Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal information when you use our AML compliance platform.
Legal Basis
AML Proof s.r.o. processes personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the cornerstone of European data protection law.
The GDPR was adopted by the European Parliament and the Council of the European Union and is enforced under the supervision of the European Data Protection Board (EDPB) together with the national data protection authorities of each EU Member State.
AML Proof s.r.o., as the data controller, determines the purposes and means of processing your personal data when you use our platform.
AML Proof s.r.o. acts as a processor in relation to the personal data of clients of Obliged Entities. You, as the obliged entity, remain the data controller of this data. Our relationship is governed by the Data Processing Agreement (DPA), which is part of our Terms and Conditions.
Legal Obligation
Includes: client identification and due diligence under Sections 7–9 of Act No. 253/2008 Coll., AML record-keeping, sanctions screening, reporting suspicious transactions to the Financial Analytical Unit (FAÚ).
Legitimate Interest
Includes: platform security monitoring, fraud prevention, platform improvement (pseudonymized analytics), commercial communication to existing clients.
Contractual Necessity
Includes: user account operation, generating compliance reports, access to platform features.
Information We Collect
Personal Information
- • Name and contact details
- • Email address and phone number
- • Job title and organization
- • Professional credentials
- • Account preferences
Usage Data
- • Platform usage patterns
- • Feature interactions
- • Session duration and frequency
- • Device and browser information
- • IP address and location data
Compliance Data
- • AML case information
- • Risk assessment data
- • Training records
- • Audit trail information
- • Regulatory reporting data
Technical Information
- • Cookies and tracking pixels
- • Log files and error reports
- • Performance metrics
- • Security event logs
- • API usage statistics
How We Use Your Information
Service Provision
- Provide and maintain our AML compliance platform
- Process and manage compliance cases
- Generate reports and analytics
- Facilitate training and certification
Communication
- Send service updates and notifications
- Provide customer support
- Share regulatory updates
- Deliver training materials
Improvement
- Analyze usage patterns and performance
- Develop new features and services
- Enhance security measures
- Optimize user experience
Compliance
- Meet legal and regulatory obligations
- Respond to lawful requests
- Maintain audit trails
- Protect against fraud and abuse
Data Security & Protection
We implement comprehensive security measures to protect your personal information from unauthorized access, use, or disclosure.
Technical Safeguards
- Data transmission encryption (TLS 1.2/1.3)
- Advanced encryption for data at rest
- Modern authentication (magic link and OAuth 2.0)
- Regular security monitoring and audits
Operational Controls
- Role-based access controls
- Security training programs for employees and persons in a comparable position programs
- Incident response procedures
- Regular backup and recovery testing
Privacy when using AI
- For processing within the platform, we use Google Gemini 2.5 Flash API. On the paid tier, Google does not by default use API inputs and outputs for product improvement or model training (Gemini API Terms — Paid Services).
- For adverse media screening we use Google Gemini 2.5 Flash via Google Vertex AI (Google LLC). The following minimised data is sent to the model: full name of the screened person (required for screening), birth year, country (citizenship / registration), and up to 3 aliases (first in full, remainder as initials). Full date of birth, document numbers, addresses, and contact details are not sent. For automated form completion from a scanned document (Scan to Fill), the document image is sent to Google Vertex AI (gemini-2.5-flash, region europe-west1) — extracted fields include name, date of birth, birth number, address, and document number. On the paid tier, Google does not use API data for product improvement or model training. Transfers outside the EU are governed by the Google Cloud Data Processing Addendum (SCCs under Art. 46(2)(c) GDPR).
Your Privacy Rights
You have important rights regarding your personal information. Contact us to exercise these rights.
Access
Request copies of your personal information
Correction
Update or correct inaccurate information
Deletion
Request deletion of your personal data where legally permissible. Certain AML/CTF compliance records cannot be deleted before the end of mandatory retention periods.
Portability
Export your data in a portable format
Right to Object
Object to processing based on legitimate interest or for direct marketing purposes (Art. 21 GDPR)
Right to Restriction
Request temporary restriction of processing your personal data in cases set out by Art. 18 GDPR
Data Retention
We retain your personal information only as long as necessary to fulfill the purposes outlined in this policy and comply with legal obligations.
Account Data
Operational account data (login credentials, settings, preferences) deleted within 30 days of account closure. Compliance records (client identification, AML checks, training) retained for 10 years under Section 16 of Act No. 253/2008 Coll. regardless of account closure.
Compliance Records
We retain data for 10 years in accordance with the legal requirements of AML legislation. Personal data is retained for the period stipulated by Act No. 253/2008 Coll., generally for 10 years from the transaction or the termination of the business relationship.
Usage Analytics
3 years
Annex 1: Data Processing Agreement (DPA)
1. Subject Matter and Roles
This section governs the relationship between the User (Controller) and AML Proof s.r.o. (Processor). The Processor processes the personal data of identified persons in order to enable the Controller to fulfill their obligations under Act No. 253/2008 Coll.
2. Processor's Obligations
- Process data only on documented instructions from the Controller (including parameters set in the application).
- Ensure that persons authorized to process the data have committed themselves to confidentiality.
- Implement appropriate technical and organizational measures (encryption of data in transit and at rest, secure hosting in the EU, minimisation of personal data transmitted to external processors).
- Assist the Controller in fulfilling their obligation to respond to requests for exercising data subjects' rights.
3. Engagement of Sub-processors
The Controller grants general authorization to engage further processors (e.g., EU cloud infrastructure provider). The Processor will inform the Controller of any intended changes.
4. Security
The Processor ensures that personal data is processed in accordance with GDPR. Data transfers to third countries (USA) are conducted solely within the framework of the Google Cloud Platform Terms of Service (Google Cloud Data Processing Addendum), which include Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR. AI models are used without transferring data to third parties for training purposes.
5. Audit
The Processor will allow for and contribute to audits or inspections conducted by the Controller to demonstrate compliance with Article 28 of the GDPR.
6. Termination
Upon termination of the provision of services, the Processor will delete all personal data unless legal obligation (especially Act No. 253/2008 Coll. regarding the 10-year archiving period) requires their further storage.
Questions About Your Privacy?
If you have questions about this privacy policy or how we handle your personal information, please contact our privacy team. AML Proof, s.r.o. consulted its obligation to appoint a Data Protection Officer (DPO) directly with the Czech Data Protection Authority (ÚOOÚ). Based on this consultation, it was confirmed that the company does not meet any of the three statutory conditions for mandatory appointment of a DPO: it is not a public authority, its core activities do not consist of large-scale systematic monitoring of natural persons, and it does not carry out large-scale processing of special categories of personal data (Article 37 GDPR). Therefore, no DPO has been appointed.
If you believe your personal data have been processed unlawfully, you also have the right to lodge a complaint with the Úřad pro ochranu osobních údajů (ÚOOÚ) or with your local supervisory authority within the European Economic Area.