Privacy Policy
Last updated: October 2, 2026
1. Introduction
VIESAC ("we", "us", "our") operates the VIESAC service: EU and UK VAT validation, EORI number verification, audit trail storage, timestamped PDF and XML certificates, REST API, Bulk Audit tools, and related compliance features. We take your privacy seriously and comply with the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), the EU Data Act (Regulation (EU) 2023/2854), and the EU AI Act (Regulation (EU) 2024/1689). Our primary production servers are located in the European Union (Germany, Nuremberg). We do not transfer personal data outside the EU except where necessary for specific contracted services (such as payment processing) under appropriate legal safeguards.
2. Data We Collect and Process
2.1 Account and Profile Data
When you register and manage your account, we process:
- Name, first name, last name, and business email address
- Password (stored in securely hashed form using modern cryptographic standards)
- Company name, company registration number, tax identifiers (VAT/EORI), business address, and phone number (optional)
- Language preferences and timezone settings
- If you sign in via OAuth (Google, Microsoft): provider identifier, email, and display avatar
Purpose: Account creation, authentication, security, customer support, and service delivery. Legal basis: Contract performance (Art. 6(1)(b) GDPR).
2.2 VAT & EORI Numbers You Add (Requester Identifiers)
We store your organization's VAT and EORI numbers that you configure in your profile for use as requester identifiers in official validation queries.
Purpose: Submitting qualified VAT validation requests to official registries and embedding requester proof in certificates. Legal basis: Contract performance (Art. 6(1)(b) GDPR).
2.3 Validation, Bulk Audit, and Audit Trail Data
For each verification performed (via web app, Bulk Audit CSV/Excel upload, REST API, or e-commerce integrations), we store:
- Validated tax or customs identifier (VAT number, UK VAT, EU/UK EORI, Serbian PIB, Swiss UID) and country code
- Company legal name, trading address, and registration status as returned by official government registries
- Order number, invoice reference, and internal notes (if provided by you)
- Requester tax ID, consultation number, unique reference identifier, validation timestamp, and verification channel
- Tamper-evident PDF certificate paths and technical XML evidence payloads containing cryptographic SHA-256 hashes
Purpose: Creating and preserving statutory audit trails, generating compliance certificates, and defending cross-border VAT zero-rating and customs declarations. Certificates and audits are stored for 10+ years for statutory tax compliance. Legal basis: Contract performance (Art. 6(1)(b) GDPR); legitimate interest in statutory tax compliance and audit defense (Art. 6(1)(f) GDPR).
Role: You act as the data controller for customer and counterparty data submitted for validation; VIESAC acts as a data processor.
2.4 API Keys and Usage
If you generate API keys, we store secure cryptographic hashes and usage metadata (request volumes, error rates, timestamps). We never store raw API keys in plain text.
Purpose: API authentication, rate limiting, and infrastructure protection. Legal basis: Contract performance (Art. 6(1)(b) GDPR).
2.5 Integration Data (Google Sheets, WooCommerce, Shopify, Make)
When you use our integrations, the connector transmits selected tax identifiers and associated business references directly to the VIESAC API to perform validation and record audit proof. We only access the fields required to execute the requested check. We do not inspect unrelated customer records or broader databases.
Purpose: Automated workflow verification and audit evidence creation. Legal basis: Contract performance (Art. 6(1)(b) GDPR).
2.6 Payment and Subscription Data
Payments are handled securely by Stripe. We store Stripe customer tokens, subscription status, plan tier, and renewal dates. We do not store or process complete credit card numbers on our infrastructure. Stripe privacy policy: stripe.com/privacy.
Purpose: Billing, subscription management, and tax invoicing. Legal basis: Contract performance (Art. 6(1)(b) GDPR) and legal obligations under tax law (Art. 6(1)(c) GDPR).
2.7 Support Correspondence
When you contact our support or compliance desk, we process your email address, message body, transaction references, and attached error logs.
Purpose: Resolving technical inquiries and maintaining service quality. Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) or contract performance (Art. 6(1)(b) GDPR).
2.8 Technical, Security, and Log Data
We collect standard connection logs, IP addresses, user agent details, and session tokens to ensure service security, detect brute-force attacks, and maintain operational stability. See our Cookie Policy for detailed cookie usage.
Purpose: Cyber resilience, fraud prevention, and operational debugging. Legal basis: Legitimate interest (Art. 6(1)(f) GDPR).
2.9 Optional Analytics Data
If you explicitly grant consent via our cookie banner ("Accept all"), we use Google Analytics to analyze aggregated traffic trends and page interactions. Analytics scripts remain blocked until consent is given, and consent can be revoked at any time via Cookie settings.
Purpose: Website performance optimization. Legal basis: Consent (Art. 6(1)(a) GDPR).
2.10 Multi-Source Resolution, Normalization, and AI Safeguards
To ensure maximum audit trail completeness and resilience during periods of official registry downtime or when primary government responses return placeholder strings or lack structured details, VIESAC utilizes a proprietary multi-tier resolution engine. This technology cross-references official national tax registries (such as German and French tax authority endpoints), official gazettes, and verified public corporate data repositories to normalize company addresses, verify trading names, and confirm registration status.
Proprietary Technology & Trade Secrets: All multi-source routing heuristics, data enrichment pipelines, and parsing algorithms constitute proprietary trade secrets of Comet Group OÜ protected under Directive (EU) 2016/943. Processing is strictly deterministic and objective, performed solely to construct compliant evidence records for statutory tax defense without public disclosure of internal architecture.
AI Confidentiality Guarantee: In accordance with the EU AI Act (Regulation (EU) 2024/1689) and GDPR: your validation queries, counterparty VAT/EORI numbers, company trade names, customer order references, and audit logs are strictly confidential and are NEVER used to train, retrain, or fine-tune public artificial intelligence models or large language models (LLMs). Any internal AI-assisted developer tools or automated support triage operate under enterprise Data Processing Agreements (DPAs) with strict zero-data-retention guarantees.
3. Recipients and Third-Party Registries
We share data only with trusted entities necessary to deliver the Service:
- Official Tax and Customs Registries:
- European Commission VIES (EU VAT validation)
- UK HMRC Developer Hub (UK VAT and EORI validation)
- EU EOS DDS2 (Economic Operators Registration and Identification customs database)
- National tax administration interfaces (including German, French, and other EU Member State fiscal endpoints)
- National registries including Serbian PURS and Swiss UID registers
- Public Corporate Registries and Open Data Repositories: Cross-referenced solely to normalize addresses and verify legal entity status for audit certificates.
- Hosting and Infrastructure: Dedicated servers in the EU (Germany, Nuremberg) with strict physical and network security.
- Stripe: Payment processing under Standard Contractual Clauses (SCCs) for cross-border compliance.
- Transactional Mail Services: For delivery of verification alerts, receipts, and system notices.
- OAuth Identity Providers: Google, Microsoft (solely to complete requested single sign-on authentication).
- Google Analytics: Aggregated web metrics (strictly conditional upon your explicit consent).
We never sell, rent, or trade your personal or business data.
4. Retention and EU Data Act Portability
We retain data according to strict purpose and statutory retention rules:
- Account profile data: Retained for the lifetime of your account, plus standard backup cycles.
- Audit trails, certificates, and evidence hashes: Retained for 10+ years to support statutory tax audit defense under EU Member State fiscal laws and VAT Directive requirements.
- Support correspondence: Retained for up to 3 years to maintain service records and audit logs.
- Technical server logs: Retained for up to 90 days for cybersecurity and diagnostics.
Data Portability under the EU Data Act (Regulation (EU) 2023/2854): As a user of VIESAC, you retain complete rights over the data generated by your operations. You can export all your audit trails, validation logs, and PDF/XML certificates at any time directly through your dashboard or via API in open, structured, machine-readable formats (CSV, JSON, XML, PDF). We impose no switching fees or technical barriers preventing data transfer.
5. Security and Cyber Resilience
In accordance with the EU Cyber Resilience Act (CRA) and NIS2 Directive (Directive (EU) 2022/2555), we implement comprehensive technical and organizational safeguards:
- End-to-end TLS 1.3 encryption for all data in transit; robust AES-256 encryption at rest.
- Cryptographic SHA-256 hashing of raw registry responses to guarantee non-repudiation and tamper-evident audit defense.
- Secure Software Development Lifecycle (SSDLC) featuring automated vulnerability scanning, dependency auditing, and strict human review (human-in-the-loop) for all production code and automated agents.
- Principle of least privilege, strict multi-factor access controls, and rapid incident response protocols.
6. Your Rights under GDPR and EU Law
Under GDPR and EU data legislation, you have the right to:
- Access: Request a complete copy of your personal and account data.
- Rectification: Correct inaccurate or incomplete account details.
- Erasure: Request deletion of your personal data ("right to be forgotten"), subject to statutory tax retention requirements.
- Restriction: Restrict processing under certain legal conditions.
- Data Portability: Receive and export your data in a structured, commonly used, and machine-readable format under GDPR and the EU Data Act.
- Objection: Object to processing based on legitimate interests.
- Withdraw Consent: Revoke consent for optional cookies or marketing communications at any time.
To exercise your rights, contact our Data Protection and Legal team at legal@viesac.eu. We respond within one month. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local EU supervisory authority.
7. Automated Decision-Making, AI Transparency, and Trade Secrets
In accordance with GDPR Article 22 and the EU AI Act (Regulation (EU) 2024/1689), we do not perform automated decision-making or profiling that produces legal or similarly significant effects on natural persons. Registry lookups, syntax parsing, and certificate generation are deterministic technical verifications. Any AI assistance used in informational guides or customer support is transparently labeled and subject to human editorial review.
In accordance with Directive (EU) 2016/943 on the protection of undisclosed know-how and business information (trade secrets), VIESAC's proprietary multi-source routing algorithms, internal fallback mechanisms, and metadata resolution pipelines remain protected proprietary technology of Comet Group OÜ.
8. Policy Updates and Notification
We may update this Privacy Policy to reflect evolving regulatory requirements or service enhancements. When material updates are made, we will notify you via email or prominent service notice at least 30 days before changes become effective. The "Last updated" date at the top indicates the current effective version.
9. Data Controller and Contact
Data Controller: Comet Group OÜ (registry code 12568148), Ida-Viru maakond, Narva linn, P. Kerese tn 5, 20309, Estonia. VAT: EE101678030. e-Business Register.
For data privacy requests, GDPR compliance, or legal notices: legal@viesac.eu.