Privacy Policy
1. Introduction
Go 2 Glory Ltd ("WhyAML", "we", "us", "our") is committed to protecting your privacy. This policy explains how we collect, use, store, and safeguard your personal data when you use the WhyAML service.
This policy applies to anyone interacting with WhyAML, including obliged-entity clients (estate agents, letting agents, tax accountants, and other regulated professionals) and the individuals being verified through the platform.
It is governed by the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025.
2. Data controller and our role
Go 2 Glory Ltd is the data controller for the operational data it holds and determines the purposes of - including the location and verification data described in Section 3 - and for client-firm account data.
When we carry out a verification at the request of a client firm (the obliged entity), that firm is a controller for its own customer due-diligence records, and WhyAML processes certain data on the firm’s behalf as a processor under a written Data Processing Agreement. The operational and location data we generate and hold to run and secure the service - which is not disclosed to the client firm - is processed by Go 2 Glory Ltd as controller.
Go 2 Glory Ltd
Registered in England & Wales · Company No. 15720361
Trading as WhyAML
Contact: [email protected]
3. Data we collect
WhyAML is engineered to minimise the personal data we hold. Because we verify that an individual controls an account at a regulated institution without collecting identity documents or biometrics, the highest-risk data categories are absent by design. We hold the following.
Identity and contact data (of the individual being verified)
- Name; declared current and previous residential address; and the claimed country of residence.
- The wallet address used to hold the Compliance Token.
Location and technical signals
These are operational data held by Go 2 Glory Ltd and are not disclosed to the client firm. They are triangulated in place and time to corroborate the residential address and claimed country of residence (relevant, among other things, to residency assessment under the Crypto-Asset Reporting Framework, which we support as one input and do not determine).
- The internet-protocol (IP) address recorded at the time of submission.
- Session and cookie signals.
- The time of your browser engagement and of the wallet connection.
- Timestamps of your own economic activity observed on the institutional rail (bank-rail or crypto-rail transaction history).
- The cryptographically signed DKIM timestamp on the institutional communication (the time at which it was sent or received).
Institutional-connection evidence
- DKIM header metadata (signature, sender domain, selector, and timestamp) extracted inside a hardware-isolated enclave from a DKIM-signed institutional communication you upload. The uploaded
.emlfile is read only inside the enclave and is deleted immediately after validation; your institutional login credentials and the body content of the communication are never held or disclosed to us or to anyone. - Metadata of an observed regulated-threshold transaction to or from the institution - an institutional due-diligence event that is observed, not requested.
Behavioural assessment (sealed)
- A behavioural assessment (the G-RADE assessment) across several dimensions, together with a behavioural archetype, is produced during verification. Other than the institutional-connection layer, this assessment is cryptographically committed (sealed) and is not disclosed to the client firm; it can be revealed and proven to a regulator or auditor only under proper authority.
Verification outcome metadata
- The verification determination (a binary outcome - verified or not), the proof level reached, the verification flow and timeline, and an obfuscated on-chain reference.
Client-firm account data
- Firm name, registered address, and Companies House number.
- Contact name, email, and role.
- Billing details.
What we do NOT collect
- No passport scans, driving licences, or other identity documents.
- No selfies, biometric data, or liveness recordings.
- No bank-statement images or proof-of-address documents.
- No institutional login credentials and no email body content.
- No verification artefacts imported from third-party DVS providers.
4. How we use your data
We use personal data only for the purposes for which it was collected:
- To provide the WhyAML verification service to obliged-entity clients.
- To establish and corroborate the institutional connection, and to corroborate the residential address and country of residence associated with a verification.
- To issue Broker Compliance Certificates and the customer-held Compliance Token.
- To maintain records for the five-year period required by the Money Laundering Regulations 2017 (Regulation 40).
- To secure the service, prevent fraud and gaming, and respond to enquiries.
- To comply with our regulatory obligations.
5. Lawful basis for processing
We process personal data on the following lawful bases under UK GDPR Article 6:
- Legal obligation (Article 6(1)(c)): processing required for our clients to discharge their AML obligations under the Money Laundering Regulations 2017.
- Legitimate interests (Article 6(1)(f)): the operation, security, and integrity of the WhyAML service, including the location and technical signals used to corroborate a verification.
- Contract (Article 6(1)(b)): the provision of services to client firms under our terms.
6. Automated decision-making
The WhyAML platform uses automated processing to produce a verification determination: the behavioural (G-RADE) assessment, the composition of the proof path, and the binary determination are generated automatically.
The determination is evidence provided to the client firm; the firm remains responsible for its own customer due-diligence decision, including any decision that produces legal or similarly significant effects for you. Where a verification does not complete, the platform requests further proof rather than making an adverse decision about you.
If you would like information about the logic involved, or wish to request human review of a determination that affects you, contact us at [email protected] or the client firm that requested your verification. We do not use your personal data for solely automated decisions producing legal or similarly significant effects without the safeguards required by Article 22 of the UK GDPR.
7. Data retention
Verification records are retained for five years after the end of the business relationship between the obliged entity and the verified customer, as required by Regulation 40 of the Money Laundering Regulations 2017.
The uploaded DKIM-signed communication (.eml file) is not retained: it is deleted immediately after validation. Location and technical signals are retained only for as long as needed to run and secure the service and to evidence the verification, and are then deleted or anonymised.
Client-firm account data is retained while the account is active and for a reasonable period afterwards for accounting and legal purposes. Where retention is no longer required, data is deleted or anonymised.
8. Data sharing
We share personal data only as set out below:
- With our service providers: hosting, infrastructure, and security suppliers, all bound by written data processing agreements.
- With the obliged-entity client: the verification determination and the Broker Compliance Certificate are made available to the firm that requested the verification. The sealed behavioural assessment and the location and technical signals are not disclosed to the firm.
- With regulators and law enforcement: where required by law, court order, or regulatory request, including disclosure of sealed material under proper authority.
We never sell your personal data and we do not share data for marketing purposes.
9. On-chain data and your right to erasure
When a verification completes, a Compliance Token is written to your own record and an obfuscated reference is recorded on-chain. The on-chain reference contains no personal data - no name, no residential address, no wallet address, no institution name, and no behavioural detail - so the immutability of the ledger does not hold your personal data and does not conflict with your right to erasure.
The personal data associated with a verification is held off-chain by Go 2 Glory Ltd and is subject to the retention and erasure provisions in this policy. The Compliance Token is held in your own self-custody and is revocable by you.
10. International transfers
Personal data is stored on infrastructure located in the United Kingdom and the European Union (an adequacy region under UK GDPR). Where data is processed outside the UK or EU, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or equivalent safeguards.
11. Your rights
Under UK GDPR and the Data (Use and Access) Act 2025, you have the right to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- request erasure, subject to our legal retention obligations;
- object to processing, or restrict processing, in certain circumstances;
- data portability;
- information about, and human review of, automated decisions that affect you (see Section 6);
- lodge a complaint with the Information Commissioner’s Office (ICO).
Because a client firm may also be a controller of its own due-diligence records, some requests - particularly those relating to the firm’s decision about you - may need to be directed to, or handled jointly with, that firm; we will help route your request. Your right to erasure is subject to our Regulation 40 retention obligations (Section 7) and does not require deletion of the immutable on-chain reference, which holds no personal data (Section 9).
To exercise any of these rights, contact us at [email protected]. We will respond within one calendar month.
12. Security
We apply security measures proportionate to the sensitivity of the data:
- Encryption at rest (AES-256 equivalent) and in transit (TLS).
- Sensitive verification operations - including reading the uploaded DKIM-signed communication and extracting only the required header fields - are performed inside hardware-isolated AWS Nitro Enclaves; the uploaded file is deleted immediately after validation.
- Strict access controls, least-privilege permissions, and audit logging.
- UK / EU-based data residency under UK GDPR adequacy.
- Independent technology audit pre-launch.
Why we hold less to begin with. The WhyAML architecture is designed so that - in the event of any breach - the data at risk is limited to name, address, wallet address, and the location and technical signals described above. We do not hold identity documents, biometric data, financial-account images, institutional credentials, or email content. The highest-severity breach categories are removed by design, not by control.
13. Cookies
We use two strictly necessary cookies to make the site work, plus optional analytics and advertising cookies that are only set if you accept them through the cookie banner. Non-essential cookies are denied by default until you consent.
Our full Cookies Policy lists every cookie we use - who sets it, what it does, and how long it lasts - including the Google Analytics, Microsoft Clarity, and Google Ads cookies.
You can change your cookie choices at any time - open your here, use the link in the footer.
14. Children’s data
The WhyAML service is provided to regulated businesses and is used to verify adults in a professional or property context. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child’s data has been provided to us, contact [email protected] and we will delete it.
15. Patent notice
The WhyAML verification methodology - including the G-RADE™ assessment engine, the multi-level proof architecture, and the location-corroboration method - is patented in the European Patent Office (EPO), the United States Patent and Trademark Office (USPTO), and under the Patent Cooperation Treaty (PCT). Zero prior art was identified at filing.
16. Contact
For any privacy enquiry, please contact us at [email protected] or use the contact form.
If you are not satisfied with our response, you may complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
Questions about how we handle your data?
[email protected]