Verinido · VN-PRIVACY

Privacy & cookies

Review draft — not in force

These proposed documents do not replace previously accepted terms. Legal and operational review is required before activation. Reading or downloading is not acceptance.

Version: 2026-09-17.1-draft
Document date: 2026-09-17
Effective date: not set
Language: English
English drafting master: en

1. Controller and scope

Pablo Adrian Fernandez Terra, Södra Ligården 12, 425 30 Hisings Kärra, Sweden, is the proposed controller for Verinido's platform processing. Contact support@verinido.com for privacy matters. A host may separately be controller for accommodation and statutory guest-register processing. A host authorisation does not by itself settle these roles: any processing on a host's instructions requires the appropriate written arrangement. This draft must be reconciled with the actual providers and reporting configuration before activation.

2. Information and sources

Depending on the role and enabled service, data includes account and contact information, booking and property details, traveller identity and contact fields, dates of birth and legally required child/guardian details, signatures and authorisations, messages and support requests, payment references and status, verification outcomes, tax-reporting fields, partner applications, attribution, reviews, security logs and consent records. Sources include the person concerned, the booking adult, hosts, payment/verification providers and relevant official sources. Information about other travellers must be accurate and this notice made available to them. Do not send identity-document scans or bank details through ordinary support messages.

3. Purposes and legal bases

Contract necessity supports account, booking and payment administration for the relevant contracting person. Applicable legal duties support required accounting, tax and authorised traveller reporting; the specific duty and controller role must be identified for each report. Legitimate interests may support proportionate fraud prevention, security, dispute evidence and administration, subject to balancing and objection rights; contract necessity is not assumed for every accompanying traveller. Optional marketing and non-essential tracking require valid consent where applicable, which can be withdrawn. Required fields and the effect of not providing them must be explained at collection. Data is not authorised for unrelated uses merely by accepting terms.

4. Recipients and AI

Access is limited to what recipients need: the relevant host and guest, authorised personnel, contracted hosting/email/support providers, Stripe for payments and verification, and competent authorities when required and lawfully authorised. Provider roles may include independent controllership. AI features may process selected text for assistance or partner assessment; direct identifiers should be removed before partner scoring. Applicants must receive meaningful information about ranking criteria, consequences and review options before assessment. This draft does not authorise solely automated decisions with legal or similarly significant effects. A lawful decision process and effective human review must be verified before launch.

5. International processing and safeguards

If a provider processes personal data outside the EEA, the applicable transfer mechanism must be documented, such as an adequacy decision or approved contractual safeguards with necessary supplementary measures. Obtain details or a copy of relevant safeguards through support. Access controls, encryption, audit logs and data minimisation should protect information, but no system can promise absolute security. Personal certificate keys and payment-card secrets must not be uploaded to ordinary booking or support fields. The final provider and transfer register must be checked against the deployed service.

6. Retention and deletion

Keep each category only as long as necessary for its stated purpose: active account and booking administration, applicable accounting/tax or traveller-register retention, resolution of claims, and proportionate security evidence. Rejected partner applications should be deleted or anonymised after six months unless a specific lawful exception applies; a wait-list should expire after six months. Closing an account does not require deletion of records that must lawfully be retained. Payment and identity providers may have independent retention obligations. Before activation, the category-level retention schedule and deletion jobs must be confirmed; this draft does not assert that every deletion routine is already active.

7. Your rights

Subject to the GDPR's conditions, you can request access, correction, erasure, restriction and portability, object to legitimate-interest processing and direct marketing, and withdraw consent without affecting prior lawful processing. You may challenge qualifying automated decisions and request human intervention where applicable. Contact support; proportionate identity checks may be needed. Responses are normally due within one month, with a lawful extension explained if needed. You can complain to Sweden's IMY or your competent data-protection authority. Necessary processing may continue under another valid legal basis, which must be explained.

8. Cookies and changes

Essential session and security storage may support sign-in and protection. Non-essential analytics or advertising storage must not be activated before the required choice; refusing must be as accessible as accepting and withdrawal must be available. A current inventory must specify provider, purpose and lifetime before such tools are enabled. This privacy notice is information, not a blanket consent request. Material changes require appropriate notice. The version and date identify this text; historic versions must remain accessible.