Skip to content

Privacy

Privacy Policy

Effective 18 August 2026. How Valty, Inc. collects, uses, stores, and protects personal and customer data on valty.ai and the Valty platform.

1. Who we are

Valty, Inc. (“Valty,” “we,” “us”) is a Delaware corporation based in Atlanta, Georgia. We operate valty.ai and the Valty platform, which turns security evidence into EBITDA-impacting cyber loss-exposure ranges for private-equity operating partners and their portfolio companies.

For privacy requests, write privacy@valty.ai. Postal notices may be sent to Valty, Inc., Atlanta, Georgia, United States, marked “Privacy.”

2. Data we collect

We collect the minimum data needed to run the site and the platform. Categories include:

  • Account data: Name, work email, organization, and role provided when you request access, register, or become a design partner.
  • Usage data: Page interactions, feature navigation, session events, and error logs used to operate and improve the service.
  • Customer security evidence: Controls, findings, cloud signals, supplier records, and financial context that customers upload or connect. This data belongs to the customer and is processed only to deliver the service.
  • Communication data: Support requests, feedback, and email correspondence with Valty.
  • Technical data: IP address, browser type, device identifiers, cookie identifiers, and first-party field performance signals (LCP, CLS, INP, TTFB when the browser reports them) used for security, fraud prevention, and performance.
  • Marketing-site telemetry: For human visitors, a first-party beacon may record page path, referrer, UTM parameters, viewport size, browser language and time zone, a random session identifier, and a coarse network hint derived from IP. Automation and known bots are excluded.

Valty does not knowingly collect personal data from anyone under 18, or outside a business context.

3. How we use data

We use collected data to:

  • Provision, maintain, and improve the Valty platform and marketing site.
  • Process customer security evidence to produce risk quantification, proof packs, and evidence artifacts as the customer instructs.
  • Authenticate users, enforce access controls, and detect unauthorized activity.
  • Send transactional communications (account setup, security alerts, service updates).
  • Send marketing communications where permitted by law and subject to opt-out.
  • Comply with legal obligations and respond to lawful government requests.
  • Run internal analytics and product research, using aggregated or anonymized data where we can.

Where a legal basis is required, we rely on: performance of a contract; legitimate interests in operating, securing, and improving a B2B service; consent for optional analytics cookies and marketing email; and legal obligation. Valty does not sell personal data. Valty does not use customer security evidence to train machine-learning models without explicit, documented customer consent.

4. Cookies and similar technologies

Necessary cookies keep the site working and remember your cookie choice. A first-party beacon for human visitors records page views, interactions, engagement, and, when the browser reports them, field LCP, CLS, INP, and TTFB. That beacon is not gated by the notice. Our servers also derive a daily hash from the IP address and browser user agent to count unique visitors; it rotates each UTC day. We send that same first-party measurement to PostHog, our analytics processor, from our servers; your browser never connects to PostHog, and no profile of you is built there. Optional third-party visitor identification (currently Apollo) loads only if you choose “Accept all.” “Decline” and a Global Privacy Control browser signal keep Apollo off. Closing or scrolling past the notice does not grant permission. Details live in the Cookie Policy.

5. Subprocessors and transfers

Valty uses subprocessors to deliver the service. Material processors today include Google Cloud Platform (application hosting, load balancing, and secret management), Neon (database), Upstash (queue and cache), PostHog (first-party site measurement, received from our servers), Google (authentication when enabled), and, if you allow visitor identification, Apollo, which performs visitor identification and shares identifiers with its provider LiveIntent, including a visitor identifier and hashed email addresses. That identification data is not anonymous. A current list is available from privacy@valty.ai.

We require subprocessors to protect data consistent with this policy. We review them before addition and when material changes occur. Customers with an active agreement get reasonable notice of material subprocessor changes.

Valty is based in the United States. If you access the service from another country, your data may be processed in the United States and in other countries where our subprocessors operate. Where a transfer mechanism is required, we use the mechanism available under the applicable agreement or DPA.

6. Retention

We keep personal data only as long as needed to deliver the service or meet a legal obligation:

  • Account data: For the customer relationship plus a reasonable post-termination period required by law or contract.
  • Customer security evidence: As the customer agreement states. Customers may export or request deletion before termination.
  • Usage and technical data: Typically up to 24 months in operational logs; aggregated analytics may be kept longer.
  • Communication data: For the customer relationship plus a reasonable period for support continuity.
  • Briefing requests: Request receipts expire after 90 days, and duplicate-prevention records after 24 hours. These limits do not automatically delete separate inquiry records in our lead list, CRM, email, or other communication systems. Those records may remain for follow-up and support, subject to applicable deletion requests.

On request, and subject to applicable law, we delete or anonymize personal data that is no longer required.

7. Security

We apply technical and organizational controls appropriate to the risk of handling customer security evidence: access management, encryption in transit and at rest, audit logging, and periodic security review. Control detail is available to customers through the authenticated workspace and security review. Valty does not hold a SOC 2 report today.

No transmission or storage system is completely secure. We will notify affected customers of a security incident affecting their data as required by law and any applicable customer agreement.

Report security concerns to security@valty.ai.

8. Your rights

Depending on where you live, you may have the right to access personal data we hold about you; correct it; request deletion, subject to legal retention; object to or restrict certain processing; receive a portable copy of data you provided; withdraw consent where processing is based on consent; and lodge a complaint with a supervisory authority.

If you are a California resident, you may also request to know, delete, or correct personal information, and you have the right not to be discriminated against for exercising those rights. Valty does not sell personal information and does not share it for cross-context behavioral advertising.

To exercise these rights, write privacy@valty.ai. We respond within the time the applicable law requires, usually 30 days, and may take a permitted extension if the request is complex. We may need to verify your identity. Some rights may be limited by legal or contractual grounds. Authorized agents may submit requests with proof of authorization.

9. Changes

We may update this policy as the product, subprocessors, or the law changes. The effective date at the top of this page is the version in force. Material changes will be posted here and, for customers with an active agreement, sent to the notice email on file.

Proof matrix

Privacy claim traceability

Each material privacy claim maps to a stated source, a confidence level, and a required review cadence before it is treated as a buyer-facing guarantee.

ClaimSourceConfidenceFreshness
Customer security evidence stays customer-ownedPlatform architecture + Terms of ServiceStructural (not contractual alone)Review on product change
Data collected is limited to what the service requiresPrivacy policy §2–§3Current operating policyQuarterly or on subprocessor change
Subprocessors are disclosed and reviewedPrivacy policy §5Point-in-timeOn addition or material change
Data-subject rights honored within stated response windowsPrivacy policy §8Current operating policyOn material law or product change

Contact

Reach the right team.

Privacy

privacy@valty.ai

Data subject rights requests, policy questions, and subprocessor inquiries.

Legal

legal@valty.ai

Contract review, DPA requests, and regulatory questions.

Security

security@valty.ai

Security incidents, vulnerability disclosure, and trust-center inquiries.