Valcenra

Trust centre

Controls for financial records and the conclusions drawn from them

A procurement-review starting point. Contractual commitments and the production schedule control where they differ from this summary.

Security

Subprocessors, including AI providers

ProviderPurposeLocation note
RailwayApplication hostingUnited States
Neon / AWSManaged PostgreSQLOhio, United States (us-east-2) for the current environment
Microsoft 365Operational emailUS/EU service footprint
StripePayment processing when enabledUnited States/global
PlaidOptional bank connectionUnited States
CloudflareAbuse protection and cookieless visit counts on the public pagesGlobal
Google AnalyticsPublic-page visit measurement, only after a visitor opts inUnited States/global
Internal operations tooling operated by the Globixera groupAuthenticates, routes and meters AI phrasing requestsUnited States
Configured AI providerOptional phrasing of an already-calculated explanationThe exact provider/model is disclosed before enablement; customer records are not training data.

Retention and location

Live customer data is kept for the subscription and 30 days after cancellation, then deleted; backups roll off within a further 30 days. Audit trails and published reports may be retained for seven years, and contact enquiries for two years, subject to the contract and legal holds. A customer requiring another jurisdiction must agree it before onboarding.

DPA and data protection

Transfers of personal data from the EEA, UK and Switzerland rely on the EU standard contractual clauses, with the UK addendum. The DPA is a draft for legal review and is not published. Request it, the current subprocessor schedule or a security review through the contact page, which is also the route for data-protection requests. The privacy policy lists every provider.