KYC Policy

KNOW YOUR CUSTOMER (KYC) POLICY

Novellis.io

Document Type: Know Your Customer (KYC) Policy
Version: 1.0
Effective Date: January 1, 2026
Responsible Department: Compliance
Review Cycle: Regular review and updating

 

1. Purpose and Objectives

The Know Your Customer (KYC) Policy of Novellis.io defines the principles and procedures for identifying and verifying our customers.

KYC verification is an essential component of our compliance and security framework. It is designed to reliably establish the identity of our customers, prevent misuse of our services, and identify financial risks at an early stage.

Our KYC measures specifically support the prevention of:

  • Identity misuse and identity theft;

  • Fraud and other abusive activities;

  • Money laundering;

  • Terrorist financing;

  • Unauthorized payments;

  • Misuse of customer or payment accounts.

Novellis.io follows a risk-based approach. The nature and scope of verification may therefore vary depending on the individual customer, transaction, and associated risk.

 

2. Customer Verification Principle

Novellis.io aims to ensure that every customer account can be clearly assigned to an identifiable individual or appropriately verified customer.

For this purpose, Novellis.io may request appropriate information and documentation before or during the business relationship.

Verification may be required in particular:

  • When opening a customer account;

  • Before certain financial transactions;

  • Before processing a withdrawal request;

  • When relevant customer information changes;

  • In the event of unusual or high-risk activities;

  • Where required by applicable laws or internal compliance requirements.

The use of certain account or payment functions may be made conditional upon successful completion of the required verification.

 

3. Risk-Based KYC Approach

Our KYC procedures are based on a risk-based approach.

Not every customer or transaction presents the same level of risk. Therefore, different levels of verification may apply.

The assessment may take into consideration, among other things:

  • Customer identity and profile;

  • Country of residence and/or origin;

  • Payment instruments used;

  • Transaction amounts and frequency;

  • Previous transaction behavior;

  • Potential sanctions or PEP-related concerns;

  • Unusual account activity;

  • Source of funds;

  • Other relevant compliance factors.

Where a higher level of risk is identified, Enhanced Due Diligence (EDD) may be conducted.

 

4. Standard KYC Verification

As part of the standard customer verification process, Novellis.io may request the following documents.

4.1 Proof of Identity

Accepted documents may include, in particular:

  • Valid passport;

  • Valid national identity card;

  • Driver’s license or comparable government-issued identification document.

The document should generally:

  • Be valid;

  • Be complete and clearly legible;

  • Clearly establish the customer’s identity;

  • Match the information provided in the customer account.

Where necessary, an additional identity verification may be required.

4.2 Proof of Residential Address

To verify the stated residential address, Novellis.io may request an appropriate proof of address.

Examples may include:

  • Electricity, gas, or water bill;

  • Bank or credit card statement;

  • Government-issued correspondence;

  • Tax document;

  • Other official proof of residential address.

The document should generally contain the customer’s full name, full address, and a verifiable date of issue.

Depending on the customer’s risk profile or country of origin, additional requirements may apply.

4.3 Verification of Payment Instrument

Where necessary to verify a payment or prevent payment fraud, Novellis.io may request appropriate evidence relating to the payment instrument used.

For payment cards, for example, the last four digits of the card number may remain visible for identification purposes.

CVV/CVC security codes and other unnecessary sensitive payment information must not be disclosed.

Novellis.io may request alternative evidence depending on the payment provider or payment method used.

 

5. Additional Verification Requirements

In certain circumstances, standard KYC verification may not be sufficient.

Novellis.io may therefore request additional information or documentation, including:

  • Additional identity documents;

  • Additional proof of address;

  • Information regarding the customer’s financial background;

  • Evidence of the source of funds;

  • Evidence of the source of wealth;

  • Information regarding the purpose of specific transactions;

  • Additional information concerning payment instruments used.

The specific requirements will depend on the circumstances of the individual case and the applicable risk assessment.

 

6. Enhanced Due Diligence (EDD)

For customers or transactions presenting an increased level of risk, Novellis.io may conduct Enhanced Due Diligence (EDD).

Enhanced verification may be required, for example, where:

  • Unusually high transaction volumes are identified;

  • Transactions significantly differ from the customer’s previous activity;

  • The source of funds cannot be adequately established;

  • Increased geographical risk is identified;

  • A potential PEP or sanctions-related concern is identified;

  • There are indications of fraud or identity misuse;

  • Other relevant compliance risks are identified.

As part of EDD, additional evidence and information may be requested.

 

7. Source of Funds

Where appropriate risk indicators exist, Novellis.io may request evidence concerning the source of funds used for a transaction.

Possible evidence may include:

  • Bank statements;

  • Salary or income documentation;

  • Tax records;

  • Sale or purchase documentation;

  • Loan documentation;

  • Corporate or business records;

  • Other appropriate supporting documentation.

The evidence requested must be sufficient to reasonably establish and document the origin of the relevant funds.

 

8. PEP and Sanctions Screening

As part of our compliance procedures, customer information may be screened against relevant sanctions lists and other legally permissible compliance data sources.

Customers may also be screened for potential Politically Exposed Person (PEP) status.

A potential match does not automatically constitute a violation or result in rejection. However, it may require additional review and, where appropriate, enhanced due diligence measures.

 

9. Ongoing Monitoring and Review

KYC verification does not necessarily end with the initial verification process.

Novellis.io may periodically or event-driven review customer information and verification records throughout the business relationship.

Re-verification may be required, for example, where:

  • Personal information changes;

  • Documents expire;

  • Significant changes occur in transaction behavior;

  • Additional risks are identified;

  • Existing information is no longer current or sufficient;

  • Legal or compliance requirements require renewed verification.

Customers are responsible for keeping relevant information accurate and up to date.

 

10. Withdrawals and KYC Verification

For the protection of customers and to prevent fraud, withdrawal requests may be subject to successful completion of KYC verification.

If a required verification has not yet been completed, the processing of a withdrawal may be placed on hold until the verification process has been completed.

In such cases, the customer may be informed of the required next steps and, where applicable, any outstanding documentation.

A transaction may also be subject to additional review where discrepancies are identified between customer, payment, and verification information.

 

11. Document Review

Submitted documents may be reviewed for plausibility, completeness, authenticity, and consistency with the information held in the customer’s account.

Documents may be rejected in particular where they:

  • Are illegible;

  • Are incomplete;

  • Have expired;

  • Do not match the customer’s stated information;

  • Appear to have been altered or manipulated;

  • Are otherwise insufficient for verification purposes.

In such cases, Novellis.io may request a new or alternative document.

 

12. Submission of KYC Documents

KYC documents should only be submitted through a verification channel provided by Novellis.io and designated for the relevant verification process.

Where submission by email is expressly requested or offered, documents must be provided in a clear and readable format.

Generally accepted file formats may include:

  • PDF;

  • JPEG/JPG;

  • PNG.

Documents should be:

  • Complete;

  • Clear and legible;

  • Not unnecessarily compressed;

  • Current;

  • Free from avoidable damage or distortion.

Sensitive security information, including CVV/CVC codes, must not be submitted.

Novellis.io may specify additional technical requirements depending on the verification procedure.

 

13. Protection of Personal Data

The protection of personal data is an essential component of our KYC process.

Information collected as part of the verification process will be processed in accordance with applicable data protection laws and only to the extent necessary for legitimate business, legal, regulatory, or compliance purposes.

We implement appropriate technical and organizational security measures designed to protect customer information against unauthorized access, loss, alteration, or unauthorized disclosure.

Access to KYC information is generally restricted to individuals and service providers who require such information to perform their respective duties.

Further information regarding the processing of personal data is provided in our Privacy Policy.

 

14. Retention of KYC Records

KYC data and verification records may be retained in accordance with applicable legal and regulatory requirements.

Such records may include, in particular:

  • Identification information;

  • Submitted documents;

  • Verification results;

  • Risk assessments;

  • Communications relating to KYC procedures;

  • Relevant transaction and compliance information.

After the applicable retention periods have expired, information will be deleted or otherwise handled appropriately in accordance with applicable legal requirements, unless another legal basis requires or permits continued retention.

 

15. Rejection or Restriction of Account Activities

Novellis.io may restrict certain account or payment activities where required verification cannot be completed or where relevant compliance risks are identified.

This may apply in particular where:

  • Required documents are not provided;

  • Information provided is inconsistent;

  • The customer’s identity cannot be sufficiently established;

  • Documents cannot be adequately verified;

  • A relevant fraud or compliance risk is identified;

  • The use of a particular payment method cannot be sufficiently verified or explained.

Measures will generally be taken based on the circumstances of the individual case and the identified level of risk.

 

16. False or Manipulated Information

The submission of false, forged, manipulated, or deliberately misleading information is prohibited.

Where indications of manipulated documents or false information are identified, Novellis.io may expand the verification process and take appropriate measures.

Depending on the circumstances, such measures may include:

  • Additional verification procedures;

  • Temporary restriction of certain account functions;

  • Rejection of individual transactions;

  • Restriction or termination of the business relationship;

  • Disclosure of relevant information to competent authorities where legally required or permitted.

 

17. Customer Responsibilities

Each customer is responsible for ensuring that the information maintained in their customer account is accurate, complete, and up to date.

Customers must, in particular:

  • Provide truthful information;

  • Provide valid documentation;

  • Notify Novellis.io of relevant changes to personal information;

  • Use only their own or properly authorized payment instruments;

  • Provide requested KYC documentation within a reasonable period;

  • Not submit forged, falsified, or manipulated documents.

Successful initial verification does not release the customer from these ongoing obligations.

 

18. Confidentiality

KYC information will be treated confidentially and processed only in accordance with applicable legal and operational requirements.

In certain circumstances, Novellis.io may be legally required to disclose information to competent authorities, courts, payment service providers, or other authorized parties.

Where legally permitted, such disclosures will be limited to the information reasonably required for the relevant purpose.

 

19. Compliance and Fraud Prevention

The KYC procedures of Novellis.io form part of our broader compliance and security framework.

KYC checks may therefore be combined with additional control measures, including:

  • Anti-Money Laundering (AML) controls;

  • Transaction monitoring;

  • Fraud prevention;

  • Sanctions screening;

  • PEP screening;

  • Payment verification;

  • Risk assessments.

The purpose of these measures is to maintain the security of our platform and the integrity of our business relationships.

 

20. Updates to this KYC Policy

Novellis.io regularly reviews this KYC Policy and may update it where necessary.

Updates may be required due to, among other things:

  • Changes in applicable legal requirements;

  • Regulatory developments;

  • New fraud and security risks;

  • Changes to our business model;

  • New payment methods;

  • Changes to our internal compliance procedures.

The latest version of this KYC Policy will be made available on the Novellis.io website.

 

21. Contact

For questions regarding our KYC procedures or a requested verification, customers may contact our Support or Compliance Team.

Email: support@novellis.net

Novellis.io

KYC & Compliance Department