valueIQ Privacy Policy
Effective Date: Upon execution of this Agreement or, for self-serve Customers, upon acceptance of the Terms of Service
Last Updated: August 26, 2026
Your privacy matters to us. This Privacy Policy explains how valueIQ Technologies Inc. ("valueIQ," "we," "us"), a corporation incorporated under the laws of British Columbia, Canada, with a registered address at #302-118 Carrie Cates Court, North Vancouver, BC, Canada, V7M 0G6, collects, uses, shares, and protects personal data in connection with the valueIQ Services (the "Services") and our website. It applies to our customers, their Users, website visitors, and anyone else whose personal data we process. Capitalized terms not defined here have the meaning given in our Terms of Service.
We serve customers based in Canada, the United States, the United Kingdom, the European Union, and elsewhere. This Policy is written to meet the requirements of those jurisdictions, and Section 10 covers rights specific to some of them.
1. Controller and Processor Roles
For account administration, billing, marketing, and our own website, valueIQ is the controller of the personal data described in this Policy — we decide how and why it's processed.
For Customer Content — the data a customer and its Users submit to or generate within the Services, which may incidentally contain personal data about a customer's own contacts, employees, or business relationships — the customer is the controller and valueIQ is the processor. We process that data only on the customer's instructions, under the terms of our Data Processing Addendum ("DPA"). If you're an individual whose personal data appears in someone else's valueIQ workspace — for example, as a contact in a deal record — the customer that put it there is responsible for your rights request, though we'll help them fulfill it as the DPA describes, and you're welcome to contact us directly and we'll direct you to them.
2. Personal Data We Collect
- Account information: your name, work email, company, and role, when you or your organization sign up.
- Customer Content: the data you and your team create inside valueIQ — deals, value models, business cases, coaching conversations, and similar workspace content — which may incidentally include personal data about people connected to your business dealings.
- Billing information: if you're on a paid plan, billing details are collected and processed by our payment processor, Stripe. We don't store your full card number.
- Usage and log data: login activity, feature usage, and performance data, which we use to operate, secure, and improve the Services, consistent with our Terms of Service's treatment of Usage Data.
- Cookies and analytics: we use Google Tag Manager on our website for usage analytics — for example, which pages are visited. These aren't used for advertising or ad targeting. Where the law requires it (for example, for visitors in the UK or EU), we ask for your consent before setting non-essential cookies.
- Information from AI assistants and the MCP Server: covered separately in Section 5, since it works a little differently from the categories above.
3. How We Use Personal Data
We use personal data to: provide, operate, and maintain the Services and the features you use; process billing and payments; respond to support requests; maintain security and reliability; and understand aggregate usage so we can improve valueIQ.
For readers in the UK, EU, or Switzerland, our legal basis is generally contract (processing needed to provide the Services you've signed up for), legitimate interests (security, service improvement, and responding to you), or legal obligation (where the law requires it) — we don't rely on consent for these core purposes, except for non-essential cookies as Section 2 describes.
Your data is yours, and we mean that:
- We don't use it for advertising, and we don't use it for any purpose other than providing and operating valueIQ, except the aggregate/de-identified uses this Policy and our Terms of Service describe.
- We don't sell or rent it, and we don't share it with third parties for their own marketing purposes.
- We don't share it beyond the limited circumstances Section 4 describes — and never without your direction when it comes to connecting your own AI assistant, as Section 5 explains.
- Our service providers, including the AI vendors named in Section 5, are contractually prohibited from using Customer Content to train their own models or retaining it beyond what's needed to deliver the Services to you, consistent with Section 10.5 of our Terms of Service.
4. How We Share Personal Data
We don't sell or rent personal data. We share it only in these circumstances:
- Subprocessors. Trusted service providers who help us operate the Services — hosting, AI orchestration and inference, email delivery, billing, and similar functions — process data only as needed to perform those services and only under obligations no less protective than our own, per our DPA. Our current subprocessors, their locations, and what each one does are listed in our Subprocessor List, which we update as Section 5.3 of the DPA describes.
- Legal requirements. If required by law, regulation, or legal process.
- Protecting rights and safety. To protect our rights, property, or safety, or that of our users.
- Business transfers. If valueIQ is involved in a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction, subject to this Policy's continued protections.
- With your direction. When you connect a third-party AI assistant, as Section 5 describes.
5. AI Assistants and the valueIQ MCP Server
valueIQ offers a Model Context Protocol (MCP) connection that lets a Connected AI Assistant — such as Claude, ChatGPT, Cursor, or another AI tool — work directly with your own valueIQ account, at your direction. This section explains how that works and what it means for your data.
- You decide what connects. Connecting a Connected AI Assistant requires you to sign in and explicitly authorize that specific tool. We don't send your data to any AI assistant unless you've personally authorized the connection, and you can revoke that authorization anytime.
- What it can see. A Connected AI Assistant can only read and write the Customer Content the authorizing User already has access to inside valueIQ — for example, your deals, value models, business cases, and coaching conversations. It can't see anything outside that User's own account permissions, and it can't see other customers' data under any circumstances.
- It's your tool, acting on your instructions. When you connect your own AI assistant, you're directing your own tool to access your own data — the same as if you opened valueIQ yourself and copied information out. We don't block or interfere with that choice, we don't profit from it, and we're not the one deciding what that assistant or its provider then does with the data once it's left our systems; that's between you and the assistant's provider, under that provider's own terms. We do not sell, rent, or otherwise hand your data to AI companies for our own purposes.
- Our own AI processors don't train on it. The AI models and orchestration tooling behind valueIQ and the MCP connection — including our foundation model providers — are contractually prohibited from using your Customer Content to train their own models, or from retaining it beyond what's needed to serve your request. This is a factual representation about our current contracts with those providers; if that ever changes, we'll update this Policy and our Subprocessor List first.
- You can revoke access anytime. Go to Settings → API Access to disconnect any Connected AI Assistant. This immediately invalidates that connection.
- Credentials are short-lived. Connection tokens expire within an hour and refresh only while the connection stays active; refresh tokens rotate at least every 30 days. We don't log the content of prompts or AI responses, and we don't include personal information in system logs beyond what's needed to operate and secure the connection itself.
- Who's responsible for what. As between you and us, you're responsible for confirming you're authorized to connect a given Connected AI Assistant and that doing so complies with that assistant provider's own terms — the same allocation our Terms of Service (Section 9.6) sets out. As between us and our foundation model providers, valueIQ is the one that provides the AI system making up the Services; you're the one deploying it for your own use, and this Policy and our AI-specific terms are meant to give you the information you need to meet your own obligations as deployer under applicable law.
- Who processes data through this connection. The subprocessors that support the Services generally, and the MCP connection specifically, are the same ones listed in our Subprocessor List — as of this Policy's Last Updated date, that includes Supabase (hosting and database), Vellum (AI orchestration), and OpenAI and Anthropic (foundation model inference, engaged directly by valueIQ). That list, not this Policy, is the current and authoritative source, since it's updated on its own notice cycle.
6. International Data Transfers
valueIQ is Canadian, and Canada holds a European Commission adequacy decision covering PIPEDA-regulated organizations like us — meaning the European Commission has determined Canada provides an adequate level of data protection, so personal data can move from the EEA to valueIQ without Standard Contractual Clauses being strictly required for that leg. The UK and Switzerland recognize Canada's adequacy on the same basis.
Where our subprocessors are located outside Canada, the EEA, UK, or Switzerland — as most of ours are, being US-based — we rely on the Standard Contractual Clauses to cover that onward transfer, as our DPA's Section 11 sets out in detail. A subprocessor located in Canada, like our general hosting provider, doesn't require this additional mechanism, since the transfer stays inside an adequate jurisdiction.
If your own compliance program requires it regardless of the adequacy decision, we'll execute Standard Contractual Clauses with you directly on request — see our DPA for details.
7. Data Retention
We keep personal data only as long as necessary for the purposes described in this Policy:
- Customer Content: for the life of your subscription. After termination, you have 30 days to request access by emailing support@valueiq.ai; after that, we delete it from production systems and from backups on our normal rotation, consistent with Section 5.4 of our Terms of Service and Section 9 of our DPA.
- Account information: for as long as your account is active, then deleted or de-identified within a reasonable period after closure, unless we need to keep it longer for a legal or accounting reason.
- Billing records: as required by applicable tax and accounting law, which can require retention of several years even after your account closes.
- Usage and log data: for as long as reasonably needed for security, support, and service-improvement purposes, then deleted or aggregated so it no longer identifies you.
8. Data Security
We use industry-standard security measures to protect personal data from unauthorized access, loss, misuse, or disclosure, including encryption in transit and at rest, role-based access controls, and multi-factor authentication for our own production infrastructure access. Our DPA's Schedule 2 describes our technical and organizational measures in more detail, including an honest account of the security programs we have and don't yet have — we'd rather tell you the truth than overstate our posture.
9. Automated Decision-Making
valueIQ doesn't make automated decisions that produce legal or similarly significant effects about individuals. The Services generate recommendations, analyses, and Output for your review — not automated decisions made on your behalf — and our Terms of Service (Section 9.2) prohibit using the Services as the sole or primary basis for a decision with a legal or similarly significant effect on someone (credit, employment, housing, insurance, education, healthcare, or essential services) without meaningful human review.
10. Your Rights and Choices
Wherever you're located, you have the following rights regarding your personal data, subject to the limits and exceptions applicable law provides:
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate personal data.
- Deletion: request that we delete your personal data, subject to Section 7's retention needs.
- Objection: object to or ask us to restrict certain uses of your personal data.
- Portability: request your personal data in a portable format, where applicable law provides this right.
To exercise any of these rights, contact us at privacy@valueiq.ai. If your personal data is Customer Content controlled by one of our customers rather than by valueIQ directly, we'll typically direct your request to that customer, consistent with Section 1's controller/processor split, and assist them as our DPA requires.
If you're in the UK or EU, you also have the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office; in the EU, the supervisory authority in your member state.
If you're in Canada, you can also direct a complaint to the Office of the Privacy Commissioner of Canada, or the equivalent provincial authority where applicable (for example, British Columbia's Office of the Information and Privacy Commissioner).
If you're in California or another US state with a comprehensive privacy law (including Colorado, Connecticut, Virginia, and others that have since followed), you have rights to know what personal information we've collected about you, to correct or delete it, to opt out of the sale or sharing of your personal information for cross-context behavioral advertising, and to non-discrimination for exercising these rights. We do not sell or share personal information, as those terms are defined under the CCPA/CPRA, and we don't use automated decision-making technology in a way that requires the opt-out and risk-assessment obligations those laws impose on covered uses. You can exercise these rights yourself or through an authorized agent by contacting privacy@valueiq.ai.
11. Children's Privacy
valueIQ is intended for business use by adults. We don't knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us so we can remove it promptly.
12. Third-Party Links
Our website and Services may link to third-party sites we don't control, including the sites of Connected AI Assistant providers and other subprocessors. This Policy doesn't cover those sites — review their own privacy policies before providing personal data to them.
13. Changes to This Policy
We may update this Policy from time to time. If we make a material change, we'll notify you by email or by updating this page and revising the Last Updated date above. Your continued use of the Services, or continued engagement with our communications, after a change takes effect means you accept it.
14. Contact Us
Questions about this Policy or how we handle your personal data can be sent to privacy@valueiq.ai, or by mail to:
valueIQ Technologies Inc.
#302-118 Carrie Cates Court
North Vancouver, BC, Canada V7M 0G6
© 2026 valueIQ Technologies Inc. All rights reserved.