Legal
Privacy notice
Last updated: 12 August 2026. Operator: Valentica (valentica.io).
What we collect
We collect only what is needed to run the product and the design-partner programme:
- Design-partner form — name, fund, role, work email, optional notes, and consent. A short math captcha and a honeypot field protect the form; we do not sell form data to third parties.
- Account registration — email address and a password hash (argon2id). Passwords are never stored in plaintext.
- Session cookie — an opaque server-side session token (
vsession, HttpOnly, SameSite=Strict) so you stay signed in. - Server logs — standard request metadata (path, status, timestamps) for reliability and abuse prevention. No advertising trackers or third-party analytics scripts ship with the site.
Why we process it
- To respond to design-partner access requests and operate the credit-analysis product.
- To authenticate accounts and keep sessions secure.
- To protect the service against automated abuse (rate limits, captcha).
Legal bases: your consent (form checkbox) and our legitimate interest in securing and operating the service.
Where it is stored
Data is stored on the Valentica application server (EU — AWS eu-central-1) in local SQLite databases under the application’s control. Design-partner notifications may be emailed via Amazon SES SMTP to our team inbox. We do not use third-party form hosts (Formspree, Tally, etc.).
Retention
- Access requests are kept until reviewed or deleted by the operator.
- Accounts and sessions remain until you ask us to delete them or the session expires (default 14 days).
- Server logs are rotated as part of normal operations.
Your rights
You may request access, correction, or deletion of personal data we hold about you by emailing partners@valentica.io. You may also lodge a complaint with your local data-protection authority.