Risk Disclosure
Crypto-assets and the related custody, exchange and payment services involve substantial risk. You may lose some or all of a crypto-asset’s value and may temporarily or permanently lose access to assets or funds. |
|---|
Read this document together with the Multi-Party Terms of Use, Custody Services Schedule, Exchange and Fiat Services Schedule, Fees and Limits Schedule, AML/KYC Notice and Privacy Notice. If you do not understand a risk or cannot bear its consequences, do not use the affected service.
Contents
1. Purpose and legal effect | 13. Cybersecurity and fraud |
|---|---|
2. Provider model and allocation | 14. Availability and operational risks |
3. No advice or guarantee | 15. Compliance and sanctions risks |
4. Crypto-asset value and volatility | 16. Legal, territorial and enforcement risks |
5. Stablecoin and token risks | 17. Forks, airdrops and unsupported features |
6. Custody and key-control risks | 18. Tax and accounting risks |
7. Omnibus, records and insolvency | 19. Privacy and public-blockchain risks |
8. Blockchain and protocol risks | 20. Provider change and exit risks |
9. Deposit and withdrawal risks | 21. Risk-reduction measures |
10. Exchange, pricing and liquidity | 22. Acknowledgement, support and language |
11. Fiat, vIBAN and payment risks | 23. Definitions |
12. Third-party and concentration risks |
Key risk summary
Risk area | What may happen | Practical response |
|---|---|---|
Loss of value | A crypto-asset or stablecoin may lose most or all value, become illiquid or be delisted. | Use only amounts you can afford to lose; do not rely on past performance or marketing. |
Custody | Key compromise, ledger error, legal process or provider insolvency may delay or reduce recovery. | Protect account access; review custody terms and records; avoid excessive concentration. |
Irreversibility | A wrong address, network, tag or authorized scam payment may be impossible to reverse. | Verify full details independently and use a test transaction where appropriate. |
Exchange | Quotes may expire; spreads, slippage, liquidity and third-party failures may change the result. | Review the accepted confirmation, fees and amount received before approving. |
Fiat payments | Banks and payment providers may delay, return, deduct, freeze or recall payments. | Use only displayed payment details and an account held in your name unless approved. |
Cyber fraud | Phishing, malware, impersonation or account takeover may cause irreversible loss. | Use multi-factor authentication; never share passwords, one-time codes or seed phrases. |
Compliance | Sanctions, fraud or source-of-funds checks may restrict access or transactions. | Keep verification information current and respond promptly to lawful requests. |
Legal change | New law, sanctions, tax rules or provider restrictions may change or end a service. | Maintain records and be prepared to withdraw, return or migrate assets. |
1. Purpose and legal effect
1.1 This Risk Disclosure forms part of the Plumex Multi-Party Terms of Use and explains material risks associated with the Platform, Custody Service, Exchange Service and Fiat Service.
1.2 It is not exhaustive. Risks may arise from the specific asset, network, payment method, provider, user circumstances, market conditions or legal environment and may change rapidly.
1.3 You should use a service only after understanding the applicable Terms, Schedules, fees, transaction details and risks. Do not use funds or crypto-assets that you cannot afford to lose or have unavailable for an extended period.
1.4 This Disclosure does not waive mandatory rights, reduce a provider’s contractual obligations or exclude liability that cannot lawfully be excluded.
2. Provider model and allocation of risk
2.1 Plum Labs s.r.o. provides the Platform and general platform support. It does not provide custody, exchange or fiat services and does not become responsible for those services merely because they are accessed through the App.
2.2 Capitalista S.A. provides the Custody Service under the Custody Services Schedule and is responsible for custody-specific records, withdrawals, restrictions, complaints and service exit.
2.3 Innovate Payments Inc. (“IPI”) acts as direct counterparty and principal for supported exchange and fiat transactions under the Exchange and Fiat Services Schedule.
2.4 LMLP consulting s.r.o. provides non-contracting technical, identity-verification and routing support. PSP (TBD), Sumsub, AMLBot and other disclosed providers may support payments, verification, screening, infrastructure or operations.
2.5 A failure, restriction or insolvency affecting one provider may interrupt other services even though each provider remains responsible only for its allocated obligations.
3. No advice, suitability or guarantee
3.1 No provider gives investment, trading, legal, tax or financial-planning advice through the ordinary operation of the Platform. Prices, charts, educational content and support communications are general information.
3.2 Availability of an asset or service does not mean that it is suitable, safe, recommended or expected to increase in value.
3.3 Past performance, historical prices, market capitalization, reserve attestations, ratings or promotional statements do not predict future performance.
3.4 No provider guarantees profit, preservation of capital, a fixed exchange rate, continuous liquidity, transaction acceptance, processing time, uninterrupted access, recovery of an unsupported transfer or protection from fraud.
3.5 Registration of IPI with the Financial Transactions and Reports Analysis Centre of Canada or the Bank of Canada is not a licence, investment recommendation, endorsement, insurance or government guarantee. App-store availability is not regulatory approval.
4. Crypto-asset value and volatility
4.1 Crypto-asset prices may change materially within seconds and may be affected by speculation, market concentration, leverage, news, social media, technology, regulation, macroeconomic events and manipulation.
4.2 A crypto-asset may lose most or all of its value. There may be no buyer, reliable price or practical method of converting it to fiat currency when you wish to sell.
4.3 Market prices may differ between venues, currencies and regions. A Platform display may be delayed, indicative or based on third-party data and may differ from the price available when IPI accepts an order.
4.4 Using borrowed funds, emergency savings or assets needed for essential expenditure materially increases the consequences of loss.
5. Stablecoin, issuer and token-specific risks
5.1 A stablecoin may fail to maintain its reference value because of reserve, issuer, custodian, banking, redemption, liquidity, governance, legal, sanctions or market risks.
5.2 A stablecoin is not automatically a bank deposit, electronic money, legal tender or a claim protected by a deposit-guarantee scheme. Redemption may be unavailable, delayed, limited or subject to issuer terms.
5.3 Token smart contracts may contain vulnerabilities, administrative keys, transfer restrictions, blacklisting, pausing, upgrade or freezing functions. An issuer or authority may restrict or invalidate transfers.
5.4 Wrapped, bridged or synthetic assets add dependency on smart contracts, validators, bridges, reserve assets and third-party operators and may lose value independently of the referenced asset.
5.5 The provider may suspend or remove support for an asset if its legal, technical, market, security or liquidity risk becomes unacceptable.
6. Custody and private-key-control risks
6.1 The Custody Service is custodial. Capitalista, or infrastructure used by it, controls the signing process and private keys required to transfer supported custody assets. You do not directly control those keys.
6.2 Loss, theft, compromise, misuse or unavailability of keys, signing systems, credentials, personnel or infrastructure may cause delay, unauthorized transfer or loss.
6.3 Security controls may require withdrawal reviews, limits, waiting periods, address whitelisting, additional authentication or temporary restrictions. These controls can delay access even where no wrongdoing is established.
6.4 No security system is immune from cyberattack, insider misconduct, human error, supply-chain compromise, software defect or physical disruption.
6.5 Insurance, if any, may be limited, subject to exclusions, paid to the provider rather than the user or insufficient to cover all losses. Do not assume insurance unless expressly confirmed in the Custody Services Schedule.
7. Omnibus wallets, custody records and insolvency risks
7.1 Capitalista may use individual addresses, omnibus wallets or a combination of wallet structures. In an omnibus structure, blockchain records may not identify your individual entitlement; entitlement depends on Capitalista’s internal ledger and reconciliation.
7.2 Ledger, reconciliation, allocation or operational errors may temporarily cause differences between the Platform display, custody records and blockchain balances.
7.3 The legal effectiveness of segregation, your proprietary or contractual claim and the treatment of assets in insolvency may depend on the custody structure, records, governing law, facts and decisions of a court or insolvency official.
7.4 The Terms do not represent that custody assets are bankruptcy remote. If Capitalista or a critical custodian or infrastructure provider becomes insolvent, access and recovery may be delayed, disputed, reduced or unavailable.
7.5 Assets may be temporarily unavailable during reconciliation, security incidents, legal process, provider replacement or orderly return.
8. Blockchain, network and protocol risks
8.1 Public blockchains operate independently of the providers. No provider controls block production, confirmations, transaction ordering, network fees, validators, miners, protocol governance or finality.
8.2 Transactions may be delayed, rejected, reorganized, replaced, duplicated, censored or become permanently irreversible. A confirmed transaction may be affected by a chain reorganization or protocol failure.
8.3 Network congestion, denial-of-service attacks, validator concentration, software bugs, consensus failure, quantum or cryptographic developments and changes to network economics may impair an asset or network.
8.4 Smart-contract interactions may fail or behave unexpectedly. Code may contain undiscovered vulnerabilities or dependencies outside provider control.
8.5 Network fees may rise sharply and may exceed the transferred amount. Fees paid to a network are generally not refundable.
9. Deposit, withdrawal and transfer risks
9.1 Sending an unsupported asset, using the wrong network, entering an incorrect address, omitting or entering an incorrect tag or memo, or sending below a minimum amount may cause permanent loss or make recovery impracticable.
9.2 A deposit is not credited until the required confirmations, screening, allocation and technical checks are completed. A blockchain receipt does not by itself prove acceptance or correct allocation.
9.3 A withdrawal may be delayed by authentication, security review, compliance checks, network congestion, provider limits or third-party infrastructure.
9.4 Address poisoning, clipboard malware, QR-code substitution and impersonation may cause you to authorize a transfer to an attacker. Always verify the complete address, network and recipient using an independent method.
9.5 Recovery of an unsupported or incorrectly addressed transfer is not guaranteed and may require technical feasibility, proof of ownership, additional checks and payment of recovery costs.
10. Exchange, pricing, liquidity and execution risks
10.1 A quote may be indicative, time-limited or subject to acceptance. Market movement, liquidity, payment confirmation or technical delay may cause expiry, rejection or a new quote.
10.2 The transaction price may include a spread and may differ from prices shown on other platforms. Fees, network costs and payment-provider charges reduce the amount received.
10.3 Low liquidity, market stress, large orders or venue disruption may cause slippage, partial execution, execution delay or inability to execute at any reasonable price.
10.4 IPI may use liquidity or settlement providers. Their failure, insolvency, suspension, pricing error or operational restriction may delay or prevent execution or settlement.
10.5 An order may be rejected for compliance, payment, liquidity, pricing, technical or legal reasons. Submission of an order does not guarantee acceptance.
11. Fiat funds, vIBAN, payment and safeguarding risks
11.1 A virtual International Bank Account Number (vIBAN) or payment reference may be a routing identifier rather than a bank account opened in your name. The displayed account holder, beneficiary and payment instructions control the specific flow.
11.2 Fiat funds may pass through IPI, PSP (TBD), correspondent banks, payment institutions, banks or other providers. Payment chains may create delay, additional fees, returns, screening, cut-off times and information requests.
11.3 Where IPI holds end-user funds and safeguarding requirements apply, the legal method and operational arrangements are intended to protect access and insolvency recovery, but they do not eliminate bank, trustee, insurer, guarantor, reconciliation, liquidity, fraud, legal or operational risk.
11.4 Fiat balances are not necessarily bank deposits and may not be covered by a deposit-guarantee or investor-compensation scheme. Safeguarding is not the same as deposit insurance.
11.5 Incorrect payer details, third-party payments, missing references, payment recalls, chargebacks, bank rejection, capital controls or correspondent-bank deductions may delay, reduce or reverse a transfer.
11.6 Foreign-exchange rates, bank charges, intermediary fees and timing differences may result in the user receiving less than expected.
12. Third-party, outsourcing and concentration risks
12.1 The services depend on payment providers, banks, liquidity providers, blockchain nodes, cloud services, identity-verification services, analytics, telecommunications, app stores and other third parties.
12.2 A third-party outage, termination, cyber incident, licence or registration issue, sanctions restriction, insolvency or policy change may interrupt a service even where the responsible provider remains operational.
12.3 Concentration in one bank, cloud region, blockchain, stablecoin issuer, liquidity provider or technology vendor can amplify the effect of a single failure.
12.4 Replacement of a critical provider may require new verification, changed payment details, service suspension, asset migration or acceptance of updated terms.
13. Cybersecurity, fraud and account-takeover risks
13.1 Crypto services are targets for phishing, malware, SIM swapping, impersonation, social engineering, remote-access scams, false support, investment scams, romance scams, invoice fraud and address substitution.
13.2 Transactions authorized under deception may be irreversible and may not qualify as unauthorized solely because you were manipulated into approving them.
13.3 Compromise of your device, email, password, one-time code, biometric method or session may allow an attacker to access the account or submit instructions.
13.4 No provider will ask for your private key, seed phrase, password or one-time authentication code. A request for such information is likely fraudulent.
13.5 Provider controls may not detect every scam or unauthorized instruction. You remain responsible for independently checking the recipient, purpose and transaction details.
14. Availability, operational and business-continuity risks
14.1 Services may be unavailable or degraded because of maintenance, software defects, cyber incidents, telecommunications or power failure, network congestion, banking hours, liquidity, human error, provider outage, natural disaster, war, emergency measures or other events.
14.2 Displayed balances, prices, fees or status may be delayed, incomplete or temporarily inaccurate. A pending or processing status is not final settlement.
14.3 Backups, disaster recovery, incident response and alternative providers reduce but do not eliminate the risk of data loss, prolonged outage or operational failure.
14.4 Support response and transaction processing may take longer during high demand, market stress, security incidents or public holidays.
14.5 No provider guarantees no downtime, uninterrupted access or a fixed completion time.
15. Compliance, sanctions and legal-hold risks
15.1 Providers may conduct identity, residence, location, sanctions, politically exposed person, source-of-funds, source-of-wealth, wallet-ownership, fraud and blockchain-risk checks before and during the relationship.
15.2 A transaction or service may be delayed, rejected, frozen, returned, reported, restricted or terminated because of law, sanctions, court or authority orders, suspicious activity, provider policy, payment-provider requirements or risk controls.
15.3 Screening tools may produce false positives or incomplete results. Additional documents, explanations or human review may be required and can delay access or settlement.
15.4 A provider may be prohibited from explaining the reason for a report, investigation, law-enforcement request or confidential restriction.
15.5 Sanctions, restricted-country rules and blockchain exposure can change without notice and may affect assets or counterparties that were previously acceptable.
16. Legal, territorial, regulatory and enforcement risks
16.1 Crypto, custody, exchange, payment, tax, sanctions, consumer and data-protection laws are developing and may change rapidly or be interpreted differently by authorities and courts.
16.2 A legal or regulatory change may prohibit a service, require additional verification, change fees or taxes, restrict transfers, require reporting, delist an asset, freeze funds or require an orderly exit.
16.3 The Ukraine Service Route excludes users resident or located in the European Union or European Economic Area. Incorrect residence or location information may lead to restriction and legal consequences.
16.4 Providers are located in different jurisdictions. Cross-border complaints, court proceedings, insolvency and enforcement may be slower, more expensive or less effective than domestic proceedings.
16.5 Choice-of-law clauses do not remove mandatory consumer protections, but determining and enforcing those protections may require legal advice and proceedings in more than one jurisdiction.
17. Forks, airdrops, staking, rewards and unsupported features
17.1 A blockchain may split, upgrade, migrate or create a new asset. Providers may choose which chain or asset to support based on security, legal, technical and operational factors.
17.2 You have no entitlement through the services to an airdrop, forked asset, staking reward, governance right, promotional reward or other distribution unless the applicable Schedule or App expressly confirms support.
17.3 Staking, lending, yield, derivatives, leverage, margin, decentralized-finance and similar features are not included in the Ukraine v1 route unless separately introduced under specific terms and disclosures.
17.4 An unsupported feature or blockchain event may require suspension, migration or conversion and may result in delay or loss of opportunity.
18. Tax, accounting and reporting risks
18.1 Buying, selling, exchanging, transferring, receiving or holding crypto-assets may create tax, reporting, accounting or record-keeping obligations.
18.2 Tax treatment may depend on residence, purpose, frequency, cost basis, holding period, asset classification and changes in law. A crypto-to-crypto exchange may be taxable even without a fiat withdrawal.
18.3 Providers do not determine your tax liability and may not provide complete tax reports for your circumstances.
18.4 You are responsible for maintaining records, obtaining professional advice and making required filings and payments.
19. Privacy, identity and public-blockchain risks
19.1 Identity verification and financial-crime controls may require sensitive personal data, identity documents, biometric or liveness data, financial records, wallet addresses and transaction information.
19.2 Data may be transferred internationally among the providers and supporting vendors. Contractual and security measures reduce but do not eliminate unauthorized-access, breach, government-access and cross-border-enforcement risk.
19.3 Public blockchain transactions are generally visible, persistent and difficult or impossible to delete. Combining blockchain data with other information may identify or profile a user.
19.4 Closing the account does not remove public blockchain records and does not require deletion of records that must be retained for legal, tax, payment, compliance, fraud, security or dispute purposes.
20. Provider change, termination, migration and exit risks
20.1 A provider, payment rail, supported asset or operating structure may change because of contract termination, legal requirements, risk, insolvency, technical needs or commercial reasons.
20.2 A change may require service suspension, new verification, acceptance of updated terms, changed deposit or payment details, withdrawal, return or migration of assets and data.
20.3 Migration carries risks of delay, reconciliation error, address error, duplicate or missing records, technical incompatibility and temporary loss of access.
20.4 A user who does not accept a required provider change may need to close the affected service and withdraw or receive the return of supported assets or funds, subject to legal and compliance restrictions.
20.5 Termination does not automatically reverse completed transactions, release an asset subject to legal restriction or eliminate valid debts, complaints, records or claims.
21. Practical measures to reduce risk
21.1 Use only assets, networks, currencies and payment details displayed for the specific service and transaction. Verify the complete destination, network, tag or memo and beneficiary before confirmation.
21.2 Enable multi-factor authentication, secure your email and device, keep software updated and never share passwords, one-time codes, private keys or seed phrases.
21.3 Start with a small test transaction where appropriate and keep independent records of confirmations, bank references, wallet addresses and transaction hashes.
21.4 Do not act under pressure, follow unsolicited investment instructions, grant remote access or send assets to “support”, “recovery”, “tax” or “verification” wallets.
21.5 Diversify exposure where appropriate, consider the consequences of provider or stablecoin failure and do not hold more than you can afford to lose or have temporarily unavailable.
21.6 Review the Terms, Schedules, Fees and Limits Schedule, Privacy Notice, AML/KYC Notice and transaction confirmation and obtain independent advice where needed.
22. Acknowledgement, support, complaints and language
22.1 By using a service after this Disclosure is presented, you acknowledge that you have had an opportunity to read it and understand that crypto, custody, exchange and payment services involve a risk of delay, restriction and loss, including possible total loss of a crypto-asset’s value.
22.2 Your acknowledgement does not waive mandatory rights or excuse a provider from liability for fraud, wilful misconduct, gross negligence, failure to exercise legally required care or another liability that cannot lawfully be excluded.
22.3 General support is available at support@plumex.io. Complaints may be submitted to complaints@plumex.io and will be routed to the provider responsible for the relevant service.
22.4 This Disclosure is published in English and Ukrainian. For the Ukraine Service Route, the Ukrainian version prevails in the event of inconsistency, unless mandatory law requires otherwise.
22.5 If this Disclosure conflicts with a provider-specific Schedule concerning a specific service, that Schedule prevails for that service. The Multi-Party Terms of Use govern the overall contractual relationship.
23. Definitions
“App” the Plumex mobile application published by Plum Labs.
“Capitalista” Capitalista S.A., provider of the Custody Service.
“Custody Service” the receipt, holding, recording and authorized transfer or withdrawal of supported crypto-assets provided by Capitalista.
“Exchange Service” a supported crypto-to-crypto transaction provided by IPI as principal.
“Fiat Service” a supported fiat-to-crypto, crypto-to-fiat or related fiat-transfer service provided by IPI.
“IPI” Innovate Payments Inc., provider and principal for the Exchange Service and Fiat Service.
“Platform” the Plumex software, interface, platform account and related technology operated by Plum Labs.
“Provider” Plum Labs, Capitalista or IPI when acting in relation to its allocated service.
“Schedule” a provider-specific or subject-specific document incorporated into the Multi-Party Terms of Use.
“Stablecoin” a crypto-asset designed or represented as seeking to maintain a value relative to a currency, asset or basket, without any guarantee that the reference value will be maintained.
“Ukraine Service Route” the service configuration intended for eligible users under the Ukraine App Store storefront and residence and actual-location controls.