Privacy Policy

Personal data, KYC information, API logs, cookies and international processing

Provider: "WEB SOLUTIONS" LLC («ՎԵԲ ՍՈԼՅՈՒՇՆՍ» ՍՊԸ)
Legal address: 11/1, Apt. 14/1, Adonts Street, Arabkir, Yerevan, Republic of Armenia
Effective date: 5 August 2026
Version: 2.0

IMPORTANT: This document forms part of the binding agreement governing use of amlkyc.tech, its dashboard, reports, applications, bots, APIs and related services.

1. Controller and scope

"WEB SOLUTIONS" LLC («ՎԵԲ ՍՈԼՅՈՒՇՆՍ» ՍՊԸ) is the controller for account, website, billing, security and direct-user data. For identity-verification or screening data submitted by a business customer about third parties, that customer normally acts as controller and AMLKYC acts as processor/service provider under its instructions, unless law or the context makes AMLKYC an independent controller.

This Policy applies to amlkyc.tech, accounts, dashboards, APIs, bots, applications, support and related services. It does not govern third-party websites or independent customer processing. It should be read with the Terms of Use and any data processing addendum.

2. Personal data we process

  • Account and contact data: name, email, telephone, organisation, role, country, credentials and authentication records.
  • Billing and commercial data: plan, invoices, payment status, transaction references and tax/business details. Full payment-card data is normally handled by payment providers.
  • Technical and security data: IP address, device, browser, operating system, timestamps, API requests, key identifiers, logs, cookies, session data, error and fraud signals.
  • Customer-submitted compliance data: wallet addresses, transaction hashes, network, counterparties, case notes, screening subjects and supporting documents.
  • KYC data where the KYC feature is used: identification details, identity-document images and metadata, selfie/video, liveness and face-match results, proof of address and verification outcomes. Biometric templates or biometric-related data may be processed where enabled and lawful.
  • Communications, support requests, feedback, consent choices and marketing preferences.
  • Public and third-party data: blockchain records, sanctions/PEP/adverse-media information, public registers and attribution labels from data providers.

3. Sources

We obtain data from you, your organisation or authorised users; devices and integrations; payment, identity and compliance vendors; public blockchains and official/public sources; cookies and analytics; and security or fraud-prevention partners. Business customers are responsible for notifying data subjects and ensuring lawful collection before uploading their data.

4. Purposes and legal bases

  • Contract: create accounts, authenticate, process requests, generate reports, provide API access, bill and support users.
  • Legitimate interests: secure and improve the Service, prevent abuse and fraud, maintain audit logs, manage claims, develop de-identified analytics and communicate with business users, balanced against individual rights.
  • Legal obligation: accounting, tax, sanctions, lawful requests, record preservation and compliance duties applicable to us.
  • Consent: non-essential cookies, certain marketing and processing requiring consent, including biometric processing where consent is the applicable basis. Consent may be withdrawn prospectively.
  • Substantial public interest or legal claims where recognised by applicable law, particularly for fraud prevention, compliance screening and establishment or defence of claims.

Where GDPR or similar laws apply, the exact basis depends on the processing context. We do not rely on consent where another lawful basis is more appropriate. We do not use KYC images or biometric templates for general-purpose facial recognition advertising.

5. Controller/processor instructions

When AMLKYC is a processor, it processes personal data only on documented customer instructions, ensures authorised personnel are bound by confidentiality, uses appropriate security, assists with rights and incident obligations as reasonably required, governs subprocessors by contract, and deletes or returns data at the end of service subject to legal retention. Customers must configure retention and access appropriately and must not instruct unlawful processing.

6. Sharing and subprocessors

We may disclose data to hosting, cloud, database, email, analytics, customer-support, cybersecurity, payment, KYC/liveness, sanctions and blockchain-data vendors; professional advisers and auditors; affiliates or successors; and competent authorities where lawfully required. We do not sell personal data or share it for cross-context behavioural advertising.

Subprocessors receive only data reasonably necessary for their tasks and are subject to confidentiality, security and data-protection obligations. A current subprocessor list should be made available on request or on the website. Business customers may contact us about material subprocessor changes where their contract provides an objection mechanism.

7. International transfers

Data may be processed in Armenia and other countries where we or our providers operate. Where required, we use recognised safeguards such as adequacy decisions, standard contractual clauses or equivalent contractual and organisational measures. Users may request information about applicable safeguards, subject to confidentiality and security restrictions.

8. Retention

  • Account and contract records: for the account term and generally up to 6 years afterwards for accounting, tax, claims and audit purposes, unless a different period is legally required.
  • Security and API logs: generally 12 months, and longer when necessary to investigate abuse, preserve evidence or meet a contractual/legal duty.
  • Support communications: generally 3 years after closure.
  • KYC documents and verification data processed for customers: according to customer instructions and plan settings; if no period is specified, no longer than reasonably necessary to complete and evidence the requested verification, subject to legal obligations.
  • Backups: deleted data may remain in protected, access-restricted backups until routine overwrite, generally within 90 days.
  • Public blockchain data cannot be altered or deleted by AMLKYC. We may retain derived risk records where necessary to protect integrity, prevent fraud or establish legal claims.

Periods are targets, not promises, and may be shortened or extended based on law, legal hold, disputes, security events and customer instructions. We periodically review and delete or de-identify data no longer needed.

9. Cookies and analytics

Strictly necessary cookies support login, security and preferences. Analytics or marketing cookies are used only where permitted and, when required, after consent. Cookie controls should identify categories, providers, purposes and durations. Disabling necessary cookies may prevent some functions. Browser signals such as “Do Not Track” are handled where legally required.

10. Automated analysis

The Service may automatically calculate risk scores, matches and verification signals. These outputs are decision-support tools and may contain false positives or negatives. Unless AMLKYC expressly determines purposes and means for its own decision, the customer decides what action to take. Customers must provide human review and safeguards where required for decisions producing legal or similarly significant effects.

11. Rights and complaints

Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, objection, withdrawal of consent and information about automated decision-making. They may also complain to the competent data-protection authority. Where we process data only for a customer, we may forward the request to that customer.

Requests must be sent to support@amlkyc.tech and should identify the person, account/customer relationship, requested right and relevant context. We may verify identity and authority, redact third-party or protected information, and refuse or charge for manifestly unfounded or excessive requests where law permits. We aim to respond within one month where GDPR applies, subject to lawful extension.

12. Security and incidents

We use risk-appropriate technical and organisational measures, including access controls, encryption in transit, credential protection, logging, monitoring, backups, vendor review and incident procedures. No service can guarantee absolute security. Users must protect credentials and notify us immediately of suspected compromise.

Where required, we notify affected customers or authorities of a personal-data breach within applicable legal timeframes. Customers remain responsible for notifications arising from their own systems, instructions and controller obligations.

13. Children and sensitive submissions

The Service is not directed to persons under 18. Do not submit a minor’s data unless legally authorised and necessary for a legitimate customer workflow. Do not submit health, genetic, political, religious, sexual-life or other special-category data unless the Service expressly supports it and you have a valid legal basis and safeguards.

14. Changes

We may update this Policy for legal, technical or operational reasons. We will post the effective date and provide reasonable notice of material changes where required. Prior versions may be requested. Material changes do not retroactively change the lawful basis for data already processed.

Contact and notices

Legal notices, privacy requests and support communications must be sent to support@amlkyc.tech. Notices to the Provider may also be delivered to its legal address: 11/1, Apt. 14/1, Adonts Street, Arabkir, Yerevan, Republic of Armenia. Electronic notices are deemed received on the next business day after transmission unless the sender receives a delivery failure notice.

APPS

The AMLKYC app — checks at your fingertips

Check addresses and transactions from your phone: Telegram bot, RuStore and App Store.

GET IN TOUCH

Have a question? Write to us

Fill in the form and we will get back to you.

GET IN TOUCH

Have a question? Write to us

Fill in the form and we will get back to you.