Data Processing Agreement (DPA)

Applies to B2B clients who, via our API or an integration, submit data relating to their own end-users. This document is a template; for binding use, sign a version of it and account for the applicable law of your jurisdiction.

1. Roles & subject matter

For AML screening you initiate, you act as the Controller and AMLConsensus (the "Operator", entity details to be added after registration) acts as the Processor, acting on your instructions. The subject matter is screening the blockchain addresses/hashes you submit for risk.

2. Data categories & purpose

3. Processor obligations

4. Sub-processors

To provide the service we engage screening and infrastructure providers. They receive only the address being checked, not personal profiles: sanctions/screening sources (OFAC, Chainalysis, TRM Labs, MistTrack), infrastructure (Cloudflare), email (Zoho), payments (CryptoBot). By using the service you give general authorisation for these sub-processors; we will notify of material changes.

5. Data-subject rights

We reasonably assist you in responding to data-subject requests (access, rectification, erasure, objection) with respect to data processed on your behalf.

6. Deletion & return

On termination or your request, related data is deleted (see also the Privacy Policy and the data-deletion feature), except where the law requires retention.

7. Security incidents

If an incident affects your data, we will notify you without undue delay and provide available information to help you meet your obligations.

8. Audit & assistance

On reasonable request we provide the information needed to demonstrate compliance with this DPA, including a description of security measures.

9. International transfers

Where data is transferred across borders, applicable data-protection safeguards are used.

10. Governing law

To be specified after entity registration. Until then, the general approach set out in the Terms of Service applies.

Request a signed DPA: support@amlconsensus.com.