Whistleblowing Procedure · Violation Reporting System
Pursuant to the Protected Disclosures Act 2014 (as amended by the Protected Disclosures (Amendment) Act 2022) and in implementation of Directive (EU) 2019/1937 · Version April 2026 · V 5.0
Togo Infinity Limited, trading under the trading name THE REAL MONEY, has adopted this Whistleblowing System in the belief that the timely reporting of any violation is a fundamental tool to prevent unlawful conduct, protect customers and the integrity of the platform, and promote a corporate culture based on legality and transparency.
The system is adopted in compliance with the Protected Disclosures Act 2014 and in implementation of Directive (EU) 2019/1937, in line with the highest standards of governance, legality and transparency.
What is Whistleblowing and why is it important?
Whistleblowing is the reporting by a person —an employee, collaborator, customer, or other individual— of unlawful, irregular, or non-compliant behavior that they have become aware of in the context of a work context or a professional or commercial relationship.
Togo Infinity Limited (hereinafter "the Company"), trading under the trading name THE REAL MONEY, has adopted this Whistleblowing System in the belief that timely reporting of any violations is a fundamental tool for:
- Preventing illegal or non-compliant conduct before it causes damage;
- Protecting customers, workers and the integrity of the THE REAL MONEY platform;
- Promoting a corporate culture based on legality, fairness and transparency.
1.2 Objectives of the whistleblowing system
- Prevention: promptly identify non-compliant conduct or conduct that is potentially harmful to corporate integrity;
- Protection: protect whistleblowers from any form of retaliation or discrimination;
- Transparency: ensuring a clear, defined process that is accessible to legitimate parties;
- Continuous improvement: use reporting as a tool to strengthen compliance controls;
- Regulatory compliance: ensuring compliance with applicable regulations.
1.3 Scope of application
This document governs the Company's whistleblowing system and, in particular:
- defines the reporting management system;
- establishes organizational roles and responsibilities for reporting management;
- regulates staff training and awareness-raising activities;
- implements a whistleblowing system compliant with Directive (EU) 2019/1937;
- ensures the protection of whistleblowers and the proper management of reports of regulatory violations.
1.4 Guiding principles
- confidentiality of the whistleblower's identity;
- prohibition of retaliation of any kind;
- access to the system via a single internal channel (MITWhistle platform);
- timeliness in managing and responding to reports;
- proportionality of actions to the seriousness of the violations;
- traceability of reports and management activities.
1.5 Definitions
| Term | Definition |
|---|---|
| Whistleblower | A natural person who makes a report or publicly discloses information about violations acquired in the context of work or professional activity with the Company. |
| Internal reporting | Written or oral communication of information on violations, made through the internal channels made available by the Company. |
| External reporting | Disclosure of information about breaches made through competent authorities, including authorities designated under the Protected Disclosures Act 2014 (as amended). |
| Public disclosure | Making information about violations public through the media or through public disclosure, where required by applicable law. |
| Violations | Behaviors, acts or omissions, even if only potentially illicit or non-compliant with applicable legislation, which may harm the public interest, the Company's regulatory compliance, or organizational and reputational integrity. |
| Information on violations | Information, including reasonable suspicions, regarding violations committed or likely to be committed within the Company's work or organizational context. |
| Work context | Any current or past work or professional activity performed in connection with the Company in which a person may acquire information about violations and suffer retaliation for reporting them. |
| Person involved | Natural or legal person mentioned in the report as the alleged author of the infringement or in any case implicated in it. |
| Facilitator | Natural person who assists the whistleblower in the reporting process and whose identity is protected by applicable law. |
| Retaliation | Any act, behavior, or omission, even attempted or threatened, committed as a result of the report and which may cause unfair harm to the reporter or the protected individuals. |
| Protective measures | Set of protections provided by applicable legislation to protect the whistleblower and related parties from any form of retaliation. |
| Report Manager | The individual appointed by the Company to receive, analyze, and manage reports, with autonomy and independence, identified as the Company's Compliance Officer. |
| Anonymous report | Report made without identifying the whistleblower. If the whistleblower's identity is subsequently revealed, the protections provided by current legislation apply. |
Regulatory references
This Procedure is adopted in compliance with the European and Irish regulatory frameworks regarding whistleblowing, compliance, personal data protection, and corporate risk prevention. In particular, the Company's reporting system is governed by the following main regulatory sources:
- Directive (EU) 2019/1937 on the protection of whistleblowers — on the protection of persons reporting breaches of Union law;
- Protected Disclosures Act 2014 (as amended by the Protected Disclosures (Amendment) Act 2022) — Irish legislation implementing the EU Directive and the main legislation on whistleblowing;
- Regulation (EU) 2016/679 — on the protection of personal data and the free movement of such data;
- Data Protection Act 2018 — Irish national legislation that complements the GDPR;
- Directive 2014/65/EU (MiFID II) — with reference to the organizational and governance requirements applicable to entities providing investment advice services, including the adoption of adequate internal control and compliance systems;
- Any further European and Irish sectoral legislation applicable to the Company, including those relating to Prevention of Money Laundering and Terrorist Financing (AML/CFT), financial services and prudential regulation, governance and internal controls.
Who can make a report
The Company's Whistleblowing System is accessible to all individuals who, within a working, professional or commercial context, acquire information relating to potentially relevant unlawful acts (relevant wrongdoing), pursuant to applicable law. Reports can be made by both internal and external parties, in compliance with the conditions and protections provided by current legislation, including the Protected Disclosures Act 2014.
3.1 Internal whistleblowers — workers and collaborators
All individuals who work or have worked for the Company, in any form or capacity, are entitled to make reports, including:
- Permanent and fixed-term employees;
- Collaborators, consultants and freelancers;
- Interns and trainees, even unpaid;
- Temporary workers;
- Members of the administrative, management or supervisory bodies;
- Members of the sales network (including financial advisors and agents);
- Former employees or collaborators, due to facts learned during the relationship;
- Candidates, for information acquired during the selection process.
For the purposes of this Procedure, these individuals fall within the definition of "workers" provided for by the applicable legislation.
3.2 External whistleblowers — customers and third parties
External parties who have or have had professional or commercial relationships with the company are also entitled to make reports, including:
- Clients of the The Real Money platform, limited to facts learned in the context of the relationship with the Company;
- Suppliers, business partners and third parties who operate or have operated on behalf of the Company;
- Other individuals who, in the context of professional or commercial relationships, have acquired knowledge of potential illicit activities.
3.3 Conditions for the protection of the whistleblower
The protections provided by this Procedure apply to whistleblowers who make a report provided that, at the time of the report:
- have reasonable grounds to believe that the information reported is true;
- the information concerns a relevant offence under applicable law;
- the report is made in good faith and without abuse of the tool.
Reports made in bad faith or with gross negligence, as well as those that are manifestly unfounded or instrumental, are not covered by the protections. To the extent permitted by applicable law, such conduct may involve:
- the adoption of disciplinary measures (for workers);
- contractual, civil or, where provided by law, criminal liability;
- any further consequences provided by law.
What can be reported
Violations —or reasonable suspicions of violations— that constitute a significant offense under applicable law may be reported. This scope includes, by way of example and not limited to:
- violations of European Union law;
- violations of applicable national regulations;
- deficiencies in internal control, risk management and compliance systems;
- illegal, fraudulent or unethical behavior;
- conduct aimed at evading legal or regulatory obligations.
4.1 Violations of anti-money laundering (AML/CFT) regulations
Violations, or reasonable suspicions of violations, of applicable legislation on the prevention of money laundering and terrorist financing, where applicable to the Company, may be reported. By way of example, this scope includes:
- failure or inadequate identification and verification of customer identity (Customer Due Diligence);
- deficiencies in the application of internal know-your-customer (KYC/KYB) procedures;
- failure to report or inadequately report suspicious transactions to the competent authorities;
- failure to retain or record information relevant to AML/CFT purposes;
- deficiencies in internal control systems aimed at preventing money laundering and terrorist financing;
- behaviors aimed at circumventing internal regulations or procedures.
4.2 Violations of personal data protection
Pursuant to Regulation (EU) 2016/679, violations, or reasonable suspicions of violations, of the legislation on personal data protection may be reported, including:
- processing of personal data carried out without a valid legal basis or in violation of the principles of lawfulness, fairness, transparency, and data minimization;
- failure to adopt adequate technical and organizational measures to ensure the security of personal data, including unauthorized access, loss or undue disclosure of data;
- failure to manage obligations relating to the personal data breach, including failure to notify the supervisory authority and, where applicable, the data subjects;
- violations of data subject rights, including the right to access, rectification, erasure, restriction of processing, data portability, and objection.
4.3 Violations of digital operational resilience regulations
Pursuant to Regulation (EU) 2022/2554 (DORA), violations, or reasonable suspicions of violations, of the legislation on digital operational resilience may be reported, including:
- deficiencies in the management of information and communications technology (ICT) risks, including security systems, processes and controls;
- inadequate management of cyber incidents and failure to adopt response and recovery measures;
- failure to report or incomplete reporting of serious ICT incidents to the competent authorities, in the cases provided for by the legislation.
4.4 Violations of internal procedures
Violations, or reasonable suspicions of violations, of internal procedures, company policies, and organizational controls adopted by the Company may be reported, in compliance with applicable legislation and the principles of good governance. By way of example, this scope includes:
- failure to comply with the management, control and monitoring processes provided for by internal operating procedures;
- violations of IT security policies and corporate systems and data protection measures;
- behaviors that do not comply with the company's Code of Ethics and the Company's principles of integrity, fairness, and transparency;
- deficiencies or circumventions of internal control systems and compliance mechanisms;
- conduct that does not comply with the organizational and governance obligations set forth by applicable legislation.
4.5 What CANNOT be reported through this channel
Reports that do not concern significant wrongdoing under applicable law are not covered by this whistleblowing system. For example, the following are not included in this system:
- personal complaints relating to one's employment or business relationships, which must be handled through the ordinary channels made available by the Company;
- differences of opinion on management or strategic choices, in the absence of elements that could constitute a violation or an illicit act;
- reports made in bad faith or with abuse of the reporting tool;
- information already in the public domain, unless it is connected to potentially significant illegal activities;
- reports relating to suspicious money laundering or terrorist financing transactions, which must be transmitted through dedicated AML channels, except in cases where they concern deficiencies or violations of the relevant control mechanisms;
- complaints relating to products or services, to be handled through the Company's complaints procedure.
How to report — the three channels
The Company provides whistleblowers with a reporting system compliant with current legislation, designed to ensure confidentiality, security, and protection of the whistleblower. Reports can also be submitted anonymously. However, providing personal contact information can facilitate any requests for clarification or updates.
The Company issues an acknowledgement of receipt of the report within 7 days, in accordance with the applicable whistleblowing legislation.
5.1 Official Internal Channel — MITWhistle Platform
Official reporting channel
The official internal channel for submitting reports is the dedicated digital platform MITWhistle, which allows written and anonymous reports, confidential communication with the report manager, data protection through encrypted systems, and separation between the identity of the reporter and the content of the report.
Access the MITWhistle platformThe access link to the platform is provided by the Company. If you do not have the link, please contact the Compliance Officer.
The system is provided by a specialized external provider. Personal data is handled in compliance with current legislation, and privacy roles are defined in accordance with the GDPR.
5.2 Residual alternative channel
Alternatively, and only if it is not possible to use the platform, it is possible to:
- request a direct and confidential interview with the Compliance Officer;
- submit a report via confidential written communication.
These channels guarantee the confidentiality of the whistleblower and are managed according to the same protections provided by the legislation.
5.3 External channel — Competent authorities
Where the conditions set out in the applicable legislation are met, the whistleblower may make a report through external channels by contacting the competent authorities designated under the Protected Disclosures Act 2014 (as amended) (cd. "Prescribed Persons"), in relation to the nature of the reported violation. By way of example, such authorities may include:
- Central Bank of Ireland, for financial violations;
- Data Protection Commission, for violations of personal data protection;
- Workplace Relations Commission, for workplace issues.
The use of the external channel is permitted, among others, in the following cases:
- the internal channel is not active or does not comply with applicable regulations;
- the internal report has already been made and has not been adequately followed up;
- there are reasonable grounds to believe that using the internal channel could expose the whistleblower to the risk of retaliation;
- there is an imminent or manifest danger to the public interest.
Furthermore, in the cases and under the conditions established by applicable legislation, the possibility of making a public disclosure of the information remains unchanged.
5.4 Public disclosure
In the cases provided for by the legislation, the whistleblower may make a public disclosure of the information, for example through the press or media, if:
- no follow-up has been given to an internal or external report;
- there is an imminent or obvious danger to the public interest;
- there is reasonable cause to believe that the report will not receive adequate response.
Content of the report
To enable effective management of the report, it is useful —but not mandatory— to provide the following information:
- description of the reported facts (what happened, in what context and with what frequency, if any);
- dates or periods in which the events occurred;
- place where the events occurred;
- subjects involved, if known;
- any supporting documentation (emails, contracts, screenshots, system logs, other);
- how the facts were learned.
The whistleblower does not need to be absolutely certain that the violation has occurred: it is sufficient to have reasonable grounds to believe that the reported facts are true. Pursuant to applicable law, the whistleblower's protection applies even if subsequent investigations demonstrate that the reported facts were unfounded, provided the report was made in good faith and based on reasonable evidence.
Protection measures for the whistleblower
The Company guarantees maximum protection to those who report in good faith, in compliance with applicable legislation.
7.1 Confidentiality of identity
The identity of the whistleblower is treated with the utmost confidentiality. It is known exclusively by those authorized to manage the report and is not disclosed to third parties without the explicit consent of the reporting party. All reports and documents relating to the reporting are prepared in such a way as not to contain references that could allow the identification of the reporting person.
The identity of the whistleblower may be revealed only in the following cases provided by law:
- legal obligation, at the request of the Judicial Authority in the context of criminal investigations;
- defense needs of the accused, within the limits and according to the guarantees provided by the judicial authority;
- with the explicit consent of the whistleblower.
7.2 Absolute prohibition of retaliation
The Company prohibits any form of retaliation, discrimination, or prejudicial behavior toward the whistleblower, his or her colleagues, or his or her family members as a result of the report. The following are considered retaliation, for example:
- dismissal, suspension or failure to renew the contract;
- demotion, transfers or worsening changes in working conditions;
- reduction in pay or benefits;
- negative evaluations not justified by objective criteria;
- failure to promote or advance;
- acts of mobbing, isolation or undue pressure;
- interruption or worsening of the commercial relationship (for external parties).
A whistleblower who believes he or she has suffered retaliation may:
- use the Company's internal reporting channel;
- contact, in the cases provided for by the applicable legislation, the designated competent authorities (so-called prescribed persons);
- avail of any additional legal remedies available, including, where applicable, public disclosure.
7.3 Extended Protection
The protections provided by this Procedure also extend to:
- Facilitators: people who assist the whistleblower in the reporting process (legal, trade union representative);
- Colleagues and family members of the whistleblower who may suffer retaliation in connection with the report;
- Entities controlled by the whistleblower: companies or entities where the whistleblower works or in which he or she holds shares.
7.4 Processing of the whistleblower's personal data
The personal data of the whistleblower are processed in compliance with Regulation (EU) 2016/679 and applicable national legislation, including the Data Protection Act 2018. The processing occurs exclusively for purposes related to managing the report and is based on compliance with a legal obligation pursuant to the GDPR. The data is retained for the time strictly necessary to manage the report and in any case no longer than 5 years after the closure of the proceeding, unless otherwise required by law.
For further information, please refer to the privacy policy available on the company website.
How we handle reports
The Company adopts a structured process for managing reports divided into six phases, with timeframes defined in compliance with the terms established by applicable legislation:
| Phase | Timing | Activity | Responsible |
|---|---|---|---|
| 1. Reception | Day 0 | Receipt of the report via the MITWhistle platform, automatic logging and registration in the confidential register of reports, with segregation of the reporting person's identifying information. | Compliance Officer / MITWhistle System |
| 2. Confirmation | Within 7 days | Sending of the acknowledgement of receipt to the reporting party via the platform, with assignment of the practice code and indication of the management times. | Compliance Officer |
| 3. Evaluation | Within 30 days | Analysis of the admissibility of the report, assessment of the seriousness and urgency, and possible request for additions to the reporting party. | Compliance Officer |
| 4. Investigation | Within 90 days of receipt | Gathering documentation from those involved, conducting hearings with those involved, conducting technical checks, and conducting regulatory analysis. External consultants may be involved, ensuring confidentiality is maintained. | Compliance Officer + any consultants |
| 5. Resolution | Within 90 days of receipt | Presentation of reports to the Board of Directors, resolution on corrective and/or disciplinary actions to be taken. | Board of Directors on the proposal of the Compliance Officer |
| 6. Feedback | Within 90 days of receipt | Communication of the outcome to the whistleblower (within the limits permitted by confidentiality), initiation of the corrective actions decided upon. | Compliance Officer |
Management of conflicts of interest
The Company has established specific measures to ensure the independent management of reports in cases where conflicts of interest may arise.
9.1 Reporting to the Compliance Officer
If a report concerns the Compliance Officer, it is managed through the MITWhistle platform and assigned directly to the Chairman of the Board of Directors, who assumes responsibility for its investigation. The Compliance Officer is excluded from any access or activity related to the report.
9.2 Reporting regarding the Board of Directors
If the report concerns one or more members of the Board of Directors, management is entrusted to independent individuals with adequate autonomy, such as:
- independent members of the Board of Directors;
- audit committee, where established;
- additional independent third parties, where necessary.
Reporting can be done via:
- MITWhistle platform, selecting the option relating to "reports with conflicts of interest";
- or, in the cases provided for by applicable law, through the external channels provided for by Irish law, including designated entities (prescribed persons) under the Protected Disclosures Act 2014.
Relations with the supervisory authorities
The Company cooperates fully with the relevant authorities regarding whistleblowing, data protection, and enforcement of applicable laws. In accordance with applicable legislation, including the Protected Disclosures Act 2014, the whistleblower may, where the conditions set by law apply, also make reports to external parties (so-called prescribed persons) or to the competent authorities.
The main categories of competent authorities may include, but are not limited to:
- competent authorities designated under the whistleblowing legislation (prescribed persons);
- competent data protection authorities, including the Irish Data Protection Commission;
- competent judicial or investigative authorities, in the cases provided for by law;
- any other applicable sectoral supervisory authorities.
The Company guarantees that the use of the internal channel does not in any way prejudice the reporting party's right to use the external channels provided for by applicable legislation.
Training and communication
The Company undertakes to ensure that all subjects to whom this Procedure is addressed are adequately informed and trained on the Whistleblowing System:
- mandatory training for all staff upon hiring and with periodic refresher courses;
- communication of this Procedure to all collaborators, consultants and relevant subjects of the commercial network;
- publication of the Procedure on the website in the dedicated section;
- making reporting channels available.
Procedure updates
This Procedure is subject to annual review by the Compliance Officer and the Board of Directors, or whenever significant regulatory changes or events require its updating. Any changes are approved by the Board of Directors and promptly communicated to all staff. The updated version is always available on the company website in the section dedicated to Whistleblowing.


