01Our commitment
VeroPass was designed in Europe, for Europe. Data protection is not a layer bolted on at the end - it is a building principle, alongside record tamper-resistance and brand ownership of data. We comply with Regulation (EU) 2016/679 (GDPR) and national implementing legislation.
Data minimisation, European hosting by default and layered access are present from the very first line of code.
02Controller and processor
Our role under the GDPR depends on the context:
Note: most of a passport's data is product data, not personal. But when, for example, the first owner of an item is registered, the customer is the controller and VeroPass the processor.
03Principles we follow
- Lawfulness and transparency - we process data only on a valid basis and in a clear way.
- Purpose limitation - we do not reuse data for purposes incompatible with collection.
- Minimisation - we collect only what is necessary.
- Accuracy - we keep data correct and up to date.
- Storage limitation - we keep data only for as long as necessary.
- Integrity and confidentiality - we protect data proportionately to the risk.
04Legal bases
Each processing rests on one of the bases in Article 6 of the GDPR - performance of a contract, legitimate interest, consent or legal obligation. The detail per purpose is described in the Privacy Policy. When we act as a processor, the legal basis is set by the controlling customer.
05Data subject rights
We ensure the full exercise of the rights provided by the GDPR: access, rectification, erasure, restriction, objection and portability. When a data subject contacts us directly about data we process on behalf of a customer, we promptly forward the request to the controller and provide the necessary assistance.
06Security measures
We apply technical and organisational measures appropriate to the risk, under Article 32:
- Encryption of data in transit (TLS) and at rest.
- Access control by role, with least-privilege principle.
- Tamper-resistant audit logs - each event signed and dated.
- Backups and tested recovery plans.
- Security reviews and impact assessments where applicable.
07Data processing agreement (DPA)
For business customers, we provide a Data Processing Agreement (DPA) setting out the subject matter, duration, nature and purposes of processing, the categories of data and data subjects, and the obligations of both parties - in compliance with Article 28 of the GDPR. The DPA is signed before any processing of personal data on our part.
Request our DPA template at dpo@veropass.eu. We will also review yours, within reason.
08Sub-processors
We rely on a restricted set of sub-processors, all under contract with adequate safeguards and, wherever possible, with infrastructure in the European Union:
We give advance notice of any change to the list of sub-processors, giving the customer the opportunity to object.
09International transfers
Data is, in principle, processed and hosted in the European Union. Should a transfer outside the European Economic Area be unavoidable, we ensure adequate safeguards: an adequacy decision of the European Commission or standard contractual clauses, complemented by technical measures where necessary.
10Data breaches
We have procedures to detect, contain and assess security incidents. In the event of a personal data breach, we notify the competent supervisory authority within 72 hours, where applicable, and inform affected customers without undue delay, so they can meet their own obligations.
11Data Protection Officer
We have appointed a Data Protection Officer (DPO) responsible for overseeing compliance, responding to data subjects and serving as point of contact with the supervisory authority - in Portugal, the National Data Protection Commission (CNPD).
12How to exercise rights
To exercise any right, request the DPA or clarify a compliance question, contact our DPO directly. We respond within a maximum of one month.
Data Protection Officer
dpo@veropass.eu · VeroPass, Lda. · Lisbon, Portugal