Anti-Money Laundering and Asset Freezing Policy
ARTICLE 1. COMPLIANCE COMMITMENT AND SCOPE
1.1. Pho Tue SoftWare And Technology Solutions Joint Stock Company (Công ty Cổ phần Giải pháp Công nghệ và Phần mềm Phổ Tuệ) (the "Company" / "HiTechCloud") is firmly committed to preventing its services from being exploited for money laundering (ML), terrorist financing (TF), proliferation financing of weapons of mass destruction, and violations of international sanctions.
1.2. This Policy applies to all operations, personnel, customers and business partners of the Company; it is an integral part of the Terms of Service and applies together with the Personal Data Protection Policy (PDPD).
ARTICLE 2. LEGAL BASIS
2.1. Vietnamese law:
- Anti-Money Laundering Law 2022 (Law No. 14/2022/QH15, effective 01/3/2023);
- Decree 19/2023/NĐ-CP guiding implementation of the Anti-Money Laundering Law;
- Circular 27/2025/TT-NHNN (Thông tư 27/2025/TT-NHNN) guiding the Anti-Money Laundering Law (effective 1 November 2025, replacing/updating Circular 09/2023/TT-NHNN); Decision 11/2023/QD-TTg (Quyết định 11/2023/QĐ-TTg) on the reporting threshold for large-value transactions;
- Anti-Terrorism Law 2013 (Luật số 28/2013/QH13);
- Decree 122/2021/NĐ-CP on administrative penalties in the monetary and banking sector;
- Penal Code 2015 (Article 324 on money laundering; Article 300 on terrorist financing).
2.2. International standards: the FATF 40 Recommendations and its guidance on virtual assets and VASPs; the OFAC SDN list (US Department of the Treasury); the EU Consolidated Sanctions List; the UN Security Council Consolidated List; and the BIS Entity List.
ARTICLE 3. CUSTOMER IDENTIFICATION AND VERIFICATION (KYC / CDD / EDD)
3.1. Customer due diligence requirements by risk level:
| Level | Customer type | Verification required | Review frequency |
|---|---|---|---|
| Low | Individuals, Vietnamese SMEs, basic services | National ID/passport + address | Every 3 years |
| Average | Enterprise; large recurring transactions | Identification documents + Business Registration + UBO | Annually |
| Cao | PEPs, high-risk countries, virtual assets, offshore | Enhanced due diligence (EDD) plus senior approval | Every 6 months |
| Very high | Unusual transactions or those on a blacklist | Refuse or report suspicious transactions (STR) | Immediately |
3.2. Beneficial ownership identification (UBO): identify the UBO as any individual who directly or indirectly owns or controls ≥ 25% of the capital or voting rights; establish and maintain an updated UBO list for corporate customers; verify UBO identity to the same standard required for individuals; where the UBO cannot be identified, apply enhanced due diligence (EDD) and consider filing a suspicious transaction report.
3.3. Politically Exposed Persons (PEP): customers are screened against PEP lists (World-Check, Refinitiv, or equivalent); PEPs, their family members, and related persons require senior management approval before the service is provided; PEP transactions are subject to enhanced monitoring for the entire duration of the customer relationship.
3.4. Electronic identity verification (eKYC) is mandatory from 15 June 2026, in line with Article 3 of the Terms of Service.
ARTICLE 4. TRANSACTION MONITORING, REPORTING, AND SANCTIONS SCREENING
4.1. Currency transaction reports (CTR): transactions with a value from 400,000,000 VND (four hundred million dong) upwards must be reported to the Anti-Money Laundering Department (State Bank of Vietnam) under Decision 11/2023/QD-TTg (Quyết định 11/2023/QĐ-TTg). The reporting deadline is 1 working day for an electronic report or 2 working days for a paper report from the date the transaction arises, under Article 37 of the Anti-Money Laundering Law 2022 (Luật Phòng, chống rửa tiền 2022).
4.2. Electronic funds transfer reporting: electronic funds transfers that reach the threshold under Circular 27/2025/TT-NHNN must be reported and must include complete information on the originator and beneficiary; international transfers of USD 1,000 or more must include complete sender/recipient information.
4.3. Suspicious transaction reports (STRs): the Company files an STR with the Anti-Money Laundering Department without delay whenever there are grounds for suspicion, including where: (a) a transaction has no clear economic rationale or is unusual against the customer's profile; (b) the customer refuses to provide verification information or provides false information; (c) the transaction involves a country or territory on the FATF high-risk list; (d) transactions are structured to stay below reporting thresholds (smurfing or structuring); (e) payment is made to a third party with no clear economic relationship.
4.4. Sanctions screening: customers and transactions are screened against the OFAC SDN list, the EU Consolidated List, the UN Security Council Consolidated List, the BIS Entity List and the lists of organizations and individuals linked to terrorism and terrorist financing published by the Ministry of Public Security of Vietnam — both before and during service provision. Transactions with listed parties are automatically blocked or refused, and reported immediately to the competent authority and asset freezing at the direction of the competent authority when a sanctioned party is identified.
ARTICLE 5. CUSTOMER AND PARTNER UNDERTAKINGS ON SANCTIONS AND ANTI-MONEY LAUNDERING
5.1. When establishing a transaction, entering into a contract, or concluding an agreement of equivalent effect ("Transaction") with HiTechCloud, the Customer/Partner (including its subsidiaries, affiliates, branches, and personnel) represents and warrants that, to the best of its knowledge, it has not and will not:
(a) Is a party on an embargo or sanctions list (as defined in clause 5.3);
(b) Entering into any transaction or taking any action that could result in becoming subject to an embargo or sanctions list;
(c) Carrying out transactions to conceal or evade, or intended to conceal or evade, or attempting to breach, any embargo or sanction;
(d) Directly or indirectly transacting for the benefit of a party on an embargo or sanctions list;
(e) Is or has been in violation of, or is under investigation in connection with, embargoes, sanctions or anti-money laundering rules.
5.2. The Customer/Partner confirms that no payment has been made by or on its behalf that results in: (a) a direct or indirect payment to a party on an embargo or sanctions list, or to a legal entity 50% or more owned (directly or indirectly) by such a party; or (b) funds being used, directly or indirectly, for the purpose of money laundering.
5.3. “Entities on embargo or sanctions lists” means an individual or organization that: (i) is listed on, or is owned or controlled by a party listed on, the embargo and sanctions lists of the United Nations Security Council or its Sanctions Committees, the lists of organizations and individuals linked to terrorism and terrorist financing published by the Ministry of Public Security of Vietnam, or the OFAC, EU or BIS lists; or (ii) is currently subject to embargo or sanctions.
ARTICLE 6. SERVICE REFUSAL, TERMINATION, AND ASSET FREEZING
6.1. HiTechCloud may refuse or terminate service in respect of: (a) individuals or organizations on the OFAC, EU or UN sanctions lists or on Vietnamese lists; (b) customers who refuse to cooperate with the KYC/CDD process; (c) services suspected of being used for money laundering or terrorist financing; (d) customers resident in a country or territory under Vietnamese embargo; and (e) services relating to virtual assets or cryptocurrency that do not comply with Vietnamese law.
6.2. If the Customer/Partner breaches any undertaking in Article 5, HiTechCloud is entitled, immediately and irrevocably, to: (a) terminate and cancel the Transaction without incurring any penalty or compensation; (b) demand full repayment of any amounts HiTechCloud has already paid or disbursed (if any); (c) claim compensation for the full amount of any damages (if any).
6.3. Asset freeze and transaction suspension: HiTechCloud freezes accounts and assets, and delays or suspends transactions, on the lawful order or request of a competent state authority, or where there are grounds to suspect a link to money laundering, terrorist financing or a sanctioned party, in accordance with the Anti-Money Laundering Law 2022 (Luật Phòng, chống rửa tiền 2022) and related legislation. Taking such measures does not constitute a breach of contract by HiTechCloud.
6.4. HiTechCloud may amend and supplement this Policy, giving the Customer/Partner written or email notice at least 15 days before the intended effective date.
ARTICLE 7. SANCTIONS FOR VIOLATIONS
7.1. Administrative violations: penalties under Decree 122/2021/NĐ-CP and related legislation.
7.2. Criminal offenses: money laundering under Article 324 of the Penal Code 2015 (Bộ luật Hình sự 2015); terrorist financing under Article 300 of the Penal Code 2015.
7.3. Breach of international sanctions: the party concerned may face enforcement action by foreign authorities (for example OFAC) and prosecution under the applicable law.
7.4. Damages: under the Civil Code 2015 and the contract terms.
This Policy is an integral part of the agreements/contracts between the Parties, takes effect from 1 July 2026 and supersedes all previous versions. The Vietnamese version has the highest legal validity.