Legal

Compliance Policy

How we approach operating GABBAR’s enabled services lawfully, transparently and with appropriate controls.

Customer policy · Version 0.1 beta

Customer policy

This document forms part of the GABBAR customer policy set. Read it together with the applicable Terms and product rules.

Version
0.1 beta
Platform owner and operator
Pipscapital Pvt Ltd
Technology
Powered by Pips Forex Technology
Website
https://gabbarex.com/
Document owner
Compliance, Pipscapital Pvt Ltd

1Purpose and accountability

1.1This policy explains how we approach operating GABBAR's enabled services lawfully, transparently and with appropriate controls. GABBAR Exchange is a brand and platform owned and operated by Pipscapital Pvt Ltd, with technology powered by Pips Forex Technology. Pipscapital Pvt Ltd is accountable for the controls we perform. The technology attribution does not transfer our customer obligations. We do not claim a specific regulatory authorisation in this document.

1.2Our compliance framework covers product governance, customer treatment, market integrity, financial crime, privacy, security, complaints, records, third parties and incident response. It applies proportionately to the services that are actually enabled.

1.3We assign responsibility for material obligations and maintain escalation to management. No policy eliminates every risk; controls are reviewed using incidents, testing, legal developments and customer feedback.

2Legal and product controls

2.1Before enabling a product, we assess applicable legal requirements, who may use it, what assets or jurisdictions are supported, how customer assets and data move, and what disclosures and records are needed. We present applicable product rules and fees before use. A feature shown in a test environment is not proof of live availability or regulatory approval.

2.2Restrictions and controls may change to address new law, sanctions, court orders, security incidents or material operational risks. We maintain an internal owner for each material control and document changes.

2.3A product assessment considers its customer purpose, eligibility, asset and money flows, execution and settlement, custody implications, pricing and fees, conflicts, data use, financial-crime exposure, resilience, support and exit arrangements. We do not rely on a navigation link as proof that these requirements are satisfied.

2.4Before material launch or change, relevant owners review required customer terms, risk warnings, operational procedures, access controls and monitoring. High-severity unresolved issues can prevent or limit launch.

2.5We monitor an enabled product for complaints, errors, misuse, unexpected losses and control failures. We may restrict availability, change limits or suspend a service while we investigate and remediate a material issue.

3Customer protection and market conduct

3.1We seek clear order states, accurate balances, auditable executions, understandable fees and an accessible complaints route. We prohibit market manipulation, wash trading, misleading advertisements, misappropriation of customer assets and deliberate concealment of errors. Material incidents are investigated and customer records reconciled before an affected service is restored.

3.2We do not use promotional statements that imply guaranteed returns, risk-free assets, insured deposits, regulatory approval or an unverified custody arrangement. We explain material risks in the Risk Disclosure and applicable product rules before activation.

3.3Trading controls address order validation, available balance, precision, price and quantity limits, duplicate instructions, self-trade handling, market status, execution records and cancellation. Customer records distinguish submitted orders from completed executions and identify partial fills.

3.4We prohibit employees, contractors and users from manipulating markets, fabricating volume, misusing confidential information or exploiting a malfunction. Suspected abuse may lead to order review, restriction, evidence preservation and lawful reporting.

3.5We provide a complaint route without charging for an ordinary complaint. Confirmed errors are corrected through an auditable adjustment, and recurring issues are reviewed for broader customer impact and root cause.

3.6We design customer communications to be clear, balanced and capable of being retained. Material limitations, fees and risks should not be hidden by promotional prominence or a misleading button label.

4Financial-crime controls

4.1Identity verification, sanctions screening, transaction monitoring, escalation and legally required reporting are addressed in the AML, KYC and Sanctions Policy. We may restrict an account or transaction when law or a documented risk assessment requires it, with a review and complaint route where lawful.

4.2We apply risk-based due diligence to customers and material counterparties, understand beneficial ownership where relevant and review unusual activity. Product and commercial teams must refer potential red flags to Compliance rather than attempting to resolve them informally.

4.3We protect the confidentiality of investigations and legally protected reports. Customer communications must not reveal detection methods or information where disclosure could enable evasion, prejudice an inquiry or breach law.

5Privacy and security

5.1We use personal data for defined purposes, limit access, secure systems and respond to incidents as described in the Privacy Policy. Please report a suspected compromise to security@gabbarex.com and send privacy requests to privacy@gabbarex.com.

5.2Product design considers data minimisation, access, retention, user rights and security before collection begins. New or materially changed high-risk processing receives an appropriate privacy and security review.

5.3Security controls include identity and access management, logging, change management, vulnerability handling, backup and recovery, incident response and provider oversight appropriate to the system's risk. Administrative and financial actions require traceable records.

5.4Personnel must not request or handle a customer's password, private key, seed phrase or one-time authentication code as part of ordinary support. Suspected credential compromise is escalated immediately.

6Conflicts and third parties

6.1We assess conflicts involving fees, listings, liquidity, related-party trading and referral rewards. We prevent, control or disclose material conflicts. We assess material vendors and partners, but remain responsible for obligations we undertake toward customers.

6.2A conflict can arise when we or a related party benefit from a listing, transaction route, spread, fee, liquidation, reward, provider selection or use of information. Relevant personnel must disclose conflicts internally and avoid participating in a decision where impartiality is compromised.

6.3Controls can include separation of duties, restricted access, independent approval, objective criteria, transaction monitoring, disclosure and refusal of an activity. Disclosure is used only where it adequately informs the customer and does not replace a control that law requires.

6.4Material providers are assessed for capability, security, legal and compliance risk, resilience, data handling and exit options. Contracts define responsibilities, audit or information rights where appropriate, incident reporting and termination support.

7Incidents and reporting

7.1We record significant service, financial, security and compliance incidents; contain harm; preserve evidence; reconcile transactions; notify affected customers and authorities when required; and review root causes. We do not promise that every incident or investigation can be disclosed immediately where doing so would be unlawful or unsafe.

7.2Incident severity considers customer harm, value and number of affected transactions, data sensitivity, market integrity, duration, legal duties and recurrence. A serious incident is escalated promptly to appropriate management and specialists.

7.3Recovery includes validating authoritative records, preventing duplicate or inconsistent processing, testing restoration and communicating known limitations. A service is not treated as safely restored solely because its interface loads.

7.4After containment, we document root cause, corrective action, affected customers and lessons learned. Where an error may affect multiple accounts, we assess the population rather than waiting only for individual complaints.

8Training, records and review

8.1Personnel receive training appropriate to their duties. We retain required records, restrict access and periodically review policies, controls, incidents and customer complaints. Material findings are assigned an owner and tracked to resolution.

8.2Records include approvals, decisions, transactions, administrative changes, investigations, complaints, incidents, training and control evidence needed to demonstrate operation and reconstruct material events.

8.3Testing may be performed by a person independent of the control owner and proportionate to risk. Findings are classified, assigned a completion target and re-tested before closure where appropriate.

8.4Policies are reviewed after material legal, business, technology or risk changes and periodically even if no such change occurs. We preserve previous versions and relevant acceptance records.

9Questions and complaints

9.1Compliance questions: compliance@gabbarex.com. Security incidents: security@gabbarex.com. Formal complaints: complaints@gabbarex.com.

9.2Include sufficient information for us to identify the issue without sending passwords, private keys, seed phrases or authentication codes. We route a matter to the responsible team and preserve confidentiality according to its nature.

9.3Raising a concern in good faith does not remove your access to the complaint process. We prohibit retaliation by personnel against a person who reports a suspected breach or control failure in good faith.

End of Compliance Policy.