Skip to content
  • How it works
  • Security
  • About
Book a demo
Menu+
  • How it works
  • Security
  • About
Book a demo

Privacy Policy

Last updated: 2025-12-09

Privacy at a glance

  • EU company, GDPR applies. Valigent AB is based in the EU and processes personal data in line with the GDPR.

  • What we collect. We collect basic business contact details (e.g. name, email, company) and usage logs when you use the Valigent platform.

  • Why we collect it. We use this data to provide and secure the service, support you, understand how the platform is used and improve it over time.

  • Your inventions and data. Customer content (including inventions) is handled as confidential Customer Data. We process it only to provide the service, and do not treat it as public disclosure.

  • Infrastructure and AI providers. We use Google Cloud and Supabase for hosting and OpenAI for AI features, under contracts that prohibit training on your data and require appropriate security.

  • No selling of personal data. We do not sell personal data or use your platform usage for unrelated third-party advertising.

  • Limited retention. Technical logs are typically kept for 30 days, and other data only as long as needed for service, legal or security reasons.

  • International transfers. When data is accessed from outside the EU/EEA (e.g. by US-based providers), we use EU Standard Contractual Clauses and other safeguards.

  • Your rights. You can contact us at privacy@valigent.io to access, correct or delete your personal data, object to certain processing, or exercise other GDPR rights.

For details, please see our full Privacy Policy.

This Privacy Policy explains how Valigent AB (“Valigent”, “we”, “us” or “our”) processes personal data in connection with:

  • the Valigent SaaS platform (“Valigent Platform” or the “Service”),
  • our websites, and
  • our business contacts and customer relationships.

This Privacy Policy applies primarily to representatives and users of our business customers, prospective customers and partners. We do not offer our services to consumers.

Valigent AB is established in the European Union, and we process personal data in accordance with the EU General Data Protection Regulation (“GDPR”).

1. Data controller and contact details

For the processing activities described in this Privacy Policy, Valigent AB is the data controller.

  • Company: Valigent AB
  • Registered address: Tvistevägen 47 A, 907 29, Umeå, Sweden
  • Organisation number: 559480-1143
  • Email for privacy matters: privacy@valigent.io

We have not appointed a formal Data Protection Officer, but you can contact us at the email above with any questions or requests related to privacy or data protection.

2. Roles: controller vs. processor

We act in different roles under data protection law:

  • For account and contact data, usage data, communications and website analytics, we generally act as data controller. This Privacy Policy covers that processing.
  • For personal data contained in Customer Data uploaded to or generated within the Valigent Platform by or on behalf of a customer, we typically act as data processor, and the customer is the data controller.
    • That processing is governed by a Data Processing Agreement (DPA) between Valigent and the customer.
    • In case of conflict between this Privacy Policy and the DPA regarding such processing, the DPA prevails.

3. Categories of personal data we process

We process the following categories of personal data, depending on how you interact with us.

3.1 Account and contact data (B2B SaaS)

For users and contacts at our B2B customers, prospects and partners:

  • Name
  • Business email address
  • Employer / company name
  • Job title / role
  • Business contact details (e.g. phone number, office address, if provided)
  • User account identifiers (username, internal IDs)

3.2 Platform usage and log data

When you use the Valigent Platform, we collect:

  • Login information (timestamps, IP address, approximate location based on IP)
  • Technical information (device type, browser, operating system)
  • Usage data (pages/screens viewed, features used, clicks, actions performed, error events and similar logs)

Logs are typically stored for 30 days and then deleted or overwritten automatically, unless we need to retain specific data longer for security or legal reasons (see Section 8).

3.3 Communication data

When you communicate with us, we process:

  • Emails and other messages you send us (e.g. support requests, feedback, meetings)
  • Information you provide in meetings, demos or calls that is linked to you as a contact person (e.g. notes in our CRM)

3.4 Customer Data in the Valigent Platform

Our customers use the Valigent Platform to upload and process content (for example invention descriptions or related documents), which may occasionally contain personal data. In relation to such personal data:

  • The customer is typically the data controller.
  • Valigent acts as data processor, processing the personal data only on documented instructions from the customer, as set out in the DPA.

3.5 Website and cookies

When you visit our website(s), we may process:

  • IP address and general location (city/region level, where available)
  • Device and browser information
  • Date, time and duration of visit
  • Pages visited, navigation paths and interactions
  • Referring site or campaign (if applicable)

We may use cookies or similar technologies for essential functions and, where allowed, for analytics. More detail can be provided in a separate cookie notice or banner.

4. Purposes and legal bases for processing

We only process personal data where we have a legal basis under GDPR. Below we explain our purposes and the associated legal bases.

4.1 Providing and administering the Valigent Platform

Purpose:

  • Create and manage user accounts.
  • Authenticate users and provide access to the Valigent Platform (including trial access).
  • Operate core functionality of the Service.

Personal data:

  • Account and contact data, platform usage data.

Legal basis:

  • Performance of a contract (Art. 6(1)(b) GDPR) where we provide the Service to the customer and you are a user designated by that customer; and
  • Our legitimate interest (Art. 6(1)(f) GDPR) in operating and managing a B2B SaaS platform.

4.2 Customer support and communication

Purpose:

  • Respond to enquiries and support requests.
  • Provide onboarding and training where agreed.
  • Send important information about the Service (e.g. security notices, changes to terms).

Personal data:

  • Account and contact data, communication data, relevant usage data.

Legal basis:

  • Performance of a contract (Art. 6(1)(b) GDPR); and
  • Legitimate interest (Art. 6(1)(f) GDPR) in providing support and maintaining customer relationships.

4.3 Monitoring, maintenance and improvement of the Service

Purpose:

  • Monitor usage to detect, investigate and fix technical issues and errors.
  • Ensure stability, performance and security of the Valigent Platform.
  • Understand how features are used to improve and develop the Service.

Personal data:

  • Platform usage data, log data, limited account data where needed to relate issues to users.

Legal basis:

  • Legitimate interest (Art. 6(1)(f) GDPR) in running a secure, reliable service and improving our product.

We do not use platform usage data to build personal profiles for unrelated third-party advertising.

4.4 Business development, sales and marketing (B2B)

Purpose:

  • Maintain a customer and prospect database (CRM).
  • Follow up on demos, pilots and trials.
  • Send relevant information about our services to business contacts.

Personal data:

  • Account and contact data, communication data, limited usage information (e.g. whether a trial is active).

Legal basis:

  • Legitimate interest (Art. 6(1)(f) GDPR) in growing and managing our B2B business and relationships.
  • Where required by local marketing laws, we may rely on consent or applicable “soft opt-in” rules for email marketing, and we always provide an unsubscribe option.

4.5 Compliance and protection of rights

Purpose:

  • Fulfil legal obligations (e.g. accounting and tax requirements).
  • Handle complaints, disputes and legal claims.
  • Prevent and investigate misuse, fraud and security incidents.

Personal data:

  • Any of the categories above as necessary for the particular case.

Legal basis:

  • Legal obligation (Art. 6(1)(c) GDPR), where applicable; and
  • Legitimate interest (Art. 6(1)(f) GDPR) in protecting our rights, our customers, and the Service.

5. Use of AI and third-party providers

We use third-party providers to host and operate the Valigent Platform and to provide certain features, including AI/large language model (LLM) functionality.

We currently rely on providers such as:

  • Google Cloud Platform and Supabase for hosting, storage, databases and related infrastructure;
  • OpenAI for LLM-based functionality within the Valigent Platform.

This list may change over time.

These providers process personal data only as processors on our behalf, under written data processing agreements. We ensure that such providers:

  • may not use Customer Data to train general AI models,
  • may not claim ownership in Customer Data, and
  • are subject to appropriate confidentiality and security obligations.

AI-generated content and suggestions in the Valigent Platform are based on statistical models and may be inaccurate or incomplete. They are tools to support your work and do not replace your own assessment.

6. Sharing of personal data

We do not sell personal data. We may share personal data with:

  • Hosting and infrastructure providers, such as Google Cloud and Supabase, for secure hosting, databases and storage.
  • AI / LLM providers, such as OpenAI, to the extent necessary to provide AI-based functionality in the Service.
  • Analytics and monitoring providers, to understand performance, reliability and usage patterns.
  • Communication and support tools, e.g. email services, ticketing systems or collaboration tools.
  • Professional advisers, such as lawyers and accountants, where necessary.
  • Authorities or third parties, where required by law or to establish, exercise or defend legal claims.

In all such cases, we share only what is necessary for the relevant purpose and, where the recipient acts as our processor, we remain responsible for their processing and impose contractual safeguards.

7. International transfers

Some of our service providers are based in, or may access personal data from, countries outside the EU/EEA, including the United States. For example, Google Cloud, Supabase and OpenAI are headquartered in the US, even where EU/EEA data centres are used.

Where personal data is transferred to countries without an adequacy decision from the European Commission, we ensure an adequate level of protection by:

  • entering into Standard Contractual Clauses (SCCs) adopted by the European Commission with the relevant providers (and, where applicable, their sub-processors), and
  • taking additional appropriate safeguards where required (such as technical and organisational measures).

You can contact us for more information about international transfers and the safeguards used.

8. Data retention

We retain personal data only for as long as necessary for the purposes for which we collected it, and to comply with legal, accounting or reporting obligations.

In general:

  • Account and contact data: kept for the duration of the customer relationship and for a reasonable period thereafter (typically up to 3 years) for record-keeping, legal and accounting purposes, unless a longer retention period is required or justified.
  • Platform usage and log data: logs are typically kept for 30 days and then automatically deleted or overwritten, unless we need to retain specific logs for longer in connection with security incidents, investigations or legal claims.
  • Communication data (support, email): kept as long as necessary to handle the enquiry and for an additional period where needed for documentation and legal protection (typically up to 3 years, unless a longer period is required by law).
  • Customer Data where we act as processor: retained in accordance with the DPA and the customer’s instructions (for example, deletion or return after the end of the contract, subject to limited technical backup retention).

When personal data is no longer needed, we will delete it or anonymise it in a secure manner.

9. Data security

We take data security seriously and implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration. These measures include, as appropriate:

  • use of reputable hosting and infrastructure providers such as Google Cloud and Supabase,
  • access controls and role-based access for our staff,
  • encryption of data in transit and at rest (where applicable),
  • logging and monitoring of system activity,
  • regular backups and recovery procedures,
  • internal policies and training regarding information security and confidentiality.

While we work to protect personal data, no system can be completely secure. If we become aware of a personal data breach that affects you, we will inform you and the relevant authorities in accordance with applicable law.

10. Your rights under GDPR

If you are in the EU/EEA (or where GDPR applies), you have the following rights in relation to your personal data processed by us as controller:

  • Right of access: to obtain confirmation whether we process your personal data and to receive a copy.
  • Right to rectification: to correct inaccurate or incomplete personal data.
  • Right to erasure: to request deletion of your personal data in certain situations, for example where the data is no longer necessary, or you withdraw consent (where consent was the basis).
  • Right to restriction of processing: to request that we restrict processing in certain circumstances.
  • Right to data portability: to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller, where processing is based on contract or consent and carried out by automated means.
  • Right to object:
    • to processing based on our legitimate interests, on grounds relating to your particular situation; and
    • at any time to processing for direct marketing purposes.
  • Right to withdraw consent: where processing is based on your consent, you may withdraw that consent at any time (without affecting the lawfulness of processing based on consent before its withdrawal).

Some of these rights are subject to conditions and exceptions under GDPR. For example, we may need to keep certain information to comply with legal obligations or to defend legal claims.

To exercise your rights, please contact us at privacy@valigent.io. We may need to verify your identity before responding to your request.

If you are located outside the EU/EEA, you may have similar rights under your local laws. We will respect those rights where applicable.

11. Complaints

If you have concerns about how we process your personal data, we encourage you to contact us first so we can try to resolve the issue.

You also have the right to lodge a complaint with a supervisory authority. Our main supervisory authority is:

  • Integritetsskyddsmyndigheten (IMY) – the Swedish Authority for Privacy Protection Website: https://www.imy.se

You can also contact your local supervisory authority in the EU/EEA.

12. Children

Our Service and websites are directed to businesses and adult professionals. We do not knowingly target or collect personal data from children.

If you believe we have collected personal data about a child without valid legal basis, please contact us and we will delete such information.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example to reflect changes in our processing activities, the Service or applicable laws.

We will publish the updated Privacy Policy on our website and indicate the date of the latest update at the top. If we make material changes, we may also inform you by email or via the Valigent Platform.

14. Contact

If you have any questions about this Privacy Policy or our processing of personal data, or if you wish to exercise your rights, please contact us at:

  • Email: privacy@valigent.io
  • Postal address: Valigent AB, ℅ Uminova Innovation, Tvistevägen 47 A, 907 29, Umeå, Sweden

Never miss an idea again

  • How it works
  • Security
  • About
  • Book a demo
  • Privacy
  • Terms

© 2026 Valigent