KYC Policy
1. Purpose and scope
Ponme Saldo S.L., tax identification number (CIF) B56516628, operates beoneboss.com under the BeOneBoss brand. This policy explains how we verify buyers' and businesses' identities, the legitimacy of their payments and the consistency of their purchases to prevent fraud and misuse.
It applies to individual customers, businesses, distributors and representatives, through enabled channels and for products actually sold, including gift cards, vouchers, digital codes, mobile top-ups and eSIMs. It is supplemented by the AML Policy, the Privacy Policy and the terms and conditions of sale and issuer terms. Mandatory rules and consumer rights take precedence.
2. When we may request verification
The information required depends on the product, amount, quantity, frequency, payment method, destination and transaction risk. We may request checks before accepting or delivering an order, when increasing limits or when reviewing subsequent activity, particularly in the following cases:
- High, accumulated purchases or purchases close to review limits.
- Differences between identity, payment holder, billing details or access location.
- Fraud signals, declined payments, chargebacks, inconsistent documents or unusual activity.
- Business relationships, provider requirements or potential sanctions list matches.
A gift purchase, a shared network, a VPN or residence in a particular country does not, by itself, prove unlawful activity. Using accounts, third parties or separate orders to circumvent controls or product restrictions is not permitted.
3. Information and documents we may request
We apply basic, standard, enhanced and business verification levels. We request only information relevant to the case and reuse verified data where they remain valid and sufficient. As appropriate, we may request:
- First and last names, email address, telephone number, address and country of residence or billing; other identifying data only where necessary.
- A valid, legible official identity document, such as a Spanish national identity card (DNI) or passport. Other documents are accepted where they provide sufficient assurance. We may check authenticity and correspondence with the person.
- Proof of address, such as a utility bill, certificate or limited statement, where relevant. We may request documents from the previous three months, except where a different validity period or justified circumstances apply.
- Evidence of payment ownership and authorisation, purpose of the purchase and, where justified by the risk, source of funds through appropriate documents. Source of wealth is requested only if an additional check is necessary.
Customers must provide truthful, up-to-date data. They may conceal information unrelated to the check or add a watermark that does not cover necessary elements. If they do not have a usual document, they may propose an alternative that we will assess according to its reliability and the risk.
We do not request CVV/CVC, PIN, banking passwords, one-time codes or the full card number. This policy does not, by itself, authorise automated facial recognition or biometric processing for unique identification; such processing requires its own legal basis, information and safeguards.
4. Businesses and distributors
Business verification or KYB may include tax and registration data, activity, markets, expected volume, payment methods, incorporation and representation documents, ownership structure and beneficial owners. As a reference, we identify those who own or control more than 25 % of the capital or votes and those who exercise control by other means, in accordance with applicable requirements.
We may cross-check documents against registers and independent sources. If someone acts on behalf of another person, we may request identification and authorisation. Distributors must explain their activity and traceability; disclosure of end-buyer data requires necessity, a legal basis and a secure channel.
5. Sanctions and enhanced review
We may screen relevant persons and entities against sources of sanctions and politically exposed persons or PEPs. Name matches are reviewed before concluding that they relate to the customer.
PEP status, or status as a relevant family member or close associate, may require additional information, enhanced review and internal authorisation, but does not constitute an automatic prohibition. Legally applicable sanctions are managed according to their scope and ownership or control rules.
6. Procedure and updates
We will indicate the purpose of the request, the information needed and a reasonable response deadline, to the extent permitted. Sensitive documentation must be submitted through the specified secure channel; complete documents should not be attached to ordinary emails without specific instructions for secure submission.
Requests are handled without undue delay, depending on the completeness of the information and the complexity of the checks. We may consider less intrusive alternatives and justified deadline extensions. Completing verification does not guarantee all future purchases or replace the controls of the payment provider or issuer.
Customers must report relevant changes in identity, address, representation, ownership or activity. We may update verification following changes, expired documents, increased limits or new risks.
7. Decisions and refunds
A review may result in approval, an additional request, approval with limits, temporary suspension or rejection. Measures must be proportionate to the facts and respect customer rights. Customers may request a review and provide new information; automated decisions are subject to the safeguards required by law, including human intervention where applicable.
If an order is not delivered because verification cannot be completed, we will handle cancellation and the release of the authorisation or corresponding refund. As a rule, refunds are made to the original payment method and holder; alternatives require validation. Failure to complete verification does not imply automatic forfeiture of the amount.
Legal prohibitions, valid requests from authorities or payment provider restrictions may affect handling. Products already delivered or activated are subject to their terms and the corresponding legal rights.
8. Data protection and retention
Ponme Saldo S.L. is the data controller. Data are used for verification, fraud prevention, security, resolution of issues and specific applicable obligations, in accordance with the Privacy Policy. The legal basis is determined for each processing activity; acceptance of this policy does not constitute universal consent.
We apply access by role, appropriate protection of transmission and storage, access logging and scheduled deletion. Providers and international transfers must have the relevant safeguards. KYC documents are not used for advertising.
Where no specific AML retention obligation exists, the proposed criterion is to delete identity copies, supplementary images, proof of address and detailed source-of-funds evidence within 90 days after verification is closed, unless there is a documented need. The minimum result is retained during the relationship and for up to 12 months afterwards if still necessary; technical risk data, as a rule, for up to 180 days.
Commercial and accounting documents follow their specific periods, including six years from the last relevant entry. If the activity is subject to Law 10/2010, the required documentation follows the ten-year period and access restrictions after five years. Investigations or claims may justify additional documented retention; when they end, the appropriate deletion or blocking applies.
9. Rights and contact
You may exercise applicable rights of access, rectification, erasure, restriction, objection and portability at [email protected]. We will normally respond within one month, with legally permitted extensions and prior notice. You may lodge a complaint with the Spanish Data Protection Agency or another competent authority.
KYC enquiries and review requests are handled at [email protected]; general support at [email protected]. We may limit information whose disclosure would allow controls to be circumvented or breach a legal prohibition, while preserving enforceable rights.
10. Updates and validity
The policy is reviewed at least annually and following relevant changes. The approved version takes effect on its publication date, and material changes are communicated where they affect existing relationships. Publication must reflect controls actually applied.