Fraud Prevention & Transaction Security Policy

Version: 1.0 (2026)

Internal Policy: Fraud Risk Management Framework Entity: BUYONE SIA

1. Background

The Fraud Prevention and Transaction Security Policy is established to facilitate the development of controls that aid in the detection and prevention of fraudulent activities within the BuyOne marketplace. It is the intent of BUYONE SIA (hereinafter "the Company") to promote a secure "Social Utility" ecosystem by providing clear guidelines for transaction security, identity integrity, and the conduct of investigations into suspected irregularities.

2. Scope of Policy

This policy applies to any irregularity or suspected irregularity involving: • Hosts (Service Providers) and Guests (Buyers) registered on the platform. • Employees, consultants, and vendors of BUYONE SIA. • Any other third parties with a business relationship with the Company.

3. Policy Statement

Management is responsible for the detection and prevention of fraud, misappropriations, and other irregularities. For the purposes of the BuyOne marketplace, fraud is defined as the intentional, false representation or concealment of a material fact (such as a fake "Social Slot" or stolen payment credentials) for the purpose of inducing another to act upon it to his or her injury.

4. Actions Constituting Marketplace Fraud

The terms fiscal irregularities and marketplace fraud refer to, but are not limited to: • Identity Fraud: The use of synthetic or stolen identities to create "Host" or "Guest" profiles. • Payment Fraud: Use of stolen credit cards, "card testing" activities, or unauthorized transactions. • Listing Fraud: The creation of non-existent or misleading "Social Slots" to solicit payments without the intent to provide the service. • Payout Scams: Attempting to circumvent the 80/20 (Host / BUYONE SIA) split logic or the platform's integrated escrow and safeguarding protocols.

5. Fraud Prevention & Technical Controls

To mitigate the risks defined above, BUYONE SIA implements the following mandatory controls: 5.1. Identity Integrity (KYC): Mandatory Identity Verification for all Hosts and Guests via specialized third-party providers. No Host may list a service without a successfully verified biometric and document check. No Guest can buy a Social Slot without a successfully verified biometric and document check. 5.2. Strong Customer Authentication (SCA): Utilization of integrated 3D Secure 2.0 (3DS2) protocols provided by our Payment Service Provider for all pay-in transactions to ensure compliance with PSD2 and reduce unauthorized chargebacks. 5.3. Transactional Escrow (Hold-and-Release): A "Secure Hold" logic is applied to all bookings. Funds are authorized and held within a regulated safeguarding environment, with settlement to the Host only occurring after confirmed completion of the activity. 5.4. Content Governance: Human moderation of "Social Slot" listings prior to publication to prevent high-risk or prohibited activities.

6. Reporting and Investigation

6.1. Reporting Procedures: BuyOne facilitates a "Trust Infrastructure" where any user who discovers or suspects fraudulent activity (a fake profile, suspicious booking, or payment irregularity) can immediately notify the Compliance Unit via the "Report Content" button available on every profile and Social Slot. 6.2. Investigation Responsibilities: The Compliance Unit has the primary responsibility for the investigation of all suspected fraudulent acts. If an investigation substantiates that fraudulent activities have occurred, the Company will: • Immediately suspend the offending account(s). • Initiate a refund to the injured party via the regulated payment partner. • Where necessary, refer the results to appropriate law enforcement and/or regulatory agencies.

7. Confidentiality

All information received regarding suspected fraud will be treated confidentially. Investigation results will not be disclosed or discussed with anyone other than those who have a legitimate need to know, in order to protect the reputation of individuals involved and the Company from potential civil liability.