Privacy

You are a fractional executive holding your clients' financial and contractual records in our software. That makes this less about us and more about them. In short: we collect what the product needs to work and nothing for advertising, we never sell anything to anyone, we never touch your clients' money, and you can export or delete the lot whenever you like.

Who we are

This service is operated by Valzeo. For anything on this page, write to privacy@valzeo.com. Our registered address is Address to be confirmed.

What we collect

Three things, and it is worth separating them because they are governed differently.

  • Waitlist details. If you ask for an invitation we store your email address, and optionally your name, your practice title and roughly how many retainers you run. We use these to decide who to admit and in what order, and to email you when it is your turn. Nothing else.
  • Your account. Your email address, your name and practice title, your capacity ceiling, and your subscription status. If you set a password we store only a hash of it — we cannot read your password, and neither can anyone who takes a copy of the database.
  • Your workspace. Everything you enter about the work: clients and their CEOs' addresses, retainers and their terms, contracts and signed agreements, invoices, expenses, strategic initiatives, the metrics you record, and the hours you log against a week. Much of this is your clients' confidential information rather than yours, and we treat it that way.

We do not run advertising trackers, we do not build a profile of you, and we do not sell or rent anything to anybody. There is no third-party analytics script on the application.

What we never hold

  • Your clients' money. Invoices are produced here and sent by you, carrying your own bank details. Funds move between you and your client directly. We are not in the flow and hold no balance.
  • Card numbers. Your own subscription is taken by a merchant of record. We receive a status and a customer reference, not a card.
  • Payment provider keys. There is no processor to connect and nowhere to enter an API key. We hold nothing that could charge your clients or read their payment details.

Who else sees it

Only the services below, each doing one job. We keep this list specific rather than generic so it can be checked against what the software actually does.

SupabaseDatabase, authentication, and file storage

Everything you enter: account details, clients, retainers, contracts, invoices, documents and metrics.

VercelApplication hosting

Request metadata — IP address, user agent, and the pages requested.

ResendTransactional email

Your address and the contents of sign-in links and notifications.

Lemon Squeezy / PaddleMerchant of record for your subscription to us

Your billing details. They take payment and handle sales tax; we never see or store a card number.

BoldSign / Dropbox SignElectronic signature

The statement of work sent for signature and the signer's address.

Keeping it separate

Every table carrying your data is scoped to your workspace by row-level security in the database itself, not by a filter in application code. One executive cannot read another's rows even if the application asks it to.

Client portals are narrower still. A client CEO signs in with a link to their own address, and the database will only return rows for the engagements belonging to that address. A portal cannot reach your other clients, your capacity, or your revenue.

How long we keep it

  • While your account is open — your workspace stays as you left it. We do not expire your records.
  • If you close your account — we delete your workspace within 30 days, other than anything we are legally required to keep (invoice records, typically for six or seven years depending on jurisdiction).
  • Waitlist entries — kept until you ask us to remove them, or for two years after we stop operating a waitlist, whichever is sooner.

Your rights

If you are in the UK or the EU you have the right to see the data we hold about you, correct it, export it in a portable format, restrict what we do with it, object to it, or have it deleted. You do not have to be in the UK or EU for us to honour any of those — write to privacy@valzeo.com and we will act within 30 days.

Where your clients' personal data is concerned — their CEOs' names and addresses — you are the controller and we are your processor. We act on your instructions, and we will help you answer a request one of them makes to you.

If something goes wrong

If we discover a breach affecting your data we will tell you what happened, what it reached, and what we are doing about it — without waiting to have a complete picture first, and in any case within 72 hours of becoming aware of it.

Changes

If we change this in a way that affects what we collect or who sees it, we will email you before it takes effect rather than quietly revising the date at the bottom of the page.