This Policy aims to protect Sininelabs OÜ (the "Company"), its customers, its platform, and its regulated payment partners from misuse involving money laundering, terrorist financing, sanctions evasion, fraud, account compromise, or other financial crime. The Policy is designed specifically for the Company's customer payout process and the information available to Sininelabs through its own platform operations.
The Policy applies to directors, employees, contractors, outsourced personnel, and systems that influence affiliate onboarding, account security, payout eligibility, sanctions screening, fraud review, transaction monitoring, finance, customer support, partner communications, or record retention.
Sininelabs applies these controls on a risk-sensitive basis. The fact that Sininelabs uses AML/CFT terminology or adopts controls commonly used by regulated firms does not, by itself, alter the Company's legal classification. Where applicable law imposes a direct obligation on Sininelabs, that obligation prevails. Where a control arises from contract, partner instruction or Card Scheme programme conditions, it is treated as an operational requirement for the relevant payout flow.
Sininelabs OÜ is a commercial, non-financial company. This Policy is adopted to manage financial-crime and sanctions risk in connection with Affiliates' payouts and to satisfy applicable legal, acquiring-bank, payment-partner and Card Scheme expectations. It does not constitute a license, registration, or admission that Sininelabs is a credit institution, financial institution, payment institution, electronic-money institution or statutory AML obliged entity. Any material change to the platform, funds flow or payout functionality must be assessed before launch for possible regulatory consequences.
| Role | Core accountability |
|---|---|
| Director / senior management | Approve the Policy and risk appetite; provide resources; receive material escalations; ensure business-model changes receive regulatory review. |
| Director / senior management | Maintain the risk assessment and procedures; oversee affiliate screening, monitoring, and EDD; decide escalations; maintain partner-control requirements; coordinate testing and remediation. |
| Operations / Finance | Release payouts only after required controls have passed; reconcile payout records; escalate anomalies and exceptions. |
| Customer Support / Director / senior management | Apply authentication and fraud procedures; preserve evidence; escalate suspicious or sanctions-related activity without alerting the customer to sensitive investigative details. |
| All personnel | Follow controls, protect confidential information, and promptly report unusual activity. |
No employee may bypass sanctions hold, transaction limit, payout restriction, or enhanced review requirement without documented approval from an authorized person and, where required, the acquiring bank or payment partner.
The Company maintains a documented financial-crime risk assessment for the Affiliate Program. The assessment evaluates inherent risk and control effectiveness across the Affiliate relationship, marketing activity, referral quality, commission profile, payout destination, geography, and relevant third parties. It is reviewed at least annually and whenever a material change occurs.
Risk dimensions and examples:
Risk may be graded Low, Standard, Elevated or Prohibited, or by an equivalent internal scale. Elevated risk requires additional controls. Prohibited activity includes transactions that would breach sanctions, law, partner terms, Card Scheme programme conditions or the operating boundaries in Section 2.
An applicant must be approved before participating in the Affiliate Program or receiving a payout. The Company shall collect sufficient information to identify the Affiliate, assess country eligibility, establish the Affiliate relationship and perform the verification procedures required by the Affiliate Policy and applicable payment-partner requirements.
Before approval, the Company performs KYC verification, sanctions and PEP screening, country eligibility verification and compliance review. Applicants located in countries or territories subject to applicable sanctions, embargoes or internal Company restrictions are not eligible. The Company may periodically reassess eligibility throughout the relationship.
Enhanced Due Diligence (EDD) is required when any of the following triggers are met:
Where EDD is triggered, the Company must, as relevant to the trigger: re-verify the Affiliate, confirm ownership of the payout instrument; obtain supporting traffic, referral and commission records; obtain an explanation and evidence for unusual activity; apply a temporary payout hold or reduced limit where appropriate; and obtain documented approval from the Director or other authorised senior reviewer before release. The rationale, evidence reviewed, and approval decision must be retained in the case record.
Affiliate payouts are released only after the Company has established a valid contractual and commercial basis for the amount. The payout is therefore a payment of the Company's own accrued commission obligation to an approved Affiliate, not a transfer of funds belonging to a customer or another user.
| Control point | Sininelabs requirement |
|---|---|
| Affiliate status | Payouts may be made only to duly registered and approved Affiliates whose participation has not been suspended or terminated. |
| Qualified Customer validation | Referred customers supporting the commission must meet the Affiliate Policy criteria, including being new, non-duplicate, non-fraudulent, non-self-referred, and validly attributed through the Company's systems. |
| Commission calculation | The amount must correspond to the verified commission calculation under the Affiliate's agreed commission structure. No commission is payable until verified by the Company. |
| Minimum amount | The payout must meet the Affiliate Program minimum payout amount of EUR 5, unless the applicable programme terms are amended. |
| Permitted purpose | OCT, where used, is used exclusively for accrued Affiliate commissions. It must not be used for customer refunds, reimbursements or unrelated payments. |
| Destination | The payout must be made to the approved Affiliate, not an unrelated third party. A new or changed payout method remains locked until the mandatory ATO unlock procedure in Section 6.1 is completed. |
| Compliance status | Required KYC, sanctions, PEP, fraud and transaction-monitoring checks must be complete. Pending verification or unresolved risk indicators may delay the payout. |
| Value/velocity | Per-transaction and cumulative limits may be applied to Affiliate, payout instrument, device and other relevant linkage points, including stricter limits imposed by the acquiring bank or payment partner. |
| Traceability/accounting | Each payout must be documented, recorded in the Company's records and linked to the underlying commission calculation, Affiliate record and available payment transaction identifiers. |
A newly added or changed payout card must remain locked for payout until the following steps below are completed. The lock may not be bypassed solely because the Affiliate has otherwise verified identifier or an accrued commission balance.
Contact details supplied for the first time in the same payout-change email must not be used as the sole means of confirmation.
A payout-method change must not be unlocked where identity verification is incomplete, ownership cannot reasonably be established, the Affiliate cannot be reached through previously verified contact information, or other material concerns remain unresolved.
Sininelabs shall not knowingly make funds or economic resources available in breach of applicable sanctions. Sininelabs shall screen affiliate and payout data against applicable EU and UN measures and relevant Estonian sanctions requirements. Additional lists, including OFAC or other government or bank lists, may be used where required by the acquiring bank, payment partner, Card Scheme programme or contract.
PEP and adverse-information screening may be applied at onboarding and on a risk-based or partner-required basis thereafter. Relevant adverse information includes credible indications of fraud, financial crime, sanctions evasion, terrorist financing, identity abuse, cyber-enabled compromise, deceptive advertising or other serious conduct that may affect the legitimacy of the Affiliate relationship or payout.
Sininelabs monitors Affiliate, referral, commission, and payout activity using a combination of rules and manual review proportionate to transaction volume and risk. Monitoring is intended to identify fraudulent or artificial acquisition activity, misuse of the referral system, identity abuse, sanctions concerns, structuring, and misuse of the Affiliate payout channel.
An alert is not by itself a finding of suspicious activity. The reviewer must consider the available context, Affiliate history, referral evidence, marketing records, commission calculations, and any reasonable explanation. The decision, rationale, and resulting restriction or escalation must be documented.
To investigate unusual activities or validate commission entitlement, the Company may review traffic sources, support marketing statistics, advertising campaigns, approved promotional materials, referral quality and commission calculations, and may suspend payouts while an audit or compliance review is pending. Affiliates are expected to cooperate with such reviews under the Affiliate Policy.
Potential sanctions match, material fraud patterns, unexplained high-risk Affiliate activity and other suspected financial-crime concerns must be referred promptly to the designated Director or Compliance function. The Company may suspend commissions, reverse unpaid commissions, delay or reject a payout, request additional documentation, restrict an Affiliate or terminate participation where permitted by law and the Affiliate Policy.
Because Sininelabs is not assumed by this Policy to be a statutory AML obliged entity, the designated Director shall determine, with legal advice where appropriate, whether a report or notification is required under applicable law, sanctions rules, a lawful authority request, an acquiring-bank/payment-partner agreement or Card Scheme programme conditions. The Company shall cooperate with its regulated payment partners and competent authorities.
Where a sanctions issue creates a legal obligation to freeze, restrict, or notify, the Company shall follow the applicable procedure and make the required notification to the competent Estonian authority, including the Estonian Financial Intelligence Unit (RAB) where applicable. No employee may release a held payout in violation of an applicable sanctions restriction.
Communications concerning delayed, suspended or rejected Affiliate payouts must be accurate and neutral. Personnel must not disclose confidential screening logic, internal investigation details, sanctions intelligence or external reporting decisions where disclosure is prohibited or could undermine the review.
Sininelabs shall maintain records sufficient to reconstruct the Affiliate relationship, the basis for commission entitlement and the control decisions associated with each payout. Records should include onboarding and verification data, screening results, Referral Link and attribution records, Qualified Customer evidence, commission calculations, monitoring alerts, review notes, approvals, exceptions, payout details and transaction identifiers.
Consistent with the Affiliate Policy, records relating to the Affiliate Program are generally retained for at least five years following termination of the Affiliate relationship, or longer where required for legal, regulatory, accounting, tax, fraud-prevention, litigation, investigation or other legitimate purposes. At the end of the applicable retention period, records are securely deleted, anonymised or destroyed in accordance with Company procedures.
Personal data must be processed in accordance with the GDPR and applicable Estonian data-protection law, including purpose limitation, data minimisation, accuracy, security, controlled access and storage limitation. Affiliate information, payment details, performance metrics and other non-public information must be treated as confidential except where disclosure is permitted or required by law.
Where Sininelabs stores, processes, or transmits cardholder data, it must follow applicable PCI DSS and payment-partner security requirements. The Company should minimise storage of primary account numbers, use tokenisation or processor-hosted solutions where feasible, restrict access on a need-to-know basis and must not retain prohibited authentication data such as CVV after authorisation.
This Policy is reviewed at least annually and sooner following a material legal, Affiliate Program, Platform, geographic, commission-model, payout-channel, acquiring-bank, or payment-partner change.
A business-change review must occur before introducing functionality that could change the nature of the Affiliate payout or the Company's regulatory classification. The review must be completed before production launch, and resulting control changes must be reflected in procedures, system rules, Affiliate documentation, partner documentation, and training.