Privacy
privacy@valty.aiData subject rights requests, policy questions, and subprocessor inquiries.
Privacy
Effective 18 August 2026. How Valty, Inc. collects, uses, stores, and protects personal and customer data on valty.ai and the Valty platform.
Valty, Inc. (“Valty,” “we,” “us”) is a Delaware corporation based in Atlanta, Georgia. We operate valty.ai and the Valty platform, which turns security evidence into EBITDA-impacting cyber loss-exposure ranges for private-equity operating partners and their portfolio companies.
For privacy requests, write privacy@valty.ai. Postal notices may be sent to Valty, Inc., Atlanta, Georgia, United States, marked “Privacy.”
We collect the minimum data needed to run the site and the platform. Categories include:
Valty does not knowingly collect personal data from anyone under 18, or outside a business context.
We use collected data to:
Where a legal basis is required, we rely on: performance of a contract; legitimate interests in operating, securing, and improving a B2B service; consent for optional analytics cookies and marketing email; and legal obligation. Valty does not sell personal data. Valty does not use customer security evidence to train machine-learning models without explicit, documented customer consent.
Valty uses subprocessors to deliver the service. Material processors today include Google Cloud Platform (application hosting, load balancing, and secret management), Neon (database), Upstash (queue and cache), PostHog (first-party site measurement, received from our servers), Google (authentication when enabled), and, if you allow visitor identification, Apollo, which performs visitor identification and shares identifiers with its provider LiveIntent, including a visitor identifier and hashed email addresses. That identification data is not anonymous. A current list is available from privacy@valty.ai.
We require subprocessors to protect data consistent with this policy. We review them before addition and when material changes occur. Customers with an active agreement get reasonable notice of material subprocessor changes.
Valty is based in the United States. If you access the service from another country, your data may be processed in the United States and in other countries where our subprocessors operate. Where a transfer mechanism is required, we use the mechanism available under the applicable agreement or DPA.
We keep personal data only as long as needed to deliver the service or meet a legal obligation:
On request, and subject to applicable law, we delete or anonymize personal data that is no longer required.
We apply technical and organizational controls appropriate to the risk of handling customer security evidence: access management, encryption in transit and at rest, audit logging, and periodic security review. Control detail is available to customers through the authenticated workspace and security review. Valty does not hold a SOC 2 report today.
No transmission or storage system is completely secure. We will notify affected customers of a security incident affecting their data as required by law and any applicable customer agreement.
Report security concerns to security@valty.ai.
Depending on where you live, you may have the right to access personal data we hold about you; correct it; request deletion, subject to legal retention; object to or restrict certain processing; receive a portable copy of data you provided; withdraw consent where processing is based on consent; and lodge a complaint with a supervisory authority.
If you are a California resident, you may also request to know, delete, or correct personal information, and you have the right not to be discriminated against for exercising those rights. Valty does not sell personal information and does not share it for cross-context behavioral advertising.
To exercise these rights, write privacy@valty.ai. We respond within the time the applicable law requires, usually 30 days, and may take a permitted extension if the request is complex. We may need to verify your identity. Some rights may be limited by legal or contractual grounds. Authorized agents may submit requests with proof of authorization.
We may update this policy as the product, subprocessors, or the law changes. The effective date at the top of this page is the version in force. Material changes will be posted here and, for customers with an active agreement, sent to the notice email on file.
Proof matrix
Each material privacy claim maps to a stated source, a confidence level, and a required review cadence before it is treated as a buyer-facing guarantee.
Contact
Privacy
privacy@valty.aiData subject rights requests, policy questions, and subprocessor inquiries.
Legal
legal@valty.aiContract review, DPA requests, and regulatory questions.
Security
security@valty.aiSecurity incidents, vulnerability disclosure, and trust-center inquiries.