Privacy Policy
Viimos Oy, a limited liability company incorporated in Finland (Business ID 3612414-4, registered office Espoo), trading as Valuepoint Labs ("we", "us", "our"), is the data controller responsible for personal data processed about users of the Valuepoint Labs platform ("the Service"). This Privacy Policy explains how we collect, use, and safeguard that information.
1. Data We Collect
We collect the following categories of personal data:
- Account data: name, email address, and hashed password when you register. If you sign in with Google or LinkedIn instead, we receive the account identifier and the verified email address that provider returns, and store those in place of a password.
- Usage data: the features you use and the requests your session makes to the Service — which operation, whether it succeeded, and how long it took — together with session information. We do not track your browsing, on this site or anywhere else.
- Content data: the Value Cases, customer profiles and financial models you create and save in the Service, together with any material you upload or paste into them
- Shared-viewer data: if you open a business case that an account holder has shared with you by entering your email address, the email you provide, a record of your views (including timestamps), and any comments you leave
- Technical data: IP address, browser type, device information, and cookies
- Contact data you enter about other people: when you share a business case, the name and business email address of each person you invite to read, comment on or co-edit it. We are the controller for those details and use them only to deliver the invitation and operate the sharing feature. Section 5 of the Terms of Use governs what you may and may not submit about individuals.
2. How We Use Your Data
We use your data to:
- Provide and maintain the Service
- Authenticate your identity and manage your account
- Send transactional emails (e.g. password resets, invitations, billing notices)
- Send occasional product updates, but only if you asked for them when you signed up. You can tell us to stop at any time using the contact in Section 11
- Improve the Service and fix bugs
- Keep the Service secure and available, and enforce our Terms — detecting and preventing abuse, fraud and misuse, and applying the fair-use and automated controls described in Section 4 of the Terms of Service
- Comply with legal obligations
We do not sell your personal data to third parties. We do not use your content data to train AI models.
3. Legal Basis (GDPR)
Our legal basis for processing personal data is: (a) contract performance — to provide the Service you have signed up for; (b) legitimate interests — to operate, secure and improve the Service, which includes preventing abuse and misuse, controlling the cost of the AI features, and keeping a record of enforcement decisions so they can be explained and appealed; and (c) legal obligation — where required by applicable law. Where we rely on legitimate interests we have weighed them against your rights, and you may object using the contact below.
4. Data Retention
We retain your account data and the content you create for as long as your account is active. You can delete your account yourself at any time, under Your data on the Profile screen: it shows you exactly what will be destroyed before you confirm, and the deletion is immediate. You can also ask us to do it using the contact in Section 11, and we will complete it within 30 days. Either way, deletion is subject only to retention required by law and the two exceptions below.
Backups. We keep off-site backups of the database so the Service can be restored after a failure. We encrypt each backup before it leaves us, so the storage provider holds only ciphertext and cannot read it. A backup copy expires after 30 days, so data from a deleted account can persist in a backup for up to that long after deletion. Backups are never used to restore an individual account we have deleted.
Inactive shared cases. A Value Room that nobody opens for 90 days is closed automatically, and 180 days after that its contents are erased — the questions and comments readers left, the record of who accessed it, and the invitations that granted access. The account holder is warned inside the Service 30 days before each step, and can keep the room open by opening it. Your own business case is not affected; only the shared room is.
Two records are kept beyond deletion, because destroying them would destroy the evidence that what we did was permitted. The consent record stores which version of these documents was accepted, by which email address, when, and the IP address and browser the acceptance came from. The enforcement record stores any restriction applied to a workspace — what was done, by whom, when, and why. Both are kept as long as we may need to answer for the decision, and neither is used for any other purpose.
5. Data Security
We use industry-standard security measures including encrypted storage of passwords, HTTPS for all data in transit, and session-based authentication. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
6. Sub-processors and International Transfers
To provide the Service we use a small number of vetted sub-processors, each under a data-processing agreement:
- Anthropic, PBC (United States) — AI generation. Content you submit to AI features is sent to Anthropic to produce the output. Anthropic processes it under a data-processing agreement and does not use it to train its models, and deletes it within 30 days, except where it is required to keep it longer to enforce its own usage policy or to comply with law. One feature, the customer identity check, also asks Anthropic to run a web search, so the company name and website you gave us reach Anthropic's search provider as part of that request.
- Railway (United States) — application hosting and database
- Stripe (EU/United States) — payments, billing and tax
- Postmark (United States) — transactional email: account and billing messages, invitations, and notifications to people a business case is shared with
- Cloudflare R2 (European Union) — off-site database backups, stored in the EU. We encrypt each backup before uploading it, so Cloudflare holds only ciphertext
- Sentry (European Union) — error monitoring. When something fails, the Service sends Sentry the error, the address of the page or request it happened on, and the numeric identifier of the signed-in account. It does not send the content of your business cases
Sign-in providers. If you choose to sign in with Google or LinkedIn, that provider tells us your account identifier, your email address and whether it is verified, and knows that you signed in to the Service. They act as independent controllers for that exchange, under their own privacy policies. You never have to use them: an email address and a password work everywhere they do.
Content delivery. Our pages load typefaces from Google Fonts and icons from the jsDelivr network. Your browser contacts those services directly, so they receive your IP address and the page you were loading. They set no cookies for us and receive nothing else.
Pages we fetch for you. When you give the Service a web address to read — a product page, a report, a customer's site — our server fetches that page from your side, not yours, and passes its text to the AI features. The site you named will see a request from us.
Some of these process data outside the EEA (including the United States). For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK IDTA/Addendum for UK data), with supplementary measures where appropriate. We do not sell personal data and do not use it for advertising. Where we process personal data contained in the content you submit, we do so as your processor under the Data Processing Addendum. The current list is published at valuepointlabs.com/subprocessors, and we post a change there at least 30 days before a new sub-processor begins processing customer content.
7. Your Rights (GDPR)
Under GDPR, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict processing
- Data portability — Download my data, on the Profile screen, gives you everything we hold about your account as a single file, at any time and without asking us
- Lodge a complaint with a supervisory authority (in Finland: Tietosuojavaltuutettu)
7.1 Automated controls and human review
The Service applies automatic limits that can pause its AI features — described in full in Section 4.3 of the Terms of Service. These are usage and cost controls: they pause a feature, they never delete anything, and they do not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. We do not profile you: nothing about you is scored, and no rule reads anything beyond the volume and timing of the requests themselves.
Three rules act on their own without a person reviewing them first, and Section 4.3 of the Terms of Use describes each in full. We limit how many accounts can be created from one email domain in a day; we do not accept sign-ups from disposable mailbox services; and where two workspaces claim the same verified organisation name, we pause publishing for the later claim until we resolve which one holds it. None of the three reads anything about you as a person, and you can ask us to review any of them by writing to the appeal address in Section 11.
Where we pause a workspace's AI features because we have reviewed how it is being used, a person makes that decision. You may ask us for the reason, ask a person to review it, and contest it — reply to any email from us, or email the address in Section 11. Where AI has been paused we will respond within two business days.
8. Cookies
We use two strictly necessary cookies, and no others. One keeps you signed in to your account. The other keeps a reviewer signed in to a business case that was shared with them. We use no tracking or advertising cookies, and there is no advertising on the Service.
The Service also keeps working data in your browser's own storage — unsaved drafts and interface preferences such as which panels you left open. That stays on your device, is not sent to us, and clearing your browser data removes it.
9. Shared Business Cases
Account holders can share a business case with other people. If a case is shared with you and you open it by entering your email address, we process that email and your view activity (including timestamps), together with any comments you leave, and we make them visible to the account holder who shared the case (the "sender") — for example, in a list of who has viewed the case. We do this to operate the sharing feature; our legal basis is our and the sender's legitimate interest in knowing who has accessed a case they shared, and in providing the functionality you chose to use by opening the link. The sender, not Valuepoint Labs, decides what to share and with whom. To stop being shown a case, ask the sender to revoke your access; to exercise your data rights, contact us at the address below.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Where a change is material, you have to accept it: the next time you sign in, the Service shows you that the document changed and asks you to accept it before you continue. We record which version you accepted and when. Every version carries the version number and effective date at the top of this page.
11. Contact
For privacy queries, or to exercise any of the rights in Section 7 — including asking us to delete your account — contact [email protected]. We will respond within one month, as GDPR requires, and will tell you if we need longer and why.
To appeal a limit or a pause applied to your account, contact [email protected]. Where AI features have been paused by a decision of ours, a person will answer within two business days.
Both addresses reach Viimos Oy, the data controller identified at the top of this policy.