Privacy Policy

Version 1.12 · Effective 9 September 2026

Viimos Oy, a limited liability company incorporated in Finland (Business ID 3612414-4, registered office Espoo), trading as Valuepoint Labs ("we", "us", "our"), is the data controller responsible for personal data processed about users of the Valuepoint Labs platform ("the Service"). This Privacy Policy explains how we collect, use, and safeguard that information.

1. Data We Collect

We collect the following categories of personal data:

2. How We Use Your Data

We use your data to:

We do not sell your personal data to third parties. We do not use your content data to train AI models.

3. Legal Basis (GDPR)

Our legal basis for processing personal data is: (a) contract performance — to provide the Service you have signed up for; (b) legitimate interests — to operate, secure and improve the Service, which includes preventing abuse and misuse, controlling the cost of the AI features, and keeping a record of enforcement decisions so they can be explained and appealed; and (c) legal obligation — where required by applicable law. Where we rely on legitimate interests we have weighed them against your rights, and you may object using the contact below.

4. Data Retention

We retain your account data and the content you create for as long as your account is active. You can delete your account yourself at any time, under Your data on the Profile screen: it shows you exactly what will be destroyed before you confirm, and the deletion is immediate. You can also ask us to do it using the contact in Section 11, and we will complete it within 30 days. Either way, deletion is subject only to retention required by law and the two exceptions below.

Backups. We keep off-site backups of the database so the Service can be restored after a failure. We encrypt each backup before it leaves us, so the storage provider holds only ciphertext and cannot read it. A backup copy expires after 30 days, so data from a deleted account can persist in a backup for up to that long after deletion. Backups are never used to restore an individual account we have deleted.

Inactive shared cases. A Value Room that nobody opens for 90 days is closed automatically, and 180 days after that its contents are erased — the questions and comments readers left, the record of who accessed it, and the invitations that granted access. The account holder is warned inside the Service 30 days before each step, and can keep the room open by opening it. Your own business case is not affected; only the shared room is.

Two records are kept beyond deletion, because destroying them would destroy the evidence that what we did was permitted. The consent record stores which version of these documents was accepted, by which email address, when, and the IP address and browser the acceptance came from. The enforcement record stores any restriction applied to a workspace — what was done, by whom, when, and why. Both are kept as long as we may need to answer for the decision, and neither is used for any other purpose.

5. Data Security

We use industry-standard security measures including encrypted storage of passwords, HTTPS for all data in transit, and session-based authentication. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

6. Sub-processors and International Transfers

To provide the Service we use a small number of vetted sub-processors, each under a data-processing agreement:

Sign-in providers. If you choose to sign in with Google or LinkedIn, that provider tells us your account identifier, your email address and whether it is verified, and knows that you signed in to the Service. They act as independent controllers for that exchange, under their own privacy policies. You never have to use them: an email address and a password work everywhere they do.

Content delivery. Our pages load typefaces from Google Fonts and icons from the jsDelivr network. Your browser contacts those services directly, so they receive your IP address and the page you were loading. They set no cookies for us and receive nothing else.

Pages we fetch for you. When you give the Service a web address to read — a product page, a report, a customer's site — our server fetches that page from your side, not yours, and passes its text to the AI features. The site you named will see a request from us.

Some of these process data outside the EEA (including the United States). For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK IDTA/Addendum for UK data), with supplementary measures where appropriate. We do not sell personal data and do not use it for advertising. Where we process personal data contained in the content you submit, we do so as your processor under the Data Processing Addendum. The current list is published at valuepointlabs.com/subprocessors, and we post a change there at least 30 days before a new sub-processor begins processing customer content.

7. Your Rights (GDPR)

Under GDPR, you have the right to:

7.1 Automated controls and human review

The Service applies automatic limits that can pause its AI features — described in full in Section 4.3 of the Terms of Service. These are usage and cost controls: they pause a feature, they never delete anything, and they do not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. We do not profile you: nothing about you is scored, and no rule reads anything beyond the volume and timing of the requests themselves.

Three rules act on their own without a person reviewing them first, and Section 4.3 of the Terms of Use describes each in full. We limit how many accounts can be created from one email domain in a day; we do not accept sign-ups from disposable mailbox services; and where two workspaces claim the same verified organisation name, we pause publishing for the later claim until we resolve which one holds it. None of the three reads anything about you as a person, and you can ask us to review any of them by writing to the appeal address in Section 11.

Where we pause a workspace's AI features because we have reviewed how it is being used, a person makes that decision. You may ask us for the reason, ask a person to review it, and contest it — reply to any email from us, or email the address in Section 11. Where AI has been paused we will respond within two business days.

8. Cookies

We use two strictly necessary cookies, and no others. One keeps you signed in to your account. The other keeps a reviewer signed in to a business case that was shared with them. We use no tracking or advertising cookies, and there is no advertising on the Service.

The Service also keeps working data in your browser's own storage — unsaved drafts and interface preferences such as which panels you left open. That stays on your device, is not sent to us, and clearing your browser data removes it.

9. Shared Business Cases

Account holders can share a business case with other people. If a case is shared with you and you open it by entering your email address, we process that email and your view activity (including timestamps), together with any comments you leave, and we make them visible to the account holder who shared the case (the "sender") — for example, in a list of who has viewed the case. We do this to operate the sharing feature; our legal basis is our and the sender's legitimate interest in knowing who has accessed a case they shared, and in providing the functionality you chose to use by opening the link. The sender, not Valuepoint Labs, decides what to share and with whom. To stop being shown a case, ask the sender to revoke your access; to exercise your data rights, contact us at the address below.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Where a change is material, you have to accept it: the next time you sign in, the Service shows you that the document changed and asks you to accept it before you continue. We record which version you accepted and when. Every version carries the version number and effective date at the top of this page.

11. Contact

For privacy queries, or to exercise any of the rights in Section 7 — including asking us to delete your account — contact [email protected]. We will respond within one month, as GDPR requires, and will tell you if we need longer and why.

To appeal a limit or a pause applied to your account, contact [email protected]. Where AI features have been paused by a decision of ours, a person will answer within two business days.

Both addresses reach Viimos Oy, the data controller identified at the top of this policy.