Privacy Policy
Effective Date: 11 August 2026
1. Introduction
Risk Watcher LLC (formerly known as AMLWATCHER.com LLC ,the Service Provider has formally transitioned its corporate identity to Risk Watcher LLC; however, our core platform and product offerings shall maintain the recognized brand name "AML Watcher"), incorporated in Delaware, United States, together with its affiliated entities (“AML Watcher”, “we”, “us”, or “our”), provides compliance and risk management services globally.
(For the purposes of this policy, any reference to the ‘‘Service Provider’’ shall be deemed to refer to ‘‘Risk Watcher’’ and any reference to the ‘‘Platform’’ shall be deemed to refer to ‘‘AML Watcher’’ regardless of whether such terms are capitalized herein.)
In the course of providing these Services, AML Watcher processes Personal Data on behalf of its Clients, who act as Data Controllers and determine the purposes and means of processing. In this context, AML Watcher acts as a Data Processor and processes Personal Data in accordance with Client instructions.
AML Watcher may also process Personal Data as an independent Data Controller where necessary to operate, secure, and improve its services, including for analytics, fraud prevention, model training, and product development, in accordance with applicable data protection laws.
This Privacy Policy explains how Personal Data is collected, used, disclosed, and protected when processed through AML Watcher’s platforms and services. It also describes the rights available to individuals whose Personal Data is processed in connection with those services.
This Policy applies to all Personal Data processed by AML Watcher in connection with its services, including data processed on behalf of Clients and data processed independently as a Controller. It is designed to comply with applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR) and UK GDPR for data subjects in the European Economic Area (EEA) and United Kingdom, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) for California residents,Delaware Personal Data Privacy Act for Delaware residents and other relevant laws such as those in the UAE, Pakistan, or other jurisdictions where Clients or data subjects are located.
2. Scope and Governing Law
This Privacy Policy governs the processing of Personal Data by Service Provider across all its platforms, services, websites, and applications, regardless of the location of the data subject, Client, or end-user. It applies to Personal Data collected directly from individuals, from Clients, or from third-party sources in the course of providing Anti-Money Laundering (AML) compliance services.
The Policy is governed by the data protection laws applicable to the processing activities, determined by factors such as the location of data subjects, the territory of Clients, and the nature of data transfers. Specifically, AML Watcher adheres to:
- The General Data Protection Regulation (EU GDPR) and UK GDPR for data subjects located in the European Economic Area (EEA) and United Kingdom;
- The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA) for California residents;
- The Delaware Personal Data Privacy Act (DPDPA) and applicable US state privacy laws; and
- Equivalent local privacy statutes across jurisdictions where our Clients operate (e.g., UAE Federal Decree-Law No. 45/2021 on Personal Data Protection).
Where conflicts arise between international privacy frameworks, AML Watcher will apply the strictest applicable standard to protect Personal Data.
AML Watcher maintains a dedicated Data Protection Officer (DPO) to oversee compliance. The DPO can be contacted at dpo@amlwatcher.com for any inquiries related to this Policy or data protection matters.
Dispute Resolution Note: While the statutory privacy rights of Data Subjects are governed by their respective local and international privacy laws, any legal disputes, claims, or arbitration arising between AML Watcher and its Clients regarding this Privacy Policy shall be governed exclusively by the laws of the State of Delaware, USA, and resolved via binding arbitration as strictly detailed in Section 16.9 of our Terms & Conditions.
3. Role of AML Watcher
A. Data Processor
When providing services to its Clients, AML Watcher acts as a Data Processor, processing Personal Data solely on behalf of and in accordance with the documented instructions of its Clients, who act as Data Controllers. In this capacity, AML Watcher does not determine the primary purposes or means of processing. All processing activities are governed by Data Processing Agreements (DPAs) with Clients, incorporating requirements from GDPR Article 28, including confidentiality, security, and audit rights.
B. Independent Data Controller
In limited and defined circumstances, AML Watcher acts as an independent Data Controller, including where Personal Data is processed for platform security, fraud prevention, operational analytics, and systemic enhancements. The lawful basis for such processing is set forth in Section 7 below, and a detailed Legitimate Interests Assessment (LIA) is maintained for each such activity.
C. Reconciliation of Roles
In accordance with Clause 1.8 of the Terms & Conditions, Client Data that has been irreversibly anonymized and aggregated ceases to constitute Client Data and becomes the proprietary property of Risk Watcher LLC. For such anonymized/aggregated derivatives, AML Watcher acts as an independent Data Controller as permitted under Clause 10.1 and Clause 11.3 of the Terms & Conditions. For all identifiable Client Data, AML Watcher remains strictly a Data Processor bound by Client instructions. This dual role is expressly contemplated by the Terms & Conditions and does not create any conflict in AML Watcher's obligations.
4. Proprietary Anonymized & Aggregated Data (AI/ML Optimization)
In accordance with Clause 1.8 and Clause 10.1 of our Terms & Conditions, AML Watcher may process Client Data to generate anonymized, aggregated, or statistical derivatives for algorithmic refinement, machine learning model optimization, predictive modeling, threat detection, and systemic enhancement.
Where Personal Data is transformed into aggregated derivatives:
- Anonymization Standard: We enforce technical and organizational safeguards to ensure data subjects can no longer be identified directly or indirectly.
- Proprietary Ownership: Once irreversibly anonymized and aggregated, such derivatives cease to constitute Personal Data under GDPR, CCPA, and DPDPA, and become the sole proprietary property of Risk Watcher.
- Lawful Basis (GDPR Art. 6(1)(f)): The preliminary processing required to anonymize data relies on our legitimate interest in improving our financial crime compliance platform, including model training and threat detection, as further detailed in Section 7. A Legitimate Interests Assessment (LIA) is maintained for this activity, balancing AML Watcher's operational needs against data subject rights.
5. Categories and Sources of Personal Data
AML Watcher processes Personal Data as necessary to deliver its services. The categories of data processed depend on the configuration selected by Clients and are detailed in the following sub-sections.
To provide further transparency, the following detailed categories are processed where relevant:
- Identity Data: Full names, aliases, dates of birth, nationality, gender, passport numbers, national ID numbers, driver's license details, and other government-issued identification.
- Contact Data: Email addresses, phone numbers, postal addresses, and social media handles.
- Financial Data: Bank account numbers (masked), transaction histories, wallet addresses (crypto), payment details, and credit scores where integrated.
- Compliance Data: Sanctions/PEP/watchlist matches, adverse media reports, risk scores, beneficial ownership structures, and source-of-funds declarations.
- Technical and Usage Data: IP addresses, browser types, device IDs, operating systems, session logs, API call data, page views, and interaction timestamps.
- Aggregated/Anonymized Data: Non-personal statistical outputs from analytics, which fall outside this Policy's scope once anonymized.
Where identity verification services are used, AML Watcher may process biometric data derived from facial recognition technologies. Such processing is subject to enhanced safeguards and is performed only where:
(a) the Client, as Data Controller, has identified a lawful basis under applicable law (including, where required, the explicit consent of the data subject); and
(b) such processing is permitted under the applicable Data Processing Agreement and the Client's documented instructions.
Biometric data is encrypted at rest and in transit, stored separately from other Personal Data, and subject to strict access logging.
Personal Data processed by AML Watcher is obtained from multiple sources. These include data provided directly by Clients, publicly available sources such as government registers and official sanctions lists, licensed third-party data providers, blockchain analytics providers, and open-source intelligence, including global media publications. Clients upload data via secure APIs or portals; third-party sources are vetted for compliance (e.g., SOC 2 certified).
6. Purposes of Processing
AML Watcher processes Personal Data primarily to enable its Clients to comply with legal and regulatory obligations relating to financial crime prevention. This includes customer due diligence, sanctions and watchlist screening, adverse media analysis, transaction monitoring, and risk assessment.
In addition, AML Watcher processes Personal Data to support crypto compliance use cases, including blockchain transaction analysis, wallet screening, and facilitating regulatory requirements such as Travel Rule data exchange between Virtual Asset Service Providers (VASPs). Specific examples include tracing crypto flows across chains, identifying mixer/tumbler usage, and generating Travel Rule-compliant reports.
Where AML Watcher acts as a Data Controller, Personal Data may also be processed to maintain and improve services, enhance detection models, ensure system security and integrity, prevent misuse, and perform internal analytics. All such processing is conducted in a manner that is proportionate and limited to what is necessary. For clarity, the table below maps key purposes to data categories and legal bases:
| Purpose | Data Categories Involved | Primary Legal Basis (GDPR/CPRA) |
| Customer Due Diligence & Screening | Identity, Contact, Compliance | Legal Obligation; Performance of Contract |
| Transaction & Wallet Monitoring | Financial, Technical, Compliance | Legitimate Interests (Fraud Prevention); Legal Obligation |
| Blockchain Analysis & Travel Rule | Financial, Wallet Data, Identity | Contractual Performance; Legal Obligation (VASP Rules) |
| Service Improvement & ML Training | Anonymized / Aggregated Derivatives | Legitimate Interests (Platform Optimization) |
| Platform Security & Fraud Defense | Technical, Usage, Identity | Legitimate Interests; Vital Interests |
7. Legal Basis For Processing
Where AML Watcher acts as a Data Controller, it relies on one or more lawful bases for processing Personal Data. These include compliance with legal obligations, particularly those relating to AML/CFT requirements; the performance of tasks carried out in the public interest, such as the detection and prevention of financial crime; and legitimate interests pursued by AML Watcher, including service improvement and system security, provided that such interests are not overridden by the rights and freedoms of individuals. Legitimate interests assessments (LIAs) are documented for each activity, weighing AML Watcher's needs against data subject rights (e.g., anonymization where possible).
Where special categories of Personal Data are processed, including biometric data, AML Watcher relies on explicit consent where required, or other lawful bases permitted under applicable law, including substantial public interest grounds related to financial crime prevention. Consent is obtained via granular, withdrawable mechanisms; for public interest, reliance is on GDPR Art. 9(2)(g) or equivalents.
8. Automated Processing and Profiling
AML Watcher employs advanced analytical systems, including artificial intelligence and machine learning models, to support the identification of financial crime risks. These systems analyse patterns across transactional data, sanctions lists, adverse media, and other relevant datasets to generate risk indicators and match scores. Models are trained on historical compliance data, with regular bias audits and explainability features (e.g., SHAP values for key decisions).
Such processing may involve profiling individuals for compliance risk purposes. However, AML Watcher does not make decisions that produce legal or similarly significant effects solely by automated means. Final decisions, including onboarding or account restrictions, are made by the Client acting as Data Controller. Risk scores are advisory, with thresholds configurable by Clients.
Where applicable, individuals have the right to request human intervention, express their views, and contest decisions affecting them. Requests are handled within 72 hours, involving senior compliance review. Transparency notices explain model logic at a high level (e.g., "Risk based on transaction velocity, geo-IP mismatch, PEP status").
9. Data Retention, Export & Deletion Protocols
AML Watcher retains Personal Data only for as long as necessary to fulfill the operational, contractual, and regulatory purposes outlined in this Policy.
A. Active Contract Term
Compliance logs and verification data are retained for the duration specified in the applicable Statement of Work (SOW), or up to 5 years where mandated by international AML/CFT regulations.
B. Post-Termination Retention & Destruction (T&C Clauses 3, 10.3, & 15.1)
- 10-Day Data Export Request Window: Upon termination of the Client Agreement, the Client has ten (10) calendar days to submit a written request for the return or delivery of Client Data, subject to full settlement of outstanding fees.
- Six-Month Retention Period: If no export request is received, AML Watcher shall retain Client Data securely for a maximum of six (6) months following termination, unless a shorter period is requested in writing by the Client.
- Irrecoverable Deletion: Upon expiry of the Retention Period, or upon the Client's earlier written request, AML Watcher shall permanently delete all Client Data in its possession. Once deleted, data cannot be recovered. The Client retains sole responsibility for maintaining backup copies of all Client Data prior to submitting any deletion request.
10. International Data Transfers
Given the global nature of its operations, AML Watcher may transfer Personal Data to jurisdictions outside the European Economic Area or the United Kingdom, including the United States and other countries in which it operates. Transfers occur for service delivery (e.g., US servers), sub-processor support, or group reporting.
Where such transfers occur, AML Watcher implements appropriate safeguards to ensure that Personal Data is protected in accordance with applicable data protection laws. These safeguards include the use of Standard Contractual Clauses, recognised data transfer mechanisms where applicable, and supplementary technical and organisational measures. UK extension to EU SCCs or IDTA/Addendum used for UK adequacy. If eligible, EU-US Data Privacy Framework (DPF) self-certification applies.
AML Watcher conducts transfer risk assessments where required to evaluate and mitigate risks associated with cross-border data transfers. Transfer Impact Assessments (TIAs) are performed annually or on changes, documented per Schrems II. Data is stored primarily in US (AWS/GCP with EU options), UAE, or Client-specified regions.
11. Data Security
AML Watcher maintains a comprehensive information security program compliant with international standards (ISO 27001 / SSAE standards):
- Encryption: Data in transit is protected using Secure Sockets Layer (SSL) / Transport Layer Security (TLS). Data at rest is encrypted using AES 256-bit or SHA-256 cryptographic algorithms.
- Access Control: Strict role-based access control (RBAC), multi-factor authentication (MFA), and zero-trust administrative architectures are enforced.
- System Integrity: Continuous logging via SIEM tools, annual penetration testing, and routine Vulnerability Assessments and Penetration Testing (VAPT) are conducted across all server infrastructure.
12. Sharing and Disclosure of Personal Data
A. Integration & Vendor Support
AML Watcher utilizes trusted third-party sub-processors (such as cloud hosting providers and specialized data vendors) to deliver service functionality. All sub-processors are contractually bound under Data Processing Agreements to maintain strict confidentiality and security protocols.
B. Dynamic Integration Rights (T&C Clause 6.2)
Risk Watcher retains the right to alter, suspend, or terminate integrations with third-party services based on operational needs, legal mandates, or vendor agreement modifications. Where such changes are initiated by Risk Watcher (rather than by the third-party vendor), Risk Watcher shall provide reasonable advance notice to the Client and shall use commercially reasonable efforts to minimize service disruption. Risk Watcher assumes no liability for service disruptions, delayed verifications, or adverse consequences resulting from third-party vendor modifications, discontinuation of services, or Client-selected custom integrations as described in Section 12C below.
C. Client-Selected Third-Party Liabilities
Risk Watcher is not responsible for any data breaches, security incidents, or privacy violations arising from external plugins, custom APIs, widgets, or third-party platforms that Clients independently choose to integrate with AML Watcher Cloud Services. This provision operates independently of Clause 6.2 of the Terms & Conditions, which addresses Service Provider-initiated changes to third-party integrations.
13. Cookies and Similar Technologies
AML Watcher uses cookies, web beacons, and SDKs on its websites to manage sessions, analyze system performance, and improve user navigation:
- Essential Cookies: Strictly necessary for core platform security and system access.
- Analytics Cookies: Used to evaluate site performance and interaction trends (IP addresses are anonymized).
- Functional/Advertising: Personalization or retargeting; consent-based via banner.
Users may adjust cookie preferences at any time via their web browser settings or by accessing our dedicated Cookie Policy at [https://amlwatcher.com/privacy-policy/#aml-cookies-policy](https://amlwatcher.com/privacy-policy/#aml-cookies-policy).
14. Children’s Privacy
AML Watcher platforms are designed exclusively for business compliance operations and do not knowingly collect Personal Data directly from children. In cases where Client compliance checks involve the verification of minors (e.g., family members of Politically Exposed Persons), the Client acts as Data Controller and assumes sole responsibility for ensuring a lawful legal basis and obtaining necessary legal guardian consents.
15. Data Subject Rights (GDPR & International Frameworks)
Subject to applicable data protection laws, individuals have rights in relation to their Personal Data. These may include the right to access, correct, or delete Personal Data; to restrict or object to processing; to request data portability; and to withdraw consent where processing is based on consent.
Individuals also have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
Requests to exercise these rights may be submitted using the contact details below. Where AML Watcher acts as a Data Processor, such requests may be redirected to the relevant Client acting as Data Controller. We respond within one month (extendable by two months for complexity), free of charge unless manifestly unfounded/excessive (reasonable fee applies). Verification (e.g., ID copy) may be required. Use our web form at https://amlwatcher.com/contact-us/ For EU/UK: ICO (ico.org.uk), CNIL (cnil.fr), etc.; lodge complaints post-internal review.
16. California Privacy Rights Act (CCPA/CPRA) Notice
This section applies solely to California residents ("consumers").
A. Categories of Personal Information Collected & Disclosed (Past 12 Months)
- Identifiers: Real name, alias, address, IP address, email, passport/driver's license number. (Disclosed to: Cloud Hosts, Verification Partners).
- Protected Classifications: Date of birth, gender, nationality. (Disclosed for: AML/KYC Legal Compliance).
- Commercial & Financial Information: Transaction records, crypto wallet addresses, risk profiles. (Disclosed for: Risk Analysis & Transaction Screening).
- Biometric Information: Facial geometry vectors derived from identity documents. (Processed solely upon explicit authorization).
- Internet/Network Activity: Session logs, API timestamps, diagnostic reports. (Disclosed for: System Security & Performance Analytics).
B. Sale or Sharing of Personal Information
AML Watcher does NOT sell personal information for monetary consideration. AML Watcher does NOT share personal information for cross-context behavioral advertising.
C. Sensitive Personal Information (SPI) Handling
Sensitive Personal Information (including government IDs and biometric data) is processed strictly to perform requested financial verification services and satisfy statutory compliance duties. We do not use SPI for inferring consumer characteristics.
D. California Consumer Rights
California consumers have the Right to Know, Access, Correct, and Delete their personal information, as well as the Right to Non-Discrimination for exercising their privacy rights. Requests can be submitted to dpo@amlwatcher.com. Identity verification is required prior to fulfilling CPRA requests.
17. Third Party Links
AML Watcher platforms may contain links to third-party sites (e.g., sanctions lists, Client portals). We disclaim liability for their privacy practices—review their policies separately. Embeds (e.g., maps) do not share Personal Data without consent.
18. Data Breaches
In the event of a Personal Data Breach, AML Watcher will respond in accordance with applicable legal requirements. This includes notifying affected Clients without undue delay and cooperating with them to meet regulatory obligations, including notification to supervisory authorities where required.
19. Glossary of Key Terms
- Personal Data: Any information relating to an identified or identifiable natural person (GDPR Art. 4).
- Client: Entity acting as Data Controller using our services.
- Services: AML compliance platforms for screening, monitoring, etc.
- Processing: Any operation on Personal Data (collect, store, analyze, etc.).
20. Updates to Policy & Corporate Restructuring
Material changes (e.g., new purposes, changes to data processing activities) trigger platform notices to Clients and users. Continued use of the platform following the effective date of such material changes constitutes acceptance of the updated Policy. Non-material changes (including formatting, grammatical corrections, or clarification of existing provisions) will be published with a revised effective date without separate notice. For the avoidance of doubt, corporate identity or branding changes do not constitute material changes and do not require separate notice.
21. Contact Information
For questions about this Privacy Policy or to exercise your rights, please contact:
General Inquiries: info@amlwatcher.com
Legal & Privacy: legal@amlwatcher.com
Data Protection Officer: dpo@amlwatcher.com
Website: https://amlwatcher.com/contact-us/