AML/KYC Notice
Verification is ongoing and risk-based. Completing identity checks does not guarantee service activation, continued access or transaction acceptance.
1. Purpose and legal status
1.1 This AML/KYC Notice explains the risk-based identity, financial-crime, sanctions, fraud and transaction controls used for the Ukraine Service Route. It forms part of the Multi-Party Terms of Use and should be read with the Privacy Notice and provider-specific Schedules.
1.2 Completing verification does not guarantee activation, continued access or acceptance of any transaction. Controls vary by provider, service, user, geography, payment method, crypto-asset, wallet and risk profile.
2. Responsibility and provider roles
Control area | Responsible provider | Technical/supporting role | Final decision |
|---|---|---|---|
Platform access/security | Plum Labs s.r.o. | LMLP and approved security/infrastructure providers may support technical controls. | Plum Labs for Platform access; financial-service providers may also restrict their own services. |
Custody onboarding and crypto controls | Plum Global Inc. | LMLP and approved identity-verification / blockchain-analytics providers may support verification and screening. | Plum Global for Custody Service acceptance, deposits, custody, transfers and withdrawals. |
Exchange, fiat and payment | Innovate Payments Inc. (IPI) | LMLP, approved identity-verification, banking/payment and analytics providers may support the process. | IPI for exchange/fiat acceptance, orders, payments, settlement and required reports. |
Technical verification/routing | LMLP consulting s.r.o. | Approved verification and screening tools may be integrated. | LMLP performs technical steps; the responsible contracting provider makes the financial-service decision. |
2.1 A supporting provider does not become the custody or transaction counterparty merely because its technology is used. Public registration of a provider, where applicable, is not a licence, endorsement or guarantee and does not extend to another provider.
3. Risk-based approach
3.1 Providers assess relevant customer, service, geography, payment, wallet, blockchain, counterparty, fraud and sanctions factors. Risk classification may change as new information, behaviour or alerts become available.
3.2 Increased risk may lead to enhanced due diligence, additional documents, lower limits, delayed processing, management approval, manual review or increased monitoring. Unacceptable risk may lead to refusal, restriction, lawful return, termination or reporting.
4. Eligibility and onboarding
4.1 You must be at least 18 years old, have legal capacity, use the account for yourself and provide accurate/current information. Duplicate, anonymous, nominee or undisclosed-third-party accounts are prohibited.
4.2 Eligibility is determined by residence, actual location, verification results, sanctions and other lawful controls. The Ukraine Service Route is not available to persons residing in or accessing the services from the EU/EEA or another unsupported/restricted jurisdiction.
5. Information and documents
5.1 Depending on risk and service, a provider may request identity, contact, tax/residency, occupation, employer/business, expected-use, source-of-funds/wealth, payment, wallet, counterparty and transaction-purpose information.
5.2 Documents may include government-issued identification, address evidence, bank/payment statements, tax documents, employment/business evidence, contracts, invoices, payslips, sale/inheritance records or other reliable evidence. Documents must be genuine, current, complete and readable.
5.3 Never provide a password, one-time authentication code, private key, seed phrase or full payment-card security data for verification.
6. Identity and biometric verification
6.1 Verification may include document-authenticity checks, facial comparison, selfie/liveness, video verification, database checks and manual review using approved verification technology.
6.2 Biometric or liveness data is processed only where necessary, permitted and described in the Privacy Notice. Where consent or another specific legal basis is required, it will be obtained or applied as required.
6.3 Verification may be repeated after document expiry, material change, unusual activity, account recovery, security incident, provider change or periodic review.
7. Residence and actual location
7.1 Residence and actual location may be assessed using identity/address evidence, IP address, device/network signals, mobile country, time zone, payment/bank information and other reasonable indicators.
7.2 You must not use a VPN, proxy, remote device, false address or other method to conceal or misrepresent actual location or eligibility.
8. Politically exposed persons and other enhanced-risk public functions
8.1 Providers may determine whether a user, beneficial owner, family member or close associate is or has been a politically exposed person, head of an international organisation or another person requiring enhanced review under applicable rules.
8.2 Such status does not automatically prohibit service but may require senior approval, additional relationship/source information and enhanced ongoing monitoring.
9. Sanctions and restricted locations
9.1 Providers may screen users, beneficial owners, directors, counterparties, payment accounts, wallet addresses and transactions against sanctions, terrorism, proliferation-financing and other legally relevant restriction lists applicable to the provider, service or transaction.
9.2 A provider may reject, block, freeze, return, report or retain control of a transaction or asset where required or permitted by applicable law. A temporary restriction during review does not establish wrongdoing.
10. Source of funds, source of wealth and purpose
10.1 Source of Funds means the origin of the specific money or crypto-assets used in a transaction; Source of Wealth means how a person’s overall wealth was accumulated. A provider may ask for supporting evidence proportionate to risk.
10.2 Unexplained activity, rapid movement, layering/structuring, unrelated payers/wallets, high-risk services, mixers, privacy-enhancing methods or inconsistent documents may trigger enhanced review.
11. Payment-account and wallet ownership
11.1 Unless the responsible provider expressly approves otherwise, payments should originate from and be returned to a verified account held in the user’s name. Providers may request proof of wallet control using safe verification methods.
11.2 Third-party payments, mule accounts, nominee arrangements and transfers on behalf of an undisclosed person may be rejected or require prior approval and enhanced due diligence.
12. Blockchain analytics
12.1 Plum Global and IPI may screen wallet addresses, deposits, withdrawals, counterparties and transaction history using approved blockchain-analytics and other risk information.
12.2 Screening may assess exposure to sanctions, theft, fraud, ransomware, darknet markets, mixers, scams, illicit services, high-risk exchanges, gambling, terrorism financing, stolen funds or other relevant risk categories. Analytics results are indicators and may require contextual/human review.
13. Transfer information and Travel Rule
13.1 Where applicable, the responsible provider may collect, verify, retain and transmit prescribed information about the originator and beneficiary of a fiat or virtual-currency transfer.
13.2 A transfer may be delayed, rejected, returned or restricted if required information is missing, unreliable, inconsistent or cannot be transmitted securely/lawfully.
14. Ongoing monitoring and re-verification
14.1 Providers may monitor activity, transaction behaviour, payment routes, wallets, counterparties, devices, location, velocity and other indicators throughout the relationship and compare actual activity with the expected profile.
14.2 Providers may refresh identification and risk information periodically or after triggers such as document expiry, change of residence, unusual activity, large transaction, security event or sanctions update.
15. Transaction review and restrictions
15.1 A transaction may be placed in pending, compliance-review, security-review, delayed, rejected, returned, restricted or frozen status. Technical receipt of fiat or crypto-assets does not mean final acceptance.
15.2 No fixed review period is guaranteed. Where lawful and operationally possible, rejected recoverable value may be returned to the verified source or another approved destination after required checks.
16. Reporting and confidentiality
16.1 A responsible provider may make reports or disclosures to financial-intelligence units, sanctions authorities, regulators, courts, law-enforcement, tax authorities, payment providers or other competent recipients where required or permitted by applicable law.
16.2 A provider may be prohibited from informing you that a report was made or from disclosing underlying suspicion, authority requests or confidential monitoring rules.
17. Fraud and scam prevention
17.1 Do not send fiat or crypto-assets to a person promising guaranteed profit, asking you to conceal purpose, pressuring you to act urgently, requesting remote access, impersonating support or claiming payment is required to unlock/protect funds.
17.2 If you suspect fraud, contact support immediately and, where appropriate, your bank, wallet provider or law-enforcement authority. Completed blockchain or payment transactions may not be reversible.
18. Records and personal data
18.1 Identity, verification, screening, risk, transaction, payment, wallet, support and reporting records may be created and retained as described in the Privacy Notice and applicable law.
18.2 Information may be shared among the providers and approved verification, screening, analytics, banking/payment and technology providers only to the extent necessary for the relevant service, security, fraud prevention, compliance, complaints or legal obligations and according to their actual data-protection roles.
19. User obligations
19.1 Provide complete, accurate, current and non-misleading information; use only your own account/payment method/wallet unless expressly approved; respond to reasonable requests; and do not split, disguise or structure transactions to avoid controls or reporting.
20. Review, support and complaints
20.1 Contact support@plumex.io to provide requested information or request review. Complaints may be submitted to complaints@plumex.io and will be routed to the provider responsible for the affected service.
20.2 Receipt of a complaint is ordinarily acknowledged within three Business Days and the responsible provider aims to issue a final response within 30 calendar days, subject to mandatory law, complexity and third-party information.
21. Changes to this Notice
21.1 This Notice may be updated for changes in law, provider roles, sanctions, products, risk controls, technology or supporting providers. Material changes affecting user rights or required information will be notified where required.