Who owns what in the regulated stack.
OVAAL is the technology and orchestration layer. The partner's own licence owns the regulated relationship with the end-user. Authorised providers execute the regulated service. This page makes that split explicit and shows how compliance workflows are configured on top of it.
Responsibility matrix.
The same split applies to every integration: the customer holds the regulated relationship, OVAAL provides the technology and orchestration, and authorised providers execute regulated services. We agree it in writing before the first integration call.
| Activity | Customer (you) | OVAAL | Authorised provider |
|---|---|---|---|
| Regulatory permissions | Primary for your business model | Technology role unless expressly authorised | Primary for the outsourced regulated service |
| KYC / KYB policy | Policy owner | Workflow orchestration | Verification where contracted |
| AML, sanctions & Travel Rule | Programme owner under your licence | Integration and routing of the workflow | Screening and messaging where contracted |
| Safeguarding / custody | Depends on model | No, unless expressly authorised | Primary where applicable |
| Routing configuration | Oversight and commercial choices | Rules engine | Execution eligibility |
| Settlement & reconciliation | Review and finance ops | Platform record and workflow | Source confirmations |
| Support & complaints | Primary | Technical escalation | Service-specific escalation |
The DPA and MSA turn this matrix into contractual terms. Unless expressly stated, OVAAL is not a bank, payment institution, electronic-money institution or crypto-asset service provider.
Configurable compliance workflows.
OVAAL orchestrates the compliance steps; your team operates them under your own authorisation, and authorised providers run the checks. Integrations are configurable per market and per partner.
| Workflow | What OVAAL orchestrates | Executed by |
|---|---|---|
| Identity (KYC / KYB) | Onboarding flow, status, re-checks and routing | Identity-verification providers |
| AML & transaction monitoring | Screening triggers, case routing and audit trail | AML screening vendors |
| Sanctions & wallet screening | Pre-transaction checks and policy gating | Sanctions and wallet-screening vendors |
| Travel Rule | Message exchange and counterparty handling | Travel Rule providers |
| Settlement rails | Routing across eligible rails and reconciliation | Authorised providers and regulated rails partners |
This page covers who owns what. For how the orchestration is built and configured, see the risk & compliance module. We list the categories here. The specific providers we integrate with (and your options per market) are disclosed in the gated compliance pack, where contractually allowed.
Partner compliance pack.
Available to qualified partners, on request before signing, and in full on signed paperwork:
- Data Processing Agreement (DPA) template. GDPR Art. 28 and EU Transfer of Funds Regulation aware.
- Sub-processor list. Current and intended, with change-notice terms.
- Named provider options. The specific identity, AML, sanctions, Travel Rule and rails providers we integrate, per market, where contractually allowed.
- Regulatory posture summary. How deployments are designed to support authorised firms in EU and MENA markets.
- Security posture pack. See the security overview.
- Sample audit-log export. Structured format for your finance and compliance teams.
- Joint incident playbook template.
- MSA template. The commercial agreement frame.
Data protection.
- TrueThing Ltd. acts as data processor for partner data. You are the controller for your end-users.
- Legal bases: contract (the partner relationship) and legitimate interest (security and fraud prevention).
- Data-protection contact: [email protected]. Appointment detail is available to partners under NDA.
- Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tallinn. TrueThing Ltd.'s main establishment is Estonia under GDPR Art. 56.
- A GDPR Article 28 DPA is signed with every partner before production.
Legal entity.
TrueThing Ltd. (operating as "OVAAL")
- Jurisdiction: Republic of Estonia
- e-Business Register number: 12568013 (identifier EE-12568013)
- Public corporate record: ariregister.rik.ee (TrueThing OÜ). Registered office, VAT status and directors are verifiable there.
Pre-clear OVAAL with your team.
Book an architecture review and we will walk your compliance and legal stakeholders through the responsibility matrix and the integration path. The compliance pack gives your team enough to assess OVAAL before the first call.