← Back to CryptoShield AI

Legal · 2026-05-08 · Cryptoshield AI B.V.

Privacy Policies.

Everything you need to know about how we handle your data, contractually and operationally — in one document.

Contents

  1. Privacy Policy — what data, why, how long, your rights
  2. Cookie Policy — what cookies we set; manage preferences
  3. Sub-processors — third parties that touch personal data
  4. AML & Sanctions Compliance — how we screen our own customers
  5. Data Processing Agreement — the GDPR Art. 28 DPA template (B2B)
  6. Terms of Service — rules of using our site & WALLET

§ 1 of 6

Privacy Policy

Honest. Specific. GDPR-compliant. Effective 2026-05-08.

1.1 Who we are (the Controller)

Cryptoshield AI B.V. ("CryptoShield", "we") — Amsterdam, Netherlands.
KVK: 42020464 · BTW/VAT: NL869325267B01 · adama@cryptoshieldai.ai · privacy@cryptoshieldai.ai
We are the data controller for personal data collected via this website and our products.

1.2 What data we collect

SourceCategories of dataPurposeLegal basis (GDPR Art. 6)
Contact formName, email, company, role, free-text messageRespond to your enquiry, route to the right team1(f) Legitimate interest
Demo intakeSame + intended use case, preferred call timeSchedule and prepare a demo1(b) Pre-contractual measures
B2B sign-upCompany legal entity, KvK / registration number, VAT ID, signatory name + email + role, billing address, IBAN, KYB / UBO data for ENTERPRISE+Fulfil the subscription, comply with AML / KYB obligations1(b) Contract · 1(c) Legal obligation (Wwft)
WALLET sign-upEmail, wallet addresses (public on-chain identifiers), payment ID from Stripe, language preferenceProvide the WALLET protection service1(b) Contract
Inbound AML screenCustomer organisation, country, signatory name (input only) — outcome (CLEAN/FLAGGED/BLOCKED) is loggedComply with sanctions and AML obligations1(c) Legal obligation
Logs & securityIP, user-agent, timestamps, request paths, error metadataOperate the platform securely; investigate abuse1(f) Legitimate interest in security

1.3 How long we keep it

1.4 Who we share it with

We share data only with the sub-processors listed in § 3 below and only as necessary to provide the service. We do not sell personal data. We do not share for advertising. International transfers are covered by EU Standard Contractual Clauses (Module 2: controller-to-processor) plus a documented Transfer Impact Assessment.

1.5 Your rights (GDPR Articles 15–22)

Exercise any of these by emailing privacy@cryptoshieldai.ai. We respond within 30 days.

1.6 Automated decision-making

Our inbound AML pre-screen and our customer-facing AI agents make automated assessments. For B2B inbound screening, BLOCKED outcomes are not binding — they require a human (the Founder) to either clear them in writing or maintain the block. For our customer-facing services, decisions about your data are not made by our AI in a way that produces legal effects on you — they are recommendations to your compliance team. You always have the right to human review.

1.7 Children

Our services are not intended for individuals under 18. WALLET FAMILY tier supports household members of any age but is operated by an adult account-holder.

1.8 Security

Encryption at rest (AES-256), TLS in transit, MFA for privileged access, least-privilege IAM, centralised audit logging, post-quantum signing (NIST FIPS 204 ML-DSA-65) where enabled, breach notification within 72 hours of awareness. Full Art. 32 measures detailed in § 5 (DPA).

1.9 Contact

Cryptoshield AI B.V. · Amsterdam, Netherlands
privacy@cryptoshieldai.ai · adama@cryptoshieldai.ai
Supervisory authority: NL Autoriteit Persoonsgegevens

↑ Back to top

§ 2 of 6

Cookie Policy

We default to no tracking. The site currently sets no non-essential cookies.

2.1 What is a cookie

A cookie is a small text file stored in your browser. We also use localStorage (which behaves similarly). Both are governed by the EU ePrivacy Directive and GDPR.

2.2 What we currently set

Nothing. Our public website does not currently set analytics, marketing, or tracking cookies. If we ever add analytics, we will deploy a consent banner first and only set those cookies after you opt in.

2.3 If we ever add cookies — categories that may apply

CategoryWhat it doesDefault if introduced
Strictly necessarySite functionality, security, sessionAlways on (no consent required by ePrivacy)
AnalyticsAnonymous traffic measurementOff — opt in via banner
MarketingUsed by ad networks if we run a campaignOff — opt in via banner

2.4 Browser-level controls

You can clear or block cookies in your browser settings at any time.

↑ Back to top

§ 3 of 6 · Required by GDPR Art. 28(2)

Sub-processors

Every third party that processes personal data on our behalf is listed here. We notify customers 30 days before adding any new sub-processor.

3.1 Active sub-processors

NamePurposeHosting regionPersonal data scopeTransfer mechanism
Amazon Web Services EMEA SARL Cloud hosting (compute, storage, database, secrets, networking) eu-west-1 (Ireland) primary; eu-central-1 (Frankfurt) DR All platform data including customer accounts, processed data, logs EEA · no transfer required
Anthropic PBC Large-language-model inference for AI agents EU residency where available; US fallback Prompts & responses generated by the platform; no PII unless customer pastes it SCCs Module 2 + TIA
Stripe Payments Europe Ltd. Payment processing, invoicing, tax (Stripe Tax) Ireland (EEA) Customer name, email, billing address, VAT ID, payment instrument metadata EEA · no transfer required
Resend Inc. Transactional email delivery EU + US Recipient email + email body content SCCs Module 2 + TIA
Cloudflare Inc. CDN, DDoS protection, email obfuscation EU edge IP, user-agent, request metadata (transient) SCCs Module 2 + TIA
Notification of new sub-processors. We notify customers by email at least 30 days before adding any new sub-processor that has access to Personal Data. Customers may object on reasonable grounds; if we cannot accommodate, the customer may terminate the affected service with refund of pre-paid unused fees (per the MSA).

3.2 Subscribe to changes

Email privacy@cryptoshieldai.ai with subject "Subscribe sub-processor updates" and we will add you to the notification list. B2B contract holders are notified automatically.

↑ Back to top

§ 4 of 6 · AML / CTF / Sanctions

AML & Sanctions Compliance

We sell AML compliance. We apply it to ourselves. Public-facing summary of how we screen our own inbound customers before activation.

4.1 Legal basis

NL Wwft (Wet ter voorkoming van witwassen en financieren van terrorisme) · EU Sanctions Regulations ((EU) 269/2014, 833/2014) · OFAC SDN screening · FATF guidance · MiCA Title II · DORA · EU AI Act (Reg. (EU) 2024/1689 — active 2026-08).

4.2 Risk-based tiered approach (B2B)

We apply controls proportional to risk. Higher-revenue customer types receive deeper scrutiny.

TierAuto pre-screenFull KYB formUBO disclosureAdverse-media check
GRC Tier 1 · €134,999/mo
GRC Tier 2 + 20 workspaces · €224,999/mo✅ + Founder approval✅ + Founder confirmation✅ + AI-enhanced

4.3 What the auto pre-screen checks

4.4 B2C WALLET

Retail consumers undergo email verification, wallet-address sanctions screening (powered by our ADDRESS_SHIELD agent), and ongoing transaction monitoring. WALLET SOVEREIGN tier requires basic stated KYC (no document upload — privacy-first).

4.5 Decision matrix

4.6 Record-keeping

Every screening outcome, KYB case, Founder decision, and clearance is retained for 5 years post-contract-end (matching Wwft Art. 33).

4.7 AML Compliance Officer

The Founder & Board Member, Owner (Adama Jeng) is the designated AML Compliance Officer for Cryptoshield AI B.V. Contact: adama@cryptoshieldai.ai · compliance@cryptoshieldai.ai.

4.8 Reporting suspected illicit activity

If you believe a customer or counterparty using CryptoShield is engaged in illicit activity, report to compliance@cryptoshieldai.ai. We assess and, where required, file Suspicious Activity Reports (SARs) with FIU-NL.

↑ Back to top

§ 5 of 6 · GDPR Art. 28 · B2B Template

Data Processing Agreement (Template)

The DPA template signed alongside every B2B Master Services Agreement. Available here for pre-contract review.

How to use this template. The auto-generated, customer-specific DPA is bundled with your MSA at quote-stage. The text below is identical to the auto-generated version, with placeholders filled in at execution time. To get the customer-specific version: contact adama@cryptoshieldai.ai with your company details.

5.1 Roles

Customer is the Controller. Provider (Cryptoshield AI B.V.) is the Processor. Provider processes Personal Data only on documented instructions from Customer and as required to perform the Service.

5.2 Subject matter, nature, purpose, duration

Subject: GRC, AML, transaction monitoring, smart-contract auditing for digital-asset organisations.
Data processed: as described in the Service documentation.
Duration: term of the MSA + 30 days for export.

5.3 Security measures (Art. 32)

5.4 Sub-processors

Provider engages: AWS · Anthropic · Resend · Stripe · Cloudflare. Current list: see § 3 above. Customer notified 30 days before any new sub-processor is added.

5.5 International transfers

Personal Data is processed primarily in eu-west-1 (Ireland). Any transfer outside the EEA is covered by Standard Contractual Clauses (SCCs, EU 2021/914, Module 2: controller-to-processor) and a documented Transfer Impact Assessment.

5.6 Data subject rights

Provider will assist Customer in responding to data-subject requests within 14 days, where the Service does not let Customer self-serve.

5.7 Personal-data breach notification

Provider will notify Customer without undue delay (and in any event within 72 hours of awareness) of any breach of Personal Data, including: nature of the breach · approximate categories and number of data subjects · categories and approximate volume of records · likely consequences · measures taken or proposed.

5.8 Audit

Provider makes available all information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by Customer or another auditor mandated by Customer (subject to reasonable confidentiality and access controls).

5.9 Return / deletion

On termination, Provider returns or deletes all Personal Data within 30 days, unless EU/Member-State law requires retention.

Request customer-specific DPA ↑ Back to top

§ 6 of 6

Terms of Service

For B2C WALLET subscribers and visitors to cryptoshieldai.ai. B2B subscriptions are governed by a separately signed Master Services Agreement.

B2B note: if you are an organisation subscribing to STARTER, PROFESSIONAL, ENTERPRISE, INFRASTRUCTURE, or SOVEREIGN tier, your relationship with CryptoShield is governed by the signed MSA + DPA + MNDA bundle — not by these Terms.

6.1 Who we are

Cryptoshield AI B.V. — a private limited company registered in the Netherlands. Amsterdam-based. KVK 42020464. BTW NL869325267B01.

6.2 Acceptance

By using cryptoshieldai.ai or by subscribing to a CryptoShield WALLET tier, you accept these Terms. If you don't accept them, don't use the service.

6.3 The service (WALLET tiers)

CryptoShield WALLET is a B2C cryptocurrency-protection service. We monitor wallet addresses you provide for: address-poisoning, drainer signatures, sanctions exposure, scam patterns, post-quantum readiness signals. We deliver alerts and recommendations. We do not custody your assets. You retain sole control of all keys, signatures, and on-chain actions.

6.4 What you must do

6.5 What we promise

6.6 What we don't promise

The service is provided as is. We do not guarantee:

To the maximum extent permitted by NL law, all implied warranties (merchantability, fitness for a particular purpose, non-infringement) are disclaimed.

6.7 Liability

Our aggregate liability to you under these Terms is capped at the fees you have paid in the 12 months preceding the event giving rise to the claim, or €500, whichever is greater. We are not liable for indirect, consequential, or punitive damages. This cap does not apply to liability that cannot be excluded under NL law (e.g. fraud, wilful misconduct, death or personal injury caused by negligence).

6.8 Termination

You can cancel your subscription at any time from your account settings — it remains active until the end of the current billing cycle. We can terminate immediately if you breach these Terms or if required by law / regulator.

6.9 Refunds

Per EU Consumer Rights Directive (2011/83/EU), you have a 14-day right of withdrawal for distance-purchased digital services unless you've expressly waived it during checkout. Outside that window, fees are non-refundable except for service unavailability that we cause.

6.10 Changes

We may update these Terms. Material changes are notified by email at least 30 days in advance.

6.11 Governing law

These Terms are governed by NL law. Disputes go to Amsterdam District Court. EU consumers retain mandatory rights under their home jurisdiction.

6.12 Contact

adama@cryptoshieldai.ai · privacy@cryptoshieldai.ai

↑ Back to top

Effective: 2026-05-08 · Version 1.0 · Owner: Founder & Board Member, Owner. NL counsel review pending pre-launch.