Privacy Policy

Last updated: June 3, 2026

1. Introduction

AMLDroid ("we", "us", "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store and share information about you when you use our website and services (collectively, the "Services").

We process personal data in accordance with the General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and other applicable privacy laws. By using our Services you acknowledge that you have read and understood this policy.

2. Definitions

  • Company:Second February Limitada (reg. 3-102-918773), twelfth avenue, ninetieth street, ERP Lawyers Law Firm offices, Sabana Oeste, Mata Redonda, San José, Costa Rica — the data controller for users outside the European Economic Area.
    For users in the EU/EEA, the data controller is Digihub OÜ, Tartu mnt 65, Kesklinna linnaosa, Tallinn, Harju maakond 10115, Estonia.
  • Website:The website available at amldroid.com and associated subdomains.
  • Services:AML screening, transaction monitoring, API access, PDF reporting and related features.
  • Personal Data:Any information that identifies or can identify a natural person.
  • User / You:Any individual or legal entity accessing or using our Services.
  • Processing:Any operation performed on Personal Data, including collection, storage, use and deletion.

3. Data We Collect

We may collect the following categories of personal data:

  • Account data:Name, email address, company name, billing details provided during registration.
  • Usage data:Pages visited, API requests made, features used, timestamps, IP address, browser/device type.
  • Screening inputs:Cryptocurrency addresses, transaction hashes and other data submitted for AML checks.
  • Support communications:Messages sent to our support team, including metadata.
  • Payment data:Billing information processed via third-party payment providers (we do not store full card numbers).

4. How We Collect Data

  • Directly from you when you register, subscribe, or contact us.
  • Automatically through cookies, log files and analytics tools as you interact with our platform.
  • From third-party AML data providers (Elliptic, Crystal, Chainalysis) in the course of providing screening results.
  • From payment processors and identity verification services where applicable.

5. Purposes of Processing

We process your personal data for the following purposes and legal bases:

PurposeLegal basis (GDPR Art. 6)
Providing and improving our ServicesPerformance of a contract (6(1)(b))
Account management and authenticationPerformance of a contract (6(1)(b))
Billing and invoicingPerformance of a contract (6(1)(b))
Fraud prevention and securityLegitimate interests (6(1)(f))
Regulatory compliance and legal obligationsLegal obligation (6(1)(c))
Product analytics and usage insightsLegitimate interests (6(1)(f))
Marketing communications (opt-in only)Consent (6(1)(a))

6. Sharing Your Data

We do not sell your personal data. We may share it with:

  • AML data providers (Elliptic, Crystal Intelligence, Chainalysis) — to process screening requests on your behalf.
  • Cloud infrastructure providers — for hosting and data storage under appropriate data processing agreements.
  • Payment processors — to handle billing transactions securely.
  • Analytics tools (e.g. PostHog, Google Analytics) — under data processing agreements, with IP anonymisation where required.
  • Legal and regulatory authorities — when required by law, court order or to protect our legal rights.

All third-party processors are bound by contractual obligations that meet GDPR requirements.

7. Data Retention

  • Account data is retained for the duration of your account plus 3 years after closure.
  • AML screening results may be retained for up to 5 years to comply with anti-money laundering record-keeping obligations.
  • Support communications are retained for up to 3 years.
  • Marketing consent records are kept until you withdraw consent.

After the applicable retention period, data is securely deleted or anonymised.

8. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or disclosure. These include:

  • TLS/HTTPS encryption for all data in transit.
  • Encryption at rest for sensitive data stored in our databases.
  • Role-based access controls and least-privilege principles for internal systems.
  • Regular security reviews and penetration testing.
  • 99.9% uptime SLA with redundant infrastructure.

9. Your Rights

Under GDPR and applicable law, you have the following rights regarding your personal data:

  • Right of access (Art. 15):Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16):Ask us to correct inaccurate or incomplete data.
  • Right to erasure (Art. 17):Request deletion of your data where no legal basis for retention exists.
  • Right to restriction (Art. 18):Ask us to pause processing of your data in certain circumstances.
  • Right to data portability (Art. 20):Receive your data in a structured, machine-readable format.
  • Right to object (Art. 21):Object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent:Withdraw any previously given consent at any time without affecting prior processing.

To exercise any of these rights, contact us at hello@amldroid.com. We will respond within 30 days.

10. International Data Transfers

If we transfer your personal data outside the European Economic Area (EEA), we ensure an adequate level of protection through Standard Contractual Clauses approved by the European Commission, or other mechanisms recognised under GDPR Chapter V.

11. Cookies

We use the following categories of cookies:

  • Strictly necessary:Required for the platform to function (authentication, session management). Cannot be disabled.
  • Performance / analytics:Collect anonymised usage data to help us improve the product (e.g. page load times, feature usage).
  • Functional:Remember your preferences such as language selection.
  • Third-party:Set by our analytics and support providers (Google Analytics, Intercom). Subject to their own privacy policies.

You can control non-essential cookies via your browser settings or our cookie consent banner.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes we will post the updated policy on this page and update the "Last updated" date. We encourage you to review this page periodically.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:

Second February Limitada (non-EU users)

Reg. 3-102-918773 · twelfth avenue, ninetieth street, ERP Lawyers Law Firm offices, Sabana Oeste, Mata Redonda, San José, Costa Rica

Email: hello@amldroid.com

Digihub OÜ (EU/EEA users)

Tartu mnt 65, Kesklinna linnaosa
Tallinn, Harju maakond 10115, Estonia

Email: hello@amldroid.com

Website: amldroid.com

You also have the right to lodge a complaint with your local data protection supervisory authority.