Kyc Policy

Policy scope and purpose

The KYC Policy of Rr89 establishes the measures by which we identify, verify, monitor, and report client information to prevent money laundering and the financing of terrorism. It applies to all applicants, accounts, and transactions conducted on the Rr89 platform, including real‑money and bonus‑enabled activity.

Regulatory framework and governance

Rr89 acts in accordance with applicable anti‑money laundering and counter‑terrorism financing laws and supervisory guidance. Our AML Program is risk‑based, regularly reviewed, and overseen by a designated compliance function responsible for customer due diligence, ongoing monitoring, and suspicious activity reporting to the appropriate authorities where required.

Definitions

  • KYC: Know Your Customer, the process of verifying a customer’s identity and assessing risk.
  • AML/CTF: Anti‑Money Laundering and Counter‑Terrorism Financing obligations.
  • CDD: Customer Due Diligence; EDD: Enhanced Due Diligence.
  • PEP: Politically Exposed Person.
  • Sanctions screening: checks against lists maintained by competent authorities.
  • Data controller: entity responsible for processing personal data under this policy.

Onboarding and identity verification

At registration and for monetary transactions that benefit the customer, Rr89 will identify and verify the customer’s identity. Verification may be completed using documents supplied by the customer or via a trusted third‑party verification service. We will maintain records of verification checks and the information used to verify identity.

  • Acceptable documents include: government‑issued photo ID (passport, national ID, or driver’s license); proof of full name and date of birth; proof of address showing the customer resides at the stated address (issued within the last three months); proof of payment method (e.g., card used, recent statement from the payment provider); and, where required, a selfie or live verification to confirm identity.

Ongoing monitoring and enhanced due diligence

We continuously monitor account activity relative to the customer’s risk profile. Activities that are unusual or potentially suspicious trigger enhanced due diligence, including the collection of additional documentation or verification. High‑risk customers, including those identified as PEPs or located in high‑risk jurisdictions, will be subject to enhanced due diligence and more frequent reviews.

Transaction monitoring and suspicious activity reporting

We monitor transactions for consistency with the customer’s risk profile and expected activity. Suspected money laundering or financing of terrorism will be reported to the appropriate authorities in accordance with applicable laws and regulations. We retain records of investigations and any reports submitted to authorities.

Thresholds, restrictions, and escalation

Identity verification may be prompted or renewed when cumulative deposits or withdrawals reach 500 EUR or the equivalent in the customer’s currency, or when regulatory or internal indicators necessitate additional verification. During verification, we may restrict withdrawals or other transactions until checks are complete. Providing false or misleading information may result in immediate account termination or restriction.

Prohibited jurisdictions and sanctions

Accounts and funds are not available to individuals located in or resident of jurisdictions subject to sanctions or prohibitions, or where Rr89 is not licensed to operate. A current restricted‑jurisdiction list is maintained for compliance purposes and will be enforced at onboarding and upon updates. Customers will be notified of changes that affect eligibility.

Record retention and privacy

Rr89 retains all KYC and related records for a minimum of eight years after account termination or as required by applicable law. Personal data is processed in accordance with our privacy policy and applicable data‑protection laws. Data subjects may exercise rights to access or correct their information, subject to legal and contractual limitations.

Data sharing and third‑party processors

We may disclose relevant information to regulatory authorities, financial institutions, and licensed third‑party KYC/AML service providers as required to fulfill our legal obligations. All processing is conducted under our data controller arrangements in compliance with applicable privacy laws.

Customer obligations and rights

Customers must provide accurate information, promptly update data when changes occur, and cooperate with verification requests. Providing false information constitutes a material breach of contract and may result in account termination or restriction. Customers may contact [email protected] to exercise data rights or request access to their information.

Security and governance

Rr89 employs appropriate technical and organizational safeguards to protect KYC data, including access controls, encryption, secure storage, and audit logging. Access is restricted to authorized personnel in accordance with internal policies.

Policy amendments and notice

Rr89 may amend this policy to reflect changes in law or in our risk management approach. Material changes will be communicated in accordance with legal requirements. Continued use of the platform after changes constitutes acceptance of the updated policy.

Contact and escalation

For questions about this policy, contact [email protected]. For compliance concerns, contact [email protected]. For privacy inquiries, contact [email protected].