Data Sharing Agreement · Art. 26 GDPR · Version 1.1 · March 2026
This agreement governs the relationship between Verifento (Luxria s.r.o.) and each registered B2B client (rental company, accommodation, etc.). This is not a DPA under Art. 28 GDPR – both parties are independent controllers (Art. 26 GDPR).
Preamble – Legal Classification
This agreement is concluded between two independent controllers of personal data under Art. 4(7) GDPR. Each contracting party independently and separately determines the purpose and means of processing personal data in relation to its customers.
Verifento (Luxria s.r.o.) acts as Network Administrator – an independent controller that:
- Determines the technical means of the cross-company network (HMAC-SHA256, traffic light algorithm, retention policy)
- Manages a shared database of pseudonymized risk signals
- Returns exclusively aggregated data to other network members – never raw identifiers
B2B client acts as Network Member – an independent controller that:
- Determines the legal basis for processing personal data of its customers (Art. 6(1)(f) GDPR)
- Is responsible for the accuracy and justification of uploaded records
- Informs its customers about sharing pseudonymized data through Verifento
This agreement is NOT a DPA under Art. 28 GDPR. It is a Controller-to-Controller Data Sharing Agreement under Art. 26 GDPR. The legal classification is based on EDPB Opinion 07/2020 (Fashion ID).
Art. 1 – Subject Matter, Purpose and Legal Basis
1.1 Subject Matter
The subject of this agreement is the regulation of conditions for sharing pseudonymized risk signals between two independent controllers through the Verifento platform in accordance with Art. 26 GDPR.
1.2 Purpose of Processing
Fraud prevention and asset protection – each party independently on the basis of Art. 6(1)(f) GDPR, Recital 47 GDPR.
1.3 Type of Shared Data
- HMAC-SHA256 hashes of identifiers (phone, email, document number)
- Business ID number for sole traders/companies
- Incident category, incident severity, incident date
1.4 Output for the Controller
Exclusively aggregated data – risk level + incident count + categories. The identity of the reporting company and raw records are never disclosed.
1.5 Categories of Data Subjects
Customers of the Controller – natural persons entering into a rental agreement.
1.6 Duration
For the duration of this agreement and the retention period under Art. 6.
Art. 2 – Obligations of the Network Administrator (Verifento)
2.1
The Network Administrator processes pseudonymized hashes exclusively for the purposes defined in Art. 1.
2.2 Technical and Organizational Measures (Art. 32 GDPR)
- HMAC-SHA256 hashing – plaintext identifiers never enter the database
- Server-side PEPPER key – stored exclusively in encrypted environment variables, never in DB
- Row Level Security (RLS) – PostgreSQL-level data isolation between clients
- Immutable audit log – REVOKE UPDATE, DELETE – every access permanently recorded
- HTTPS/TLS 1.2+ – all communication is encrypted
- SECURITY DEFINER check_subject_risk – returns only aggregated data, raw records of other companies are not technically accessible
2.3
The Network Administrator shall not provide other network members with direct personal identifiers of the Controller's customers.
2.4
The Network Administrator shall inform the Controller of a security incident under Art. 33 GDPR within 72 hours.
2.5
The Network Administrator shall make available upon request information necessary to demonstrate compliance, including the right to audit.
2.6
The Network Administrator publishes and maintains an up-to-date Privacy Policy at verifento.com/privacy.
Art. 3 – Obligations of the Controller (B2B Client)
This article is critical from the perspective of Art. 22 GDPR (CJEU C-634/21 SCHUFA). Violation of clause 3.4 may establish direct legal liability of the Controller towards data subjects.
3.1
The Controller shall ensure a valid legal basis (Art. 6(1)(f) GDPR) before transmitting data to the Verifento network.
3.2 Clause for Terms of Service / Privacy Policy
“Based on our legitimate interest in protecting assets and preventing fraud, your contact identifiers (in the form of an irreversible cryptographic hash) and information about serious contract violations may be processed through the Verifento platform (verifento.com) for the purpose of security risk assessment for other network members.”
3.3
The Controller shall report into the system EXCLUSIVELY verified incidents supported by objective evidence (signed protocol, unpaid invoice, police report). Uploading unsubstantiated or subjective records is prohibited.
3.4 Prohibition of Automated Decision-Making
The Controller MUST NOT use the traffic light assessment result as the sole and automatic reason for rejecting a customer. The traffic light is exclusively a decision-support tool. The final decision MUST include human assessment.
Legal reference: Art. 22 GDPR; CJEU C-634/21 (SCHUFA).
3.5
The Controller shall cooperate with SAR requests – upon request, provide evidence within 10 business days.
3.6
The Controller is responsible for the accuracy and justification of uploaded records and for damages caused by false records.
3.7
The Controller shall ensure that persons authorized to upload records are trained on the obligations under this agreement.
Art. 4 – Infrastructure and Subprocessors
The Controller will be informed of subprocessor changes at least 30 days in advance. The Controller has the right to raise a reasoned objection.
Art. 5 – Rights of Data Subjects
5.1
Both contracting parties are, each within the scope of their processing, responsible for enabling the exercise of data subject rights under Art. 15-22 GDPR.
5.2
The Network Administrator operates a public SAR form at verifento.com/gdpr-request. Upon receipt of a request: search for records by hash; for erasure/restriction requests, automatic freeze (is_active=false); request for Controller cooperation; response within 30 days (Art. 12(3) GDPR).
5.3 Quarantine Mechanism
Upon filing an objection, the Network Administrator automatically sets is_active=false. The record does not enter the traffic light assessment during the investigation.
5.4
The Controller is obliged to provide evidence for the disputed record within 10 business days upon request.
Art. 6 – Retention Policy and Erasure
6.2
Records are automatically deactivated after the retention period expires via pg_cron (nightly job at 02:00 UTC). Deactivation = is_active=false; the record stops entering the traffic light.
6.3
After termination of the agreement, the Network Administrator deactivates the Controller's access within 30 days. Records remain in the DB for the period under 6.1 – they serve other network members.
6.4
Upon the Controller's request, the Network Administrator shall provide an export of their records within 30 days.
Art. 7 – Sanctions for Violations
7.1
The Network Administrator is entitled to immediately suspend the Controller's access in case of:
- Repeated uploading of unsubstantiated records (ref. Art. 3.3)
- Proven automatic rejection of a customer solely based on the traffic light (ref. Art. 3.4)
- Other serious violation of the agreement or GDPR
7.2
The Controller is liable for damages incurred by third parties (affected customers) as a result of false records.
7.3
Violation of Art. 3.4 may establish the Controller's liability towards the data subject under Art. 22(4) GDPR.
Art. 8 – Final Provisions
- 8.1 This agreement is governed by the law of the Slovak Republic and GDPR (EU 2016/679).
- 8.2 The District Court of Banská Bystrica has jurisdiction over disputes arising from this agreement.
- 8.3 Amendments to this agreement are valid only in written form signed by both parties.
- 8.4 If any provision is invalid, the remaining provisions remain in force.
- 8.5 This agreement supersedes all previous agreements regarding data sharing in the Verifento network.
Appendix A – Technical Security Measures (Art. 32 GDPR)
A.1 HMAC-SHA256 Hashing
Every personal identifier is transformed using HMAC-SHA256 with a secret PEPPER key before storage. The PEPPER is stored exclusively in encrypted environment variables (Vercel) – never in the DB or repository. It is technically impossible to reconstruct the original identifier from the stored hash without knowledge of the PEPPER.
Loss of PEPPER = effective anonymization effect. All records become unidentifiable.
A.2 Row Level Security + SECURITY DEFINER
RLS at the PostgreSQL level ensures that each company sees exclusively records it reported itself. Cross-company lookup is only possible through the SECURITY DEFINER function check_subject_risk, which returns exclusively aggregated data – risk level + count + categories.
A.3 Traffic Light System – Risk Levels
This DSA agreement is concluded automatically (click-wrap) upon registration on the Verifento Platform. By signing the registration form, the Controller confirms consent to this agreement in its current version. The current version is always available at verifento.com/dsa.
© 2026 Luxria s.r.o. · Verifento · IČO: 52921361 · privacy@verifento.com