ANTI-MONEY LAUNDERING (AML) & COUNTER-TERRORIST

FINANCING (CTF) POLICY

Lucky Days

Last updated: 07/16/2026

1. Purpose

This Anti-Money Laundering ("AML") and Counter-Terrorist Financing ("CTF") Policy (the "Policy") sets out the mandatory standards, controls and procedures adopted by 3-102-961212 Sociedad de Responsabilidad Limitada, operating https://luckydays.co (the "Company"), to prevent the Company's services from being used for money laundering, terrorist financing, proliferation financing, or any other financial crime.

This Policy constitutes the Company's written AML/CTF policy as required by Section 10.1 of the Anjouan Gaming AML & CTF Code of Conduct (the "Code"), covering risk assessment, customer due diligence, monitoring and reporting, record keeping and staff training. The Company formally acknowledges and agrees to comply with the Code as a condition of its licence.

2. Scope

This Policy applies to:

  • All operations of the Company conducted under the Lucky Days brand;
  • The Company's Ultimate Beneficial Owner, shareholders, directors, officers and key personnel;
  • All employees, contractors and agents of the Company; and
  • Third-party service providers involved in gaming, payments, or player onboarding.

The Company remains fully responsible for AML/CTF compliance at all times, including where functions such as identity verification, payment processing, or customer support are outsourced to third parties.

3. Definitions and Abbreviations
  • AML — Anti-Money Laundering.
  • CTF/CFT — Counter-Terrorist Financing / Combating the Financing of Terrorism.
  • CDD — Customer Due Diligence: the process of identifying and verifying a customer's identity and understanding the nature of the business relationship.
  • EDD — Enhanced Due Diligence: additional due diligence measures applied to higher-risk customers or relationships.
  • SDD — Simplified Due Diligence: reduced measures permitted only for demonstrably lowrisk situations.
  • PEP — Politically Exposed Person: an individual entrusted with a prominent public function, or a family member or known close associate of such a person.
  • SAR — Suspicious Activity Report: a report of suspected money laundering or terrorist
    financing.
  • CTR — Currency Transaction Report: a report of transactions exceeding the prescribed
    threshold, whether suspicious or not.
  • Compliance Officer — the individual appointed under Section 10.2 of the Code, who also performs the function of Money Laundering Reporting Officer (MLRO) for the Company.
  • Anjouan Gaming — Anjouan Licensing Services Inc., the competent licensing and supervisory authority acting on behalf of the Autonomous Island of Anjouan.
  • FATF — Financial Action Task Force.
4. Legal and Regulatory Framework

The Company complies with:

  • The Computer Gaming Licensing Act 007 of 2005, under which the Company's Anjouan Online Gaming Licence is issued;
  • The Anjouan Gaming AML & CTF Code of Conduct, compliance with which is mandatory and forms an integral part of the Company's licensing conditions;
  • AML/CFT laws and regulations applicable in Anjouan and directives, guidance and notices issued by Anjouan Gaming; and
  • International AML/CTF standards, including the FATF Recommendations.

The Company is incorporated in Costa Rica and additionally observes applicable Costa Rican legal requirements. The Company cooperates fully with Anjouan Gaming, the Anjouan Offshore Financial Authority and other relevant authorities.

5. Risk-Based Approach and Risk Assessment

5.1 Risk-Based Approach

The Company applies a risk-based approach: AML/CTF controls are proportionate to the money laundering and terrorist financing risks identified. Funds and player activity must be traceable, responsibility for AML compliance is clearly established and the Company cooperates fully with the authorities.

5.2 Business Risk Assessment

The Company maintains a documented AML/CTF risk assessment considering, at a minimum:

  • Player risk profiles, including geography, behaviour and funding sources;
  • The online gaming products and services offered;
  • Payment methods and delivery channels, including cards, e-wallets and cryptocurrencies; and
  • The jurisdictions involved, including FATF-identified high-risk countries.

5.3 Risk Mitigation and Review

Based on the identified risks, the Company implements proportionate controls and applies Enhanced Due Diligence where required. The risk assessment is reviewed and updated at least annually, or upon any material change to the business, its products, its markets, or the regulatory environment.

5.4 Customer Risk Scoring

Each customer is assigned a risk rating at registration, which is dynamically re-assessed based on: individual status (PEP status, sanctions matches, adverse media), geographical location, gambling and transactional behaviour, payment methods used and fraud red flags. Higher risk ratings trigger enhanced monitoring and, where warranted, Enhanced Due Diligence.

6. Customer Acceptance and Due Diligence

6.1 Customer Due Diligence at Registration

In accordance with Section 6.1 of the Code, the Company collects and records the following at signup: full legal name, valid email address, date of birth and residential address. No account is activated unless all of this information has been provided. The Company does not open or maintain anonymous accounts and does not accept customers acting on behalf of undisclosed third parties.

6.2 Restrictions

The Company does not accept customers who are under 18 years of age (or the applicable legal gambling age), residents of Restricted Countries as listed in the Company's KYC Policy, or persons appearing on applicable sanctions lists. Age verification forms part of the KYC process and accounts suspected of underage use are suspended immediately pending investigation.

6.3 Enhanced Due Diligence — Mandatory Triggers

In accordance with Section 6.2 of the Code, EDD is conducted where any of the following occurs:

  • Upon the player's first withdrawal request, regardless of amount;
  • When aggregate lifetime deposits reach USD 10,000 (or equivalent); or
  • Where elevated risk indicators or suspicious activity are identified.

6.4 Enhanced Due Diligence — Documentation

EDD includes, at a minimum: government-issued photo identification; a utility bill or equivalent document confirming residential address; and proof of source of funds where required based on the risk assessment. Detailed documentary standards are set out in the Company's KYC Policy.

6.5 Restrictions Pending Completion of EDD

Where EDD has been triggered but not completed: withdrawals are not processed and financial activity on the account is restricted where necessary to mitigate risk.

6.6 Inability to Complete Due Diligence

Where a customer fails to provide required CDD/EDD information or documentation within a reasonable timeframe, the Company shall not carry out further transactions for the customer, shall consider filing a Suspicious Activity Report and may restrict or close the account. Refunds of verified deposits, where appropriate, are made only to the originating payment method.

7. Politically Exposed Persons and Sanctions Screening

All customers are screened at registration and on an ongoing basis against:

  • Applicable sanctions lists, including OFAC, EU and UN consolidated lists; and
  • PEP and adverse media databases.

Confirmed sanctions matches result in immediate account suspension, rejection of transactions and reporting to the relevant authorities. Customers identified as PEPs are automatically classified as high-risk: establishing or continuing the relationship requires senior management approval, source of funds and source of wealth verification and enhanced ongoing monitoring. PEP status is treated as continuing for at least 12 months after the individual leaves the prominent public function, subject to a risk-based assessment thereafter.

8. Source of Funds and Source of Wealth

Source of funds documentation is requested where required by the risk assessment, upon EDD triggers, or where deposits or gambling activity are inconsistent with the customer's known profile. Acceptable evidence includes payslips or employment contracts, bank statements, tax returns or financial statements and documentation of inheritance, asset sales, or other one-time receipts. Failure to provide satisfactory evidence within a reasonable timeframe results in account restrictions, suspension of withdrawals, or account closure.

9. Transaction Monitoring

9.1 Monitoring Systems

In accordance with Section 9.1 of the Code, the Company operates monitoring systems designed to detect:

  • Structuring or threshold avoidance (e.g., multiple deposits kept just below reporting or
    verification thresholds);
  • Rapid movement of funds (e.g., deposit followed by withdrawal with minimal or no
    gameplay);
  • Unusual betting patterns (e.g., offsetting bets, minimal-risk wagering inconsistent with
    recreational play, chip dumping in poker); and
  • Activity involving high-risk jurisdictions.

9.2 Red Flag Indicators

Staff must escalate to the Compliance Officer, without delay, any of the following (nonexhaustive) indicators: reluctance to provide identification; use of payment methods registered to third parties; multiple accounts or shared devices/IP addresses; deposits inconsistent with known income; requests to withdraw to a different payment method than used for deposit; sudden changes in deposit or wagering behaviour; and any customer attempt to structure transactions around the USD 10,000 threshold.

9.3 Alert Handling

Monitoring alerts are reviewed by the Compliance Officer or designated compliance personnel within 24 hours of generation. Outcomes (dismissed, escalated, reported) are documented and retained.

10. Reporting

10.1 Internal Reporting

Any employee, contractor, or agent who knows or suspects that a transaction or activity may involve money laundering or terrorist financing must submit an internal Suspicious Activity Report to the Compliance Officer immediately. The Compliance Officer acknowledges receipt, investigates and documents the decision whether to report externally.

10.2 Suspicious Activity Reports to Anjouan Gaming

In accordance with Section 9.2 of the Code, the Company reports suspicious activity to Anjouan Licensing Services Inc. / Anjouan Gaming within 24 hours of detection, including full supporting documentation.

10.3 Currency Transaction Reports

In accordance with Section 9.3 of the Code, all transactions or linked transactions exceeding USD 10,000 (or equivalent) are reported, whether suspicious or not.

10.4 Tipping-Off Prohibition

No employee, contractor, or agent may disclose to a customer or any third party that a SAR has been made, that an investigation is underway, or that information has been provided to the authorities. Breach of this prohibition is a serious disciplinary matter and may constitute a criminal offence.

11. Record Keeping

In accordance with Section 8 of the Code, the Company retains all AML-related records for a minimum of five (5) years, including:

  • CDD and EDD documentation;
  • Transaction records (deposits, wagers and withdrawals);
  • SARs, CTRs and internal reports (including alert dispositions); and
  • Audit and compliance records, including training records.

Records are stored securely, protected against unauthorised access or alteration and are readily available to Anjouan Gaming upon request.

12. Governance: Compliance Officer and Training

12.1 Compliance Officer

The Company has appointed a suitably qualified Compliance Officer, who also acts as the Company's Money Laundering Reporting Officer, responsible for: AML/CTF oversight; regulatory liaison with Anjouan Gaming; timely reporting and escalation; maintenance of this Policy and the KYC Policy; and oversight of the risk assessment. A deputy is designated to receive internal reports and act in the Compliance Officer's absence, ensuring no gap in the escalation path.

12.2 Staff Training

In accordance with Section 10.3 of the Code, all relevant staff receive AML/CTF training upon onboarding, annually thereafter and following any regulatory or policy change. Training covers this Policy, red flag recognition, internal reporting obligations and the tipping-off prohibition. Attendance and content are documented and retained.

12.3 Employee Screening

Background checks are performed on employees in compliance-sensitive roles prior to appointment and periodically thereafter.

13. Cybersecurity and Data Protection

The Company protects the integrity and confidentiality of player data through appropriate technical and organisational safeguards. Cybersecurity incidents are reported to Anjouan Gaming within 24 hours, in accordance with Section 11 of the Code. Detailed controls are set out in the Company's IT and Information Security policies.

14. Independent Audit and Review

In accordance with Section 12 of the Code, the Company undergoes an independent AML audit annually, assessing policy effectiveness, regulatory compliance and internal controls and training. Anjouan Gaming may conduct inspections and audits at any time and the Company will cooperate fully. This Policy is reviewed at least annually by the Compliance Officer and additionally upon material regulatory or business change; the Company monitors regulatory developments and adopts approved technological solutions (including AI-based monitoring) where appropriate.

15. Breach and Enforcement

Non-compliance with this Policy by any employee, contractor, or agent is a serious disciplinary matter and may result in dismissal and referral to law enforcement. The Company acknowledges that non-compliance with the Code may result in regulatory enforcement action by Anjouan Gaming, including financial penalties, suspension or revocation of the gaming licence, public disclosure of violations and referral to law-enforcement authorities.