Last Updated: 28-May-2025
This Privacy Policy outlines how KYC2020 (“we”, “our”, or “us”) collects, uses, maintains, and discloses information from individuals (“Users”) who visit, interact with, or use our website at https://kyc2020.com (the “Site”), as well as any related services, features, or content we provide. This includes information collected directly from Users (referred to as “you” or “your”), automatically through their use of the Site (e.g., via cookies or analytics tools), or from third-party sources where permitted by law. The term “you” or “your” also includes individuals who may not be direct Users of our Site or services, but whose personal information we collect from publicly available sources such as news articles, official government sources, WIKI, or other sanctions/watchlists in our role as a Data Controller. By accessing or using the Site, Users agree to the terms of this Privacy Policy.
At KYC2020, we treat privacy as an important part of our product and service design. Our goal is to comply with data protection laws such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) and provide meaningful transparency into how we handle personal information where we act as the Data Controller of Users’ personal information. KYC2020 holds the SOC 2 Type 2 certification, which is part of the Service Organization Control framework developed by the American Institute of Certified Public Accountants (AICPA). These certifications establish rigorous standards for auditing, securely storing, and processing of Users’ data by third-party service providers on behalf of Users.
KYC2020 complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. KYC2020 has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. KYC2020 has also certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, KYC2020 commits to cooperate and comply with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.
We also commit to resolving DPF Principles-related complaints about our collection and use of your personal information. Individuals in the EU, UK and Switzerland with inquiries or complaints regarding our handling of personal data should first contact KYC2020 at: [email protected]
Under certain conditions, individuals may invoke binding arbitration for residual claims not resolved by other redress mechanisms. If you have contacted us regarding a DPF-related complaint and it has not been resolved through our internal process, independent dispute resolution, or enforcement by authorities, you may invoke binding arbitration by delivering notice to KYC2020 and following the procedures set forth in Annex I of the DPF Principles. We are committed to complying with the terms of binding arbitration as required by the Data Privacy Framework.
Individuals in the United Kingdom and Switzerland have the right to access personal data that we hold about them. This includes the right to review, correct, or delete data where legally permitted. To exercise your access rights, please contact us at the email address provided above.
I. KYC2020 is a Data Processor where we receive Personal Information from Users to process personal data on behalf of the Users for the purposes of providing Anti-Money Laundering / Counter Terrorism Financing (AML/CTF) and related services to the Users. These instances are:
We are not responsible for the data privacy practices of our Users, which may differ from ours. If you have any questions about our Users’ data privacy practices, we encourage you to contact us directly.
We are neither informed nor responsible for actions, practices, or decisions of the Users as it relates to the use of our services to accept or deny an individual or entity. Use of our services is only upon acceptance by Users of our end-user’s license agreement and terms of our service with disclaimers that include:
II. KYC2020 is a Data Controller where we receive Personal Information directly from you/with your permission. These instances are:
III. KYC2020 is a Data Controller where we collect and process Personal Information directly from public, government, and news sources to build our anti-money laundering/counter terrorism financing, sanctions, criminal, regulatory, and adverse media watchlist data. These instances are:
From time to time, we will update this Privacy Policy to include additional information about our privacy practices related to a specific activities KYC2020 undertakes.
We may collect or receive personal information from the following categories of individuals or sources:
Data Processing Subject | Description | Personal Data Collected | Purpose | Legal Basis | Who has access |
---|---|---|---|---|---|
Job Applicants | Contact & assess candidates. | Name, CV/Resumes, References. | Evaluate application and communicate status | Consent | Internal KYC2020 recruitment team |
Data Processing Subject | Description | Data Collected | Purpose | Legal Basis | Who has access |
---|---|---|---|---|---|
Employees | Manage employment and HR administration. | Payroll details, personnel records, regulatory compliance info. | Compensation, HR operations, employment records, safety, and legal compliance | Contractual Necessity | Internal KYC2020 HR & Operations Team |
Data Processing Subject | Description | Personal Data Collected | Purpose | Legal Basis | Who has access |
---|---|---|---|---|---|
User-Initiated Contact & Submissions | Handle form submissions, subscription requests, and service inquiries. | Name, email, designation, organization, and subscription-related messages. | Respond to inquiries, provide requested services or updates, and manage subscriptions. | Consent – Users may withdraw consent at any time by contacting us or using unsubscribe options. | Internal KYC2020 teams for support and communications; stored with secure cloud service providers |
Data Processing Subject | Description | Data Collected | Purpose | Legal Basis | Who has access |
---|---|---|---|---|---|
Website Visitors | Automatically collect browsing data via cookies and trackers. | Page views, session duration, navigation patterns, device/browser specs, IP address, cookie IDs, and third-party metadata. | Analyze traffic to improve site structure, functionality, and user experience. | Consent – provided through the cookie banner. Users can adjust preferences at any time. | Internal KYC2020 Web & Analytics Team |
Data Processing Subject | Description | Personal Data Collected | Purpose | Legal Basis | Who has access |
---|---|---|---|---|---|
AML/CTF Screening & Risk Intelligence | Collect publicly available data from official sources, open databases, and media reports. |
|
|
Legal Obligation under AML/CTF regulations |
Authorized users of the KYC2020 platform
|
Data Processing Subject | Description | Personal Data Collected | Purpose | Legal Basis | Who has access |
---|---|---|---|---|---|
Vendor & Partner Engagement | Collect and manage contact and company details from public sources and direct interactions. | Names, email addresses, phone numbers, mailing addresses, company names, websites. | Manage sales outreach and partnerships
|
Consent: For prospects and marketing
|
Relevant KYC2020 staff in sales, vendor management, and service delivery |
Processing Activity | Role of KYC2020 | Lawful Basis | Data Subject Rights |
---|---|---|---|
Prospect and Client Data through KYC2020 Website | Controller | Consent | Not applicable, as the data processed relates to business entities rather than individuals. |
Watchlist Database | Controller | Legal Obligation (AML/CTF Compliance) | Right of Access is applicable. Other rights are limited under GDPR Article 23 due to AML/CTF regulations. See summary below. |
Screening Engine | Data Processor as per Contract and/or End-User License Agreement (EULA) | Performance of Contract under the KYC2020 EULA with acceptance of our Service Disclaimers. | Not applicable, as KYC2020 acts on behalf of its clients and processes business-related data. |
Where the processing is based on Users’ consent, the User has the right to withdraw their consent at any point in time. Please note that the withdrawal of consent results in us not being able to continue offering our services to the User. We reserve the right to withdraw or cease our services to Users upon your withdrawal. Users may withdraw consent by contacting us with a written request to the contact details specified below in the ‘Contact Us’ section.
Where we collect and process data from public sources to create our Global Watchlist Database for Sanction, PEP, and Adverse Media Screening, the following section provides the GDPR Rights Applicability.
GDPR Right | Applicability |
---|---|
Right of Access (Article 15) | Yes: Subject to limitations (e.g., anti-tipping-off). Ensures transparency and accountability even for AML/CTF related processing. |
Right to Rectification (Article 16) | Not applicable: Data originates from official public sources; KYC2020 is not responsible for its accuracy and is not required to modify third-party data |
Right to Erasure (Article 17) | Generally overridden by legal obligations under AML/CTF regulations. |
Right to Object (Article 21) | Not applicable: Processing is based on legal obligation. |
Right to Restrict Processing (Article 18) | Not applicable: Restriction must not conflict with AML/CTF laws. |
Right to Data Portability (Article 20) | Not applicable: Data is not processed on the basis of consent or a contract with the data subject. |
As a data processor, we are not responsible for responding directly to data subject requests that come from the User’s end-user. However, in accordance with applicable data protection laws, we are required to assist our Users in responding to such requests, to the extent reasonably possible and appropriate to the nature of our processing activities.
To exercise your rights per GDPR, please contact us at [email protected]. We will process such requests in accordance with GDPR timelines and requirements.
You may also contact KYC2020 Support at [email protected].For questions or issues with how Users use our data or screening services in conjunction with other data and services, or review and clear false positives from technologies that are prone to errors, or make decisions to accept or deny for any purpose, please directly contact the User.
We adopt appropriate data collection, storage, and processing practices, as well as security, measures to protect against unauthorized access, alteration, disclosure or destruction of personal information, username, password, transaction information and data stored on our Site. Sensitive and private data exchange between the Site and its Users happens over a HTTPS / sFTP / SSL secured communication channel and is encrypted and protected with digital signatures.
We do not sell, trade, or lease our mailing lists including personal identification information to others, and we will not share Users’ personal information to any unaffiliated parties, except as follows:
For the purposes of the Services, we use automated data collection tools such as Cookies to collect certain information. “Cookies” are small text files that are placed on Users’ devices by a Web server when they access our Services.
The categories of cookies used are:
Users have the option of blocking or not allowing cookies, which is provided for by our cookie banner asking Users which type of cookie they wish to enable. For more details about how we use these technologies, please see our Cookie Policy.
We retain personal data only for as long as instructed by the Data Controller or as necessary to fulfil legal obligations, including AML/CTF, and other applicable regulatory requirements. Where permissible and upon written request from the Data Controller, we will delete or anonymize personal data that is no longer required for lawful processing.
We do not knowingly collect or maintain personal data from individuals under the age of 13, in compliance with the U.S. Children’s Online Privacy Protection Act (COPPA). Our services and website are not intended for or directed to children under 13. Where required by applicable laws in other jurisdictions, we take appropriate steps to obtain verifiable parental consent when processing personal data of minors.
We implement appropriate technical and organizational measures to safeguard Users’ personal data against unauthorized access, disclosure, alteration, or destruction. These include, where applicable, encryption, firewalls, access controls, and periodic security assessments. While we follow best practices to secure data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. As a Data Processor, we act under the instructions of the Data Controller and will promptly notify the Controller of any personal data breach, as required under applicable laws including the GDPR.
Users may find advertising or other content on our Site that link to the sites and services of our partners, suppliers, advertisers, sponsors, licensors and other third parties. We do not control the content or links that appear on these sites and are not responsible for the practices employed by websites linked to or from our Site. In addition, these sites or services, including their content and links, may be constantly changing. These sites and services may have their own privacy policies and customer service policies. Browsing and interaction on any other website, including websites which have a link to our Site, is subject to that website’s own terms and policies.
If Users are using our services to process personal data on behalf of others (e.g., their customers or end-users), they are responsible for ensuring that they have obtained the necessary consents or legal basis to transfer and process personal data on servers located in the United States. By using our services, Users represent and warrant that their data collection, use, and sharing practices comply with all applicable data protection laws and regulations, including GDPR if applicable.
As outlined in our EULA, Users acknowledge and accept that designations such as PASS, FAIL, CLEAR, VERIFY, HIT, or NO HIT provided by any KYC2020 service or software are simply identifications as to whether the search subject has likely appeared in the lists or news sources identified by KYC2020. These outcomes are generated using automated search technologies and are subject to limitations, including the risk of false positives or false negatives due to factors beyond KYC2020’s control.
It is the sole responsibility of the User to review all results and make final determinations regarding acceptance, rejection, or further due diligence. KYC2020 does not control or influence the inclusion or removal of individuals or entities on the underlying lists and assumes no liability for reliance on these outcomes.
We take reasonable measures to protect Users’ personal data and comply with applicable laws, but we do not warrant that our services are completely error-free or secure against all risks. By using our services, Users’ acknowledge and accept this limitation.
KYC2020 is subject to the investigatory and enforcement powers of the United States Federal Trade Commission (FTC). This means that the FTC has the authority to enforce our compliance with the DPF Principles, including the handling of personal data transferred from the EU, UK, or Switzerland under the DPF program.
KYC2020 has the discretion to update this privacy policy at any time. When we do, we will revise the updated date at the top of this Privacy Policy. We encourage Users to frequently check this page for any changes to stay informed about how we are helping to protect the personal information we collect. You acknowledge and agree that it is your responsibility to review this privacy policy periodically and become aware of modifications.