Summary. We are a small seller of digital goods and do not hold customer funds. Payments are processed by FreeKassa and Card2Crypto, who run their own checks. On our side, we monitor for suspicious orders, may ask for more information, hold or decline a transaction, and keep order records for 5 years.
1. Purpose and Scope
This policy describes how Xernel (“we”, “us”) works to prevent its service from being used for money laundering, terrorist financing, fraud or sanctions evasion. We sell software licenses; we do not open accounts or wallets, hold customer funds, exchange currencies or crypto-assets, or transfer money to third parties.
We are not a credit or financial institution or a crypto-asset service provider. Nevertheless, our measures are based on the principles of the EU framework — the Anti-Money Laundering Regulation ((EU) 2024/1624, AMLR) and the EU AML Directives (AMLD) — in proportion to the risks of a small digital-goods seller.
2. Role of Payment Providers
Payments are accepted by our payment providers: FreeKassa (bank cards, SBP) and Card2Crypto (card payments through the provider’s partners such as Stripe or Revolut, settled in crypto). The providers and their partners carry out their own payer due diligence, transaction monitoring and sanctions screening under their own rules and may decline or hold a payment independently of us.
Crypto-asset transfers are, where applicable, subject to the Transfer of Funds Regulation ((EU) 2023/1113), which requires crypto-asset service providers to accompany transfers with originator and beneficiary information. We help providers supply such information on request.
3. Our Measures
- monitoring orders for risk indicators: unusual volume or frequency, many payment methods per buyer, inconsistent details, repeated failed payments, signs of payment methods being used without the holder’s consent;
- matching every payment event to a specific order;
- limits and additional checks for higher-risk transactions;
- refunds only to the original payment method unless separately agreed;
4. Requests for Information
In some cases we may ask you to confirm that you own the payment method and email address used, or to explain a transaction. Requests are proportionate to the risk: we do not ask for documents unnecessarily, and anything you provide is handled under our Privacy Policy.
5. Declining, Holding or Cancelling Transactions
We may decline an order, delay delivery of a key, or cancel an order and refund it if a transaction raises reasonable suspicion or requested information is not provided. Where we can, we will tell you why, unless the law or a provider’s requirements prevent it.
6. Sanctions
We do not accept payments from persons subject to EU restrictive measures (including those on the EU consolidated sanctions list) or to other sanctions regimes that apply to us or to our payment providers, and we do not carry out transactions prohibited by those regimes, including with comprehensively sanctioned jurisdictions. Providers may restrict payments from certain countries under their own rules.
7. Prohibited Conduct
- using the service to conceal the origin of funds;
- paying with stolen payment methods or ones that are not yours;
- splitting payments to evade limits or checks;
- providing false information;
- acting on behalf of sanctioned persons.
Such conduct leads to cancelled orders and terminated licenses.
8. Record Keeping
Records of orders and payment events (order number, amount, payment method, transaction identifiers, statuses, timestamps and technical data) are kept for 5 years from the order date (in line with the period used in the AMLR), unless the law requires a different period.
9. Cooperation with Providers and Authorities
We cooperate with our payment providers on compliance checks and disputed transactions, normally responding to their inquiries within 3 business days. Requests from public authorities are handled in accordance with the law after verifying their authority and legal basis.
10. Review and Contact
We review this policy as provider requirements and the law change. To report a suspicious transaction or ask a question: legal@xernel.cc — Xernel’s sole official email address.