AML/KYC Notice
Verification is an ongoing risk-based process. Completing identity checks does not guarantee activation, continued access or acceptance of a transaction. |
|---|
This Notice explains why information is requested, which provider makes each compliance decision, how transactions may be screened and what may happen when information is incomplete or risk cannot be managed. It should be read with the Multi-Party Terms of Use, the Privacy Notice and the provider-specific Schedules.
Contents
1. Purpose and legal status | 12. Blockchain analytics |
|---|---|
2. Responsibility and provider roles | 13. Transfer information and Travel Rule |
3. Risk-based approach | 14. Ongoing monitoring and re-verification |
4. Eligibility and onboarding | 15. Transaction review and restrictions |
5. Information and documents | 16. Reporting and confidentiality |
6. Identity and biometric verification | 17. Fraud and scam prevention |
7. Residence and actual location | 18. Records and personal data |
8. Politically exposed persons and HIOs | 19. User obligations |
9. Sanctions and restricted locations | 20. Review, support and complaints |
10. Source of funds, source of wealth and purpose | 21. Changes to this Notice |
11. Payment-account and wallet ownership | 22. Definitions |
1. Purpose and legal status
1.1 This Anti-Money Laundering, Know Your Customer and Sanctions Notice (the “Notice”) explains the risk-based identity, financial-crime, sanctions, fraud and transaction controls used for the Ukraine Service Route.
1.2 The Notice forms part of the Multi-Party Terms of Use. It does not create a separate financial service and does not limit a provider’s rights or obligations under applicable law, the Terms or a provider-specific Schedule.
1.3 The controls are intended to prevent money laundering, terrorist financing, proliferation financing, sanctions evasion, fraud, trafficking, ransomware, theft and other unlawful use and to protect users, providers, payment systems and the public.
1.4 Providers apply controls according to the service, user, geography, payment method, crypto-asset, wallet, transaction pattern and other relevant risk factors. The precise controls, thresholds and detection rules are confidential and may change.
1.5 Creating an account, completing verification or previously completing a transaction does not guarantee continued eligibility, service activation or acceptance of another transaction.
2. Responsibility and provider roles
2.1 Capitalista S.A. makes the final customer-acceptance, custody-risk and transaction-control decisions for the Custody Service, including crypto-asset deposits, custody, transfers and withdrawals.
2.2 Innovate Payments Inc. (“IPI”) makes the final customer-acceptance, exchange, fiat, payment and transaction-monitoring decisions for the Exchange Service and Fiat Service. IPI is registered with the Financial Transactions and Reports Analysis Centre of Canada as a money services business under number C100000559.
2.3 Plum Labs s.r.o. applies Platform account, security, fraud and misuse controls and coordinates general support. It does not replace Capitalista or IPI as the final decision maker for their financial services.
2.4 LMLP consulting s.r.o. provides non-contracting technical identity-verification intake, residence and location checks, routing, screening integration and transmission of information and instructions. LMLP does not make the final customer or transaction decision for Capitalista or IPI.
2.5 The Platform and the relevant providers may use Sumsub, AMLBot, sanctions-data providers, payment institutions, banks, blockchain analytics and other technology or compliance providers. Use of a supporting provider does not transfer the responsible provider’s contractual responsibility.
2.6 Registration of IPI with a public authority is not a licence, endorsement or guarantee by that authority and does not extend to another provider.
Control area | Responsible provider | Technical/supporting role | Final decision |
|---|---|---|---|
Platform access and account security | Plum Labs s.r.o. | LMLP and security/infrastructure providers may support technical controls. | Plum Labs for Platform access; service providers may also restrict their services. |
Custody onboarding and crypto-asset controls | Capitalista S.A. | LMLP, Sumsub and blockchain-screening providers may support verification and screening. | Capitalista for Custody Service acceptance, deposits, custody, transfers and withdrawals. |
Exchange, fiat and payment controls | Innovate Payments Inc. (IPI) | LMLP, Sumsub, banks, payment providers and blockchain analytics may support the process. | IPI for Exchange and Fiat Service acceptance, orders, payments, settlement and required reports. |
Technical identity intake and routing | LMLP consulting s.r.o. | Sumsub and other approved tools may be integrated. | LMLP performs technical steps; Capitalista or IPI makes the final financial-service decision. |
3. Risk-based approach
3.1 Risk is assessed using relevant customer, product, service, geography, delivery-channel, payment, wallet, blockchain, transaction, counterparty, fraud and sanctions factors.
3.2 A user or transaction may be classified as lower, standard, increased or unacceptable risk, or by another internal risk category. Risk classification may change when new information, behaviour, alerts or external data become available.
3.3 Increased risk may lead to enhanced due diligence, additional documents, lower limits, delayed processing, management approval, manual review, increased monitoring or a narrower service scope. Increased risk does not automatically mean that the user has committed wrongdoing.
3.4 Unacceptable risk may result in refusal, restriction, return of funds or assets where lawful, termination or reporting. Providers do not accept risk merely because a transaction is technically possible.
3.5 Controls are applied on relevant and lawful risk factors and must not be based solely on a protected characteristic that is unrelated to the risk or legal requirement.
4. Eligibility and onboarding
4.1 You must be at least 18 years old, have legal capacity, use the account for yourself and provide accurate and current information.
4.2 Eligibility is determined by residence, Actual Location, identity-verification results, sanctions and other risk controls. Nationality alone does not determine eligibility.
4.3 The Ukraine Service Route is not available to persons residing in or accessing the services from the European Union, the European Economic Area or another unsupported or restricted jurisdiction.
4.4 You may not create duplicate or anonymous accounts, use a nominee, conceal a beneficial owner or operate the account for an undisclosed third party.
4.5 A provider may decline onboarding or activate only selected services, assets, networks, currencies, payment methods or limits.
5. Information and documents
5.1 Depending on risk and service, a provider may request your full legal name, date and place of birth, citizenship, residential address, contact details, taxpayer or national identification number, occupation, employer, business activity and expected account use.
5.2 Documents may include a passport, national identity card, residence permit, driver licence where accepted, address evidence, bank statement, tax document, employment or business evidence, contract, invoice, payslip, sale agreement, inheritance record or other reliable evidence.
5.3 A provider may request transaction purpose, intended counterparty, relationship to the counterparty, expected volumes, payment method, wallet details, source of funds, source of wealth and documents supporting an unusual or higher-risk transaction.
5.4 Information may be checked against reliable documents, databases, public sources, sanctions and adverse-information sources, device and network signals, payment records and blockchain data.
5.5 Documents must be genuine, current, complete and readable. Translation, certification, notarisation or an additional document may be required where reasonably necessary.
5.6 Never send a password, one-time authentication code, private key, seed phrase or full payment-card security data. No provider needs a private key or seed phrase to perform verification.
6. Identity and biometric verification
6.1 Verification may include document authenticity checks, facial comparison, selfie, liveness detection, video verification, database checks and manual review.
6.2 Biometric or liveness data may be processed where permitted and described in the Privacy Notice. Where required by law, an appropriate consent or another valid legal basis will be used.
6.3 If automated verification fails, a provider may request a new capture, additional document, live review or another reasonably available method. An alternative method is not guaranteed where it cannot meet legal, security or provider requirements.
6.4 Verification may be repeated after expiry of a document, material change, unusual activity, account recovery, security incident, provider change or periodic review.
6.5 A successful technical check does not require a provider to accept a user or transaction. The responsible provider makes the final risk and eligibility decision.
7. Residence and actual location
7.1 You may be required to prove residential address and legal residence using current official or reliable evidence.
7.2 Actual Location may be assessed using internet protocol address, device, mobile-country, time-zone, payment, bank, document and other reasonable signals.
7.3 A mismatch between residence, Actual Location, payment account, bank, wallet, device or declared purpose may require explanation, additional evidence or restriction.
7.4 You must not use a virtual private network, proxy, remote device, false address or another method to conceal or misrepresent Actual Location or eligibility.
7.5 Temporary travel does not automatically create eligibility. A provider may restrict access until it can establish that the service may lawfully and safely be provided.
8. Politically exposed persons and heads of international organizations
8.1 Providers may determine whether you, a beneficial owner, family member or close associate is or has been a politically exposed person, a head of an international organization or another person requiring enhanced review.
8.2 Such status does not automatically prohibit service. It may require senior approval, additional identity and relationship information, source-of-funds and source-of-wealth evidence and enhanced ongoing monitoring.
8.3 You must answer related questions accurately and notify support if relevant circumstances materially change.
8.4 A provider may decline or restrict service if it cannot obtain sufficient information or manage the identified risk.
9. Sanctions and restricted locations
9.1 Providers may screen users, beneficial owners, directors, counterparties, payment accounts, wallet addresses and transactions against sanctions, terrorist, proliferation-financing and other legally relevant restriction lists.
9.2 Screening may include lists and measures applicable to the provider, service or transaction, including relevant United Nations, Canadian, Ukrainian, European Union, United Kingdom, United States and other national or international measures.
9.3 The Availability Schedule identifies unsupported and restricted jurisdictions and territories. Providers may also restrict a location or person where required by a bank, payment provider, blockchain provider, court, authority or risk policy.
9.4 Where required or permitted, a provider may reject, block, freeze, return, report or retain control of a transaction or asset. Mandatory asset-freezing or legal-process obligations may prevent return or withdrawal.
9.5 A sanctions match may require manual review. A temporary restriction during review does not establish that the user is a sanctioned person.
10. Source of funds, source of wealth and transaction purpose
10.1 Source of Funds means the origin of the specific money or crypto-assets used in a transaction. Source of Wealth means how your total wealth or net worth was accumulated.
10.2 Evidence may include employment income, savings, business revenue, investment sale, property sale, loan, gift, inheritance, mining, staking, prior crypto purchase or another lawful source, supported by appropriate records.
10.3 A provider may ask how an asset was acquired, the route of fiat or crypto funds, the beneficial owner, the purpose and expected recipient and why the transaction is consistent with your profile.
10.4 Unexplained cash-intensive activity, rapid movement, layering, structuring, use of multiple unrelated payers or wallets, high-risk services, mixers, privacy-enhancing methods or inconsistent documents may trigger enhanced review.
10.5 A provider may refuse, limit or return a transaction where the source, ownership, purpose or economic rationale cannot be established to its reasonable satisfaction.
11. Payment-account and wallet ownership
11.1 Unless IPI expressly approves another arrangement, fiat payments must come from and be returned to a bank or payment account held in the verified user’s name.
11.2 A provider may verify account ownership through a statement, account-holder record, confirmation from a payment provider, controlled test transfer or another reliable method.
11.3 A provider may require proof that you control a sending or receiving wallet, including a signed message, small test transaction, wallet-provider record or another safe method.
11.4 You must never disclose a private key or seed phrase. A provider will not treat disclosure of a private key or seed phrase as an acceptable verification method.
11.5 Third-party payments, undisclosed custodial wallets, mule accounts, nominee arrangements and transfers on behalf of another person may be rejected or require prior written approval and enhanced due diligence.
12. Blockchain analytics
12.1 Capitalista and IPI may screen wallet addresses, deposits, withdrawals, counterparties and transaction history using blockchain analytics and other risk information.
12.2 Screening may assess exposure to sanctions, theft, fraud, ransomware, darknet markets, mixers, scams, illicit services, high-risk exchanges, gambling, terrorism financing, stolen funds or other risk categories.
12.3 Analytics results are risk indicators and may be incomplete or incorrect. A material alert may be reviewed with available transaction, customer and contextual information before a final decision where practicable.
12.4 A provider may refuse an unsupported asset, token, network, privacy-enhancing feature or transaction that cannot be screened or managed within its risk appetite.
12.5 You may be asked to identify the originating or destination wallet, counterparty, exchange or transaction purpose and provide supporting evidence.
13. Transfer information and Travel Rule
13.1 Where applicable, IPI or another responsible provider may collect, verify, retain and transmit information about the originator and beneficiary of a fiat or virtual-currency transfer.
13.2 Required information may include legal name, account or wallet identifier, address, date of birth, identification number and information about the originating or beneficiary institution.
13.3 Information may be exchanged with a bank, payment provider, virtual-asset service provider or other regulated counterparty before, during or after a transfer.
13.4 A transfer may be delayed, rejected, returned or restricted if required information is missing, unreliable, inconsistent or cannot be transmitted securely or lawfully.
13.5 Providing transfer information does not guarantee that the recipient or counterparty will accept or complete the transfer.
14. Ongoing monitoring and re-verification
14.1 Providers may monitor account activity, transaction behaviour, payment routes, wallets, counterparties, devices, location, velocity, frequency and other indicators throughout the relationship.
14.2 Monitoring may compare actual activity with the expected purpose, volumes, source of funds, risk profile and information previously provided.
14.3 Providers may refresh identification and risk information periodically or after a trigger such as document expiry, change of residence, unusual activity, large transaction, security event, sanctions update or provider request.
14.4 Multiple connected transactions may be assessed together, including transactions conducted within a defined time period, across services or through related accounts or wallets.
14.5 You must respond to reasonable re-verification requests within the stated time. Service may be restricted while required information is outstanding.
15. Transaction review and restrictions
15.1 A transaction may be placed in pending, compliance review, security review, delayed, rejected, returned, restricted or frozen status.
15.2 Technical receipt of fiat or crypto-assets does not mean final acceptance. A provider may wait for payment finality, blockchain confirmations, screening, verification, liquidity or other required conditions.
15.3 A provider does not guarantee a fixed review period. It will use reasonable efforts to complete review without undue delay, subject to legal restrictions, third-party response times, complexity and risk.
15.4 Where lawful and operationally possible, rejected funds or crypto-assets may be returned to the verified source or another approved destination after deducting disclosed unavoidable network, banking or return costs.
15.5 A restriction affecting one service does not automatically terminate another service, but providers may coordinate restrictions where necessary to protect users, assets, systems or legal obligations.
15.6 A provider may require withdrawal or closure where it can no longer support the user, territory, asset, network, payment method or risk. Legal holds and asset-freezing obligations may prevent immediate withdrawal.
16. Reporting and confidentiality
16.1 IPI and other providers may make reports or disclosures to Financial Transactions and Reports Analysis Centre of Canada, financial intelligence units, sanctions authorities, regulators, courts, law-enforcement bodies, tax authorities, payment providers or other competent recipients where required or permitted by law.
16.2 Reports may include suspicious transaction, terrorist property, sanctions-evasion, large virtual-currency, large cash, electronic funds transfer or other prescribed reports where the relevant conditions are met.
16.3 A report or enquiry does not establish that a user committed an offence. Providers assess and report according to applicable legal thresholds and available information.
16.4 Providers may be prohibited from informing you that a report was made, describing the underlying suspicion, disclosing an authority request or explaining the full reason for a restriction.
16.5 You must not ask staff to disclose confidential monitoring rules, reporting decisions, law-enforcement communications or information that a provider cannot lawfully provide.
17. Fraud and scam prevention
17.1 Do not send fiat or crypto-assets at the request of a person who promises guaranteed profit, asks you to conceal the purpose, pressures you to act urgently, requests remote access, impersonates support or claims that payment is required to unlock or protect funds.
17.2 Do not allow another person to control your device, screen, account, wallet or authentication process. A provider may pause a transaction if fraud, coercion, impersonation or authorised-push-payment risk is suspected.
17.3 Support will not ask for a private key, seed phrase, full payment-card security data or remote control of your device.
17.4 If you suspect fraud, contact support immediately and, where appropriate, your bank, wallet provider or law-enforcement authority. Blockchain or completed payment transactions may not be reversible.
18. Records and personal data
18.1 Identity, verification, screening, risk, transaction, payment, wallet, support and reporting records may be created and retained as described in the Privacy Notice and applicable law.
18.2 Information may be shared among Plum Labs, Capitalista, IPI and LMLP to the extent necessary for the relevant service, security, fraud prevention, compliance, complaints and legal obligations, subject to their respective data roles.
18.3 Information may be shared with Sumsub, AMLBot, banks, payment providers, blockchain analytics providers, authorities and other recipients described in the Privacy Notice.
18.4 Data may be processed or transferred internationally. Appropriate legal, contractual and security measures will be used where required.
18.5 Closing or deleting an account does not require deletion of records that must or may lawfully be retained. Blockchain records may remain public and technically immutable.
19. User obligations
19.1 Provide complete, accurate, current and non-misleading information and promptly correct any material change.
19.2 Use only your own account, payment method and wallet unless the responsible provider has expressly approved another arrangement.
19.3 Respond to reasonable information requests and provide genuine supporting evidence within the requested time.
19.4 Do not split, route, disguise, layer or structure transactions to avoid a limit, threshold, screening rule, reporting obligation or review.
19.5 Do not use the services for unlawful activity, on behalf of an undisclosed person or in breach of sanctions, court orders or the Terms.
19.6 Notify support if you become aware that previously provided information was incorrect or that your account, payment method or wallet may have been compromised or misused.
20. Review, support and complaints
20.1 You may contact support@plumex.io to provide requested information, correct an apparent error or request review of an eligibility, restriction or transaction issue.
20.2 Complaints may be submitted to complaints@plumex.io and will be routed to the provider responsible for the affected service.
20.3 A request should identify the account, service, date, transaction or custody reference and include relevant non-secret evidence. Do not provide passwords, private keys, seed phrases or one-time codes.
20.4 Receipt of a complaint is ordinarily acknowledged within three business days. The responsible provider aims to issue a final response within 30 calendar days, subject to applicable law, complexity and third-party information.
20.5 A review request or complaint does not automatically lift a legal hold, sanctions control, fraud restriction, payment recall or blockchain finality. A provider may be unable to disclose confidential reasons.
21. Changes to this Notice
21.1 This Notice may be updated to reflect changes in law, guidance, provider roles, sanctions, products, risk controls, technology, supporting providers or operational processes.
21.2 Material changes affecting user rights or required information will be notified through the App, email, website or another durable electronic method where required.
21.3 An urgent legal, sanctions, fraud or security change may take effect immediately. Continued use after the effective date is subject to any acceptance required by law or the Terms.
21.4 The version and effective date shown on the first page identify the applicable Notice.
22. Definitions
“Actual Location” the country or territory from which you access or use a service, assessed using reasonable technical, payment, device and verification information.
“AML” anti-money laundering and the prevention of terrorist financing and proliferation financing.
“Capitalista” Capitalista S.A., the provider responsible for compliance decisions relating to the Custody Service.
“Enhanced Due Diligence” additional information, verification, approval and monitoring applied to increased-risk circumstances.
“HIO” a head of an international organization and, where applicable, a family member or closely associated person.
“IPI” Innovate Payments Inc., the provider responsible for compliance decisions relating to the Exchange Service and Fiat Service.
“KYC” Know Your Customer identity, verification and customer due-diligence measures.
“LMLP” LMLP consulting s.r.o., the non-contracting technical verification and routing provider.
“PEP” a politically exposed person and, where applicable, a family member or close associate.
“Provider” Plum Labs, Capitalista or IPI when acting in relation to the service allocated to it.
“Source of Funds” the origin of the specific fiat funds or crypto-assets used in a transaction.
“Source of Wealth” the origin of a person’s overall wealth or net worth.
“Travel Rule” requirements to collect, retain and transmit prescribed originator and beneficiary information with certain funds or virtual-currency transfers.
“Ukraine Service Route” the service configuration intended for eligible users under the Ukraine App Store storefront and the applicable residence and Actual Location controls.