← Back to home

    Terms

    Terms of Service

    Last updated: 2026-09-26

    These Terms of Service (the "Terms") govern access to and use of the Valerium platform, operated by Grovic Data ("Grovic Data", "we", "us"). By creating an account, accepting these Terms during sign-up, subscribing to a plan or using any part of the Services, the entity on whose behalf you act (the "Customer", "you") agrees to be bound by these Terms, the Privacy Policy and the Security page. If you do not agree, do not use the Services.

    On this page

    • 1. Acceptance and contracting party
    • 2. Definitions
    • 3. The Services
    • 4. Accounts and access
    • 5. Customer responsibilities for Customer Data
    • 6. Shared security responsibility
    • 7. Trial, plans and payments
    • 8. Cancellation, refunds and data export
    • 9. Acceptable use
    • 10. Third-party services and integrations
    • 11. Intellectual property
    • 12. Confidentiality
    • 13. Disclaimer of warranties
    • 14. Limitation of liability
    • 15. Indemnification
    • 16. Suspension and termination
    • 17. Force majeure
    • 18. Data Processing Addendum
    • 19. Changes to these Terms
    • 20. Governing law and disputes
    • 21. General provisions
    • 22. Contact

    1. Acceptance and contracting party

    Acceptance is given electronically and forms a binding agreement under applicable electronic-signature laws, including Brazilian Law No. 14.063/2020 and the U.S. ESIGN Act. If you accept on behalf of a company or other legal entity, you represent that you have authority to bind it, and "Customer" refers to that entity.

    The Services are intended exclusively for business and professional use. You must be at least 18 years old and legally able to enter into contracts.

    2. Definitions

    • Services: the Valerium platform, its APIs, integrations, AI features and related support.
    • Authorized User: any person the Customer allows to access the Services through its accounts, including employees, contractors and invited members.
    • Customer Data: all data, including personal data, that the Customer or its Authorized Users submit to, import into or generate through the Services.
    • End User: any individual whose personal data is contained in Customer Data (for example, the Customer's clients, patients, leads or staff).
    • Security Incident: a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data.

    3. The Services

    Valerium is a multi-tenant business management platform (finance, invoicing, contracts, CRM, scheduling, integrations and vertical modules). The Services are a software tool. They do not provide legal, tax, accounting, financial, medical or other professional advice, and the Customer remains solely responsible for the decisions it makes and the records it keeps using them.

    AI-assisted features generate outputs automatically and may be inaccurate, incomplete or unsuitable. The Customer must review any output before relying on it. We may add, change or discontinue features with reasonable notice when the change materially reduces functionality the Customer is paying for.

    4. Accounts and access

    • The Customer is responsible for the accuracy of its account information and for keeping it up to date.
    • The Customer is responsible for all activity carried out under its accounts, whether or not authorized by it, including every act and omission of its Authorized Users.
    • Multi-factor authentication is available. The Customer is responsible for enabling it and for requiring it of its Authorized Users.
    • The Customer must notify us at support@grovicdata.com without undue delay, and in any event within 24 hours, after becoming aware of or suspecting any unauthorized use of its accounts or credentials.

    5. Customer responsibilities for Customer Data

    The Customer is solely responsible for:

    • having a valid legal basis for collecting and processing Customer Data, and for providing End Users with every notice and obtaining every consent required by law;
    • the accuracy, quality, legality and content of Customer Data, and for having all rights needed to submit it to the Services;
    • complying with the laws and professional rules of its own industry, including health, financial, labor, tax and consumer-protection rules. Unless a separate written business associate agreement has been signed, the Customer must not use the Services to create, receive, maintain or transmit protected health information subject to the U.S. HIPAA;
    • maintaining its own backup copies of data that is critical to its business, using the export features available in the Services;
    • responding to End Users who wish to exercise their data protection rights, as the controller of Customer Data.

    6. Shared security responsibility

    Security is a shared responsibility. Grovic Data is responsible for implementing appropriate technical and organizational measures for the infrastructure it operates and the processing it performs, as described on the Security page. The Customer is responsible for everything within its control, including:

    • the confidentiality of passwords, sessions, tokens and API keys of its accounts and Authorized Users;
    • granting, reviewing and revoking access and roles, and removing former employees and contractors promptly;
    • the security of the devices, networks, email accounts and browsers used to access the Services;
    • links, customer portals, shared reports, public pages and exports that it creates, shares or downloads;
    • third-party applications and integrations that it connects to the Services, and the permissions it grants them;
    • phishing, social engineering or malware affecting its personnel.

    To the maximum extent permitted by applicable law, any Security Incident, unauthorized access, loss, alteration or disclosure of data that results from any of the causes listed above, or from a breach of these Terms by the Customer or its Authorized Users, is the sole responsibility of the Customer. In those cases Grovic Data shall not be liable for the resulting damages, fines, claims or costs, consistent with Article 43, III of the Brazilian General Data Protection Law (LGPD) and with the allocation of responsibilities between controllers and processors under other applicable data protection laws. The Customer, as controller, remains responsible for any notification to authorities and End Users that such an incident requires.

    7. Trial, plans and payments

    • We may offer a free trial of 7 (seven) days, with no credit card required. Access to paid features after the trial depends on subscribing to a plan.
    • Current plans and prices are shown in US dollars before purchase. The Starter and Pro plans have no setup fee. The Ultimate plan is contracted through a written proposal. Subscriptions renew automatically at the end of each billing cycle until cancelled.
    • Payments are processed by Stripe. We do not store full card numbers. Stripe's own terms also apply.
    • Fees are exclusive of taxes, which are the responsibility of each party as required by law. We may suspend the Services if an amount remains unpaid more than 10 days after its due date.
    • We may change prices with at least 30 days' notice; the new price applies from the next billing cycle after the notice period.

    8. Cancellation, refunds and data export

    The Customer may cancel at any time from its account settings. Cancellation stops the next renewal; the current paid period remains active until it ends. Amounts already paid are not refundable, except where a refund is required by mandatory law (for example, the 7-day withdrawal right under Article 49 of the Brazilian Consumer Protection Code, where it applies).

    After the subscription ends, the Customer has 30 days to export Customer Data. After that period, Customer Data may be permanently deleted from active systems, and residual copies in backups are overwritten on the infrastructure provider's backup cycle. Grovic Data is not responsible for data the Customer did not export within that period.

    9. Acceptable use

    The Customer and its Authorized Users must not, and must not allow anyone to:

    • violate any law or the rights of any third party;
    • attempt to access data of other customers, probe, scan or test the vulnerability of the Services outside the responsible disclosure process, or circumvent security controls;
    • reverse engineer the Services, or use them to build a competing product;
    • send spam or unsolicited communications, distribute malware, or overload the infrastructure;
    • store or process data they have no right to process, or use the Services for fraudulent or unlawful activity.

    10. Third-party services and integrations

    The Services may connect to services not operated by us (for example payment providers, banks and open-finance aggregators, delivery marketplaces, messaging, email, calendar and AI providers). The Customer chooses which integrations to enable and authorizes the related data exchange. Those services are governed by their own terms and privacy policies. To the maximum extent permitted by law, Grovic Data is not responsible for their availability, accuracy, security, data handling or any change to them.

    11. Intellectual property

    The Services, including software, design, trademarks and documentation, belong to Grovic Data or its licensors. We grant the Customer a limited, non-exclusive, non-transferable right to use the Services during the subscription. Customer Data belongs to the Customer; the Customer grants us a limited license to process it solely to provide, secure and support the Services and as required by law. We may use aggregated, de-identified data that does not identify the Customer or any individual to operate and improve the Services. Feedback may be used by us without restriction.

    Grovic Data does not develop software to order for Customers. The Ultimate plan is a subscription to the Services plus the services described in its proposal (such as integration support, process mapping and priority support); its fees do not pay for software development. On any plan, the Customer may send suggestions and feature requests. Grovic Data decides, at its sole discretion, whether, how and when to build them, as features of the Valerium platform, developed at its own cost and risk and made available to its customers generally. Those features, and any rights in the suggestions sent, belong exclusively to Grovic Data: the Customer acquires no ownership, exclusivity or license over them beyond using them as part of its subscription, and assigns to Grovic Data any rights it may have in its suggestions. Prioritizing a request does not create an obligation to build it or a deadline for doing so. This paragraph does not affect Customer Data or the Customer's confidential information, which remain the Customer's.

    12. Confidentiality

    Each party will protect the other's non-public information with at least reasonable care and use it only to perform these Terms. This obligation does not cover information that is or becomes public without breach, was already lawfully known, is independently developed, or must be disclosed by law or court order (in which case, where lawful, the disclosing party will give prior notice).

    13. Disclaimer of warranties

    To the maximum extent permitted by applicable law, the Services are provided "as is" and "as available". Grovic Data does not warrant that the Services will be uninterrupted, error-free or completely secure, that data will never be lost, or that the Services will meet every requirement of the Customer, and disclaims all implied warranties, including merchantability, fitness for a particular purpose and non-infringement. No security measure can guarantee absolute protection.

    14. Limitation of liability

    To the maximum extent permitted by applicable law:

    • Grovic Data shall not be liable for indirect, incidental, special, consequential, exemplary or punitive damages, or for lost profits, revenue, goodwill, business opportunities or data, however caused and even if advised of their possibility;
    • Grovic Data's total aggregate liability arising out of or relating to these Terms and the Services, under any theory, shall not exceed the amounts actually paid by the Customer for the Services in the 12 months preceding the event giving rise to the claim;
    • these limitations are an essential element of the bargain and reflect the allocation of risk between business parties (Brazilian Civil Code, art. 421-A).

    Nothing in these Terms limits liability that cannot be limited under applicable law, such as liability for willful misconduct or, where the Customer qualifies as a consumer, rights that consumer law makes non-waivable.

    15. Indemnification

    The Customer shall defend, indemnify and hold harmless Grovic Data, its affiliates, officers, employees and contractors from and against any claim, fine, penalty, loss, damage, cost and expense (including reasonable attorneys' fees) arising from: (a) Customer Data, including any claim by End Users or authorities concerning its processing; (b) any incident or event described in section 6 as the Customer's responsibility; (c) the Customer's or its Authorized Users' breach of these Terms or of applicable law; and (d) integrations and third-party services enabled by the Customer.

    16. Suspension and termination

    We may suspend or restrict access immediately, without liability, if we reasonably believe that an account is compromised, that the Services are being used in breach of section 9 or of the law, that continued access threatens the security or integrity of the Services or other customers, or if payment is overdue. Either party may terminate for material breach not cured within 15 days of written notice. Sections that by their nature should survive termination (including 5, 6, 11 to 15, 18 and 20) will survive.

    17. Force majeure

    Neither party is liable for failure or delay caused by events beyond its reasonable control, including natural disasters, outages or failures of internet, cloud, telecommunications or energy providers, large-scale cyberattacks, acts of government, war, strikes or pandemics (Brazilian Civil Code, art. 393). Payment obligations are not excused.

    18. Data Processing Addendum

    This section applies to personal data contained in Customer Data and forms the data processing agreement required by Article 39 of the LGPD, Article 28 of the EU and UK GDPR, and the service provider provisions of the California Consumer Privacy Act as amended (CCPA) and similar U.S. state laws.

    • Roles. The Customer is the controller (controlador) and Grovic Data is the processor (operador) and service provider. Grovic Data processes personal data only on the Customer's documented instructions, which consist of these Terms and the Customer's use and configuration of the Services. We will inform the Customer if we believe an instruction infringes the law, and may decline to follow it.
    • Confidentiality. Personnel with access to Customer Data are bound by confidentiality obligations.
    • Security. We maintain the technical and organizational measures described on the Security page, which may be updated provided the overall level of protection is not materially reduced.
    • Sub-processors. The Customer gives general authorization for the sub-processors listed in the Privacy Policy. We will give notice of new sub-processors, and the Customer may object on reasonable data protection grounds within 15 days; if we cannot address the objection, the Customer may terminate the affected Services as its sole remedy. We impose data protection obligations on sub-processors that are substantially equivalent to these.
    • Assistance. Taking into account the nature of the processing, we will provide reasonable assistance, through the features of the Services, with End User rights requests, security, and data protection impact assessments. Assistance beyond those features may be charged at reasonable rates.
    • Security Incidents. We will notify the Customer without undue delay after becoming aware of a Security Incident affecting Customer Data that is attributable to Grovic Data or its sub-processors, with the information reasonably available to us. The Customer, as controller, is responsible for assessing the incident and for any notification to the Brazilian National Data Protection Authority (ANPD, including within the deadline set by ANPD Resolution No. 15/2024), to other supervisory authorities and to End Users. Notification by us is not an acknowledgement of fault or liability.
    • International transfers. Where personal data is transferred across borders, the transfer relies on the mechanisms of LGPD Article 33 and ANPD Resolution No. 19/2024, and, where applicable, the EU Standard Contractual Clauses (Commission Decision 2021/914) and the UK International Data Transfer Addendum, which are incorporated by reference.
    • Return and deletion. On termination, Customer Data is handled as described in section 8, except where the law requires us to retain it.
    • Audits. We will make available information reasonably necessary to demonstrate compliance with this section. Any on-site audit requires 30 days' written notice, may occur no more than once per year, must not disrupt the Services or compromise other customers' data, is subject to confidentiality, and is carried out at the Customer's expense.
    • CCPA. Grovic Data will not sell or share personal information received from the Customer, will not retain, use or disclose it outside the direct business relationship or for any purpose other than performing the Services, and will not combine it with personal information from other sources except as permitted for service providers.
    • Liability. Each party's liability under this section is subject to section 14, to the extent permitted by applicable law.

    19. Changes to these Terms

    We may update these Terms. Material changes will be notified to the administrators of active accounts at least 30 days before they take effect. Continued use of the Services after the effective date constitutes acceptance. If the Customer does not agree, it may cancel before the changes take effect.

    20. Governing law and disputes

    These Terms are governed by the laws of the Federative Republic of Brazil. The courts of the judicial district of Grovic Data's registered office have exclusive jurisdiction, with express waiver of any other, however privileged. This does not remove mandatory rights a Customer that qualifies as a consumer may have to sue in its own domicile, nor mandatory data protection rights under the laws of the Customer's or an End User's country.

    21. General provisions

    • If any provision is held invalid, it will be limited to the minimum extent necessary and the rest remains in effect.
    • These Terms, the Privacy Policy and any order form are the entire agreement between the parties on their subject matter.
    • Failure to enforce a right is not a waiver. The Customer may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition or sale of assets.
    • These Terms are available in Portuguese and English. If they conflict, the Portuguese version prevails for Customers established in Brazil and the English version prevails for all other Customers.

    22. Contact

    Questions about these Terms: support@grovicdata.com. Privacy and data protection matters: dpo@grovicdata.com.

    By continuing to use Valerium, the Customer confirms that it has read and agrees to these Terms of Service.