VERI-TRUST

Legal information

Privacy Policy

How Veri-Trust collects, uses, protects, and shares account, subscription, security, moderation, and community feedback data.

Last updated: July 2026

1. Data controller

The controller responsible for the processing described in this Privacy Policy is Collier Consulting Company SARL, which operates and develops the Veri-Trust platform.

Collier Consulting Company SARL is a French limited liability company registered in France. Its registered office is located at 128 rue La Boétie, 75008 Paris, France.

Privacy and data protection requests may be sent to privacy@veri-trust.app.

2. Scope of this Privacy Policy

This Privacy Policy applies to personal data processed through the Veri-Trust website, user accounts, search functionality, community feedback system, subscriptions, moderation tools, reporting procedures, security systems, and support channels.

It applies both to registered users and, where community feedback is associated with a protected identifier, to individuals who do not have a Veri-Trust account.

3. Categories of data processed

Veri-Trust may process account data such as an email address, internal user identifier, authentication status, account status, selected plan, subscription status, confirmation status, and account creation or update timestamps.

Veri-Trust may process usage and technical data such as search activity, action logs, timestamps, IP addresses where required for rate limiting or security, device or browser information made available through technical logs, failed requests, authentication events, and security indicators.

Veri-Trust may process community feedback data such as ratings, reliability scores, categories, tags, comments, creation timestamps, moderation status, report history, translations, and administrative decisions.

Veri-Trust may process subscription and transaction data such as the selected plan, Stripe customer identifier, Stripe subscription identifier, payment status, renewal status, cancellation status, invoice references, and related timestamps.

Veri-Trust may process correspondence and request data submitted through support, privacy, legal, moderation, reporting, objection, correction, or removal procedures.

4. Protected and hashed identifiers

A phone number or email address entered for a search or linked to community feedback may constitute personal data before it is transformed.

Veri-Trust converts eligible phone numbers and email addresses into hashed or otherwise protected identifiers for matching and lookup purposes. Hashing is a pseudonymisation measure and does not necessarily make the data anonymous under applicable data protection law.

Raw phone numbers and email addresses used for matching are not publicly displayed in search results or community feedback.

Veri-Trust must not be used to reverse, reconstruct, expose, publish, or misuse protected identifiers.

5. Community feedback concerning non-users

Community feedback may concern an individual who has not created a Veri-Trust account and who has not directly provided their information to Veri-Trust.

In such cases, Veri-Trust may process a protected or pseudonymised identifier together with ratings, reliability indicators, categories, tags, comments, timestamps, moderation records, reports, and Trust Score information concerning that individual.

The fact that a person does not have a Veri-Trust account does not automatically prevent the processing of information concerning them. Such processing must nevertheless have a valid legal basis, remain necessary and proportionate, and respect the rights and interests of the person concerned.

This Privacy Policy is made publicly available as a transparency measure. Where Article 14 of the GDPR requires Veri-Trust to provide additional individual information and no applicable exemption applies, Veri-Trust will take appropriate steps to provide that information.

Individuals who do not have an account may exercise applicable rights through the Data & Review Removal Requests procedure or by contacting privacy@veri-trust.app.

6. Account creation and authentication

Purpose: to create and administer user accounts, authenticate users, maintain secure sessions, confirm email addresses, reset passwords, manage account status, and provide access to requested platform functionality.

Data concerned: email address, user identifier, authentication status, session information, account status, confirmation information, and relevant timestamps.

Legal basis: performance of a contract or steps taken at the user’s request before entering into a contract, under Article 6(1)(b) of the GDPR.

Certain authentication and security processing may additionally be based on Veri-Trust’s legitimate interests under Article 6(1)(f) of the GDPR, including preventing unauthorised access and protecting accounts and infrastructure.

7. Searches and access to platform functionality

Purpose: to process a search requested by a user, match a protected identifier against published community feedback, return permitted results, enforce plan limits, and record the use of the requested service.

Data concerned: the identifier submitted for the search, its protected or hashed representation, user identifier where applicable, search timestamp, plan information, usage count, and technical security information.

Legal basis for registered users: performance of the service contract under Article 6(1)(b) of the GDPR.

Legal basis for guest users who deliberately request a search: steps taken at the user’s request and Veri-Trust’s legitimate interest in providing a controlled guest-access service under Articles 6(1)(b) and 6(1)(f), as applicable to the relevant processing operation.

Legal basis for processing information concerning the person searched: Veri-Trust’s and its users’ legitimate interests under Article 6(1)(f) in enabling privacy-protected access to moderated community trust information, subject to necessity, proportionality, safeguards, and the rights of the person concerned.

8. Submission and publication of community feedback

Purpose: to receive structured community feedback, associate it with a protected identifier, assess it under platform rules, publish eligible feedback, calculate trust-related indicators, and support community awareness.

Data concerned: protected identifier, rating, reliability score, category, tags, comment, timestamps, language and translation data where applicable, moderation status, and author account identifier.

Legal basis for processing the contributor’s data: performance of the platform contract under Article 6(1)(b) and Veri-Trust’s legitimate interests in maintaining an accountable feedback system under Article 6(1)(f).

Legal basis for processing data concerning the person reviewed: legitimate interests under Article 6(1)(f), namely supporting informed and cautious interactions, sharing relevant experience-based trust signals, preventing abuse, and protecting platform users.

Before relying on legitimate interests, Veri-Trust must assess whether the processing is necessary and whether the rights, freedoms, and reasonable expectations of the person concerned override those interests.

Publication is subject to safeguards including protected identifiers, content restrictions, moderation, reporting tools, access limits, removal procedures, and a prohibition on unnecessary identifying information.

9. Trust Scores and aggregated indicators

Purpose: to calculate and display aggregated trust-related indicators based on eligible published community feedback.

Data concerned: ratings, reliability scores, categories, number of reviews, publication status, timestamps, and other inputs defined in the Trust Score Methodology.

Legal basis: Veri-Trust’s legitimate interests under Article 6(1)(f) in organising published community feedback into understandable and privacy-protected indicators for platform users.

Trust Scores are informational indicators generated from available community feedback. They do not constitute identity verification, a criminal-record check, a legal finding, a guarantee of safety, or a prediction of future conduct.

Information about the calculation, limitations, weighting, minimum data requirements, and review procedure will be provided in the Trust Score Methodology.

10. Moderation, reports, disputes, and appeals

Purpose: to review submitted content, investigate reports, enforce platform rules, prevent abusive or fabricated feedback, handle disputes, document decisions, and provide an appeal or reconsideration procedure.

Data concerned: review content, report reasons, account identifiers, protected identifiers, communications, supporting context, moderation decisions, internal notes, timestamps, and audit records.

Legal basis: Veri-Trust’s legitimate interests under Article 6(1)(f) in protecting users, ensuring platform integrity, preventing abuse, and establishing, exercising, or defending legal claims.

Where a specific legal duty requires content review, preservation, disclosure, restriction, or removal, processing may instead be based on compliance with a legal obligation under Article 6(1)(c).

Moderation decisions are not intended to produce legal effects comparable to a judicial or governmental decision.

11. Security, rate limiting, and fraud prevention

Purpose: to secure accounts and infrastructure, prevent unauthorised access, detect suspicious activity, enforce rate limits, investigate abuse, prevent fraud, and protect Veri-Trust, its users, and third parties.

Data concerned: IP address where necessary, timestamps, action type, authentication events, technical logs, failed attempts, account status, usage activity, security indicators, and related audit information.

Legal basis: Veri-Trust’s legitimate interests under Article 6(1)(f) in maintaining a secure, reliable, and abuse-resistant service.

Where security processing is required by applicable law, the legal basis may be compliance with a legal obligation under Article 6(1)(c).

12. Subscriptions, billing, and payments

Purpose: to create and manage paid subscriptions, initiate Stripe checkout, maintain access rights, process renewals and cancellations, handle failed payments, provide billing support, and reconcile subscription status.

Data concerned: user identifier, email address where transmitted to the payment provider, selected plan, Stripe customer and subscription identifiers, payment status, renewal and cancellation status, invoice references, and transaction timestamps.

Legal basis for subscription administration: performance of a contract under Article 6(1)(b) of the GDPR.

Legal basis for accounting, tax, invoicing, anti-fraud, and legally required financial records: compliance with legal obligations under Article 6(1)(c).

Stripe processes payment information according to its own applicable privacy documentation and may act as a processor or independent controller depending on the relevant processing activity. Veri-Trust does not directly store full payment card details.

13. Privacy, legal, support, and removal requests

Purpose: to respond to questions, exercise-of-rights requests, objections, correction requests, deletion requests, removal requests, legal notices, complaints, and support enquiries.

Data concerned: contact details, request type, identifier concerned, message content, supporting context, verification information where necessary, communications, outcome, and timestamps.

Legal basis: compliance with legal obligations under Article 6(1)(c), performance of the service contract where the request concerns an account or subscription under Article 6(1)(b), and legitimate interests under Article 6(1)(f) in handling disputes and protecting legal rights.

Veri-Trust will request only the information reasonably necessary to understand, verify, and process the request. Users should not submit unnecessary identity documents or sensitive information unless specifically required through a secure procedure.

14. Legal compliance and authorities

Purpose: to comply with applicable laws, binding court orders, valid regulatory requests, tax and accounting obligations, consumer protection duties, and other enforceable legal requirements.

Data concerned: the information necessary for the relevant obligation, request, investigation, claim, or proceeding.

Legal basis: compliance with a legal obligation under Article 6(1)(c).

Where disclosure is not legally mandatory but is necessary to establish, exercise, or defend legal claims, Veri-Trust may rely on its legitimate interests under Article 6(1)(f), subject to applicable law.

15. Optional communications and non-essential technologies

Veri-Trust does not rely on consent where processing is necessary to provide the requested service, administer an account, secure the platform, or comply with legal obligations.

Where Veri-Trust introduces optional marketing communications, analytics technologies, advertising technologies, or other non-essential cookies requiring consent, the legal basis will be the user’s consent under Article 6(1)(a).

Consent must be freely given, specific, informed, and unambiguous. It may be withdrawn at any time without affecting processing carried out before withdrawal.

Further information will be provided in the Cookie Policy and, where applicable, through the cookie preference interface.

16. Special-category and criminal-offence data

Users must not submit information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for unique identification, health data, or information concerning a person’s sex life or sexual orientation.

Users must not submit allegations, records, or detailed information concerning criminal convictions, criminal offences, police records, investigations, or security measures.

Veri-Trust does not design the community feedback system for processing special-category data under Article 9 of the GDPR or criminal-offence data under Article 10.

Such content may be blocked, restricted, redacted, or removed when detected, except where processing is strictly required and permitted by applicable law.

17. Service providers and recipients

Personal data may be made available only to recipients who require it for the relevant purpose, subject to contractual, technical, organisational, or legal safeguards.

These recipients may include authorised Veri-Trust administrators and moderators, hosting and deployment providers, authentication and database providers, payment providers, security and anti-abuse providers, email or communication providers, translation or language-processing providers where enabled, professional advisers, and competent authorities where legally required.

Current technical providers may include Vercel, Supabase, Stripe, Cloudflare, Google Workspace, and OpenAI where the relevant feature is enabled.

The inclusion of a provider in this list does not mean that every provider receives every category of personal data.

18. International data transfers

Some service providers may process or make data accessible outside the European Economic Area.

Where an international transfer is subject to Chapter V of the GDPR, Veri-Trust will rely on an applicable transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or another legally recognised safeguard.

Where required, Veri-Trust will assess the circumstances of the transfer and implement supplementary contractual, technical, or organisational measures.

Additional information about applicable transfer safeguards may be requested from privacy@veri-trust.app.

19. Data security

Veri-Trust applies technical and organisational measures intended to protect personal data against unauthorised access, disclosure, alteration, loss, destruction, or misuse.

Measures may include access controls, authentication safeguards, protected identifiers, server-side authorisation, role-based permissions, rate limits, audit logs, moderation controls, encrypted communications, provider security controls, and operational monitoring.

No online service can guarantee absolute security. Users must protect their credentials and report suspected account compromise or security incidents without delay.

20. Data retention periods

Veri-Trust applies the retention periods described below. A shorter or longer period may apply where deletion is requested, the data is no longer necessary, a legal obligation requires retention, a dispute or investigation is ongoing, or the data is required for the establishment, exercise, or defence of legal claims.

Active account data: account information required to provide the service is retained for the duration of the active account and subscription relationship.

Inactive accounts: an account that has not been used for 24 consecutive months may be classified as inactive. Veri-Trust may notify the account holder before deactivation or deletion. Unless continued retention is justified, inactive account data will be deleted or anonymised no later than 3 months after the inactivity notice or the decision to close the inactive account.

Account closure and deletion: when an account is deleted, access is disabled without undue delay. Account information that is not required for another lawful purpose is deleted from the active database within 30 days. Limited records may remain in restricted archives for the periods specified below.

Authentication and session data: active session information is retained only for the duration necessary to maintain and secure the session. Password reset and email confirmation tokens are retained until they expire or are used, and in any event for no longer than 30 days unless managed under a shorter provider-defined expiry period.

Search and usage records: identifiable search and usage logs associated with a registered user are retained for a maximum of 12 months from the relevant action, unless a shorter period is sufficient or the record is required for an active security, abuse, moderation, or legal investigation.

Guest-search and rate-limit records: IP addresses and records used solely to enforce short-term guest limits or request limits are retained for a maximum of 30 days. Records linked to detected abuse, fraud, circumvention, or security incidents may be transferred to security records and retained for the applicable security period.

General technical and security logs: authentication logs, administrative access logs, failed-request logs, security-event records, and infrastructure audit logs are normally retained for a rolling period of 12 months. Logs that are not required for security or investigation purposes may be deleted earlier.

Published community feedback: published reviews, ratings, tags, comments, translations, and associated protected identifiers are retained for a maximum initial period of 3 years from publication. At the end of that period, the content must be reviewed, removed, anonymised, or retained for a new limited period where continued publication remains necessary, proportionate, accurate enough for the stated purpose, and compatible with the rights of the person concerned.

Updates to community feedback: where a published review is materially updated or reconsidered following a substantiated report, the 3-year review period may run from the date of the latest substantive moderation decision. A purely technical modification does not automatically restart the retention period.

Rejected or withdrawn feedback: feedback that is rejected before publication, withdrawn by its author, or removed because it is unnecessary or non-compliant is deleted from the active feedback system within 30 days, unless limited retention is required for moderation, abuse prevention, legal compliance, or dispute handling.

Reports, moderation decisions, appeals, and dispute records: reports, moderation history, appeal records, internal decision records, and related communications may be retained for 5 years after the final closure of the relevant moderation or dispute procedure. Information that is not necessary to document or defend the decision should be deleted earlier.

Account sanctions and abuse-prevention records: records of warnings, suspensions, bans, fraudulent activity, coordinated abuse, circumvention attempts, or serious platform-rule violations may be retained for 5 years after the end of the sanction or the last relevant incident. A minimal exclusion record may be retained for the same period where necessary to prevent the immediate recreation of abusive accounts.

Subscription administration data: operational subscription data is retained for the duration of the subscription and for 5 years after its termination, cancellation, or expiry where necessary for contractual evidence, customer support, payment disputes, or legal claims.

Invoices, accounting records, and legally required financial documents: accounting documents, invoices, transaction evidence, and associated legally required records are retained for 10 years from the end of the relevant financial year or for any longer period required by applicable law.

Failed payments and chargeback records: records necessary to manage payment failures, refunds, disputes, fraud, or chargebacks may be retained for 5 years after the final resolution of the relevant payment event, without prejudice to longer mandatory accounting retention periods.

Privacy and data-subject-rights requests: access, rectification, erasure, restriction, objection, portability, and other privacy-request files are retained for 5 years after the request is finally closed. Identity-verification documents, where exceptionally required, are deleted as soon as the verification is complete and normally within 30 days unless they are required for an active dispute or legal obligation.

Removal requests and legal notices: requests concerning review removal, unlawful content, defamation, privacy, or legal rights, together with the response and decision record, may be retained for 5 years after final closure of the request.

General support communications: support correspondence that is not part of a legal, billing, security, moderation, or privacy file is retained for a maximum of 3 years after the request is closed.

Translation data: translations and detected-language information associated with community feedback are retained for the same period as the underlying review. When the underlying review is deleted, the related translation should also be deleted, subject to temporary backup retention.

Cookie and preference records: records of consent or refusal relating to non-essential cookies are retained according to the Cookie Policy. Veri-Trust currently intends to retain such choices for 6 months before requesting a new choice where appropriate.

Backups: deleted information may remain in encrypted or access-restricted technical backups for a maximum of 90 days before being overwritten or permanently removed through the normal backup rotation. Backups must not be used to restore deleted data into active production systems except where necessary for disaster recovery, security, or legal compliance.

Legal holds and active proceedings: where information is necessary for an active complaint, investigation, litigation, regulatory request, fraud investigation, or the establishment, exercise, or defence of legal claims, deletion may be suspended for the duration of the relevant matter. Access must remain restricted and the data must be reviewed once the matter ends.

Deletion and anonymisation: at the end of the applicable period, information is deleted, irreversibly anonymised, or placed outside active use where continued restricted retention is legally required. Pseudonymised or hashed information is not treated as anonymous unless re-identification is no longer reasonably possible.

Periodic review: Veri-Trust will periodically review the continued necessity of retained information, with particular attention to community feedback concerning individuals who do not have an account, security records, moderation records, and data processed on the basis of legitimate interests.

21. Rights of registered users and other individuals

Subject to applicable conditions and exceptions, a person may request access to personal data concerning them, rectification of inaccurate data, erasure, restriction of processing, data portability, or information about the processing.

Where processing is based on consent, the person may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Where processing is based on legitimate interests under Article 6(1)(f), the person may object at any time on grounds relating to their particular situation.

Following an objection, Veri-Trust must stop the relevant processing unless it demonstrates compelling legitimate grounds that override the person’s interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defence of legal claims.

The right to data portability generally applies only where processing is based on consent or contract and is carried out by automated means.

Rights are not absolute. A request may be limited or refused where permitted by law, including where information must be retained to protect the rights of others, prevent fraud or abuse, comply with a legal obligation, or establish, exercise, or defend legal claims.

22. Exercising privacy rights

Privacy rights may be exercised through the Data & Review Removal Requests page or by emailing privacy@veri-trust.app.

The request should identify the right being exercised, provide sufficient information to locate the relevant data, and explain any relevant circumstances.

Veri-Trust may request proportionate additional information where reasonably necessary to confirm the identity or authority of the requester and prevent fraudulent access or deletion.

Veri-Trust will respond within the period required by applicable data protection law. Where legally permitted, that period may be extended for complex or numerous requests, in which case the requester will be informed.

23. Complaints

Individuals may contact Veri-Trust first so that the request or concern can be reviewed.

Individuals also have the right to lodge a complaint with the competent data protection supervisory authority, particularly in the country of their habitual residence, place of work, or the place of the alleged infringement.

For Collier Consulting Company SARL in France, the competent supervisory authority is the Commission Nationale de l’Informatique et des Libertés, subject to the rules determining supervisory competence under the GDPR.

24. Automated processing and human review

Veri-Trust may use automated rules to calculate aggregated indicators, enforce usage limits, identify potentially prohibited content, prioritise moderation, or detect suspicious activity.

Veri-Trust does not intend these automated operations, by themselves, to make decisions producing legal effects or similarly significant effects concerning an individual within the meaning of Article 22 of the GDPR.

Where a moderation or account decision materially affects a user, Veri-Trust may provide an appropriate review or appeal mechanism as described in the Moderation Policy.

25. Changes to this Privacy Policy

Veri-Trust may update this Privacy Policy to reflect legal, technical, organisational, or product changes.

The updated version will be published on this page with a revised update date. Where required by law, Veri-Trust will provide additional notice or request renewed consent.

26. Contact

Privacy and data protection requests: privacy@veri-trust.app

Legal and compliance requests: legal@veri-trust.app

General support: support@veri-trust.app

Website: https://veri-trust.app