Legal

Privacy Policy

Last updated: September 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

VALENTO GmbH
Kaiser-Joseph-Str. 254
79098 Freiburg im Breisgau
Germany
Represented by: Eva Brandenburg, Shahad Hussain Kavassery Sakeer
Email: hello@valento.io
Website: valento.io

2. General information on data processing

2.1 Scope of the processing of personal data

As a matter of principle, we process our users’ personal data only to the extent necessary to provide a functioning website together with our content and services. Personal data of our users is generally processed only with the user’s consent. An exception applies in cases where obtaining prior consent is not possible for factual reasons and the processing of the data is permitted by law.

2.2 Legal basis for the processing of personal data

Where we obtain the consent of the data subject for processing operations involving personal data, Art. 6(1)(a) GDPR serves as the legal basis.

Where the processing of personal data is necessary for the performance of a contract to which the data subject is a party, Art. 6(1)(b) GDPR serves as the legal basis. This also applies to processing operations necessary for the performance of pre-contractual measures.

Where the processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Art. 6(1)(c) GDPR serves as the legal basis.

Where the processing is necessary to protect a legitimate interest of our company or of a third party, and the interests, fundamental rights and freedoms of the data subject do not override that interest, Art. 6(1)(f) GDPR serves as the legal basis for the processing.

2.3 Erasure of data and storage period

The personal data of the data subject is erased or blocked as soon as the purpose of storage ceases to apply. Data may be stored beyond that point where this has been provided for by the European or national legislator in Union regulations, laws or other provisions to which the controller is subject. Data is also blocked or erased when a storage period prescribed by the standards referred to expires, unless there is a need for continued storage of the data for the conclusion or performance of a contract.

3. Provision of the website and creation of log files

3.1 Description and scope of the data processing

Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing device. The following data is collected: information about the browser type and version used, the user’s operating system, the user’s internet service provider, the user’s IP address, the date and time of access, websites from which the user’s system reaches our website, and websites accessed by the user’s system via our website. This data is also stored in our system’s log files. This data is not stored together with other personal data of the user.

3.2 Legal basis and purpose

The legal basis for the temporary storage of the data and the log files is Art. 6(1)(f) GDPR. The temporary storage of the IP address by the system is necessary in order to deliver the website to the user’s device. Storage in log files takes place in order to ensure the functionality of the website and the security of our information technology systems.

3.3 Storage period

The data is erased as soon as it is no longer required to achieve the purpose for which it was collected. Where data is collected in order to provide the website, this is the case when the respective session has ended. Where data is stored in log files, this is the case after seven days at the latest.

4. Hosting

Our website is hosted on Amazon Web Services (AWS). The provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg. We use AWS data centres in the European Union (region Frankfurt). When you visit our website, technically necessary data (in particular IP addresses) is processed by AWS as a processor within the meaning of Art. 28 GDPR on the basis of a data processing agreement including the EU standard contractual clauses. AWS deletes access logs automatically after a short period. For details, please see the AWS privacy notice: aws.amazon.com/privacy

Support access by AWS from outside the EU cannot be fully ruled out. Where personal data is transferred to the USA in this context, we base the transfer on the European Commission’s adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR), under which Amazon Web Services, Inc. is certified, and in addition on the EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR. You can request a copy of the safeguards at hello@valento.io.

The hosting service provider is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably and securely as possible.

5. Contact by email

You can contact us via the email address provided, hello@valento.io. In this case, the personal data transmitted with your email is stored. The data is not passed on to third parties in this context. The data is used exclusively for processing the conversation.

The legal basis for processing data transmitted in the course of sending an email is Art. 6(1)(f) GDPR. Where the email contact is aimed at concluding a contract, Art. 6(1)(b) GDPR is an additional legal basis for the processing.

The data is erased as soon as it is no longer required to achieve the purpose for which it was collected. This is the case when the respective conversation with you has ended and the matter has been finally resolved.

6. Appointment booking (Microsoft Bookings)

We use Microsoft Bookings to book appointments, a service provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The booking page opens in a new browser tab on Microsoft’s servers. When you book an appointment, your details (name, email address and, where applicable, further data entered by you) are transmitted to Microsoft and processed there. The data processing takes place on the basis of your consent (Art. 6(1)(a) GDPR) or for the performance of pre-contractual measures (Art. 6(1)(b) GDPR).

Further information can be found in Microsoft’s privacy statement: privacy.microsoft.com

7. Newsletter "The Margin Brief" (Brevo)

If you subscribe to our newsletter, we use Brevo (formerly Sendinblue) to manage subscriptions and send the emails. The provider is Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.

We use a double opt-in procedure: after you submit the form you receive a confirmation email and your subscription only becomes active once you click the confirmation link. We store the email address you entered, the wording of the consent you gave, the time of the subscription and of the confirmation, and the page from which you subscribed, in order to be able to prove your consent. Brevo may also record whether emails were opened and which links were clicked.

The data processing takes place on the basis of your consent (Art. 6(1)(a) GDPR). You can withdraw this consent at any time with effect for the future, for example via the unsubscribe link in every newsletter or by writing to hello@valento.io. Your data is deleted from the mailing list after you unsubscribe; data required to document your earlier consent may be retained on a suppression list.

For detailed information on Brevo, please see: brevo.com/legal/privacypolicy

8. Data from public sources (business contacts)

We process personal data of contact persons at companies which we would like to approach as potential business partners, including where we did not collect this data from you directly. With the following information we fulfil our duty to provide information under Art. 14 GDPR.

8.1 Categories of data and sources

We process exclusively work-related details: first and last name, function or position, company affiliation, business contact details and publicly available information on professional activities. The sources we use are the commercial and company registers, legal notice details and websites of companies, professional networks such as LinkedIn, and the trade and business press.

8.2 Purposes and legal basis

We use this data to assess whether working together makes sense professionally, to identify the right contact person, to prepare our conversations and documents, and to approach you in a business context. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the initiation of business relationships in a B2B environment. We do not process special categories of personal data under Art. 9 GDPR and we do not take automated decisions within the meaning of Art. 22 GDPR.

8.3 Storage period

We store this data for as long as there is a legitimate reason to make contact, and for no longer than 24 months after the last contact. If you object to the processing, we will erase the data without delay; we may then only store your contact details on a suppression list in order to prevent you being approached again.

8.4 Your right to object

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data (Art. 21(1) GDPR). Where the processing is for direct marketing purposes, you may object at any time without giving reasons (Art. 21(2) GDPR); we will then no longer process your data for that purpose. A message to hello@valento.io is sufficient.

9. Audience measurement (TWIPLA)

Where you have consented to the "Analytics" category in the cookie banner, we use TWIPLA (Visitor Analytics) to analyse user behaviour on our website. The provider is TWIPLA GmbH, Friedrichstraße 68, 10117 Berlin, Germany. TWIPLA processes data in compliance with the GDPR within the EU.

The data processed includes the anonymised IP address, pages accessed, time spent on the site and the referrer. This data is not combined with other data. Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time with effect for the future by adjusting your cookie settings via the "Cookie settings" link in the footer.

If you do not give consent, we use TWIPLA exclusively in a cookieless mode: no cookies are set and no personal profiles are created; only aggregated, anonymous statistics (for example page views) are recorded, which do not allow any conclusions to be drawn about you personally. The legal basis for this is Art. 6(1)(f) GDPR, our legitimate interest in anonymous audience measurement in order to improve our offering. As long as you have not made a decision in the cookie banner, TWIPLA is not loaded at all.

Further information: twipla.com/en/privacy-policy

10. Website tracking for company identification (Overloop)

Where you have consented to the "Marketing" category in the cookie banner, we use Overloop to identify companies visiting our website. The provider is Overloop SRL, Rue des Pères Blancs 4, 1040 Brussels, Belgium (VAT no. BE 0645.917.753).

When a page is opened, an invisible frame is loaded which transmits the page address, the page title and your IP address to Overloop. Overloop matches the IP address against a database in order to determine the company behind it. The purpose is to approach potential business customers. Since IP addresses may constitute personal data, this is used solely on the basis of your consent.

In doing so, Overloop stores an identifier in your browser’s local storage under a key beginning with "overloopai_" followed by our customer number. This identifier is used to recognise your browser on subsequent visits. No cookies are set. The entry remains stored until you delete it via your browser settings.

Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent). Section 25 TDDDG covers any storage of information on your terminal equipment, regardless of whether this happens via cookies or via local storage. You can withdraw your consent at any time with effect for the future by adjusting your cookie settings. Without consent, no frame is loaded, no data is transmitted to Overloop and nothing is stored in your browser.

We have instructed Overloop to delete the data collected in this way no later than twelve months after collection. The identifier stored in your browser’s local storage remains in place independently of this until you delete it.

Overloop is established in the EU. However, Overloop uses sub-processors with infrastructure in the United States, so a transfer to third countries cannot be ruled out. Any such transfer takes place on the basis of the EU-US Data Privacy Framework or the European Commission’s standard contractual clauses.

Further information: overloop.com/privacy and overloop.com/gdpr

11. Web fonts (Google Fonts)

This website uses the fonts "Mona Sans" and "Space Grotesk", which are loaded from Google Fonts servers when a page is opened. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. To load the font files, your browser connects to Google’s servers and transmits your IP address and technical browser information. Google states that no cookies are set by the Fonts API and that requests are not linked to a Google account.

The fonts are used on the basis of Art. 6(1)(f) GDPR, our legitimate interest in a consistent presentation of our website. Where data is transferred to the USA, this takes place on the basis of the EU-US Data Privacy Framework, under which Google LLC is certified. If your browser does not support web fonts or blocks the connection, a standard font of your system is used instead.

Further information: developers.google.com/fonts/faq/privacy and policies.google.com/privacy

12. LinkedIn

This website contains a link to our LinkedIn profile. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. If you reach LinkedIn via a link on our website, LinkedIn may collect information about your visit. No LinkedIn code is embedded on our pages; data is only transmitted once you follow the link. We point out that, as the provider of these pages, we have no knowledge of the content of the data transmitted or of how it is used by LinkedIn. Further information: linkedin.com/legal/privacy-policy

13. Cookies and local storage

Our website itself does not set cookies. It stores your decision from the cookie banner in your browser’s local storage under the key "valento_cookie_consent" so that the banner is not shown again. This storage is technically necessary to honour your choice; the legal basis is Art. 6(1)(f) GDPR and Section 25(2) TDDDG.

For the same purpose this website stores three further entries in your browser’s local storage. They are written by the website itself in your browser, are not transmitted to us or to any third party, and are not used to analyse your behaviour. “valentoLang” holds the language you chose with the EN/DE switch, so that the site opens in that language again. “valento-fit-result” holds the five answers you gave in the “Does this fit us?” check together with the date you gave them, so that the check can show you your result again instead of starting from the first question; it deliberately contains neither your name nor your email address. “valento-fit-profile” holds the company context (role, company type, revenue band, size of the product range) if you entered it before starting the check. We do not use your IP address to recognise you. These entries remain in your browser until they are deleted: you can delete them at any time in your browser settings, and the “Start again” button in the check deletes the check entry immediately. The legal basis is Art. 6(1)(f) GDPR and Section 25(2) TDDDG, as the entries are required in order to provide the function you requested.

Where consent has been given, the analysis and marketing services described in sections 9 and 10 may store cookies or local storage entries. The legal basis for these is Art. 6(1)(a) GDPR and Section 25(1) TDDDG (German Digital Services Data Protection Act). You can withdraw or adjust your consent at any time via the "Cookie settings" link in the footer.

By changing the settings in your internet browser, you can deactivate or restrict the transmission of cookies. Cookies and storage entries which have already been saved can be deleted at any time.

14. SSL/TLS encryption

For security reasons, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the padlock symbol in your browser line.

15. Rights of the data subject

You have the right of access (Art. 15 GDPR), to rectification (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR), to data portability (Art. 20 GDPR) and to object (Art. 21 GDPR). You also have the right to withdraw your consent at any time (Art. 7(3) GDPR) and to lodge a complaint with a supervisory authority (Art. 77 GDPR).

Competent supervisory authority: Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg), Lautenschlagerstraße 20, 70173 Stuttgart, Germany.

16. Changes to this privacy policy

We reserve the right to amend this privacy policy so that it always complies with current legal requirements, or in order to reflect changes to our services. The new privacy policy will then apply to your next visit.

17. Questions about data protection

If you have any questions about data protection, please contact: VALENTO GmbH, Kaiser-Joseph-Str. 254, 79098 Freiburg im Breisgau, Germany, hello@valento.io