Legal · 2026-05-08 · Cryptoshield AI B.V.
Everything you need to know about how we handle your data, contractually and operationally — in one document.
§ 1 of 6
Honest. Specific. GDPR-compliant. Effective 2026-05-08.
Cryptoshield AI B.V. ("CryptoShield", "we") — Amsterdam, Netherlands.
KVK: 42020464 · BTW/VAT: NL869325267B01 · adama@cryptoshieldai.ai · privacy@cryptoshieldai.ai
We are the data controller for personal data collected via this website and our products.
| Source | Categories of data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Contact form | Name, email, company, role, free-text message | Respond to your enquiry, route to the right team | 1(f) Legitimate interest |
| Demo intake | Same + intended use case, preferred call time | Schedule and prepare a demo | 1(b) Pre-contractual measures |
| B2B sign-up | Company legal entity, KvK / registration number, VAT ID, signatory name + email + role, billing address, IBAN, KYB / UBO data for ENTERPRISE+ | Fulfil the subscription, comply with AML / KYB obligations | 1(b) Contract · 1(c) Legal obligation (Wwft) |
| WALLET sign-up | Email, wallet addresses (public on-chain identifiers), payment ID from Stripe, language preference | Provide the WALLET protection service | 1(b) Contract |
| Inbound AML screen | Customer organisation, country, signatory name (input only) — outcome (CLEAN/FLAGGED/BLOCKED) is logged | Comply with sanctions and AML obligations | 1(c) Legal obligation |
| Logs & security | IP, user-agent, timestamps, request paths, error metadata | Operate the platform securely; investigate abuse | 1(f) Legitimate interest in security |
We share data only with the sub-processors listed in § 3 below and only as necessary to provide the service. We do not sell personal data. We do not share for advertising. International transfers are covered by EU Standard Contractual Clauses (Module 2: controller-to-processor) plus a documented Transfer Impact Assessment.
Exercise any of these by emailing privacy@cryptoshieldai.ai. We respond within 30 days.
Our inbound AML pre-screen and our customer-facing AI agents make automated assessments. For B2B inbound screening, BLOCKED outcomes are not binding — they require a human (the Founder) to either clear them in writing or maintain the block. For our customer-facing services, decisions about your data are not made by our AI in a way that produces legal effects on you — they are recommendations to your compliance team. You always have the right to human review.
Our services are not intended for individuals under 18. WALLET FAMILY tier supports household members of any age but is operated by an adult account-holder.
Encryption at rest (AES-256), TLS in transit, MFA for privileged access, least-privilege IAM, centralised audit logging, post-quantum signing (NIST FIPS 204 ML-DSA-65) where enabled, breach notification within 72 hours of awareness. Full Art. 32 measures detailed in § 5 (DPA).
Cryptoshield AI B.V. · Amsterdam, Netherlands
privacy@cryptoshieldai.ai · adama@cryptoshieldai.ai
Supervisory authority: NL Autoriteit Persoonsgegevens
§ 3 of 6 · Required by GDPR Art. 28(2)
Every third party that processes personal data on our behalf is listed here. We notify customers 30 days before adding any new sub-processor.
| Name | Purpose | Hosting region | Personal data scope | Transfer mechanism |
|---|---|---|---|---|
| Amazon Web Services EMEA SARL | Cloud hosting (compute, storage, database, secrets, networking) | eu-west-1 (Ireland) primary; eu-central-1 (Frankfurt) DR | All platform data including customer accounts, processed data, logs | EEA · no transfer required |
| Anthropic PBC | Large-language-model inference for AI agents | EU residency where available; US fallback | Prompts & responses generated by the platform; no PII unless customer pastes it | SCCs Module 2 + TIA |
| Stripe Payments Europe Ltd. | Payment processing, invoicing, tax (Stripe Tax) | Ireland (EEA) | Customer name, email, billing address, VAT ID, payment instrument metadata | EEA · no transfer required |
| Resend Inc. | Transactional email delivery | EU + US | Recipient email + email body content | SCCs Module 2 + TIA |
| Cloudflare Inc. | CDN, DDoS protection, email obfuscation | EU edge | IP, user-agent, request metadata (transient) | SCCs Module 2 + TIA |
Email privacy@cryptoshieldai.ai with subject "Subscribe sub-processor updates" and we will add you to the notification list. B2B contract holders are notified automatically.
↑ Back to top§ 4 of 6 · AML / CTF / Sanctions
We sell AML compliance. We apply it to ourselves. Public-facing summary of how we screen our own inbound customers before activation.
NL Wwft (Wet ter voorkoming van witwassen en financieren van terrorisme) · EU Sanctions Regulations ((EU) 269/2014, 833/2014) · OFAC SDN screening · FATF guidance · MiCA Title II · DORA · EU AI Act (Reg. (EU) 2024/1689 — active 2026-08).
We apply controls proportional to risk. Higher-revenue customer types receive deeper scrutiny.
| Tier | Auto pre-screen | Full KYB form | UBO disclosure | Adverse-media check |
|---|---|---|---|---|
| GRC Tier 1 · €134,999/mo | ✅ | ✅ | ✅ | ✅ |
| GRC Tier 2 + 20 workspaces · €224,999/mo | ✅ | ✅ + Founder approval | ✅ + Founder confirmation | ✅ + AI-enhanced |
Retail consumers undergo email verification, wallet-address sanctions screening (powered by our ADDRESS_SHIELD agent), and ongoing transaction monitoring. WALLET SOVEREIGN tier requires basic stated KYC (no document upload — privacy-first).
Every screening outcome, KYB case, Founder decision, and clearance is retained for 5 years post-contract-end (matching Wwft Art. 33).
The Founder & Board Member, Owner (Adama Jeng) is the designated AML Compliance Officer for Cryptoshield AI B.V. Contact: adama@cryptoshieldai.ai · compliance@cryptoshieldai.ai.
If you believe a customer or counterparty using CryptoShield is engaged in illicit activity, report to compliance@cryptoshieldai.ai. We assess and, where required, file Suspicious Activity Reports (SARs) with FIU-NL.
↑ Back to top§ 5 of 6 · GDPR Art. 28 · B2B Template
The DPA template signed alongside every B2B Master Services Agreement. Available here for pre-contract review.
Customer is the Controller. Provider (Cryptoshield AI B.V.) is the Processor. Provider processes Personal Data only on documented instructions from Customer and as required to perform the Service.
Subject: GRC, AML, transaction monitoring, smart-contract auditing for digital-asset organisations.
Data processed: as described in the Service documentation.
Duration: term of the MSA + 30 days for export.
Provider engages: AWS · Anthropic · Resend · Stripe · Cloudflare. Current list: see § 3 above. Customer notified 30 days before any new sub-processor is added.
Personal Data is processed primarily in eu-west-1 (Ireland). Any transfer outside the EEA is covered by Standard Contractual Clauses (SCCs, EU 2021/914, Module 2: controller-to-processor) and a documented Transfer Impact Assessment.
Provider will assist Customer in responding to data-subject requests within 14 days, where the Service does not let Customer self-serve.
Provider will notify Customer without undue delay (and in any event within 72 hours of awareness) of any breach of Personal Data, including: nature of the breach · approximate categories and number of data subjects · categories and approximate volume of records · likely consequences · measures taken or proposed.
Provider makes available all information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by Customer or another auditor mandated by Customer (subject to reasonable confidentiality and access controls).
On termination, Provider returns or deletes all Personal Data within 30 days, unless EU/Member-State law requires retention.
Request customer-specific DPA ↑ Back to top§ 6 of 6
For B2C WALLET subscribers and visitors to cryptoshieldai.ai. B2B subscriptions are governed by a separately signed Master Services Agreement.
Cryptoshield AI B.V. — a private limited company registered in the Netherlands. Amsterdam-based. KVK 42020464. BTW NL869325267B01.
By using cryptoshieldai.ai or by subscribing to a CryptoShield WALLET tier, you accept these Terms. If you don't accept them, don't use the service.
CryptoShield WALLET is a B2C cryptocurrency-protection service. We monitor wallet addresses you provide for: address-poisoning, drainer signatures, sanctions exposure, scam patterns, post-quantum readiness signals. We deliver alerts and recommendations. We do not custody your assets. You retain sole control of all keys, signatures, and on-chain actions.
The service is provided as is. We do not guarantee:
To the maximum extent permitted by NL law, all implied warranties (merchantability, fitness for a particular purpose, non-infringement) are disclaimed.
Our aggregate liability to you under these Terms is capped at the fees you have paid in the 12 months preceding the event giving rise to the claim, or €500, whichever is greater. We are not liable for indirect, consequential, or punitive damages. This cap does not apply to liability that cannot be excluded under NL law (e.g. fraud, wilful misconduct, death or personal injury caused by negligence).
You can cancel your subscription at any time from your account settings — it remains active until the end of the current billing cycle. We can terminate immediately if you breach these Terms or if required by law / regulator.
Per EU Consumer Rights Directive (2011/83/EU), you have a 14-day right of withdrawal for distance-purchased digital services unless you've expressly waived it during checkout. Outside that window, fees are non-refundable except for service unavailability that we cause.
We may update these Terms. Material changes are notified by email at least 30 days in advance.
These Terms are governed by NL law. Disputes go to Amsterdam District Court. EU consumers retain mandatory rights under their home jurisdiction.
adama@cryptoshieldai.ai · privacy@cryptoshieldai.ai
↑ Back to top