Skip to content
Legal documents

Privacy Policy

Contents

Version 1.1 · Effective from March 31, 2026 · Operator: Luxria s.r.o.

1. Who We Are

Luxria s.r.o.
Rakytovská cesta 6952/36, 974 05 Banská Bystrica
Company ID: 52921361 · Tax ID: 2121219661 · VAT ID: SK2121219661 under § 7a
Registered in the Commercial Register of the District Court Banská Bystrica, Section Sro, File No. 38174/S

We operate the Verifento platform (verifento.com) – an all-in-one solution for rental companies, equipment rental businesses, and B2B enterprises. The platform combines shared customer and business partner verification across a network of companies, rental and contract management, invoicing, and business website creation with an integrated booking system.

Contact for data protection inquiries: privacy@verifento.com

2. What Data We Process and Why

Data TypeStorage FormatPurpose
Phone numberHMAC-SHA256 hashFraud prevention – identification of high-risk customers
Email addressHMAC-SHA256 hashFraud prevention – identification of high-risk customers
Identity document numberHMAC-SHA256 hashFraud prevention – identification of high-risk customers
Company ID (sole trader / company)Plaintext (public record)Subject identification from the public register
Incident categoryEnum valueDescription of the situation type (damage, non-payment, etc.)
Audit logTimestamp + hash + IPSystem security and GDPR compliance demonstration

Processing of verified customers' data is carried out on the basis of legitimate interest pursuant to Art. 6(1)(f) GDPR. Fraud prevention is explicitly recognized as a legitimate interest in Recital 47 GDPR.

To other companies in the Verifento network, we return exclusively an aggregated traffic-light signal (5 levels: grey / green / blue / orange / red) along with the number of records and categories. We never disclose incident details or the identity of the reporting company.

Your personal data is NEVER stored in a readable form. We store exclusively cryptographic hashes (HMAC-SHA256 with a secret key) that cannot be reversed to the original identifier.

4. How Long We Retain Data

  • Negative records (low/medium) – 3 years (§ 101 of the Slovak Civil Code – general limitation period)
  • Negative records (high – fraud, theft) – 5 years (§ 87 of the Slovak Criminal Code – limitation period for criminal offences)
  • Positive records – 3 years (reference loses relevance after the limitation period)
  • Audit logs – 5 years (Art. 5(2) GDPR – compliance demonstration)
  • Billing data – 10 years (Act No. 431/2002 Coll. on Accounting)

After the retention period expires, records are automatically deactivated (is_active = false) and are excluded from the traffic-light assessment.

5. Your Rights

Under GDPR (Art. 15–21) you have the following rights:

  • Right of access (Art. 15) – you can find out whether data about you is recorded in the system
  • Right to rectification (Art. 16) – you can request correction of inaccurate data
  • Right to erasure (Art. 17) – you can request deletion upon demonstrating inaccuracy
  • Right to restriction of processing (Art. 18) – you can request freezing of data during a dispute investigation
  • Right to object (Art. 21) – you can object to processing based on legitimate interest
  • Right to data portability (Art. 20) – data in a machine-readable format

How to Exercise Your Rights

We will respond to your request within 30 days in accordance with Art. 12 GDPR.

Right to lodge a complaint: Office for Personal Data Protection of the Slovak Republic – dataprotection.gov.sk

6. Automated Decision-Making

The Verifento traffic-light system (grey / green / blue / orange / red) is a decision-support tool – it provides an informational signal to the lessor, but is not an automated decision within the meaning of Art. 22 GDPR.

The final rental decision is always made by a human (an employee of the business). The system does not make any automated decisions with legal effects or similarly significant consequences for the data subject.

Reference: CJEU C-634/21 (SCHUFA) – scoring constitutes automated decision-making only if it is the sole basis for a decision with legal effects. In the case of Verifento, the traffic light enters the human decision-making process as one of several factors.

7. Where Data Is Stored

  • Supabase (PostgreSQL) – AWS eu-central-1 (Frankfurt, EU) – SCCs pursuant to Art. 46(2)(c) GDPR
  • Vercel – EU + USA edge – SCCs pursuant to Art. 46(2)(c) GDPR + EU-U.S. Data Privacy Framework (DPF certified since July 2023)

Transfer of data to the USA (Vercel edge) is secured by a combination of Standard Contractual Clauses (SCCs) and certification under the EU-U.S. Data Privacy Framework. All sub-processors are bound by DPA agreements.

8. Cookies

The platform dashboard does not use analytical or advertising cookies. We use only strictly necessary cookies to ensure functionality (authentication, CSRF protection). Details at verifento.com/cookies.

9. Changes to This Policy

We will inform you of changes to this policy by publishing the updated version on this page. Data subjects can check the current version at any time at verifento.com/privacy.

Last updated: March 31, 2026 · Version 1.1