Applicable to all subscribers regardless of country of registration, as Verdini operates under EU jurisdiction.
All personal data (names, GPS coordinates, contact details, KYB documents) collected on or through Verdini is processed in accordance with GDPR. Subscribers act as Data Controllers for their project data. Verdini acts as Data Processor. You have rights to access, rectify, erase, restrict, and port your data. Data breach notification within 72 hours is required under Art. 33. Lawful basis for processing must be documented by your organisation. Data Processing Agreement (DPA) is automatically activated upon subscription.
Subscribers using Verdini for environmental monitoring of critical infrastructure or agriculture are subject to NIS2 security obligations. Mandatory 2FA is enforced by the platform. Significant cyber incidents must be reported to relevant national CSIRT within 24 hours (early warning) and 72 hours (full report). Verdini implements security-by-design, access logging, and anomaly detection on all accounts.
All subscribing entities undergo KYB/KYC verification in accordance with AMLD5/6. Anonymous or pseudonymous accounts are not permitted. Beneficial ownership must be disclosed for entities with >25% ownership. Carbon credits and related payments are subject to AML scrutiny. Suspicious transactions are reported to relevant Financial Intelligence Units (FIUs). Verdini reserves the right to suspend accounts pending AML review.
All payments are processed with PSD2-compliant Strong Customer Authentication (SCA) via 3D Secure 2.0. This means two-factor authentication is required for every transaction. Payment data is processed by Stripe (PCI DSS Level 1). Verdini does not store raw card data. Recurring subscriptions are authorised under PSD2 mandate provisions.
Projects involving land use change, timber, or deforestation-risk commodities (cattle, soy, palm oil, cocoa, coffee, wood, rubber) must provide EUDR due diligence statements. Verdini's satellite-based virtual camera monitoring provides geolocation data required for EUDR compliance. Applicable to projects placed on the EU market or exported to the EU after December 2024.
Verdini operates as an online platform under DSA. Subscribers must not upload false, fraudulent, or misleading project data. Content moderation is applied to all publicly visible project information. Verdini is required to maintain a transparent register of content removal decisions. Subscribers have the right to appeal content moderation decisions.