Applies to B2B clients who, via our API or an integration, submit data relating to their own end-users. This document is a template; for binding use, sign a version of it and account for the applicable law of your jurisdiction.
For AML screening you initiate, you act as the Controller and AMLConsensus (the "Operator", entity details to be added after registration) acts as the Processor, acting on your instructions. The subject matter is screening the blockchain addresses/hashes you submit for risk.
To provide the service we engage screening and infrastructure providers. They receive only the address being checked, not personal profiles: sanctions/screening sources (OFAC, Chainalysis, TRM Labs, MistTrack), infrastructure (Cloudflare), email (Zoho), payments (CryptoBot). By using the service you give general authorisation for these sub-processors; we will notify of material changes.
We reasonably assist you in responding to data-subject requests (access, rectification, erasure, objection) with respect to data processed on your behalf.
On termination or your request, related data is deleted (see also the Privacy Policy and the data-deletion feature), except where the law requires retention.
If an incident affects your data, we will notify you without undue delay and provide available information to help you meet your obligations.
On reasonable request we provide the information needed to demonstrate compliance with this DPA, including a description of security measures.
Where data is transferred across borders, applicable data-protection safeguards are used.
To be specified after entity registration. Until then, the general approach set out in the Terms of Service applies.
Request a signed DPA: support@amlconsensus.com.