Skip to content

Privacy

Privacy Policy

Effective: Draft, pending counsel review. Governs how Valty collects, uses, stores, and protects personal and customer data in connection with the Valty platform.

1. Data we collect

Valty collects the minimum data necessary to operate the platform. Categories include:

  • Account data: Name, work email address, organization name, and role provided during registration or access request.
  • Usage data: Page interactions, feature navigation, session events, and error logs collected to operate and improve the service.
  • Customer security evidence: Controls, findings, cloud signals, supplier records, and financial context that customers upload or connect through source adapters. This data belongs to the customer and is processed only to deliver the service.
  • Communication data: Content of support requests, feedback submissions, and email correspondence with Valty.
  • Technical data: IP address, browser type, device identifiers, and cookie identifiers used for security, fraud prevention, and performance monitoring.

Valty does not knowingly collect personal data from individuals under 18 years of age or outside a business context.

2. How we use data

We use collected data to:

  • Provision, maintain, and improve the Valty platform and its features.
  • Process customer security evidence to produce risk quantification, proof packs, and evidence artifacts as instructed by the customer.
  • Authenticate users, enforce access controls, and detect unauthorized activity.
  • Send transactional communications (account setup, security alerts, service updates).
  • Send marketing communications where permitted by applicable law and subject to opt-out rights.
  • Comply with legal obligations and respond to lawful requests from government authorities.
  • Conduct internal analytics and product research, using aggregated or anonymized data where possible.

Valty does not sell personal data. Valty does not use customer security evidence to train machine-learning models without explicit, documented customer consent.

3. Subprocessors

Valty engages third-party subprocessors to deliver the service. Material subprocessors include infrastructure providers (cloud hosting and database), authentication providers, communication and email delivery services, product analytics, and error monitoring. A current subprocessor list is available on request at privacy@valty.ai.

Valty contractually requires subprocessors to maintain data protection standards consistent with this policy. Subprocessors are reviewed before addition and when material changes occur.

Subprocessor list is subject to change. Customers with active agreements will be notified of material changes with reasonable notice.

4. Retention

Valty retains personal data for as long as necessary to deliver the service or comply with legal obligations:

  • Account data: Retained for the duration of the customer relationship plus a reasonable post-termination period as required by law or contract.
  • Customer security evidence: Retained in accordance with the applicable customer agreement. Customers may export or request deletion prior to termination.
  • Usage and technical data: Typically retained for up to 24 months in operational logs; aggregated analytics may be retained longer.
  • Communication data: Retained for the duration of the customer relationship plus a reasonable period for support continuity.

Upon request and subject to applicable law, Valty will delete or anonymize personal data that is no longer required.

5. Security

Valty applies technical and organizational security controls appropriate to the risk associated with handling customer security evidence. Controls include access management, encryption in transit and at rest, audit logging, and periodic security review. Specific control detail is available to customers through the authenticated workspace and security review process.

No transmission method or storage system is completely secure. Valty will notify affected customers of a security incident affecting their data in accordance with applicable law and any applicable customer agreement.

Report security concerns to security@valty.ai.

6. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access personal data Valty holds about you.
  • Correct inaccurate personal data.
  • Request deletion of personal data, subject to legal retention requirements.
  • Object to or restrict certain processing activities.
  • Receive a portable copy of personal data you provided.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with a supervisory authority.

To exercise these rights, contact privacy@valty.ai. We will respond within a reasonable timeframe consistent with applicable law. Some rights may be limited by legitimate legal or contractual grounds.

Specific jurisdictional rights (e.g. GDPR, CCPA) will be scoped and documented by counsel before this policy is finalized.

Proof matrix

Privacy claim traceability

Each material privacy claim maps to a stated source, a confidence level, and a required review cadence before it is treated as a buyer-facing guarantee.

ClaimSourceConfidenceFreshness
Customer security evidence stays customer-ownedPlatform architecture + Terms of ServiceStructural (not contractual alone)Review on product change
Data collected is limited to what the service requiresPrivacy policy §1–§2Policy-statedQuarterly or on subprocessor change
Subprocessors are disclosed and reviewedSubprocessor list §3Point-in-timeOn addition or material change
Data subject rights honored within stated response windowsPrivacy policy §6Pending legal reviewReview before first paid customer

Contact

Reach the right team.

Privacy

privacy@valty.ai

Data subject rights requests, policy questions, and subprocessor inquiries.

Legal

legal@valty.ai

Contract review, DPA requests, and regulatory questions.

Security

security@valty.ai

Security incidents, vulnerability disclosure, and trust-center inquiries.