AML Policy
1. Purpose of the Policy
This Policy sets out PayHot's approach to screening Users, Projects, payment transactions, and cryptocurrency wallets in order to reduce the risks of money laundering, terrorist financing, fraud, sanctions evasion, and other unlawful activity.
The Policy applies to Merchants, their representatives and beneficial owners, Payers, and payout recipients to the extent that their data is available to PayHot or requested by a Partner Provider.
PayHot does not perform financial settlements itself. Mandatory AML/KYC procedures for a particular transaction may be performed by Partner banks, payment institutions, and cryptocurrency processors. PayHot supports those procedures through its own risk-based checks and by transmitting required data.
2. Key Principles
- a risk-based approach reflecting the business category, geography, turnover, and payment scenario;
- screening before connection and continuous monitoring after launch;
- minimised data access and confidentiality of review materials;
- cooperation with regulated Partner Providers;
- prioritising security over connection speed where risk is elevated;
- no disclosure to a User of confidential financial monitoring actions where disclosure is restricted by law.
3. Roles and Responsibilities
PayHot collects and analyses information, assigns an internal risk profile, applies anti-fraud and AML tools, requests documents, restricts Platform functions, and cooperates with Partners.
A Partner Provider independently performs the duties imposed on it by applicable law, including identification, verification, monitoring, transaction decisions, retention of mandatory records, and reports to competent authorities where required.
The Merchant must provide accurate information, keep it current, exercise the necessary oversight over its own customers, and not use the Platform to conceal the actual participants or nature of its activities.
4. Merchant Screening — KYB/KYC
The scope of a review depends on the connection model. PayHot or a Partner may request:
- an individual's name, date of birth, nationality, contact details, and identification data;
- an organisation's registration documents, address, tax number, and evidence of a representative's authority;
- ownership structure and information about ultimate beneficial owners;
- product descriptions, domains, applications, Telegram bots, agreements, rates, and refund policies;
- traffic sources, advertising materials, customer geography, average transaction value, and turnover;
- bank and cryptocurrency details and proof of ownership of an account or wallet;
- information about the source of funds and economic purpose of transactions.
Screening may include checks against official registers, sanctions and restriction lists, politically exposed person lists, lost-document databases, adverse media, and other lawful sources.
5. Risk Categories
A Project is assigned a risk level based on all relevant factors. The internal classification is not a public assessment of business quality and is used to determine controls.
Product and model — digital goods, subscriptions, intermediary models, bulk payouts, and cryptocurrency transactions.
Geography — countries of registration and those of Users, banks, and Partners, and the purpose of cross-border transactions.
Structure — transparency of ownership, authority, bank accounts, and related persons.
Transactions — turnover, average transaction value, speed, refunds, anomalies, and the proportion of failed attempts.
Traffic and reputation — customer sources, complaints, misleading advertising, and adverse information.
Cryptocurrency — risk associated with addresses, sources of funds, mixing services, hacks, and sanctions links.
6. Enhanced Due Diligence
Elevated risk may result in additional measures:
- an expanded document package and proof of source of funds or wealth;
- screening of beneficial owners and related companies;
- manual review of the Project and advertising channels;
- restricted limits, a reserve, delayed settlement, or staged launch;
- additional confirmation of transactions and wallet addresses;
- more frequent repeat screening;
- refusal to connect or termination of service where risk is unacceptable.
7. Transaction Monitoring and AI Anti-Fraud
PayHot analyses payment flows in real time or with minimal delay using rules, statistical methods, and machine-learning models. The system compares an individual transaction with Project behaviour and related events.
Factors may include transaction frequency and speed, repeated attempts, geographic inconsistencies, sudden changes in amounts or conversion, sequences of actions, technical identifiers, refund history, links between Accounts, and other indicators.
AI analysis helps detect new combinations of factors not covered by a single static rule. When a rule or model is triggered, the transaction may be referred for additional review, blocked technically, or sent to a Partner for a final decision.
Exact algorithms, thresholds, and weights are not published so that controls cannot be more easily circumvented.
8. AML Screening of Cryptocurrency Wallets
Before or after a cryptocurrency transaction, PayHot and a Partner may analyse sender and recipient addresses, transaction history, sources of incoming funds, and links to known risk categories.
Screening may identify links to:
- hacks, theft, fraud, and extortion;
- sanctioned addresses and restricted jurisdictions;
- illegal marketplaces, darknet markets, and prohibited services;
- mixers, anonymisers, and schemes concealing the source of funds;
- unlicensed or high-risk exchanges;
- other sources classified as elevated risk by an analytics provider.
A risk signal does not necessarily mean that a transaction is unlawful, but it may require an explanation, documents, or the use of another wallet. A decision is based on all circumstances and Partner requirements.
9. Suspicious Indicators
- transactions inconsistent with the stated activity or turnover;
- no clear goods, services, or economic purpose;
- frequent refunds, chargebacks, complaints, and payments showing signs of card testing;
- artificial splitting of amounts, rapid transit, and attempted immediate withdrawal;
- many unrelated Payers funding a single recipient;
- inconsistent documents, concealed owners, and refusal to explain the source of funds;
- unusual links to high-risk countries, wallets, or services;
- attempts to circumvent limits, reviews, or Partner Provider requirements.
10. Response Measures
Where a risk is identified, PayHot may:
- request documents, information, or an explanation;
- restrict a particular method, Project, withdrawal, or Account access;
- change limits, confirmation procedures, and the level of monitoring;
- transmit information to a Partner Provider to the extent necessary;
- reject a Project or terminate cooperation;
- retain data and provide it to a competent authority on a lawful basis.
A decision to freeze, hold, refund, or transfer funds is made by the Partner actually performing the financial transaction in accordance with its authority and the law.
11. Sanctions and Restrictive Measures
PayHot and its Partners may screen persons, organisations, countries, banks, and addresses against applicable sanctions and restriction lists. A transaction or relationship may be prohibited if it would breach a mandatory restriction or create an unacceptable infrastructure risk.
12. Data Retention and Confidentiality
AML/KYC materials are retained for the period necessary to perform contractual, evidentiary, and legal obligations. Access is limited to authorised persons and contractors who need the information for their work.
PayHot does not disclose details of an internal investigation, specific risk sources, algorithms, or a possible report to an authority where disclosure is restricted by law or may interfere with a review.
13. Merchant Obligations
- provide complete and accurate information and update it without delay;
- use only approved Projects, domains, goods, and traffic sources;
- not accept payments for third parties without written approval;
- maintain evidence of orders, service fulfilment, and refunds;
- comply with sanctions, tax, consumer, and other requirements of its jurisdiction;
- promptly report suspicious activity and compromise;
- not attempt to discover or circumvent internal control criteria.
14. User Rights
A User may request correction of inaccurate identification data and provide explanations concerning a risk signal. This does not guarantee approval of a transaction or connection if a Partner or PayHot assesses the risk as unacceptable.
15. Changes to the Policy
The Policy may be updated to reflect legislation, Partner requirements, new risks, and the development of control tools. The current version is published on the PayHot Website.
16. Regulatory Framework and Contact
This Policy has been prepared with regard to applicable Brazilian anti-money laundering requirements, including Law No. 9,613/1998, general international principles of risk-based controls, and mandatory rules of Partner Providers in the relevant jurisdictions.
Questions about screening may be sent to team@pay.hot. To maintain confidentiality, PayHot may not disclose certain details of its internal monitoring system.