Last updated: 21 August 2026

AML / Compliance Policy

E-STEPS s.r.o.

1. Purpose

1.1 This Policy establishes the Company's internal compliance principles for preventing the misuse of its Services for money laundering or terrorist financing and for managing compliance risks arising from its activities. 1.2 The Policy is applied according to the actual nature, scope and manner of the Company's activities and applicable law.

2. Definitions

"Company" means E-STEPS s.r.o. "Client" means any natural or legal person using or requesting the Company's Services. "Licensed Provider" means an appropriately authorised professional, regulated entity or service provider to which the Company introduces or refers a Client, including in connection with company formation or with the opening of a bank or payment account. "AML/CFT" means anti-money laundering and counter-terrorist financing. "PEP" means a politically exposed person within the meaning of applicable AML legislation. "AML Act" means Act No. 253/2008 Coll., on Certain Measures against the Legalisation of Proceeds of Crime and Financing of Terrorism, as amended.

3. Regulatory Status

3.1 The Company acts as an intermediary in connection with certain company-formation services and, where applicable, in connection with the opening of a bank or payment account by the Client with a Licensed Provider. 3.2 The Company introduces Clients to Licensed Providers who provide the relevant regulated or professional services. 3.3 The Client pays the Licensed Provider directly for the underlying regulated or professional service where applicable. 3.4 The Company does not itself provide regulated legal, notarial, tax, banking, payment, investment or insurance services requiring a specific authorisation. 3.5 The Company does not hold Client funds or assets as part of its ordinary intermediary activities. 3.6 The Company's AML status depends on the actual nature and manner of its activities and the applicable provisions of the AML Act. The Company shall not rely solely on contractual descriptions when determining whether a particular activity falls within the scope of the AML Act. 3.7 Where a Client requests assistance in connection with the opening of a bank or payment account, the Company's role is limited to introducing the Client to a Licensed Provider (a bank, payment institution or similar regulated entity) and providing administrative and coordination support. The decision whether to open the account, and all matters relating to its operation and ongoing compliance, rest solely with the relevant Licensed Provider.

4. Internal AML Regulatory Status Assessment

4.1 The Company has prepared an internal document entitled "AML Regulatory Status Assessment — E-STEPS s.r.o." 4.2 Based on that internal assessment and the Company's activities as assessed at the relevant date, the Company has determined that, within the scope and manner of activities covered by the assessment, it does not currently fall within the category of an obliged entity under Section 2 of the AML Act. 4.3 This assessment is based on the Company's actual activities and operating model and does not constitute a general exemption from the AML Act. 4.4 The internal assessment forms part of the Company's internal compliance documentation and is not intended for publication on the Website. 4.5 The Company shall reassess its status whenever its activities, business model or manner of operation materially changes. The AML Act defines the categories of obliged entities in Section

5. Risk-Based Approach

5.1 The Company applies a proportionate, risk-based approach to compliance. 5.2 The level of due diligence and monitoring shall depend on the nature, scale and assessed risk of the relevant relationship, service or transaction.

6. Client Identification and Due Diligence

6.1 Where legally required or reasonably necessary for compliance purposes, the Company may request information necessary to identify the Client. 6.2 Such information may include: identity information; representative information; beneficial ownership information; ownership and control structure; and information concerning the purpose and intended nature of the relationship. 6.3 The Company may refuse to proceed where required information has not been provided or cannot reasonably be verified.

7. Beneficial Ownership

7.1 Where applicable, the Company shall obtain and verify beneficial ownership information to the extent required by law and proportionate to the assessed risk. the assessed risk.

8. Enhanced Due Diligence

8.1 Where a relationship presents increased compliance risk, the Company may apply enhanced due diligence measures. 8.2 Higher-risk circumstances may include: (a) involvement of a PEP; (b) connection with a jurisdiction identified as high-risk under applicable law; or (c) unusually complex, unusual or economically unexplained circumstances. 8.3 Enhanced measures may include requesting additional information concerning ownership, purpose, source of funds or source of wealth where legally relevant.

9. PEP and Sanctions Screening

9.1 Where appropriate, the Company may conduct PEP and sanctions screening using publicly available and reasonably accessible official or reputable sources. 9.2 The scope and frequency of screening shall be proportionate to the assessed risk. 9.3 The Company does not represent that it operates an automated or continuous real-time screening system unless such a system has actually been implemented.

10. Suspicious Activity

10.1 Where the Company identifies circumstances giving rise to a genuine suspicion of money laundering or terrorist financing, it shall comply with applicable reporting obligations to the extent those obligations apply to the relevant activity. 10.2 Where the Company is not subject to a statutory reporting obligation, it may take other lawful compliance measures. 10.3 Where legally applicable, the Company and persons acting on its behalf shall not disclose information in circumstances where disclosure would constitute prohibited tipping-off.

11. Refusal, Suspension and Termination

The Company may refuse, suspend or terminate Services where: (a) required identification information is not provided; (b) information cannot reasonably be verified; (c) applicable law requires refusal or suspension; or (d) continuing the relationship would create an unacceptable compliance risk.

12. Data Protection

12.1 Personal data processed for compliance purposes shall be processed in accordance with applicable data-protection law and the Company's Privacy Policy. 12.2 Personal data shall not be processed for unrelated purposes without an appropriate legal basis.

13. Confidentiality

13.1 Compliance information shall be treated as confidential. 13.2 Information may be disclosed where required or permitted by law, including to competent authorities. 13.3 Nothing in this Article restricts a statutory reporting obligation.

14. Records

14.1 Compliance records shall be retained for as long as reasonably necessary for the relevant compliance purpose. 14.2 Where a statutory retention obligation applies, records shall be retained for the period required by law.

15. Responsible Person

15.1 The Managing Director has internal responsibility for oversight and day-to-day implementation of this Policy. 15.2 This internal organisational arrangement does not, by itself, constitute an acknowledgement that the Company is an obliged entity under the AML Act. 15.3 Where the AML Act imposes specific statutory requirements on an obliged entity concerning a responsible person or AML officer, those requirements shall be assessed separately and complied with to the extent applicable.

16. Review and Amendments

16.1 This Policy shall be reviewed periodically. 16.2 The Company shall review the Policy whenever there is a material change in: the Company's activities; its business model; the nature of its Services; applicable legislation; its compliance risk profile; or relevant regulatory guidance. 16.3 Nothing in this Policy waives or limits any obligation imposed on the Company by mandatory law.

17. Approval

Approved by: Managing Director, E-STEPS s.r.o. Effective date: 21 August 2026 Last updated: 21 August 2026

Need assistance?

Our team is here to help you with any questions about your privacy or data.

Contact us →