ValueAmp

Financial Intelligence Platform

โ† Back to login
๐Ÿ”’

Privacy Policy

Last updated: 25 March 2026 ยท Effective from: 25 March 2026

Data hosted in EU (Dublin, Ireland) ยท GDPR compliant

This Privacy Policy explains how ValueAmp Advisory Ltd ("ValueAmp", "we", "us", "our") collects, uses, stores, and protects your personal data when you use our platform at app.valueamp.co.uk. We are committed to protecting your privacy in accordance with the UK GDPR, the Data Protection Act 2018, and applicable EU data protection law.

1. Who We Are

ValueAmp Advisory Ltd is the data controller responsible for your personal data. We operate a financial intelligence platform providing management accounts, forecasting, and value creation tools to UK SMEs and PE portfolio companies.

Registered in England and Wales. For data protection enquiries, contact us at: privacy@valueamp.co.uk

2. Data We Collect

2.1 Account & User Data

  • Email address (required for account creation and login)
  • Full name (provided during registration or invite acceptance)
  • Profile avatar (optional)
  • Role and access permissions (admin, analyst, viewer)
  • Login timestamps and session activity
  • IP address (collected by Supabase Auth at sign-in)

2.2 Employee Data (uploaded by your organisation)

Where your organisation uploads employee information for use in the People module, we process: full name, job title, department, start/leave dates, salary, employment type, and FTE fraction. This data is provided by you and processed under your instruction as data processor.

2.3 Financial Data

Your organisation uploads financial data (trial balances, budgets, forecasts, customer revenue, and commercial data). This data belongs to your organisation. We process it solely to provide the platform services.

2.4 Usage & Technical Data

  • Browser type and version
  • Device type (desktop, mobile)
  • Pages visited and features used within the platform
  • Error logs and diagnostic data

2.5 Data We Do Not Collect

  • Payment card details (we do not currently process payments through the platform)
  • Government ID numbers or National Insurance numbers
  • Biometric or health data
  • Data relating to individuals under 18

3. How We Use Your Data

PurposeData UsedLegal Basis
Providing the platform and servicesAccount data, financial data, employee dataContract performance
User authentication and access controlEmail, role, session dataContract performance
Sending invite and password reset emailsEmail addressContract performance
Improving platform functionalityUsage data, error logsLegitimate interests
Security monitoring and fraud preventionIP address, login activityLegitimate interests
Communicating service updatesEmail addressLegitimate interests
Legal and regulatory complianceAll data as requiredLegal obligation

5. Who We Share Data With

We do not sell your personal data. We share data only with the following categories of sub-processors, each bound by appropriate data processing agreements:

Sub-ProcessorRoleLocationPurpose
Supabase Inc.Data ProcessorEU (Dublin, Ireland)Database hosting, authentication, and storage
Vercel Inc.Data ProcessorUSA (with EU SCCs)Platform hosting and content delivery network
Brevo (Sendinblue)Data ProcessorEU (France)Transactional email delivery (invites, magic links)
Cloudflare Inc.Data ProcessorUSA (with EU SCCs)DNS management and email routing

We ensure all sub-processors outside the UK/EEA have appropriate safeguards in place, including Standard Contractual Clauses (SCCs) where required.

Legal Disclosures

We may disclose personal data to law enforcement or regulatory authorities where required by law, or where we believe disclosure is necessary to protect the rights, property, or safety of ValueAmp, our clients, or others.

6. Data Retention

Data CategoryRetention PeriodBasis
Active user account dataDuration of account + 30 days post-deletionContract performance
Financial data (TB, budgets, forecasts)Duration of subscription + 12 monthsContract performance / legitimate interests
Employee dataDuration of subscription + 12 monthsContract performance
Authentication logs (login timestamps, IP)90 daysSecurity / legitimate interests
Error logs and diagnostic data30 daysLegitimate interests
Deleted user dataRemoved within 30 days of account deletionData minimisation

You may request earlier deletion of your personal data under your rights described in Section 8. We will action deletion requests within 30 days unless we have a legal obligation to retain the data.

7. Data Residency & International Transfers

โœ“ Your data stays in the EU

All financial and personal data is stored in Supabase Cloud, hosted in eu-west-2 (AWS Dublin, Ireland). This is within the European Economic Area and does not require any international transfer mechanism under UK GDPR Chapter V or EU GDPR.

Vercel (our hosting provider) and Cloudflare (our DNS provider) are US-based. We rely on Standard Contractual Clauses (SCCs) and Vercel/Cloudflare's UK/EU data transfer mechanisms for any processing that occurs outside the EEA. In practice, all financial data at rest remains in Dublin.

8. Your Rights

Under UK GDPR and the Data Protection Act 2018, you have the following rights regarding your personal data:

RightDescriptionHow to Exercise
AccessReceive a copy of all personal data we hold about youEmail privacy@valueamp.co.uk
RectificationCorrect inaccurate or incomplete dataUpdate in Settings, or email us
ErasureRequest deletion of your personal data ("right to be forgotten")Email privacy@valueamp.co.uk
RestrictionRestrict processing of your data in certain circumstancesEmail privacy@valueamp.co.uk
PortabilityReceive your data in a machine-readable formatEmail privacy@valueamp.co.uk
ObjectionObject to processing based on legitimate interestsEmail privacy@valueamp.co.uk
Withdraw consentWithdraw consent where processing is consent-basedEmail privacy@valueamp.co.uk
Automated decisionsNot be subject to solely automated decision-making with legal effectsN/A โ€” we do not use automated decision-making

We will respond to all valid requests within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

9. Security

We take the security of your data seriously and implement appropriate technical and organisational measures including:

  • All data transmitted over HTTPS/TLS 1.2+ (enforced at Cloudflare edge)
  • Database-level Row Level Security (RLS) โ€” your data cannot be accessed by other tenants even if application code were compromised
  • JWT-based session tokens with short expiry (1 hour)
  • Passwords hashed using bcrypt via Supabase Auth
  • Access controls: role-based permissions limit data visibility within your organisation
  • Service role key (unrestricted DB access) used only in server-side API routes, never exposed to browsers
  • Daily automated database backups by Supabase

No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at privacy@valueamp.co.uk.

10. Cookies & Local Storage

ValueAmp uses the following cookies and browser storage:

Name / TypePurposeDurationCategory
sb-* (Supabase session)Maintains your authenticated sessionSession / 1 hourStrictly necessary
Vercel analytics cookiesAnonymous usage analyticsSessionAnalytics (anonymous)

We do not use advertising cookies, third-party tracking cookies, or cookies that identify you across other websites. Strictly necessary cookies cannot be disabled as they are required for the platform to function.

11. Children's Privacy

ValueAmp is a professional B2B platform. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has submitted personal data to us, please contact privacy@valueamp.co.uk and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify registered users by email and update the "Last updated" date at the top of this page.

Continued use of the platform after changes take effect constitutes acceptance of the updated policy.

13. Contact Us

Data Controller

ValueAmp Advisory Ltd

ValueAmp Advisory Ltd, England & Wales

Email: privacy@valueamp.co.uk

Platform: app.valueamp.co.uk

If you have a complaint, you also have the right to contact the Information Commissioner's Office (ICO): ico.org.uk

ยฉ 2026 ValueAmp Advisory Ltd