This page summarises how Valify handles data under UK GDPR. The privacy policy and the data processing information are the governing documents — where this summary and those pages differ, those pages are correct.
The two kinds of data
Account data — your name, work email, company name, plan and billing records — is data we hold as controller, because we decide what to do with it in order to run the service.
Document content is different. When you upload a RAMS, we process it on your instructions in order to return a report, which makes you the controller and Valify the processor for that content. Your documents may contain personal data — named supervisors, first aiders, operatives — and that is the material this distinction matters for.
What we store
- Account details: name, email address, company name, hashed password.
- Uploaded documents and the text extracted from them, until 90 days after upload.
- Reports and their findings, associated with the document.
- Usage records: scan counts, dates, plan state.
- Billing records held by us and by Stripe. Card details are held by Stripe, never by Valify.
How long
- Documents and extracted text: permanently deleted 90 days after upload — see what happens to documents after 90 days.
- Account data: for as long as the account is open, and removed when you delete it.
- Billing and VAT records: for the period UK financial-records law requires, which is longer than the account.
Who else processes it
Supabase for database and file storage, Stripe for payments, Resend for transactional email, Vercel for hosting, and OpenRouter routing to the AI model — currently Anthropic's Claude — for the review itself. Document content is sent to the model strictly to generate your report and is not used to train models. The current list, with roles and locations, is maintained on the data processing page.
Your rights
Under UK GDPR you can request access to your personal data, correction of anything inaccurate, deletion, restriction of processing, portability, and you can object to processing. Most of them you can exercise yourself: correction from Settings, deletion by deleting your account. For anything else, contact us and we will respond within one month.
Where Valify acts as processor for document content, requests from individuals named in your documents should come to you as the controller, and we will support you in answering them.
Practical advice on document content
A RAMS legitimately names people — a named supervisor and a named first aider are requirements of a usable document, as how to complete a RAMS explains. What is not necessary is personal contact details, home addresses or health information beyond what the document needs. Keep the personal data in the document to what the job requires, and the retention question mostly answers itself.
Complaints
If you are unhappy with how we have handled your data, tell us first — and you have the right to complain to the Information Commissioner's Office at any point.
Was this helpful?
Still need help?
If this did not answer your question, email support@valify.co.uk and we will get back to you as quickly as we can. Tell us what you were trying to do and what happened — it saves a round trip.
Contact Support