Valuesync AS (reg. no. 933 375 854)
This Privacy Policy explains how Valuesync AS ("Valuesync," "we," "us," or "our") collects, uses, discloses, and protects personal data in connection with our website (the Website) and our hosted software platform for M&A analysis (the Platform). It also describes your choices and rights.
If anything in this Policy conflicts with an agreement between Valuesync and your organization, whether our Data Processing Agreement (the "DPA") or our Terms of Service, that agreement controls.
1. Who we are (Controller)
Controller: Valuesync AS, Gaustadalléen 21, 0349 Oslo, Norway. Contact: contact@valuesync.ai Website: https://www.valuesync.ai
For personal data that we process on behalf of business customers within the Platform, meaning Customer Data, we act as a processor, and your organization is the controller. Our DPA governs that processing.
For Operational Data, described in Section 5, we act as an independent controller.
2. Scope
This Policy applies to:
- Visitors to our Website (including contact forms, newsletters, and cookies);
- Users of our Platform (account, usage, and support data);
- Business contacts and prospects (sales, marketing, events).
When your organization uploads files or information to the Platform (Customer Data), your organization is the controller of that data and our DPA applies.
3. What we collect
- Customer Data (Platform content): documents and other data your organization submits to or generates in the Platform. Your organization controls this data; we process it under the DPA.
- Operational Data: account and profile data (name, business email, job title, company, authentication identifiers, role and permissions, billing contact details), usage and telemetry data (log data, IP address, device, browser, timestamps, feature usage, performance metrics), and error and security logs. See Section 5.
- Support and communications: messages you send us (support tickets, chats, emails), meeting notes, feedback.
- Cookies and similar technologies: see Section 8.
- Third-party sources: we may receive business contact data from providers (e.g., CRM enrichment) and integration metadata from services you connect to the Platform.
4. Why we process personal data (Purposes and legal bases)
Provide and secure the Platform (create accounts, authenticate users, operate features, monitor uptime, secure and troubleshoot). Legal bases: Contract (Art. 6(1)(b)); legitimate interests in security and operations (Art. 6(1)(f)).
Customer support and communications (respond to requests, manage incidents, provide updates). Legal bases: Contract; legitimate interests.
Operate and improve the Platform (diagnostics, quality, technical usage analytics). Legal bases: Legitimate interests; consent where ePrivacy requires it for non-essential cookies or analytics.
Marketing to business contacts (newsletters, event invitations, product updates to corporate email addresses). Legal bases: Legitimate interests (B2B marketing) or consent where required; you can opt out at any time.
Compliance and enforcement (recordkeeping, fraud prevention, enforcing the Terms, legal obligations). Legal bases: Legal obligation; legitimate interests.
5. Operational Data: where we are the controller
Alongside the Customer Data we process for your organization, we process a separate category of data about the operation and use of the Platform. We call this Operational Data, and we process it for our own purposes as an independent controller. It does not include the content of Customer Data.
| Category | What it is | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Account data | Name, business email, job title, role and permissions, authentication data | Provide access, authenticate users, administer the account | Contract (Art. 6(1)(b)) | For the duration of the account, then 12 months |
| Usage and telemetry | Feature usage counts, performance metrics, timestamps, device and browser information | Operate the Platform, monitor performance, understand which features are used | Legitimate interests (Art. 6(1)(f)) | 12 months |
| Error logs | Technical error data and user identifier | Detect, diagnose, and fix faults | Legitimate interests | 90 days |
| Security logs | Login events and security-relevant events | Detect and investigate unauthorized access | Legitimate interests; legal obligation | 12 months |
| Billing data | Billing contact, invoicing and payment records | Invoice and account administration | Contract; legal obligation | 5 years, as required by the Norwegian Bookkeeping Act |
What we do not do with it. Operational Data tells us how the Platform is performing and which features are used. It does not tell us what is in your documents, and we do not use it to derive or disclose customer-specific information for the benefit of other customers or third parties.
Your rights. Because we are the controller for Operational Data, you can exercise the rights in Section 12 directly with us. Where we rely on legitimate interests, you have the right to object.
6. AI, Customer Data, and Outputs
No model training. We do not use Customer Data or Outputs to train foundation models or third-party AI models. This applies both to us and to our model providers.
How AI processing works. The Platform uses large language models from more than one provider and routes requests between them depending on the task. When you use AI functionality, relevant Customer Data is submitted to such a provider to the extent necessary to deliver it. Content sent to a model provider is used only to generate the response. It may be stored for a limited period for abuse monitoring under the provider's terms and is then deleted automatically. The providers we use, where they process, and the retention period for each are set out at valuesync.ai/subprocessors.
No automated decision-making. The Platform's outputs are decision support and presuppose human assessment. They do not produce legal or similarly significant effects within the meaning of GDPR Article 22.
Limits on our use of Customer Data. We do not use Customer Data to derive or disclose customer-specific information for the benefit of other customers or third parties. Your Customer Data is kept logically separated and is not aggregated, benchmarked, or otherwise combined across customers. We use Operational Data, not Customer Data, to analyze and improve the Platform. See Section 5.
Outputs. As set out in the Terms, your organization owns the Outputs generated from its Customer Data and prompts, subject to applicable law.
7. Sharing and disclosures
- Sub-processors and service providers (hosting, storage, AI model providers, email, error monitoring). Each is bound by a data processing agreement. The current list, including what each processes, where, and on what transfer basis, is published at valuesync.ai/subprocessors.
- External data sources. The Platform may retrieve publicly available company information from external sources. We transmit only the information reasonably necessary to perform the relevant lookup.
- Professional advisers (legal, accounting, insurers) under confidentiality.
- Corporate transactions (merger, acquisition, financing) with appropriate safeguards.
- Legal compliance (court orders, law enforcement) where required by law.
We do not sell personal data.
8. Cookies and similar technologies
Our Website sets no cookies. We do not use analytics, advertising, or tracking cookies on valuesync.ai, and there is nothing for you to consent to or opt out of.
The Platform uses only cookies that are strictly necessary to operate it, keeping you signed in and maintaining your session. These are essential to a service you have asked to use, and no consent is required for them.
If we introduce analytics or other non-essential cookies, we will ask for your consent first and update this Policy before doing so.
9. International transfers
Customer Data is stored within the EEA. Customer Data may be processed by us and our sub-processors in the EEA and, where applicable, outside it.
Any transfer outside the EEA takes place only where a valid transfer mechanism is in place: the EU-U.S. Data Privacy Framework, or a data processing agreement incorporating the EU Standard Contractual Clauses. The recipient countries and the mechanism for each provider are set out at valuesync.ai/subprocessors.
10. Data retention
We keep personal data for as long as necessary for the purposes described above, or as required by law. Retention for each category of Operational Data is set out in Section 5.
Customer Data is retained according to your organization's instructions and our DPA. After your subscription ends, you may export Customer Data for 30 days. We then delete it from active systems within 90 days, and copies held in backups are deleted in line with our standard backup retention procedures, unless we are legally required to retain the data. We confirm deletion in writing on request.
11. Security
We implement technical and organizational measures designed to ensure a level of security appropriate to the risk. These include encryption in transit and at rest, role-based access control on the principle of least privilege, logical separation of customer data, logging and monitoring, separate development and production environments, and written confidentiality undertakings for personnel with data access.
The measures in place are described in Annex B to our Data Processing Agreement.
12. Your rights (GDPR/EEA/UK)
Depending on your location, you may have rights to access, rectify, erase, restrict, object to, and port your personal data, and to withdraw consent where processing is based on consent.
For Operational Data, contact us directly at contact@valuesync.ai. For Customer Data, we are the processor, so direct your request to your own organization, and we will assist them in responding. You also have the right to lodge a complaint with your local supervisory authority, such as the Norwegian Data Protection Authority (Datatilsynet).
13. Children's data
Our services are for professional and business use and are not directed to children. We do not knowingly collect personal data from children under 18. If you believe a child has provided us data, contact us to delete it.
14. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you via the Website or Platform, or by email to your admin contact, before the effective date. Changes to the DPA follow the separate process set out in the DPA.
15. Contact
Valuesync AS Gaustadalléen 21, 0349 Oslo, Norway Website: https://www.valuesync.ai Email: contact@valuesync.ai
Version history
| Version | Date | Change | Status |
|---|---|---|---|
| 1.0 | 11.08.2025 | First published version | Superseded |
| 2.0 | 6 August 2026 | Harmonised with the Terms of Service and the Data Processing Agreement. New Section 5 on Operational Data | Current |

