CONSENT

to the Processing of Personal Data When Using AML Crypto LLC Online Resources

Version dated 28 July 2026

1. General Provisions

1.1. This Consent to the Processing of Personal Data, hereinafter referred to as the “Consent,” applies when an individual provides their Personal Data through:
  • the website available at https://amlcrypto.io, including its language versions, contact forms, and individual webpages;
  • the Btrace service available at https://btrace.amlcrypto.io;
  • web interfaces associated with Btrace;
  • the Btrace Telegram bot @AMLCryptobot, provided that the user is given access to this Consent before the processing of Personal Data begins.

1.2. Depending on the user’s actions:
  • Section 3 applies when forms are completed on amlcrypto.io;
  • Section 4 applies when registering for and using Btrace;
  • Section 4 may also apply when using the Btrace Telegram bot, subject to the categories of Personal Data actually provided through the bot.

1.3. Consent is provided by:
  • the user independently selecting a checkbox that has not been pre-selected;
  • subsequently clicking the button used to submit the form, register, or continue using the relevant service;
  • clicking a separate confirmation button in the Telegram bot, where this method is used.

1.4. Consent is provided separately from:
  • the Terms of Use;
  • the Personal Data Processing Policy;
  • the Cookie and Similar Technologies Policy;
  • consent to receive advertising communications;
  • consent to the dissemination of Personal Data.

1.5. Providing this Consent does not constitute consent to receive advertising communications or to the public dissemination of the user’s Personal Data.

2. Controller Details

The Personal Data Controller is:

AML Crypto Limited Liability Company
  • abbreviated name: AML Crypto LLC;
  • Taxpayer Identification Number (INN): 9731092966;
  • Primary State Registration Number (OGRN): 1227700289695;
  • registered address: 42, Building 1, Bolshoy Boulevard, Skolkovo Innovation Center Territory, Mozhaysky Municipal District, Moscow, 121205, Russian Federation;
  • email address for Personal Data matters and withdrawal of Consent: legal@amlcrypto.io;
  • email address for general and customer enquiries: info@amlcrypto.io.
AML Crypto LLC is hereinafter referred to as the “Controller” or the “Company.”

3. Processing of Personal Data Submitted Through Forms on amlcrypto.io

3.1. Provision of Consent

By completing a form on amlcrypto.io, selecting the relevant checkbox, and submitting the form, the user freely, voluntarily, and in their own interest consents to the Controller processing their Personal Data in accordance with this Section.


3.2. Purposes of Processing

Personal Data is processed for the following purposes:
  • receiving and reviewing an enquiry;
  • contacting the user through the communication method selected by the user;
  • providing a response or the requested information;
  • determining the nature of the request and whether the relevant Service can be provided;
  • preparing a commercial proposal;
  • conducting negotiations;
  • taking actions at the user’s request before entering into an agreement;
  • arranging a consultation;
  • reviewing an application for a blockchain investigation or another Service;
  • providing customer and technical support;
  • preventing misuse and ensuring the security of forms;
  • confirming that an enquiry was submitted and Consent was provided;
  • reviewing complaints and resolving potential disputes.
Personal Data obtained through a standard enquiry form shall not be used for advertising communications without the user’s separate prior consent.


3.3. Categories of Personal Data

Depending on the fields included in the relevant form and the information voluntarily provided by the user, the Controller may process:
  • first name;
  • surname and patronymic, where provided;
  • email address;
  • telephone number;
  • username, login, or identifier in a messaging service;
  • organisation name;
  • job title;
  • country and city;
  • preferred communication method;
  • contents of the enquiry;
  • information concerning the Service in which the user is interested;
  • cryptocurrency addresses;
  • transaction hashes;
  • information concerning the circumstances of an incident;
  • information concerning digital assets and transaction amounts;
  • attached documents, images, screenshots, and files;
  • other information entered by the user in free-text fields;
  • IP address;
  • date and time of form submission;
  • webpage address and form identifier;
  • technical information concerning the device and browser;
  • information concerning the Consent provided and the applicable version of the Consent.


3.4. The Controller shall process only those categories of Personal Data from the above list that the user has actually provided or that were automatically collected when the form was submitted, to the extent necessary for security purposes and to confirm the enquiry.


3.5. This Consent applies only to the user’s own Personal Data. It does not constitute consent on behalf of third parties whose information the user may include in an enquiry or attached materials.

The user should not provide excessive information concerning third parties and must have a lawful basis for disclosing such information.


3.6. Personal Data Processing Operations

The Controller may perform the following operations:
  • collection;
  • recording;
  • organisation;
  • accumulation;
  • storage;
  • clarification and updating;
  • modification;
  • retrieval;
  • use;
  • matching;
  • analysis;
  • transfer and provision to persons engaged to perform processing;
  • granting access to authorised employees;
  • restriction;
  • deletion;
  • destruction.
Processing may be automated, non-automated, or mixed.


3.7. Processing Period

Personal Data relating to an enquiry that does not result in an agreement shall be processed:
  • until the relevant processing purposes have been achieved;
  • for one year from the date of the last substantive interaction with the user;
  • or until Consent is withdrawn, provided that there is no other lawful basis for continuing the processing.
Negotiation materials may be retained for up to three years after negotiations have ended where this is objectively necessary to confirm the agreed terms, review a complaint, or protect the Company’s rights.

Where an agreement is entered into following the enquiry, the Personal Data necessary for entering into and performing that agreement may subsequently be processed on the basis of the agreement and applicable law, irrespective of the withdrawal of this Consent.

4. Processing of Personal Data When Registering for and Using Btrace

4.1. Provision of Consent

By registering for Btrace, selecting the relevant checkbox, and clicking the registration button, the user freely, voluntarily, and in their own interest consents to the Controller processing their Personal Data in accordance with this Section.

When using the Btrace Telegram bot, Consent may be provided by clicking a separate confirmation button after reviewing this document.


4.2. Purposes of Processing

Personal Data is processed for the following purposes:
  • registering the user;
  • creating and maintaining an Account;
  • identification and authentication;
  • providing access to Btrace;
  • providing the Service’s functionality;
  • recording purchased, credited, and used Screenings;
  • generating, providing, and storing AML Reports;
  • accepting and recording payments;
  • issuing payment receipts and transaction confirmations;
  • providing technical and customer support;
  • restoring access;
  • ensuring information security;
  • identifying unauthorised access, fraud, and misuse;
  • performing the Terms of Use;
  • processing refunds, enquiries, complaints, and claims;
  • confirming actions performed by the user;
  • complying with obligations established by the laws of the Russian Federation.
Btrace user data shall not be used for advertising communications without separate prior consent.


4.3. Categories of Personal Data

The Controller may process:
  • login or username;
  • email address;
  • password hash;
  • authentication codes and information;
  • internal Account identifier;
  • Telegram ID, username, and displayed name when the Telegram bot is used;
  • registration date;
  • login dates and times;
  • IP address;
  • device, browser, and operating system information;
  • interface language;
  • history of actions performed within the Account;
  • selected Tariff;
  • number of Screenings purchased, credited, and used;
  • information concerning generated Reports;
  • cryptocurrency addresses and transaction hashes submitted for Screening;
  • Screening results;
  • information concerning customer support enquiries;
  • contents of correspondence;
  • payment and refund information;
  • payment amount, currency, date, status, and identifier;
  • information required to issue and deliver a payment receipt;
  • security logs;
  • information concerning the version of the Terms of Use accepted by the user;
  • the date, time, method, and version of the Consent provided.


4.4. Cryptocurrency addresses, transaction hashes, and public blockchain information shall be processed as Personal Data where, together with other information available to the Controller, they relate to a directly or indirectly identified or identifiable individual.


4.5. The Controller does not receive or store the full bank card number, expiry date, or card security code where such information is entered directly through the secure interface of a payment service provider.


4.6. Personal Data Processing Operations

The Controller may perform the following operations:
  • collection;
  • recording;
  • organisation;
  • accumulation;
  • storage;
  • clarification;
  • updating;
  • modification;
  • retrieval;
  • use;
  • matching;
  • analysis;
  • transfer and provision to persons engaged to perform processing;
  • granting access to authorised employees;
  • restriction;
  • anonymisation;
  • deletion;
  • destruction.
Processing may be automated, non-automated, or mixed.


4.7. Processing Period

Btrace Account data shall be processed:
  • for the lifetime of the Account and the duration of the contractual relationship;
  • for up to three years after the Account has been deleted or the relevant agreement has been terminated;
  • or until Consent is withdrawn, provided that there is no other lawful basis for continuing the processing.
Screening and Report history may be retained for the lifetime of the Account and for up to three years after the Account has been closed, unless a shorter period is established through the user’s settings or a separate agreement.

Payment, accounting, and tax records shall be retained for the periods established by the laws of the Russian Federation.

Following withdrawal of Consent, the Controller may continue processing Personal Data necessary for:
  • performing an existing agreement;
  • completing financial settlements;
  • accounting and tax compliance;
  • ensuring security;
  • resolving disputes;
  • protecting the rights of the Company and the user;
  • complying with statutory requirements.
Where the Account cannot technically or legally operate without the relevant processing, withdrawal of Consent may result in termination of access to Btrace and deletion of the Account after completion of any mandatory retention procedures.

5. Engagement of Other Persons and Personal Data Transfers

5.1. The Controller may engage other persons to process Personal Data and may grant them access to Personal Data to the extent necessary for the stated purposes.

5.2. Such persons may include:
  • server and cloud infrastructure providers;
  • Yandex Cloud;
  • the operator of the Tilda platform;
  • the operator of the amoCRM system;
  • corporate email service providers;
  • developers and technical contractors;
  • information security service providers;
  • payment and acquiring service providers selected by the user through the payment interface;
  • accounting and legal advisers;
  • providers of communications services and messaging services selected by the user.

5.3. The current categories of recipients and persons engaged in processing are specified in the AML Crypto LLC Personal Data Processing Policy.

5.4. Persons engaged in processing shall receive only the Personal Data necessary to perform the relevant function.

5.5. Where the user selects Telegram, WhatsApp, or another external service as a communication method, the information necessary for the correspondence shall also be processed by the operator of the selected service in accordance with its own terms and policies.

5.6. Use of a foreign messaging service may result in Personal Data being processed outside the Russian Federation. The Company shall carry out such transfers only in compliance with applicable requirements of Russian law.

5.7. The Controller does not sell Personal Data.

6. Special Categories of Personal Data

6.1. Through standard forms and Btrace registration, the Controller does not intentionally collect information concerning:
  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • health;
  • intimate life;
  • biometric Personal Data used to establish a person’s identity.

6.2. The user should not provide such information through free-text fields, files, or messaging services without prior agreement with the Controller.

6.3. Where the user independently provides such information, the Controller may delete it or restrict its processing where it is unnecessary for the stated purpose or there is no lawful basis for processing.

7. This Consent Does Not Apply to Cookies or Advertising

7.1. This Consent does not govern the use of non-essential cookies, Yandex Metrica, Webvisor, Google Analytics, or retargeting technologies.

7.2. Choices relating to such technologies shall be made separately through the cookie management interface.

7.3. This Consent does not constitute consent to:
  • receive advertising;
  • receive advertising communications;
  • receive advertising telephone calls;
  • receive advertising messages through messaging services;
  • disclose Personal Data to an indefinite group of persons;
  • publish a user’s name, photograph, review, or customer information.
Where necessary, separate consent shall be obtained for such activities.

8. Withdrawal of Consent

8.1. The user may withdraw this Consent in whole or in part by submitting a request:
  • by email to legal@amlcrypto.io;
  • by post to the Controller’s registered address;
  • through the relevant Btrace Account function, where available.

8.2. The request should include:
  • the user’s first name, surname, and patronymic;
  • the email address or other identifier used when interacting with the Company;
  • the resource or form through which the Personal Data was provided;
  • the substance of the request;
  • information enabling the relevant Account or enquiry to be identified.

8.3. The Controller may request additional information reasonably necessary to verify the applicant’s identity and prevent Personal Data from being deleted or disclosed at the request of an unauthorised person.

8.4. Following receipt of the withdrawal, the Controller shall discontinue processing based on Consent and destroy the relevant Personal Data within the period established by law, unless another lawful basis for processing applies.

8.5. Withdrawal of Consent:
  • does not affect the lawfulness of processing carried out before the withdrawal was received;
  • does not terminate processing necessary to perform an agreement;
  • does not override mandatory retention periods applicable to accounting, tax, or other records;
  • may make it impossible to continue reviewing an enquiry or providing access to Btrace.

9. Final Provisions

9.1. The user confirms that they:
  • reviewed this Consent before selecting the checkbox;
  • understand the purposes and conditions of processing;
  • provide Consent freely, voluntarily, and in their own interest;
  • provide accurate information;
  • are not acting on behalf of another individual without appropriate authority.

9.2. The Controller records:
  • the date and time on which Consent was provided;
  • the online resource, webpage, and form;
  • the relevant Account or enquiry identifier;
  • the IP address and technical identifier;
  • the applicable version of the Consent;
  • the fact that the checkbox was selected;
  • any subsequent withdrawal or amendment of the Consent.

9.3. A new version of the Consent shall apply to new actions taken by the user after its publication. Where the purposes, categories of Personal Data, or processing conditions change materially, the Controller shall obtain new Consent where required by law.

9.4. Detailed information concerning Personal Data processing is provided in the AML Crypto LLC Personal Data Processing Policy.

9.5. The Controller’s contact email for Personal Data matters is: legal@amlcrypto.io