Privacy Policy
Effective: 1 May 2026. Last updated: 8 September 2026. This notice explains what personal data valicon.ai processes and on what legal basis, for both founder accounts and the investors and other counterparties who visit a data room. Questions? Email hello@valicon.ai.
1. Controller
Spectup, sole proprietorship, Niclas Schlopsna, Geitauer Straße 14, 81379 München, Germany. Email hello@valicon.ai. See our Imprint for full operator information.
Spectup operates valicon.ai as the sole controller within the meaning of GDPR Art. 4(7). For founders who use valicon.ai to host investor data on their own behalf, Spectup acts as a processor for that hosted content under GDPR Art. 28; the founder is the controller in that relationship and we sign a data-processing addendum (DPA) on request.
2. Data we process
Founder accounts (you signed up directly):
- Account fields: full name, work email, company name, password (hashed with bcrypt).
- Deal profile: purpose (startup / growth / fund), industry, stage, HQ country, target raise, headline metric (revenue or AUM band), traction signals.
- Files you upload to your data room (decks, financials, legal documents, etc.).
- Billing data when you upgrade to Pro: handled directly by Stripe; we store only the Stripe customer ID and subscription metadata, never your card.
- Referral data: a unique referral code we assign to your workspace, plus an optional link to the workspace that referred you (if you signed up via someone else’s link). Used to credit one-month rewards to the referrer when you upgrade to a paid plan.
- Email preferences: the on/off state of three optional notification categories (first-view alerts, weekly digest, product updates). Always-on transactional emails are listed above.
- Server logs: IP address, user agent and timestamps of API calls, recorded for security and abuse detection.
- Audit log: per-action records of writes you perform inside the workspace (file upload/delete, invite send, NDA template edit, etc.) so you can reconstruct who did what. Retained for 90 days.
Investors and other counterparties visiting a data room:
- Contact details supplied by the founder who invited you, or that you enter yourself at a share-link entry gate: email address, and where provided a name, company, phone number or professional profile link.
- NDA acceptance, where the room requires one: typed name, signature image, timestamp and IP address, kept as legal evidence.
- Activity inside the data room: room opens, pages and slides viewed, time spent per slide, block and tab, file opens and downloads, and questions you submit. This is recorded against your contact record and is visible to the workspace that invited you.
- Technical session data: IP address, browser user-agent string and timestamps, recorded when a session is created.
- Where the workspace that invited you has opted in, eligible activity may also contribute to aggregate benchmark statistics - for example the typical time readers spend on a slide across comparable deals. The benchmark system does not create or maintain a separate cross-workspace profile of you: it reads the records described above and reports group figures. Those underlying records still exist and still relate to you; this bullet is about what the benchmarks add, not a statement that we hold nothing. Rooms that present an NDA offer a checkbox to exclude your activity from them.
We do not use third-party advertising trackers, social-media pixels, or cross-site analytics. There is no tracking on the public marketing site beyond essential server logs.
3. Legal basis (GDPR Art. 6)
- Contract performance (Art. 6(1)(b)) - for everything needed to operate your account: login, hosting your files, sending invites, billing.
- Legitimate interest (Art. 6(1)(f)) - for security logs, abuse detection, and the activity tracking we expose to founders inside their own data rooms (the founder’s legitimate interest in protecting confidential deal materials).
- Consent (Art. 6(1)(a)) - for optional analytics cookies on the marketing site, and for a workspace’s participation in cross-workspace benchmarks.
- Legal obligation (Art. 6(1)(c)) - where a statutory obligation applies to a record, for example commercial or tax record-keeping duties for billing records.
Signing a room’s non-disclosure agreement is not the legal basis for the activity data described in section 2. Rooms do not require an NDA by default, so many visitors are never presented with one; where an NDA is presented, it governs confidentiality rather than data protection.
4. Cookies and similar technologies
Every cookie valicon.ai sets is first-party. We set no third-party cookies, and the optional analytics cookies described in section 4a load only after you accept them. The full list follows, grouped by what each one does.
Account and session
dr_session- signed login token for founder and staff accounts. HTTP-only, SameSite=Lax. Persists 30 days when “keep me signed in” is selected, otherwise cleared when the browser closes.dr_investor- signed login token for the separate investor account area. HTTP-only, SameSite=Lax.dr_pending_2fa- short-lived token held between password entry and two-factor confirmation. HTTP-only, expires after 5 minutes.
Data-room visitors
dr_inv_<id>- one per invitation link. Identifies your visit session so a password, one-time code or NDA already completed is not asked for again on the next page. HTTP-only, SameSite=Lax, 30-day expiry.
Workspace interface state
dr_active_client- which workspace the dashboard is currently showing. Readable by the page so the interface can render without an extra request; the server independently re-validates your membership on every request, so editing it grants nothing. SameSite=Lax, 30-day expiry.dr_observe_client- set only for our own support staff, recording which customer workspace they are viewing. Re-validated against their role on every request.dr_room_<id>- the room you last opened in a given workspace, so the dashboard returns you to it. SameSite=Lax.
Signup attribution
dr_ref_code- present only if you arrived through a referral link. Carries the referring workspace’s code across the signup pages so the referrer can be credited. SameSite=Lax, expires after 1 hour.dr_ref_room- present only if you arrived from a data room’s “create your own room” link. Records which room introduced you. SameSite=Lax, expires after 1 hour.
Consent state
valicon_consent- stores your accept/reject choice for the analytics cookies in section 4a. Set only on the marketing site, 6-month lifetime. We also try browser storage first and fall back to this cookie where storage is blocked.
Every cookie listed above other than the two attribution cookies is necessary to operate the service. The two attribution cookies are first-party, expire within an hour, and are used solely to credit a referral.
Activity analytics inside a data room are collected server-side and tied to your visit session. We do not run device fingerprinting. Where a room reports that a link appears to have been forwarded, that is inferred from the number of distinct IP addresses that have opened the same link, not from any device signature.
4a. Google Analytics (only with your consent)
On the public marketing site (valicon.ai) we use Google Analytics 4, property ID G-C8W8MJGMVF, to understand which pages help founders the most. GA4 only loads after you click “Accept” on the cookie banner. If you click “Reject” or dismiss the banner, no Google script is loaded and no GA cookie is set.
When loaded, GA4 may set the following cookies in your browser:
_ga- distinguishes unique visitors, lifetime up to 2 years._ga_C8W8MJGMVF- session state for our specific property, lifetime up to 2 years._gid- short-term visitor distinction, lifetime 24 hours.
Pseudonymous events (page views, clicks, scroll depth) are sent to Google LLC (US) for processing. We enable IP anonymisation(anonymize_ip: true) so the last octet of your IP is truncated before storage. The legal basis is your consent under GDPR Art. 6(1)(a). You can withdraw consent at any time using the “Cookie settings” link in our footer; this clears thevalicon_consent entry in your browser’s site data, removes any GA cookies, and re-shows the banner. Google’s own privacy notice: policies.google.com/privacy.
Google Analytics is loaded only on the public marketing site. It is never loaded inside the authenticated app, on data-room pages, or in invitation flows. The privacy policy is enforced in code via a path-based blocklist; even with consent, GA does not run on those surfaces.
4b. In-app announcements & product-update emails (founders only)
We use two channels to communicate platform-level updates to founders who have signed up: an in-app notification bell on the dashboard, and transactional product-update emails when an update is time-sensitive (a new feature shipped, a roadshow we’re running, an upcoming change to your plan). Investors visiting a data room never receive either of these; they only see content their inviting founder has placed in the room.
Announcements can be filtered by your workspace profile (industry, stage, purpose, country, raise band). The filter applies to which announcements you see; we never send the announcement about you to third parties. Filter dimensions are derived from data you yourself entered during the welcome wizard or in Settings.
Opt-out: the email half of this channel respects the Product updates toggle in Settings → Notifications. Turning it off stops product-update emails immediately; the in-app bell still surfaces relevant announcements unless you archive them. Always-on transactional emails (verification codes, password resets, the invite emails you send to investors, billing receipts) are required for the service to function and are not controllable here.
5. Processors and subprocessors
The following third-party services receive personal data in the course of operating valicon.ai. This list is intended to be complete for the features currently offered; where a service is engaged only by an optional feature, that is stated.
- Hosting & database - Railway Corp. Application servers and database storage, so all data described in section 2 resides there. Processing location depends on the configured service arrangement.
- Transactional email - Resend. Receives recipient addresses, names and the full content of every message we send: invitations, verification and password-reset mail, investor updates and billing notifications.
- AI inference - Anthropic PBC. Used across several features, and the material sent varies by feature: the text and, for PDFs, the file itself for documents you upload to a room; room content for the AI room drafter, readiness review and the “ask this room” assistant; questions submitted by visitors; and, where the call-notetaker feature below is enabled, meeting transcripts. We rely on Anthropic’s commercial terms in respect of model training; we do not make an independent retention commitment on their behalf.
- Payments - Stripe, for billing. Card data never touches our servers; we hold only the customer and subscription identifiers.
- Google LLC / Google Ireland Ltd. - only if you choose to use them: “Sign in with Google”, which returns your email address, name and a stable account identifier; and calendar connection, which reads free/busy information and creates meeting events, including attendee email addresses.
- Microsoft - only if you choose to connect an Outlook or other Microsoft work-account calendar. The same calendar features as above run through the Microsoft Graph API: we read free/busy information and create meeting events, including attendee email addresses. Disconnecting removes the connection credentials we store and stops Valicon using that connection. Authorisation held at the provider can also be managed through your own Microsoft account controls.
- Recall.ai - call-notetaker feature, which is not currently enabled. The feature is built but switched off, and no meeting is recorded or sent to Recall today. It is described here so the position is clear rather than discovered later: were it enabled for a workspace, a recording bot would join the scheduled meeting and produce a transcript, so Recall would receive the meeting link and the meeting audio, and the resulting transcript would be stored by us and processed by Anthropic as described above.
- Our email hosting provider - optional call-notetaker feature only. Where a workspace uses the calendar-invitation route into that feature, calendar invitations sent to our notetaker address are retrieved over IMAP, so the organiser and attendee addresses on those invitations are held by the provider that hosts that mailbox. That feature is not currently enabled.
A workspace can also choose to send its own activity alerts to a Slack channel by pasting a Slack webhook into an alert rule. Where a workspace does that, the alert text - which names the contact and the room activity that triggered it - is delivered into that workspace’s own Slack. This is configured by the customer, in their own Slack workspace; we hold no Slack account and cannot act there.
No visitor IP address is sent to any geolocation service.
Contact us at the address above if you need the current data-protection position for a specific service.
6. Your rights
Under GDPR Art. 15-22 you have the right to:
- Access the personal data we hold about you (Art. 15).
- Correct inaccurate data (Art. 16).
- Have your data erased (Art. 17).
- Restrict processing (Art. 18).
- Receive your data in a portable format (Art. 20).
- Object to processing on legitimate-interest grounds (Art. 21).
- Withdraw consent at any time without affecting prior lawful processing.
To exercise any of these rights, email hello@valicon.ai. We respond to data-subject requests without undue delay, ordinarily within one month, which may be extended where the GDPR permits. These requests are handled by our team.
If you visit a data room, you can object to engagement tracking yourself, without contacting us. The Privacy & tracking control in the room footer turns off new engagement analytics (page views, time spent and downloads) for you across that company’s rooms. This takes effect immediately and applies wherever you open their rooms. It does not delete activity already recorded, and it does not stop the records we need to operate the room securely or the things you send us on purpose, such as a signed NDA, a question or an introduction request.
A workspace owner can also delete their workspace from Settings. This removes the workspace, its rooms, its files and its contact records immediately, and cannot be undone. Some records are retained beyond that step, including our record of messages sent and records relating to calls and commitments. To request erasure of personal data we hold about you, contact us at the address above. Requests are handled in accordance with applicable GDPR requirements, including any lawful retention obligations or exceptions.
You may lodge a complaint with the Bavarian data-protection authority (BayLDA, lda.bayern.de) or any other competent supervisory authority.
7. Retention
We keep personal data for as long as it is needed for the purpose it was collected for, or for as long as the law requires. One period is fixed today:
- Billing and commercial records: subject to separate retention requirements. The applicable period depends on the record type and the legal obligations that apply to it, and is reviewed separately.
- Workspace audit-log entries: 90 days.
Everything else - account records, room content, contact records, visit sessions and the activity data described in section 2 - is retained for as long as the workspace exists.
We also keep a rolling set of the most recent database backups so that a failed upgrade can be rolled back. That set is bounded by the number of copies kept rather than by their age, so data you have deleted may remain in a backup until enough newer copies have replaced it.
8. International transfers
Some providers listed in Section 5 may process data outside the EEA. Which arrangement applies depends on the provider, the configured processing location and the contractual setup with that provider. Details of the applicable safeguards must be established for the relevant provider arrangement. We do not state a particular safeguard for a provider here unless it has been verified for that arrangement.
9. Children
valicon.ai is a B2B product not intended for children under 16. We do not knowingly process data from children.
10. Changes to this policy
We update this notice when our processing changes. The current version is always posted at /privacy. Material changes are emailed to active account holders at least 14 days before they take effect.
Questions or want to exercise a right? Email hello@valicon.ai and we will respond within 30 days.