Legal document · Version 1.0

Privacy Policy

Effective from: August 5, 2026Original language: EnglishController: [legal entity name]

Briefly and to the point - Art. 12 GDPR requires “clear and simple language”

This summary does not replace the full text below and is not a legal document in itself.

Base: Art. 12–14 GDPR

1.General provisions and scope

This Privacy Policy (hereinafter referred to as the “Policy”) describes how [name of legal entity] (hereinafter referred to as the “Company”, “we”) processes personal data in connection with the use of the AutoAML service, software that helps obligated entities (real estate agencies, small and medium-sized enterprises) comply with the requirements of anti-money laundering legislation.

The Policy applies to: (a) visitors to the public website; (b) registered users of your personal account (“Clients”); (c) to individuals whose data Clients upload to the service as part of their own obligations to verify counterparties (“Inspection Subjects”). The processing of data from Audit Subjects is described separately in Section 3.

We apply the General Data Protection Regulation (Regulation (EU) 2016/679 (“GDPR”) and, in relation to the storage of AML documentation, Regulation (EU) 2024/1624 (“AMLR”) and relevant national legislation.

Base: Art. 13(1)(a) GDPR

2.Who we are and how to find us

Personal data controller (data controller in relation to account data):

Name[legal name of the company]
Registration number[registry number]
Legal address[address]
Email[email for questions about data]
Representative in the EU (Article 27 GDPR)[indicate if the Company is established outside the EEA and processes data of EU residents]

If the Company does not have an establishment in the EEA, but the service is offered to persons in the EU, Article 27 of the GDPR will usually require the appointment of a representative in one of the Member States - this is a separate organizational task that should be completed before launching in the EU.

Base: Art. 4(7)–4(8), 28 GDPR

3.Two roles: operator and data processor

This distinction is key to understanding who is responsible for what:

Category of dataOur roleWho determines the purpose of processing
Client account data (name, email, payment details, login logs)Operator (controller)Company
AML/KYC data of the Verification Subjects uploaded by the Client for screeningProcessorThe Client is an obligated subject within the meaning of AMLR

In relation to data of the second category, the Company acts on the documented instructions of the Client within the framework of the Personal Data Processing Agreement (DPA), which is an integral part of the agreement for the use of the service. The terms of the DPA take precedence in matters relating to this particular category of data.

Base: Art. 13(1)(c), 14(1)(d) GDPR

4.What data we collect

4.1 Account information

  • Identification data: name, position, email, telephone.
  • Data of the client company: name, TIN/registration number, industry (to set up the risk profile of the obligated entity).
  • Payment data - processed by the payment provider (see section 7); We do not store full card numbers.
  • Technical data: IP address, device and browser type, event and system activity logs (for auditing and security).

4.2 AML/KYC data (processed as a processor)

  • Data that the Client uploads to verify counterparties: name, date of birth, citizenship, identification document, address, beneficial ownership information, source of funds.
  • Screening results against sanctions lists, PEP (public official) and adverse media lists obtained through third-party providers.
  • Draft risk assessments and suspicious transaction reports (SAR/STR), generated using the AI ​​functions of the service.

Important. Some of the data in this category relates to special categories of personal data (for example, information from identity documents, in some cases, criminal records). Their processing is permitted on the basis of Art. 9(2)(g) GDPR - “substantial public interest” - and relevant national anti-money laundering legislation.

Base: Art. 6(1) GDPR

5.Purposes and legal grounds of processing

PurposeLegal basis
Registration and maintenance of an account, invoicingExecution of the contract - Art. 6(1)(b) GDPR
Performing AML checks on behalf of the ClientThe Client’s legal obligation is Art. 6(1)(c); for us - agreement of agency (DPA)
Storage of inspection documentation for a specified periodLegal obligation - Art. 6(1)(c) GDPR in conjunction with Art. 77 AMLR
Service improvement, usage analytics, fraud preventionLegitimate interest - Art. 6(1)(f) GDPR
Marketing communicationsConsent - Art. 6(1)(a) GDPR (can be revoked at any time)
Base: Art. 77 AMLR; Art. 5(1)(e) GDPR

6.Retention periods

We store data for no longer than is necessary for the purposes specified in section 5, subject to the following guidelines:

  • Account data - during the term of the agreement and up to [X] years after its termination (for accounting and tax purposes).
  • AML/KYC documentation and inspection results - at least 5 years from the end of the business relationship between the Client and the Subject of the inspection, as required by Art. 77 AMLR; a specific period may be extended at the reasonable request of the competent authority, but not more than for an additional 5 years.
  • Security and audit logs - [X months/years], depending on incident investigation requirements.

After expiration of the deadlines, the data is deleted or anonymized irrevocably, unless longer storage is expressly required by law.

Base: Art. 28, 44–49 GDPR

7.Who do we transfer data to

We engage a limited circle of verified sub-processors, with each of whom an agreement has been concluded for the processing of personal data under conditions no less stringent than those provided for in this Policy:

CategorySupplier examplePurpose
Screening for sanctions / PEP / KYCSumsub / ComplyAdvantage / ComplyCube / PersonaVerification of identity and reputation lists
Crypto-asset screeningChainalysis / TRM LabsAML screening of cryptocurrency addresses
Cloud hosting and data storage[provider, EU region]Storage and processing of service data
Payments[payment provider]Processing payments for subscription
AI models for generating drafts[AI infrastructure provider]Generating draft risk assessments and SAR/STR - under human control

We do not sell personal information to third parties or share it for marketing purposes without specific consent.

A current and complete list of sub-processors is provided to Clients upon request and in annex to the DPA.

Base: Art. 44–49 GDPR

8.Data transfer outside the EEA

If data is transferred to a supplier located outside the European Economic Area, we provide the legal basis for such transfer in one of the following ways:

  • decision of the European Commission on the adequacy of protection for the country concerned;
  • Standard Contractual Clauses (SCC), approved by the European Commission;
  • Supplier's Binding Corporate Rules (BCR) - where applicable.

A copy of the applicable warranties may be requested from the address provided in Section 16.

Base: Art. 32 GDPR

9.Security measures

  • Data encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
  • Role-based access model: employees receive access to Clients’ AML data only to the extent necessary to perform their tasks.
  • Logging of actions with sensitive data and regular access auditing.
  • Multi-factor authentication for administrative access and Client accounts.
  • Regular security testing; incident response plan, including notification to the supervisory authority within 72 hours in accordance with Art. 33 GDPR in case of a leak that poses a risk to the rights of data subjects.

Security measures are built in advance, prior to formal ISO 27001 / SOC 2 certification, to avoid costly infrastructure modifications later.

Base: Art. 15–22 GDPR

10.Your rights

  • Access (Article 15) - receive a copy of the processed data.
  • Correction (Article 16) - demand correction of inaccurate data.
  • Deletion (Article 17) - with a caveat: in relation to AML documentation, this right is limited by the mandatory storage period under Art. 77 AMLR.
  • Restriction of processing (Article 18).
  • Data portability (Article 20) – applies to data provided by you independently based on consent or contract.
  • Objection (Article 21) – regarding processing based on legitimate interest, including direct marketing.
  • Withdrawal of consent - at any time, without retroactive effect for processing already performed.

If data about you as a Review Subject is processed by us as a processor on behalf of a Client, the relevant request to exercise rights should be made directly to that Client as a data processor; We assist the Client in fulfilling such a request in accordance with the DPA.

Basis: Directive 2002/58/EC (ePrivacy)

11.Cookies and analytics

The public website and personal account use strictly necessary cookies (for authorization and security) and, with your consent, analytical cookies to understand the use of the service. A detailed list of cookies and how to manage them is provided in [consent banner / separate Cookie Policy page].

Base: Art. 22 GDPR

12.Automated decisions and AI functions

The Service uses AI models to help the Client prioritize alerts, generate draft risk assessments and suspicious transaction reports. We do not accept or allow the service to make fully automated decisions that have legal consequences for Review Subjects, without meaningful human participation: any draft generated by AI requires review and confirmation by an authorized Client employee (for example, a compliance officer or MLRO) before it is used.

Base: Art. 8 GDPR

13.Children

The Service is intended for use by legal entities and their employees and is not intended for persons under 18 years of age. We do not knowingly collect data from children as users of the service.

Base: Art. 12(1) GDPR

14.Changes to this Policy

We may update the Policy as the service or legislation changes. We will notify you of significant changes by email at least [14/30] days before they come into force. The date of last update is indicated at the beginning of the document.

Base: Art. 77 GDPR

15.Complaints and supervisory authority

If you believe that the processing of your data violates the GDPR, you have the right to contact us directly (section 16) or lodge a complaint with the data protection supervisory authority of your country of residence or the country where the violation allegedly occurred. Supervisory authority at the place of establishment of the Company: [name of authority and link].

Contacts

16.How to contact us

For questions related to this Policy and the processing of personal data:

Data Protection Officer (DPO)[name / role if assigned]
Email[privacy@domain]
Mail address[address]