Legal & Disclosures
Recovery Plan Procedure
1. ABOUT THE PROCEDURE
This Procedure has been prepared pursuant to Article 99/B of Capital Markets Law No. 6362 and Article 47 of Communiqué No. III-35/B.1, in order for Crypto Asset Service Providers to identify actions and risks that may result in the loss of Crypto Assets and to set out the actions to be taken if such risks and actions materialise. As CLTS Kripto Varlık Alım Satım Platformu A.Ş., our principal priorities are to ensure system continuity, protect the security of User assets, and act in full compliance with legal obligations.
2. DEFINITIONS
Platform: CLTS Kripto Varlık Alım Satım Platformu A.Ş.
Wallet: Software, hardware, systems, or applications that enable the transfer of Crypto Assets and the storage of those assets or the private and public keys relating to them.
Crypto Asset: Intangible assets that may be created and stored electronically using distributed ledger technology or similar technology, distributed over digital networks, and represent value or rights.
Board: The Capital Markets Board of Türkiye.
Legislation: Capital Markets Law No. 6362, Communiqué No. III-35/B.1 on the Establishment and Operating Principles of Crypto Asset Service Providers, Communiqué No. III-35/B.2 on the Working Procedures and Principles and Capital Adequacy of Crypto Asset Service Providers, Principle Decisions, and other relevant regulations.
MASAK Legislation: Law No. 5549 on the Prevention of Laundering Proceeds of Crime and the relevant subordinate legislation.
Hot Wallet: Internet-connected wallet technology that does not have the characteristics of a Cold Wallet and is used by Crypto Asset Service Providers to meet their customers' Crypto Asset transfer requests.
Cold Wallet: Wallet technology in which the keys controlling the Crypto Asset are protected by physical, administrative, and technical information-security controls and which enables critical operations such as transaction approval and signing to be carried out with the intervention of authorised personnel in environments isolated from the internet by physical or technical air gaps.
3. GENERAL PRINCIPLES
Our Recovery Plan is structured to provide a rapid and effective response to various scenarios that may threaten our systems and User assets. In this context, operational risks, depreciation of Crypto Assets or network risks, cyberattacks, disruptions arising from external service providers, and liquidity risks have been assessed as priorities.
The actions to be taken if these risks materialise are set out clearly and sequentially under our Plan. First, the nature of the incident is identified and the relevant teams take over the process and promptly begin to implement the necessary technical and security measures. Systems or Wallets under threat are isolated. To secure the assets, Crypto Assets held in Hot Wallets are transferred immediately to Cold Wallets. Meanwhile, the integrity of all system records is secured and backup processes are activated to prevent data loss in accordance with the legislation.
While these steps are being carried out, a comprehensive assessment is made of the affected systems and the potential impact of the incident. Temporary transaction restrictions for our Users, such as suspending withdrawals or switching to view-only mode, may be applied where considered necessary. These temporary measures are lifted once system security has been fully restored, and transactions continue as normal.
In addition, in a scenario where the Platform is unable to continue its activities, User assets are transferred to secure Wallets, Users are provided with the information necessary to withdraw their assets, and these transactions are carried out under security controls.
4. RECOVERY PLAN IMPLEMENTATION STAGES
Under the Recovery Plan, it is critical to classify incidents according to their severity (risk level) and determine the appropriate response levels.
Severity: Very Critical,
Definition: Access to Platform systems has completely stopped or customer assets are under direct threat.
Response Level: A rapid and comprehensive response is implemented. The system is isolated, and asset security is prioritised.
Severity: Critical
Definition: The system outage is at a critical level and transaction integrity is at risk.
Response Level: Priority technical and security actions are taken, and system-restoration plans are activated.
Severity: Medium
Definition: There is a limited service disruption or risk in isolated units.
Response Level: An isolated response is carried out and service continuity is maintained. The sources of the issue are assessed.
Severity: Low
Definition: Circumstances do not affect the service as a whole but require monitoring.
Response Level: Monitoring, reporting, and preventive-maintenance processes are initiated.
Once the threat has been eliminated, the source of the incident is identified using system logs and analytical tools. All relevant units work together to remediate the identified weaknesses. The response plans prepared to verify the effectiveness of these processes are tested at least annually, and the results are reported to the Board of Directors.
5. PROTECTION OF CUSTOMER ASSETS AND NOTIFICATION PROCESS
When the Recovery Plan is activated, the security of our Users' assets is our highest priority. All User assets are segregated from the Platform's own assets and safeguarded solely as customer assets. Assets held in Hot Wallets are rapidly transferred to Cold Wallets, Wallets under threat are isolated and disabled for transactions, and all transfers are made subject to a multi-approval process.
Throughout this process, our Users are informed regularly through in-system messages, email, and SMS. The legally required notifications are made to the relevant institutions, including primarily the CMB and MASAK. Within 15 days after activation of the Recovery Plan, a proof-of-reserves audit is performed by an independent audit firm and submitted to the Board.
6. REVIEW OF THE PLAN AND RESPONSIBLE PERSONS
This Procedure is reviewed at least annually. It may be updated before the end of the year where considered necessary. Two authorised members of staff, one at deputy general manager level, have been appointed as responsible for implementing the Plan approved by the Board of Directors, and their contact details have been notified to the Board.