Privacy & Cookie Policy
Last updated: June 8, 2026. This policy describes how personal data is processed in compliance with the European Union General Data Protection Regulation (GDPR, EU Regulation 2016/679).
1. Data Controller
The Data Controller of the personal data collected through this application is:
2. Nature of the Service and Zero-Knowledge Principle
Verifybit is designed to guarantee the maximum confidentiality and privacy of the user's documents:
-
Zero-Knowledge Hashing: The calculation of the cryptographic fingerprint (SHA-256 hash) of your files takes place locally inside your browser. The original file **never leaves your device** during standard operations.
-
No File Storage: Our server does not store in any database nor keep on disk the files submitted for notarization. We exclusively receive the cryptographic hash (SHA-256) to register it on the Bitcoin blockchain. If a file is uploaded to the server to facilitate processing, it is **permanently and immediately deleted** as soon as the hash calculation is complete.
3. Types of Data Processed and Purposes
We process exclusively the personal data strictly necessary to provide the service:
Data voluntarily provided by the user
-
Email Address: Collected during registration to create your personal account, enable login, manage credit balances for notarization, and send you transactional notifications (e.g., password reset or notarization confirmation).
-
Billing Data (optional for professionals/businesses): Company Name, VAT number / Tax ID, PEC address, SDI recipient code, billing address. This data is used solely to comply with bookkeeping and tax obligations for issuing invoices.
Navigation and statistical data
-
Google Analytics (with anonymization): If you consent via the cookie banner, we collect anonymous and aggregated statistical data about visits (e.g., pages visited, browser used, approximate geographic area) to monitor portal operations and improve usability.
4. Legal Basis of the Processing
The processing of your data is based on the following legal grounds:
-
Execution of a contract: For managing your account, credits, and executing the blockchain notarization service.
-
Compliance with legal obligations: For billing and mandatory tax compliances.
-
Consent of the data subject: For activating third-party analytical cookies (Google Analytics). Consent can be revoked at any time by clearing cookies from your browser.
5. Data Retention Period
-
Account data (email and credits) are retained as long as the account remains active. In case of a deletion request by the user, the data will be removed within 30 days, except for billing and tax data which must be retained for 10 years by law.
-
The cryptographic footprint (hash) of files registered on the Bitcoin blockchain is immutable and is part of a global public ledger not controlled by the Data Controller. The hash does not contain personal data, and it is impossible to reconstruct the original file from the hash.
6. User Rights (GDPR)
In accordance with articles 15-22 of the GDPR, you have the right to:
- Access your personal data in our possession.
- Request the rectification of inaccurate data or the integration of incomplete ones.
- Request deletion (right to be forgotten) of your account and associated data.
- Request restriction of processing or object to it for legitimate reasons.
- Obtain the portability of your data in a structured, readable format.
To exercise these rights, you can send a written request by email to: dorian.carollo@gmail.com.
7. Cookie Policy
This site uses cookies to improve the browsing experience. Cookies are small text files saved on your device.
Types of cookies used
-
Technical (Session) Cookies: Essential to enable authentication to the private area and for portal security (e.g., CSRF protection). Without them, the application could not function. These cookies do not require prior user consent.
-
Analytical Cookies (Google Analytics 4): Third-party cookies used to analyze users' interactions on the site anonymously and in aggregate. They are activated **exclusively** if the user clicks 'Accept all' in the cookie banner.
How to manage cookies
You can change cookie preferences or disable them entirely directly from your browser settings (Chrome, Firefox, Safari, Edge, etc.). Note that disabling technical cookies may compromise your ability to log in and use the private area of the portal.