Custody policy - EEA
1. Introduction
System Pay Services (Malta) Limited (“BVNK EU”, “we”, “our” or “us”) is a company registered in Malta. We are authorised as a crypto-asset service provider (“CASP”) under the Markets in Crypto-Assets Act (Chapter 647 of the Laws of Malta) by the Malta Financial Services Authority (the “MFSA”) to provide the following crypto-asset services:
- providing custody and administration of crypto-assets on behalf of clients;
- exchange of crypto-assets for funds;
- exchange of crypto-assets for other crypto-assets;
- execution of orders for crypto-assets on behalf of clients; and
- providing transfer services for crypto-assets on behalf of clients.
We are responsible for the custody and administration of your assets where these are held or controlled by us and recorded in our internal records as held by us on your behalf, and until such time as they are transferred to you, or a relevant third party, at your request. In doing so, as a CASP authorised by the MFSA, we adhere to the specific obligations set out under the Markets in Crypto-Assets Regulation (EU) 2023/1114 (“MiCAR”) in relation to the safeguarding of client crypto-assets.
Our Custody Policy (the “Policy”) aims to provide an understanding of our:
- overall approach to the custody of our client’s crypto-assets including management, storage, access, and security across all our service models;
- overarching custody solution for crypto-assets; and
- procedures and controls to ensure the proper safekeeping of client’s crypto-assets, accountability, backup, recovery steps and reconciliation.
Our Custody Policy is designed to outline the high-level custody management principles in relation to crypto-assets which are held and/or controlled by us in respect of our clients.
2. General Principles
The General Principles governing our custody of crypto-assets are the following:
- Segregation: We hold, or arrange the holding of, client crypto-assets separate from our own assets, including (where applicable) in the records of any third-parties, and maintains ledger-level segregation between our own crypto-assets and client assets. We ensure that client crypto-assets are clearly identified as such in our internal records and in the records of any relevant third-parties. This ensures that our creditors do not have recourse to clients’ crypto-assets, particularly in the event of insolvency.
- Protection and Use: Crypto-assets held on behalf of our clients are safeguarded against unauthorised use, misappropriation, theft, or loss, and will not be used for third-party transactions, investments or proprietary trading.
- Right of Ownership: Clients retain full ownership rights over the crypto-assets held by us on their behalf, even when held in an omnibus wallet. We act solely as your custodian and do not acquire any proprietary interest in the crypto-assets we safeguard on your behalf.
- Sub-Custody: We may engage authorised sub-custodians to hold or safeguard client assets. We however will remain responsible for ensuring the safekeeping of your crypto-assets and will ensure that such arrangements are subject to rigorous due diligence and oversight in accordance with applicable law.
- Liability: We are liable for the loss of clients’ crypto-assets resulting from incidents attributable to us, even when those crypto-assets are held at an approved sub-custodian. Where we are liable, our liability is capped at the market value of the crypto-asset at the point in time the loss occurred. Incidents not attributable to us include any event that occurred independently of the services or operations provided by us.
These principles apply whether we provide our conversion services in an agency capacity (executing orders at third-party venues) or in a principal capacity (as direct counterparty).
3. Classification of Custodied Assets
We classify crypto-assets based on their operational status and the nature of control exercised over them to ensure accurate safeguarding and record-keeping:
- Custodied Crypto-Assets: These are crypto-assets held in BVNK-hosted wallets or with an approved sub-custodian. These assets are protected under our custody framework and are reflected in your balance as being under custody.
- In-Flight Crypto-Assets: These are crypto-assets that are temporarily ‘in-flight’ pending the settlement or completion of a transaction. These assets are classified as being in transit and fall outside the custody perimeter until they are received and recorded in our internal books as being held on behalf of a client.
Crypto-assets will cease to be treated as client assets when they are:
- Successfully transferred out of our control, such as to an external wallet address or a third-party as per your instructions.
- Transferred as part of trade execution where we act in a principal capacity (at which point ownership transfers to us) or in an agency capacity (where assets are transferred to a third-party venue for the purpose of fulfilling an order, where they may temporarily fall outside our control).
- Utilised to settle authorised fees, charges or other obligations owed to us or relevant third-parties.
Safeguarding obligations will not apply in the following circumstances:
- During the period your crypto-assets are In-Flight Crypto-Assets and we do not have control over these assets.
- For losses resulting from the failure of underlying blockchain protocols, DLT networks, or other external factors beyond our control.
- Where losses arise from the insolvency or technical failure of a third-party venue which is not acting as an approved sub-custodian.
Note. If you hold fiat with us, these are treated as electronic money and are subject to a different set of regulatory requirements. This means that fiat funds and crypto-assets are managed and protected by us in different ways.
4. Custody Platform
We maintain a technological infrastructure and a comprehensive security framework to ensure the highest level of protection for crypto-assets held in custody.
We have implemented secure and multi-layered security measures for the storage and all movements of our client’s crypto-assets. Key elements of our security measures include:
- Secure key generation within a highly secure and controlled environment;
- Secure storage of private cryptographic keys within certified Hardware Security Modules (“HSMs”) or equivalent secure cryptographic devices (e.g., secure enclaves on dedicated hardware);
- Strict access controls and permissions based upon principles of least privilege and clear segregation of duties;
- Strong data encryption of all sensitive data both at rest and in transit; and
- Robust key backup and recovery procedures.
In respect of our own wallet structure, we utilise “warm wallets” which are designed to enable real-time access to crypto-assets, supporting rapid transaction processing and timely user withdrawals, whilst maintaining optimum security. We regularly review our approach to wallets based on evolving threats and client requirements to determine whether the use of other types of wallets (e.g. cold wallets) would be more suitable to ensure the safekeeping of crypto-assets.
We may pool client crypto-assets using an omnibus wallet. An omnibus wallet is used to custody client crypto-assets relating to more than one client, meaning individual entitlement will not be identifiable by separate wallet addresses. As a result of other clients also beneficially owning crypto-assets held in the same omnibus wallet, a client may be exposed to risks arising from the pooled nature of the wallet, including potential shortfalls.
Should our custody arrangements materially change, our clients will be informed of such changes.
Note. Crypto-assets held with third-party providers may not be subject to the same technical controls and are instead managed through our third-party risk and oversight framework.
5. Reconciliation of Client Crypto-Assets and Record Keeping
We adopt a thorough reconciliation process and complete regular reconciliations between our company records, records of third-parties (where applicable), client records, and distributed ledger holdings. This ensures accurate asset allocation and full alignment with client entitlements.
We keep adequate and well-documented records in compliance with the applicable laws.
6. Risk Management Frameworks
We have implemented a comprehensive risk management framework. This framework is designed to identify, assess, manage, monitor and report on all risks relating to our crypto-asset services. The scope of such a framework includes operational risks and ICT risks (including cyber-security threats).
Operational risks include human errors, process failures, physical security risks, and sub-custody risks. ICT risks include cyber-security threats, system downtime, data integrity risks and third party risks.
To appropriately manage and mitigate identified risks, we:
- Employ a multi-layered cyber-security framework;
- Enforce strict access controls;
- Follow a comprehensive incident, business continuity and disaster recovery response plans;
- Implement robust network security measures; and
- Conduct due diligence and ongoing monitoring of custody arrangements
7. Reporting of Client Crypto-Assets
Clients receive statements of holdings at least every three (3) months and upon reasonable request indicating the balance, the value, and any transfer of crypto-assets during the relevant period.
We ensure that our clients can access their transaction history on a real-time, continuous basis, via the dedicated user interface.
We will inform you as soon as possible of any operations involving their crypto-assets that require a response or action.
8. Return of Client Crypto-Assets
To ensure the safe return of client’s crypto-assets, we maintain verification protocols, secure transfer methods, detailed records and timely executions.
Any delays to processing client crypto-asset requests will be communicated with reasons provided and alternative arrangements suggested where necessary.