Vallor
HomeBlog
Trust
Book a demo
Terms of ServicePrivacy Policy
Trust & security

Vallor / Legal

Privacy Policy

How Vallor collects, uses, and protects information, and the choices available to you.

Last updated: September 26, 2026

Board AI, Inc. d/b/a Vallor

On this page

  1. 1. Our Role: Controller and Processor
  2. 2. Information We Collect
  3. 3. How We Use Information and Our Legal Bases
  4. 4. Cookies and Tracking
  5. 5. Subprocessors and Sharing
  6. 6. International Data Transfers
  7. 7. Data Retention
  8. 8. Your Privacy Rights
  9. 9. Automated Decision-Making and AI
  10. 10. Security
  11. 11. Children
  12. 12. Changes to This Policy
  13. 13. Contact
On this page
  1. 1. Our Role: Controller and Processor
  2. 2. Information We Collect
  3. 3. How We Use Information and Our Legal Bases
  4. 4. Cookies and Tracking
  5. 5. Subprocessors and Sharing
  6. 6. International Data Transfers
  7. 7. Data Retention
  8. 8. Your Privacy Rights
  9. 9. Automated Decision-Making and AI
  10. 10. Security
  11. 11. Children
  12. 12. Changes to This Policy
  13. 13. Contact

Board AI, Inc., doing business as “Vallor” (“Vallor,” “we,” “us,” or “our”), provides an AI-powered contract management platform available at vallor.ai and its subdomains (the “Service”).

This Privacy Policy explains what information we collect, how we use it, who we share it with, how long we keep it, and the rights and choices you have. It applies to visitors to our website and to users of the Service.

1. Our Role: Controller and Processor

Vallor acts in two different roles depending on the data:

  • As a controller, we determine how and why we process account information, website and marketing data, and business-contact data. This policy governs that processing.
  • As a processor, we handle the contracts and related documents that our customers upload or connect to the Service. Our customer is the controller of that data, and we process it only on the customer’s documented instructions under our Data Processing Agreement. If you are an individual whose data appears in a customer’s contracts, please direct privacy requests to that customer; we will assist them as required.

Personal data of Vallor’s own employees, contractors, and job applicants (including unsuccessful candidates) is processed by Vallor as a controller under a separate internal staff privacy notice and is not covered by this policy.

2. Information We Collect

Category Examples Source
Account information Name, email address, company name, role, login credentials You or your organization, when your organization provisions or authorizes an account, when you activate an account, or when you book a demo
Customer contract data Complete contracts, related documents, and metadata uploaded or connected to the Service, which may include names and contact details of signatories, financial terms, personal information, and communication content Our customers (we act as processor)
Usage and device data Product usage events, pages viewed, feature interactions, IP address, browser and device information Automatically, via PostHog and our infrastructure, subject to applicable consent requirements
Business-contact data Name, business email, phone, company, role, engagement history You, your organization, or business-development sources
Communications Support requests, feedback, and correspondence with us You
Cookies and similar technologies Authentication, session, preference, and analytics identifiers Your browser or device

The authenticated application uses essential cookies only. Non-essential analytics and marketing cookies are used on our marketing website and are controlled through our cookie consent banner.

3. How We Use Information and Our Legal Bases

We use information to:

  • Provide, operate, secure, and maintain the Service.
  • Process complete contracts and the information they contain as instructed by the customer, including AI-powered extraction, analysis, redlining, and search, subject to the customer agreement, confidentiality obligations, and applicable law.
  • Respond to support requests and communicate about the Service.
  • Analyze usage and improve features, performance, and reliability.
  • Use aggregated, anonymized data derived from customer content and system usage solely to develop, optimize, and improve Vallor’s products and services. Such data must not identify a customer, organization, or individual or disclose their confidential information. We do not attempt to reidentify it.
  • Send marketing communications where permitted.
  • Comply with legal obligations and enforce our agreements.

For individuals in the European Economic Area (EEA) and the United Kingdom, we rely on the following legal bases under Article 6(1) of the GDPR:

Processing Legal basis
Providing the Service and managing accounts Performance of a contract (Art. 6(1)(b))
Processing customer contract data (as processor) The legal basis is determined by the customer as controller; Vallor processes this data only on the customer’s documented instructions under the Data Processing Agreement
Security logging and monitoring Legitimate interests in protecting the Service (Art. 6(1)(f))
Product analytics and improvement Legitimate interests in operating and improving the Service (Art. 6(1)(f)), with consent for non-essential website analytics cookies (Art. 6(1)(a))
Marketing communications Consent (Art. 6(1)(a))
Meeting legal and regulatory obligations Legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to this processing as described in Section 8.

We do not sell personal information. We do not use customer content, system data, or data derived from either to train or fine-tune any artificial intelligence or machine learning model, including our own or a third party’s models, and we do not permit our AI service providers to do so. Processing customer content through AI components to provide the Service is permitted and does not constitute model training. Uploading a contract does not make it public or authorize disclosure of its confidential information to other customers.

4. Cookies and Tracking

We use cookies and similar technologies for authentication, session management, preferences, and analytics. On our marketing website, you can accept or reject non-essential cookies through our consent banner, and you can change your choice at any time using “Cookie preferences” in the footer. Non-essential website analytics cookies are enabled only after you opt in.

We honor recognized browser-based opt-out signals, including the Global Privacy Control (GPC), where required by law. You can also control cookies through your browser settings.

5. Subprocessors and Sharing

We share information only with service providers that help us deliver the Service, under contracts that restrict their use of the data. Categories include:

  • Cloud hosting and infrastructure (including Amazon Web Services and Vercel), which host the Service and store data.
  • Database hosting (including PlanetScale and Neon).
  • AI model and document-processing providers (including Anthropic, OpenAI, Google, Mistral, and Cohere) that process contract content to deliver extraction and analysis features. These providers are contractually restricted from using customer data to train their models, and we use zero- or limited-data-retention configurations where the provider offers them.
  • Authentication (WorkOS).
  • Product and website analytics (PostHog), subject to applicable consent requirements.
  • Support, communications, and forms (including Intercom, Resend, and Typeform).

A current and complete list of subprocessors is available through our Trust Center or on request at admin@vallor.ai. We may also disclose information if required by law, to comply with legal process, or to protect the rights, property, or safety of Vallor, our customers, or others. If we are involved in a merger, acquisition, or sale of assets, we will continue to protect personal information and notify affected parties where required.

6. International Data Transfers

Vallor is based in the United States, and our service providers may process data in the United States and other countries. When we transfer personal data from the EEA, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards, principally the European Commission’s Standard Contractual Clauses (SCCs) and, for UK transfers, the UK International Data Transfer Addendum.

Our AI and infrastructure providers are bound by these safeguards, together with no-training commitments and, where the provider offers them, zero- or limited-data-retention configurations. Our primary processing region is the EU (AWS eu-west-1), with a US secondary region used for resilience and disaster recovery. This is an operational measure and not a data-localization or data-residency commitment; personal data may be processed in the United States and other regions under the safeguards described above.

You may request a copy of the relevant safeguards at admin@vallor.ai.

7. Data Retention

We retain personal data only as long as needed for the purposes described in this policy:

  • Account information is retained while your account is active and then deleted, subject to legal retention requirements.
  • Customer contract data is retained for the duration of the customer agreement and deleted or returned within 60 days of termination, subject to any legal retention requirement and the governing customer agreement.
  • Usage and analytics data is retained in line with our log-retention schedule and held in aggregated or pseudonymized form where feasible.
  • Business-contact data is retained while the relationship is active and reviewed periodically for relevance.

8. Your Privacy Rights

8.1 EEA and UK (GDPR)

Depending on your location, you have the right to: access your personal data; request correction; request deletion; receive your data in a portable format; object to or request restriction of certain processing; and, where processing is based on consent, withdraw that consent at any time without affecting prior processing.

To exercise these rights, contact us at admin@vallor.ai. If we process your data on behalf of a Vallor customer, we will direct your request to that customer. You also have the right to lodge a complaint with your local data protection supervisory authority.

8.2 California (CCPA/CPRA)

California residents have the right to know what personal information we collect and how we use and disclose it; to request deletion; to request correction; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and to be free from discrimination for exercising these rights.

In the preceding 12 months, we have collected the categories of personal information described in Section 2, which map to the CCPA categories of identifiers, commercial information, internet or other electronic network activity, professional or employment-related information, and inferences. We collect this information from the sources described in Section 2, use it for the purposes described in Section 3, and disclose it to the service providers described in Section 5.

We have not sold or shared personal information, and we do not use or disclose sensitive personal information for purposes that require an opt-out.

Where we would otherwise sell or share personal information, we treat a Global Privacy Control (GPC) signal as a valid opt-out. You may submit requests at admin@vallor.ai, and you may use an authorized agent to submit a request on your behalf with proof of authorization.

8.3 Other US States

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and others) have similar rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, sale, and certain profiling. We do not sell personal data or use it for targeted advertising or profiling that produces legal or similarly significant effects.

Where these laws provide an appeal process, you may appeal a denied request by replying to our response or contacting admin@vallor.ai. Where applicable, we treat recognized universal opt-out signals such as GPC as a valid opt-out.

We will verify your identity before fulfilling a request and respond within the timeframes required by applicable law.

9. Automated Decision-Making and AI

The Service uses AI to assist with contract extraction, analysis, redlining, classification, and search. These outputs are recommendations presented for human review; we do not make decisions that produce legal or similarly significant effects about individuals solely by automated means within the meaning of Article 22 of the GDPR. AI-generated content is labeled in the Service so users can distinguish it from source data.

10. Security

Vallor maintains a SOC 2 Type II audited security program and an ISO/IEC 27001-aligned information security management system. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to customer data is restricted on a least-privilege basis, logged, and monitored, and customer data is isolated per tenant. Details on our security posture, reports, and documentation are available through our Trust Center or by contacting admin@vallor.ai.

11. Children

The Service is intended for business use and is not directed to anyone under 18, and we do not knowingly collect personal information from children under 16 (the GDPR Article 8 age of consent). If you believe a child has provided us personal information, contact admin@vallor.ai and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version at vallor.ai/legal/privacy and update the “Last updated” date. We will communicate material changes to customers in advance where required. Our Terms of Service govern use of the Service, subject to the governing customer agreement.

13. Contact

Board AI, Inc. (d/b/a Vallor)
1000 Brickell Avenue, Suite 715, PMB 690
Miami, Florida 33131, United States
admin@vallor.ai

EU Representative (GDPR Article 27)
Instant EU GDPR Representative Ltd (Adam Brogden)
Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland
contact@gdprlocal.com

UK Representative (UK GDPR Article 27)
GDPRLocal Ltd (Adam Brogden)
1st Floor, Front Suite, 27-29 North Street, Brighton, England, BN1 1EB, United Kingdom
contact@gdprlocal.com

EEA and UK data subjects may contact the relevant representative directly regarding the processing of their personal data.

This policy is governed by the laws of the State of Florida, without regard to its conflict-of-laws principles, except where applicable data protection law provides otherwise.

Questions? Contact us.

Back to top ↑
Vallor

The AI coworker for procurement, legal, and sales. Live in 5 minutes, with every answer cited back to the source contract.

Product

  • Platform
  • Book a demo
  • Trust & Security
  • Compare

Resources

  • Blog
  • Resources
  • Glossary
  • Benchmarks

Company

  • Contact
  • Security
  • Trust Center

© 2026 Board AI, Inc. All rights reserved.

PrivacyTermsSub-processorsSecurity