AML CRYPTO LLC COOKIE AND SIMILAR TECHNOLOGIES POLICY

Version dated 28 July 2026

1. General Provisions

1.1. This Cookie and Similar Technologies Policy, hereinafter referred to as the “Policy,” sets out the manner in which AML Crypto Limited Liability Company uses cookies, browser local storage, analytics identifiers, and other similar technologies.

1.2. Details of the owner of the online resources and the personal data controller:

AML Crypto Limited Liability Company

  • abbreviated name: AML Crypto LLC;
  • Taxpayer Identification Number (INN): 9731092966;
  • Primary State Registration Number (OGRN): 1227700289695;
  • registered address: 42, Building 1, Bolshoy Boulevard, Skolkovo Innovation Center Territory, Mozhaysky Municipal District, Moscow, 121205, Russian Federation;
  • email address for personal data enquiries: legal@amlcrypto.io;
  • email address for general enquiries: info@amlcrypto.io.
AML Crypto LLC is hereinafter referred to as the “Company.”

1.3. This Policy applies to:
  • the website available at https://amlcrypto.io, including its language versions and individual webpages;
  • the Btrace service available at https://btrace.amlcrypto.io;
  • related webpages, user accounts, and web interfaces containing a link to this Policy.

1.4. This Policy supplements the AML Crypto LLC Personal Data Processing Policy.

1.5. This Policy does not replace the user’s consent to the processing of personal data. Where the use of a particular technology requires consent, the Company shall obtain such consent through a separate cookie management mechanism.

2. What Cookies and Similar Technologies Are

2.1. A cookie is a small data file stored by an online resource in the user’s browser or on the user’s device.

2.2. Cookies may be used to:
  • maintain a user session;
  • enable access to an Account;
  • ensure security;
  • retain interface settings;
  • remember the user’s choices;
  • analyse website traffic;
  • study user interaction with the website;
  • assess the effectiveness of webpages and informational materials;
  • create audiences for retargeting.

2.3. In addition to cookies, the Company may use:
  • localStorage;
  • sessionStorage;
  • pixels and web beacons;
  • browser and device identifiers;
  • analytics tags and scripts;
  • other technologies serving similar purposes.

2.4. This Policy applies to all such technologies regardless of their technical name.

2.5. A cookie or technical identifier does not necessarily constitute personal data in isolation. The Company shall treat it as personal data where, together with other available information, it relates to a directly or indirectly identified or identifiable individual.

3. Information That May Be Processed

The following information may be processed through cookies and similar technologies:
  • IP address;
  • browser or device identifier;
  • date and time of access;
  • referral source;
  • addresses of webpages viewed;
  • duration of the visit;
  • sequence of actions;
  • clicks, scrolling, and interaction with webpage elements;
  • device type;
  • browser type and version;
  • operating system;
  • screen resolution;
  • interface language;
  • approximate location determined from technical information;
  • information concerning the use of an ad blocker;
  • technical error information;
  • Account login and user session information;
  • selected cookie settings;
  • information concerning the completion of analytics goals;
  • other technical information supported by the relevant technology.
The Company shall not intentionally transmit names, email addresses, telephone numbers, payment details, the contents of enquiries, or other information directly identifying a user to analytics providers unless such transmission forms part of a separate lawful process and is properly covered by the Company’s documentation.

4. Categories of Technologies Used

4.1. Strictly Necessary Technologies

These technologies are required to:
  • open and operate the Website correctly;
  • ensure security;
  • protect against attacks and misuse;
  • maintain a user session;
  • enable registration and authentication in Btrace;
  • operate the Account;
  • retain the user’s cookie choices;
  • perform an action expressly requested by the user.
Strictly necessary technologies are enabled by default. They cannot be disabled through the cookie banner because certain Website or Btrace functions may not operate without them.

The user may block such technologies through browser settings, but doing so may prevent the user from accessing Btrace, retaining settings, or using certain functions.


4.2. Functional Technologies

Functional technologies may be used to:
  • retain the selected language;
  • remember interface settings;
  • retain certain user preferences;
  • make repeat use of the Website more convenient.
They are not required for the basic operation of the Website and shall be used only where the relevant functionality exists and the user has made the appropriate choice.


4.3. Analytics Technologies

Analytics technologies enable the Company to:
  • determine the number of visitors;
  • analyse traffic sources;
  • assess the popularity of webpages;
  • identify technical and interface-related issues;
  • analyse aggregated user behaviour;
  • improve the Website and Btrace;
  • assess the effectiveness of publications and interface changes.
This category includes Yandex Metrica, Webvisor, and Google Analytics.

Analytics technologies shall not be activated before the user provides consent.


4.4. Retargeting and Advertising Measurement Technologies

Such technologies may be used to:
  • create visitor audiences;
  • reduce the display of irrelevant advertising;
  • assess the effectiveness of advertising sources;
  • limit the frequency of advertising impressions;
  • conduct retargeting through advertising platforms.
The Company shall not send automated advertising messages to a user solely because the user has accepted advertising cookies.

Retargeting technologies shall be activated only after the user has expressly enabled the relevant category.

5. Services Used

5.1. Yandex Metrica

The Company uses Yandex Metrica to obtain website traffic statistics, analyse traffic sources, analyse visitor activity, and assess webpage performance.

Yandex Metrica may receive:
  • information concerning activity on the Website;
  • cookie data;
  • IP address;
  • browser and device information;
  • operating system information;
  • technical identifiers;
  • information concerning webpages viewed and actions performed.
In relation to visitor data, the Company acts as the personal data controller, while Yandex processes the relevant information on the Company’s behalf within the scope of the applicable service terms.


5.2. Webvisor

Webvisor is a Yandex Metrica feature that may record the sequence of a user’s actions on a webpage, including:
  • pointer movements;
  • clicks;
  • scrolling;
  • page transitions;
  • interaction with interface elements;
  • technical characteristics of webpage display.
The Company shall configure Webvisor so that passwords, payment details, the contents of sensitive fields, and other information unnecessary for interface analysis are not transmitted in session recordings.

Webvisor shall be activated only after the user has consented to analytics technologies.


5.3. Yandex Retargeting Functions

Where the relevant settings are enabled, the Company may use Yandex audience creation and retargeting functions.

These functions may use technical identifiers to record that a user has visited particular webpages and subsequently include the user in an advertising audience.

Retargeting shall not be activated without the user’s consent to advertising technologies.


5.4. Google Analytics

The Company may use Google Analytics to assess traffic, traffic sources, user sessions, and interaction with its online resources.

Google Analytics may receive:
  • technical identifiers;
  • IP address and information derived from it;
  • device and browser information;
  • webpages viewed;
  • session events and parameters;
  • referral source;
  • approximate geographical location;
  • cookie data.
Google Analytics shall be activated only after the user has consented to analytics technologies and provided that the Company has complied with all applicable requirements concerning personal data localisation, cross-border transfers, and notification of Roskomnadzor.

Consent provided through a cookie banner does not, by itself, replace compliance with the statutory requirements governing cross-border transfers.

6. Main Cookies and Identifiers

The actual set of identifiers may depend on the relevant Website, browser, analytics account settings, and the user’s actions.
Before publication of this Policy, the Company’s developer shall confirm the actual names of AML Crypto’s proprietary session, security, and functional cookies and update the table where necessary.

7. Obtaining Consent

7.1. When a user first visits the Website, the user shall be shown a cookie management interface.

7.2. The user shall be able to:
  • accept all categories;
  • reject all non-essential categories;
  • open detailed settings;
  • enable or disable individual available categories.

7.3. Strictly necessary technologies shall remain active regardless of the user’s choice to the extent required for operation of the Website, security, and performance of an action requested by the user.

7.4. Analytics, functional, and advertising technologies shall not be activated before the user makes a positive choice in relation to the relevant category where their use is based on consent.

7.5. Failure to make a choice, closing the banner, continuing to browse the Website, or remaining inactive shall not constitute consent to non-essential technologies.

7.6. Consent shall be obtained separately from acceptance of:
  • the Terms of Use;
  • the Personal Data Processing Policy;
  • an agreement;
  • registration terms;
  • other Company documents.

7.7. The Company shall retain the information required to demonstrate the user’s choice, including:
  • date and time;
  • technical identifier;
  • selected categories;
  • the version of the interface and notification text;
  • any subsequent amendment or withdrawal of the choice.

7.8. The Company is not required to identify the user personally solely for the purpose of recording the user’s cookie choice. The record may be linked to a pseudonymous technical browser identifier.

8. Amendment and Withdrawal of Consent

8.1. The user may change their choice at any time through the “Cookie Settings” link available in the footer of the Website.

8.2. Once a category has been disabled, the Company shall discontinue future use of that category on the relevant device and in the relevant browser.

8.3. Withdrawal of consent shall not affect the lawfulness of processing carried out before consent was withdrawn.

8.4. Cookies already placed by third-party services may technically remain in the browser until they expire. The user may delete them manually through browser settings.

8.5. When using a different browser, device, or private browsing mode, the user may be required to make a new choice.

8.6. The Company may request the user’s choice again:
  • after the retention period for the settings has expired;
  • following a material change to the services used;
  • after the introduction of a new processing category;
  • following a change to the purposes for which data is used;
  • where the previously recorded choice cannot be reliably determined.

9. Browser Settings

9.1. The user may delete or block cookies through their browser settings.

9.2. Depending on the browser, the user may:
  • delete all stored cookies;
  • prevent cookies from being stored;
  • block third-party cookies;
  • create exceptions for specific websites;
  • delete localStorage and sessionStorage data;
  • use private browsing mode.

9.3. Blocking strictly necessary cookies may result in:
  • inability to register;
  • termination of the Account session;
  • inability to use Btrace;
  • incorrect operation of forms;
  • inability to retain selected settings;
  • reduced security.

9.4. Browser settings do not always provide separate controls for each analytics or advertising service. The Website’s cookie management interface should be used for more precise control.

10. Transfers to Third Parties

10.1. Where the relevant categories are activated, information may be transferred to:
  • Yandex;
  • Google and its affiliated entities;
  • technical infrastructure providers;
  • persons responsible for the operation and support of the Websites;
  • other providers identified in the Company’s settings and documentation.

10.2. Third parties may:
  • process information on the Company’s behalf;
  • or act as independent personal data controllers in relation to particular processing activities.

10.3. The Company does not sell users’ Personal Data.

10.4. The Company shall not transmit more information to analytics providers than is necessary for the stated purposes.

11. Data Localisation and Cross-Border Transfers

11.1. When collecting Personal Data relating to citizens of the Russian Federation, the Company shall comply with the personal data localisation requirements of Russian law.

11.2. The use of foreign analytics services may result in information being transferred to foreign countries.

11.3. Before carrying out a cross-border transfer, the Company shall:
  • identify the foreign recipient and the relevant country;
  • determine the categories of Personal Data to be transferred;
  • determine the purpose and lawful basis of the transfer;
  • obtain the required information from the recipient;
  • submit the required notification to Roskomnadzor;
  • assess the relevant risks;
  • implement appropriate security measures;
  • obtain the user’s consent where required.

11.4. Where the lawful requirements for a cross-border transfer have not been satisfied, the relevant foreign technology shall not be activated, even where the user has clicked “Accept All.”

12. Retention Periods

12.1. Cookies may be:
  • session cookies, which are deleted when the browser is closed;
  • persistent cookies, which remain until their specified expiry date or until deleted by the user.

12.2. The approximate durations of the principal identifiers are specified in Section 6.

12.3. The user’s cookie choices shall be retained for up to 12 months unless the user changes or withdraws them earlier.

12.4. Evidence of consent and withdrawal may be retained for the duration of the relevant processing and for up to three years after processing ends, unless a longer period is required to resolve a dispute or comply with applicable law.

12.5. Data generated by analytics services shall be retained in accordance with:
  • the settings of the relevant analytics account;
  • the terms of the relevant service;
  • the Personal Data Processing Policy;
  • the retention periods established by the Company.

12.6. The Company shall apply the shortest retention periods reasonably sufficient for the stated purposes.

13. Information Security

13.1. The Company implements organisational and technical measures to protect information processed through cookies and similar technologies.

13.2. In particular, the Company:
  • restricts access to analytics dashboards;
  • uses individual user accounts;
  • manages and reviews access permissions;
  • protects administrative interfaces;
  • prevents the transmission of excessive parameters;
  • reviews and controls Webvisor settings;
  • periodically audits installed tags and scripts;
  • removes analytics tools that are no longer used;
  • records and applies the user’s choice before activating relevant tags;
  • supervises contractors with access to analytics systems.

13.3. Users are also responsible for maintaining the security of their devices, browsers, and Accounts.

14. User Rights

The user has the right to:
  • obtain information concerning the technologies used;
  • accept or reject non-essential categories;
  • change a previous choice;
  • withdraw consent;
  • delete cookies through browser settings;
  • submit an enquiry concerning the processing of Personal Data;
  • request correction, restriction, or destruction of Personal Data in the circumstances provided by law;
  • submit a complaint to Roskomnadzor or a court.

15. Amendments to the Policy

15.1. The Company shall review this Policy where:
  • an analytics service is introduced or discontinued;
  • the identifiers used are changed;
  • the processing purposes are changed;
  • retention periods are changed;
  • the cross-border transfer arrangements are changed;
  • applicable law is amended;
  • the cookie management interface is changed.

15.2. A new version shall take effect from the date stated at the beginning of that version.

15.3. The Company shall retain the ability to determine the contents of the Policy and the consent interface that applied during a particular period.

15.4. Where processing changes materially, the Company may request the user’s consent again.

16. Contact Details

Enquiries concerning cookies, analytics, and the processing of Personal Data may be sent to:

legal@amlcrypto.io

AML Crypto LLC

42, Building 1, Bolshoy Boulevard,
Skolkovo Innovation Center Territory,
Mozhaysky Municipal District,
Moscow, 121205, Russian Federation.