1. Purpose and status
This policy establishes proportionate controls for K 3 GOFIX ASIA VENTURES ("GoFix") as a digital home and commercial maintenance-services platform and merchant. GoFix is not presenting itself as a bank, remittance provider, e-money issuer, or payment processor. Payments are processed through approved regulated or authorised payment-service providers. Where GoFix is not legally classified as a reporting institution, this policy is a voluntary governance framework and does not replace any mandatory obligations imposed by law, a regulator, a bank, an acquirer, or Fiuu.
2. Scope
- All owners, managers, employees, contractors, administrators, developers, customer-support
personnel, and service crews who handle users, bookings, transactions, refunds, settlements, or records.
- The GoFix customer application, GoFix Crew application, administration portal, website, Firebase
environment, payment integrations, and related bank or merchant accounts.
- Customer payments, crew payouts, refunds, promotional credits, chargebacks, disputes, and any
other movement of value connected with the platform.
3. Governance and responsibilities
- Management approves this policy, assigns a responsible person, and provides adequate authority
and access to records.
- The responsible person oversees screening, monitoring, escalation, training, record retention, and
communication with Fiuu, banks, regulators, or law-enforcement authorities where appropriate.
- All personnel must promptly report suspicious behaviour internally and must not warn a customer
or other person that a review, report, or investigation may be taking place.
- Access to payment and identity information must follow least-privilege principles and be removed
immediately when a person leaves or changes role.
4. Risk-based approach
GoFix assesses risk by considering the customer, service type, location, payment method, transaction value and frequency, device or account behaviour, refund pattern, crew relationship, and any indicators supplied by its payment provider. Higher-risk activity receives enhanced review, may be delayed, rejected, restricted, or escalated.
5. Customer and crew verification
- Collect only information reasonably needed to create an account, deliver a service, process a
payment, prevent fraud, and meet legal or provider requirements.
- Verify customer contact details and booking information using proportionate methods such as one-
time passwords, valid addresses, service-location confirmation, and payment-provider authentication.
- Verify crew identity, contact details, role, bank-account ownership, and supporting business or
professional information before permitting payouts or access to customer locations.
- Do not accept anonymous crew accounts, fabricated identities, duplicate identities used to evade
controls, or payout accounts held by unrelated third parties without documented justification and approval.
- Where required by Fiuu, a bank, law, or risk assessment, request additional documents and verify
beneficial ownership or authority to act for a business customer.
6. Sanctions and prohibited activity
- GoFix will not knowingly provide services or process transactions involving sanctioned persons,
designated entities, terrorism-related activity, proceeds of crime, illegal goods or services, or attempts to evade legal restrictions.
- Where screening is required, GoFix will use current lists or controls supplied by competent
authorities or its payment providers and will document potential-match reviews.
- A potential match must not be treated as confirmed solely because of a similar name. The
responsible person must review available identifiers and escalate when uncertainty remains.
7. Transaction monitoring and red flags
- Unusually high-value or repeated bookings inconsistent with normal maintenance needs.
- Multiple failed payments, rapid retries, frequent account/device changes, or many cards/accounts
linked to one user.
- Payments followed by immediate cancellation or repeated refund requests without a genuine
service issue.
- Requests to refund to a different card, wallet, bank account, or person from the original payer.
- Customer and crew collusion, fabricated jobs, self-dealing, circular payments, or bookings with no
evidence that services were delivered.
- Unexplained changes to payout accounts, multiple crews sharing a bank account, or payout
accounts not matching verified names.
- Attempts to split a transaction to avoid limits, conceal the true payer, use GoFix to transfer
cash/value, or process activity unrelated to GoFix services.
- Transactions involving high-risk locations, unusual IP/device behaviour, sanctions alerts, stolen
credentials, or law-enforcement/provider warnings.
8. Review and escalation procedure
- Place the transaction, refund, payout, or account under review where permitted and proportionate.
- Preserve relevant records, including account identifiers, booking details, timestamps, payment
references, communications, device or access logs, and evidence of service delivery.
- Conduct a documented review using available facts; request additional information only through
authorised channels.
- Decide whether to approve, reject, restrict, suspend, refund to the original payment method,
terminate the relationship, or escalate to Fiuu, the bank, a competent authority, or law enforcement.
- Where a statutory report is required, submit it through the legally prescribed channel by the
authorised person and maintain confidentiality.
9. Payments, refunds, and payouts
- No GoFix user may use the platform as a cash-advance, remittance, peer-to-peer transfer, or value-
conversion service.
- Refunds must normally be returned only through the original payment channel and to the original
payer, subject to payment-provider rules.
- Crew payouts must be supported by completed-service records and paid only to a verified payout
account approved for that crew or business.
- Manual payment overrides, refunds, payout changes, and exceptional adjustments require
documented approval and audit logging.
- GoFix may impose transaction limits, temporary holds, reserves, or additional verification where
risk or provider requirements justify them.
10. Record keeping and privacy
GoFix will retain relevant transaction, booking, verification, investigation, refund, payout, and communication records for the period required by applicable law, tax rules, contractual obligations, dispute needs, or payment-provider requirements. Records must be protected against unauthorised access, alteration, loss, or disclosure. Personal data must be collected and used only for lawful and stated purposes.
11. Training, testing, and breaches
- Relevant personnel receive role-appropriate onboarding and refresher training on red flags,
escalation, confidentiality, refunds, account access, and record preservation.
- Management periodically tests access controls, transaction-review procedures, payout changes, and
incident escalation.
- Breaches may result in access removal, disciplinary action, contract termination, reporting to
providers or authorities, and remediation.
References
This policy is informed by the following sources. It should be read together with applicable laws, payment-provider agreements, and GoFix customer-facing terms.
- Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (Act
613), Malaysia, as amended.
- Bank Negara Malaysia, AML/CFT and Targeted Financial Sanctions policy resources and guidance
(including the 5 February 2024 policy documents applicable to regulated sectors).
- Fiuu Malaysia Terms of Services and applicable payment-channel schedules, including restrictions
on illegal transactions, refund handling, transaction limits, disputes, and chargebacks.