HomePrivacy Policy
Legal

Privacy Policy

This policy explains what personal data Vaalti handles, why we handle it, who we share it with and what you can ask us to do about it. It covers this website, our early-access sign-up and the Vaalti platform.

Last updated

Who we are

Vaalti ("Vaalti", "we", "us", "our") provides a data vault and enrichment platform that lets businesses store, filter and enrich the contact data they already own. Our registered office is 30 Riverhead Close, London, England, E17 5PY, United Kingdom.

We are established in the United Kingdom, so we handle personal data under the UK GDPR and the Data Protection Act 2018. For the data described in this policy we are the data controller, except where the section on your vault says otherwise.

Questions about anything on this page go to support@vaalti.com. We are not required to appoint a statutory Data Protection Officer, but privacy requests are owned by a named member of our team and answered from that address.

Two kinds of data, treated differently

Vaalti touches two very different categories of personal data. Keeping them apart is the key to understanding the rest of this policy.

  • Site and account data: information about you as a visitor, an early-access sign-up, or a customer using the platform. We decide how and why it is used, so we are the controller for it.

  • Vault data: the contact records our customers import, enrich and store in their own vault. Our customers decide what goes in and what it is used for, so they are the controller and we act as their processor.

The next two sections are about site and account data. The section on your vault sets out how we handle customer data, and the section on business contact data explains where enrichment results come from.

What we collect

We collect what we need to run the service and nothing we cannot justify.

CategoryWhat it includesWhy we hold it
Identity and contactFull name, business email address, phone number, company name.To answer your enquiry, set up and administer your account, and reach you about the service.
Early-access sign-upThe details you submit in the early-access form, together with the page that referred you.To manage the early-access list, confirm your place and send your invite when it is ready.
Account and workspaceSign-in credentials (passwords are stored hashed, never in readable form), workspace and team membership, roles and permissions, saved preferences.To operate your account securely and give the right people the right level of access.
BillingBilling contact, company registration and tax details, plan, invoices and payment status. Card numbers are handled by our payment provider and never reach our systems.To take payment, issue invoices and meet our accounting obligations.
Usage and productFeatures used, jobs run, volumes processed, imports and exports, sign-in times and in-app actions.To run, support, secure and improve the service, and to bill accurately against your plan.
TechnicalIP address, browser and device type, operating system, referring page and timestamps.To keep the service available and secure, diagnose faults and detect abuse.
Support and correspondenceEmails, support tickets, call notes and anything else you send us.To answer you properly and keep a record of what was agreed.
Cookies and preferencesThe small set of cookies described in the cookies section, including your light or dark theme choice.To keep you signed in, protect the service and remember how you like it to look.

What we do not ask for

We do not ask for special category data about you, such as health, race, religion, political opinions, sexual orientation or biometrics. Please do not send it to us in support messages.

Where it comes from

  • Directly from you, when you fill in a form, create an account, buy a plan or contact us.

  • Automatically, as you use the site and the platform, through server logs and the cookies described below.

  • From your colleagues, when a workspace administrator invites you to their team.

  • From our service providers, such as our payment processor confirming that an invoice was paid.

  • From public and licensed sources, for the business contact database behind our enrichment tools. That is set out in its own section below.

Your vault: your data, our commitments

When you upload an export, run a bulk job or enrich a record, the result sits in your vault. You choose what to collect and what to do with it, so for that data you are the controller and Vaalti is your processor.

What we commit to

  • We process vault data only on your documented instructions, which for most customers means only to provide the service you asked for.

  • We do not sell it, rent it, or make one customer's vault visible to another. Workspaces are logically separated.

  • We do not mine your vault to enrich other customers' results.

  • Access is limited to the staff who need it to run and support the platform, and every one of them is under a confidentiality obligation.

  • We use only vetted sub-processors, under contracts that hold them to the same standard.

  • We help you respond to data subject requests, security incidents and impact assessments.

  • On termination we return or delete your vault data as described in the retention section.

What you are responsible for

  • Having a lawful basis for collecting, enriching and contacting the people in your vault. For business-to-business outreach that is usually legitimate interests, documented in a balancing test.

  • Giving those people the privacy information they are entitled to, including who you are and where you got their details.

  • Honouring objections, opt-outs and erasure requests promptly, and keeping your own suppression list current.

  • Complying with the UK GDPR, the EU GDPR, PECR, CAN-SPAM, CASL and the marketing rules of every market you contact.

  • Not uploading special category data, criminal offence data, payment card numbers or data about children.

Need this in writing?

We have a standard data processing agreement covering all of the above, including sub-processors, security measures and international transfers. Email support@vaalti.com and we will put it in place before you go live.

Business contact data and our enrichment tools

Our Google Maps Scraper, Website Finder, Website Extractor, Email Finder and Verifier, and LinkedIn Phone Finder return business contact details. Those details are compiled from publicly accessible sources, such as company websites, business directories and public professional profiles, and from third-party data we license under contract.

  • We hold business-context data only: work email address, work telephone number, job title, employer, company website, business address and public professional profile links.

  • We do not build profiles of anyone's private life, and we do not collect special category data.

  • Results are checked against your existing records so the same contact is not stored twice.

  • Where a verification is uncertain we say so, with a confidence score. Where we have no match at all, we tell you that rather than inventing one.

Our lawful basis for maintaining this database is legitimate interests: helping businesses reach the right suppliers, partners and candidates. We have carried out a legitimate interests assessment weighing that against the rights of the individuals concerned, and you can request a summary of it.

Not a customer, and would rather not be listed?

You do not have to be a Vaalti customer to exercise your rights. Email support@vaalti.com with the details you want removed. We will suppress them across our database within 30 days and add them to a permanent suppression list so they cannot be re-added by a later crawl.

How we use it, and our legal basis

What we doLegal basis under the UK GDPR
Provide the platform, your vault, the enrichment tools and support.Performance of a contract with you.
Manage the early-access list and answer enquiries.Steps taken at your request before entering a contract, and your consent.
Take payment, issue invoices and chase overdue amounts.Performance of a contract, and our legitimate interest in being paid.
Keep the service secure, prevent fraud, abuse and misuse.Legitimate interests in protecting our platform and our customers.
Monitor performance and improve features using aggregated usage data.Legitimate interests in running and developing a reliable product.
Send product updates and relevant marketing to business contacts.Legitimate interests, with an opt-out in every message, or your consent where the law requires it.
Maintain the business contact database behind our enrichment tools.Legitimate interests, subject to the assessment described above.
Keep accounting records and respond to lawful requests from authorities.Compliance with a legal obligation.

We do not make decisions about you by automated means alone that produce legal effects or similarly significant consequences.

Marketing messages

If you join the early-access list or become a customer, we may email you about the product, new tools and your place in the queue. We keep it infrequent and relevant.

  • Every marketing email carries a one-click unsubscribe, and we act on it immediately.

  • You can also opt out at any time by emailing support@vaalti.com.

  • Service messages such as invoices, security notices and changes to these policies are not marketing, so they continue while you hold an account.

  • We do not pass your details to third parties for their own marketing.

Cookies and similar technologies

We keep this deliberately light. There are no advertising cookies and no cross-site tracking pixels on this site.

  • Strictly necessary: keeping you signed in, protecting forms against abuse and routing traffic. These cannot be switched off without breaking the service.

  • Preferences: a small cookie that remembers whether you chose the light or dark theme, so the page renders correctly the moment it loads.

  • Analytics: aggregated statistics about which pages and features are used, so we can improve them. These are only set where you allow them, and they are not used to identify you.

You can clear or block cookies in your browser settings. Blocking the strictly necessary ones will stop you signing in.

Who we share it with

We do not sell personal data, and we never will. We share it only with the following, and only as far as each one needs.

  • Infrastructure providers who host the platform, store data and run backups.

  • Email delivery providers who send transactional messages such as invites, invoices and password resets.

  • Payment processors who take card and bank payments. They handle card details directly; we only see the outcome.

  • Analytics and error-monitoring providers who help us find faults and understand aggregate usage.

  • Support tooling used to answer your tickets and emails.

  • Professional advisers such as accountants, auditors and lawyers, under a duty of confidence.

  • Authorities and regulators, where we are legally required to disclose, and only to the extent required.

  • An acquirer or successor, if the business is sold, merged or restructured. We will tell you before your data becomes subject to a different policy.

Every provider works under a written contract, processes data only on our instructions, and is held to appropriate security and confidentiality terms. Ask support@vaalti.com for our current sub-processor list, and we will tell you when it changes if you are a customer.

Sending data outside the UK

We are based in the United Kingdom and some of our providers are not. Where personal data leaves the UK or the EEA, we make sure it stays protected by relying on one of the following.

  • UK adequacy regulations, where the destination country has been recognised as offering equivalent protection.

  • The UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

  • Additional technical and organisational measures, such as encryption and access restrictions, where a transfer risk assessment shows they are needed.

You can ask for a copy of the safeguards in place for a specific transfer by emailing support@vaalti.com.

How long we keep it

We keep personal data only as long as it is doing a job, then delete or anonymise it.

DataHow long we keep it
Early-access sign-upsUntil you ask to be removed, or 24 months after our last contact with you, whichever comes first.
Account and workspace dataFor as long as your account is open, then 90 days after closure.
Vault data (customer data)For as long as your account is open. On termination you have 30 days to export it, after which we delete it, and in any event within 90 days.
Billing and tax records7 years from the end of the relevant accounting period, as UK law requires.
Support correspondence24 months from the last message in the thread.
Security, access and audit logs12 months, unless a log is needed for a live investigation.
Suppression list entriesKept indefinitely. Holding the minimum needed to recognise a removed contact is the only reliable way to make sure they are never added back.

How we protect it

  • Data is encrypted in transit with TLS, and encrypted at rest on our infrastructure.

  • Passwords are hashed with a modern algorithm and are never readable by our staff.

  • Access follows least privilege, with multi-factor authentication on administrative systems.

  • Workspaces are logically isolated so one customer's vault is never exposed to another.

  • We log and monitor access to production systems, and review those logs.

  • Backups run regularly and restores are tested.

  • New providers go through security due diligence before they touch personal data.

  • Staff are bound by confidentiality obligations and trained on handling data.

No system is perfectly secure. If a personal data breach occurs and it is likely to result in a risk to people's rights, we will notify the Information Commissioner's Office within 72 hours where required, and tell affected customers and individuals without undue delay.

Your rights

Under the UK GDPR you have the right to:

  • Be informed about how your data is used, which is what this policy is for.

  • Access a copy of the personal data we hold about you.

  • Rectify data that is inaccurate or incomplete.

  • Erase your data where we no longer have a good reason to keep it.

  • Restrict how we use it while a concern is being resolved.

  • Port the data you gave us to another provider in a structured, machine-readable format.

  • Object to processing based on legitimate interests, and to direct marketing at any time and without giving a reason.

  • Withdraw consent where our basis is consent, without affecting anything done beforehand.

To exercise any of these, email support@vaalti.com. We answer within one month. If a request is complex we may take up to two further months, and we will tell you why within the first month. Requests are free unless they are manifestly unfounded or excessive. We may need to verify your identity first, and we will only ask for what is necessary to do so.

If your details sit in a customer's vault, that customer is the controller. We will pass your request to them promptly and support them in answering it, and we will suppress your details in our own database as described above.

Complaints

We would like the chance to put things right first, so please come to us at support@vaalti.com. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

If you are in the EEA or California

Individuals in the EEA have equivalent rights under the EU GDPR and may complain to their local supervisory authority. California residents have the right to know, delete and correct their personal information, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA and CPRA, and we will never discriminate against you for exercising a privacy right.

Children

Vaalti is a business tool for professional use, and it is not directed at children. We do not knowingly collect data about children, and customers must not upload it. If you believe a child's data has reached us, tell us and we will delete it.

Changes to this policy

We update this policy as the product and the law change. The date at the top of the page always reflects the current text.

Where a change materially affects your rights, we will tell customers by email or an in-app notice at least 14 days before it takes effect. Earlier versions are available on request from support@vaalti.com.