Terms &
Conditions
These terms govern your use of the AlgoVoi browser extension and all services operated under algovoi.co.uk, including payment gateway APIs, MCP servers, and ecommerce platform adapters.
Last updated: 26 April 2026 · Version 1.5
1. Acceptance of Terms
By installing the AlgoVoi browser extension, accessing any algovoi.co.uk service, or integrating any AlgoVoi-Hand payment adapter, you agree to be bound by these Terms and Conditions in full.
If you do not agree to these terms, you must not use any AlgoVoi or algovoi.co.uk service. Continued use following any update to these terms constitutes acceptance of the revised terms.
These terms apply to all users including individuals, merchants, developers, and automated agents acting on behalf of a user.
2. Services Covered
These terms apply to all of the following:
- AlgoVoi Browser Extension — Chrome and Firefox wallet extension for Algorand and Voi networks
- AlgoVoi-Hand Payment Gateway — x402, MPP, and AP2 payment protocol infrastructure (api.algovoi.co.uk)
- Payment Gateway API — Ecommerce platform adapters and tenant management (api.algovoi.co.uk)
- UluMCP Server — AI agent MCP tool server (mcp.algovoi.co.uk)
- algovoi.co.uk websites — All pages, documentation, and web properties
- AlgoVoi Cloud — Hosted merchant dashboard and KYC onboarding portal (
cloud.algovoi.co.uk/dash.algovoi.co.uk) - A2A Agent Protocol — Google A2A v0.3 agent skills for AI-to-AI payment orchestration (
api.algovoi.co.uk) - Platform Adapters — WooCommerce, OpenCart, PrestaShop, Shopware, and native language adapters
3. Permitted Use
You may use AlgoVoi and algovoi.co.uk services for lawful purposes only, including:
- Managing and transacting with your own cryptocurrency wallets
- Integrating payment functionality into legitimate ecommerce platforms
- Building and operating lawful AI agent applications via the MCP server
- Development and testing of payment protocol integrations
- Personal, non-commercial use of the AlgoVoi extension under the BSL licence
Commercial use of the AlgoVoi source code requires a separate commercial licence from the copyright holder. See Section 7.
Age and capacity: By using these services you confirm that you are at least 18 years of age and have full legal capacity to enter into a binding agreement. Use by persons under 18 is strictly prohibited.
Sanctions representation: By using these services you represent and warrant that you are not (i) located in, or a resident of, any country subject to UK, EU, or US sanctions; (ii) listed on any sanctions list maintained by HM Treasury (OFSI), OFAC, or the EU; and (iii) acting on behalf of any sanctioned person or entity. Access from sanctioned jurisdictions is prohibited. Wallet addresses are screened against live sanctions databases on every transaction — access will be denied automatically and without explanation in the event of a match.
4. Prohibited Use
The following activities are strictly prohibited and will result in immediate termination of access, reporting to relevant authorities, and potential legal action.
Illegal activity — zero tolerance:
- Any use that violates applicable local, national, or international law
- Money laundering, terrorist financing, or sanctions evasion
- Fraud, theft, or unauthorised access to third-party accounts or funds
- Drug trafficking, weapons dealing, or trade in illegal goods or services
- Child sexual abuse material or any content that exploits or harms minors
- Ransomware, malware distribution, or any form of cyberattack
- Market manipulation, wash trading, or cryptocurrency fraud
- Operating unlicensed financial services or unregistered securities offerings
- Identity theft or impersonation of individuals or organisations
- Human trafficking or exploitation
Technical misuse:
- Attempting to circumvent authentication, payment verification, sanctions screening, or access controls
- Reverse engineering, decompiling, or extracting proprietary server-side logic
- Automated scraping, denial-of-service attacks, or abuse of rate limits
- Injecting malicious instructions into AI agent sessions (prompt injection attacks)
- Using the platform to relay, obscure, or launder proceeds of crime
- Reselling or sublicensing API access without authorisation
5. Law Enforcement Cooperation
AlgoVoi and algovoi.co.uk will cooperate fully with any lawful request from law enforcement, regulatory authorities, or courts of competent jurisdiction, to the extent permitted by applicable law including UK GDPR.
This cooperation includes but is not limited to:
- Providing access logs, transaction records, IP addresses, and user data in response to valid legal process (court order, warrant, or equivalent)
- Preserving data upon receipt of a lawful preservation request
- Suspending or terminating accounts under investigation
- Proactively filing Suspicious Activity Reports (SARs) with the UK Financial Intelligence Unit (UKFIU) via SARs Online where required under the Proceeds of Crime Act 2002 s.330 and UK Money Laundering Regulations 2017
- Assisting with forensic investigations into fraud, cyberattacks, or financial crime involving our infrastructure
- Responding to requests from the Financial Conduct Authority, HM Treasury, OFSI, and other UK regulatory bodies
Money Laundering Reporting Officer (MLRO): We have designated a Money Laundering Reporting Officer responsible for overseeing our AML/CTF programme, reviewing escalated compliance events, and making SAR filing decisions. See Section 16 for MLRO contact details.
Tipping-off prohibition: Under SAMLA 2018 s.20 and PoCA 2002, we are legally prohibited from disclosing to any person that a SAR has been filed or that a sanctions investigation is under way. Generic error responses are returned in place of specific explanations in such circumstances.
Blockchain transparency: All on-chain transactions processed via AlgoVoi and the payment gateway are permanently recorded on public blockchains (Algorand, Voi, Hedera, Stellar). These records are immutable, publicly auditable, and available to law enforcement without any request to us. There is no anonymity guarantee for on-chain activity.
No safe harbour for illegal use: The non-custodial nature of the AlgoVoi wallet does not confer any protection against legal accountability. Users are solely responsible for the lawful use of their wallets and any transactions they execute.
6. AML / KYB Requirements for Merchants
Merchants and individuals accessing AlgoVoi services in live mode are subject to the following obligations under the UK Money Laundering Regulations 2017 (MLRs), SAMLA 2018, and related legislation.
Know Your Customer (KYC) — Individual & Sole Trader Accounts:
- Individuals and sole traders onboarding via
cloud.algovoi.co.ukmust complete a KYC document submission before accessing live payments - Required documents: government-issued photo ID, selfie, proof of address, and source of funds declaration. Sole traders must additionally provide a business registration document
- Documents are automatically accepted and verified upon upload. Once all required documents are submitted, the account is automatically approved without manual MLRO review — subject to our automated risk assessment
- We reserve the right to suspend automatic approval and revert to manual review for any account where risk indicators are present
- KYC documents are retained for a minimum of 5 years after the relationship ends, as required by MLRs Reg 40
Know Your Business (KYB) — Company Accounts:
- Simplified CDD (trial accounts): Before processing any mainnet payment during the trial period, merchants must provide their business name, country of incorporation, and primary contact name. This is required under UK MLRs 2017 Reg 37 and is enforced automatically at the payment gateway
- Full KYB (live mode): All company merchants must complete full KYB document verification before accessing live mode. KYB requires submission of business identity documents appropriate to the merchant's legal entity type
- Required documents for UK limited companies include: Certificate of Incorporation, Proof of Business Address, PSC / UBO Register, Director Passport or equivalent ID, and Source of Funds declaration
- Documents are reviewed by our MLRO. KYB approval is at our sole discretion
- We reserve the right to request additional documents, conduct enhanced due diligence, or decline onboarding without providing a reason, in accordance with our risk-based approach under MLRs Reg 18
- Merchant identity documents are retained for a minimum of 5 years after the business relationship ends, as required by MLRs Reg 40
Risk tiers:
- Each merchant account is assigned a risk tier (
low,medium,high, orrestricted) based on our ongoing risk assessment - Risk tier affects daily transaction volume caps. High-risk accounts are subject to reduced caps; restricted accounts cannot process live payments
- Risk tier may be adjusted at any time without notice if our assessment changes
Sanctions screening:
- All payer wallet addresses are screened against live sanctions databases (OFSI, OFAC SDN, EU Consolidated) on every payment in real time
- Merchant wallet addresses are screened at KYB approval and following any material change to the account
- Payments from sanctioned wallet addresses will be blocked automatically. Merchants will not be notified of the specific reason for a payment failure in order to comply with tipping-off provisions
- Sanctions data is refreshed daily from official public feeds
Transaction monitoring:
- All payment activity is subject to automated transaction monitoring rules designed to detect money laundering, terrorist financing, and fraud indicators
- Unusual activity may result in: an alert to our compliance team, an AML hold placed on the payment record, escalation to the MLRO, or temporary suspension of the merchant account pending review
- Merchants are obligated to maintain their own AML/CTF compliance programme appropriate to their business and jurisdiction
Ongoing monitoring:
- We conduct ongoing due diligence on merchant accounts as required by MLRs Reg 28(12)
- Merchants must promptly notify us of any material change to their business, beneficial ownership, or legal structure
- We reserve the right to conduct enhanced due diligence reviews at any time without notice
7. Software Licence
The AlgoVoi browser extension source code is licensed under the Business Source Licence 1.1 (BSL 1.1).
- Copyright: © 2026 Christopher Hopley — algovoi.co.uk
- Personal non-commercial use: Freely permitted
- Commercial use: Requires a separate licence from the copyright holder
- Change Date: 7 April 2030 — on this date the licence converts to MIT
- Forks and derivatives: Must carry the same BSL licence and copyright notice
The MCP server, payment gateway APIs, and platform adapters are proprietary. No licence is granted to copy, modify, or redistribute server-side code without explicit written permission from the copyright holder.
For commercial licensing enquiries contact: [email protected]
8. Payment Services
AlgoVoi-Hand operates as a non-custodial on-chain payment gateway. The following conditions apply:
- All payments are executed on public blockchains and are irreversible once confirmed on-chain
- AlgoVoi-Hand does not hold, pool, or custody any fiat or cryptocurrency funds
- Merchants are responsible for verifying payment receipt via webhook or API status check
- We are not liable for failed, delayed, or misdirected transactions resulting from incorrect wallet addresses or network congestion
- Merchants using the payment gateway must comply with all applicable laws in their jurisdiction including tax obligations and consumer protection requirements
- Test mode transactions use testnet only — no real funds are moved
- Payments may be declined or blocked at any time without notice where required by our AML/CTF obligations, sanctions screening results, or risk management policies. No reason will be provided where disclosure would breach tipping-off provisions
8.1 Outbound Notifications & Webhooks
Merchants may configure outbound notification destinations from the dashboard at dash.algovoi.co.uk/connect. Currently supported: Slack, Discord, Microsoft Teams, Mattermost, Rocket.Chat, Google Chat, Zulip, Telegram, and a generic HTTPS webhook destination. The following conditions apply to all outbound notifications:
- Event triggers: Notifications are dispatched on the
payment.confirmedevent after on-chain settlement is verified. Additional event types may be added without prior notice; merchants can opt in or out of any event from the dashboard - Payload integrity: Every outbound POST carries an
X-AlgoVoi-Signatureheader containing a Stripe-style timestamp and HMAC-SHA256 of{timestamp}.{raw_body}, signed with a per-destination secret. Merchants should verify this signature on the receiving end and reject requests where the timestamp is more than five minutes old to prevent replay attacks - Signing secret: A unique
algvw_*signing secret is generated when a destination is connected and shown once in the dashboard. Merchants are responsible for storing the secret securely. The secret can be rotated at any time from the dashboard, which immediately invalidates the previous secret - Retry policy: Failed deliveries are retried automatically with exponential backoff (30 seconds → 2 minutes → 10 minutes → 1 hour → 6 hours → dead-letter), up to six attempts over approximately 32 hours. Merchants can manually retry any delivery from the dashboard at
dash.algovoi.co.uk/notifications - Audit log: Every dispatch attempt is recorded in the merchant's account with the destination, status (pending / delivered / failed), HTTP status code, error message, and a payload preview. Audit log entries are retained for 90 days under our standard log retention policy, or 5 years where the related payment is subject to an AML hold
- Receiver responsibilities: Merchants are solely responsible for the security, availability, and correctness of any URL they configure as a notification destination. AlgoVoi-Hand makes no warranty that a notification will be delivered, processed, or persisted by the receiving system; the on-chain settlement is the canonical record of payment
- Third-party platforms: Where a destination is a third-party platform (Slack, Discord, Microsoft Teams, etc.), the merchant is responsible for compliance with that platform's own terms of service. AlgoVoi-Hand is not affiliated with any third-party platform and provides no warranty of compatibility, uptime, or feature parity
- Data transmitted: Outbound notifications include payment metadata (chain, asset, amount, transaction ID, payer address, resource ID, optional tenant label). They do not include personal data of customers beyond a truncated on-chain wallet address. Merchants who configure receiving systems handling personal data are responsible for their own UK GDPR / data protection obligations
- Discontinuation: AlgoVoi-Hand may add, modify, or discontinue support for any destination type with reasonable notice. Existing destinations of a discontinued type will continue to operate until the merchant disconnects them or the destination provider becomes unavailable
9. Fees & Pricing
Simple, transparent pricing. No monthly subscription, no hidden charges. You only pay when you earn — a single percentage fee on verified payments.
Trial period:
- New merchants receive a 60-day free trial on testnet. Testnet access is granted immediately on wallet signup — no identity verification or platform fees required during this period
- Mainnet payments require completed identity verification:
- Individuals / sole-traders: auto-approved via document and selfie ID check (typically completes within minutes)
- Companies: KYB document review by our MLRO (typically approved within 1 business day)
- Once verified, merchants receive a $1,000 free mainnet allowance (USD equivalent at current market price). This is a single dollar budget shared across all 7 supported chains (Algorand, VOI, Hedera, Stellar, Base, Solana, Tempo) and across every AlgoVoi channel (hosted checkout, e-commerce adapters, chat bots, MCP, A2A, x402, MPP, AP2)
- No platform fees are charged on payments processed within this $1,000 mainnet allowance. Merchants keep 100% of these payments (less network gas, paid by the payer)
- The standard 0.50% platform fee applies automatically once the merchant's cumulative mainnet volume exceeds $1,000. The transition is instant and requires no action by the merchant — fees begin being deducted at settlement on the next payment
- Self-payments — where the payer wallet matches the merchant's payout wallet — are not eligible for the free allowance and are rejected at the gateway. A minimum payment value of $1.00 USD equivalent applies during the free allowance to prevent automated micro-payment exhaustion of the trial budget
- The free mainnet allowance is non-transferable, expires when the merchant's account is closed, and may be reduced or suspended if abuse is detected
Paid plan (after trial):
- Platform fee: 0.50% (50 basis points) per verified payment
- The fee is deducted from the merchant's settlement — customers pay the listed price with no surcharge
- Fees are collected atomically at settlement via an on-chain multi-output transaction (atomic group on Algorand/Voi, multi-party CryptoTransfer on Hedera, multi-operation transaction on Stellar, ERC-20 multi-call on Base/Tempo)
- No monthly minimums, no setup fees, no cancellation fees
- High-volume tiers (documented for transparency, applied on request when sustained volume thresholds are met): $10K–$100K/month at 0.40%, $100K+/month at 0.30% or by negotiation
Fee transparency:
- The current fee rate is included in every 402 payment challenge (
extra.feeBps) - All fee transactions are recorded in a tamper-proof on-chain audit trail alongside the merchant payment
- Merchants can view fee history and totals via the billing API and operator dashboard
Fee changes: We reserve the right to adjust the platform fee rate with 30 days' written notice. Existing verified payments are unaffected by rate changes — the fee rate is locked at the time of each payment challenge.
10. Non-Custodial Wallet
AlgoVoi is a non-custodial wallet. This means:
- Your private keys and seed phrase are generated and stored exclusively on your device
- We have no access to your private keys, seed phrase, or funds at any time
- We cannot recover your wallet, reset your password, or reverse transactions on your behalf
- You are solely responsible for safeguarding your seed phrase and private keys
- Loss of your seed phrase means permanent, irrecoverable loss of access to your funds
The 30-day local signing key feature stores an encrypted key with a time-limited TTL. This key is never transmitted to our servers.
11. Privacy & Data
Our full Privacy Policy is available at privacy-policy.html. Key principles:
- The AlgoVoi extension does not collect or transmit personal data beyond what is necessary for wallet operation
- Server logs are retained for security and fraud prevention purposes with a 90-day PII purge policy under UK GDPR
- No PII is included in audit log lines
- AML retention override: Where a payment record is subject to an AML hold — due to a sanctions hit, a transaction monitoring escalation, or a manual compliance hold — that record and its associated data are retained for a minimum of 5 years from the date of the transaction, as required by UK MLRs 2017 Reg 40(1)(b). This retention overrides the standard 90-day purge. The legal basis for this extended retention is our obligation to comply with anti-money laundering legislation, which takes precedence over erasure requests under UK GDPR (ICO guidance 2020)
- KYB documents are retained for a minimum of 5 years after the business relationship ends, as required by MLRs Reg 40(2)
- KYC/KYB documents are encrypted at rest using Fernet symmetric authenticated encryption (AES-128-CBC with HMAC-SHA256) before any file is written to disk. The encryption key is held separately from the key used for tenant secrets, supports multi-key rotation, and is never exposed to merchants or third parties. Plaintext exists only in memory while a document is being uploaded or reviewed by an authorised compliance reviewer
- We comply with UK GDPR. Data subjects may exercise their rights (access, rectification, erasure, portability, objection) by contacting [email protected] — we will respond within 30 days. Note that erasure requests may be refused or deferred where retention is required by AML legislation
- Data may be disclosed to law enforcement to the extent required or permitted by applicable law, in accordance with Section 5 of these terms
- Where we act as a data processor on behalf of merchants, a Data Processing Agreement (DPA) is available on request
12. Disclaimers & Limitation of Liability
Services are provided "as is" without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, or non-infringement.
- We do not guarantee uninterrupted availability of any service
- We are not liable for losses arising from blockchain network failures, smart contract bugs, or third-party protocol issues
- We are not liable for losses arising from user error, including sending funds to incorrect addresses
- We are not liable for losses arising from compromise of a user's device, seed phrase, or private keys
- We are not liable for losses arising from payment delays or blocks resulting from sanctions screening, AML holds, or risk management controls applied in good faith
- Cryptocurrency values are volatile. Nothing in these services constitutes financial advice
- To the maximum extent permitted by applicable law, our total liability shall not exceed the fees paid by you in the 30 days preceding the claim
Exclusion of indirect losses: To the maximum extent permitted by law, we shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, loss of data, loss of goodwill, or loss of cryptocurrency.
User indemnity: You agree to indemnify, defend, and hold harmless Christopher Hopley, algovoi.co.uk, and AlgoVoi from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable legal fees) arising from: (i) your breach of these terms; (ii) your violation of any applicable law; (iii) your use of the services for any prohibited purpose; or (iv) any third-party claim arising from your use of the services.
Nothing in these terms limits liability for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation, or any other liability that cannot be excluded by law.
13. Termination
We reserve the right to suspend or terminate access to any service, immediately and without notice, if we reasonably believe a user is:
- Engaged in any prohibited activity listed in Section 4
- Under investigation by law enforcement or a regulatory authority
- Listed on, or associated with a party listed on, a sanctions list
- In breach of their AML/KYB obligations under Section 6
- In breach of these terms in any material respect
- Using the service in a manner that could expose us or other users to legal, regulatory, or reputational harm
Termination of access does not affect our obligation to cooperate with law enforcement under Section 5, nor does it result in deletion of logs or records that may be subject to a preservation, disclosure, or AML retention obligation.
14. General Provisions
Severability: If any provision of these terms is found by a court of competent jurisdiction to be invalid, illegal, or unenforceable, that provision shall be modified to the minimum extent necessary to make it enforceable, or severed if modification is not possible. The remaining provisions shall continue in full force and effect.
Entire Agreement: These terms, together with our Privacy Policy, constitute the entire agreement between you and us relating to your use of the services and supersede all prior agreements, representations, and understandings, whether written or oral.
Force Majeure: We shall not be liable for any failure or delay in performance arising from circumstances beyond our reasonable control, including but not limited to blockchain network failures, third-party protocol outages, acts of God, government action, internet service disruptions, or cyberattacks on infrastructure we do not operate.
Assignment: We may assign our rights and obligations under these terms to a successor entity in the event of a merger, acquisition, or sale of assets, without your consent. You may not assign your rights or obligations under these terms without our prior written consent.
Waiver: Failure to enforce any provision of these terms shall not constitute a waiver of our right to enforce that provision in the future.
Amendments: We reserve the right to update these terms at any time. Continued use of the services following notice of updated terms constitutes acceptance. Material changes will be communicated via the extension or website.
15. Governing Law
These terms are governed by and construed in accordance with the laws of England and Wales. Any dispute arising from these terms shall be subject to the exclusive jurisdiction of the courts of England and Wales.
If any provision of these terms is found to be unenforceable, the remaining provisions shall continue in full force and effect.
16. Contact
Christopher Hopley — algovoi.co.uk
[email protected]
Money Laundering Reporting Officer (MLRO):
Christopher Hopley — designated MLRO
[email protected]
Law enforcement and regulatory authorities (including FCA, OFSI, UKFIU, and NCA) may contact us at the above address. We will respond to all lawful requests promptly and without reservation. For SAR-related matters, please mark correspondence Private & Confidential — MLRO.