Anti-Money Laundering Policy
Last updated: [TBD] · This is a working draft pending legal review.
1. Purpose and Scope
This Anti-Money Laundering Policy (the "Policy") sets out the framework Coded B.V. ("Coded", "we", "us") applies to deter, detect, and respond to money laundering, terrorist financing, sanctions evasion, and related financial crime across its commerce platform (the "Platform").
The Platform lets a merchant operate one or more branded online shops and other projects under an Organization account, using a curated product catalog, built-in payments, and built-in fulfilment. This Policy applies to all Organizations, merchants, and authorized users that access or use the Platform, regardless of the country in which they are established or operate.
Coded is an international company. While Coded B.V. is registered in the Netherlands and the Netherlands is its initial launch market, the Platform serves merchants worldwide. This Policy is written as a single global framework intended to satisfy Dutch and EU anti-money laundering and counter-terrorist-financing ("AML/CTF") expectations and to align with comparable obligations in other jurisdictions where merchants operate. Where the mandatory law of a merchant's own jurisdiction imposes stricter or additional requirements, those requirements also apply to that merchant.
1.1 Relationship to other documents
This Policy works alongside Coded's Terms of Service, Acceptable Use Policy, Privacy Policy, and Sanctions and Restricted Activities standards. Where this Policy conflicts with the Terms of Service on a financial-crime matter, this Policy controls for that matter.
2. Coded's Regulatory Position
Coded is a software and commerce platform. Coded is not a bank, payment institution, electronic money institution, money services business, or other regulated financial institution, and does not hold, transmit, or take custody of merchant or customer funds.
Payment transactions on the Platform are processed by regulated third-party payment service providers — currently Stripe and Mollie (each a "Processor") — under the Processor's own regulatory licenses and direct contractual relationship with the merchant. The Processors perform the regulated payment functions, including merchant onboarding checks, identity verification, transaction settlement, and the AML/CTF controls required of a licensed payment institution.
Because Coded does not itself move or hold funds, certain AML/CTF obligations that apply to a payment institution do not apply to Coded in the same form. Coded nonetheless maintains this Policy as a matter of responsible operation and to support the integrity of the Platform, to honor its contractual commitments to its Processors, and to comply with any AML/CTF obligations that do apply to it directly. Coded relies on the Processors' regulated due diligence and monitoring where appropriate (see Section 8), but reliance does not relieve Coded of its own internal controls described here.
2.1 0% platform fee
Coded charges no platform fee on a merchant's payment transactions. Merchants pay only the pass-through processing cost charged by the Processor. Coded's commercial relationship with a merchant is based on separate subscription fees for publishing projects and is not transaction-volume-based. This Policy is not affected by Coded's fee model and applies regardless of payment volume.
3. Definitions
- Money laundering — the process of disguising the origin of criminally derived property so that it appears legitimate.
- Terrorist financing — the provision or collection of funds intended to be used for terrorist acts or by terrorist organizations.
- Customer due diligence (CDD) — measures to identify and verify a customer and understand the nature and purpose of the relationship.
- Enhanced due diligence (EDD) — additional CDD measures applied to higher-risk relationships.
- Beneficial owner — the natural person(s) who ultimately own or control a merchant entity.
- Politically exposed person (PEP) — an individual entrusted with a prominent public function, and their family members and close associates.
- Sanctions — restrictive measures imposed by competent authorities against named persons, entities, jurisdictions, or activities.
- Processor — a regulated third-party payment service provider integrated with the Platform (currently Stripe and Mollie).
- Suspicious activity — conduct or a transaction that gives rise to a reasonable suspicion of money laundering, terrorist financing, fraud, or sanctions evasion.
4. Governance and Responsibility
Coded maintains a designated person responsible for AML/CTF matters (the "AML Officer") with authority to escalate concerns, suspend or restrict accounts, and make reports to or coordinate with competent authorities and Processors.
The AML Officer is responsible for:
- maintaining and periodically reviewing this Policy and the underlying risk assessment;
- overseeing the controls in Sections 5 through 10;
- handling internal escalations of suspicious activity;
- coordinating with Processors on financial-crime matters; and
- maintaining staff awareness and training appropriate to roles.
Coded's management is accountable for ensuring the AML function has the resources and independence needed to operate effectively. AML/CTF responsibilities are documented and assigned to specific roles rather than left informal.
5. Risk-Based Approach
Coded applies a risk-based approach. Controls are calibrated to the assessed level of financial-crime risk so that higher-risk relationships and activities receive more scrutiny and resources, and lower-risk relationships are not subjected to disproportionate friction.
Coded maintains a documented financial-crime risk assessment that is reviewed periodically and after material changes to the Platform, product set, geographic footprint, or threat environment. The assessment considers at least the following risk factors:
- Merchant risk — entity type, ownership and control structure, beneficial owners, presence of PEPs, adverse media, and prior account history.
- Product and channel risk — the nature of goods sold, average and peak transaction values, refund and chargeback patterns, and the use of multiple projects under one Organization.
- Geographic risk — the countries in which the merchant is established, sells, ships, or receives settlement, with particular attention to jurisdictions subject to sanctions or identified as higher risk by competent international bodies.
- Transaction risk — velocity, structuring patterns, mismatch between stated business and actual activity, and unusual payment or fulfilment flows.
The output of the risk assessment determines whether standard or enhanced measures apply to a given relationship.
6. Merchant Onboarding and Due Diligence
6.1 Layered due diligence
Merchant due diligence on the Platform is layered. The regulated identity verification and KYC/KYB checks required to accept payments are performed by the Processor as part of the merchant's payment-account setup. Coded performs platform-level due diligence appropriate to its role as the software and commerce provider, and does not duplicate the Processor's regulated checks where reliance is appropriate (see Section 8).
6.2 Platform-level checks
Before and during a merchant relationship, Coded may collect and verify information sufficient to understand who the merchant is and what they intend to sell, including:
- Organization and legal-entity name, registration details where applicable, and registered or business address;
- the identity of the individuals who control the Organization account and, where relevant, beneficial owners;
- the nature of the projects to be operated and the categories of goods to be sold;
- contact details and, where required, confirmation of the merchant's acceptance of the Terms of Service and Acceptable Use Policy.
Coded may decline to onboard, or may suspend or terminate, any merchant that does not provide requested information, that operates a prohibited or restricted activity, or that presents an unacceptable financial-crime risk.
6.3 Enhanced due diligence
Where the risk assessment indicates higher risk — for example, a merchant connected to a higher-risk jurisdiction, an identified PEP, an opaque ownership structure, adverse media, or activity inconsistent with the stated business — Coded applies enhanced measures. These may include additional information requests, senior-level review before activation or continuation, closer ongoing monitoring, and coordination with the relevant Processor.
7. Ongoing Monitoring
Coded monitors Platform activity on a risk-sensitive basis to identify behavior that is inconsistent with a merchant's expected profile or that suggests financial crime. Monitoring signals may include unusual transaction velocity or value, patterns consistent with structuring, abnormal refund or chargeback behavior, mismatches between catalog/fulfilment activity and payment flows, and the creation of multiple projects to obscure activity.
Regulated transaction monitoring at the payment level is performed by the Processors. Coded's monitoring is complementary and focuses on platform-level signals. Where monitoring raises concern, the matter is escalated to the AML Officer for review and, where appropriate, action under Sections 9 and 10.
8. Sanctions Screening
Coded supports compliance with applicable sanctions regimes. Sanctions screening of payment counterparties and merchant payment accounts is performed by the Processors as part of their regulated obligations, including screening against applicable consolidated sanctions lists.
At the platform level, Coded does not knowingly onboard or provide services to any person, entity, or jurisdiction that is the target of applicable sanctions, and reserves the right to screen Organizations, merchants, and associated individuals against relevant sanctions and watch lists and to restrict, suspend, or terminate access where a match or credible concern arises. Sanctions controls are applied on an ongoing basis, not only at onboarding. Coded will act on instructions and findings communicated by its Processors in respect of sanctioned parties.
9. Reliance on Processor Due Diligence
Coded relies on the regulated KYC/KYB, sanctions screening, and transaction-monitoring functions performed by its Processors where it is appropriate and permitted to do so. This reliance is governed by Coded's contracts with each Processor and reflects that the Processor — not Coded — performs the regulated payment functions and holds the corresponding license.
Reliance is subject to the following principles:
- Reliance does not transfer or extinguish Coded's own obligations under this Policy or under any law that applies to Coded directly.
- Coded does not knowingly rely on a Processor's checks where it has information suggesting those checks are inadequate or have been circumvented.
- Coded cooperates with Processors on information requests, account reviews, and remediation, and may suspend or restrict a merchant on the Platform where a Processor declines, restricts, or terminates that merchant's payment account.
10. Suspicious Activity Handling
Any employee or contractor who identifies activity that may indicate money laundering, terrorist financing, sanctions evasion, or related financial crime must escalate it promptly to the AML Officer through the internal escalation path. Escalation is mandatory and must not be discussed with the merchant or any third party in a way that could amount to "tipping off".
On escalation, the AML Officer assesses the matter and determines an appropriate response, which may include requesting further information, applying enhanced monitoring, restricting or suspending the relevant Organization or project, terminating the relationship, notifying the relevant Processor, and — where a legal reporting obligation applies — making or supporting a report of unusual or suspicious activity to the competent financial intelligence unit.
Because the Processors hold the regulated payment relationship, regulated suspicious-transaction reporting in respect of payment activity is generally made by the Processor. Where Coded is itself subject to a reporting obligation, it complies with that obligation directly and does not rely on the Processor to discharge it. Coded does not disclose the existence or content of any report to the subject of that report except as permitted by law.
11. Record-Keeping
Coded retains the records it creates or holds in connection with this Policy — including merchant onboarding information, risk-assessment outputs, monitoring escalations, sanctions concerns, and decisions to restrict or terminate — for the period required by applicable law and, absent a specific legal period, for a reasonable period proportionate to the financial-crime risk and limitation considerations.
Records are stored securely and processed in accordance with Coded's Privacy Policy and the principle of data minimization. Platform data is hosted in the European Union (Frankfurt, Germany), which provides a strong, EU-based data-protection environment for the personal data processed under this Policy. Access to AML/CTF records is restricted to personnel with a legitimate need.
12. Training and Awareness
Coded provides AML/CTF awareness appropriate to each role so that staff who interact with merchant accounts, payments, or escalations can recognize and report red flags. The AML Officer maintains awareness of relevant legal and regulatory developments and updates this Policy and the underlying controls accordingly.
13. Cooperation with Authorities and Processors
Coded cooperates with competent supervisory authorities, financial intelligence units, law-enforcement bodies, and its Processors in connection with the prevention and detection of financial crime, to the extent permitted and required by applicable law. Coded may suspend or terminate access, freeze affected accounts pending review, and take other proportionate measures to protect the integrity of the Platform.
14. Changes to this Policy
Coded may update this Policy from time to time to reflect changes in law, regulatory guidance, the Platform, or its Processors. The current version is published on Coded's website and applies from its stated effective date. Material changes will be communicated through the Platform or by other reasonable means.
This Policy is effective from 11 June 2026.
15. Governing Law and Jurisdiction
This Policy is governed by the laws of the Netherlands. The courts of Amsterdam, the Netherlands, have jurisdiction over disputes arising out of or in connection with this Policy. This does not deprive a merchant or user of the protection of mandatory provisions of the law of their own jurisdiction, including mandatory consumer-protection and data-protection law, which may also apply.
Contact
Questions about this Policy or about a financial-crime concern can be directed to Coded's AML function:
- AML / Legal: legal@coded.eu
- Security concerns: security@coded.co
Coded B.V. De Taling 15, 2761 SL Zevenhuizen, The Netherlands Chamber of Commerce (KvK): 42027097 VAT: NL869368795B01
<!-- OPEN ITEMS FOR COUNSEL: 1. Confirm whether Coded B.V. is in fact out of scope as a Wwft "institution" given its platform-only, no-funds-custody role, and whether any Coded activity (e.g. subscription billing, fulfilment intermediation) pulls it into direct AML scope in NL or any other launch market. 2. Confirm the legal basis and conditions for "reliance" on Stripe/Mollie KYC under Wwft and equivalent regimes — true third-party reliance vs. outsourcing vs. simply not being a reporting entity. Wording in Sections 2, 8, 9, 10 depends on this. 3. Confirm whether Coded must appoint a formal AML/compliance officer and whether the generic "AML Officer" designation here is sufficient or needs a named, registered function. 4. Verify suspicious/unusual activity reporting trigger and channel — FIU-Nederland reporting obligation applies to Coded directly or only to the Processors? Tipping-off provisions wording to be confirmed. 5. Confirm sanctions screening obligations on Coded directly (Sanctiewet 1977 / EU consolidated list) vs. fully delegable to Processors. 6. Confirm record-keeping retention periods — set concrete durations (e.g. 5 years) once direct obligations are confirmed; current "reasonable period" language is a placeholder. 7. Confirm international framing is accurate — that one global policy with NL governing law plus mandatory-local-law carve-out is defensible across US state regimes and other launch markets; verify no jurisdiction requires a separate registered AML program. 8. Confirm Coded's actual contractual AML obligations to Stripe and Mollie and align Sections 9/10 with those agreements. 9. Confirm placeholder facts: KvK number, VAT number, registered address, effective date, and contact domain (coded.eu (legal/privacy) · coded.co (ops)). 10. Confirm we make no implied regulatory-license or certification claims anywhere in this document. -->