Policy

AML / KYC Policy

Last updated: 24 August 2026 · Scope: client due diligence and the Platform's player verification framework

Introduction

www.lumivanttech.com is operated by Lumivant Technologies Limited, having its registered office at F2-2A, Oceanic House, Providence Estate, Mahé, Seychelles, company registration number 251824. Lumivant Technologies Limited is licensed by the Anjouan Betting and Gaming Board (Autonomous Island of Anjouan, Union of the Comoros) with licence no. [to be inserted upon licence issuance].

Lumivant is a B2B supplier of gaming platform software (the "Platform"). We do not offer gambling services to the public, and we hold no player accounts and no player funds. Our counterparties are licensed B2C operators. This policy therefore operates on two levels: first, the due diligence we apply to our own clients and material suppliers (know-your-business, "KYB"); and second, the player verification framework embedded in the Platform, which our licensed operator clients apply to the players of their sites. In the framework set out below, references to "users" and "customers" are references to the players of those licensed operators.

Objective of the AML Policy

We seek to offer the highest security to the operators we supply and to the players of the sites running on the Platform. For that purpose, a three-step account verification framework is embedded in the Platform in order to ensure the identity of players. The reason behind this is to prove that the details of the person registered are correct and the deposit methods used are not stolen or being used by someone else, and to create the general framework for the fight against money laundering. We also take into account that, depending on nationality and origin, the way of payment and of withdrawing, different safety measures must be taken.

The Platform and Lumivant Technologies Limited expressly prohibit and disallow the use of the Platform and all its products for any form of illicit activities, including but not limited to money laundering, terrorist financing and sanctions violations, in line with national AML and other laws, regulations, international norms and best practices. For this reason, the Platform puts reasonable measures in place to control and limit ML risk, including dedicating the appropriate means, and is committed to high standards of anti-money laundering compliance according to the EU guidelines, and requires management and employees to enforce these standards in preventing the use of its services for money laundering purposes. The Platform regularly monitors regulatory updates and will initiate all necessary actions as deemed appropriate to reflect in its policies, systems, programs and operation any future amendments in AML laws and regulations.

The AML program of the Platform is designed to be compliant with:

  • EU: 5th Anti-Money Laundering Directive (Directive (EU) 2018/843);
  • EU: 4th AML Directive (Directive (EU) 2015/849) on the prevention of the use of the financial system for the purposes of money laundering;
  • EU: Regulation 2015/847 on information accompanying transfers of funds;
  • EU: regulations imposing sanctions or restrictive measures against persons and embargo on certain goods and technology, including all dual-use goods;
  • EU: General Data Protection Regulation (GDPR), Regulation (EU) 2016/679;
  • BE: Law of 18 September 2017 on the prevention of money laundering and limitation of the use of cash;
  • any other local laws and regulations in each country and/or state in which the Platform operates and is available.

Definition of money laundering

Money laundering is understood as:

  • the conversion or transfer of property, especially money, knowing that such property is derived from criminal activity or from taking part in such activity, for the purpose of concealing or disguising the illegal origin of the property or of helping any person who is involved in the commission of such an activity to evade the legal consequences of that person's or company's action;
  • the concealment or disguise of the true nature, source, location, disposition, movement, rights with respect to, or ownership of, property, knowing that such property is derived from criminal activity or from an act of participation in such an activity;
  • the acquisition, possession or use of property, knowing, at the time of receipt, that such property was derived from criminal activity or from assisting in such an activity;
  • participation in, association to commit, attempts to commit and aiding, abetting, facilitating and counselling the commission of any of the actions referred to above.

Money laundering shall be regarded as such even when the activities which generated the property to be laundered were carried out in the territory of another Member State or in that of a third country.

Organisation of AML for the Platform

In accordance with AML legislation, the Platform has appointed the "highest level" for the prevention of ML: the full management of Lumivant Technologies Limited is in charge, and has implemented in its operations specialised software and technologies in order to better monitor, track, detect, assess risks and combat any form of illicit activities, including money laundering, terrorist financing and sanctions violations.

Furthermore, an AMLCO (Anti-Money Laundering Compliance Officer) is appointed and is in charge of the enforcement of the AML policy and procedures within the system. The AMLCO's duties include, amongst others:

  • developing AML initiatives;
  • revising AML policies;
  • assessing new regulatory requirements;
  • overseeing compliance with AML regulations;
  • monitoring and investigating suspicious and/or unusual activities;
  • assessment of risks.

The AMLCO and Lumivant Technologies Limited conduct regular training programs, by which all employees, including employees of the Platform, are trained on KYC procedures, including identifying fraudulent documentation, recognising red flags for ML/TF activities, and reporting obligations to the relevant authorities. The AMLCO is placed under the direct responsibility of the general management.

AML policy changes and implementation requirements

Each major change of this AML policy is subject to approval by the general management of Lumivant Technologies Limited and the Anti-Money Laundering Compliance Officer.

Client due diligence (Know Your Business)

Before entering into a business relationship, Lumivant carries out due diligence on every prospective operator client and material supplier. This includes: collection of corporate documents (certificate of incorporation, registers of directors and members, constitutional documents); identification and verification of directors and ultimate beneficial owners; sanctions and PEP screening of the entity and of the individuals behind it; verification of the client's gaming licence with the issuing authority or its public register; and a review of the client's own AML and responsible gaming arrangements.

Clients are risk-rated and monitored on an ongoing basis. Licences are re-verified at least annually and screening is refreshed periodically. Our agreements allow us to suspend services immediately if a client's licence lapses or is revoked, or if the client fails to meet its AML obligations. We do not onboard operators that do not hold a valid gaming licence.

The Platform's player verification framework, set out in the following sections, is made available to every operator we supply and is applied by those operators to the players of their sites.

Three-step verification (Platform framework)

Step one verification

Step one verification must be done by every user and customer during registration/onboarding on the Platform. Without the completion of this step, no withdrawal nor any deposit shall be allowed. Regardless of the choice of payment, the amount of payment, the amount of withdrawal, the choice of withdrawal and nationality of the user/customer, step one verification must be done first. Step one verification is a document that must be filled out by the user/customer himself, containing the following information:

  • First name;
  • Last name;
  • Date of birth (to confirm minimum legal age);
  • Nationality;
  • Country of usual residence;
  • Full residential address;
  • Contact information (email and phone number);
  • Payment information (e.g. bank account or e-wallet details).

Step two verification

Step two verification must be done by every user who deposits over $2,000 (two thousand dollars) or withdraws over $2,000, and every user/customer classified based on risk assessment as a high-risk user/customer, whether due to geographic location, user activity or user type (politically exposed persons or individuals with adverse media mentions). Until step two verification is done, the withdrawal, tip or deposit will be placed on hold. Step two verification leads the user or customer to a subpage where they must submit a valid government-issued ID (such as an international passport, national ID card or driver's licence). The user/customer must take a picture of their ID with a paperclip bearing a six-digit randomly generated number next to it. Only an official ID may be used for ID verification; depending on the country, the variety of accepted IDs may differ. There is also an electronic check of whether the data filled in at step one is correct. The electronic check verifies via two different databases that the given information matches the filled document and the name on the ID. If the electronic test fails or is not possible, the user/customer is required to send in a confirmation of their current residence — a certificate of registration by the government or a similar document.

Step three verification

Step three verification must be done by every user who deposits over $10,000 (ten thousand dollars) or withdraws over $10,000, and every user/customer classified based on risk assessment as a high-risk user/customer, whether due to geographic location, user activity or user type (politically exposed persons or individuals with adverse media mentions). Until step three verification is done, the withdrawal, tip or deposit will be placed on hold. For step three, a user/customer will be asked for a source of wealth and source of funds.

Customer identification and verification (KYC)

The formal identification of customers on entry into commercial relations is a vital element, both for the regulations relating to money laundering and for the KYC policy. This identification relies on the following fundamental principles:

A copy of your passport, ID card or driving licence, each shown alongside a handwritten note mentioning six randomly generated numbers, together with a second picture showing the face of the user/customer. The user/customer may blur out all information besides date of birth, nationality, gender, first name, last name and the picture, to protect their privacy. All four corners of the ID have to be visible in the same image and all details have to be clearly readable besides those named above. We might ask for all details if necessary. An employee and/or the AMLCO may do additional checks if necessary based on the situation.

Proof of address

Proof of address is carried out via two different electronic checks, which use two different databases. If an electronic test fails, the user/customer has the option to submit proof manually: a recent utility bill sent to the registered address, issued within the last 3 months, or an official document made by the government that proves the state of residence (for example an electricity bill, water bill, bank statement or any governmental post addressed to the user). To make the approval process as speedy as possible, the document should be sent with a clear resolution where all four corners of the document are visible and all text is readable. An employee and/or the AMLCO may do additional checks if necessary based on the situation.

Source of funds

If a user/customer deposits over five thousand euro and/or the user/customer was classified based on risk assessment as a high-risk user/customer — whether due to geographic location, user activity or user type (politically exposed persons or individuals with adverse media mentions) — there is a process of understanding the source of wealth (SOW) and source of funds (SOF) of the user/customer. Examples of SOW are:

  • ownership of business;
  • employment;
  • inheritance;
  • investment;
  • family.

It is critical that the origin and legitimacy of that wealth is clearly understood. If this is not possible, an employee and/or the AMLCO may ask for additional documents or proof. The account will be frozen if the same user deposits either this amount in one go or multiple transactions which amount to this, and if the user is classified as high-risk. An email will be sent to them manually to go through the above and see more information on the website itself. The Platform also asks for a bank wire/credit card to further ensure the identity of the user/customer; this also gives additional information about the financial situation of the user/customer.

Basic document for step one

The basic document is accessible via the settings page on the Platform. Every user has to fill out: first name; last name; date of birth (to confirm minimum legal age); nationality; country of usual residence; full residential address; contact information (email and phone number); and payment information (e.g. bank account or e-wallet details). The document will be saved and created by an AI; an employee and/or the AMLCO may do additional checks if necessary based on the situation.

Risk management

In order to deal with the different risks and different states of wealth in different regions of the world, the Platform categorises every nation into three different regions of risk.

Region one: low risk

For every nation in region one, the three-step verification is done as described above.

Region two: medium risk

For every nation in region two, the three-step verification is done at lower deposit, withdrawal and tip amounts. Step one is done as usual. Step two is done after depositing $1,000 (one thousand dollars), withdrawing $1,000, or tipping another user/customer $500 (five hundred dollars). Step three is done after depositing $2,500 (two thousand five hundred dollars), withdrawing $2,500, or tipping another user/customer $1,000. Also, users from a low-risk region who exchange cryptocurrency into any other currency are treated like users/customers from a medium-risk region.

Region three: high risk

Regions of high risk are banned. High-risk regions are regularly updated to keep up with the changing environment of a fast-changing world.

Additional measures

In addition, an AI which is overseen by the AMLCO looks for any unusual behaviour and reports it right away to an employee of the Platform and the AMLCO. According to the results produced by the AI, employees and/or the AMLCO recheck all results and may proceed with redoing the checks or performing additional checks themselves according to the situation.

In addition, a data scientist supported by modern electronic analytic systems looks for unusual behaviour such as: depositing and withdrawing without longer betting sessions; attempts to use a different bank account for deposit and withdrawal; nationality changes; currency changes; residential address changes; behaviour and activity changes; as well as checks whether an account is used by its original owner.

Also, a user has to use the same method for withdrawal as used for deposit, for the amount of the initial deposit, to prevent money laundering.

Enterprise-wide risk assessment

As part of its risk-based approach, the Platform has conducted an AML enterprise-wide risk assessment (EWRA) to identify and understand risks specific to the Platform and its business lines. The AML risk policy is determined after identifying and documenting the risks inherent to its business lines, such as the services the website offers, the users to whom services are offered, transactions performed by these users, delivery channels used, the geographic locations of operations, customers and transactions, and other qualitative and emerging risks. The identification of AML risk categories is based on the Platform's understanding of regulatory requirements, regulatory expectations and industry guidance. Additional safety measures are taken to address the additional risks the world wide web brings with it. The EWRA is reassessed yearly.

Ongoing transaction monitoring

The AMLCO ensures that ongoing transaction monitoring is conducted to detect transactions which are unusual or suspicious compared to the customer profile. This transaction monitoring is conducted on three levels:

First line of control

The Platform works solely with trusted payment service providers, all of which have effective AML policies in place, to prevent the large majority of suspicious deposits onto the Platform from taking place without proper execution of KYC procedures on the potential customer.

Second line of control

The Platform makes its network aware that any contact with the customer or player or authorised representative must give rise to the exercise of due diligence on transactions on the account concerned. In particular, these include requests for the execution of financial transactions on the account and requests in relation to means of payment or services on the account. The three-step verification with adjusted risk management should provide all necessary information about all customers of the Platform at all times. All transactions must be overseen by employees, overwatched by the AMLCO, who is overwatched by the general management. Specific transactions submitted to the customer support manager, possibly through their compliance manager, must also be subject to due diligence. Determination of the unusual nature of one or more transactions essentially depends on a subjective assessment, in relation to the knowledge of the customer (KYC), their financial behaviour and the transaction counterparty. These checks are done by an automated system, while an employee and/or the AMLCO cross-checks them for additional security. Transactions observed on customer accounts for which it is difficult to gain a proper understanding of the lawful activities and origin of funds must rapidly be considered atypical. Any Lumivant staff member must inform the AML division of any atypical transactions which they observe and cannot attribute to a lawful activity or source of income known of the customer.

Third line of control

As a last line of defence against money laundering, the Platform and/or the AMLCO performs manual checks on all suspicious and higher-risk users in order to fully prevent money laundering. If fraud or money laundering is found, the authorities will be informed.

Reporting of suspicious transactions

In its internal procedures, the Platform describes in precise terms, for the attention of its staff members, when it is necessary to report and how to proceed with such reporting. Reports of atypical transactions are analysed within the AML team in accordance with the precise methodology fully described in the internal procedures. Depending on the result of this examination and on the basis of the information gathered, the AML team will decide whether it is necessary to send a report to the relevant financial intelligence unit, in accordance with applicable legal obligations, and whether or not it is necessary to terminate the business relations with the customer.

Procedures

The AML rules, including minimum KYC standards, are translated into operational guidance or procedures available on the intranet site of the Platform.

Record keeping

Records of data obtained for the purpose of identification must be kept for at least ten years after the business relationship has ended. Records of all transaction data must be kept for at least ten years following the carrying-out of the transactions or the end of the business relationship. These data are safely stored, encrypted, offline and online. All of the above is done in light of Lumivant Technologies Limited's legal obligations to combat and not allow any form of illicit activities, including money laundering, terrorist financing and sanctions violations, as well as the relevant reporting obligations.

Training

Lumivant's employees carry out manual controls on a risk-based approach, for which they receive special training. The training and awareness program includes a mandatory AML training program in accordance with the latest regulatory developments for all staff in touch with finances, and academic AML learning sessions for all new employees. The content of this training program is established in accordance with the kind of business the trainees are working for and the posts they hold. These sessions are given by an AML specialist working in Lumivant Technologies Limited's AML team. In addition, the AMLCO and Lumivant Technologies Limited conduct regular training programs by which all employees are trained on KYC procedures, including identifying fraudulent documentation, recognising red flags for ML/TF activities, and reporting obligations to the relevant authorities.

Auditing

Internal audit regularly establishes missions and reports about AML activities.

Data security

All data given by any user/customer is kept secure and will not be sold or given to anyone else. Only if required by law, or to prevent money laundering, may data be shared with the AML authority of the affected state. Lumivant follows all guidelines and rules of the General Data Protection Regulation (GDPR), Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.