Terms of Service

Last updated: October 2, 2026

1. Definitions

"VIESAC" (or "we", "us", "our") refers to the VIESAC service and its operator, Comet Group OÜ. "Service" means the VIESAC platform: EU and UK VAT validation, EORI number verification, audit trail storage, timestamped PDF and XML certificates, REST API, Bulk Audit tools, extensions (e.g. WooCommerce, Shopify), and related compliance features. "User" (or "you", "your") means any person or legal entity accessing or using the Service. "Official & Public Registries" means electronic databases and public records operated by tax, customs, and corporate authorities, including the European Commission's VAT Information Exchange System (VIES), His Majesty's Revenue and Customs (HMRC) Developer Hub, the EU Economic Operators Registration and Identification database (EOS DDS2), national tax authority registries (such as German and French tax interfaces, Serbian PURS, and Swiss UID registers), and verified public business records.

2. Agreement and Acceptance

By registering, accessing, or using VIESAC, you agree to these Terms of Service ("Terms"). If you are acting on behalf of an organization, you represent that you have the authority to bind that organization. If you do not agree, do not use the Service.

3. Eligibility

You must have the legal authority to bind your organization (if acting on its behalf) and use the Service in full compliance with applicable national and European Union legislation.

4. Description of Service and Compliance Boundaries

VIESAC provides:

  • EU VAT number validation via the European Commission VIES database and Member State fiscal interfaces
  • UK VAT number validation via the official UK HMRC API
  • EU and UK EORI customs status validation via the EOS DDS2 database and HMRC
  • Proprietary multi-source verification and fallback routing across national tax registries (including German, French, and other EU Member State fiscal interfaces) and public corporate records to maintain validation continuity during official gateway outages
  • National non-EU tax register lookups (including Swiss UID, Serbian PIB/PDV, and Norwegian VOEC/MVA)
  • Audit trail storage with certificates and validation history (10+ years statutory tax audit retention)
  • Tamper-evident, timestamped PDF certificates and technical XML evidence files with SHA-256 cryptographic hashes
  • Asynchronous Bulk Audit batch processing for high-volume CSV and Excel files
  • REST API, webhooks, and integrations for e-commerce, ERP, and automation workflows (WooCommerce, Shopify, Make, Zapier, Google Sheets)

The Service is designed to assist businesses with technical verification under EU VAT rules (Council Directive 2006/112/EC), VAT in the Digital Age (ViDA), UK tax and customs regulations, and general international KYB/AML compliance. VIESAC provides technical validation and evidentiary record-keeping; we do not provide tax, legal, customs, or accounting advice.

Taxpayer Responsibility: You, as the taxpayer or trader, remain solely and exclusively legally responsible for determining your tax liability, validating cross-border zero-rating (reverse charge) eligibility, preparing and submitting tax returns or recapitulative statements, and ensuring proper customs declarations. VIESAC does not guarantee that any tax administration will accept an exemption, credit, or deduction based solely on automated verification records.

5. Official Registries, Public Sources, and Government Non-Affiliation Disclaimer

To provide resilient verification and high audit completeness, VIESAC utilizes a proprietary multi-source verification engine connecting to public electronic endpoints, official APIs, national tax systems (including the UK HMRC Developer Hub, the European Commission VIES system, the EU EOS DDS2 customs register, and Member State fiscal authority endpoints like German and French tax registers), as well as open corporate datasets.

Disclaimer of Official Affiliation: VIESAC is an independent commercial platform operated by Comet Group OÜ. VIESAC is not affiliated with, associated with, authorized by, endorsed by, accredited by, or in any way officially connected to His Majesty's Revenue and Customs (HMRC), the UK Government, the European Commission, the European Union, or any national tax administration, customs agency, or public registry. Interfacing with official APIs or public data records does not constitute or imply official government partnership or accreditation.

Multi-Source Routing and Registry Availability: Official government systems and public databases may experience unscheduled outages, high latency, or routine maintenance. VIESAC employs proprietary fallback routing, asynchronous queues, and cross-referenced public records to maximize validation continuity; however, VIESAC disclaims all liability for failures, delayed responses, or data unavailability originating directly from third-party government or public data sources.

6. Usage Limits, Plans, and Bulk Audit Policy

Usage is governed by your selected plan. Each plan includes monthly allowances for validations, on-demand audits, monitoring entries, and certificate refreshes. Exceeding monthly limits will pause further validations until the next billing period or until an upgrade is completed.

Bulk Audit Policy: When processing high-volume CSV or Excel files via the Bulk Audit tool, syntactically invalid, malformed, or unprocessable rows (e.g. invalid country prefix or corrupt input structure) do not consume your monthly validation quota. Quotas are deducted exclusively for valid, actionable lookup queries processed against official registries or retrieved through active audit records.

Plan pricing and quotas are as displayed at the time of purchase; we may modify plan limits or pricing with at least 30 days' advance notice to existing subscribers.

7. Acceptable Use and AI Safety

You agree to use the Service only for lawful purposes and in compliance with these Terms. You must not:

  • Use the Service for VAT carousel fraud (MTIC fraud), tax evasion, money laundering, deceptive shell company schemes, or any illegal activity
  • Circumvent usage limits, rate limits, security measures, or access controls
  • Attempt to reverse engineer, decompile, or extract proprietary source code
  • Resell, sublicense, or provide the Service to third parties except as permitted by your specific API or Business plan
  • Transmit malware, spam, denial-of-service payloads, or abusive automated scraping requests
  • Use the Service or its generated certificates to produce synthetic misinformation, deceptive tax documentation, or deepfakes in violation of the EU AI Act (Regulation (EU) 2024/1689)
  • Scrape or extract Service data to train public artificial intelligence models without our prior written consent

We may immediately suspend or terminate accounts that violate these rules.

8. Data Ownership, EU Data Act, and Privacy

You retain full ownership of your data. We process account-registration and service data in accordance with our Privacy Policy and the EU General Data Protection Regulation (GDPR). Our primary servers are located in the European Union (Germany, Nuremberg); we do not transfer personal data outside the EU except with appropriate legal safeguards.

Data Portability under the EU Data Act: In accordance with the EU Data Act (Regulation (EU) 2023/2854), you have an unrestricted right to access, retrieve, and export all data generated through your use of the Service, including validation histories, batch audit logs, and PDF/XML evidence certificates. We provide standardized, open, and machine-readable export formats (CSV, JSON, XML, PDF) to ensure seamless data portability and prevent vendor lock-in.

Statutory Retention: Audit records, consultation numbers, and cryptographic XML evidence are retained for 10+ years to support statutory tax audit defense under EU Member State legislation and international tax compliance rules.

You act as data controller for business and validation data you submit (e.g. partner VAT numbers, customer order references); we act as data processor. For data subject requests and privacy inquiries, contact legal@viesac.eu.

9. Intellectual Property and Proprietary Technology

VIESAC, its name, logo, software architecture, verification routing algorithms, multi-source resolution engines, metadata normalization heuristics, and all related brand materials are the intellectual property and proprietary trade secrets of Comet Group OÜ or our licensors, protected under applicable intellectual property laws and Directive (EU) 2016/943 (Trade Secrets Directive). You receive a limited, revocable, non-exclusive license to use the Service in accordance with your plan. You must not attempt to reverse engineer, decompile, extract, or reconstruct our internal data pipelines, routing logic, or verification mechanics. We do not claim ownership of your business data or validation inputs; by using the Service you grant us the limited technical rights required to operate it (e.g. storing, hashing, processing, and displaying your audit records).

10. Subscription, Billing, and Easy Cancellation

Subscriptions are billed in advance (monthly or annually) via Stripe. By subscribing, you agree to Stripe's payment terms. Pricing, billing cycle, and plan entitlements are clearly stated at checkout.

Easy Cancellation: In compliance with European consumer protection standards, you may cancel your recurring subscription at any time directly through your account dashboard or billing settings with a single click, without administrative friction or cancellation penalties. Cancellation takes effect at the end of the current pre-paid billing cycle, and you retain full access to your plan and audit evidence until that date.

Refunds: Payments for past or ongoing billing periods are generally non-refundable, except where required by mandatory EU consumer law (such as the statutory 14-day right of withdrawal for initial consumer purchases, provided performance has not been fully executed with express consent). We may adjust pricing with at least 30 days' advance notice before renewal.

11. Service Availability and Fallback Mechanisms

The Service depends on official third-party systems (EU VIES, UK HMRC, EU EOS DDS2, and national tax registers). We strive to maintain 99.9% uptime for our core API and infrastructure. When an official registry undergoes an outage or returns temporary errors, VIESAC employs automated queuing, scheduled retries, and registered fallback methods. However, we cannot guarantee uninterrupted or instantaneous responses from third-party state servers.

12. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, VIESAC AND ITS OPERATOR SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING LOST PROFITS, LOST REVENUE, TAX PENALTIES, RETROACTIVE VAT OR CUSTOMS ASSESSMENTS, RECLASSIFICATION OF ZERO-RATED SUPPLIES, DATA LOSS, OR BUSINESS INTERRUPTION ARISING OUT OF OR IN CONNECTION WITH THE SERVICE. OUR TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS UNDER THESE TERMS SHALL NOT EXCEED THE TOTAL FEES PAID BY YOU TO VIESAC IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO LIABILITY.

13. Indemnification

You agree to indemnify, defend, and hold harmless VIESAC, Comet Group OÜ, its officers, employees, and agents from and against any third-party claims, liabilities, damages, losses, or legal expenses (including reasonable attorneys' fees) arising from: (a) your use or misuse of the Service, (b) your violation of these Terms or applicable tax, customs, or privacy laws, or (c) tax or customs disputes arising between your organization and any government authority.

14. Account Termination and Data Retrieval

We may suspend or terminate your account for material breach of these Terms, non-payment, or upon reasonable advance notice. You may close your account at any time via your settings. Upon termination, your right to conduct new validations ceases immediately. In accordance with the EU Data Act and GDPR, you have the right to request a full export of your existing audit records and certificates prior to account termination.

15. Artificial Intelligence and Cybersecurity Standards

In accordance with the EU Cyber Resilience Act (CRA) and NIS2 Directive, VIESAC enforces rigorous security practices, including secure code reviews, automated vulnerability scanning, and incident response procedures. Any artificial intelligence or automated engineering agents utilized in platform maintenance undergo mandatory human verification (human-in-the-loop) before code deployment. Customer validation queries, VAT/EORI numbers, and commercial transaction records are strictly confidential and are never used to train or fine-tune public artificial intelligence models.

16. Modifications to Terms

We may update these Terms from time to time to reflect operational, legal, or regulatory changes. When material modifications occur, we will notify you by email or via a prominent notification within the Service at least 30 days before the new terms take effect. Continued use of VIESAC after the effective date constitutes your agreement to the updated Terms.

17. Governing Law and Dispute Resolution

These Terms are governed by the laws of the European Union and the Republic of Estonia, without regard to conflict of law principles. Any dispute arising under or in connection with these Terms shall first be addressed through good-faith negotiation. If unresolved, disputes shall be submitted to the competent courts of Tallinn, Estonia, without prejudice to mandatory consumer jurisdiction rights under EU law.

18. Operator and Contact

Operator: Comet Group OÜ (registry code 12568148), Ida-Viru maakond, Narva linn, P. Kerese tn 5, 20309, Estonia. VAT: EE101678030. e-Business Register.

For legal, compliance, or regulatory inquiries: legal@viesac.eu.

For customer support: support@viesac.eu.