Version 1.2 · Effective from March 31, 2026 · Operator: Luxria s.r.o.
Art. 1 – Operator and Identification
Art. 2 – Definitions
Art. 3 – Contract Formation and Registration
3.1 Contract conclusion (click-wrap)
The contract is formed upon completion of the registration process: (a) filling out the registration form with truthful information; (b) checking all mandatory consents; (c) submitting the registration form.
Verifento retains metadata about contract conclusion (date, time, IP address, GTC version) for the duration of the contract + 5 years.
3.2 Mandatory consents during registration
- Data Processing Agreement (DPA, Art. 28 GDPR) – Annex A
- These GTC
- Privacy Policy – verifento.com/privacy
- Confirmation of authorization to act on behalf of the Client
3.3 Authorization to act
The User declares: (a) they are an authorized person to act on behalf of the Client; (b) they have the authority to enter into a contractual relationship with Verifento; (c) all information provided is truthful, complete, and up to date.
Art. 4 – Platform Description and Services Provided
4.1 Platform Core – Customer Verification
- Verification of the Customer's risk profile through the Verifento Network
- Semaphore risk indicator – 5 levels: grey (no records) / green (positive references) / blue (low risk) / orange (elevated risk) / red (high risk)
- Cross-company lookup: The Platform returns only an aggregated signal – not the identity of other clients or incident details
4.2 Incident and Record Management
- Reporting negative incidents (non-payment, damage, attempted fraud, identity theft, breach of contract, aggressive behavior)
- Reporting positive records
- Incident history – overview of own records
- Audit log – immutable record of all actions
4.3 Website Builder – Company Websites
- Creation of a public Client page at verifento.com/p/[slug]
- Management of products, reservations, reviews, blog
- Invoicing system with PDF invoice generation
4.4 Pricing Plans and Payments
Payments are processed through Stripe. The trial period is 14 days with no payment obligation. Currently: The Platform is available free of charge for all registered Clients (Beta phase).
Art. 5 – Semaphore – Decision-Support, Not Automatic Command
The Semaphore advises – you decide. A customer with a red score may have a legitimate explanation. Verifento is your assistant, not a judge. Human oversight is also required by GDPR Art. 22 (CJEU C-634/21 Schufa).
5.1 Nature of the Semaphore Indicator
The Semaphore is exclusively a decision-support tool. The result is not: (a) a guarantee of accuracy; (b) an automated decision; (c) a legally binding assessment of a person; (d) a substitute for the Client's own judgment.
5.2 Obligation of Meaningful Human Oversight
The Client undertakes to ensure that no decision is based solely on the Semaphore output. Meaningful human oversight includes: an authorized employee with the power to override the indicator; consideration of information beyond the Semaphore; actual exercise of discretion; completion of data protection training.
5.3 Prohibited Uses of the Semaphore
- Automatically refuse a rental solely on the basis of the Semaphore indicator without independent assessment
- Implement automated workflows that systematically reject Customers when a threshold score is exceeded
- Use the Semaphore for purposes other than risk assessment in connection with rental, accommodation, or B2B transactions within the Client's business
- Use the Semaphore as a proxy for any protected characteristic under anti-discrimination law
- Share or otherwise make Semaphore results available to third parties outside the Client's business
5.4 Adverse Decision – Duty to Inform
If the Client makes an adverse decision and Verifento data was one of the factors, the Client shall inform the Customer and provide Verifento's contact details for exercising the Customer's rights.
Art. 6 – Incident Reporting – Client Obligations
6.1 Standard of Evidence
The Client shall report only incidents that: (a) are based on an actual and proven incident; (b) are supported by clear evidence (police report, signed handover protocol, enforcement title, damage documentation); (c) meet incident category definitions; (d) accurately describe the facts of the incident.
6.2 Prohibition of False Records
The Client is expressly prohibited from: (a) reporting incidents without irrefutable evidence; (b) reporting subjective evaluations as factual incidents; (c) using the Platform for revenge or unfair competition; (d) publishing personally identifiable information in the Incident Description field.
6.3 Record Keeping and Archival
The Client shall retain evidence for a minimum of 4 years from the date of the incident. Upon Verifento's request, the Client shall provide evidence within 10 business days.
6.4 Penalties for Violations
Art. 7 – Client's GDPR Obligations
7.1 Cascading Transparency
The Client shall include in their GTC or Privacy Policy a clause about data sharing with Verifento. Sample clause:
“Based on our legitimate interest in protecting our property and preventing fraud, your contact and identification data (in the form of an irreversible cryptographic hash) and information about serious contract breaches may be sent to the Verifento platform (verifento.com), where they are processed for the purpose of security risk assessment for other network members. More information at verifento.com/privacy.”
7.2 Legal Basis for Own Processing
The Client is responsible for ensuring their own legal basis (Art. 6 GDPR). Recommended legal basis: legitimate interest (Art. 6(1)(f)) – the Client is required to have their own documented LIA test.
The Verifento platform serves lessors across all sectors: accommodation and premises; vehicles and transport; sports and outdoor; boats and water sports; machinery and tools; home and garden; furniture and interior; electronics and IT; photo, video and audio; events and parties; fashion and luxury; travel and luggage; health and rehabilitation aids – as well as B2B segments: wholesale and distribution; construction; manufacturing; transport and logistics; marketing and agencies; IT services; professional services; B2B equipment rental.
7.3 Cooperation with SAR Requests
If a data subject submits a SAR request (Art. 15–22 GDPR), the Client shall: (a) provide Verifento with evidence within 10 business days; (b) cooperate in processing the request; (c) provide information in accordance with the facts.
Art. 8 – Company Websites – Website Builder
8.1 License for Use
Verifento grants the Client a non-exclusive, non-transferable license to use the Website Builder feature on the domain verifento.com/p/[slug].
8.2 Client Content – Responsibility
The Client is solely responsible for: (a) the accuracy and truthfulness of the content; (b) compliance with applicable law; (c) intellectual property rights; (d) product and pricing descriptions; (e) communication with Customers.
Verifento reserves the right to immediately remove content that violates applicable law or third-party rights.
8.3 Booking System and Customer Payments
Payment transactions take place directly on the Client's Stripe account. Verifento is not a payment intermediary and bears no responsibility for payment disputes.
Art. 9 – Intellectual Property Rights
9.1 Platform Ownership
Verifento and its licensors are the exclusive owners of the Platform, including software, algorithms, databases, design, trademarks, and know-how.
9.2 Client Data
The Client retains all rights to the data they provide to the Platform. The Client grants Verifento a non-exclusive license to process this data solely for the purpose of providing the Services.
9.3 Anonymized Network Data
Identifier hashes and aggregated risk signals remain in the Network even after termination of the Client's contract – they are essential for the protection of other Network Clients.
Art. 10 – Availability and SLA
Verifento undertakes to ensure Platform availability at the level of 99.5% (annual average), measured monthly. Scheduled maintenance is announced at least 24 hours in advance by email and is not counted in the availability calculation.
Exclusions: outages caused by the Client, third parties, force majeure (Art. 15), or scheduled maintenance.
Art. 11 – Limitation of Liability
Legal framework – § 386 Commercial Code
11.1 Informational Nature of Results
The Platform is provided “as-is.” Verifento makes no warranties regarding: (a) the accuracy of the Semaphore indicator; (b) 100% fraud detection; (c) uninterrupted operation; (d) compatibility with the Client's specific use.
11.2 Liability Cap
Verifento's total liability shall not exceed the greater of: the amount of fees paid in the 12 months preceding the event, OR EUR 500 (for the free plan).
Exceptions to the cap: (a) breach of confidentiality; (b) intentional conduct (§ 380 Commercial Code); (c) gross negligence in processing personal data leading to GDPR violation; (d) infringement of intellectual property rights.
11.3 Excluded Types of Damages
Verifento is not liable for: (a) lost profits caused by Semaphore inaccuracy; (b) data loss resulting from Client negligence; (c) costs of substitute services except in cases of intentional conduct by Verifento.
11.4 Liability for False Records
The Client is solely liable for damages caused by false incidents. This liability is not subject to the cap under Art. 11.2.
Art. 12 – Acceptable Use Policy (AUP)
12.1 Permitted Uses
The Platform is intended exclusively for: verifying Customers in connection with rental, accommodation, or B2B deliveries; reporting proven incidents; managing the Client's web presence; invoicing own Customers.
12.2 Prohibited Activities
- Creating multiple accounts to circumvent limits
- Automated scanning or mass searching above rate limits
- Attempting reverse engineering or decompilation
- Sharing access credentials between multiple persons or companies
- Using the Platform for marketing, HR decisions, credit scoring, or insurance outside of rental
- Uploading personal data without a legitimate legal basis
- Any activity violating applicable Slovak law or the GDPR
12.3 Access and Security
The Client is required to: (a) use strong passwords and MFA; (b) assign access rights based on roles; (c) immediately report suspected unauthorized access to security@verifento.com; (d) not disclose API keys or login credentials.
Art. 13 – Confidentiality
Each party shall maintain in strict confidence the confidential information of the other party, including trade secrets, technical architecture, business plans, and pricing. The confidentiality obligation shall last for 5 years after contract termination.
Art. 14 – Contract Termination
14.1 Termination by the Client
The Client may terminate the contract at any time without giving a reason by deactivating their account in settings.
14.2 Termination by Verifento
Verifento may terminate the contract: (a) with 30 days' notice; (b) immediately upon material breach of the GTC (especially Art. 5, 6, 12); (c) immediately upon bankruptcy or liquidation of the Client.
14.3 Data After Termination
The Client has 30 days to export their data. After expiration, data is automatically deleted – with the exception of data required to be retained by law (accounting 10 years), HMAC hashes in the Verifento Network, audit logs (5 years).
Art. 15 – Force Majeure
Neither party shall be liable for failure to fulfill obligations caused by circumstances beyond its control (§ 374 Commercial Code). Force majeure events include: natural disasters, armed conflicts, systemic cloud infrastructure outages (AWS, Vercel) exceeding the provider's SLA, government-imposed restrictions.
Force majeure does not relieve the Client of payment obligations for services already rendered.
Art. 16 – Changes to GTC
Verifento shall notify of material changes by email at least 30 days in advance. Continued use of the Platform after the changes take effect constitutes acceptance of the new version.
Art. 17 – Personal Data Protection
Personal data processing is governed by: (a) Privacy Policy v1.1 – verifento.com/privacy; (b) DPA (Annex A) for processing as a Processor; (c) DSA v1.1 (Annex B) for processing as an independent Controller; (d) GDPR (EU) 2016/679; (e) Act No. 18/2018 Coll. as amended by Act No. 108/2024 Coll.
Art. 18 – Severability
If any provision of these GTC is invalid, this shall not affect the validity of the remaining provisions.
Art. 19 – Contractual Penalty
For violation of the prohibitions under Art. 5.3, Art. 6.2, and Art. 12.2, the Client shall pay Verifento a contractual penalty of EUR 500 for each individual violation, in addition to the claim for damages.
Art. 20 – References and Marketing
Verifento shall not disclose the Client's business name or logo in marketing materials without their prior express consent. Consent is voluntary and revocable at any time.
Art. 21 – Verifento Network – Special Provisions
21.1 Equal Responsibility for Data Quality
In accordance with the principles of CIFAS and EDPB Guidelines 1/2024, each Client bears equal responsibility for the accuracy and legitimacy of the records they report to the Network.
21.2 Records After Leaving the Network
After contract termination: (a) validated records remain in the Network; (b) the Client's identity as the data source is anonymized within 90 days; (c) the Client may request deletion of unconfirmed records.
21.3 Dispute and Correction Mechanism
- Verifento shall notify the Client of the dispute within 5 business days
- The record is marked as “Disputed”
- The Client shall provide evidence within 30 calendar days
- Verifento shall issue a decision within 15 days
- The Customer may add a statement of up to 200 words
Art. 22 – Platform Changes and Service Termination
Verifento may at any time: (a) add, modify, or remove Platform features; (b) terminate Platform provision with 90 days' notice.
In the event of termination, Verifento shall provide data export and refund a proportional part of the fees.
Art. 23 – Governing Law and Jurisdiction
23.1 Governing Law
These GTC are governed by the law of the Slovak Republic, Act No. 513/1991 Coll. (Commercial Code), and GDPR (EU) 2016/679.
23.2 Out-of-Court Dispute Resolution
The parties undertake to make reasonable efforts toward amicable dispute resolution within 30 days.
23.3 Jurisdiction
All disputes shall be exclusively resolved by the courts of the Slovak Republic, specifically the District Court Banská Bystrica. For Clients headquartered in other EU Member States, this clause is valid pursuant to Art. 25 of Regulation (EU) No. 1215/2012 (Brussels I Recast).
Art. 24 – Final Provisions
- These GTC replace any previous agreements relating to the Platform
- Failure to exercise any right by Verifento does not constitute a waiver of that right
- The Client may not assign these GTC to a third party without Verifento's consent
- These GTC are available in the Slovak language as the binding version; the Czech and English versions are for information only
Art. 25 – Annexes
Art. 26 – Document Metadata
© 2026 Luxria s.r.o. · Verifento · Company ID: 52921361 · support@verifento.com · verifento.com/privacy · verifento.com/cookies