1.General provisions and scope
This Privacy Policy (hereinafter referred to as the “Policy”) describes how [name of legal entity] (hereinafter referred to as the “Company”, “we”) processes personal data in connection with the use of the AutoAML service, software that helps obligated entities (real estate agencies, small and medium-sized enterprises) comply with the requirements of anti-money laundering legislation.
The Policy applies to: (a) visitors to the public website; (b) registered users of your personal account (“Clients”); (c) to individuals whose data Clients upload to the service as part of their own obligations to verify counterparties (“Inspection Subjects”). The processing of data from Audit Subjects is described separately in Section 3.
We apply the General Data Protection Regulation (Regulation (EU) 2016/679 (“GDPR”) and, in relation to the storage of AML documentation, Regulation (EU) 2024/1624 (“AMLR”) and relevant national legislation.
2.Who we are and how to find us
Personal data controller (data controller in relation to account data):
| Name | [legal name of the company] |
| Registration number | [registry number] |
| Legal address | [address] |
| [email for questions about data] | |
| Representative in the EU (Article 27 GDPR) | [indicate if the Company is established outside the EEA and processes data of EU residents] |
If the Company does not have an establishment in the EEA, but the service is offered to persons in the EU, Article 27 of the GDPR will usually require the appointment of a representative in one of the Member States - this is a separate organizational task that should be completed before launching in the EU.
3.Two roles: operator and data processor
This distinction is key to understanding who is responsible for what:
| Category of data | Our role | Who determines the purpose of processing |
|---|---|---|
| Client account data (name, email, payment details, login logs) | Operator (controller) | Company |
| AML/KYC data of the Verification Subjects uploaded by the Client for screening | Processor | The Client is an obligated subject within the meaning of AMLR |
In relation to data of the second category, the Company acts on the documented instructions of the Client within the framework of the Personal Data Processing Agreement (DPA), which is an integral part of the agreement for the use of the service. The terms of the DPA take precedence in matters relating to this particular category of data.
4.What data we collect
4.1 Account information
- Identification data: name, position, email, telephone.
- Data of the client company: name, TIN/registration number, industry (to set up the risk profile of the obligated entity).
- Payment data - processed by the payment provider (see section 7); We do not store full card numbers.
- Technical data: IP address, device and browser type, event and system activity logs (for auditing and security).
4.2 AML/KYC data (processed as a processor)
- Data that the Client uploads to verify counterparties: name, date of birth, citizenship, identification document, address, beneficial ownership information, source of funds.
- Screening results against sanctions lists, PEP (public official) and adverse media lists obtained through third-party providers.
- Draft risk assessments and suspicious transaction reports (SAR/STR), generated using the AI functions of the service.
Important. Some of the data in this category relates to special categories of personal data (for example, information from identity documents, in some cases, criminal records). Their processing is permitted on the basis of Art. 9(2)(g) GDPR - “substantial public interest” - and relevant national anti-money laundering legislation.
5.Purposes and legal grounds of processing
| Purpose | Legal basis |
|---|---|
| Registration and maintenance of an account, invoicing | Execution of the contract - Art. 6(1)(b) GDPR |
| Performing AML checks on behalf of the Client | The Client’s legal obligation is Art. 6(1)(c); for us - agreement of agency (DPA) |
| Storage of inspection documentation for a specified period | Legal obligation - Art. 6(1)(c) GDPR in conjunction with Art. 77 AMLR |
| Service improvement, usage analytics, fraud prevention | Legitimate interest - Art. 6(1)(f) GDPR |
| Marketing communications | Consent - Art. 6(1)(a) GDPR (can be revoked at any time) |
6.Retention periods
We store data for no longer than is necessary for the purposes specified in section 5, subject to the following guidelines:
- Account data - during the term of the agreement and up to [X] years after its termination (for accounting and tax purposes).
- AML/KYC documentation and inspection results - at least 5 years from the end of the business relationship between the Client and the Subject of the inspection, as required by Art. 77 AMLR; a specific period may be extended at the reasonable request of the competent authority, but not more than for an additional 5 years.
- Security and audit logs - [X months/years], depending on incident investigation requirements.
After expiration of the deadlines, the data is deleted or anonymized irrevocably, unless longer storage is expressly required by law.
7.Who do we transfer data to
We engage a limited circle of verified sub-processors, with each of whom an agreement has been concluded for the processing of personal data under conditions no less stringent than those provided for in this Policy:
| Category | Supplier example | Purpose |
|---|---|---|
| Screening for sanctions / PEP / KYC | Sumsub / ComplyAdvantage / ComplyCube / Persona | Verification of identity and reputation lists |
| Crypto-asset screening | Chainalysis / TRM Labs | AML screening of cryptocurrency addresses |
| Cloud hosting and data storage | [provider, EU region] | Storage and processing of service data |
| Payments | [payment provider] | Processing payments for subscription |
| AI models for generating drafts | [AI infrastructure provider] | Generating draft risk assessments and SAR/STR - under human control |
We do not sell personal information to third parties or share it for marketing purposes without specific consent.
A current and complete list of sub-processors is provided to Clients upon request and in annex to the DPA.
8.Data transfer outside the EEA
If data is transferred to a supplier located outside the European Economic Area, we provide the legal basis for such transfer in one of the following ways:
- decision of the European Commission on the adequacy of protection for the country concerned;
- Standard Contractual Clauses (SCC), approved by the European Commission;
- Supplier's Binding Corporate Rules (BCR) - where applicable.
A copy of the applicable warranties may be requested from the address provided in Section 16.
9.Security measures
- Data encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
- Role-based access model: employees receive access to Clients’ AML data only to the extent necessary to perform their tasks.
- Logging of actions with sensitive data and regular access auditing.
- Multi-factor authentication for administrative access and Client accounts.
- Regular security testing; incident response plan, including notification to the supervisory authority within 72 hours in accordance with Art. 33 GDPR in case of a leak that poses a risk to the rights of data subjects.
Security measures are built in advance, prior to formal ISO 27001 / SOC 2 certification, to avoid costly infrastructure modifications later.
10.Your rights
- Access (Article 15) - receive a copy of the processed data.
- Correction (Article 16) - demand correction of inaccurate data.
- Deletion (Article 17) - with a caveat: in relation to AML documentation, this right is limited by the mandatory storage period under Art. 77 AMLR.
- Restriction of processing (Article 18).
- Data portability (Article 20) – applies to data provided by you independently based on consent or contract.
- Objection (Article 21) – regarding processing based on legitimate interest, including direct marketing.
- Withdrawal of consent - at any time, without retroactive effect for processing already performed.
If data about you as a Review Subject is processed by us as a processor on behalf of a Client, the relevant request to exercise rights should be made directly to that Client as a data processor; We assist the Client in fulfilling such a request in accordance with the DPA.
11.Cookies and analytics
The public website and personal account use strictly necessary cookies (for authorization and security) and, with your consent, analytical cookies to understand the use of the service. A detailed list of cookies and how to manage them is provided in [consent banner / separate Cookie Policy page].
12.Automated decisions and AI functions
The Service uses AI models to help the Client prioritize alerts, generate draft risk assessments and suspicious transaction reports. We do not accept or allow the service to make fully automated decisions that have legal consequences for Review Subjects, without meaningful human participation: any draft generated by AI requires review and confirmation by an authorized Client employee (for example, a compliance officer or MLRO) before it is used.
13.Children
The Service is intended for use by legal entities and their employees and is not intended for persons under 18 years of age. We do not knowingly collect data from children as users of the service.
14.Changes to this Policy
We may update the Policy as the service or legislation changes. We will notify you of significant changes by email at least [14/30] days before they come into force. The date of last update is indicated at the beginning of the document.
15.Complaints and supervisory authority
If you believe that the processing of your data violates the GDPR, you have the right to contact us directly (section 16) or lodge a complaint with the data protection supervisory authority of your country of residence or the country where the violation allegedly occurred. Supervisory authority at the place of establishment of the Company: [name of authority and link].
16.How to contact us
For questions related to this Policy and the processing of personal data:
| Data Protection Officer (DPO) | [name / role if assigned] |
| [privacy@domain] | |
| Mail address | [address] |