Spoof Expert

Compliance and Requests

This document describes Spoof Expert's approach to compliance controls, event logging, and the handling of official requests from competent authorities.

1. Risk-based controls. The platform applies automated and organizational measures to detect abuse, including anomaly monitoring, review of high-risk transactions, and moderation of certain features (for example, outbound email sending).

2. What is logged. For security and investigation purposes, the following may be recorded: authentication and sessions, actions in the interface, service operations, technical request parameters, account setting changes, moderation decisions, errors, and system events.

3. Purposes of logging. Logs are used to prevent fraud, spam, threats, and other unlawful actions, to protect users and infrastructure, and to establish facts when reviewing incidents and disputes.

4. Measures in response to violations. Upon detecting unlawful activity or high compliance risk, the platform may issue a warning, restrict functionality, temporarily freeze operations, block individual tools, or fully block the account.

5. Grounds for disclosure of information. Information is provided only where there is a proper legal basis: an official request, a demand from an authorized body, a court order, or another form provided for by applicable law.

6. Verification of government requests. Each request is verified for the applicant's authority, its subject matter, scope, and legal validity. In the absence of lawful grounds, a request may be denied, limited, or returned for clarification.

7. Principle of minimum sufficiency. We disclose only the amount of data necessary to comply with a lawful request and do not disclose information beyond the required subject matter.

8. Chain of custody. Material compliance actions and data transfers are recorded in an internal log to confirm the integrity and traceability of processing.

9. Confidentiality and limitations. Information is not transferred to third parties outside of lawful procedures. Access to data within the platform is granted on a need-to-know basis and with role separation.

10. Retention periods. Compliance logs and related materials are retained for the period necessary for security, fulfillment of legal obligations, and protection of the platform's rights, after which they are deleted or archived in accordance with internal regulations and the law.

11. User cooperation. The user is obligated to provide accurate information and not to obstruct checks in cases where this is required by the platform's rules and the law.

12. Policy updates. The platform reserves the right to amend this document. The current version takes effect upon publication on the site, unless a different date is separately specified.