Privacy Policy
Last updated: 8 July 2026 · Version 1.2
This English text is a translation provided for information only. In the event of any discrepancy, the German Datenschutzerklärung prevails.
With this privacy policy we inform you about the processing of personal data pursuant to Art. 13 and 14 GDPR when you use
- our public website at valiro.ai (marketing website), and
- our platform — the desktop web application (app.valiro.ai) and the browser-based mobile app (together “Valiro”, “platform” or “service”).
1. Controller
The controller within the meaning of the GDPR is:
Valiro Solutions UG (haftungsbeschränkt) Eduard-Kandl-Str. 23 82211 Herrsching am Ammersee Germany
represented by its managing director Olga Ryannel Munich Local Court (Amtsgericht München), HRB 311011
Email: info@valiro.ai · Website: www.valiro.ai
Data protection contact: info@valiro.ai
Data protection officer. No data protection officer has been appointed, as the requirements of Art. 37 GDPR / Sec. 38 BDSG are not currently met.
2. Controller or Processor
Valiro is aimed exclusively at businesses (B2B). For data processing, two roles must be distinguished:
-
Valiro as controller. For the processing described in this policy we are the controller, in particular for visits to the website, the provision and technical operation of the platform, registration and management of the user account, contract handling and billing, and communication with our customers.
-
Valiro as processor. Content that a customer enters into the platform (e.g. projects, tasks, documents, messages, and any personal data of third parties contained therein, such as the customer’s employees or end customers) is processed by us exclusively on behalf of and on the instructions of the respective customer. The customer is the controller for this. The basis is the data processing agreement (DPA, available at valiro.ai/avv). Informing the data subjects (e.g. employees) is the responsibility of the customer as employer or controller.
3. Legal Bases for Processing
The legal basis is Art. 6(1)(a) GDPR (consent), (b) (contract/pre-contractual measures), (c) (legal obligation) or (f) (legitimate interest). A summary per processing activity:
| Processing | Area | Legal basis |
|---|---|---|
| Delivery, server log files, IT security | Website + platform | Art. 6(1)(f) |
| Contact / demo appointment booking | Website | Art. 6(1)(b), (f) |
| Registration, user account, authentication | Platform | Art. 6(1)(b) |
| Provision and operation of the application | Platform | Art. 6(1)(b) |
| AI features (search, assistance) | Platform | Art. 6(1)(b) |
| Map function / address geocoding | Platform | Art. 6(1)(b) |
| Payment processing | Platform | Art. 6(1)(b), (c) |
| Transactional emails | Platform | Art. 6(1)(b) |
| Reach measurement (Umami, anonymous) | Website + platform | Art. 6(1)(f) |
| IT security, abuse prevention | Website + platform | Art. 6(1)(f) |
| Product improvement (anonymized only) | Platform | Art. 6(1)(f) |
| Own advertising, reference listing | Website + platform | Art. 6(1)(f) |
4. Categories of Data Processed
- Master data: name / display name, where applicable organization and place of work.
- Contact data: business email address, where applicable phone number and address.
- Access and authentication data: login identifier, password (only as a secure hash), where applicable 2-factor secret.
- Usage and log data: IP address, timestamp, device and browser information, activity and log data.
- Content data [platform]: projects, work packages, tasks, documents, messages, comments and information contained therein (processing on behalf, cf. section 2). This also includes inputs and outputs of the AI features as well as address and location data for geocoding.
- Contract and billing data: plan, order and invoice data (card data is collected exclusively by the payment service provider, not by us).
For user accounts we generally collect only business contact data of users, not private data. Special categories under Art. 9 GDPR are not subject to processing.
5. Recipients and Processors
To provide the service we use carefully selected service providers who process personal data on our behalf pursuant to Art. 28 GDPR. A data processing agreement is in place with each of them.
| Service provider | Registered office / location | Purpose | Basis / third country |
|---|---|---|---|
| Hetzner Online GmbH, Gunzenhausen | Germany (EU) | Hosting, database, file storage, backups | EU/EEA — no third-country transfer |
| Cloudflare Germany GmbH, Munich (Cloudflare, Inc., USA) | Germany (EU); global (CDN) | DNS as well as delivery and protection of the public website (landing page); for the platform DNS only | US group affiliation: EU-US DPF, supplemented by EU SCC + TIA |
| EDEN AI SAS (DATAGENIUS), Villeurbanne | France (EU) | AI gateway: orchestration of language model (chat) and embeddings | EU/EEA; model provider see next row |
| Google (Gemini) via EdenAI — Google Ireland Ltd.; processing via Google Vertex AI (EU multi-region) | EU | AI model processing of transmitted inputs via EdenAI’s EU endpoint (routing only via EU-capable providers) | EU/EEA — no third-country transfer |
| Google Maps Platform — Google Ireland Ltd. / Google LLC | USA | Address autocomplete (Places API) and geocoding (Geocoding API) | USA: EU-US DPF, supplemented by EU SCC + TIA |
| Stripe Payments Europe, Ltd., Dublin | Ireland (EU) | Payment and subscription processing | EU contractual partner; Stripe, Inc. (USA): EU-US DPF, supplemented by SCC |
| Brevo GmbH, Berlin | Germany (EU) | Sending of transactional emails (SMTP) | EU/EEA |
We host our fonts and other assets ourselves on our own infrastructure (Hetzner); no data is transferred to third parties (e.g. Google Fonts) for this purpose. Reach measurement is carried out with self-operated software (Umami) on our own infrastructure; no data transfer to third parties takes place (section 9). Map tiles are loaded from the OpenStreetMap Foundation, which is independently responsible in this respect (section 12). A demo appointment booking is made via a Google service under its own responsibility (section 15).
A current list of sub-processors is set out in Annex 2 of the DPA. Beyond this, we only pass on data where we are legally obliged to do so. There is no sale or transfer for advertising purposes.
6. Transfers to Third Countries
Where processing takes place outside the EU / EEA (in particular Google for address geocoding, Cloudflare for the delivery of our website, and Stripe’s US sub-processor), we base the transfer primarily on an adequacy decision of the EU Commission pursuant to Art. 45 GDPR: the US recipients named (including Google LLC, Cloudflare, Inc., Stripe, Inc.) are certified under the EU-US Data Privacy Framework. In addition, and in case a certification or the adequacy decision ceases to apply, the EU Standard Contractual Clauses pursuant to Implementing Decision (EU) 2021/914 together with the necessary additional measures (TIA) exist as a safeguard under Art. 46 GDPR. On request we provide information about the safeguards agreed.
7. Delivery and Server Log Files (Website + Platform)
When you access and use the website and platform (desktop web and mobile app), technically necessary data is processed and briefly stored in log files, in particular IP address, date and time, requested resource, status code, volume of data transferred, and browser and device information. Transmission is consistently encrypted via TLS/HTTPS.
Legal basis: Art. 6(1)(f) GDPR (secure, stable operation).
8. Content Delivery Network and DNS (Cloudflare)
Our public website (marketing/landing page) is delivered and protected via Cloudflare (hosting of the static site, DNS, protection against attacks such as DDoS). In doing so, Cloudflare processes connection data of website visitors, in particular the IP address. The platform (app.valiro.ai), by contrast, runs directly on our infrastructure at Hetzner; its traffic does not run through Cloudflare — for the platform Cloudflare only handles DNS resolution. For provider, third-country reference and safeguards see sections 5 and 6.
Legal basis: Art. 6(1)(f) GDPR (security and availability).
9. Reach Measurement (Umami)
To design our offering according to demand and to statistically evaluate usage, we use the self-hosted software Umami on our own infrastructure within the EU. The analysis is carried out without cookies, without creating user profiles and without transfer to third parties.
Legal basis: Art. 6(1)(f) GDPR (demand-oriented design).
10. Registration and User Account
Use of the platform requires the registration of a user account. In doing so we process in particular the business email address, the name / display name and a password (exclusively as a secure hash, bcrypt). Optionally, two-factor authentication (TOTP) can be activated. Through a user account, a company account can be created and access granted to further users.
Legal basis: Art. 6(1)(b) GDPR.
11. AI-Powered Features
Valiro offers AI-powered features (semantic search, document analysis, assistance).
- Embeddings. For semantic search, content is converted into vectors and stored in our database.
- AI requests. When used, the relevant inputs and text excerpts are transmitted to our AI service provider for processing. EdenAI is used as an orchestration layer; via its EU endpoint (api.eu.edenai.run) routing takes place exclusively via EU-capable providers. The language model (Google Gemini) is processed via Google Vertex AI in the EU multi-region — no transfer to a third country takes place in this respect (section 5).
- No training with your data. Inputs and outputs are not used to train third-party AI models.
- Responsibility for outputs. AI outputs may be inaccurate and must be reviewed by the user. No automated decision-making within the meaning of Art. 22 GDPR takes place (section 18).
- Labeling (AI transparency). The AI-powered features are marked as such within the service; you are interacting with an AI system and not with a human. Results are presented to you as AI-generated within the AI features (Art. 50 of Regulation (EU) 2024/1689, the “AI Act”).
Where personal content data of the customer is used, we act as a processor (section 2).
Legal basis: Art. 6(1)(b) GDPR.
12. Map Function and Address Search
Address resolution (Google). For location management and address completion we use the Google Maps Platform (Places API for autocomplete/details, Geocoding API for address↔coordinates). The connection is made server-side via our own proxy; only the address text, the place identifier (place_id) or coordinates are transmitted — not the IP address or browser data of users. To minimize data, results are cached in our database so that the same address is transmitted to Google only once. Processing in the USA; for safeguards see sections 5 and 6.
Map display (OpenStreetMap). To display maps (desktop and mobile app) we use the Leaflet library and load the map material (map tiles) from the tile server of the OpenStreetMap Foundation (St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom). In doing so, the user’s IP address is transmitted to this server; the OpenStreetMap Foundation is independently responsible for this. An adequacy decision of the EU Commission exists for the United Kingdom (Art. 45 GDPR). Privacy notice: wiki.osmfoundation.org/wiki/Privacy_Policy.
Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (display of locations on a map).
13. Payment Processing (Stripe)
For paid plans we process payments via Stripe (Stripe Payments Europe, Ltd.), including the checkout and billing portal provided by Stripe. Payment and billing data is processed to perform the contract and to fulfill commercial and tax obligations. Card data is collected and processed exclusively by Stripe, not by us.
Legal basis: Art. 6(1)(b) and (c) GDPR.
14. Transactional Emails (Brevo)
To deliver service- and contract-related emails (e.g. registration confirmation, notifications, security-relevant messages) we use Brevo GmbH as a dispatch service provider (SMTP). The email address and the content of the message are processed.
Legal basis: Art. 6(1)(b) GDPR.
15. Contact and Appointment Booking
- Email. If you contact us by email (info@valiro.ai), we process your information to handle the request.
- Demo appointment booking. To book an appointment we link to a scheduling service by Google (Google Calendar / Appointment Scheduling). If you access it, Google processes the data provided there under its own responsibility; Google’s privacy notices apply.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (handling of requests).
16. Cookies and Local Storage
We do not use tracking, advertising or profiling cookies. We use exclusively technically necessary cookies and the browser’s local storage (localStorage), in particular for authentication/session management, security functions, user settings (language, appearance) and cached data for the offline functionality of the app. Since reach measurement (section 9) also works without cookies, no consent under Sec. 25(1) TDDDG is required (Sec. 25(2) no. 2 TDDDG). Further information can be found in our cookie policy.
Legal basis: Art. 6(1)(b) and (f) GDPR.
17. Communication, Advertising and Reference Listing
Within the scope of trial access and use, we may contact the customer by email or telephone for the purposes of service, contract performance, improvement of our services, surveys and advertising in our own interest. The customer can object to marketing communications at any time via the unsubscribe link or support (valiro.ai/support); important information about the service and account will continue to be provided. We may name the customer (name and logo) as a reference customer; the customer can object to this at any time with effect for the future in text form.
Legal basis: Art. 6(1)(f) GDPR; Sec. 7(3) UWG for email advertising to existing customers.
18. Automated Decision-Making
Automated decision-making, including profiling, with legal effect or similarly significant impact within the meaning of Art. 22 GDPR does not take place. The AI features provide suggestions; the decision is always made by the user.
19. Retention Periods
| Type of data | Duration |
|---|---|
| User account and master data | until deletion of the account |
| Content data (projects, documents, messages) | until deletion by the customer or until end of contract |
| Activity logs | 12 months |
| Server log files (incl. IP address) | generally 7 days |
| Invoice and accounting data | statutory retention periods (generally 10 years) |
| After end of contract | 30 days for export, then deletion or data-protection-compliant blocking |
Data no longer required is deleted unless statutory retention obligations prevent this; where deletion is disproportionate (e.g. in backups), the data is blocked in a data-protection-compliant manner.
20. Your Rights
Within the statutory requirements, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and withdrawal of consent (Art. 7(3) GDPR). To exercise these rights, a message to info@valiro.ai is sufficient.
If your rights concern content data that a customer has entered into the platform, the respective customer is the controller; in this case we forward a request addressed to us without undue delay.
Right to object (Art. 21 GDPR): You have the right, on grounds relating to your particular situation, to object at any time to processing of data concerning you which is based on Art. 6(1)(f) GDPR. In the case of direct marketing you can object at any time without giving reasons.
21. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Bavarian State Office for Data Protection Supervision (BayLDA) Promenade 18, 91522 Ansbach · www.lda.bayern.de
22. Data Security
We take technical and organizational measures pursuant to Art. 32 GDPR, in particular: encrypted transmission (TLS/HTTPS); passwords exclusively as secure hashes (bcrypt); optional two-factor authentication (TOTP, secret AES-256-GCM-encrypted); role-based access control and tenant separation per organization; logging of security-relevant access; regular, separately stored backups; monitoring and timely security updates; operation in a certified data center (Hetzner, ISO 27001). For details see Annex 3 of the DPA and our security page.
23. Obligation to Provide Data
The provision of certain data (in particular business email address and access data) is necessary to establish and perform the usage relationship; without this data we cannot provide the service. Otherwise the provision is voluntary.
24. Changes to This Privacy Policy
We adapt this privacy policy if the legal situation, our processing activities or the service providers used change. The current version is available at valiro.ai/datenschutz.