Valnivo Professional
Privacy notice for Valnivo Professional
Who you are dealing with
Valnivo Professional is operated from Luxembourg by Valnivo Labs. Valnivo Labs is a trade name, not a registered company. The name of the person responsible is given on request — write to privacy@valnivo.eu — and is given without condition for a formal data-protection request or a complaint to a supervisory authority, so no right of yours depends on it being printed here.
This is weaker than the law wants, and it is said plainly rather than hidden. Art. 13(1)(a) GDPR and the Luxembourg e-commerce law of 14 August 2000 both expect the controller to be named. The same is true of the consumer app's notice, and the real fix in both cases is a legal entity rather than better wording.
No lawyer has reviewed these documents. That is stated because a firm deciding whether to rely on them is entitled to know it.
What is in force today
Valnivo Professional is an early-stage service and there is no charge for it. No price is quoted anywhere, nothing is invoiced, and no payment method is taken — so any clause below about fees describes an arrangement that does not yet exist. If that changes it changes by agreement, in a new version, and never by a figure appearing on a screen.
The processing agreement is the exception, and it is in force. An art. 28 agreement attaches to processing and not to payment: the moment a firm puts a client's figures into this service there has to be one, whether or not anybody is being charged. It is accepted when a firm claims its account, and that acceptance is what executes it.
Two roles, and the line between them
This is the part a firm's procurement team reads first, so it comes first:
| Who decides | Who we are | |
|---|---|---|
| The clients you enter in the application — your own reference for each, and their figures, sealed | You | Your processor. We act on your documented instructions under the processing agreement |
| The cases you send to the API — figures, a currency, a country, your own reference | You | Your processor, under the same agreement |
| Your account — your organisation, the people at it, their devices and keys, and the request that led to it | Us | Controller. This notice is about that |
The people whose futures you project are your clients. They have no account with us and never meet us, and a client's identity stays in your own system — see "What a client or a case may not contain" below. Telling them a third-party tool is used is art. 14 GDPR and is your duty; it is also a warranty in the terms, so it is not left to goodwill.
What we hold about your organisation, and why
All of it is in this product's own Firestore database, in a Google Cloud project of its own (valnivo-pro), stored in the European Economic Area, in Berlin (europe-west10).
| What | Why | Basis | Kept |
|---|---|---|---|
| The request to join: the firm's name and country, the role of the person asking (a role, not a name), their work e-mail, the number of seats and of clients a month, what was asked for, when it was sent, whether it was accepted or declined, and which of us answered | To answer it, and to keep the record of why an account exists | Legitimate interests, art. 6(1)(f) — ordinary B2B contact data, given by the firm | Kept as that record. No automatic deletion period is set yet; you may ask for a request to be deleted |
| The firm: its name, its country of establishment, a contact address, the request it came from and which member owns the account | To have a counterparty | Performance of the contract, art. 6(1)(b) | While the account exists, then the period the accounting record requires |
| Its members: each one's name as colleagues see it, work e-mail, role, when they joined and the public half of their key; and each invitation: the address, the role it carries, who sent it and when | To operate the account and let the right people in | Legitimate interests, art. 6(1)(f) | A member while they are one; an invitation until it is used or withdrawn |
| How they sign in: an account with Google's identity service — an identifier, the work e-mail and, if they chose one, a password that Google holds and we never see | To let the right people in and nobody else | Performance of the contract | While the account exists |
| Their devices: for each browser a member approves, the public half of its key, a label such as "Chrome on Windows", when it was added and which device approved it; the member's key wrapped for each approved device; and, only if the member made one, a copy of that key sealed under a recovery code that only they hold | To keep the client keys usable across a member's own devices, and only theirs | Performance of the contract | Until the device is removed or the member leaves |
| The firm's price-service key, only if a member saved one, sealed so that only that member's key opens it | To ask the price service a firm has chosen for a closing price, on a press | Performance of the contract | Until the member removes it or leaves |
| What the firm accepted: the version of the terms, this notice and the processing agreement, when, and the account that accepted them | The art. 28 record your own procurement will ask to see | Legal obligation, art. 28(9) and art. 5(2) | While the contract runs, then the limitation period |
| API keys, if one is issued: a hash of the key, its scope, who issued it, when, when it expires and when it was revoked. None has been issued yet | To check a key at the edge and to be able to revoke one | Performance of the contract | Revoked keys kept as a hash with the revocation date |
| An audit trail, when one is recorded: a member, a client scope's id, an action and a time — never a figure, a reference or anything on the screen. The database accepts it append-only; the application does not write one yet | To answer the audit right the processing agreement gives you | Legitimate interests, art. 6(1)(f) | Five years by default, because that is what a regulated firm is usually required to keep; a period agreed with you |
The private halves of the keys never leave the browser: each device keeps its own in that browser's storage, and nothing we hold can open it. Never an API key itself, because a leaked table must not be a leaked key.
No usage counts are kept. The API limits how often it may be called in memory, per running instance, and writes nothing down. Google Cloud keeps its own request logs for the API service — the time, the address called, the status code and the caller's network address — under its default retention of 30 days.
Signing in, and what that means for what is held
Two ways in, both through the work address: a password, or a sign-in link sent by e-mail. There is no "sign in with Google" here; that is the consumer app's. Signing in through your firm's own identity provider (single sign-on) is not offered.
- With a password, the credential is held by Google's identity service and never by us: we receive an account identifier, not a password, and cannot read one. Resetting it is the only self-service an account has, and the reset e-mail is sent by that service.
- With a sign-in link, there is no password at all. The work address is sent to Google's identity service, which e-mails a one-time link to it. The browser that asked keeps the address so the sign-in can be completed when the link is opened, and removes it once it is.
A new browser waits until one of the person's own devices approves it — never a colleague's, and never by signing in alone. Without an approved device or a recovery code, a colleague who holds a client's key can give the person access again, one client at a time.
There is no self-registration into a firm. A sign-in on its own reaches nothing: an account belongs to a firm because the firm's request to join was accepted and its contact claimed it, or because somebody at the firm invited them, and an invitation carries the role they join as.
What removing somebody does, stated plainly. Taking them out of the organisation ends their access immediately: every rule asks the organisation record first, so they are refused whatever credential they still hold. What it cannot do is un-see what they had already opened — which is true of any system and worth saying rather than implying otherwise.
What is stored of what you enter, and how
The API stores no case you send it. A request arrives, is checked, is computed and is answered; nothing about its content is written down, so there is no retention period for a case and no erasure request to answer about one.
The application stores each client you enter, because a book of clients is what it is for:
- In the clear, one thing: your own reference, at most 64 characters, so your book can be listed without opening every record. That is why it must never be a name.
- Sealed, everything else: the country of residence, the currency, what is already put by and added each month, each plan (its label, horizon, assumed return and monthly amount), a target if you record one, when the client was last reviewed and how often, income and spending in six fixed groups if you record them, and holdings — a ticker, a number of units and, once priced, a closing price and its date.
- Sealed with a key your own people hold. Each client has its own key, wrapped for the members allowed to open it. Valnivo holds no key and keeps no escrow: we cannot read a client of yours, and we cannot recover one for you. If no member of your firm holds a key, the record can never be opened again, by you or by us.
Pricing a holding sends one ticker, from your browser, to the price service your firm chose, with the key your firm saved, and nothing else — not the units, not the client, not the reference. That service acts under your own agreement with it; Valnivo ships no key for it and is not a party.
A projection is not stored. The handover document is written in your browser and downloaded; the handover link that would store one sealed for a client to open is switched off, and turning it on would be a new version of this notice.
What a client or a case may not contain
No name, e-mail address, telephone number, postal address, date of birth, account number or national identifier. In the API the named fields are refused at the boundary rather than asked about: the request comes back naming the field it will not take. A client's record has no field for any of them. Your own reference is free text and only you can keep it clean, which is why your terms warrant that you will.
What is left is figures, a currency and a country. It is still personal data in your hands — you can re-identify it and recital 26 says so — and it is close to useless in anybody else's.
Who else receives it
| Recipient | What | Why | Transfer |
|---|---|---|---|
| Google (Google Ireland Limited, with Google LLC in the United States) | Everything above | Firebase Authentication signs people in and sends the sign-in and password-reset e-mails; Cloud Firestore stores the records above in the EEA (europe-west10); Cloud Run runs the API, in Belgium (europe-west1); Firebase App Check with reCAPTCHA Enterprise, where it is switched on, tells the genuine application from scripts. The database, the sign-in and the API are in Google Cloud projects of this product's own, not the consumer app's; the pages themselves are served by the same Firebase Hosting that serves valnivo.eu, which holds nothing you enter | Google Cloud Data Processing Addendum and the Firebase terms; Google's infrastructure may include the United States — EU–US Data Privacy Framework and standard contractual clauses |
Nobody else, and deliberately no new company: Google is already a processor this project uses, which is the reason Cloud Run was chosen over an edge platform nobody here had a contract with. The price service a firm chooses is the firm's own and receives only a ticker, as said above. No analytics, no advertising — the second is checked by an automated test rather than merely promised — and nothing is sold, shared or used to train anything.
Nothing about this product shares a record with the consumer app: not a database, not a Firestore project, not a key and not a rule.
Your rights, and your clients'
The people at your firm whose details we hold have the ordinary rights — access, rectification, erasure, restriction, portability, objection — exercisable by writing to privacy@valnivo.eu, and the right to complain to a supervisory authority, in Luxembourg the CNPD.
Your clients' rights are exercised against you, because you are their controller. Where answering one needs something from us, the processing agreement says we help: a client is deletable on its own, by your firm, from the application, and a handover document can be written for any one of them, because your own client may ask you about exactly one of them and you have a month. We cannot open a client's record, so we cannot answer about its content ourselves.
Security
What protects this is written down rather than asserted, including what the design does not protect against as well as what it does. In outline — client figures stored only sealed, with keys your members hold and we do not; a new device approved only from one of the person's own devices; every read and write checked against your organisation's record; API keys checked before any arithmetic runs and stored only as hashes; and a Google Cloud project separate from every other.
What changed in this version
| Version | Date | What changed |
|---|---|---|
| v2 | 30 September 2026 | Describes what the application stores: each client a firm enters, sealed, with its reference in the clear; members' devices and keys, and the optional recovery code; the firm's price-service key; the request to join; the acceptance record. Sign-in is by password or e-mail link, not single sign-on. No usage counts are kept; Google Cloud's request logs are named. The price service a firm chooses is described. A new kind of thing held, so a new version. |
| v1 | 22 September 2026 | First published. |
Changes
A version and a date, a row saying what changed and whether it matters, and the same rule the consumer notice follows: a change in what is collected, why, who receives it, how long it is kept or what you may ask for is a new version, not a dated correction. The version and its date are at the head of this notice.
The controller. Valnivo Labs, based in Luxembourg. Valnivo Labs is a trade name, not a registered company. The name of the person responsible is given on request, and without condition for a formal request or a complaint to a supervisory authority.