Effective Date: April 2026 | Last Updated: April 2026
Valiqa
This Privacy Policy describes how Valiqa ("Valiqa," "we," "us," or "our"), collects, uses, stores, shares, and protects information when you use the Valiqa platform and related services (collectively, the "Service"). By using the Service, you acknowledge that you have read and understood this Privacy Policy.
We use collected information for the following purposes:
Equipment specifications, process parameters, and company formatting data you provide are used as input to generate documents for your account only. Your data is processed in real time during document generation and is not persistently stored in AI model memory beyond your account context.
When you edit AI-generated content (such as modifying test steps or acceptance criteria), the Service may store those editing patterns to improve the quality of future document generation for your account specifically. This learning is isolated to your account and is not shared across accounts.
Your data is never used to train models, improve generation quality, or provide any benefit for other companies or accounts. Cross-account data sharing does not occur. Each account operates in a fully isolated data environment.
The Service uses third-party AI model providers to power document generation. Your data is transmitted to these providers solely for the purpose of generating documents in response to your requests. We select AI providers that offer commercial data protections, and your data is subject to data processing agreements that prohibit these providers from using your data to train their models.
AI-generated content may contain errors, omissions, or inaccuracies. All generated documents must be reviewed and approved by qualified personnel before use. See Section 7 of our Terms of Service for complete disclaimers.
All data is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256 or equivalent encryption provided by our infrastructure providers.
Your company's data is tenant-isolated, enforced at the database level using row-level security (RLS) policies.
Every action in the system is logged in an immutable audit trail. Records are append-only and cannot be modified or deleted by any user, including administrators.
Access to production systems is restricted to authorized personnel using multi-factor authentication. We follow the principle of least privilege for all system access.
All data is stored on infrastructure hosted in the United States.
In the event of a data breach or security incident that affects your data, we will notify you by email within 72 hours of becoming aware of the incident.
We do not sell your data. We do not share your data with third parties for advertising, marketing, or profiling purposes.
We share data only in the following limited circumstances:
We retain your data for as long as your account is active and as necessary to provide the Service.
If you close your account, we will:
Audit trail records may be retained for up to 7 years after account closure to support regulatory compliance requirements.
We may retain certain data beyond the standard deletion timeline when required by law, tax obligations, or to resolve disputes.
Free tier accounts that remain inactive for 180 consecutive days may be subject to data deletion, with 30 days prior email notice.
You have the right to request a copy of the personal data we hold about you in a commonly used, machine-readable format.
You may correct inaccurate personal information through your account settings or by contacting us.
You may request deletion of your account and all associated personal data, subject to the retention exceptions in Section 6.
You may export all documents, protocols, reports, and associated data from your account at any time.
You may opt out of non-transactional email communications at any time.
In certain circumstances, you may request that we restrict the processing of your personal data.
If you are a California resident, you have additional rights under CCPA/CPRA:
To exercise these rights, contact us at [email protected]. We will respond within 45 days.
If you are in the EU/EEA, you have additional rights under GDPR:
Our lawful basis for processing: (a) performance of a contract, (b) legitimate interests, (c) consent.
Contact us at [email protected]. We will verify your identity before processing any request.
We use a minimal set of cookies:
valiqa_cookie_consent_v2 entry in your browser's local storage and choosing "Decline" when the banner reappears, or by opting out globally at clarity.microsoft.com/optout.The Service is designed for use by qualified professionals and is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18.
The Service is operated from the United States. If you access the Service from outside the United States, you understand and consent to the transfer of your data to the United States. For EU/EEA users, we use Standard Contractual Clauses (SCCs).
The Service does not currently respond to DNT signals automatically. We do not use advertising or retargeting cookies regardless of DNT settings. Optional analytics (Microsoft Clarity) is opt-in via the cookie banner; if you decline, no third-party analytics scripts are loaded.
We may update this Privacy Policy from time to time:
We use essential cookies for authentication and security. With your consent, we also use Microsoft Clarity on our marketing pages to understand how visitors navigate the site. Learn more.