[bracketed] placeholder.
1. Who We Are
EKEDOS LTD. ("we", "us", "our") operates the AML Shield platform (the "Service"). This Privacy Policy explains how we collect, use, and protect personal data when you use our website, dashboard, and API, and — separately — how we process personal data that our customers submit to the Service for screening purposes.
Data Controller contact: [privacy@ekedos.example]
[Registered address] · [Data Protection Officer, if applicable]
2. Two Categories of Data We Process
This policy distinguishes between two roles we play:
- Account & billing data (we are the controller): information about you as our customer — name, work email, organisation details, billing information, login activity, API usage logs.
- Screening subject data (we are the processor): the names, dates of birth, nationalities, identification numbers, transaction details, and similar data that our customers submit via the API to screen their own end-users. We process this data solely on our customers' instructions, as their processor, under the terms of our Terms of Service and, where executed, a Data Processing Agreement.
If you are an individual who was screened by one of our customers and have questions about that processing, please contact that customer directly — they are the data controller for that data, not us.
3. Account & Billing Data We Collect
- Identity & contact: name, email address, job title, phone number.
- Account: organisation name, password (hashed), role, login timestamps.
- Billing: billing address and payment details — processed directly by Stripe; we do not store full card numbers.
- Usage & technical: API request logs (endpoint, timestamp, status code, IP address), audit logs of actions taken in the dashboard, browser/device information.
4. How We Use Account & Billing Data
- To provide, maintain, and secure the Service (contract performance).
- To process subscription payments and manage your account (contract performance).
- To send service-related communications — security alerts, billing notices, verification emails (contract performance / legitimate interest).
- To monitor for fraud, abuse, and to enforce our Terms of Service (legitimate interest).
- To send product updates or marketing, where you have opted in (consent — you may withdraw at any time).
5. Legal Bases (GDPR / UK GDPR)
Where GDPR or UK GDPR applies, we rely on: performance of a contract (providing the Service), legitimate interests (security, fraud prevention, service improvement), legal obligation (e.g. responding to lawful regulatory requests), and consent (marketing communications, where used).
6. Sub-processors & Third Parties
[Placeholder — list all sub-processors that touch customer or screening data, e.g.:]
- Stripe, Inc. — payment processing.
- [Cloud hosting provider] — application and database hosting.
- [Transactional email provider] — sending verification, password reset, and notification emails.
- [Watchlist / sanctions data provider(s)] — supplies reference data used in screening (once licensed data replaces the sample dataset).
- [Error monitoring provider, e.g. Sentry] — application error tracking.
We require sub-processors to provide an equivalent level of data protection through contractual commitments.
7. International Data Transfers
[Placeholder — describe transfer mechanism if data leaves the UK/EEA, e.g. Standard Contractual Clauses, adequacy decisions, or that data is hosted within a specific region.]
8. Data Retention
- Account data: retained for the life of your account and for [X years] after closure for legal, tax, and dispute-resolution purposes.
- API request logs: retained for [X months] for billing, security, and support purposes.
- Audit logs: retained for [365 days / X years] to support compliance and security investigations.
- Screening subject data submitted by customers: retained per the customer's instructions and applicable AML record-keeping law (which may require multi-year retention); see your Data Processing Agreement for specifics.
9. Your Rights
Subject to applicable law (e.g. GDPR, UK GDPR, CCPA), you may have the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate data;
- Request deletion of your data, subject to legal retention obligations;
- Object to or restrict certain processing;
- Request a copy of your data in a portable format;
- Withdraw consent at any time where processing is based on consent;
- Lodge a complaint with your local data protection authority.
To exercise these rights, contact [privacy@ekedos.example].
10. Security
We apply technical and organisational measures appropriate to the sensitivity of the data we process, including encryption of data in transit (TLS), hashed storage of passwords and API keys, role-based access control, and audit logging of account actions. No system is completely secure, and we cannot guarantee absolute security.
11. Cookies
We use essential session cookies required for authentication and security (e.g. CSRF protection). [Add details of any analytics or marketing cookies if used, plus a cookie consent mechanism where required by law.]
12. Children's Privacy
The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from children.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via the dashboard or email at least [14] days before taking effect.
14. Contact Us
Privacy questions or rights requests: [privacy@ekedos.example]
EKEDOS LTD. — [registered address] — [company registration number]
© 2026 EKEDOS LTD. All rights reserved.