AML Policy
1. Purpose and scope
Ponme Saldo S.L., tax identification number (CIF) B56516628, operator of beoneboss.com under the BeOneBoss brand, establishes this policy to prevent money laundering, terrorist financing, fraud, sanctions evasion and proliferation financing to the extent relevant to its activity.
It applies to customers, businesses, distributors, suppliers and partners, in sales of gift cards, vouchers, digital codes, mobile top-ups, eSIMs and other products actually enabled. It is supplemented by the KYC Policy, the Privacy Policy and the terms and conditions of sale.
2. Risk based approach
Controls are adapted to the customer, product, amount, frequency, payment method, associated countries, channel and distribution model. We assess ease of resale or conversion, traceability and code delivery that cannot easily be reversed. Risk is classified as low, medium, high or unacceptable and reviewed when the facts change.
High volume or a previous commercial relationship does not justify ignoring an alert or carrying out a prohibited transaction. A technical signal, nationality, VPN or name match does not, by itself, suffice to establish unlawful activity.
We observe the applicable Spanish and European framework and use FATF recommendations as a reference. This policy does not grant authorisation for regulated financial services or assume that every gift card sale is subject to the same legal obligations.
3. Customer knowledge and enhanced due diligence
Individuals, businesses, representatives and beneficial owners are identified in accordance with the KYC Policy. Business or distribution relationships require an understanding of activity, ownership, representation, markets and expected volume.
Where risk is higher, we may request additional documentation, clarification of purpose, payment ownership, source of funds and, where necessary, source of wealth, as well as internal review and authorisation. We may limit or reject relationships where identity, purpose or residual risk cannot be resolved.
Politically exposed person or PEP status, or status as a relevant family member or close associate, may require enhanced due diligence and additional monitoring; it does not constitute an automatic prohibition.
4. Sanctions and restrictions
Where appropriate, we screen relevant persons and entities against applicable sanctions sources. We review potential matches, identifying data, ownership and control before reaching a conclusion. An issuer's regional restriction differs from a public sanction.
Transactions prohibited by binding regimes will not be carried out. Legally required blocking, freezing or reporting will be managed under the applicable regime. Resources subject to a prohibition will not be disposed of to make an ordinary refund.
5. Transaction monitoring
Monitoring considers individual and related purchases, amounts, units, frequency, products, payments and relevant account and device signals, according to enabled capabilities. We may review a transaction before delivering codes where the risk cannot be corrected afterwards.
Transaction splitting, multiple payers without a clear relationship, constant data changes, altered documents, activity inconsistent with the profile, insufficient explanations of funds or refunds to different destinations may require examination. Indications of scams or purchases under coercion are also reviewed.
Splitting orders, using third parties or creating accounts to circumvent limits is not permitted. Sharing an IP address or device does not, by itself, demonstrate that two persons are the same. Anti-fraud and screening tools support the analysis; their results require assessment and do not, by themselves, prove a crime.
6. Review and measures
Alerts are analysed using facts, documents, explanations and reliable sources that may lawfully be processed. We record decisions and may request information, place an order on hold, reduce limits, reject a transaction or suspend or terminate a relationship because of non-compliance or risk that cannot be mitigated.
Measures must be proportionate and respect the customer's legal rights. An operational hold is not equivalent to a legal freeze. Lack of cooperation or verification does not imply automatic forfeiture of the amount. If a necessary check cannot be performed, it will not be considered completed merely because a tool is unavailable.
7. Payments and refunds
Payments must use the buyer's own or legitimately authorised payment methods and enabled channels. We may check ownership, status, amount, currency and reference. We do not request CVV, PIN, passwords or banking codes as part of KYC.
Ordinary refunds are directed to the original payment method and holder, after checking chargebacks, prior refunds and restrictions. Alternatives require verification of the reason, legitimacy and authorisation. Turning a purchase into a mechanism for sending money to third parties is not permitted.
Convertible products and cryptoasset payments, if enabled, require assessment of their specific risks and obligations. Only authorised channels and checks appropriate to the activity are used; a general sanctions tool does not replace blockchain analysis where necessary. Consumer rights and the terms of products already delivered remain applicable.
8. Suppliers and data protection
We assess relevant suppliers and distributors, their identity, activity, capacity, permissions, payment channels and commercial restrictions. Trust in a third party does not replace our risk decisions.
We retain the records necessary to reconstruct transactions and decisions, with restricted access, security and periods according to category and applicable obligation, in accordance with the KYC Policy and the Privacy Policy. Customer data are shared only where necessary, with a legal basis and safeguards; providers do not routinely receive complete KYC files.
9. Responsibility and cooperation
Management approves the programme, allocates resources and appoints the responsible internal officer. Personnel receive instructions appropriate to their role and must promptly report relevant indications. Controls and their effectiveness are reviewed at least annually; external reviews are carried out where required or agreed on the basis of risk.
We cooperate with authorities through valid requests or legally justified reports. Where an activity is subject to suspicious transaction reporting to Sepblac, we follow the corresponding procedure and requirements to refrain from execution. This policy does not, by itself, imply obliged entity status or formal appointment of a representative before Sepblac.
Investigation information is handled confidentially where appropriate. The existence or content of reports subject to a prohibition on disclosure is not revealed, without indiscriminately denying information or rights.
10. Contact and validity
Enquiries about this policy are handled at [email protected]; general support at [email protected]. Privacy requests should be addressed to [email protected].
The approved version takes effect on its publication date and is reviewed at least annually or following relevant changes. Material changes are communicated to affected relationships. Publication must reflect operations and available controls and cannot exclude legal obligations, consumer rights or data protection safeguards.