Privacy
privacy@valty.aiData subject rights requests, policy questions, and subprocessor inquiries.
Privacy
Effective: Draft, pending counsel review. Governs how Valty collects, uses, stores, and protects personal and customer data in connection with the Valty platform.
Contents
Valty collects the minimum data necessary to operate the platform. Categories include:
Valty does not knowingly collect personal data from individuals under 18 years of age or outside a business context.
We use collected data to:
Valty does not sell personal data. Valty does not use customer security evidence to train machine-learning models without explicit, documented customer consent.
Valty engages third-party subprocessors to deliver the service. Material subprocessors include infrastructure providers (cloud hosting and database), authentication providers, communication and email delivery services, product analytics, and error monitoring. A current subprocessor list is available on request at privacy@valty.ai.
Valty contractually requires subprocessors to maintain data protection standards consistent with this policy. Subprocessors are reviewed before addition and when material changes occur.
Subprocessor list is subject to change. Customers with active agreements will be notified of material changes with reasonable notice.
Valty retains personal data for as long as necessary to deliver the service or comply with legal obligations:
Upon request and subject to applicable law, Valty will delete or anonymize personal data that is no longer required.
Valty applies technical and organizational security controls appropriate to the risk associated with handling customer security evidence. Controls include access management, encryption in transit and at rest, audit logging, and periodic security review. Specific control detail is available to customers through the authenticated workspace and security review process.
No transmission method or storage system is completely secure. Valty will notify affected customers of a security incident affecting their data in accordance with applicable law and any applicable customer agreement.
Report security concerns to security@valty.ai.
Depending on your jurisdiction, you may have the right to:
To exercise these rights, contact privacy@valty.ai. We will respond within a reasonable timeframe consistent with applicable law. Some rights may be limited by legitimate legal or contractual grounds.
Specific jurisdictional rights (e.g. GDPR, CCPA) will be scoped and documented by counsel before this policy is finalized.
Proof matrix
Each material privacy claim maps to a stated source, a confidence level, and a required review cadence before it is treated as a buyer-facing guarantee.
Contact
Privacy
privacy@valty.aiData subject rights requests, policy questions, and subprocessor inquiries.
Legal
legal@valty.aiContract review, DPA requests, and regulatory questions.
Security
security@valty.aiSecurity incidents, vulnerability disclosure, and trust-center inquiries.