Swipelux
Compliance

Governance and Roles

Liability and responsibility matrix for Swipelux and sub-merchants

Governance and Roles

Liability Matrix

ResponsibilitySwipelux (VASP)Sub-Merchant
Crypto Custody100% ResponsibleNot-allow
Blockchain Execution100% ResponsibleNot-allow
User Verification (KYC)Responsible (Direct or Reliance)Responsible for UX Handoff
Sanctions ScreeningResponsible (All Users)Responsible for own staff
GeoblockingEnforces via IP/KYCMust implement at UI level
LicensingVASP License onlySector License (e.g., Gaming)

Responsibility Matrix

  • Swipelux: custody, blockchain execution, KYC/KYB, monitoring, Travel Rule, sanctions
  • Sub-merchant: user journey design, geoblocking, vertical licensing, marketing compliance, prevention of unsolicited US targeting

Swipelux is the only regulated crypto custodian in the flow. Sub-merchants never hold, control, or access user assets or private keys.

Auditability & Retention

Swipelux retains user identity and transactional data for 5 years, as required under EU AML laws and Estonia's MLTFPA.

Data subject deletion requests do not apply to AML-mandated records.

Swipelux stores all data within compliant EU infrastructure aligned with GDPR.

On this page