Product
Exchange Markets Premium service FAQ
Company
About the company About us Contacts
Legal
Terms of Service Privacy Policy Affiliate Terms Cookies Policy AML / KYC Policy
Log in Start exchange
Legal

AML / CTF and KYC Policy

Last updated June 26, 2026

This Anti-Money Laundering / Counter-Terrorist Financing (AML/CTF) and Know Your Customer (KYC) Policy of Ezorex explains the checks we run, how we assess risk, and what we may ask of you. It is designed to keep the Service clean and compliant.

I. General Provisions

This AML/CTF and KYC Policy of Ezorex, operated by Limited Liability Company “Kosmoteka” (the “Service”, “Ezorex”, “we” or “us”), has been developed in accordance with the recommendations of the Financial Action Task Force (FATF), applicable law, and the requirements of the Financial Market Regulation and Supervision Service of the Kyrgyz Republic.

1.1. Purpose of the Policy. The purpose of this Policy is to prevent the use of the Service for: (1) the legalisation (laundering) of proceeds obtained through criminal activity; (2) the financing of terrorism and extremist activity; and (3) the circumvention of sanctions and other unlawful actions.

1.2. Prohibited Activity. The Service strictly prohibits the use of its infrastructure for: (1) operations involving funds of knowingly illegal origin; (2) payment for prohibited goods and services; (3) interaction with persons and organizations on international sanctions lists; and (4) transfers for the benefit of third parties without proper justification.

1.3. Jurisdictional Restrictions. The Service may restrict or prohibit the use of its services by residents of, and/or operations involving, jurisdictions with elevated sanctions and compliance risk, including (but not limited to): Afghanistan, Bosnia and Herzegovina, Democratic Republic of the Congo, Eritrea, Ethiopia, Guyana, Iran, Iraq, the Democratic People’s Republic of Korea, the Lao People’s Democratic Republic, Libya, Somalia, South Sudan, Sri Lanka, Sudan, Syria, Trinidad and Tobago, Tunisia, Uganda, Vanuatu, as well as other countries according to the applicable, regularly updated sanctions lists.

II. Risk-Based Approach and Risk Score Model

2.1. Risk-Based Approach. The Service applies a risk-based approach, as recommended by FATF, when analysing operations and clients. This means that the intensity of AML/CTF and KYC measures is proportionate to the level of identified risk. For the analysis of crypto transactions, the Service uses a Risk Score model — a quantitative risk assessment based on data from one or more valid AML analytics tools.

2.2. AML Analytics Sources. To assess the Risk Score, the Service uses licensed and recognized industry AML analytics services. The specific list of analytics tools used, their names and statuses may be updated from time to time. Current information about them may be reflected in the user agreement and/or on a separate page of the Service’s website.

2.3. Risk Score Levels and Action Thresholds. The Service classifies crypto addresses and sources of funds by the following risk levels: Low risk — operations are allowed without additional checks; Medium risk — the Service may request additional data and carry out a selective KYC/SoF check; High risk — operations are subject to suspension, and funds may be temporarily blocked until KYC procedures and confirmation of the Source of Funds (SoF) are completed; Critical risk — operations may be rejected, and funds returned or withheld pending a decision by the competent authorities.

2.4. Risk Score Threshold. The specific numerical Risk Score threshold above which (1) automatic execution of an exchange is suspended and (2) KYC/SoF procedures are initiated is established by the Service’s internal regulations in accordance with the requirements of the Financial Market Regulation and Supervision Service of the Kyrgyz Republic and international practice. As a guideline, when a level of 50–75% on the Risk Score scale is exceeded, the exchange is suspended until KYC/SoF is completed. The exact threshold may be adjusted depending on the analytics tool used and the nature of the operation.

III. KYC and SoF Procedures

3.1. General. The Service maintains its own verification procedures under KYC (Know Your Customer) and SoF (Source of Funds) standards. The sender and the recipient of a payment under an order must be one and the same person. Transfers for the benefit of third parties are strictly prohibited, except where the client has provided proper documents confirming the legality and economic substance of such an operation. All contact and personal data provided by the User to the Service must be current and fully accurate. It is strictly prohibited to create orders using anonymous proxy servers or VPN services intended to conceal the real location, or any other anonymous connection to the Internet, without notifying the Service.

3.2. When KYC/SoF Is Conducted. A KYC/SoF check is carried out in the following cases: (1) the established Risk Score threshold is exceeded for an address or transaction; (2) internal limits on the volume and/or frequency of transactions are reached or exceeded; (3) signs of unusual activity or typologies of money laundering or terrorist financing are detected; (4) a request is received from law enforcement or supervisory authorities; (5) selective checks under the risk-based approach; or (6) previously provided data changes or inconsistencies in the client’s information are detected.

3.3. Requested Materials. To complete KYC/SoF, the Service may request the following documents and information.

3.3.1. Identity Documents: (1) the passport of a citizen of the country of residence; (2) a national ID card; (3) a driver’s license (in certain cases); or (4) another government-issued document bearing a photograph and recognized in the relevant jurisdiction.

3.3.2. Proof of Address: (1) a bank statement no older than 3 months; (2) a utility bill (electricity, gas, water, internet) no older than 3 months; (3) a tenancy agreement or title to real estate; or (4) other documents containing the full name and actual residential address.

3.3.3. Source of Funds (SoF) Confirmation. To confirm the origin of funds, the User may be asked to provide answers to the following and supporting documents: (1) the source of the crypto assets — the name of the exchange, wallet, platform, deposit service or other source from which the funds reached the client; (2) screenshots of the withdrawal and/or transaction history from the source platform; (3) a description of the economic substance of the operation — for what service, goods or activity the client received the funds; (4) the date, time and amount of the transaction; (5) links to the transactions in blockchain explorers; and (6) where necessary, contracts, invoices, payment orders and other supporting documents.

3.3.4. Additional Documents and Verification. The Service may also request: (1) a second identity document; (2) a selfie with the identity document and a sheet of paper showing the current date and the name of the Service; or (3) video verification (a short video demonstrating the document and stating a code phrase), where there are suspicions about the integrity of the information provided or the use of forged documents.

3.4. Stages and Timelines. A typical KYC/SoF check includes the following stages: (1) temporary suspension of the exchange and/or blocking of funds under the order when a Risk Score threshold is exceeded or other triggers are identified; (2) notification of the client about the need to undergo the check and a request for the required set of documents (sent to the contact details specified in the order); (3) analysis of the submitted documents and AML analytics data by the responsible officer (AML/Compliance Officer); and (4) a decision: (i) approval of the operation and continuation of the exchange; (ii) return of funds to the client subject to the conditions set out in Section IV; or (iii) refusal of service and possible transfer of information to the competent authorities (where there are grounds to believe the funds are connected to criminal activity). As a guideline, the review and decision are made within 1 to 7 business days from the moment the client provides the full set of requested documents; in complex cases, or where additional verification is required, this period may be extended, of which the client is informed by a separate notice. The Service verifies the authenticity of documents and information provided by Users and reserves the right to obtain additional information about Users identified as high-risk or suspicious. If a User’s identification information has changed, or their activity appears suspicious, the Service may request updated documents even if they previously passed authenticity checks.

IV. Refund Fees and Conditions

4.1. Refund Fee for AML Cases. Where funds are returned in the context of AML cases (where an operation was suspended for AML/CTF/KYC/SoF control purposes and, following the check, a decision to refund is made), the Service may charge a refund fee. The amount of the refund fee: (1) is no more than 5% of the amount of the blocked funds; but (2) no more than 100 USD equivalent at the time of the return. The specific amount depends on the nature of the case, the volume of the check carried out, and any additional costs (engagement of external experts, requests to authorities, etc.).

4.2. Conditions for Bona Fide Clients. For clients found to be bona fide following a KYC/SoF check (where the funds are not confirmed as connected to money laundering, fraud or other unlawful acts): (1) the fee for the exchange or return is limited only to the actual network fees and/or unavoidable infrastructure costs (payment system and gateway fees); and (2) no additional fees for the AML check and return are charged. Thus, a bona fide client who has passed KYC/SoF bears no penalty costs beyond technical network fees.

4.3. Refund Timelines. Funds are returned within a reasonable time after the check is completed and a decision to refund is made: (1) as a rule, within 1–10 business days after the refund is approved; and (2) taking into account the load on the relevant blockchain and payment systems. In the event of delays, the client is notified of the reasons and the estimated timelines.

4.4. Refusal to Refund. The Service reserves the right to refuse a refund and/or to withhold funds in the following cases: (1) where there are reasonable suspicions or evidence of a connection between the funds and criminal activity; (2) at the request of law enforcement or judicial authorities; or (3) where the client refuses to provide the requested documents or provides knowingly false information. In such cases, the funds may be transferred to the competent authorities in accordance with applicable law.

V. Ensuring the “Cleanliness” of Outgoing and Incoming Transactions

5.1. Asset Quality Obligation. The Service undertakes to ensure the quality and legitimacy of the assets transferred to clients, regardless of the direction of the exchange. This means that the Service takes measures to avoid transferring to clients crypto assets with an elevated level of risk (tainted coins, funds connected to mixers, hacks, fraud, etc.).

5.2. Measures to Ensure “Clean” Transactions. To minimise the risk of clients receiving assets with a high Risk Score, the Service: (1) uses tagged crypto addresses identified in valid AML analytics tools as belonging to the Service, with correct clustering of service wallets; (2) may use addresses of licensed and verified platforms (major exchanges, payment solutions with a low Risk Score) while observing requirements for the cleanliness of outgoing transactions; (3) applies unique (one-time) crypto addresses for each order, with subsequent consolidation of funds in a common Service wallet belonging to tagged/licensed addresses; and (4) regularly monitors its outgoing and incoming transactions for high-risk tags and updates clustering for correctness of tagging.

5.3. Monitoring of Address Infrastructure. The Service conducts a regular audit of the crypto addresses it uses, ensuring their compliance with cleanliness requirements and the currency of their tagging in AML analytics tools.

VI. Transaction Monitoring

6.1. Goals of Monitoring. The Service applies automated and/or manual monitoring of transactions and client behaviour in order to: (1) identify operations that deviate from the client’s usual profile or from typical patterns of using the Service; (2) detect signs of the use of mixers, chain-hopping (rapid movement of funds between blockchains), rapid consolidation of funds, or interaction with known illicit services; and (3) respond promptly to updates to sanctions lists, PEP (Politically Exposed Persons) status, and adverse media.

6.2. Monitoring Tools. Monitoring is carried out using: (1) AML analytics tools (as referred to in Section 2.2); (2) internal systems for analysing transactions and user behaviour; (3) sanctions list databases (OFAC, UN, EU and others); and (4) open-source intelligence (OSINT).

6.3. Actions Following Monitoring. The Service reserves the right to: (1) report suspicious operations to the competent law enforcement and supervisory authorities; (2) request additional documents and information; (3) suspend operations and block assets during a check; (4) terminate service to a client where the risk is deemed unacceptable; and (5) return funds to the user, cancelling the exchange procedure, in accordance with the user agreement. The above list is not exhaustive. The officer responsible for AML compliance monitors User transactions daily to determine whether they should be reported and treated as suspicious.

VII. AML/CTF and KYC Officer

7.1. Appointment and Functions. Compliance with this AML/CTF and KYC Policy is the responsibility of a designated officer (Compliance/AML Officer) or an authorized external specialist (outsourcing company). The functions of the responsible person include: (1) developing and updating internal AML/CTF and KYC procedures and regulations; (2) overseeing KYC/SoF checks; (3) monitoring transactions and analysing suspicious activity; (4) training and briefing Service staff on AML/CTF matters; (5) liaising with regulators and law enforcement on AML/CTF matters; (6) collecting Users’ identification information and transferring it to the responsible personal data processing agent; (7) creating and updating internal policies and procedures for writing, reviewing, submitting and storing all reports required under existing laws and rules; (8) implementing a records management system for storing and retrieving documents, files, forms and logs; and (9) regularly updating the risk assessment.

7.2. Powers. The officer responsible for AML compliance has the right to interact with law enforcement authorities engaged in preventing the legalisation of funds, the financing of terrorism, and other illegal activity.

VIII. Processing and Storage of Personal Data

8.1. Legal Basis. The Service processes users’ personal data in accordance with applicable data protection law and its own Privacy Policy published on the Service’s website. This AML/CTF and KYC Policy describes the processing of personal data in the context of meeting AML/CTF and KYC requirements; a full description of the principles, data subject rights and security measures is set out in the Privacy Policy.

8.2. Purposes of Collection. The Service collects only the personal data necessary to: (1) provide crypto-to-crypto exchange services; (2) meet AML/CTF and KYC requirements (client identification, source-of-funds verification, transaction monitoring); (3) protect the legitimate interests of the Service and its clients; and (4) comply with legal requirements and requests from the competent authorities.

8.3. Categories of Personal Data Processed. The following categories of data may be processed under this Policy: (1) identification data (full name, date of birth, citizenship, identity document number); (2) contact data (email address, phone number, messengers); (3) residential address; (4) document data (scans/photos of passport, ID card, utility bills); (5) biometric data (photo, video for verification); (6) transaction data (amounts, wallet addresses, blockchain hashes); and (7) information about the source of funds.

8.4. Storage and Protection of Data. The Service ensures: (1) storage of personal data on secure servers with restricted access, in encrypted form (where applicable); (2) the application of technical and organizational security measures, including encryption of data in transit and at rest, role-based access control (RBAC), logging of access to and actions on personal data, regular backups and recovery testing, and protection against unauthorized access, leakage, destruction or alteration of data; and (3) storage of data for the period necessary to fulfil AML/CTF obligations (as a rule, no less than 5 years from the end of the business relationship or the transaction) and legal requirements.

8.5. Transfer of Data to Third Parties. Personal data is not transferred to third parties, except in the following cases: (1) compliance with legal requirements and requests from the competent authorities (court, prosecutor’s office, police, financial regulator, etc.); and (2) the use of licensed KYC/ID-verification providers and hosting providers, under contracts that ensure an adequate level of data protection and confidentiality. In all cases, data is transferred on a lawful basis and in accordance with the principle of minimisation (only the necessary data is transferred).

8.6. Data Subject Rights. Users have the right to: (1) know what data about them is being processed; (2) request a copy of their personal data; (3) request the correction of inaccurate data; (4) request the deletion of data (subject to the obligation to retain data under AML/CTF requirements); and (5) withdraw consent to processing (where processing is based on consent, subject to the legal grounds for processing data for AML/CTF purposes). To exercise these rights, a user may submit a request through the Contact us page on the Service’s website.

IX. Active User Consent

9.1. Mandatory Consent. Before creating an exchange order, the user must: (1) review this AML/CTF and KYC Policy; (2) review the Privacy Policy; (3) review the Terms of Service (user agreement); and (4) tick the checkbox confirming their consent to these documents and their awareness of the risks associated with AML checks and the possible blocking or return of funds.

9.2. No Order Without Consent. Without active consent (ticking the checkbox) on the website, creating an order and carrying out an exchange is technically impossible.

9.3. Logging of Consent. The fact of consent is recorded in the Service’s system, linked to the order, the IP address and a timestamp. This information may be used in the event of disputes or checks.

X. Preliminary AML Check at the User’s Initiative

10.1. Option for a Preliminary Check. On the order creation page, the Service offers the user the option to carry out a paid preliminary AML check of the sender’s/recipient’s crypto address.

10.2. The User’s Choice. After carrying out a preliminary AML check, the user may: (1) provide the check results to the Service operator for assessment of the exchange risks, in which case the operator takes the provided data into account when deciding whether to continue the exchange; or (2) knowingly decline to provide the results by ticking a separate checkbox confirming that the user (i) has been informed of the risks associated with AML checks, (ii) accepts those risks, and (iii) understands the possibility of funds being blocked and the obligation to undergo KYC/SoF if a high Risk Score is identified.

10.3. Effect on Order Processing. Providing the results of a preliminary AML check may speed up the processing of an order and reduce the likelihood of funds being blocked. Declining to provide the results does not prevent the creation of an order, but increases the likelihood of a KYC/SoF check being initiated if risks are identified during monitoring.

XI. Risk Assessment

In accordance with international requirements, the Service applies a risk-based approach to combating the legalisation of funds and the financing of terrorism, so that measures to prevent the legalisation of funds and the financing of terrorism are commensurate with the identified risks. The Service regularly assesses the risks associated with: (1) the types of clients and their jurisdictions; (2) the types of products and services; (3) the geographic directions of operations; (4) the service delivery channels (online platform); and (5) new technologies and methods of fraud. The results of the risk assessment are used to adjust internal procedures, limits and AML/CTF measures.

XII. Cooperation with Law Enforcement

The Service does not enter into business relationships with persons known to be criminals and/or terrorists and does not process operations that result from knowingly criminal and/or terrorist activity. The Service does not facilitate any transactions connected to knowingly criminal and/or terrorist activity. Upon identifying suspicious operations or receiving a request from the competent authorities, the Service: (1) provides the necessary information and documents in accordance with the requirements of the law; (2) suspends or blocks operations and funds at the direction of the authorities; and (3) cooperates in investigations and checks. The Service maintains the confidentiality of the fact that suspicious activity reports have been filed and does not notify the client of such reports where this is prohibited by law.

XIII. Employee Training

The Service provides regular training and briefing for staff involved in processing operations and interacting with clients, on: (1) AML/CTF and KYC requirements; (2) typologies of money laundering and terrorist financing; (3) the use of AML analytics tools and internal monitoring systems; and (4) procedures for escalating suspicious cases.

XIV. Policy Updates

The Service regularly reviews and updates this Policy, taking into account: (1) changes in AML/CTF and data protection legislation; (2) international standards (FATF, the Basel AML Index, and others); (3) requirements and recommendations of partners; (4) newly identified risks and typologies of money laundering and terrorist financing; and (5) the results of internal and external audits. Users will be notified of material changes to the Policy by the publication of the updated version on the Service’s website. The effective date of a new version is indicated at the top of the document. Continued use of the Service after the updated Policy takes effect constitutes the user’s consent to its provisions.

XV. Contact Information

For questions related to this AML/CTF and KYC Policy, the processing of personal data, undergoing verification, or to submit requests and complaints, users may contact the Service through the Contact us page on the Ezorex website.

This Policy takes effect upon publication on the Service’s website and remains in force until a new version is adopted. Ezorex reserves the right to amend this Policy unilaterally, notifying users by publishing the updated version on the website.