← Back to home

    Privacy

    Privacy Policy

    Last updated: 2026-09-13

    This Privacy Policy explains how Grovic Data handles personal data in connection with the Valerium platform, in accordance with the Brazilian General Data Protection Law (Law No. 13.709/2018, "LGPD"), the EU and UK General Data Protection Regulation ("GDPR") and applicable U.S. state privacy laws, including the California Consumer Privacy Act as amended ("CCPA"). It should be read together with the Terms of Service and the Security page.

    On this page

    • 1. Scope and our role
    • 2. Personal data we collect as controller
    • 3. Purposes and legal bases
    • 4. Sensitive data
    • 5. Sharing and sub-processors
    • 6. International transfers
    • 7. Retention
    • 8. Security
    • 9. Security incidents
    • 10. Your rights under the LGPD (Brazil)
    • 11. Your rights in the EEA and the UK
    • 12. Your rights under U.S. state privacy laws
    • 13. Cookies
    • 14. Communications
    • 15. AI and automated decisions
    • 16. Children
    • 17. Changes to this Policy
    • 18. Contact and Data Protection Officer

    1. Scope and our role

    We act in two different roles:

    • As controller for the personal data of our own customers and prospects: account, billing, support and website data, described in section 2.
    • As processor (operator) and service provider for the personal data our customers store in Valerium about their own clients, patients, leads and staff ("Customer Data"). For that data, our customer is the controller and decides why and how it is processed; we process it only on its instructions, under the data processing terms in section 18 of the Terms of Service.

    If your data was entered into Valerium by a company you have a relationship with, please contact that company to exercise your rights. We will support them as their processor, and we may forward your request to them.

    2. Personal data we collect as controller

    • Account: name, email, phone number, job title, company and authentication data (including multi-factor authentication settings).
    • Billing: plan, invoices, tax identifiers and payment status. Card data is collected directly by our payment providers; we do not store full card numbers.
    • Usage and technical: IP address, device and browser data, access logs, security events and product usage analytics.
    • Communications: support requests and messages you send us.
    • AI features: prompts and content you submit to AI-assisted features, processed to generate the requested output.

    3. Purposes and legal bases

    • Providing and operating the Services, account management and support: performance of a contract (LGPD art. 7, V; GDPR art. 6(1)(b)).
    • Billing, tax and accounting records: compliance with legal obligations (LGPD art. 7, II; GDPR art. 6(1)(c)).
    • Security, fraud prevention, abuse detection and access logs: legal obligation (including the 6-month access log retention required by art. 15 of Brazil's Internet Civil Framework, Law No. 12.965/2014) and legitimate interests (LGPD art. 7, IX; GDPR art. 6(1)(f)).
    • Improving the Services and aggregated analytics: legitimate interests.
    • Marketing communications and non-essential cookies: consent, which you may withdraw at any time (LGPD art. 7, I; GDPR art. 6(1)(a)).
    • Exercising and defending rights in legal, administrative or arbitration proceedings (LGPD art. 7, VI; GDPR art. 6(1)(f)).

    4. Sensitive data

    We do not intentionally collect sensitive personal data as controller. Customers in regulated sectors (such as health) may store sensitive data, including health data, as Customer Data. In that case the customer, as controller, is responsible for having a valid legal basis (LGPD art. 11; GDPR art. 9) and for complying with sector rules. Unless a separate business associate agreement has been signed, the platform must not be used to process protected health information subject to the U.S. HIPAA.

    5. Sharing and sub-processors

    We do not sell personal data and we do not share it for cross-context behavioral advertising. We share personal data only with:

    • Sub-processors that help us run the Services: Supabase (database, authentication and file storage), Hostinger (application hosting), Cloudflare (bot protection), Trigger.dev (background jobs), Stripe, AbacatePay and PagBank (payments), Resend (transactional email), Sentry (error monitoring), OpenPanel (product analytics), and OpenAI and NVIDIA (AI-assisted features).
    • Third-party services the customer chooses to connect (for example banks and open-finance aggregators, delivery marketplaces, calendars, messaging and CRM tools). Those transfers happen at the customer's direction and are governed by the third party's own terms.
    • Authorities, when required by law, court order or to protect rights, safety and security.
    • A successor in a merger, acquisition or sale of assets, subject to this Policy.

    6. International transfers

    Our primary database is hosted in the São Paulo, Brazil region. Some sub-processors process data in other countries, including the United States. Transfers rely on the mechanisms of LGPD art. 33 and ANPD Resolution No. 19/2024 and, where applicable, the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.

    7. Retention

    • Account and billing data: for the life of the contract and for up to 5 years afterwards, to meet tax obligations and the limitation periods for legal claims.
    • Access logs: at least 6 months, as required by Law No. 12.965/2014.
    • Customer Data: as instructed by the customer; after the subscription ends, as described in section 8 of the Terms of Service.
    • Data processed on the basis of consent: until consent is withdrawn, unless another legal basis applies.

    8. Security

    We apply technical and organizational measures designed to protect personal data, described on the Security page. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Security is shared: customers are responsible for protecting their credentials, managing the access of their users, and securing the devices and integrations they use, as set out in section 6 of the Terms of Service.

    9. Security incidents

    If a security incident affects personal data for which we are the controller and may cause relevant risk or damage, we will notify the Brazilian National Data Protection Authority (ANPD) and affected individuals as required by LGPD art. 48 and ANPD Resolution No. 15/2024, and other authorities where the law requires. For incidents affecting Customer Data, we notify the customer, which as controller is responsible for any notification to authorities and individuals.

    10. Your rights under the LGPD (Brazil)

    You may request confirmation of processing, access, correction of incomplete or inaccurate data, anonymization, blocking or deletion of unnecessary or unlawfully processed data, portability, information about sharing, information about the possibility of refusing consent and its consequences, withdrawal of consent, and review of decisions taken solely on automated processing (LGPD arts. 18 and 20). Requests are answered within the deadlines of LGPD art. 19. You may also file a complaint with the ANPD.

    11. Your rights in the EEA and the UK

    You have the rights of access, rectification, erasure, restriction, portability and objection, the right not to be subject to decisions based solely on automated processing with legal or similarly significant effects, and the right to withdraw consent at any time (GDPR arts. 15 to 22). We respond within one month, extendable where the law allows. You may lodge a complaint with your local supervisory authority or, in the UK, the Information Commissioner's Office.

    12. Your rights under U.S. state privacy laws

    Depending on your state of residence (including California under the CCPA, and states such as Virginia, Colorado, Connecticut, Utah and Texas under their comprehensive privacy laws), you may have the right to:

    • know and access the personal information we hold about you;
    • correct inaccurate personal information;
    • delete personal information, subject to legal exceptions;
    • obtain a portable copy;
    • opt out of the sale or sharing of personal information and of targeted advertising. We do not sell or share personal information and we honor Global Privacy Control signals;
    • limit the use of sensitive personal information. We do not use it for purposes that require offering this right;
    • not be discriminated against for exercising these rights.

    We verify requests before acting on them, you may use an authorized agent where the law allows, and we respond within 45 days, extendable where permitted. If we decline a request, you may appeal by replying to our decision.

    13. Cookies

    We use essential cookies (authentication, security and preferences) and, with your consent, analytics cookies. We do not use cookies for behavioral advertising or cross-site tracking. You can change your choices through the cookie banner or your browser settings; blocking essential cookies may prevent the Services from working.

    14. Communications

    We send transactional messages needed to operate your account. We send marketing messages only with a valid legal basis, and every marketing email includes a way to unsubscribe, as required by the U.S. CAN-SPAM Act and applicable law.

    15. AI and automated decisions

    AI-assisted features help users draft, summarize and analyze information. They do not make decisions that produce legal or similarly significant effects on individuals without human involvement. Outputs must be reviewed by the user before use.

    16. Children

    The Services are intended for businesses and are not directed to anyone under 18. We do not knowingly collect personal data from children under 13, as defined by the U.S. COPPA. If you believe a child has provided us personal data, contact us and we will delete it.

    17. Changes to this Policy

    We may update this Policy. Material changes will be notified in advance to the administrators of active accounts, and the date at the top of this page will be updated.

    18. Contact and Data Protection Officer

    Data Protection Officer (Encarregado): dpo@grovicdata.com. General support: support@grovicdata.com. Brazilian authority: ANPD.