This Policy aims to protect Sininelabs OÜ (the "Company"), its customers, its platform, and its regulated payment partners from misuse involving money laundering, terrorist financing, sanctions evasion, fraud, account compromise, or other financial crime. The Policy is designed specifically for the Company's customer payout process and the information available to Sininelabs through its own platform operations.
The Policy applies to directors, employees, contractors, outsourced personnel and systems that influence customer onboarding, account security, payout eligibility, sanctions screening, fraud review, transaction monitoring, finance, customer support, partner communications or record retention.
Sininelabs applies these controls on a risk-sensitive basis. The fact that Sininelabs uses AML/CFT terminology or adopts controls commonly used by regulated firms does not, by itself, alter the Company's legal classification. Where applicable law imposes a direct obligation on Sininelabs, that obligation prevails. Where a control arises from contract, partner instruction or Card Scheme programme conditions, it is treated as an operational requirement for the relevant payout flow.
Sininelabs OÜ is a commercial, non-financial company. This Policy is adopted to manage financial-crime and sanctions risk in connection with customer payouts and to satisfy applicable legal, acquiring-bank, payment-partner and Card Scheme expectations. It does not constitute a license, registration, or admission that Sininelabs is a credit institution, financial institution, payment institution, electronic-money institution or statutory AML obliged entity. Any material change to the platform, funds flow or payout functionality must be assessed before launch for possible regulatory consequences.
Sininelabs operates a commercial online platform. Customers may become entitled to receive a payout only where that entitlement arises from activity recognized and validated within the Company's platform and under the applicable customer terms. The payout function is therefore ancillary to the Company's commercial activity; it is not offered as an independent facility for transferring money between persons.
If future functionality would permit users to transfer value to each other, hold transferable balances, fund accounts for withdrawal, or cause Sininelabs to receive or transmit money as an intermediary, a new regulatory compliance assessment must be performed before the functionality is enabled.
| Role | Core accountability |
|---|---|
| Director / senior management | Approve the Policy and risk appetite; provide resources; receive material escalations; ensure business-model changes receive regulatory review. |
| Director / senior management | Maintain the risk assessment and procedures; oversee screening, monitoring, and EDD; decide escalations; maintain partner-control requirements; coordinate testing and remediation. |
| Operations / Finance | Release payouts only after required controls have passed; reconcile payout records; escalate anomalies and exceptions. |
| Customer Support / Director / senior management | Apply authentication and fraud procedures; preserve evidence; escalate suspicious or sanctions-related activity without alerting the customer to sensitive investigative details. |
| All personnel | Follow controls, protect confidential information, and promptly report unusual activity. |
No employee may bypass a sanctions hold, transaction limit, payout restriction or enhanced review requirement without documented approval from an authorized person and, where required, the acquiring bank or payment partner.
The Company maintains a documented financial-crime risk assessment that evaluates both inherent risk and the effectiveness of controls. Risk is considered at customer, account, transaction, geography, payout and third-party level. The assessment is reviewed at least annually and whenever a material change occurs.
Risk dimensions and examples:
Risk may be graded Low, Standard, Elevated or Prohibited, or by an equivalent internal scale. Elevated risk requires additional controls. Prohibited activity includes transactions that would breach sanctions, law, partner terms, Card Scheme programme conditions or the operating boundaries in Section 2.
Before a customer can use payout functionality, Sininelabs must hold sufficient information to identify the customer, connect the payout to an authenticated platform account and understand the basis on which the customer is entitled to receive funds.
Enhanced review is required when the available facts indicate materially higher risk. Measures may include stronger identity verification, additional explanation of account activity, evidence of account or payout-instrument ownership, source-of-Funds or source-of-wealth information, where relevant management approval, lower limits, or enhanced post-transaction procedures. monitoring. A PEP relationship is not automatically prohibited, but it may require enhanced review and senior approval.
A payout is released only where Sininelabs can establish a clear and legitimate basis for the amount and the intended destination. Payout controls are designed to ensure that the Company pays its own commercial obligation to the proper customer and does not provide an unrelated transfer service.
| Control point | Sininelabs requirement |
|---|---|
| Entitlement | The amount must be supported by validated platform activity and must not exceed the customer's legitimate net entitlement after applicable fees, reserves, refunds, reversals or other adjustments. |
| Destination | The payout must be directed to a permitted instrument for the intended customer. Unexplained third-party destinations require rejection or documented enhanced review. |
| Authentication | The payout request or eligibility event must arise from an authenticated account and receive step-up authentication where risk warrants. |
| Instrument changes | New or changed payout cards/accounts require risk-based re-authentication and re-screening before release. |
| Value and velocity | Per-transaction and cumulative limits must be applied by customer, account, instrument, device, and other relevant linkage points. |
| Traceability | The Company must retain internal payout identifiers and available processor/Card Scheme identifiers to support reconciliation, support and investigation. |
| Exceptions | Failed, rejected, reversed, disputed, or repeatedly retried payouts are reviewed for unusual patterns; manual overrides require documented authority. |
Sininelabs shall not knowingly make funds or economic resources available in breach of applicable sanctions. Customers and payout data shall be screened against applicable EU and UN measures and relevant Estonian sanctions requirements. Additional lists, including OFAC or other government/bank lists, may be used where required by the acquiring bank, payment partner, Card Scheme programme or contract.
PEP and adverse-information checks may be applied universally or on a risk-based basis, depending on the screening solution, customer profile and partner requirements. Relevant adverse information includes credible indications of fraud, financial crime, sanctions evasion, terrorist financing, cyber-enabled account compromise or serious criminal conduct that may affect the legitimacy of the platform activity or payout. Automated results should receive reasonable human review before an adverse decision where appropriate.
Sininelabs monitors account and payout behavior using automated rules, manual review or a combination proportionate to transaction volume and risk. The objective is to identify abnormal behavior, account takeover, structuring, collusion, sanctions evasion, fraud and misuse of the payout channel.
Below are behavioral scenarios that may trigger alerts and enhanced monitoring:
An alert is not, by itself, a finding of suspicious activity. Reviewers must consider context, customer history, available explanations and related evidence. The decision, rationale and any resulting restriction or escalation must be recorded.
Potential sanctions match, material fraud patterns, unexplained high-risk payouts and other suspected financial-crime concerns must be referred promptly to the Director. The Company may delay, reject, cancel or restrict a payout or account activity where permitted by law and contract while the matter is reviewed.
Because Sininelabs is not an AML obliged entity, the Director shall determine, with legal advice, where appropriate, whether a report or notification is required under applicable law, sanctions rules, a lawful authority request, an acquiring-bank/payment-partner agreement or Card Scheme programme conditions. Sininelabs will cooperate promptly with its regulated payment partners and competent authorities.
Where a sanctions issue gives rise to a legal obligation to freeze, restrict or notify, the Company shall follow the applicable procedure and make the required notification to the competent Estonian authority, including the Estonian Financial Intelligence Unit (RAB) where applicable.
Communications about delayed or rejected payouts must be accurate and neutral. Personnel must not disclose confidential screening logic, internal investigative details, sanctions intelligence or external reporting decisions where disclosure is prohibited or could undermine a review.
Sininelabs shall maintain records sufficient to reconstruct the basis for a payout and the control decisions taken. Records should include customer/account data, identity checks, screening results, monitoring alerts, review notes, approvals, exceptions, payout calculations and transaction identifiers.
As an internal best-practice baseline, relevant payout and financial-crime records should ordinarily be retained for five years after the transaction or end of the customer relationship, unless a different period is required by law, legal hold, acquiring-bank/payment-partner requirement or the Company's approved retention schedule.
Personal data must be processed in accordance with the GDPR and applicable Estonian data-protection law, including purpose limitation, data minimization, accuracy, security, controlled access and storage limitation. Where Sininelabs stores, processes or transmits cardholder data, applicable PCI DSS and partner security requirements must be followed. Prohibited authentication data such as CVV must not be retained after authorization.
A business-change review must occur before introducing functionality that could alter the Company's regulatory classification or the character of customer payouts. The review must be completed before production launch, and resulting control changes must be reflected in procedures, system rules, partner documentation, and training.