1. Controller and contact
The controller responsible for data processing on this website and for the operation of the Valued platform is:
Digital Pioneers GmbH, Lilienstraße 11, 20095 Hamburg, Germany
Managing Director: Heiko Hubertz
Commercial register: Amtsgericht Hamburg, HRB 108462
Data protection contact: privacy@valued.com
2. Two roles: Controller and processor
Valued processes data in two distinct roles, and it is important to distinguish between them:
Controller
For data relating to the customer relationship itself — account and profile data, user administration, billing, support communication and website usage — we act as the controller. This section of the policy describes that processing.
Processor
For the investment content the customer uploads or imports (fund documents, capital calls, distributions, reports, cap tables, shareholder and loan data, and any personal data contained therein), we act as a processor on the customer's instructions. The customer remains the controller for that content and determines its purposes. This processing is governed by a data processing agreement pursuant to Art. 28 GDPR, which we make available on request.
3. Categories of data we process
Account and organisation data
- Name, business email address, password (stored only as a salted hash), preferred language and display settings.
- Organisation and team data, invitations, roles and permissions.
- Plan, subscription status and billing data (invoice address, VAT ID, payment status; card data is processed exclusively by our payment provider).
- A record of the emails we send you: the kind of email, the address it went to, its subject and language, when it was sent, and whether it was delivered, opened, clicked, rejected or reported as spam.
- Your notification settings, including the kinds of email you have switched off or unsubscribed from.
Investment content (processed on customer instruction)
- Uploaded documents such as capital call and distribution notices, quarterly and annual reports, capital account statements, tax documents, term sheets, SPAs, SHAs, loan and convertible loan agreements and cap tables.
- Financial data extracted from those documents: commitments, called and distributed amounts, equalisation, NAV, valuations, share classes, ownership percentages, shareholder names and loan terms.
- Names and contact details of natural persons that appear in these documents, for example shareholders, founders or signatories.
- Documents received via inbound email ingestion at platform email addresses configured by the customer.
Portal access data
Where a customer activates automated portal retrieval, we store the access credentials required for that portal in encrypted form and use them exclusively to log in on the customer's behalf and download documents made available to the customer.
Technical data
- Log data: IP address, timestamp, requested resource, status code, referrer, browser and operating system.
- Security and audit records: sign-in events, document access, processing jobs and administrative actions.
4. Purposes and legal bases
- Provision of the Service, account administration, document processing and support — Art. 6(1)(b) GDPR (performance of a contract).
- Processing of investment content containing personal data — on the customer’s instruction, Art. 6(1)(b) and Art. 28 GDPR; the legal basis vis-à-vis the data subject is determined by the customer as controller.
- Billing, accounting and retention of commercial documents — Art. 6(1)(c) GDPR (legal obligation).
- IT security, abuse prevention, logging, backups and troubleshooting — Art. 6(1)(f) GDPR (legitimate interest in a secure and stable service).
- Product improvement based on aggregated, anonymised usage statistics — Art. 6(1)(f) GDPR.
- Emails that the use of the Service requires, such as sign-in codes, security notices, invitations and billing notices — Art. 6(1)(b) GDPR.
- Notifications about your portfolio and emails that help you set up and use your account, including measuring whether they are opened and clicked — Art. 6(1)(f) GDPR (legitimate interest in informing customers about their own account and in sending only emails that are read); you can object at any time through the unsubscribe link in each of these emails. Details are under “Emails we send you”.
- Marketing emails and newsletters — Art. 6(1)(a) GDPR (consent), revocable at any time.
5. AI-assisted document processing
To classify documents and extract financial data, the content of uploaded documents — or a machine-readable rendition of it — is transmitted to our AI provider Anthropic via its commercial API and processed there transiently to generate the extraction result.
- Customer documents and the data derived from them are not used to train AI models, neither by us nor by our AI provider.
- The API is used under a commercial agreement with data processing terms; inputs and outputs are not retained by the provider for its own purposes beyond the limited period required for abuse monitoring under its terms.
- Extraction results are always presented to the customer for review before they are stored in the portfolio; there is no automated decision-making producing legal effects within the meaning of Art. 22 GDPR.
- Where a customer selects file-only storage, no AI analysis of the document takes place.
Customers who do not wish specific documents to be processed by AI can upload them in file-only mode or enter the corresponding data manually.
6. Connecting Valued to ChatGPT
Users can connect a Valued workspace to ChatGPT, OpenAI's AI assistant, so that ChatGPT can read their investment information while answering their questions. The connection is optional, is set up only by the user and can be ended at any time.
What the user decides
- The user starts the connection in ChatGPT, signs in to Valued and selects one workspace.
- The user chooses which categories ChatGPT may read: investments and financial records, stored document text and summaries, stored emails, and investment notes. Nothing is preselected.
- The connection can only read. It cannot change investments, upload or delete documents, send emails or execute transactions.
- Access ends after 30 days without use, and after 90 days at the latest; after that it requires the user’s consent again. The user can disconnect earlier under Settings → ChatGPT. Changing the password or the multi-factor authentication settings, or removal from the workspace, also ends it. Signing out of Valued does not.
- Every new connection is announced to the user by email.
What is transmitted to OpenAI
While the connection is active, ChatGPT requests information from Valued in response to the user's questions. Valued returns only records from the selected workspace and the selected categories, together with links to the corresponding pages in Valued. These records can contain personal data, for example names of shareholders, founders or signatories that appear in investment documents.
OpenAI is not our subprocessor. The transmission takes place on the user's instruction, and OpenAI processes the information it receives as a separate provider under its own terms and privacy policy, which the user has agreed to with OpenAI, including processing outside the European Union. Information already returned to ChatGPT remains in the existing conversation after the user disconnects; deleting it is done in ChatGPT.
What we record
- The connection itself: the user, the selected workspace and categories, the client (ChatGPT), when access was granted and last used, when it expires and when it was ended.
- For each read: the user and connection, which kind of information was requested, the identifier of a record that was opened, the outcome and the number of rows returned. We do not record the text of questions or searches, the content returned, or access tokens.
- Security events of the connection, such as consent granted, access revoked by the user or revoked after a reused credential, which are kept for 90 days and deleted after that at the next routine clean-up, which runs when a connection is set up.
These records serve the security of the Service and the investigation of misuse, on the basis of Art. 6(1)(f) GDPR. Transmitting the selected information to ChatGPT is part of performing the Service as requested by the user (Art. 6(1)(b) GDPR); for investment content uploaded by a customer, it takes place on that customer's instruction as described under "Two roles". Technical log data is retained as described under "Retention and deletion".
7. Hosting and place of processing
The application, the database and all uploaded documents are hosted within the European Union. Backups are stored in the same region.
Some of the specialised services listed below are provided by companies established outside the EU. In those cases, transfers are based on the EU Standard Contractual Clauses together with supplementary technical and organisational measures, and are limited to the data required for the respective function.
8. Subprocessors and service providers
We work with the following subprocessors. Each is bound by a data processing agreement and processes data only on our documented instructions.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting of the application database, document storage, authentication and backend functions; delivery of the application files | European Union (Stockholm region); application files also delivered from AWS edge locations |
| Anthropic | AI models used to classify documents and extract financial data from uploaded files | United States (Standard Contractual Clauses; no training on customer data) |
| Stripe | Processing of subscription payments and billing data | EU / United States (Standard Contractual Clauses) |
| Mailgun (Sinch) | Sending the emails described under "Emails we send you" and reporting whether they were delivered, opened and clicked; receiving inbound documents sent to platform email addresses | European Union (EU sending region) |
| Browserbase | Automated, customer-initiated retrieval of documents from investor portals | United States (Standard Contractual Clauses) |
| PostHog | Product analytics and session recording: which pages are opened, which elements are clicked, and where the Service fails. Every text and every form field is masked in the browser before transmission, so no portfolio or document content is included | European Union (PostHog EU Cloud) |
| Twelve Data | Market data for listed securities (prices, dividends, company information) | European Union / United States |
| Frankfurter (European Central Bank data) | Foreign exchange reference rates for currency conversion | European Union |
We will inform customers of any intended change to this list in advance, giving them the opportunity to object for good cause. To be notified of changes, write to privacy@valued.com.
9. Retention and deletion
- Investment content and derived data are retained for the term of the contract and are deleted upon deletion of the account or on the customer’s documented instruction.
- Account data is deleted after the end of the contract, unless statutory retention periods apply.
- Invoices and accounting records are retained for the statutory periods under German commercial and tax law (generally six to ten years).
- Technical log data is retained for a maximum of 90 days, unless required longer to investigate a specific security incident.
- The record of emails sent to you is deleted together with your account and, in any case, twelve months after the email was sent.
- Data contained in encrypted backups is removed within the regular backup rotation cycle of up to 30 days after deletion from the live system.
Account deletion can be initiated from the account settings and is confirmed via a one-time code sent by email.
10. Your rights
As a data subject, you have the following rights under the GDPR:
- Access to the personal data we process about you (Art. 15).
- Rectification of inaccurate data (Art. 16).
- Erasure (Art. 17) and restriction of processing (Art. 18).
- Data portability in a structured, commonly used, machine-readable format (Art. 20).
- Objection to processing based on legitimate interests (Art. 21).
- Withdrawal of consent with effect for the future (Art. 7(3)).
Requests can be sent to privacy@valued.com. If your data was uploaded to the platform by one of our customers, we will forward your request to that customer as the responsible controller.
You also have the right to lodge a complaint with a supervisory authority, for example the Hamburg Commissioner for Data Protection and Freedom of Information (Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit).
11. Security measures
- Encryption of all traffic in transit via TLS and encryption of stored data at rest.
- Row-level security in the database so that each account can access only its own records.
- Role-based access control for team members and support for multi-factor authentication.
- Time-limited signed URLs for document downloads instead of publicly accessible file links.
- Separation of production and test environments, least-privilege access for administrators, and logging of administrative actions.
- Automated backups with point-in-time recovery and regular restore verification.
- Encrypted storage of portal credentials and secrets in a dedicated secret store.
Suspected vulnerabilities can be reported confidentially to security@valued.com. We investigate all reports and will not pursue good-faith security research.
12. Emails we send you
We send email only to people who have an account with us or who have written to us, and to third parties a customer asks us to contact on their behalf. All email is sent through our processor Mailgun in the European Union.
Emails the Service requires
- Sign-in and confirmation: verification and reset codes, confirmation links.
- Security: notices that a password, a second factor, an email address or a connected application has changed, and the confirmation that an account has been deleted.
- Your team: invitations, and notices that an invitation was accepted, a member was removed or a role was changed.
- Your plan: notices about a failed payment, a plan that starts, changes or ends, and credits you have bought.
- Messages a member of our support team writes to you.
These emails belong to the contract and cannot be switched off. We do not measure whether they are opened or clicked.
Notifications about your portfolio
Members of an account are notified when something happens in it: a capital call, a distribution, a new document, a weekly report, a payment falling due, a price alert you set. These are switched on when an account is created. Each kind has its own switch under Settings, Notifications, and every such email carries two links: one that unsubscribes you from that kind of email and one that unsubscribes you from all notifications. Both work with one click and without signing in.
Emails that help you use your account
We look once a day at where an account stands (whether investments or documents have been added, whether documents are waiting for review, how many credits are left, when its owner last signed in) and may send the owner an email that fits: a first step after signing up, a reminder that documents are waiting, a notice that credits are running out, a note when you have not signed in for some weeks. An account's owner receives at most one of these per day, and none within two days of the last; a reminder that a data request you sent is still unanswered may come in addition. These emails have their own switches under Settings, Notifications, and the same two unsubscribe links. No profile is built beyond the state of the account described here, and nothing is passed on to third parties for advertising.
What we record and measure
- For every email we keep a record of what was sent to which address and when, and whether the receiving mail server accepted it, rejected it or the recipient reported it as spam. We need this to answer the question whether an email arrived, and to stop writing to addresses that do not exist.
- In notifications, in the emails that help you use your account and in the welcome email we also measure whether the email was opened and whether a link in it was clicked. For this the email contains a small image, and its links lead through the address email.app.valued.com operated by Mailgun before they open the page. We record that and when this happened, not what you do afterwards.
- Most mail programs let you stop images from being shown automatically; the opening of the email is then not recorded.
- If you report one of our emails as spam, we switch off all notifications for your address.
The record is deleted together with your account and, in any case, twelve months after the email was sent.
14. Automated decisions, minors and changes
Automated decision-making: we do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you.
Minors: the Service is directed exclusively at businesses and professional investors and is not intended for persons under 18 years of age.
Changes: we may update this policy to reflect changes to the Service or to legal requirements. Material changes will be communicated by email or through a notice in the application. The version and effective date at the top of this page always indicate the current version.
15. Contact
Privacy enquiries: privacy@valued.com
Security reports: security@valued.com
General contact: contact@valued.com
A data processing agreement pursuant to Art. 28 GDPR, including the current list of subprocessors, is available on request.
Effective date: 3 October 2026 · Version 2.8