Skip to content
Legal documents

General Terms and Conditions

Version 1.2 · Effective from March 31, 2026 · Operator: Luxria s.r.o.

Please read these terms before registering. By using the Verifento platform, you confirm your agreement with these GTC.

Art. 1 – Operator and Identification

ItemData
Business NameLuxria s.r.o.
Company ID52921361
Tax ID2121219661
VAT IDSK2121219661 under § 7a
AddressRakytovská cesta 6952/36, 974 05 Banská Bystrica, Slovak Republic
PlatformVerifento - Customer Verification Platform (verifento.com)
Contactsupport@verifento.com | privacy@verifento.com
Legal FormInnominate contract pursuant to § 269(2) of Act No. 513/1991 Coll. (Commercial Code)
Governing LawLaw of the Slovak Republic
Competent CourtDistrict Court Banská Bystrica (Art. 23)

Art. 2 – Definitions

TermDefinition
PlatformThe Verifento software service available at verifento.com, including all features, APIs, and related services
ClientAn entrepreneur (legal entity or natural person – entrepreneur) registered on the Platform
UserA natural person acting on behalf of the Client with authorization to access the Platform
CustomerA natural person whom the Client verifies through the Platform
Verifento NetworkA shared database of risk signals (anonymized hashes) managed by Verifento
SemaphoreA 5-level risk indicator (grey/green/blue/orange/red) – exclusively a decision-support tool
IncidentA record of a negative or positive experience with a Customer reported by a Client
HMAC HashA cryptographic fingerprint of an identifier (HMAC-SHA256 + PEPPER) – plaintext is not stored
DSAData Sharing Agreement – Controller-to-Controller data sharing agreement (Annex B)
DPAData Processing Agreement – pursuant to Art. 28 GDPR (Annex A)
GTCThese General Terms and Conditions in their currently effective version

Art. 3 – Contract Formation and Registration

3.1 Contract conclusion (click-wrap)

The contract is formed upon completion of the registration process: (a) filling out the registration form with truthful information; (b) checking all mandatory consents; (c) submitting the registration form.

Verifento retains metadata about contract conclusion (date, time, IP address, GTC version) for the duration of the contract + 5 years.

3.2 Mandatory consents during registration

  1. Data Processing Agreement (DPA, Art. 28 GDPR) – Annex A
  2. These GTC
  3. Privacy Policy – verifento.com/privacy
  4. Confirmation of authorization to act on behalf of the Client

3.3 Authorization to act

The User declares: (a) they are an authorized person to act on behalf of the Client; (b) they have the authority to enter into a contractual relationship with Verifento; (c) all information provided is truthful, complete, and up to date.

Art. 4 – Platform Description and Services Provided

4.1 Platform Core – Customer Verification

  • Verification of the Customer's risk profile through the Verifento Network
  • Semaphore risk indicator – 5 levels: grey (no records) / green (positive references) / blue (low risk) / orange (elevated risk) / red (high risk)
  • Cross-company lookup: The Platform returns only an aggregated signal – not the identity of other clients or incident details

4.2 Incident and Record Management

  • Reporting negative incidents (non-payment, damage, attempted fraud, identity theft, breach of contract, aggressive behavior)
  • Reporting positive records
  • Incident history – overview of own records
  • Audit log – immutable record of all actions

4.3 Website Builder – Company Websites

  • Creation of a public Client page at verifento.com/p/[slug]
  • Management of products, reservations, reviews, blog
  • Invoicing system with PDF invoice generation

4.4 Pricing Plans and Payments

PlanPriceIncludes
Free€0/monthIncident reporting, basic verification, 1 user
Starter€4.99/monthUnlimited verification, website, 3 users
Business€14.99/monthAll features, invoicing, API access, unlimited users

Payments are processed through Stripe. The trial period is 14 days with no payment obligation. Currently: The Platform is available free of charge for all registered Clients (Beta phase).

Art. 5 – Semaphore – Decision-Support, Not Automatic Command

The Semaphore advises – you decide. A customer with a red score may have a legitimate explanation. Verifento is your assistant, not a judge. Human oversight is also required by GDPR Art. 22 (CJEU C-634/21 Schufa).

5.1 Nature of the Semaphore Indicator

The Semaphore is exclusively a decision-support tool. The result is not: (a) a guarantee of accuracy; (b) an automated decision; (c) a legally binding assessment of a person; (d) a substitute for the Client's own judgment.

5.2 Obligation of Meaningful Human Oversight

The Client undertakes to ensure that no decision is based solely on the Semaphore output. Meaningful human oversight includes: an authorized employee with the power to override the indicator; consideration of information beyond the Semaphore; actual exercise of discretion; completion of data protection training.

5.3 Prohibited Uses of the Semaphore

  • Automatically refuse a rental solely on the basis of the Semaphore indicator without independent assessment
  • Implement automated workflows that systematically reject Customers when a threshold score is exceeded
  • Use the Semaphore for purposes other than risk assessment in connection with rental, accommodation, or B2B transactions within the Client's business
  • Use the Semaphore as a proxy for any protected characteristic under anti-discrimination law
  • Share or otherwise make Semaphore results available to third parties outside the Client's business

5.4 Adverse Decision – Duty to Inform

If the Client makes an adverse decision and Verifento data was one of the factors, the Client shall inform the Customer and provide Verifento's contact details for exercising the Customer's rights.

Art. 6 – Incident Reporting – Client Obligations

6.1 Standard of Evidence

The Client shall report only incidents that: (a) are based on an actual and proven incident; (b) are supported by clear evidence (police report, signed handover protocol, enforcement title, damage documentation); (c) meet incident category definitions; (d) accurately describe the facts of the incident.

6.2 Prohibition of False Records

The Client is expressly prohibited from: (a) reporting incidents without irrefutable evidence; (b) reporting subjective evaluations as factual incidents; (c) using the Platform for revenge or unfair competition; (d) publishing personally identifiable information in the Incident Description field.

6.3 Record Keeping and Archival

The Client shall retain evidence for a minimum of 4 years from the date of the incident. Upon Verifento's request, the Client shall provide evidence within 10 business days.

6.4 Penalties for Violations

LevelConditionConsequence
WarningFirst minor inaccuraciesWritten warning; 14 days to correct
RestrictionRepeated inaccuracies30–90 days suspension of reporting rights
SuspensionDeliberately false recordsImmediate access suspension
TerminationFraud, criminal activityPermanent ban; referral to authorities upon suspicion of criminal offense

Art. 7 – Client's GDPR Obligations

7.1 Cascading Transparency

The Client shall include in their GTC or Privacy Policy a clause about data sharing with Verifento. Sample clause:

“Based on our legitimate interest in protecting our property and preventing fraud, your contact and identification data (in the form of an irreversible cryptographic hash) and information about serious contract breaches may be sent to the Verifento platform (verifento.com), where they are processed for the purpose of security risk assessment for other network members. More information at verifento.com/privacy.”

7.2 Legal Basis for Own Processing

The Client is responsible for ensuring their own legal basis (Art. 6 GDPR). Recommended legal basis: legitimate interest (Art. 6(1)(f)) – the Client is required to have their own documented LIA test.

The Verifento platform serves lessors across all sectors: accommodation and premises; vehicles and transport; sports and outdoor; boats and water sports; machinery and tools; home and garden; furniture and interior; electronics and IT; photo, video and audio; events and parties; fashion and luxury; travel and luggage; health and rehabilitation aids – as well as B2B segments: wholesale and distribution; construction; manufacturing; transport and logistics; marketing and agencies; IT services; professional services; B2B equipment rental.

7.3 Cooperation with SAR Requests

If a data subject submits a SAR request (Art. 15–22 GDPR), the Client shall: (a) provide Verifento with evidence within 10 business days; (b) cooperate in processing the request; (c) provide information in accordance with the facts.

Art. 8 – Company Websites – Website Builder

8.1 License for Use

Verifento grants the Client a non-exclusive, non-transferable license to use the Website Builder feature on the domain verifento.com/p/[slug].

8.2 Client Content – Responsibility

The Client is solely responsible for: (a) the accuracy and truthfulness of the content; (b) compliance with applicable law; (c) intellectual property rights; (d) product and pricing descriptions; (e) communication with Customers.

Verifento reserves the right to immediately remove content that violates applicable law or third-party rights.

8.3 Booking System and Customer Payments

Payment transactions take place directly on the Client's Stripe account. Verifento is not a payment intermediary and bears no responsibility for payment disputes.

Art. 9 – Intellectual Property Rights

9.1 Platform Ownership

Verifento and its licensors are the exclusive owners of the Platform, including software, algorithms, databases, design, trademarks, and know-how.

9.2 Client Data

The Client retains all rights to the data they provide to the Platform. The Client grants Verifento a non-exclusive license to process this data solely for the purpose of providing the Services.

9.3 Anonymized Network Data

Identifier hashes and aggregated risk signals remain in the Network even after termination of the Client's contract – they are essential for the protection of other Network Clients.

Art. 10 – Availability and SLA

Verifento undertakes to ensure Platform availability at the level of 99.5% (annual average), measured monthly. Scheduled maintenance is announced at least 24 hours in advance by email and is not counted in the availability calculation.

AvailabilityCompensation
99.5% and aboveNone – SLA met
99.0% – 99.5%5% monthly fee credit
Less than 99.0%15% monthly fee credit

Exclusions: outages caused by the Client, third parties, force majeure (Art. 15), or scheduled maintenance.

Art. 11 – Limitation of Liability

Legal framework – § 386 Commercial Code

11.1 Informational Nature of Results

The Platform is provided “as-is.” Verifento makes no warranties regarding: (a) the accuracy of the Semaphore indicator; (b) 100% fraud detection; (c) uninterrupted operation; (d) compatibility with the Client's specific use.

11.2 Liability Cap

Verifento's total liability shall not exceed the greater of: the amount of fees paid in the 12 months preceding the event, OR EUR 500 (for the free plan).

Exceptions to the cap: (a) breach of confidentiality; (b) intentional conduct (§ 380 Commercial Code); (c) gross negligence in processing personal data leading to GDPR violation; (d) infringement of intellectual property rights.

11.3 Excluded Types of Damages

Verifento is not liable for: (a) lost profits caused by Semaphore inaccuracy; (b) data loss resulting from Client negligence; (c) costs of substitute services except in cases of intentional conduct by Verifento.

11.4 Liability for False Records

The Client is solely liable for damages caused by false incidents. This liability is not subject to the cap under Art. 11.2.

Art. 12 – Acceptable Use Policy (AUP)

12.1 Permitted Uses

The Platform is intended exclusively for: verifying Customers in connection with rental, accommodation, or B2B deliveries; reporting proven incidents; managing the Client's web presence; invoicing own Customers.

12.2 Prohibited Activities

  • Creating multiple accounts to circumvent limits
  • Automated scanning or mass searching above rate limits
  • Attempting reverse engineering or decompilation
  • Sharing access credentials between multiple persons or companies
  • Using the Platform for marketing, HR decisions, credit scoring, or insurance outside of rental
  • Uploading personal data without a legitimate legal basis
  • Any activity violating applicable Slovak law or the GDPR

12.3 Access and Security

The Client is required to: (a) use strong passwords and MFA; (b) assign access rights based on roles; (c) immediately report suspected unauthorized access to security@verifento.com; (d) not disclose API keys or login credentials.

Art. 13 – Confidentiality

Each party shall maintain in strict confidence the confidential information of the other party, including trade secrets, technical architecture, business plans, and pricing. The confidentiality obligation shall last for 5 years after contract termination.

Art. 14 – Contract Termination

14.1 Termination by the Client

The Client may terminate the contract at any time without giving a reason by deactivating their account in settings.

14.2 Termination by Verifento

Verifento may terminate the contract: (a) with 30 days' notice; (b) immediately upon material breach of the GTC (especially Art. 5, 6, 12); (c) immediately upon bankruptcy or liquidation of the Client.

14.3 Data After Termination

The Client has 30 days to export their data. After expiration, data is automatically deleted – with the exception of data required to be retained by law (accounting 10 years), HMAC hashes in the Verifento Network, audit logs (5 years).

Art. 15 – Force Majeure

Neither party shall be liable for failure to fulfill obligations caused by circumstances beyond its control (§ 374 Commercial Code). Force majeure events include: natural disasters, armed conflicts, systemic cloud infrastructure outages (AWS, Vercel) exceeding the provider's SLA, government-imposed restrictions.

Force majeure does not relieve the Client of payment obligations for services already rendered.

Art. 16 – Changes to GTC

Verifento shall notify of material changes by email at least 30 days in advance. Continued use of the Platform after the changes take effect constitutes acceptance of the new version.

Art. 17 – Personal Data Protection

Personal data processing is governed by: (a) Privacy Policy v1.1 – verifento.com/privacy; (b) DPA (Annex A) for processing as a Processor; (c) DSA v1.1 (Annex B) for processing as an independent Controller; (d) GDPR (EU) 2016/679; (e) Act No. 18/2018 Coll. as amended by Act No. 108/2024 Coll.

Art. 18 – Severability

If any provision of these GTC is invalid, this shall not affect the validity of the remaining provisions.

Art. 19 – Contractual Penalty

For violation of the prohibitions under Art. 5.3, Art. 6.2, and Art. 12.2, the Client shall pay Verifento a contractual penalty of EUR 500 for each individual violation, in addition to the claim for damages.

Art. 20 – References and Marketing

Verifento shall not disclose the Client's business name or logo in marketing materials without their prior express consent. Consent is voluntary and revocable at any time.

Art. 21 – Verifento Network – Special Provisions

21.1 Equal Responsibility for Data Quality

In accordance with the principles of CIFAS and EDPB Guidelines 1/2024, each Client bears equal responsibility for the accuracy and legitimacy of the records they report to the Network.

21.2 Records After Leaving the Network

After contract termination: (a) validated records remain in the Network; (b) the Client's identity as the data source is anonymized within 90 days; (c) the Client may request deletion of unconfirmed records.

21.3 Dispute and Correction Mechanism

  1. Verifento shall notify the Client of the dispute within 5 business days
  2. The record is marked as “Disputed”
  3. The Client shall provide evidence within 30 calendar days
  4. Verifento shall issue a decision within 15 days
  5. The Customer may add a statement of up to 200 words

Art. 22 – Platform Changes and Service Termination

Verifento may at any time: (a) add, modify, or remove Platform features; (b) terminate Platform provision with 90 days' notice.

In the event of termination, Verifento shall provide data export and refund a proportional part of the fees.

Art. 23 – Governing Law and Jurisdiction

23.1 Governing Law

These GTC are governed by the law of the Slovak Republic, Act No. 513/1991 Coll. (Commercial Code), and GDPR (EU) 2016/679.

23.2 Out-of-Court Dispute Resolution

The parties undertake to make reasonable efforts toward amicable dispute resolution within 30 days.

23.3 Jurisdiction

All disputes shall be exclusively resolved by the courts of the Slovak Republic, specifically the District Court Banská Bystrica. For Clients headquartered in other EU Member States, this clause is valid pursuant to Art. 25 of Regulation (EU) No. 1215/2012 (Brussels I Recast).

Art. 24 – Final Provisions

  • These GTC replace any previous agreements relating to the Platform
  • Failure to exercise any right by Verifento does not constitute a waiver of that right
  • The Client may not assign these GTC to a third party without Verifento's consent
  • These GTC are available in the Slovak language as the binding version; the Czech and English versions are for information only

Art. 25 – Annexes

AnnexTitleURL
AData Processing Agreement (DPA)verifento.com/dpa
BData Sharing Agreement (DSA v1.1)verifento.com/dsa
CPrivacy Policy (v1.1)verifento.com/privacy
DCookie Policy (v1.2)verifento.com/cookies
EAcceptable Use Policy (AUP)verifento.com/aup

Art. 26 – Document Metadata

ItemValue
Version1.2
Effective fromMarch 31, 2026
ReplacesGTC v1.0 (internal draft from March 9, 2026)
LanguageSlovak (binding); Czech and English versions are informational
Legal StatusPending verification by a lawyer specializing in GDPR and the Commercial Code

© 2026 Luxria s.r.o. · Verifento · Company ID: 52921361 · support@verifento.com · verifento.com/privacy · verifento.com/cookies