Whitely

Summary of the Custody and Administration Policy (WHITE TECH d.o.o.)

This policy describes how WHITE TECH d.o.o. holds and administers clients' crypto-assets in its own name but on behalf of clients, and what controls and security measures it applies to prevent loss, fraud, cyber-attacks or operational errors. The policy is aligned with Regulation (EU) 2023/1114 (MiCA), the national Act on the Implementation of MiCA, and the Ordinance on the Safeguarding of Clients' Assets of Crypto-Asset Service Providers (OG 157/2025).

What this policy covers

The policy applies to all activities relating to the safekeeping and control of clients' crypto-assets, clients' funds, and the means of access to those assets (e.g. private keys), including record-keeping, transfers, reporting and the return of assets.

Key principles of client-asset protection

WHITE TECH treats crypto-assets and funds received in connection with the services as clients' assets and holds them in its own name but on behalf of clients. The Company keeps records on a per-client basis such that, at all times, there is a clear separation of the assets of:

  • an individual client,
  • other clients,
  • the Company itself.

Records are updated without delay and reconciled daily with the relevant sources on each change (e.g. on-chain balances and, where applicable, third-party records). If discrepancies are identified, the Company resolves them as soon as possible and documents everything.

Omnibus wallets (pooled holding)

Clients' crypto-assets are stored in one or more omnibus wallets under the Company's control (not in separate per-client on-chain wallets). Although clients do not have direct access to the private keys, they have full visibility of their assets and balance through the Company's client portal. Within the omnibus wallets, the Company maintains an internal ledger in its internal records that allows each client's assets to be clearly identified and segregated.

Clients are informed of this method of safekeeping and the resulting risks through the General Terms and Conditions, as well as of the fact that acceptance of the General Terms and Conditions constitutes consent to the safekeeping of the client's assets as explained here.

Transfers of assets

A transfer of a client's crypto-assets to a third party is carried out solely on the basis of the client's instruction, given in the manner agreed in advance and described in the General Terms and Conditions. The Company applies the "two pairs of eyes" principle (dual control) for approving transfers, or ensures appropriate controls where input is automated.

Use of clients' assets

The Company does not use clients' crypto-assets for its own account or for the account of other persons.

Clients' funds

Clients' funds are deposited without delay upon receipt into an account or accounts opened for that purpose in segregated accounts at a credit institution, in accordance with the rules of the Ordinance (OG 157/2025). The Company ensures on a daily basis that the amount of clients' funds held at the relevant institutions is at least equal to the amount recorded in its internal records, with reconciliation carried out through daily settlements by no later than the end of the next business day. If a shortfall is identified due to erroneous or incomplete records of the Company, the Company without delay provides additional funds to protect clients. Where reconciliation or the provision of funds cannot be carried out, the Company notifies HANFA accordingly in line with the regulations.

Records and availability of data to competent authorities

The Company maintains an up-to-date "Register of Positions" for each client (balances, movements and associated rights). Data and records on clients' assets are available to HANFA and other competent authorities on request, in accordance with the regulations.

Reporting to clients

Clients are provided with a statement of positions at least once every three months or on request. The same content is also available in the client portal. The Company notifies clients as soon as possible of events that require their attention or action.

Clients' rights and blockchain events

The Company supports clients in exercising rights relating to their crypto-assets. Events that may affect rights or assets (e.g. protocol changes, blockchain upgrades) are recorded in the register of positions, and clients are notified of them without delay.

Return of crypto-assets (withdrawal)

The client retains the right to the return of their crypto-assets at all times. The Company has a defined process for handling withdrawal requests, which includes authentication of the order, security and technical checks, and verification of compliance with legal/regulatory requirements. Following these checks, the transfer is executed without delay. A return may be temporarily suspended or postponed only where required by law or regulatory obligations (e.g. freezing measures, investigations, security incidents).

Liability for loss of assets

The Company is liable for the loss of crypto-assets or access credentials where the loss results from its operations, up to the market value of the lost assets at the time of the loss, in accordance with applicable regulations. The Company is not liable for events outside its control, or where it can prove that the event is not connected to its services/operations. Examples include: a client's failure to observe security measures (e.g. not enabling 2FA), blockchain network risks, regulatory changes, market trading risks, and technical errors in transaction data (e.g. an incorrect address).

In the event of an incident, an internal investigation and root-cause assessment is carried out and liability is determined, with findings documented.

Delegation and third parties

The Company does not delegate custody or administration functions to external custodians/sub-custodians. It may use external ICT/technical providers (infrastructure, security, development), but they have no control over clients' assets and do not make custody decisions. Before engaging such providers, the Company carries out an appropriate assessment of their reliability and risk, and monitors them on an ongoing basis throughout the business relationship.

Security measures (summary)

The Company applies a combination of organisational and technical measures, including: segmentation and access control, multi-factor authentication, encryption, system monitoring, intrusion-detection systems, logging and audit trails, fraud protection, transaction-approval procedures (including multi-sig where applicable), backups and recovery testing, and measures to prevent money laundering and terrorist financing and to monitor transactions, together with the establishment of controls to prevent unauthorised access to and use of clients' assets, including the management of access credentials and private keys.

Adoption

This version of the policy was approved by the Company's Management Board.

Company details

Company name: WHITE TECH d.o.o.
OIB: 22301840862
MBS: 060486036
Address: Petrinjska ulica 6, 10000 Zagreb, Republic of Croatia