information will be treated as serious misconduct.
  • These reviews help the company stay compliant, improve processes, and strengthen trust.

3. Consequences of Not Following the Rules

Following this handbook is mandatory, not optional. These rules are in place to protect our clients, our reputation, and our ability to operate as a licensed Virtual Asset Service Provider (VASP). When an employee fails to follow them, it puts not only Bitkaya at risk, but also clients and the integrity of the wider market.

3.1 Types of Violations

a) Minor Mistakes

  • Examples: missing a training deadline, forgetting to update a compliance form, or minor administrative oversights.
  • Consequences: may result in verbal or written warnings, mandatory retraining, or closer supervision. These are handled as opportunities for learning and improvement but will still be documented.

b) Serious Violations

  • Examples: failing to follow AML/CFT procedures, ignoring cybersecurity protocols, mishandling confidential client data, or failing to disclose conflicts of interest.
  • Consequences: may lead to formal disciplinary action, including suspension, demotion, reassignment, or termination of employment. Such cases may also be reported to regulators, depending on severity.

c) Gross Misconduct

  • Examples: insider trading, fraud, bribery, market manipulation, theft, or misusing client funds.
  • Consequences: gross misconduct will almost always result in immediate dismissal. In addition, individuals may face criminal prosecution, civil penalties, or regulatory enforcement actions. Bitkaya will cooperate fully with law enforcement and regulators in such cases.

3.2 Accountability

  • Personal Liability: Employees can be held personally responsible under law for certain actions (such as insider trading, bribery, or AML/CFT violations). Penalties may include fines, bans from working in financial services, or imprisonment.
  • Company Liability: Bitkaya itself may face heavy fines, sanctions, reputational damage, and even loss of its licenses if employees fail to comply with laws and policies.

3.3 Why It Matters

These consequences are not about punishment, they are about protecting clients, the company, and the integrity of the digital asset market. By following this handbook, employees help ensure that Bitkaya remains a safe, ethical, and fully compliant VASP, trusted by clients and regulators alike.

4. Commitment from Leadership

At Bitkaya, our leaders set the tone for the entire organization. The Board of Directors, Executive Management, and Senior Leaders are responsible not only for guiding the company strategy, but also for ensuring that our culture is built on integrity, accountability, and trust. Leadership recognizes that employees look to them as role models, and therefore their actions must reflect the same standards that all staff are required to follow.

4.1 Leadership Commitments

  • Integrity and Accountability: All decisions made by leadership must be fair, ethical, and transparent. Leaders are accountable for both their own actions and for creating an environment where compliance is a priority.
  • Providing Resources and Training: Leaders will ensure that employees have the tools, knowledge, and training necessary to meet legal, regulatory, and ethical expectations. This includes access to compliance guidance, ongoing professional development, and systems to support proper decision-making.
  • Supporting a Speak-Up Culture: Leaders actively encourage employees to raise questions or concerns without fear of retaliation. By supporting the Whistleblower Policy, leadership ensures that problems are addressed quickly and fairly.
  • Maintaining Compliance and Ethical Standards: Leaders are responsible for ensuring that Bitkaya consistently meets all regulatory requirements, international standards, and ethical obligations, and that compliance is embedded in day-to-day operations.

4.2 Equal Accountability

Leadership is bound by the same rules as every other employee. If a senior leader violates company policy, they will be subject to the same disciplinary procedures and regulatory reporting obligations as any other staff member.

5. Anti-Bribery and Corruption (ABC) Policy

5.1 Why It Matters

Bribery and corruption damage trust, harm markets, and are illegal. Bitkaya maintains a zero-tolerance approach to bribery and corruption. All forms of bribery, whether direct or indirect, are strictly prohibited. Employees and associated persons must not offer, give, solicit, or accept bribes or improper inducements.

5.2 Definitions

  • Bribery: Offering, giving, receiving, or soliciting anything of value to influence a decision or action improperly.
  • Corruption: Abuse of entrusted power for private gain.
  • Facilitation Payments: Small payments made to expedite routine governmental actions. Bitkaya prohibits such payments.

5.3 Gifts and Hospitality

Employees must not offer or accept gifts or hospitality that could influence, or appear to influence, business decisions. All gifts and hospitality must be:

  • Of nominal value
  • Infrequent
  • Transparent
  • Not intended to secure an improper advantage

5.4 Political and Charitable Contributions

Bitkaya does not make political contributions. Charitable donations must be legal, ethical, and not used to conceal bribery.

5.5 Due Diligence

Prior to engaging with third parties, Bitkaya will conduct due diligence to assess the risk of bribery and corruption. This includes evaluating the third party reputation, ownership, and compliance history.

5.6 Financial Record-Keeping

Accurate and complete records of all transactions must be maintained. No accounts may be kept off-book to facilitate or conceal improper payments, nor may they be falsified.

5.7 Disciplinary Action

Violations of this policy may result in disciplinary action, up to and including termination of employment, and may also lead to legal proceedings.

5.8 Your Role

  • Always complete ABC training.
  • Report suspected bribery immediately.
  • Remember: breaking this policy can lead to dismissal and even criminal prosecution.

6. Whistleblower Policy and Reporting

6.1 Why It Matters

Sometimes you may see or suspect misconduct. Speaking up protects the company, clients, and our reputation.

6.2 Scope

This policy applies to all employees, officers, directors, contractors, consultants, suppliers, and any third parties engaged with Bitkaya, across all locations and jurisdictions in which the company operates.

6.3 Reportable Conduct

Individuals are encouraged to report any conduct that they reasonably believe constitutes:

  • Fraud, corruption, or financial misconduct
  • Violation of laws or regulations
  • Unethical behavior or breaches of company policies
  • Health and safety violations
  • Environmental damage
  • Harassment, discrimination, or bullying
  • Any other conduct that may cause financial or reputational harm to the company

Personal work-related grievances that do not have broader implications for the company are not covered under this policy and should be addressed through the appropriate grievance procedures.

6.4 Reporting Channels

Reports can be made through the following channels:

  • Internal Reporting:
    • Operational Manager
    • Human Resources Manager
    • Board of Directors
  • External Reporting:
    • If internal reporting is not feasible or appropriate, reports can be made to the Centrale Bank of Curacao and St. Maarten (CBCS).

Reports can be submitted anonymously; however, providing contact information may facilitate a more thorough investigation.

6.5 Protection Against Retaliation

Bitkaya strictly prohibits retaliation against any individual who, in good faith, reports a concern or participates in an investigation under this policy. Retaliation includes, but is not limited to, dismissal, demotion, harassment, or any adverse employment action. Any act of retaliation will result in disciplinary action, up to and including termination.

6.6 Confidentiality

All reports and investigations will be handled confidentially to the extent possible, consistent with the need to conduct an adequate investigation and comply with legal obligations. The identity of the whistleblower will be protected unless disclosure is required by law.

6.7 Investigation Process

Upon receiving a report, the receiving officer will:

  1. Acknowledge receipt of the report within 5 business days.
  2. Conduct a preliminary assessment to determine the appropriate course of action.
  3. Initiate a formal investigation if warranted, ensuring impartiality and fairness.
  4. Maintain records of the investigation process and findings.
  5. Communicate the outcome to the whistleblower, if contact information is provided, and to relevant stakeholders as appropriate.

6.8 False or Malicious Reports

Reports made in bad faith, or with the knowledge that the allegations are false, are not protected under this policy and may result in disciplinary action.

7. Code of Ethics

7.1 Why It Matters

Our reputation depends on how we behave. The Code of Ethics ensures that we all act consistently and uphold trust.

7.2 Key Principles

  • Integrity: Always be honest and fair.
  • Compliance: Follow all laws, regulations, and company rules.
  • Client First: Protect client assets and always put their interests before personal or company gain.
  • Conflicts of Interest: Disclose anything that could affect your impartiality.
  • Confidentiality: Keep client and company information secure.
  • Professionalism: Treat everyone with respect and represent Bitkaya responsibly.

7.3 In Practice for a VASP

  • AML/CFT: Always follow anti-money laundering and counter-terrorist financing requirements.
  • Market Integrity: Never misuse inside information or manipulate markets.
  • Technology Ethics: Use systems responsibly and report cybersecurity risks immediately.
  • Global Standards: Follow international codes, like the Global Digital Finance (GDF) Code of Conduct.

7.4 Enforcement

Everyone must certify compliance with the Code annually. Breaches can result in disciplinary action, termination, and regulatory reporting.

8. Proportionality Implementation

At Bitkaya, proportionality ensures that our policies, controls, and procedures are practical, effective, and aligned with the scale and complexity of our operations. As a small Virtual Asset Service Provider (VASP) startup, we apply a risk-based approach that balances regulatory compliance with operational feasibility, meeting all legal obligations while avoiding unnecessary burdens.

8.1 Why Proportionality Matters

Proportionality recognizes that not all companies face the same level of risk. Our internal systems are designed to reflect the size of our team, the nature of our products, our client base, and the volume of our transactions. This approach helps us remain both compliant and agile as we grow.

8.2 How Bitkaya Applies Proportionality

Bitkaya policies, including those on AML/CFT, cybersecurity, data protection, and business continuity, are implemented according to the principle of proportionality. This means:

  • Right-Sized Controls: We apply compliance measures that are suitable for a small company but scalable for growth. For example, a single Compliance Officer may oversee multiple control areas, supported by automated systems and external advisors.
  • Scalable Frameworks: Policies and processes are reviewed periodically to ensure they evolve with business expansion, technological changes, or new regulatory requirements.
  • Practical Resource Allocation: Responsibilities are clearly defined so that compliance and risk management remain achievable within available resources while maintaining accountability at all levels.
  • Technology Leverage: Automated tools and cloud-based systems are used to ensure consistency, reduce manual errors, and maintain efficient oversight without excessive cost.

8.3 Proportionality in Practice

  1. Compliance and Risk Management
    • Policies are applied in a risk-based and proportionate way. For lower-risk activities or customers, simplified procedures may be used (e.g., reduced KYC documentation where allowed by law).
    • Higher-risk situations trigger enhanced due diligence, additional verification, or management review.
    • Compliance monitoring is ongoing but adjusted to the company transaction volume and risk profile.
  2. Employee Training and Awareness
    • All employees receive AML/CFT, ethics, and cybersecurity training that fits their role and risk exposure.
    • Training content and frequency are proportional to each employee responsibilities and updated as the company grows.
  3. Governance and Oversight
    • The Board and management ensure proportional oversight by focusing on key risk areas that reflect Bitkaya current business model.
    • Reporting lines are clear and scalable, allowing for more structured committees or departments as the company expands.
  4. Business Continuity
    • Continuity and contingency plans are designed to fit Bitkaya operational scale but are flexible to expand as operations become more complex.
    • Critical dependencies such as cloud infrastructure, communication channels, and data backups are maintained at levels appropriate to the company size and risk exposure.

8.4 Proportionality and Scalability for a Growing VASP

Bitkaya proportionality model is scalable, meaning controls will strengthen and diversify as the company grows, adds new products, or expands into new markets. Regular reviews will ensure that our governance, risk management, and compliance frameworks remain appropriate to our business model and regulatory expectations. This approach ensures:

  • Efficient use of resources in early stages;
  • Full compliance with Curacao Landsverordening toezicht virtuele activa dienstverleners (Virtual Asset Service Providers Supervision Act); and
  • Readiness for future supervisory expectations under the Central Bank of Curacao and Sint Maarten (CBCS).

8.5 Employee Role

Every Bitkaya employee has a role in maintaining proportional compliance. This includes:

  • Following procedures relevant to your job function;
  • Reporting risks or inefficiencies to your manager or Compliance Officer;
  • Adapting to changes as the company grows and policies evolve.

By understanding and applying proportionality, every employee contributes to an efficient, compliant, and sustainable company culture, one that meets regulatory expectations while remaining practical for a growing VASP.

9. Conclusion

This handbook reflects Bitkaya ongoing commitment to integrity, compliance, and responsible innovation. It is more than just a set of rules, it is a guide to how we work together to protect our clients, our company, and the broader digital asset ecosystem. Every employee, from new hires to senior leadership, has an essential role to play in ensuring Bitkaya remains safe, ethical, and trusted. By following these policies, you help us to:

  • Protect our Clients: Safeguard their assets, data, and interests at all times.
  • Maintain our Licenses: Ensure we meet all legal, regulatory, and supervisory requirements in every jurisdiction we operate.
  • Uphold our Reputation: Build and maintain trust with clients, partners, regulators, and the global financial community.

Bitkaya strength lies in its people. Together, we can build a company that not only delivers innovation but does so responsibly, thriving on trust, accountability, and integrity.

This handbook should serve as your daily reference point. When in doubt, ask yourself:

  • Is this action honest and fair?
  • Does it protect clients and the company?
  • Would I be comfortable if this decision were reviewed by a regulator or made public?

If the answer is yes, you are likely on the right path. If you are unsure, seek guidance from your manager, HR, or Compliance before acting.

Together, we will continue to shape Bitkaya into a leader in the digital asset industry, trusted by clients, respected by regulators, and driven by innovation with integrity.

10. Appendix: Employee Handbook Acknowledgment Form

I, _______________________________ (employee name), acknowledge that I have received and read the Bitkaya Employee Handbook.

I understand that this handbook contains important information about:

  • My responsibilities as an employee of Bitkaya.
  • The company Anti-Bribery and Corruption (ABC) Policy.
  • The Whistleblower Policy and Reporting process.
  • The Code of Ethics that governs behavior at Bitkaya.

By signing this form, I confirm that:

  1. I have read and understood the contents of the handbook.
  2. I agree to follow the rules, standards, and principles described in it.
  3. I understand that failure to follow these policies may result in disciplinary action, up to and including termination, and may be reportable to regulators or law enforcement.
  4. I understand that this handbook does not create an employment contract but provides guidance on company policies and expectations.

If I have questions about any part of the handbook, I know I can reach out to the Compliance Department, HR, or my manager for clarification.

  • Employee Name: ______________________________________
  • Employee Signature: __________________________________
  • Date: ______________________________________________
  • Manager/Supervisor Signature: _________________________

11. Appendix: Bitkaya Quick Reference Guide

(Dos and Donts for All Employees)

Core Principles

  • Act with integrity, fairness, and transparency.
  • Put clients interests first.
  • Follow all laws, regulations, and company policies.
  • Safeguard assets, data, and confidential information.
  • Take personal accountability for decisions and actions.

Dos

  • Read and Understand Policies: Stay updated on rules and ask if unsure.
  • Complete Training: AML/CFT, Anti-Bribery and Corruption, Cybersecurity, Ethics.
  • Act Honestly: Always make decisions in good faith.
  • Protect Assets: Keep client funds separate and secure.
  • Speak Up: Report misconduct, fraud, or risks immediately.
  • Disclose Conflicts: Be transparent if personal interests may affect work.
  • Support Reviews and Audits: Cooperate fully with Compliance, Risk, or regulators.

Donts

  • Do not offer or accept bribes, kickbacks, or facilitation payments.
  • Do not engage in market abuse (insider trading, manipulation, front-running).
  • Do not misuse client funds, data, or confidential company information.
  • Do not retaliate against colleagues who raise concerns in good faith.
  • Do not bypass AML/CFT checks or ignore suspicious activity.
  • Do not post unauthorized statements about Bitkaya on social media.
  • Do not engage in business in jurisdictions without proper licenses.

Key Contacts

  • Compliance Department: compliance@bitkaya.io
  • Manager/Supervisor: First point of contact for general queries.

Remember: Following these rules is not optional. Violations can result in warnings, termination, regulatory reporting, or even criminal liability. When in doubt, ASK before acting.

Operating Layer

This policy is implemented through PRC-RSA-001 Resilience Systems and Assurance and the linked PROC-EMP-* procedures and CTRL-EMP-* controls.

It is subordinate to POL-ECM-001 Enterprise Compliance Manual and coordinates with the AML, ABC, market conduct, IT and business continuity frameworks where the handbook assigns employee responsibilities.

Implementing Procedures and Controls

Procedures

Controls

Source Document

  • Document title: Employee Handbook
  • Version: 1.0
  • Status in source document: FINAL
  • Date shown in source document: October 2025
  • Approver shown in change log: Board
  • Exact BCMS approval and effective date: 2026-04-21, taken from the approved PDF metadata because the visible document states only October 2025
  • Permanent approved artifact: Bitkaya Employee Handbook v10 Approved.pdf
  • Note: the handbook is an internal policy artifact and is not registered as a regulatory source.

Assurance

  • Design status: implemented from approved Employee Handbook version 1.0
  • Operating assurance: pending system-derived assessment
  • Evidence status: expected evidence is defined in the implementing controls
  • Review cadence: annual and after material legal, regulatory, organizational, conduct or assurance change
  • Overall status: implemented design; operating-effectiveness testing pending

History

  • 2026-07-28: Enriched to 100% PDF coverage, every section and paragraph of the approved Employee Handbook version 1.0 now represented in the policy body.
  • 2026-07-26: Aligned assurance wording with the system-derived Hermes/Odoo result model.
  • 2026-07-26: Registered the approved Employee Handbook and established its operating process, procedures and controls.