Valcenra privacy policy
Valcenra, LLC · 7228 Wadebridge Drive, Canton, MI 48187, United States
Last updated: 28 September 2026
In short
Valcenra analyses financial records that a business gives it, explains what changed in those records, and refuses to explain what the records do not support. To do that it has to hold the records.
We do not sell your data. We do not use your financial records to train anything. We do not show advertising. Nobody outside your organisation sees your figures unless you grant them access, and every such grant is recorded, scoped and dated.
1. Who we are
Valcenra is operated by Valcenra, LLC, a Michigan limited liability company.
For customers in the European Economic Area and the United Kingdom: when your organisation uses Valcenra, your organisation is the data controller for the records you put into it, and Valcenra is the data processor. We act on your instructions. For our own website visitors and prospective customers, we are the controller.
2. What we hold, and why
Records your organisation puts in. Ledger entries, product and transaction detail, fiscal calendars, account structures, evidence documents you attach, explanations and approvals your people write, and reports you publish. This is the material the product exists to analyse.
Information about the people who use it. Name, email address, the role granted, and the organisation. We hold a cryptographic hash of each person's password, never the password itself, and we never learn what it is — passwords are set by the person from a one-time link.
Records of what was done. Who signed in, when, from what kind of device, and what they did: every import, analysis run, approval, published report and grant of access. This trail is not optional. A financial system that cannot say who changed a figure is not one an auditor can rely on.
Bank connections. If your organisation connects a bank account, we hold an encrypted access token issued by our banking data provider, the name of the institution, the consent you gave, and the transactions retrieved. We never hold your online banking username or password, in any form.
Website visitors. If you use the contact form, we hold what you typed and your email address. We do not run advertising trackers, and we do not use Google Ads or remarketing tags on this site.
Analytics on the public pages. Two measurement tools are used on the public marketing pages only, never on the signed-in product:
- Google Analytics, only if you opt in. A banner asks first, with “Essential only” and “Allow analytics” as equal choices. Until you choose “Allow analytics”, no request is sent to Google. If you allow it, Google Analytics measures page visits and completed business enquiries, with advertising storage, ad personalisation and Google signals switched off; it receives the page address without its query string, and never the contents of a form. You can change your choice at any time with the “Analytics preferences” button at the foot of the page. Legal basis in the EEA and UK: your consent.
- Cloudflare Web Analytics, which counts page views and load performance in aggregate without setting cookies or identifying individual visitors. Legal basis in the EEA and UK: our legitimate interest in knowing that the public site works.
Error reports. If a page fails to load or a script fails in your browser, the page sends us a short technical report: the page path, the error message, the file and line, the browser version and the window size. It carries no form contents, no query string and nothing that identifies you, and it is written to our application log rather than stored in a database.
3. What we do not do
- We do not sell personal information, and never have.
- We do not use your financial records to train AI models, ours or anybody else's.
- We do not profile individuals or make automated decisions about people.
- We do not access your records except where you grant access, or where it is strictly necessary to fix a fault you have reported — and both are recorded in a trail you can read.
4. Artificial intelligence, specifically
- The figures are never produced by a model. Every amount, bridge, reconciliation and refusal is computed by the software from your records.
- A model may be used to phrase an explanation the software has already written. What it produces is checked against the underlying facts before you see it, and a draft that states anything the facts do not is discarded and the plain version shown instead.
- Your records are not training data, and our providers are contractually bound not to train on them.
- Where a model is used it receives only what it needs for the question asked, never a customer's whole dataset.
5. Where it is held
Your records are held in a managed Postgres database on Amazon Web Services in Ohio, United States (us-east-2), and the application runs on Railway. Connections are encrypted in transit and data is encrypted at rest.
If your organisation requires data to remain in a particular jurisdiction, contact us before signing up. We can provision a database in another region, and if we cannot meet your requirement we will say so rather than leave it vague.
International transfers. Valcenra is operated from the United States, so personal information from the European Economic Area, the United Kingdom and Switzerland is transferred to the United States. For those transfers we rely on the European Commission’s standard contractual clauses (Decision (EU) 2021/914), with the UK International Data Transfer Addendum for UK data. For customers, the clauses form part of our data processing agreement, which you can request using the contact details below. We do not rely on the EU–US Data Privacy Framework.
6. Who else touches it
| Provider | What it does | Where |
|---|---|---|
| Neon | Hosts the database | AWS, United States |
| Railway | Runs the application | United States |
| Microsoft 365 | Sends our email | United States / EU |
| Cloudflare | Protects the public site from automated abuse, and counts visits to the public pages without cookies (Cloudflare Web Analytics) | Global |
| Google (Google Analytics) | Measures visits to the public pages, only for visitors who choose “Allow analytics”; never used on the signed-in product | United States / global |
| Stripe | Takes payment and holds card details | United States / global |
| Plaid | Connects your bank, with your consent | United States |
| Internal operations tooling operated by the Globixera group | Authenticates, routes and meters AI phrasing requests; receives a one-way customer reference and the minimum prompt context | United States |
| Cloudflare Workers AI | Hosted inference for customer phrasing requests | Global / United States |
We never see your full card number. Payment details are entered with Stripe and held by Stripe.
Customer records are never sent to unpaid Gemini, Groq or Hugging Face AI tiers. Paid AI fallback is disabled.
We will post an updated list here before adding a provider that touches customer data.
7. How long we keep it
- While you are a customer: as long as your organisation keeps it.
- After you cancel: 30 days, so an account closed by mistake can be reinstated. Then deletion from the live database.
- Backups roll off within a further 30 days. We do not extract an individual record from a backup, because that would mean restoring and re-editing the backup itself.
- The audit trail and published reports are retained for seven years, because they exist to answer questions about what was reported and when. A trail that can be erased on request is not evidence of anything.
- Contact form messages: two years.
- Bank connections: closed with the provider as soon as you disconnect or your subscription ends, and we keep the confirmation.
8. Your rights
Wherever you are, you can ask us to see, correct, export or delete the personal information we hold about you, and to stop processing it.
If your organisation is the customer, ask them first — they control the records, and we will refer your request to them. Where we are the controller, come straight to us. We answer within 30 days.
In the EEA or UK you may also complain to your data protection authority. In California you have the right to know, delete, correct and opt out of sale or sharing — and we do not sell or share personal information.
9. How it is protected
- Passwords are stored as scrypt hashes with a per-user salt. Nobody at Valcenra can read a password.
- Sessions and one-time links are stored only as hashes.
- Separation between customers is enforced in the database schema, not only in application code.
- Every action is recorded with who took it and when.
- Access by outsiders — a consultant, an auditor — is granted by you, limited to named areas, and always has an end date.
- Encryption in transit and at rest.
No system is perfectly secure and we will not claim otherwise. If a breach affects your data we will tell you without undue delay and within 72 hours of becoming aware.
10. Children
Valcenra is business software sold to organisations and is not directed at anyone under 18.
11. Changes
If we change this policy in a way that materially affects you, we will say so here and email the account owner before it takes effect.
12. Contact
Valcenra, LLC, 7228 Wadebridge Drive, Canton, MI 48187, United States.