Know-Your-Customer & Sanctions Policy
Effective date: 2026-08-05 · Last updated: 2026-08-05
DRAFT — PENDING COUNSEL REVIEW. Working draft for public Beta; not legal advice. Counsel to confirm the KYC threshold, sanctions-screening obligations for a Türkiye-established SaaS with an EU Merchant of Record, and record-keeping duties before GA.
This policy describes how we vet customers and prevent prohibited use. It supports the Terms of Service, the Acceptable Use Policy, and the public-data compliance posture; it mirrors, in proportionate form, the customer-vetting layer that responsible public-data providers maintain.
1. Risk-based, proportionate approach
AllAPI sells access to a gateway over publicly available data. We apply a risk-based program: light-touch by default for standard self-serve accounts, with enhanced checks for higher-risk or higher-volume use.
2. Identity & payment verification
- Free / self-serve: email verification + a bot-challenge (CAPTCHA) at signup; no formal identity documents required.
- Paid plans: payment is processed by our Merchant of Record, Creem (Armitage Labs OÜ), which performs card/AML checks and tax-status collection at checkout. We receive verified billing records from Creem.
- Enterprise / bespoke: we may request company registration details, a named contact, and a description of the intended use before provisioning custom capacity or higher limits.
3. Sanctions & export screening
We do not knowingly provide the Service to individuals or entities that are:
- on applicable sanctions/consolidated lists (e.g. UN, EU, OFAC, UK HMT, and Turkish measures), or
- located in comprehensively sanctioned jurisdictions, to the extent prohibited by applicable law.
We reserve the right to screen account and billing data against such lists, to request clarification, and to refuse, suspend, or terminate access where a prohibited nexus is identified.
4. Use-case vetting (AUP push-down)
Acceptance of the Acceptable Use Policy is required. Prohibited uses include (non-exhaustive): accessing non-public/logged-in data or bypassing access controls; re-identifying individuals or building profiling/surveillance tooling; mass personal-data harvesting without a lawful basis; spam, fraud, impersonation, ranking manipulation; and reselling proxy/streaming/credential access. We monitor for abuse signals and may require an explanation of use for anomalous patterns.
5. Ongoing monitoring & cooperation
We monitor for abuse (per-IP spikes, credential stuffing, key sharing, coordinated bursts, tier-limit circumvention — Privacy §4). We may suspend or terminate offending accounts, preserve evidence, and cooperate with law-enforcement and regulators where lawfully required (Privacy §14.4).
6. Records
KYC/sanctions records are retained as needed to evidence compliance and to meet legal obligations, then purged, consistent with Privacy §5.
Contact
Compliance & abuse: [email protected] · General: [email protected] · Operator: Legal Eye Yazılım A.Ş., Kağıthane / İstanbul, Türkiye.
Draft — pending counsel review. Not legal advice.