Privacy Policy
Valerie — AI-Powered Protocol Generation
Last updated: 13 August 2026
1. Who we are
Valerie is provided by Paragonv Ltd, registered with the Registrar of Companies for England and Wales under company number 11497152, with a registered address of Stable Barn, Rudyard, Leek, Staffordshire, England, ST13 8PP.
Paragonv Ltd is registered with the UK Information Commissioner’s Office (ICO) under registration number ZA709590.
For the purposes of UK and EU data protection law, Paragonv Ltd is the data controller for the personal data described in this policy.
Contact for any privacy question: laura@valeriecqv.com
2. What data we collect, and why
a) If you fill in the “Request access” form on our website
We collect: your name, work email address, company/organisation, role, and any message you choose to add.
We use this to respond to your enquiry and follow up about access to Valerie. We do not add you to a marketing list from this form alone, and do not use this data for any purpose beyond responding to your request.
Legal basis: our legitimate interest in responding to enquiries from people who have actively contacted us.
b) If you become a Valerie user
We collect your email address and sign-in details via our authentication provider (Clerk) to create and secure your account.
Legal basis: performance of a contract with you (or steps taken at your request before entering into one).
c) Content you submit for protocol generation (URS text, design documents, requirement text)
When you use Valerie to generate protocols, the text you provide is sent to Anthropic’s Claude API to process your request and generate output. Valerie does not store this content in a database after the response is generated — it exists only for the duration of that request.
Legal basis: performance of a contract with you.
We recommend customers do not paste genuinely confidential or trade-secret information into Valerie beyond what is necessary to generate the protocol requested, in the same way you would exercise judgement with any cloud-based tool.
3. Who we share data with
We use a small number of service providers (data processors) to run Valerie:
| Provider | Purpose | Data involved |
|---|---|---|
| Web3Forms | Delivers "Request access" form submissions to our inbox | Name, email, company, role, message |
| Clerk | Authentication and account management | Email address, sign-in credentials |
| Anthropic | Processes the text you submit to generate protocol content | URS/requirement text you provide |
| Vercel | Hosts the website and application | All traffic to our site/app |
We have a Data Processing Agreement in place with each of the service providers listed above, in accordance with Article 28 of the UK GDPR. Each DPA is incorporated into that provider’s commercial terms, which Paragonv Limited has accepted. We review our processor relationships and associated DPAs at least annually.
Because these providers are based outside the UK/EU, your data may be transferred internationally — see Section 3a below.
3a. International transfers
All four service providers listed in Section 3 are based in the United States, which means that data they process on our behalf is transferred outside the United Kingdom. We ensure appropriate safeguards are in place for each transfer as follows:
| Provider | Transfer mechanism | No training on your content? | DPA reference |
|---|---|---|---|
| Anthropic | EU SCCs (Module 2) + UK IDTA — automatically incorporated into Anthropic's Commercial Terms of Service. Anthropic is also certified under the EU–US Data Privacy Framework. | Yes — Anthropic's Commercial Terms confirm it does not train models on Customer Content submitted via the API. | anthropic.com/legal |
| Vercel | EU SCCs (Module 2) + UK IDTA — incorporated into Vercel's Data Processing Addendum (effective 31 March 2026). | Vercel processes traffic data only; no content training. | vercel.com/legal/dpa |
| Clerk | EU SCCs (Modules 1–3) + UK IDTA — incorporated into Clerk's Data Processing Addendum. | Clerk processes account/authentication data only. | clerk.com/legal/dpa |
| Web3Forms | EU SCCs + UK IDTA — incorporated into Web3Forms's Data Processing Agreement. | Web3Forms stores form submission data only. | web3forms.com/dpa |
In each case, the UK International Data Transfer Addendum (UK IDTA) — approved by the Information Commissioner’s Office and in force since 21 March 2022 — is incorporated into the relevant Data Processing Agreement and constitutes an appropriate safeguard under Article 46 of the UK GDPR.
We do not transfer personal data to any country that does not have a confirmed transfer mechanism in place.
We do not sell personal data, and do not share it with anyone for their own marketing purposes.
4. How long we keep data
- Request access form submissions: Retained by us for as long as reasonably needed to respond to and track the enquiry — typically no longer than 12 months from the date of last contact. Web3Forms retains submission data on its servers for 30 days on our current plan before automatic deletion.
- Account data:Retained for as long as your Valerie account is active. If you request deletion of your account, or if we close your account, personal data held in Clerk is deleted or anonymised within 90 days of account closure, in line with Clerk’s data retention commitments under its Data Processing Addendum.
- Protocol generation content: Paragonv does not store this content after the protocol output has been returned to you. Anthropic, as our processor, retains inputs and outputs on its backend systems for up to 30 days by default, after which they are automatically deleted. Anthropic does not use this content to train its models. If you require zero retention by Anthropic, please contact laura@valeriecqv.com to discuss Enterprise-tier options.
- Website traffic and hosting data:Vercel retains server logs and traffic data in accordance with its own data retention schedule. We do not receive or store this data ourselves. Refer to Vercel’s Privacy Policy for full details.
5. Your rights
Under UK and EU GDPR, you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Request deletion of your data
- Object to or restrict certain processing
- Receive your data in a portable format
- Complain to a supervisory authority — in the UK, the Information Commissioner’s Office (ico.org.uk)
To exercise any of these rights, contact laura@valeriecqv.com
6. Cookies
Cookies are small files placed on your device when you visit a website or use a web application. Valerie uses only strictly necessary cookies — these are required for the service to function and cannot be switched off. We do not set any analytics, advertising, or tracking cookies on your device directly.
6a. Strictly necessary cookies — always active
These cookies are required for Valerie to work. They are typically set in response to actions you take, such as logging in to your account.
| Cookie name | Set by | Purpose | Expires |
|---|---|---|---|
| __clerk_db_jwt / __clerk_db_jwt_k5MfsOKo | Clerk | Authentication token — verifies your identity when you log in. Without this cookie you cannot access your account. | Session / 1 year |
| __client_uat / __client_uat_DvIHvy3E / __client_uat_k5MfsOKo | Clerk | User authentication state — keeps you logged in as you move between pages. Cleared when you log out. | 2027 / Session |
| __session / __session_k5MfsOKo | Clerk | Active session token — manages your current login session and secures API requests made on your behalf. | 2027 |
| __refresh_k5MfsOKo | Clerk | Session refresh token — silently renews your session so you do not have to log in repeatedly. | 2027 |
| clerk_active_context | Clerk | Tracks which Clerk account context is active. | Session |
| dvb_3Hm7... | Clerk | Clerk internal device verification token — used to identify trusted devices during authentication. | 2027 |
| __cf_bm / _cfuvid | Cloudflare (via Clerk) | Bot management — distinguishes human users from automated traffic. Required for security. | Session / 1 hour |
6b. Third-party cookies via Clerk
Some additional cookies may be set on the clerk.com domain by Clerk’s own infrastructure when you authenticate with Valerie. These include analytics and performance cookies used by Clerk for their own platform monitoring and improvement (including cookies associated with Google Analytics, Google Ads, Segment, PostHog, Reddit, and Twitter/X). These cookies are set on Clerk’s own domain — not on valeriecqv.com — and are outside Paragonv’s direct control. Paragonv does not configure, access, or receive data from these cookies. For full details of cookies set by Clerk’s infrastructure, refer to Clerk’s Cookie Policy at clerk.com/legal/cookies.
6c. Managing your cookie preferences
Valerie does not set any non-essential or analytics cookies on your device directly. If you wish to control strictly necessary cookies, you can do so at browser level — see www.aboutcookies.org for guidance. Note that blocking strictly necessary cookies will prevent you from logging in to Valerie.
7. Security
We take reasonable technical and organisational measures to protect your data. These include encryption of data in transit (HTTPS), access controls on our hosting infrastructure (Vercel), and authentication security managed by our login provider (Clerk). We do not store protocol generation content submitted to Valerie.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Children’s data
Valerie is a professional tool intended for use by adults working in regulated industries. It is not directed at, and is not intended for use by, anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that personal data has been submitted by or on behalf of a person under 18, we will delete it promptly. If you have reason to believe this has occurred, please contact laura@valeriecqv.com.
9. Data protection contact
Paragonv Limited has assessed its processing activities and determined that the appointment of a statutory Data Protection Officer is not required under Article 37 of the UK GDPR, as we are not a public authority, we do not carry out large-scale systematic monitoring of individuals, and we do not process special-category or criminal conviction data at large scale.
Any questions about data protection, or requests to exercise your rights under Section 5, should be directed to: laura@valeriecqv.com
Postal address for data protection queries: Paragonv Limited, Stable Barn, Rudyard, Leek, Staffordshire, ST13 8PP.
10. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our services, our processors, or applicable law. The “Last updated” date at the top of this page always reflects the most recent version.
Where we make material changes — for example, adding a new processor, changing how long we keep your data, or changing our legal basis for any processing — we will notify registered Valerie users by email to the address associated with your account, at least 10 days before the change takes effect where practicable.
Continued use of Valerie after a change takes effect constitutes acceptance of the updated policy. The latest version of the privacy policy will be available on the website at all times.
11. Contact
Questions about this policy or your data: laura@valeriecqv.com
Version 1.0 | 13 August 2026 | Paragonv Limited | ICO Reg: ZA709590