Text in a dashed box, like this, is a placeholder to be completed before the document takes effect.
1. Who we are and what this notice covers
ChrysoSure AI (“ChrysoSure”, “we”, “us”) provides a software platform that regulated firms use to verify customers, screen them against sanctions and other lists, monitor transactions, detect fraud and investigate financial crime. The platform is operated by [Legal entity name], a company registered in [jurisdiction] under number [company number], with its registered office at [registered address].
This notice explains how we handle personal data in two different roles:
- As a processor (service provider). Most personal data in the platform belongs to our customers: the banks, payment firms, fintechs, crypto businesses and other organisations that use ChrysoSure to meet their own obligations. They decide why and how that data is processed. We process it only on their documented instructions. Sections 2 to 8 describe this processing.
- As a controller (business). We decide how to process a smaller set of data for our own purposes: visitors to this website, people who contact us, and the staff of our customers who hold accounts on the platform. Section 9 describes this processing.
If you are a customer of one of our customers (for example, you were asked to verify your identity when opening an account), the organisation you dealt with is the controller of your data and its own privacy notice applies. Please direct requests about that data to them. If you contact us instead, we will pass your request to them and help them respond.
2. Our role as a processor
When we act as a processor:
- we process personal data only on the customer’s documented instructions, set out in our agreement and our data processing agreement (“DPA”), which follows Article 28 of the EU and UK General Data Protection Regulation (“GDPR”);
- the customer is responsible for having a lawful basis for the processing, for giving people the notices the law requires, and for obtaining any consent that is needed;
- our staff and subprocessors who can access the data are bound by confidentiality;
- we help the customer respond to requests from individuals, carry out data protection impact assessments and meet its security and breach-notification duties;
- at the end of the service we delete or return the data, as the customer chooses, unless the law requires us to keep it.
Customers can request a copy of the DPA from privacy@chrysosureai.com.
3. Personal data we process for customers
Which of these categories are processed depends on the modules a customer uses and how it configures them.
- Identity data: names, dates of birth, nationality, addresses, identity document numbers and other identifiers, and information about businesses and the people who own or control them.
- Identity documents: images of passports, identity cards and similar documents, the data read from them (including the machine-readable zone), and the results of checks for signs of alteration.
- Chip data: where a customer’s journey reads the chip in an e-passport or eID card, the data groups read from the chip and the result of the authenticity check.
- Biometric data: selfie images, and the results of comparing a selfie with a document photo and of passive checks that a real person was present. We store the results of these checks; the platform is designed not to keep facial templates after a check is complete. [Confirm biometric retention with engineering before launch]
- Contact data: email addresses and phone numbers used to contact a person on the customer’s behalf.
- Device and behavioural data: IP addresses and the approximate location derived from them, device and browser characteristics (stored as a one-way fingerprint), and patterns of interaction used to recognise bots and account takeover.
- Financial data: transactions, payment and account details, chargebacks, and for crypto businesses wallet addresses and Travel Rule originator and beneficiary information.
- Screening data: potential and confirmed matches against sanctions lists, lists of politically exposed persons and their relatives and close associates, and adverse media. Adverse media and some list entries can include information about alleged or proven criminal offences.
- Case data: alerts, investigation notes, evidence, decisions, drafts of suspicious activity report narratives, and the report files a customer produces.
- Audit data: a record of who (or which agent) did what, and when.
4. Biometric and criminal offence data
Some of this data is subject to additional protection:
- Biometric data used to confirm that a person is who they claim to be is special category data under Article 9 GDPR, and “biometric information” or “biometric identifiers” under US state laws.
- Information about criminal convictions and offences, which can appear in screening and adverse media results, is covered by Article 10 GDPR.
The customer, as controller, decides whether to use these features and is responsible for the condition that makes the processing lawful. Depending on the country, this may be a legal obligation to prevent money laundering and fraud, a substantial public interest condition (in the UK, for example, the conditions in Schedule 1 of the Data Protection Act 2018 for preventing or detecting unlawful acts and for regulatory requirements), or the person’s explicit consent. Where a US state biometric privacy law applies, the customer is responsible for giving the required notice, obtaining written consent and publishing a retention schedule. We process this data only to provide the checks the customer has switched on.
5. Automated decisions and human review
The platform produces some results automatically, including:
- risk ratings, with the contribution of each factor shown;
- potential matches from screening;
- the outcome of document, chip, selfie and presence checks;
- transaction monitoring alerts;
- fraud scores, and the result of fraud rules the customer writes.
The platform is built so that the most consequential actions are not taken by automation alone. When an AI agent proposes filing a report, declining or exiting a customer, blocking activity or confirming a sanctions match, a person must approve it, and customers can require a second person to check key decisions.
A customer can still configure some outcomes to take effect without human review. For example, it can set a fraud rule to decline a payment in real time. Where a decision based solely on automated processing has legal or similarly significant effects on a person, Article 22 GDPR applies. The customer is then responsible for making sure a lawful exception applies and for providing safeguards, including the right to obtain human review, to express a point of view and to contest the decision. The platform supports this with explanations of the factors behind each result and the ability to send results for review.
If you want to challenge a decision that an organisation made using ChrysoSure, contact that organisation.
6. Artificial intelligence and language models
Some features use large language models and other machine learning, including models from third-party providers that act as our subprocessors. These features include:
- reading identity documents;
- drafting investigation summaries and suspicious activity report narratives;
- gathering evidence during agent-assisted investigations;
- answering questions asked in plain language;
- turning rules written in plain English into rules the platform can run.
We give these providers only the data a feature needs, under contracts that prohibit them from using it to train their own models. [Confirm provider terms before launch] For some features, such as narrative drafting, names and identifiers are replaced with tokens before the text leaves the platform.
We do not use one customer’s data to train models that serve other customers. Models a customer trains on its own data stay within that customer’s environment. [Confirm before launch] AI output can be wrong. It is presented to people for review, and it never replaces the approval steps described in section 5.
7. Messages sent for customers
Customers can ask the platform to contact people by SMS, email or in-app message, for example to request a missing document or an updated address. These messages are sent on the customer’s behalf. They contain a secure, single-use link to upload the information, and every message is logged. If you no longer want to receive them, contact the organisation that sent them. These messages are for collecting information needed for compliance, not for marketing.
8. Shared fraud signals
Customers can choose to take part in a shared fraud-signal network. Before a signal is shared, identifiers such as an email address, phone number, device, IP address or wallet address are converted into salted one-way hashes. The original value is never shared. Contributors are recorded under anonymous member tokens, so a signal does not reveal which organisation reported it. A match is returned only after the same signal has been reported by several separate members. Participation is off unless the customer turns it on.
9. Personal data we control
| Who | What we collect | Why | Lawful basis (GDPR) |
|---|---|---|---|
| Website visitors | IP address, browser type, the page requested and the time, in our web server logs | To deliver the site, keep it secure and investigate abuse | Legitimate interests (Art. 6(1)(f)) |
| People who contact us | Name, work email, organisation, role and what you tell us | To respond, arrange demos, and manage our relationship with prospective customers | Legitimate interests; steps before entering a contract (Art. 6(1)(b)) |
| Customer account users | Name, work email, role and permissions, sign-in identifiers from single sign-on, passkey public keys, IP addresses, session records and an audit trail of actions | To provide and secure the platform, authenticate users, support customers and keep records | Performance of a contract with our customer; legitimate interests; legal obligation (Art. 6(1)(c)) where records are required |
| Suppliers and partners | Business contact details | To manage our business relationships | Legitimate interests |
We do not sell personal data. We do not use it for targeted advertising, and we do not build marketing profiles.
10. Cookies
This website sets no cookies and uses no analytics or third-party trackers. Its fonts and images are served from our own servers.
The platform at app.chrysosureai.com uses only strictly necessary cookies. They keep you signed in and protect your session against cross-site request forgery. Because they are required to provide the service you asked for, they do not need consent. The platform does not use analytics or advertising cookies.
11. Subprocessors
We use carefully selected subprocessors in these categories:
- infrastructure hosting, storage, backup and network delivery;
- providers of large language models and machine learning;
- delivery of email and SMS messages;
- providers of sanctions, politically exposed person, adverse media and company registry data;
- electronic signature;
- billing.
Each subprocessor is bound by a written contract with data protection terms at least as protective as those in our DPA. Customers can get the current list of subprocessors, with their locations, from privacy@chrysosureai.com. We tell customers before adding or replacing one, so they have a chance to object. [Notice period, e.g. 30 days]
12. Where data is stored and international transfers
Customers choose where their platform data is primarily stored: the European Union, the United States, the United Kingdom or Asia-Pacific. Customer data is stored and processed in that region.
Some processing can still take place outside the chosen region. This includes certain language model features, support given by our staff, and fraud signals shared in hashed form. Wherever we or our subprocessors transfer personal data out of the EU, the UK or another country with transfer rules, we rely on one of the following:
- an adequacy decision (including, where applicable, the EU–US Data Privacy Framework and its UK extension);
- the European Commission’s Standard Contractual Clauses (Decision 2021/914);
- the UK International Data Transfer Addendum;
- another lawful transfer mechanism.
Where a transfer assessment finds it necessary, we add further safeguards. [Confirm transfer mechanisms per subprocessor]
13. How long we keep data
Customer data. We keep customer data for as long as the customer instructs us to and our agreement requires. Firms subject to anti-money laundering law usually must keep customer due diligence records and transaction records for a minimum period, and customers set their retention to match. For example:
- EU: at least five years after the business relationship ends or an occasional transaction completes (Anti-Money Laundering Directive, Article 40, and Regulation (EU) 2024/1624), with possible extensions under national law.
- UK: five years (Money Laundering Regulations 2017, regulation 40).
- US: five years under the Bank Secrecy Act (31 CFR 1010.430).
- Canada and Singapore: five years under FINTRAC requirements and MAS Notice 626.
When a customer’s agreement ends, we delete or return its data within [30] days, and remove it from backups as they expire, within [90] days. The exception is data that the law requires us to keep.
Our own data.
- Web server logs: [30 days]
- Enquiries from prospective customers: [2 years] after our last contact
- Account data: for the life of the customer agreement and [1 year] after it
- Financial records: as long as tax and accounting law requires
When a user account is erased, we de-identify the user in audit records instead of deleting those records. This keeps the tamper-evident trail intact, which is permitted where records are needed to meet legal obligations (Article 17(3)(b) GDPR).
14. How we protect data
We protect personal data with technical and organisational measures appropriate to its sensitivity. They include:
- encryption in transit, and encryption at rest, with an additional layer of encryption for sensitive identifiers;
- separation of each customer’s data, enforced by the database itself;
- single sign-on, passkeys and security keys, and access controls based on least privilege;
- a tamper-evident audit trail of actions taken by people and by agents;
- removal of personal data from operational logs and telemetry;
- backups, and regular testing of our ability to recover.
We are preparing for SOC 2 and ISO 27001. We do not currently hold either certification. More detail is on our security page.
If we become aware of a personal data breach affecting customer data, we notify the affected customer without undue delay, as our DPA requires. Where we are the controller, we notify the relevant supervisory authority and affected people as the law requires.
15. Your rights under GDPR and UK GDPR
Depending on where you live, you may have the right to:
- access your personal data;
- correct it;
- have it erased;
- restrict or object to its processing;
- receive it in a portable format;
- withdraw consent where processing relies on consent;
- not be subject to decisions based solely on automated processing that significantly affect you.
For data we control, email privacy@chrysosureai.com. We will respond within one month, which can be extended where the law allows. We may need to verify your identity first. For data we process for a customer, contact that customer; if you contact us, we will forward your request to them.
Some rights are limited by law. For example, a firm may be required to keep anti-money laundering records, and may be prohibited from telling someone that a suspicious activity report has been made.
You can complain to a data protection supervisory authority, such as the UK Information Commissioner’s Office or the authority where you live or work. We would appreciate the chance to address your concern first.
16. California and other US state privacy laws
This section applies to California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA), and to residents of other US states with similar laws.
As a service provider. For personal information we process for customers, we act as a service provider or contractor. We do not sell or share that information, keep or use it outside our direct relationship with the customer, or combine it with other data except as the law allows. Requests should go to the customer. Much of this information may also be exempt from the CCPA, for example where the Gramm-Leach-Bliley Act covers it.
As a business. In the last 12 months we collected these categories of personal information for the purposes in section 9:
- identifiers (name, email, IP address);
- professional information (employer and role);
- internet activity (server logs and platform audit records).
We collect them from you, your employer and your devices. We disclose them to our subprocessors for business purposes only. We have not sold or shared personal information, and we do not knowingly sell or share the personal information of anyone under 16.
Sensitive personal information. Account credentials, and biometric information processed for customers, are used only for the purposes the CCPA allows. We do not use them to infer characteristics about you.
Your rights. You have the right to know, access, correct and delete your personal information. You also have the right to limit the use of sensitive personal information, and not to be discriminated against for exercising your rights. Because we do not sell or share personal information, there is nothing to opt out of.
To make a request, email privacy@chrysosureai.com. We will verify your request by matching the information you give us with the information we hold. An authorised agent can make a request for you with your signed permission.
17. Children
Our website and platform are for businesses and are not directed at children. Customers may, within their own legal obligations, verify the identity of young people who open accounts with them. The customer is responsible for that processing.
18. Changes to this notice
We will update this notice when our processing changes. When we make a material change, we will tell customers in advance and change the date at the top of this page.
19. Contact
- Privacy questions and requests: privacy@chrysosureai.com
- Data protection officer: [DPO name or “not required”, and contact]
- EU representative (Article 27 GDPR): [name and address, if required]
- UK representative: [name and address, if required]
- Post: [Legal entity name], [registered address]