Privacy policy

Effective date: 3 October 2026 · Version 2.8

Valued is used by investors to administer highly confidential portfolio information. This policy explains what data we process, on what legal basis, where it is hosted, which subprocessors are involved and how AI-assisted document extraction works.

1. Controller and contact

The controller responsible for data processing on this website and for the operation of the Valued platform is:

Digital Pioneers GmbH, Lilienstraße 11, 20095 Hamburg, Germany
Managing Director: Heiko Hubertz
Commercial register: Amtsgericht Hamburg, HRB 108462

Data protection contact: privacy@valued.com

2. Two roles: Controller and processor

Valued processes data in two distinct roles, and it is important to distinguish between them:

Controller

For data relating to the customer relationship itself — account and profile data, user administration, billing, support communication and website usage — we act as the controller. This section of the policy describes that processing.

Processor

For the investment content the customer uploads or imports (fund documents, capital calls, distributions, reports, cap tables, shareholder and loan data, and any personal data contained therein), we act as a processor on the customer's instructions. The customer remains the controller for that content and determines its purposes. This processing is governed by a data processing agreement pursuant to Art. 28 GDPR, which we make available on request.

3. Categories of data we process

Account and organisation data

  • Name, business email address, password (stored only as a salted hash), preferred language and display settings.
  • Organisation and team data, invitations, roles and permissions.
  • Plan, subscription status and billing data (invoice address, VAT ID, payment status; card data is processed exclusively by our payment provider).
  • A record of the emails we send you: the kind of email, the address it went to, its subject and language, when it was sent, and whether it was delivered, opened, clicked, rejected or reported as spam.
  • Your notification settings, including the kinds of email you have switched off or unsubscribed from.

Investment content (processed on customer instruction)

  • Uploaded documents such as capital call and distribution notices, quarterly and annual reports, capital account statements, tax documents, term sheets, SPAs, SHAs, loan and convertible loan agreements and cap tables.
  • Financial data extracted from those documents: commitments, called and distributed amounts, equalisation, NAV, valuations, share classes, ownership percentages, shareholder names and loan terms.
  • Names and contact details of natural persons that appear in these documents, for example shareholders, founders or signatories.
  • Documents received via inbound email ingestion at platform email addresses configured by the customer.

Portal access data

Where a customer activates automated portal retrieval, we store the access credentials required for that portal in encrypted form and use them exclusively to log in on the customer's behalf and download documents made available to the customer.

Technical data

  • Log data: IP address, timestamp, requested resource, status code, referrer, browser and operating system.
  • Security and audit records: sign-in events, document access, processing jobs and administrative actions.

4. Purposes and legal bases

  • Provision of the Service, account administration, document processing and support — Art. 6(1)(b) GDPR (performance of a contract).
  • Processing of investment content containing personal data — on the customer’s instruction, Art. 6(1)(b) and Art. 28 GDPR; the legal basis vis-à-vis the data subject is determined by the customer as controller.
  • Billing, accounting and retention of commercial documents — Art. 6(1)(c) GDPR (legal obligation).
  • IT security, abuse prevention, logging, backups and troubleshooting — Art. 6(1)(f) GDPR (legitimate interest in a secure and stable service).
  • Product improvement based on aggregated, anonymised usage statistics — Art. 6(1)(f) GDPR.
  • Emails that the use of the Service requires, such as sign-in codes, security notices, invitations and billing notices — Art. 6(1)(b) GDPR.
  • Notifications about your portfolio and emails that help you set up and use your account, including measuring whether they are opened and clicked — Art. 6(1)(f) GDPR (legitimate interest in informing customers about their own account and in sending only emails that are read); you can object at any time through the unsubscribe link in each of these emails. Details are under “Emails we send you”.
  • Marketing emails and newsletters — Art. 6(1)(a) GDPR (consent), revocable at any time.

5. AI-assisted document processing

To classify documents and extract financial data, the content of uploaded documents — or a machine-readable rendition of it — is transmitted to our AI provider Anthropic via its commercial API and processed there transiently to generate the extraction result.

  • Customer documents and the data derived from them are not used to train AI models, neither by us nor by our AI provider.
  • The API is used under a commercial agreement with data processing terms; inputs and outputs are not retained by the provider for its own purposes beyond the limited period required for abuse monitoring under its terms.
  • Extraction results are always presented to the customer for review before they are stored in the portfolio; there is no automated decision-making producing legal effects within the meaning of Art. 22 GDPR.
  • Where a customer selects file-only storage, no AI analysis of the document takes place.

Customers who do not wish specific documents to be processed by AI can upload them in file-only mode or enter the corresponding data manually.

6. Connecting Valued to ChatGPT

Users can connect a Valued workspace to ChatGPT, OpenAI's AI assistant, so that ChatGPT can read their investment information while answering their questions. The connection is optional, is set up only by the user and can be ended at any time.

What the user decides

  • The user starts the connection in ChatGPT, signs in to Valued and selects one workspace.
  • The user chooses which categories ChatGPT may read: investments and financial records, stored document text and summaries, stored emails, and investment notes. Nothing is preselected.
  • The connection can only read. It cannot change investments, upload or delete documents, send emails or execute transactions.
  • Access ends after 30 days without use, and after 90 days at the latest; after that it requires the user’s consent again. The user can disconnect earlier under Settings → ChatGPT. Changing the password or the multi-factor authentication settings, or removal from the workspace, also ends it. Signing out of Valued does not.
  • Every new connection is announced to the user by email.

What is transmitted to OpenAI

While the connection is active, ChatGPT requests information from Valued in response to the user's questions. Valued returns only records from the selected workspace and the selected categories, together with links to the corresponding pages in Valued. These records can contain personal data, for example names of shareholders, founders or signatories that appear in investment documents.

OpenAI is not our subprocessor. The transmission takes place on the user's instruction, and OpenAI processes the information it receives as a separate provider under its own terms and privacy policy, which the user has agreed to with OpenAI, including processing outside the European Union. Information already returned to ChatGPT remains in the existing conversation after the user disconnects; deleting it is done in ChatGPT.

What we record

  • The connection itself: the user, the selected workspace and categories, the client (ChatGPT), when access was granted and last used, when it expires and when it was ended.
  • For each read: the user and connection, which kind of information was requested, the identifier of a record that was opened, the outcome and the number of rows returned. We do not record the text of questions or searches, the content returned, or access tokens.
  • Security events of the connection, such as consent granted, access revoked by the user or revoked after a reused credential, which are kept for 90 days and deleted after that at the next routine clean-up, which runs when a connection is set up.

These records serve the security of the Service and the investigation of misuse, on the basis of Art. 6(1)(f) GDPR. Transmitting the selected information to ChatGPT is part of performing the Service as requested by the user (Art. 6(1)(b) GDPR); for investment content uploaded by a customer, it takes place on that customer's instruction as described under "Two roles". Technical log data is retained as described under "Retention and deletion".

7. Hosting and place of processing

The application, the database and all uploaded documents are hosted within the European Union. Backups are stored in the same region.

Some of the specialised services listed below are provided by companies established outside the EU. In those cases, transfers are based on the EU Standard Contractual Clauses together with supplementary technical and organisational measures, and are limited to the data required for the respective function.

8. Subprocessors and service providers

We work with the following subprocessors. Each is bound by a data processing agreement and processes data only on our documented instructions.

ProviderPurposeLocation
Amazon Web Services (AWS)Hosting of the application database, document storage, authentication and backend functions; delivery of the application filesEuropean Union (Stockholm region); application files also delivered from AWS edge locations
AnthropicAI models used to classify documents and extract financial data from uploaded filesUnited States (Standard Contractual Clauses; no training on customer data)
StripeProcessing of subscription payments and billing dataEU / United States (Standard Contractual Clauses)
Mailgun (Sinch)Sending the emails described under "Emails we send you" and reporting whether they were delivered, opened and clicked; receiving inbound documents sent to platform email addressesEuropean Union (EU sending region)
BrowserbaseAutomated, customer-initiated retrieval of documents from investor portalsUnited States (Standard Contractual Clauses)
PostHogProduct analytics and session recording: which pages are opened, which elements are clicked, and where the Service fails. Every text and every form field is masked in the browser before transmission, so no portfolio or document content is includedEuropean Union (PostHog EU Cloud)
Twelve DataMarket data for listed securities (prices, dividends, company information)European Union / United States
Frankfurter (European Central Bank data)Foreign exchange reference rates for currency conversionEuropean Union

We will inform customers of any intended change to this list in advance, giving them the opportunity to object for good cause. To be notified of changes, write to privacy@valued.com.

9. Retention and deletion

  • Investment content and derived data are retained for the term of the contract and are deleted upon deletion of the account or on the customer’s documented instruction.
  • Account data is deleted after the end of the contract, unless statutory retention periods apply.
  • Invoices and accounting records are retained for the statutory periods under German commercial and tax law (generally six to ten years).
  • Technical log data is retained for a maximum of 90 days, unless required longer to investigate a specific security incident.
  • The record of emails sent to you is deleted together with your account and, in any case, twelve months after the email was sent.
  • Data contained in encrypted backups is removed within the regular backup rotation cycle of up to 30 days after deletion from the live system.

Account deletion can be initiated from the account settings and is confirmed via a one-time code sent by email.

10. Your rights

As a data subject, you have the following rights under the GDPR:

  • Access to the personal data we process about you (Art. 15).
  • Rectification of inaccurate data (Art. 16).
  • Erasure (Art. 17) and restriction of processing (Art. 18).
  • Data portability in a structured, commonly used, machine-readable format (Art. 20).
  • Objection to processing based on legitimate interests (Art. 21).
  • Withdrawal of consent with effect for the future (Art. 7(3)).

Requests can be sent to privacy@valued.com. If your data was uploaded to the platform by one of our customers, we will forward your request to that customer as the responsible controller.

You also have the right to lodge a complaint with a supervisory authority, for example the Hamburg Commissioner for Data Protection and Freedom of Information (Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit).

11. Security measures

  • Encryption of all traffic in transit via TLS and encryption of stored data at rest.
  • Row-level security in the database so that each account can access only its own records.
  • Role-based access control for team members and support for multi-factor authentication.
  • Time-limited signed URLs for document downloads instead of publicly accessible file links.
  • Separation of production and test environments, least-privilege access for administrators, and logging of administrative actions.
  • Automated backups with point-in-time recovery and regular restore verification.
  • Encrypted storage of portal credentials and secrets in a dedicated secret store.

Suspected vulnerabilities can be reported confidentially to security@valued.com. We investigate all reports and will not pursue good-faith security research.

12. Emails we send you

We send email only to people who have an account with us or who have written to us, and to third parties a customer asks us to contact on their behalf. All email is sent through our processor Mailgun in the European Union.

Emails the Service requires

  • Sign-in and confirmation: verification and reset codes, confirmation links.
  • Security: notices that a password, a second factor, an email address or a connected application has changed, and the confirmation that an account has been deleted.
  • Your team: invitations, and notices that an invitation was accepted, a member was removed or a role was changed.
  • Your plan: notices about a failed payment, a plan that starts, changes or ends, and credits you have bought.
  • Messages a member of our support team writes to you.

These emails belong to the contract and cannot be switched off. We do not measure whether they are opened or clicked.

Notifications about your portfolio

Members of an account are notified when something happens in it: a capital call, a distribution, a new document, a weekly report, a payment falling due, a price alert you set. These are switched on when an account is created. Each kind has its own switch under Settings, Notifications, and every such email carries two links: one that unsubscribes you from that kind of email and one that unsubscribes you from all notifications. Both work with one click and without signing in.

Emails that help you use your account

We look once a day at where an account stands (whether investments or documents have been added, whether documents are waiting for review, how many credits are left, when its owner last signed in) and may send the owner an email that fits: a first step after signing up, a reminder that documents are waiting, a notice that credits are running out, a note when you have not signed in for some weeks. An account's owner receives at most one of these per day, and none within two days of the last; a reminder that a data request you sent is still unanswered may come in addition. These emails have their own switches under Settings, Notifications, and the same two unsubscribe links. No profile is built beyond the state of the account described here, and nothing is passed on to third parties for advertising.

What we record and measure

  • For every email we keep a record of what was sent to which address and when, and whether the receiving mail server accepted it, rejected it or the recipient reported it as spam. We need this to answer the question whether an email arrived, and to stop writing to addresses that do not exist.
  • In notifications, in the emails that help you use your account and in the welcome email we also measure whether the email was opened and whether a link in it was clicked. For this the email contains a small image, and its links lead through the address email.app.valued.com operated by Mailgun before they open the page. We record that and when this happened, not what you do afterwards.
  • Most mail programs let you stop images from being shown automatically; the opening of the email is then not recorded.
  • If you report one of our emails as spam, we switch off all notifications for your address.

The record is deleted together with your account and, in any case, twelve months after the email was sent.

13. Cookies, browser storage, fonts and advertising measurement

Cookies: the website and the application set no cookies of their own. Neither www.valued.com nor our API sends a cookie to your browser. The only cookies are those of Google Ads and PostHog described below, and only after you have agreed to them.

Browser storage: the application uses your browser's local storage to keep you signed in and to remember interface preferences. It holds your session token, the selected light or dark theme, the portfolio view mode and the sort and dismiss settings of the action centre. Session storage holds the state of a document review while you are working on it and is cleared when the tab is closed. Nothing in either store is read by third parties. This storage is strictly necessary to provide the Service you have requested, so under Section 25(2) No. 2 TDDDG (formerly TTDSG) it requires no consent; the associated processing is based on Art. 6(1)(b) GDPR.

Fonts: the typeface used on this website (Inter) is served from our own servers. No connection to Google Fonts or any other font service is made when you visit, and your IP address is not transmitted to a font provider.

Advertising measurement (Google Ads): we advertise on Google and measure whether an advertisement led to a visit, a registration, an enquiry or a purchase. For this we use the Google tag and the conversion tracking of Google Ads, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, in Google's consent mode. What the tag does depends on your choice in the consent notice.

Without your consent (before you have chosen, and after you have declined), the tag is loaded from googletagmanager.com but sets and reads no cookies and stores nothing on your device. The request that fetches it transmits your IP address, browser and device information and the address of the page visited to Google. The tag also sends Google signals without cookies or advertising identifiers: that a page was viewed or that one of the events named above took place, your consent state, and, where you arrived through an advertisement, the click identifier contained in the page address. Google uses these signals to estimate statistically how many conversions our advertisements produced; according to Google they are not used to identify you or to personalise advertising. The legal basis is our legitimate interest in measuring the effectiveness of our advertising in aggregate (Art. 6(1)(f) GDPR). You may object to this processing at any time using the contact details below.

If you consent, Google additionally sets cookies in your browser (in particular_gcl_au and _gcl_aw, kept for up to 90 days) that hold the identifier of the advertisement you clicked, and receives a pseudonymous reference used only to avoid counting the same event twice. Google may link this information to your Google account and use it to personalise advertising and to build audiences for our advertisements. The legal basis is your consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR. You can withdraw it at any time with effect for the future through "Cookie settings" in the footer of the website; the Google Ads cookies are then deleted.

With your consent, Google's enhanced conversions are also active. When you send a form on this website — a registration, an enquiry — the Google tag may read the e-mail address you entered in it, convert it in your browser into an irreversible hash value (SHA-256) and transmit that value alone. Google compares it with the correspondingly hashed data of signed-in Google accounts in order to attribute a conversion to an advertisement click more reliably. The address itself does not leave your browser, and we do not transmit it to Google for this purpose; the hash value is nevertheless personal data, because it identifies the same person every time. Without your consent no such value is sent. The legal basis is your consent (Art. 6(1)(a) GDPR), and it is withdrawn in the same way as above.

In neither case do we send Google your name, your email address or any content of your portfolio or your documents. We receive aggregated statistics only and cannot identify you from them. Google may process the data on servers in the United States; Google LLC is certified under the EU-U.S. Data Privacy Framework, and Standard Contractual Clauses apply in addition. Further information is available in Google's privacy policy at policies.google.com/privacy.

Product analytics and session recording (PostHog): we use PostHog to see how the website and the application are used: which pages are opened, which elements are clicked, and where something fails. What PostHog does depends on the same choice in the consent notice.

Without your consent (before you have chosen, and after you have declined), the events are sent without any cookie and nothing is stored on your device, so each visit counts as a new visitor and no visits are linked to one another. The request transmits your IP address, browser and device information and the address of the page. No session is recorded. The legal basis is our legitimate interest in knowing in aggregate which parts of the Service are used and where they fail (Art. 6(1)(f) GDPR); you may object at any time using the contact details below.

If you consent, PostHog additionally stores an identifier in your browser (a cookie and an entry in local storage) so that your visits are recognised as one person's, and records your session: the structure of the pages you see and what you click, as a replayable reconstruction. The legal basis is your consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR, withdrawn at any time with effect for the future through "Cookie settings" in the footer, after which the recording stops and the stored identifier is discarded.

What a recording cannot contain: every text and every form field is replaced in your browser before anything is transmitted, so a recording shows the layout, the navigation and the clicks, and no figure, name, address or account number from your portfolio or your documents. For the same reason the entries you type are not transmitted. Where we use models to read your documents, we send PostHog the model, the number of tokens and the duration of the request, and neither the document nor the model's answer.

Where PostHog processes this: we use PostHog's European cloud, so the events and the recordings are stored and processed on servers in the European Union. No transfer to a third country takes place for this purpose, and no Standard Contractual Clauses are needed for it.

Beyond this we use no web analytics and no other tracking pixels on the website or in the application. What we measure in emails is described under "Emails we send you".

14. Automated decisions, minors and changes

Automated decision-making: we do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you.

Minors: the Service is directed exclusively at businesses and professional investors and is not intended for persons under 18 years of age.

Changes: we may update this policy to reflect changes to the Service or to legal requirements. Material changes will be communicated by email or through a notice in the application. The version and effective date at the top of this page always indicate the current version.

15. Contact

Privacy enquiries: privacy@valued.com
Security reports: security@valued.com
General contact: contact@valued.com

A data processing agreement pursuant to Art. 28 GDPR, including the current list of subprocessors, is available on request.

Effective date: 3 October 2026 · Version 2.8