Valnivo Professional

Privacy notice for Valnivo Professional

Valnivo Professional · v2 · last updated · about this product · the consumer app's own notice

Who you are dealing with

Valnivo Professional is operated from Luxembourg by Valnivo Labs. Valnivo Labs is a trade name, not a registered company. The name of the person responsible is given on request — write to privacy@valnivo.eu — and is given without condition for a formal data-protection request or a complaint to a supervisory authority, so no right of yours depends on it being printed here.

This is weaker than the law wants, and it is said plainly rather than hidden. Art. 13(1)(a) GDPR and the Luxembourg e-commerce law of 14 August 2000 both expect the controller to be named. The same is true of the consumer app's notice, and the real fix in both cases is a legal entity rather than better wording.

No lawyer has reviewed these documents. That is stated because a firm deciding whether to rely on them is entitled to know it.

What is in force today

Valnivo Professional is an early-stage service and there is no charge for it. No price is quoted anywhere, nothing is invoiced, and no payment method is taken — so any clause below about fees describes an arrangement that does not yet exist. If that changes it changes by agreement, in a new version, and never by a figure appearing on a screen.

The processing agreement is the exception, and it is in force. An art. 28 agreement attaches to processing and not to payment: the moment a firm puts a client's figures into this service there has to be one, whether or not anybody is being charged. It is accepted when a firm claims its account, and that acceptance is what executes it.

Two roles, and the line between them

This is the part a firm's procurement team reads first, so it comes first:

Who decidesWho we are
The clients you enter in the application — your own reference for each, and their figures, sealedYouYour processor. We act on your documented instructions under the processing agreement
The cases you send to the API — figures, a currency, a country, your own referenceYouYour processor, under the same agreement
Your account — your organisation, the people at it, their devices and keys, and the request that led to itUsController. This notice is about that

The people whose futures you project are your clients. They have no account with us and never meet us, and a client's identity stays in your own system — see "What a client or a case may not contain" below. Telling them a third-party tool is used is art. 14 GDPR and is your duty; it is also a warranty in the terms, so it is not left to goodwill.

What we hold about your organisation, and why

All of it is in this product's own Firestore database, in a Google Cloud project of its own (valnivo-pro), stored in the European Economic Area, in Berlin (europe-west10).

WhatWhyBasisKept
The request to join: the firm's name and country, the role of the person asking (a role, not a name), their work e-mail, the number of seats and of clients a month, what was asked for, when it was sent, whether it was accepted or declined, and which of us answeredTo answer it, and to keep the record of why an account existsLegitimate interests, art. 6(1)(f) — ordinary B2B contact data, given by the firmKept as that record. No automatic deletion period is set yet; you may ask for a request to be deleted
The firm: its name, its country of establishment, a contact address, the request it came from and which member owns the accountTo have a counterpartyPerformance of the contract, art. 6(1)(b)While the account exists, then the period the accounting record requires
Its members: each one's name as colleagues see it, work e-mail, role, when they joined and the public half of their key; and each invitation: the address, the role it carries, who sent it and whenTo operate the account and let the right people inLegitimate interests, art. 6(1)(f)A member while they are one; an invitation until it is used or withdrawn
How they sign in: an account with Google's identity service — an identifier, the work e-mail and, if they chose one, a password that Google holds and we never seeTo let the right people in and nobody elsePerformance of the contractWhile the account exists
Their devices: for each browser a member approves, the public half of its key, a label such as "Chrome on Windows", when it was added and which device approved it; the member's key wrapped for each approved device; and, only if the member made one, a copy of that key sealed under a recovery code that only they holdTo keep the client keys usable across a member's own devices, and only theirsPerformance of the contractUntil the device is removed or the member leaves
The firm's price-service key, only if a member saved one, sealed so that only that member's key opens itTo ask the price service a firm has chosen for a closing price, on a pressPerformance of the contractUntil the member removes it or leaves
What the firm accepted: the version of the terms, this notice and the processing agreement, when, and the account that accepted themThe art. 28 record your own procurement will ask to seeLegal obligation, art. 28(9) and art. 5(2)While the contract runs, then the limitation period
API keys, if one is issued: a hash of the key, its scope, who issued it, when, when it expires and when it was revoked. None has been issued yetTo check a key at the edge and to be able to revoke onePerformance of the contractRevoked keys kept as a hash with the revocation date
An audit trail, when one is recorded: a member, a client scope's id, an action and a time — never a figure, a reference or anything on the screen. The database accepts it append-only; the application does not write one yetTo answer the audit right the processing agreement gives youLegitimate interests, art. 6(1)(f)Five years by default, because that is what a regulated firm is usually required to keep; a period agreed with you

The private halves of the keys never leave the browser: each device keeps its own in that browser's storage, and nothing we hold can open it. Never an API key itself, because a leaked table must not be a leaked key.

No usage counts are kept. The API limits how often it may be called in memory, per running instance, and writes nothing down. Google Cloud keeps its own request logs for the API service — the time, the address called, the status code and the caller's network address — under its default retention of 30 days.

Signing in, and what that means for what is held

Two ways in, both through the work address: a password, or a sign-in link sent by e-mail. There is no "sign in with Google" here; that is the consumer app's. Signing in through your firm's own identity provider (single sign-on) is not offered.

A new browser waits until one of the person's own devices approves it — never a colleague's, and never by signing in alone. Without an approved device or a recovery code, a colleague who holds a client's key can give the person access again, one client at a time.

There is no self-registration into a firm. A sign-in on its own reaches nothing: an account belongs to a firm because the firm's request to join was accepted and its contact claimed it, or because somebody at the firm invited them, and an invitation carries the role they join as.

What removing somebody does, stated plainly. Taking them out of the organisation ends their access immediately: every rule asks the organisation record first, so they are refused whatever credential they still hold. What it cannot do is un-see what they had already opened — which is true of any system and worth saying rather than implying otherwise.

What is stored of what you enter, and how

The API stores no case you send it. A request arrives, is checked, is computed and is answered; nothing about its content is written down, so there is no retention period for a case and no erasure request to answer about one.

The application stores each client you enter, because a book of clients is what it is for:

Pricing a holding sends one ticker, from your browser, to the price service your firm chose, with the key your firm saved, and nothing else — not the units, not the client, not the reference. That service acts under your own agreement with it; Valnivo ships no key for it and is not a party.

A projection is not stored. The handover document is written in your browser and downloaded; the handover link that would store one sealed for a client to open is switched off, and turning it on would be a new version of this notice.

What a client or a case may not contain

No name, e-mail address, telephone number, postal address, date of birth, account number or national identifier. In the API the named fields are refused at the boundary rather than asked about: the request comes back naming the field it will not take. A client's record has no field for any of them. Your own reference is free text and only you can keep it clean, which is why your terms warrant that you will.

What is left is figures, a currency and a country. It is still personal data in your hands — you can re-identify it and recital 26 says so — and it is close to useless in anybody else's.

Who else receives it

RecipientWhatWhyTransfer
Google (Google Ireland Limited, with Google LLC in the United States)Everything aboveFirebase Authentication signs people in and sends the sign-in and password-reset e-mails; Cloud Firestore stores the records above in the EEA (europe-west10); Cloud Run runs the API, in Belgium (europe-west1); Firebase App Check with reCAPTCHA Enterprise, where it is switched on, tells the genuine application from scripts. The database, the sign-in and the API are in Google Cloud projects of this product's own, not the consumer app's; the pages themselves are served by the same Firebase Hosting that serves valnivo.eu, which holds nothing you enterGoogle Cloud Data Processing Addendum and the Firebase terms; Google's infrastructure may include the United States — EU–US Data Privacy Framework and standard contractual clauses

Nobody else, and deliberately no new company: Google is already a processor this project uses, which is the reason Cloud Run was chosen over an edge platform nobody here had a contract with. The price service a firm chooses is the firm's own and receives only a ticker, as said above. No analytics, no advertising — the second is checked by an automated test rather than merely promised — and nothing is sold, shared or used to train anything.

Nothing about this product shares a record with the consumer app: not a database, not a Firestore project, not a key and not a rule.

Your rights, and your clients'

The people at your firm whose details we hold have the ordinary rights — access, rectification, erasure, restriction, portability, objection — exercisable by writing to privacy@valnivo.eu, and the right to complain to a supervisory authority, in Luxembourg the CNPD.

Your clients' rights are exercised against you, because you are their controller. Where answering one needs something from us, the processing agreement says we help: a client is deletable on its own, by your firm, from the application, and a handover document can be written for any one of them, because your own client may ask you about exactly one of them and you have a month. We cannot open a client's record, so we cannot answer about its content ourselves.

Security

What protects this is written down rather than asserted, including what the design does not protect against as well as what it does. In outline — client figures stored only sealed, with keys your members hold and we do not; a new device approved only from one of the person's own devices; every read and write checked against your organisation's record; API keys checked before any arithmetic runs and stored only as hashes; and a Google Cloud project separate from every other.

What changed in this version

VersionDateWhat changed
v230 September 2026Describes what the application stores: each client a firm enters, sealed, with its reference in the clear; members' devices and keys, and the optional recovery code; the firm's price-service key; the request to join; the acceptance record. Sign-in is by password or e-mail link, not single sign-on. No usage counts are kept; Google Cloud's request logs are named. The price service a firm chooses is described. A new kind of thing held, so a new version.
v122 September 2026First published.

Changes

A version and a date, a row saying what changed and whether it matters, and the same rule the consumer notice follows: a change in what is collected, why, who receives it, how long it is kept or what you may ask for is a new version, not a dated correction. The version and its date are at the head of this notice.

The controller. Valnivo Labs, based in Luxembourg. Valnivo Labs is a trade name, not a registered company. The name of the person responsible is given on request, and without condition for a formal request or a complaint to a supervisory authority.

© 2026 Valnivo · offered from Luxembourg to firms in the European Economic Area. Enquiries: contact@valnivo.eu