Skip to content
Privacy Policy

Privacy at Valoren.

What we collect, how we use it, who we share it with, and how to exercise your rights under UK GDPR.

Last updated· September 2026· Standard Index Group·
I

Who we are

Valoren is operated by Standard Index Group, a business in formation in England and Wales. Until incorporation completes, the data controller is the proprietor of the business, trading as Standard Index Group. Valoren is its sole product.

II

What we collect

Account information — name, email address. Payment details are processed by Stripe and not stored by us.

Delivery address — only if you order something we post to you. We ask for it at checkout, use it to print and send that item, and share it with the printing and delivery provider handling it. We do not ask for it for anything digital, and we do not keep it once the item has arrived and its return window has passed.

Governance records — the information you enter into your records. This may include personal, financial, medical, and property details.

Usage data — how you interact with the portal, which features you use, browser type, and IP address.

Special category data — health information (your Medical Abstract record) is collected only with your explicit, unbundled consent, which you can withdraw independently without affecting other records.

III

How we use your data

Service delivery — preparing documents, monitoring renewals, maintaining your governance system, composing professional packs.

Service communications — renewal reminders, expiry alerts, system updates. These are operational, not marketing.

Marketing — some of our free guides, checklists and samples are followed by a short series of related emails. The page tells you so above the button, before you give us your address: what will arrive, over what period, and whether one of them carries a paid offer. We do not use a separate tick box — asking for the download is the consent, and the wording you agreed to is the wording shown on that page. Every one of those emails carries a one-click unsubscribe, and once you use it we do not add you back — on any list — even if you later download something else.

Service improvement — anonymised, aggregated usage data.

IV

Legal basis for processing

Contract performance — processing necessary to deliver the service you purchased.

Legitimate interest — service improvement, security monitoring, fraud prevention.

Consent — marketing communications, special-category health data, and analytics (PostHog), which runs only if you allow it and can be declined at any time.

V

Who we share data with

Supabase (UK hosting, London eu-west-2), Stripe (payment processing), Postmark (transactional email), Resend (the marketing and follow-up emails described above), Cloudflare (runs the services that hold your enrolment record, your unsubscribe link and the schedule those emails are sent on), Trustpilot (when we email you certain free resources, your address is copied to Trustpilot so it can invite you to review us — you are free to ignore it), DocRaptor (document generation), Anthropic PBC (document and correspondence processing infrastructure, US — Standard Contractual Clauses), Backblaze (secure storage provider used for the independent archive of sealed correspondence — see our Custody page for how that archive is used). These are data processors acting under our written instruction.

Analytics and error monitoring. If you allow it, PostHog (analytics, hosted in the EU) records which pages are visited and how they are used, including session replays with form fields masked — it does not run until you choose "Allow analytics" on the banner, and you can decline with no loss of service. Sentry (error monitoring) receives anonymous error reports so we can fix what breaks; these carry no name, email or record contents. Neither is used for advertising.

We do not sell your data. We do not share your data with advertisers. We do not use your data for AI training.

VI

Data retention

Active and cancelled accounts — data is retained for the duration of your subscription and, after cancellation, for as long as you want it kept, so your records are still there if you return. It is not deleted on a schedule. You may ask us to erase it at any time and we complete that in full within one month of the request; we then retain only the legal minimum (anonymised payment records for HMRC).

Trusted Persons access — emergency-access records survive twelve months post-cancellation under defined conditions.

Legal obligations — financial records retained for six years as required by UK Companies Act and HMRC.

Marketing suppression — where we hold a bereavement or vulnerability marker for you, it overrides marketing consent automatically. That check runs on our subscription and retention emails; the free-resource follow-up sequences described in section III are governed by the unsubscribe above, which is permanent.

VII

Your rights under UK GDPR

You have the right to access your data, rectify inaccuracies, erase your data, restrict processing, data portability, object to processing, and withdraw consent.

To exercise any right, contact privacy@valoren.uk.

We will respond within thirty days. Complex requests may take up to ninety days with notification.

VIII

International transfers

Your data is hosted in the UK (London, eu-west-2). Some processing — including document and correspondence processing carried out by Anthropic PBC — takes place in the United States, with appropriate safeguards including Standard Contractual Clauses in place. Other processors operating internationally are covered by the same safeguards.

IX

Contact and complaints

Data Protection queries: privacy@valoren.uk.

Standard Index Group, United Kingdom.

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

UK GDPR· Data Protection Act 2018

Part of a working library79form walkthroughs90+free guidesevery calculator & checker