Skip to content

What we store about customers, and who can see it

There are no names, addresses or ID numbers in the Verifento database. Only an irreversible cryptographic fingerprint of the identifier is stored (HMAC-SHA256 with a secret key): enough to confirm a match, but the original value cannot be read back from it – not even by us. Customers therefore cannot be listed out of the database; only someone whose identifier a company already holds can be checked.

What a blind index is, and why the whole network rests on it

A blind index is a fingerprint computed from an identifier and a secret key. The same input always produces the same fingerprint, so records from different companies can be compared – but a phone number or e-mail cannot be computed back from it. Without the secret key it cannot even be guessed at scale: an attacker holding the entire database holds a list of numbers that mean nothing. That is what lets the network share experience without sharing personal data.

What a company actually sees in a check

A risk level, the types of cases behind it, and the number of DISTINCT companies that reported them. Nothing more. Other companies’ records are never displayed, and which company filed a record is never returned – sharing only works if reporting does not expose the reporter to a competitor or to the customer.

Why the traffic light is not a decision

The result is input for a human, not an instruction. The system never returns “rent” or “do not rent” and never rejects anyone automatically. That is both design and law: GDPR Article 22 restricts decisions based solely on automated processing that significantly affect a person.

No evidence, no record

Every incident must carry at least one type of evidence – a signed protocol, photo documentation, an unpaid invoice, a damage or police report, a record from a booking platform or a witness statement. Without it the record cannot be submitted. It is the main difference between a documented incident and defamation, and it is what keeps the legitimate-interest basis under Article 6(1)(f) standing up.

How a record can be challenged

The data subject has the right of access, rectification, objection and erasure, and a public form exists for it. The company that created a record must be able to support it; when the matter is resolved or turns out to be unfounded, the status is updated or the record is deleted. Every access is written to an audit log that cannot be rewritten or deleted.

Where registration ends and sharing begins

These are two different scopes and they get confused. A company can register from 47 countries across five continents – that is the availability of the platform, and that is exactly what the flags on the home page mean. Sharing a record about a NATURAL PERSON across borders is something else: it is governed by GDPR, it is narrower, and its core is the European Economic Area, the United Kingdom and the countries the European Commission has found to provide adequate protection. Records about companies (business IDs) fall under a different regime – legal persons are outside GDPR. The exact country list for sharing is being confirmed by the data protection officer and will be published in the legal documents once it is settled; until then we do not put a list here that we would change in a month. Where the data physically sits and how transfers to sub-processors are secured is described in the privacy policy.

How long a record stays

Not forever, and not at anyone’s discretion. A negative record of low or medium severity is kept for three years, a record of fraud or theft for five, a positive reference for three. The periods are not invented – they follow the limitation periods after which a claim can no longer be pursued anyway, so the record stops meaning anything. Once a period expires the record is deactivated automatically and stops entering the traffic light; it is not erased by a person who remembers it, but by a system that does not forget. Access audit logs live for five years, because without them there is no way to prove who looked at what. The exact periods and their legal basis are in the privacy policy.

What works automatically today, and what by hand

The network has no borders – an incident reported in one country is visible to a company in another. What differs is the depth of integration. In Slovakia and Czechia we verify a company automatically against the commercial register (RPO, ARES) and the forms expect +421 and +420 numbers; elsewhere you enter the company details by hand and we check them during approval, which a person does in either case. More countries are being added. We write this down because “available in 47 countries” and “automatically verified in 47 countries” are two different sentences and only one of them is true.

Technical security

Transport runs exclusively over HTTPS with TLS 1.3 and HSTS. Data access is isolated at the database level (row level security), so a company technically cannot read other companies’ records – it is not merely an application check. Sessions are protected by token rotation. Two-factor authentication for account owners is being introduced; penetration testing against the OWASP Top 10 is planned before the production launch. We write it here with the “being introduced” included, because a security page that claims more than the system does becomes evidence against us at the first audit.

Details in the legal documents: Privacy · GDPR · DPA · GDPR request · Glossary