Legal
Privacy Policy & GDPR
Last updated: June 2, 2026
ValHR is based in the European Union. This policy explains how we collect, use, and protect personal data when you visit our website or use our HR platform, in line with the General Data Protection Regulation (GDPR) and applicable EU data protection law.
Who is responsible for your data
For this website and for customer accounts on the ValHR platform, ValHR acts as the data controller for personal data we determine how to process.
For employee and HR data that customers upload about their staff, your employer or organization is usually the data controller and ValHR acts as a data processor, processing that data only on their instructions and under a data processing agreement.
Privacy questions and GDPR requests: hello@valhr.com
Information we collect
We may collect the following categories of personal data:
- Account details such as name, email address, job title, and company name
- Employee and HR data you or your organization manage within the platform
- Usage data, device information, IP address, and log files
- Messages sent through contact forms, support, or email
- Cookie and consent preferences where applicable
Legal bases for processing (GDPR)
We process personal data only where we have a valid legal basis, including:
- Contract — to provide the ValHR service, manage accounts, and support billing
- Legitimate interests — to secure our platform, prevent abuse, and improve reliability, balanced against your rights
- Legal obligation — where we must retain or disclose data under EU or national law
- Consent — for optional cookies or marketing communications where required; you may withdraw consent at any time
How we use information
We use personal data to:
- Provide, operate, maintain, and improve the ValHR platform
- Authenticate users and enforce role-based access
- Respond to inquiries and provide customer support
- Send service-related communications and security notices
- Comply with legal obligations and enforce our terms
Data retention
We keep personal data only for as long as necessary for the purposes described in this policy — for example, for the life of your account plus a limited period for backups, billing records, or legal claims. Customer HR data retention is also governed by the customer's instructions and applicable employment law.
Data storage, security, and transfers
We apply technical and organizational measures designed to protect personal data against unauthorized access, loss, or misuse. Access to HR data is limited to authorized users within your organization according to role permissions.
Where personal data is processed outside the European Economic Area, we rely on appropriate safeguards such as EU Standard Contractual Clauses or equivalent mechanisms approved under GDPR.
Third-party processors
We use trusted infrastructure and service providers for hosting, email delivery, payments, and optional analytics. They process data only to deliver their services to us and under written data processing terms consistent with GDPR.
Your rights under GDPR
If you are in the EU or EEA, you have the following rights in relation to your personal data, subject to applicable exceptions:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate or incomplete data
- Erasure — request deletion where there is no compelling reason to continue processing
- Restriction — ask us to limit how we use your data in certain cases
- Portability — receive data you provided in a structured, commonly used format where processing is based on contract or consent
- Objection — object to processing based on legitimate interests or for direct marketing
- Withdraw consent — where processing is based on consent, without affecting prior lawful processing
We respond to verified requests within one month. To exercise your rights, contact hello@valhr.com. If you are an employee whose data is managed by your employer in ValHR, please contact your organization first as they are usually the data controller.
You also have the right to lodge a complaint with a supervisory authority in your EU or EEA member state, for example the data protection authority where you live or work.
Cookies
We use essential cookies required for security and basic site functionality. Optional cookies — such as analytics — are used only if you accept them through our cookie banner.
You can change your browser settings to block or delete cookies. Blocking essential cookies may affect how the site works.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date above.
Contact
Questions about privacy or GDPR? Email hello@valhr.com or hello@valhr.com.