Legal

Privacy Policy

Last updated: 27 August 2026

Documents kept90 daysFrom upload, then permanently deleted.
Card detailsNever heldPayments are handled entirely by Stripe.
Your rightsUK GDPRAccess, correction, deletion, portability and objection.
Response timeOne monthThe statutory period for a data request.

1. Who we are — data controller identity

The data controller for the purposes of the UK GDPR and the Data Protection Act 2018 is Jake Bone, trading as Valify (“Valify”, “we”, “us”), a sole trader established and operating in England and Wales, United Kingdom.

General contact: support@valify.co.uk. For data protection requests specifically, see Section 10.

2. What we collect

We collect and process the following categories of data:

  • Company name, company size, role and contact details you provide when setting up your account
  • Your email address and account credentials
  • Documents you upload for review, and the reports generated from them
  • If you sign off a report: the name and role you enter, your account email address, and the date and time of the sign-off
  • Usage data such as scans performed, features used and login activity
  • Document decision records — where a document is accepted, the name entered as the person accepting it, the date and time, the issue counts on the report at that moment, and any note added
  • Payment details — payment is handled entirely by Stripe; Valify does not store your card details

3. How your documents are processed

Documents you upload are stored in Supabase Storage, then their content is routed through OpenRouter to a large language model (currently Anthropic's Claude Sonnet) in order to generate your review report.

The model provider does not retain uploaded document content after the analysis has been returned to Valify, and does not use it to train its models. Document content is transmitted solely for the purpose of producing your report, and is not retained once that analysis is complete.

Within Valify's own systems, documents are stored in a private Supabase Storage bucket with encryption at rest, accessible only via short-lived signed URLs, subject to the retention period set out in Section 4.

4. Data retention

Uploaded documents and their reports are retained for 90 days from the date of upload and then permanently deleted. Document decision records are deleted alongside the document they relate to. Account records (company name, email, billing history) are retained for as long as your account is active, and for a reasonable period afterward as required for legal, tax and accounting purposes.

5. Lawful basis for processing

We process your account and document data on the basis of performance of a contract — it is necessary in order to provide the review service you have signed up for. We process limited usage data on the basis of our legitimate interests in operating, securing and improving the service. Billing records are retained on the basis of our legal obligations under UK tax and accounting law.

6. Your rights

Under the UK GDPR you have the right to access the personal data we hold about you, request correction of inaccurate data, request erasure of your data (“right to erasure”), object to or restrict certain processing, and request a copy of your data in a portable format. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Deleting your account (Settings → Danger Zone, or by request to privacy@valify.co.uk) erases your documents, reports and any sign-off records along with the rest of your account data. This is permanent and cannot be undone once actioned — there is no way to recover a sign-off record, or anything else, after the account it belongs to has been deleted.

7. Third-party processors and international transfers

We use the following third-party processors (sub-processors), each bound by its own data processing terms:

  • Supabase — authentication, database and document storage
  • OpenRouter — routes document content to the AI model used for analysis (currently Anthropic Claude); OpenRouter does not train models on your data and does not retain document content after the analysis is returned
  • Stripe — payment processing; Valify does not store your card details. Stripe’s fraud-prevention script (Stripe.js) also runs on the signed-in pages of the service, where it collects device and browser information used solely to detect fraudulent payments. It does not read your documents or reports.
  • Resend — transactional email delivery
  • Vercel — website hosting and content delivery

International transfers. Several of the processors above are established in the United States. Where document or account data is transferred outside the UK, that transfer is made under a Data Processing Addendum incorporating the European Commission Standard Contractual Clauses as supplemented by the UK International Data Transfer Addendum (the UK Addendum to the EU SCCs), issued by the Information Commissioner under section 119A of the Data Protection Act 2018, or under applicable UK adequacy regulations. This is the safeguard relied upon under Article 46 UK GDPR for those transfers.

8. Cookies and similar technologies

Valify uses only the technologies necessary to run your account and keep it secure. We do not use third-party advertising or tracking cookies.

  • Session/auth cookies and local storage (set by Supabase Auth) — keep you signed in between visits and remember which account is active. Without these you would need to log in on every page.
  • Rate-limit local storage — the login and signup pages record recent attempt counts in your browser's local storage only, to apply the temporary lockouts described in our sign-up and login flows. This data never leaves your browser and is not linked to your account server-side.
  • Payment cookies (set by Stripe during checkout) — required for Stripe to process your payment securely and prevent fraud.

9. Partner Programme applicants and partners

If you apply to the Valify Partner Programme, the application form collects your name, email address, current role or company, a description of how you work with construction companies, an optional LinkedIn profile URL and how you heard about the programme. That information is used to assess the application and, if it is accepted, to run the partnership. It is processed on the basis of steps taken at your request prior to entering into a contract, and afterwards on the basis of performance of a contract.

Applications that are not accepted are deleted within 12 months. For accepted partners we additionally hold the introductions you register — the company introduced, the contact named, and the date and time it was registered — together with your commission statements and payment records. Registration records are what attribute a referral, and are kept for as long as the partnership is active and for six years afterwards, which is the retention period UK tax and accounting law requires of the payment records they support.

What a partner gives us. Registering an introduction means giving us four things about somebody at another company: their name, their work email address, their company and their role. You must have a lawful basis for passing those details on — in practice, an existing business relationship and their knowledge that you are making the introduction. We use them only to recognise that company if it signs up, and to contact that person in connection with the introduction you made. We do not add a registered contact to a marketing list.

What a partner gets back. Two written records. A registration confirmation when the introduction is registered, and a second confirmation if that company later creates an account — naming the company, the date, and whether they are on a trial or a paid plan, because that is what the commission is calculated from. Monthly statements then show, for each referred client, the plan and the ex-VAT amount the commission was worked out on. Nothing else about that account is ever disclosed to a partner: not the documents uploaded, not the reports produced, not the users on it, and not anything the account holder has entered into the product.

If you are a Valify customer and want to know whether your account is attributed to a partner, ask us at privacy@valify.co.uk and we will tell you, including who and when.

We do not sell partner data, and we do not disclose which partner introduced which company to anyone outside Valify except where the introduced company already knows or asks, or where we are required to by law.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated to active account holders by email.

11. Contact for data requests

To exercise any of the rights set out in Section 6 — including access, correction, erasure, restriction, objection or data portability — or to ask any question relating to how Valify handles personal data, contact:

Data protection requests: privacy@valify.co.uk
Please include the company name on your account and the nature of your request. We will acknowledge your request and respond within one month, as required by the UK GDPR.

This address is monitored specifically for data protection matters. Support questions go to support@valify.co.uk, billing queries to billing@valify.co.uk, and Partner Programme questions to partnerships@valify.co.uk, and anything else to hello@valify.co.uk.