Legal information
GDPR Information
Information about the processing of personal data, the legal bases used by Veri-Trust, and the rights available under European data protection law.
Last updated: July 2026
1. Data controller
The data controller for personal data processed through Veri-Trust is Collier Consulting Company SARL, a French limited liability company registered in France.
Veri-Trust is a platform operated and developed by Collier Consulting Company SARL.
Registered office: 128 rue La Boétie, 75008 Paris, France.
SIREN and Paris Trade and Companies Register number: 850 065 475 RCS Paris.
Privacy contact: privacy@veri-trust.app.
Legal and compliance contact: legal@veri-trust.app.
2. Categories of personal data processed
Veri-Trust may process account data, including email addresses, user identifiers, authentication status, account status, selected plan, subscription status, and account creation or update dates.
The platform may process authentication and security data, including login events, session information, technical logs, IP addresses, security events, rate-limit records, failed attempts, and information used to prevent unauthorized access.
Veri-Trust may process search and usage data, including protected search identifiers, search timestamps, usage counters, applicable plan limits, and records necessary to enforce daily or technical limits.
Community feedback data may include ratings, reliability scores, categories, tags, comments, timestamps, report history, moderation status, translations, and information relating to moderation decisions.
Subscription data may include Stripe customer identifiers, subscription identifiers, selected plan, payment status, renewal status, cancellation status, and billing-related events. Veri-Trust does not directly store full payment card details.
Rights and support request data may include the requester’s contact details, the identifier concerned, the nature of the request, correspondence, verification information, supporting context, and the outcome of the request.
3. Protected and hashed identifiers
Email addresses and telephone numbers submitted for search or community feedback matching may be normalized and transformed into cryptographic hashes before being stored in the Veri-Trust review and search systems.
Hashing is a pseudonymization measure. It reduces direct exposure of the original identifier but does not necessarily make the resulting information anonymous under data protection law.
Veri-Trust does not publicly display the raw email address or telephone number associated with a search or community feedback record.
Users must not attempt to reverse, reconstruct, disclose, publish, or misuse protected identifiers.
4. Individuals without a Veri-Trust account
Community feedback may concern a person who has never created a Veri-Trust account.
In that situation, Veri-Trust may process a pseudonymized identifier, ratings, reliability indicators, categories, tags, comments, timestamps, reports, translations, and moderation records relating to that person.
The person concerned does not need to be registered with Veri-Trust for the information to constitute personal data under applicable law.
Individuals without an account may exercise their rights through the Data & Review Removal Requests procedure or by contacting privacy@veri-trust.app.
5. Sources of personal data
Account, subscription, support, and rights-request data are generally obtained directly from the user or requester.
Community feedback concerning another person is obtained from Veri-Trust users who submit ratings, tags, categories, comments, or reports based on an asserted personal experience.
Technical and security data may be generated automatically when the platform is accessed or used.
Payment and subscription status information may be received from Stripe.
Translation results may be generated through a translation service when a user requests the translation of a community comment.
6. Account creation and authentication
Purpose: creating and managing user accounts, authenticating users, securing sessions, confirming email addresses, resetting passwords, and providing access to account features.
Main legal basis: performance of a contract or steps taken at the user’s request before entering into a contract, under Article 6(1)(b) GDPR.
Additional legal basis: Veri-Trust’s legitimate interests under Article 6(1)(f) GDPR in protecting accounts, preventing unauthorized access, and maintaining the security and integrity of the platform.
7. Providing searches and platform functionality
Purpose: processing search requests, matching protected identifiers, displaying permitted community feedback, applying plan limits, recording usage, and providing the functionality requested by the user.
For registered users, the main legal basis is performance of the user agreement under Article 6(1)(b) GDPR.
For limited guest access, the legal basis is Veri-Trust’s legitimate interest under Article 6(1)(f) GDPR in providing a controlled demonstration of the service, managing access, and preventing misuse.
Technical records required to prevent abuse and enforce limits are also processed on the basis of Veri-Trust’s legitimate interests in platform security, service availability, and fraud prevention.
8. Community feedback concerning registered and unregistered individuals
Purpose: allowing users to contribute structured community feedback, generating community trust indicators, helping users assess interactions, and maintaining a privacy-focused trust and safety service.
The principal legal basis is Veri-Trust’s legitimate interest under Article 6(1)(f) GDPR in operating a responsible community trust service, facilitating the sharing of relevant experience-based information, improving user awareness, and helping prevent harmful or abusive interactions.
Veri-Trust must balance these interests against the rights, interests, reasonable expectations, reputation, privacy, and fundamental freedoms of the person concerned.
This balancing requires data minimization, protected identifiers, restricted access, moderation, reporting mechanisms, removal and objection procedures, limits on content, and the prohibition of unnecessary identifying or sensitive information.
Community feedback is not processed on the assumption that the person concerned has consented to it.
9. Moderation, reports, disputes, and platform integrity
Purpose: reviewing submitted content, investigating reports, preventing harassment, identifying fabricated or abusive feedback, applying platform rules, documenting moderation decisions, and protecting users and the platform.
The principal legal basis is Veri-Trust’s legitimate interest under Article 6(1)(f) GDPR in preventing abuse, protecting privacy and safety, defending legal rights, maintaining reliable moderation, and preserving platform integrity.
Processing may also be necessary to comply with legal obligations under Article 6(1)(c) GDPR, including responding to lawful requests, handling unlawful content, preserving evidence where required, and cooperating with competent authorities.
Where necessary, information may also be processed for the establishment, exercise, or defence of legal claims.
10. Subscriptions, payments, and accounting
Purpose: creating and managing paid subscriptions, processing plan changes, verifying payment status, enabling paid features, managing cancellation, and handling billing enquiries.
The main legal basis is performance of the subscription contract under Article 6(1)(b) GDPR.
Billing, invoicing, accounting, tax, and legally required transaction records may be processed under Article 6(1)(c) GDPR to comply with legal obligations.
Fraud prevention, chargeback handling, and protection against payment abuse may also rely on Veri-Trust’s legitimate interests under Article 6(1)(f) GDPR.
11. Support, privacy requests, and legal requests
Purpose: responding to support messages, privacy requests, objections, access requests, correction requests, deletion requests, restriction requests, portability requests, removal requests, and legal enquiries.
Processing required to respond to data protection rights is based on compliance with legal obligations under Article 6(1)(c) GDPR.
General support and account-related communications may be processed under Article 6(1)(b) GDPR where they are necessary to perform the user agreement.
Veri-Trust may also rely on its legitimate interests under Article 6(1)(f) GDPR to document requests, prevent abusive or fraudulent claims, maintain evidence of its responses, and defend its legal rights.
12. Security, fraud prevention, and technical logs
Purpose: detecting suspicious activity, enforcing rate limits, preventing automated abuse, protecting authentication systems, investigating security incidents, maintaining backups, and ensuring platform availability.
The principal legal basis is Veri-Trust’s legitimate interest under Article 6(1)(f) GDPR in securing its systems, protecting users, preventing fraud, and maintaining the confidentiality, integrity, and availability of the service.
Certain security processing may also be required to comply with legal obligations under Article 6(1)(c) GDPR, including applicable data security and breach-management obligations.
13. Translation of community comments
A user may request the automatic translation of a community comment into a supported language.
The comment and limited technical instructions may be transmitted to a translation service provider for the sole purpose of generating the requested translation.
For the requesting user, the processing is carried out to provide the requested platform functionality under Article 6(1)(b) GDPR.
Where the comment concerns another individual, Veri-Trust also relies on its legitimate interest under Article 6(1)(f) GDPR in making permitted community feedback understandable to users while preserving its meaning and moderation context.
Veri-Trust may store the resulting translation to avoid repeatedly transmitting the same comment and to reduce unnecessary processing and cost.
14. Communications and optional services
Service communications necessary for account operation, security, subscriptions, moderation, or changes to essential platform terms may be sent under Article 6(1)(b), Article 6(1)(c), or Article 6(1)(f) GDPR, depending on the communication.
Optional marketing communications, where introduced, will be based on consent under Article 6(1)(a) GDPR where consent is legally required.
Consent may be withdrawn at any time without affecting processing carried out before withdrawal.
15. Cookies and similar technologies
Strictly necessary cookies or storage mechanisms may be used to provide authentication, preserve sessions, maintain security, remember essential preferences, and operate requested functionality.
Where processing of personal data through necessary technologies is involved, Veri-Trust may rely on contractual necessity or legitimate interests, depending on the purpose.
Non-essential analytics, advertising, or similar technologies will not be activated without consent where consent is required by applicable law.
Further information will be provided in the Veri-Trust Cookie Policy.
16. Legitimate-interest assessment and right to object
Where Veri-Trust relies on legitimate interests, it must identify a specific and lawful interest, determine that the processing is necessary for that interest, and balance that interest against the rights and freedoms of the person concerned.
The safeguards applied may include pseudonymization, restricted visibility, access limits, moderation, reporting tools, content rules, security logs, data minimization, removal procedures, and human review.
A person has the right to object, on grounds relating to their particular situation, to processing based on Article 6(1)(f) GDPR.
Following an objection, Veri-Trust will assess the circumstances and will stop the relevant processing unless it demonstrates compelling legitimate grounds overriding the person’s interests, rights, and freedoms, or unless the processing is required for the establishment, exercise, or defence of legal claims.
17. Information where data were not collected directly
Where community feedback concerning a person is submitted by another user, the relevant information has not been obtained directly from the person concerned.
This GDPR Information page and the Privacy Policy provide general information about the controller, categories of data, sources, purposes, legal bases, recipients, rights, and available request procedures.
Direct individual notification may not be technically possible where Veri-Trust retains only a protected hash and does not retain the raw email address or telephone number required to identify or contact the person.
Any exception to individual notification will be assessed under the conditions permitted by applicable data protection law and will not remove the person’s ability to contact Veri-Trust and exercise applicable rights.
18. Sensitive data and criminal-offence information
Users must not submit data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for identification, health data, or information concerning a person’s sex life or sexual orientation.
Users must not submit information concerning criminal convictions, criminal offences, alleged offences, police records, investigations, or accusations that a person has committed a crime.
Veri-Trust is not designed to process these categories of information and may remove, restrict, redact, or investigate content containing them.
Where a user believes that a criminal offence has occurred or that a person is in immediate danger, the user should contact the competent authorities rather than publish the allegation on Veri-Trust.
19. Trust Score and automated processing
Veri-Trust may automatically calculate a Trust Score, average rating, reliability indicator, category-level score, risk label, or similar summary from published community feedback.
These outputs are generated from structured information such as ratings, reliability values, the number of published reviews, and their applicable categories.
The score is an informational summary of community feedback. It is not an identity verification, background check, criminal-risk assessment, professional certification, or guarantee of present or future conduct.
Veri-Trust does not use the Trust Score to make a decision that produces legal effects concerning the person or similarly significantly affects that person on behalf of Veri-Trust.
Moderation, removal requests, disputes, and account sanctions may involve human review. A person may request information, correction, restriction, objection, or review through the applicable request procedure.
20. Recipients and service providers
Personal data may be accessed by authorized Veri-Trust personnel and service providers only where necessary for their assigned functions.
Service providers may include Supabase for database and authentication infrastructure, Vercel for deployment and hosting, Stripe for subscription payments, Cloudflare for security services where enabled, Google Workspace for business communications, and OpenAI or another configured provider for user-requested translation functionality.
These providers may act as processors, sub-processors, or independent controllers depending on the service and the applicable contractual relationship.
Personal data may also be disclosed where legally required, including to courts, regulators, law-enforcement bodies, tax authorities, professional advisers, or other competent authorities.
21. International data transfers
Some service providers or their sub-processors may process personal data outside France or the European Economic Area.
Where a transfer is subject to GDPR transfer restrictions, Veri-Trust will rely on an applicable transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, contractual safeguards, or another legally recognized mechanism.
Where appropriate, additional technical, organizational, or contractual safeguards may be assessed in light of the nature of the data and the destination of the transfer.
22. Data retention
Personal data is not intended to be retained indefinitely.
Retention periods are determined according to the purpose of the processing, account and subscription status, legal requirements, limitation periods, fraud and abuse risks, moderation needs, dispute handling, security requirements, and the need to protect the rights of users and affected individuals.
A detailed retention schedule for each category of processing is provided or will be provided in the Privacy Policy and the internal Veri-Trust retention register.
When data is no longer required, it may be deleted, anonymized, or isolated in a restricted archive where continued retention is legally justified.
23. Security measures
Veri-Trust applies technical and organizational measures intended to protect personal data against unauthorized access, unlawful processing, accidental loss, destruction, alteration, or disclosure.
Measures may include pseudonymization, access controls, authenticated sessions, role restrictions, rate limiting, security monitoring, audit records, encrypted communications, managed infrastructure, backups, and incident-response procedures.
No online service can guarantee absolute security. Users must also protect their credentials and promptly report suspected unauthorized access.
24. Rights of data subjects
Subject to applicable conditions and exceptions, individuals may request access to their personal data, rectification of inaccurate data, erasure, restriction of processing, objection to processing, and data portability where applicable.
Individuals may also request information about the source of their data, the purposes and legal bases of processing, recipients or categories of recipients, applicable retention periods, international transfers, and relevant automated processing.
Where processing is based on consent, the individual may withdraw consent at any time without affecting the lawfulness of earlier processing.
The right to portability generally applies only to data provided by the individual, processed by automated means, and based on consent or contract.
Rights are not absolute. Veri-Trust may retain or continue processing limited information where permitted or required for legal obligations, security, fraud prevention, the rights of others, or the establishment, exercise, or defence of legal claims.
25. Exercising your rights and identity verification
Requests may be submitted through the Data & Review Removal Requests page or by email to privacy@veri-trust.app.
The request should identify the right being exercised and provide enough information to locate the relevant data. The requester should avoid sending unnecessary identity documents or sensitive information.
Where Veri-Trust has reasonable doubts about the requester’s identity or authority, it may request proportionate additional information necessary to verify the request and prevent disclosure or deletion affecting another person.
Veri-Trust will normally respond without undue delay and within one month of receiving a complete request. This period may be extended by up to two additional months where permitted because of the complexity or number of requests. The requester will be informed of any extension and the reasons for it.
Manifestly unfounded or excessive requests may be refused or subject to a reasonable fee where permitted by law. Veri-Trust will explain the reason for such a decision and the available complaint mechanisms.
26. Complaints and supervisory authority
Individuals may first contact Veri-Trust at privacy@veri-trust.app so that the request or concern can be reviewed.
Individuals also have the right to lodge a complaint with the supervisory authority responsible for data protection in their country of habitual residence, place of work, or the place of the alleged infringement.
For Collier Consulting Company SARL in France, the competent supervisory authority is the Commission nationale de l’informatique et des libertés, commonly known as the CNIL.
Exercising this right does not affect any other administrative or judicial remedy available under applicable law.
27. Updates to this information
Veri-Trust may update this GDPR Information page to reflect changes to the platform, processing activities, providers, legal requirements, or safeguards.
The date displayed at the top of the page indicates the most recent published update.
Material changes may also be communicated through the platform or by email where appropriate.
28. Contact
Privacy and GDPR requests: privacy@veri-trust.app.
Legal and compliance requests: legal@veri-trust.app.
General contact: contact@veri-trust.app.