SafeScore AML
Products Modules Reports Pricing

AML report

CASP servicesWho the modules map against GlossaryIndustry terms in the directory Complete checkChain half vs identity half FilingClocks the screen does not run AdvantagesIsolation, live data, labels Use casesWhere a screen sits PositionLombard / real-estate rail BlogMethodology notes Notes indexFull articles AssuranceWhat is certified, and what is not TermsTerms and conditions Data protectionPersonal data processing
Trusted apps Sign up Sign in

Legal

Personal data processing protection policy

This policy describes the personal data this SafeScore origin actually stores when you create an account, run a screen or upload an assistance pack. It is not a GDPR certification, not a claim that SafeScore is your KYC vendor, and not a substitute for the house’s own privacy notice.

Effective 12 September 2026 · Version 2026-09-12 · Last updated 12 September 2026

Also read Terms and conditions.

1. Who processes personal data

The controller of the workspace account, eligibility questionnaire, assistance pack and session cookie is the operator of this SafeScore origin.

A registered company name, company number, registered office, named data-protection officer and Article 27 representative are not published on this page. Those facts are therefore not stated here.

Each examiner (ScoreGuard, ChainTrace, Holistix) stores the screen you run in that product’s own database. Scores are not merged on the control plane.

2. What we collect

Account: name, email, password hash, phone number, and the time the account was created.

Eligibility questionnaire: entity type, selected crypto-asset services, answers to provider-published gates, optional wallet/exchange background, and the score computed from those answers.

Assistance pack: the house you marked, item ticks, free-text notes, and the files you upload (identity scans, proof of address, source-of-wealth evidence and similar documents you choose to attach).

Screens: the wallet, transaction or entity subject you submit, the resulting report, and the workspace token that marks the report as yours.

Session: an HTTP-only cookie named safescore_session so the browser stays signed in. It is not an advertising cookie.

3. Why we process it

To create and operate the workspace you asked for (account, plan metering, eligibility report).

To run the screen you submitted on the examiner you opened, using the indexers configured for that product.

To hold the assistance pack you are assembling so you can complete a house-specific checklist before you open the lender site.

We do not run the pack as the house’s customer-due- diligence file, we do not sell the pack, and we do not use uploaded identity documents for marketing.

4. Files you upload

Pack files are stored on this origin, under your account, against the checklist item you attached them to. Allowed types are ordinary documents and images (PDF, PNG, JPEG, WebP, CSV, text, Word, Excel). Executables are refused. A file is limited to 15 MB; an item may hold up to eight files.

Uploading a file does not send it to the lender. You can download or remove a file from the pack. Removing it deletes the stored copy for that account.

Do not upload documents you have no right to store. SafeScore does not certify authenticity or run liveness on an identity scan.

5. Wallet addresses and chain data

A screen sends the subject you typed to the live indexers configured for this deployment (the fail- closed path Alchemy → QuickNode → Blockscout → Etherscan, and CoinGecko for asset prices). Those providers receive the address or hash you submitted. They are not SafeScore companies.

Public chain data is public. A report may quote cited labels and the OFAC SDN overlay loaded in this build. Unlabelled counterparties stay unlabelled. Permissioned ledgers that cannot be observed are reported as not observable — they are not guessed.

6. Who we share with

We do not sell personal data.

A marked house does not receive your pack automatically. Requesting assistance is an introduction: you still deliver the file on the house’s own channel, and that house’s privacy notice then applies to what you send them.

Indexers and the price feed receive the technical data needed to run a screen, as above. TLS certificates for a public origin are issued by the certificate authority configured for this deployment.

We may disclose data if required by law or to protect a person from serious harm. There is no other sharing described on this page.

7. Cookies

safescore_session is set when you sign in or create an account. It authenticates the workspace. It is not used to advertise on other sites. Signing out clears it.

8. How long we keep it

Account, questionnaire and pack data are kept while the account exists. Pack files you remove are deleted from this origin. Reports stay in the examiner that produced them so My reports can reopen them.

Self-serve account erasure is not built on this origin. You can remove pack files, stop submitting screens, and sign out. To ask for the account itself to be closed, use the email address on that account.

9. Your rights

You can open and download the eligibility report (JSON, CSV, HTML), retake the questionnaire, tick or reopen pack items, and download or delete pack files.

You can ask, via the account email, for a copy of what this origin holds on the account, for a correction, or for the account to be closed. Those requests are handled as the deployment actually allows — there is no separate portal and no claimed statutory deadline published here.

This policy does not name a supervisory authority. Naming one would imply an establishment or a filing that this page does not evidence.

10. International access

This origin may be reached from more than one country. Indexers and the price feed are third-party services. This page does not claim an adequacy decision, standard contractual clauses, or a specific hosting region.

11. Children

The workspace is not directed at children. Do not create an account or upload identity documents for a person under 18.

12. Changes

This policy is version 2026-09-12, effective 12 September 2026. A new version is published on /privacy (also /data-protection). Material changes that affect an existing account are accepted again in the workspace before the assistance pack can be marked complete.

13. What this policy is not

It is not a claim that SafeScore is ISO/IEC 27001 or SOC 2 certified — see /assurance.

It is not a claim that SafeScore verified your identity or that a house will accept the pack.

It is not the privacy notice of Sygnum, AMINA, Arch, Ledn, Unchained or any other directory house.

SafeScore routes AML work into isolated examiners. Each application keeps its own score, database and label book — the control plane does not rescore across products.

Products Modules CASP services Glossary Complete check Filing Advantages Use cases Position Reports Pricing Blog Notes Assurance Terms Data protection Trusted apps Sign in