Privacy
Last updated: 2026-09-13
This Privacy Policy explains how Grovic Data handles personal data in connection with the Valerium platform, in accordance with the Brazilian General Data Protection Law (Law No. 13.709/2018, "LGPD"), the EU and UK General Data Protection Regulation ("GDPR") and applicable U.S. state privacy laws, including the California Consumer Privacy Act as amended ("CCPA"). It should be read together with the Terms of Service and the Security page.
We act in two different roles:
If your data was entered into Valerium by a company you have a relationship with, please contact that company to exercise your rights. We will support them as their processor, and we may forward your request to them.
We do not intentionally collect sensitive personal data as controller. Customers in regulated sectors (such as health) may store sensitive data, including health data, as Customer Data. In that case the customer, as controller, is responsible for having a valid legal basis (LGPD art. 11; GDPR art. 9) and for complying with sector rules. Unless a separate business associate agreement has been signed, the platform must not be used to process protected health information subject to the U.S. HIPAA.
Our primary database is hosted in the São Paulo, Brazil region. Some sub-processors process data in other countries, including the United States. Transfers rely on the mechanisms of LGPD art. 33 and ANPD Resolution No. 19/2024 and, where applicable, the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
We apply technical and organizational measures designed to protect personal data, described on the Security page. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Security is shared: customers are responsible for protecting their credentials, managing the access of their users, and securing the devices and integrations they use, as set out in section 6 of the Terms of Service.
If a security incident affects personal data for which we are the controller and may cause relevant risk or damage, we will notify the Brazilian National Data Protection Authority (ANPD) and affected individuals as required by LGPD art. 48 and ANPD Resolution No. 15/2024, and other authorities where the law requires. For incidents affecting Customer Data, we notify the customer, which as controller is responsible for any notification to authorities and individuals.
You may request confirmation of processing, access, correction of incomplete or inaccurate data, anonymization, blocking or deletion of unnecessary or unlawfully processed data, portability, information about sharing, information about the possibility of refusing consent and its consequences, withdrawal of consent, and review of decisions taken solely on automated processing (LGPD arts. 18 and 20). Requests are answered within the deadlines of LGPD art. 19. You may also file a complaint with the ANPD.
You have the rights of access, rectification, erasure, restriction, portability and objection, the right not to be subject to decisions based solely on automated processing with legal or similarly significant effects, and the right to withdraw consent at any time (GDPR arts. 15 to 22). We respond within one month, extendable where the law allows. You may lodge a complaint with your local supervisory authority or, in the UK, the Information Commissioner's Office.
Depending on your state of residence (including California under the CCPA, and states such as Virginia, Colorado, Connecticut, Utah and Texas under their comprehensive privacy laws), you may have the right to:
We verify requests before acting on them, you may use an authorized agent where the law allows, and we respond within 45 days, extendable where permitted. If we decline a request, you may appeal by replying to our decision.
We send transactional messages needed to operate your account. We send marketing messages only with a valid legal basis, and every marketing email includes a way to unsubscribe, as required by the U.S. CAN-SPAM Act and applicable law.
AI-assisted features help users draft, summarize and analyze information. They do not make decisions that produce legal or similarly significant effects on individuals without human involvement. Outputs must be reviewed by the user before use.
The Services are intended for businesses and are not directed to anyone under 18. We do not knowingly collect personal data from children under 13, as defined by the U.S. COPPA. If you believe a child has provided us personal data, contact us and we will delete it.
We may update this Policy. Material changes will be notified in advance to the administrators of active accounts, and the date at the top of this page will be updated.
Data Protection Officer (Encarregado): dpo@grovicdata.com. General support: support@grovicdata.com. Brazilian authority: ANPD.