1. Risk-based approach
The service is prepaid, low value per transaction and non-withdrawable by default, which places it at the low end of the risk spectrum. Controls are therefore risk-based rather than blanket: most customers never see an identity request.
2. Transaction monitoring
All incoming payments are screened by our payment processor against sanctioned-address lists and known illicit-source clusters. Payments from screened-out addresses are rejected and not credited. We monitor for structuring patterns, rapid top-up-and-withdraw behaviour and account-sharing.
3. When we ask for identity
We may request identity verification where cumulative top-ups exceed €2,000 in a rolling 12 months, where a withdrawal is requested, where a payment is flagged by screening, or where account behaviour suggests a third party is funding it. Requests are limited to a government-issued identity document, proof of address and, for companies, the incorporation record and beneficial-ownership declaration.
4. Prohibited sources
Funds derived from crime, from sanctioned jurisdictions or entities, or from mixing services used to obscure origin are not accepted. Accounts funded that way are frozen and reported where the law requires it.
5. Record keeping
Transaction records and any identity documents collected are retained for five years after the end of the customer relationship, as required by applicable anti-money-laundering legislation, then destroyed.
6. Reporting
We report suspicious activity to the competent authority where we are legally obliged to. Where the law forbids it, we will not tell you that a report has been made.