Anti-Money Laundering Policy

Last updated: 6 September 2026

1. Purpose and Scope

This Anti-Money Laundering Policy (AML Policy) sets out the controls DataPasa Limited applies to prevent its services and its payment channels from being used for money laundering, terrorist financing, sanctions evasion or the handling of criminal property.

It applies to every customer, every account and every payment made to us, whether by bank card, e-wallet or cryptocurrency. It applies whether you are a consumer or a business customer, and regardless of the country you are located in.

2. Status of This Policy

This AML Policy is an integral part of our Terms of Service and is incorporated into them by reference. By creating an account, funding a balance or using any DataPasa service, you accept this AML Policy and agree to comply with it. A breach of this AML Policy is a breach of the Terms of Service and may lead to suspension or termination under section 7 of those Terms. Where this AML Policy conflicts with any other document we publish, this AML Policy prevails on matters of money laundering, terrorist financing and sanctions.

3. Our Position

DataPasa Limited is a hosting provider. We are not a bank, a payment institution, an electronic money institution or a cryptoasset business. We do not exchange cryptoassets for third parties, we do not transmit value between third parties, and we do not provide custodian wallets. Cryptocurrency and card payments are handled on our behalf by external payment providers.

The prepaid balance held against your account is not a deposit, not electronic money and not a payment account. It is an advance payment for hosting services, it pays for those services only, and it cannot be transferred to another person.

We nevertheless operate the controls described below. UK criminal law on money laundering, terrorist financing and financial sanctions binds every business in the United Kingdom, not only regulated financial firms, and we align our internal standards with the customer due diligence, monitoring and record keeping requirements set out in the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017.

4. Legal Framework

This AML Policy is designed around the following United Kingdom legislation and guidance:

  • Proceeds of Crime Act 2002, in particular the principal money laundering offences at sections 327 to 329 and the authorised disclosure regime at section 338.
  • Terrorism Act 2000, in particular the terrorist property offences at sections 15 to 18.
  • Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, which we use as our benchmark for customer due diligence, enhanced due diligence, ongoing monitoring and record retention.
  • Sanctions and Anti-Money Laundering Act 2018 and the financial sanctions regimes made under it, which apply to all persons in the United Kingdom and to UK companies wherever they operate.
  • Criminal Finances Act 2017, including the corporate offences of failing to prevent the facilitation of tax evasion.
  • UK GDPR and the Data Protection Act 2018, which govern how we handle any identity information we collect under this AML Policy.

We also have regard to guidance published by HM Treasury, the Office of Financial Sanctions Implementation (OFSI), the National Crime Agency (NCA) and the Financial Action Task Force.

5. Risk-Based Approach

We apply a risk-based approach. The depth of the checks we carry out on an account is proportionate to the risk that account presents. We assess risk on an ongoing basis using factors including:

  • The payment method used and the amounts and frequency of top-ups.
  • The country the customer is connecting from or claims to be resident in, including whether it is a high-risk third country or subject to sanctions.
  • The results of blockchain analytics screening on cryptocurrency payments.
  • The results of our automated fraud and abuse checks, described in our Privacy Policy.
  • The nature of the workload hosted and any abuse reports received about it.
  • Whether the account behaviour matches the stated purpose of the service.

Most customers will never be asked for identity documents. Checks are triggered by risk, not applied to everyone by default.

6. Payments and Source of Funds

  • Own funds only. You may fund your balance only with money or cryptoassets that you legally own and that come from a legitimate source. You must not fund an account on behalf of an undisclosed third party.
  • No third-party payments. The payment instrument must belong to the account holder. We may reject or reverse a payment where the payer and the account holder do not match. Resale that has been disclosed to us and agreed under section 11 is not a third-party payment for the purposes of this rule: the reseller is our customer, pays us from its own funds, and carries the obligations set out in that section in respect of its own end users.
  • No pass-through. Our balances exist to pay for hosting. You must not use top-ups and refunds to move value, to convert between payment methods, or to create a transaction history for any purpose other than buying our services.
  • Refunds follow the source. Where a refund is due under our Refund Policy, we return funds to the original payment method wherever technically possible. We will not send a refund to a different person, a different card or a different wallet in order to work around this rule.
  • No cash. We do not accept cash in any form.

7. Cryptocurrency Deposits

Every cryptocurrency deposit made to DataPasa is screened before the corresponding balance is released for use. Screening is carried out by our cryptocurrency payment provider using blockchain analytics, and is supplemented by our own risk checks on the receiving account.

Screening traces the origin of the incoming funds across the blockchain and scores their exposure to known illicit activity. A deposit may be held, rejected or returned where the analysis shows a material link to any of the following:

  • Addresses designated under UK, United Nations, European Union or United States sanctions programmes.
  • Darknet marketplaces and illegal goods vendors.
  • Ransomware payments, extortion and fraud proceeds.
  • Coin mixers, tumblers and other services whose purpose is to obscure the origin of funds.
  • Funds stolen in exchange or protocol hacks.
  • Terrorist financing and child sexual abuse material.
  • Exchanges and services with no meaningful anti-money laundering controls, and exchanges operating in sanctioned jurisdictions.

Where a deposit is flagged, we will not credit the balance until the flag is resolved. We may ask you to evidence the source of the funds, we may return the funds to the originating address, and where the law requires it we may be unable to return them at all. We are not able to release funds where doing so would itself be a criminal offence.

Deposits sent from a mixer, from a privacy service designed to defeat tracing, or from an address you do not control, may be refused. Sending such funds to us does not create an obligation on our part to return them to an address of your choosing.

8. Identity Verification and KYC

Where our checks identify indicators of money laundering, terrorist financing, sanctions exposure or other financial crime, and where we are permitted or required to do so by law, we may require you to complete identity verification, known as KYC, before your account, your balance or your services can continue to be used.

Depending on the risk identified, we may ask an individual customer for:

  • Full legal name, date of birth and residential address.
  • A government-issued photographic identity document, such as a passport, national identity card or driving licence.
  • Proof of address issued within the last three months, such as a utility bill or bank statement.
  • A photograph or short video of you holding the identity document, to confirm that the document belongs to you.
  • Evidence of the source of the funds used to pay us, such as a bank statement, an exchange withdrawal record or a payslip.
  • Proof of control of the cryptocurrency address a deposit was sent from, such as a signed message.

Where the customer is a company or other legal entity, we may additionally ask for:

  • The certificate of incorporation and the registered address.
  • Details of directors and of any beneficial owner holding more than 25 per cent of the entity. This threshold is the customer due diligence standard and is deliberately lower than the ownership and control threshold used for sanctions in section 10, because the two tests answer different questions: who ultimately owns our customer, and whether an entity is caught by a designation.
  • Identity documents for those individuals.
  • Evidence of the authority of the person acting for the entity.

We will tell you what we need and give you a reasonable period to provide it. While a verification request is outstanding we may restrict top-ups, refunds, the provisioning of new services or access to the account. If you do not complete verification within the period we specify, or if the documents provided are not adequate, we may suspend or close the account under section 13 of this AML Policy.

9. Risk Indicators

The following are examples of circumstances that may trigger enhanced checks, a verification request or a report. The list is illustrative and not exhaustive:

  • A cryptocurrency deposit that screening links to a sanctioned address, a mixer, a darknet market or stolen funds.
  • Top-ups that are large or frequent relative to the services actually consumed, or a balance that is funded and then immediately requested back.
  • Payments from multiple different cards, wallets or people into a single account.
  • A single person operating multiple accounts, or accounts sharing device fingerprints, addresses or payment instruments.
  • A customer, a payer or a connecting address linked to a sanctioned country or to a high-risk third country.
  • Reluctance to provide information, provision of documents that appear altered, or information that conflicts with what we already hold.
  • Use of anonymising infrastructure to conceal the true location of the customer in combination with other indicators.
  • Resale or sub-letting of our capacity to third parties that was not disclosed to us, or an account whose traffic, address usage or abuse profile indicates that the real users are people we have never been told about.
  • A disclosed reseller who cannot identify the end user behind a specific server or IP address when we ask.
  • Abuse reports connecting the hosted workload to fraud, phishing, ransomware or the distribution of illegal material.
  • Any attempt to structure payments so that they stay below a threshold the customer believes will trigger a check.

10. Sanctions

We do not provide services to, and do not accept funds from, any person or entity that is subject to United Kingdom financial sanctions. We screen against the UK Sanctions List maintained by the Foreign, Commonwealth and Development Office, which is the single consolidated source of UK designations. We also take account of United Nations, European Union and United States sanctions programmes where they are relevant to a payment or a counterparty.

We do not screen for name matches alone. A person or company is treated as sanctioned, and is refused, where it is directly designated, or where it is owned or controlled by one or more designated persons. In assessing this we look at ownership of more than 50 per cent of the shares or voting rights, including holdings that only exceed that threshold when the interests of several designated persons are added together, and at control in fact, such as the ability to appoint or remove a majority of the board or to direct the affairs of the entity by any other means. Ownership and control can sit behind several layers of holding companies, and we look through those layers where the information is available to us.

Designations are made in batches throughout the year, so a customer who was clear when they registered may not be clear later. We re-screen the existing customer base against the UK Sanctions List at least weekly, and again whenever the list is updated.

Where we identify a sanctions match, we will freeze the relevant funds and the relevant account, we will not process the transaction, and we will report the matter to the Office of Financial Sanctions Implementation as required. Sanctioned funds cannot be returned to you without the appropriate licence. You must not use our services to circumvent, or to help another person circumvent, any sanctions regime.

11. Prohibited Conduct and Resale

In addition to our Acceptable Use Policy, you must not:

  • Pay us with the proceeds of crime, or with funds you have reason to believe are the proceeds of crime.
  • Use our services or our balances to layer, disguise or move criminal property.
  • Provide false, stolen or altered identity information or documents.
  • Open or operate an account on behalf of a person who is subject to sanctions, or who is concealing their identity from us.
  • Host infrastructure whose purpose is fraud, ransomware, phishing, the operation of an unlicensed money transmission or exchange business, or an investment scheme operated without the required authorisation.
  • Structure or split payments in order to avoid a control described in this AML Policy.
  • Resell, sub-let or otherwise provide our capacity, IP addresses or network to third parties without first disclosing that to us in writing and obtaining our agreement. This includes operating a hosting, VPN, proxy or bulk email business on top of our infrastructure.

We operate our own network and address space, and infrastructure that is resold onward is the point at which we have least visibility of who is actually being served. We therefore treat undisclosed resale as a serious breach. Where resale is disclosed and agreed, the following conditions apply for as long as the arrangement continues:

  • Comparable controls. You must apply anti-money laundering, sanctions and acceptable use controls to your own customers that are at least equivalent to those in this AML Policy, including screening them against the UK Sanctions List, and you must be able to describe those controls to us on request.
  • Identification of end users. You must keep records identifying which of your customers is behind each server and each IP address you take from us, and you must be able to produce them.
  • Disclosure on request. Where we receive an abuse report, a law enforcement request, a sanctions alert or any other financial crime signal touching your capacity, you must provide the identity and contact details of the end user concerned within the period we specify, which will be no longer than the deadline we ourselves are working to. Inability or refusal to do so is treated as a risk indicator under section 9.
  • Pass-through of suspension. You must be able to suspend an individual end user promptly at our request. If you cannot, we will suspend the whole account instead.
  • No onward resale beyond one level without our specific written agreement, because each additional layer removes the ability of anyone to identify the end user.

12. Monitoring and Records

Monitoring is automated at the point of the transaction and human at the point of an alert. Every payment is screened automatically as it is made, before the balance is released, and our automated account checks run continuously. A person reviews an account when one of those checks raises an alert, when an abuse report or a law enforcement request arrives, when a customer is matched during the periodic re-screening described in section 10, and when a verification request is answered. We do not review every transaction by hand, and we do not claim to. The automated checks that affect your account are described in our Privacy Policy, together with your right to ask for a human review of a decision.

We keep records of transactions, screening results, verification documents and the reasoning behind any decision taken under this AML Policy for five years from the end of our relationship with you or from the date of the transaction, whichever is later, in line with the retention standard in the 2017 Regulations. Where a longer period is required by law, or where records are needed for ongoing legal proceedings or an active investigation, we keep them for that longer period. These records are retained even if you delete your account, because we are not able to delete evidence we are required to hold.

13. Reporting and Consequences

Where we know or suspect, or have reasonable grounds to know or suspect, that funds or property are connected with money laundering or terrorist financing, we will make a disclosure to the National Crime Agency and, where relevant, seek consent before proceeding with a transaction.

We may not be able to tell you that a report has been made. Under section 342 of the Proceeds of Crime Act 2002 it is an offence to make a disclosure that is likely to prejudice a money laundering investigation, and that offence is not limited to regulated firms. Where we cannot explain a decision, this is the reason, and it is not a refusal to engage with you.

Where this AML Policy is breached, or where a risk cannot be resolved, we may take any of the following steps:

  • Decline a payment or refuse to credit a balance.
  • Hold funds pending the outcome of screening, verification or a consent request.
  • Restrict top-ups, refunds or the provisioning of new services.
  • Suspend or terminate services and close the account under section 7 of the Terms of Service.
  • Return funds to their source, where it is lawful and technically possible to do so.
  • Retain funds where releasing them would breach sanctions or the Proceeds of Crime Act 2002.
  • Report the matter to the National Crime Agency, OFSI, the police or another competent authority.
  • Decline to provide services to you in future.

We are not liable for losses arising from action taken in good faith under this AML Policy, including the loss of hosted data following a suspension, and including delays caused by a screening hold or by waiting for consent from the authorities.

14. Your Data

Identity documents and screening results are personal data. Our lawful basis for collecting and reviewing them is our legitimate interest in preventing financial crime, which is recognised in Recital 47 of the UK GDPR, together with the performance of our contract with you. Where a specific statutory duty applies, in particular the sanctions regime and the reporting duties under the Proceeds of Crime Act 2002, we also rely on legal obligation. We collect only what the assessed risk requires, we restrict access to staff who need it, and we do not use these documents for marketing or any unrelated purpose. Your rights under UK GDPR, and the limits on those rights where we are required to retain records or are prevented from disclosing a report, are set out in our Privacy Policy.

15. Responsibility and Review

This AML Policy is owned and applied by the director of DataPasa Limited, who is responsible for reviewing screening alerts, deciding on verification requests and making any disclosure to the authorities. The director is the person nominated to receive internal reports of suspicion and to make authorised disclosures for the purposes of section 338 of the Proceeds of Crime Act 2002, and is the point of contact for the National Crime Agency and for the Office of Financial Sanctions Implementation. Where we take on staff or contractors who handle payments or account decisions, they will be briefed on the indicators set out above and on how to escalate a concern before they are given access, and a record of that briefing will be kept. This AML Policy is reviewed at least annually and whenever there is a material change in our payment methods, our customer base or the applicable law.

16. Changes to This Policy

We may update this AML Policy from time to time. The date at the top of this page shows when it was last changed. Where a change materially affects your rights or obligations we will give notice in the customer dashboard or by email. Changes required by law or by a regulator may take effect immediately.

17. Contact

Questions about this AML Policy, and responses to a verification request, should be sent to support@datapasa.com, or raised through a support ticket in the customer dashboard. Our registered address is DataPasa Limited, 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.