Valtoroq policies

Data Protection Policy

Valtoroq applies technical and organizational measures intended to protect personal and operational information processed through the service.

Last updated: 30 September 2026

Service operator

Valoroq LLC operates the Valtoroq product and service. Our business address is 1621 Central Ave, Suite #8773, Cheyenne, WY 82001, United States.

Protection principles

We aim to process personal data lawfully, fairly and transparently; collect data for defined purposes; limit collection and retention; keep information accurate where practical; and protect information against unauthorized access, loss, misuse or disclosure.

Access control and authentication

Valtoroq uses authenticated accounts, role-based permissions, organization membership controls and support for two-factor authentication. Access is intended to be limited to users and administrators with an operational need.

Tenant and workspace separation

Workspace and organization controls are used to separate customer data. Application authorization and database-level controls are designed to prevent users from accessing records outside their authorized workspace.

Transport, secrets and credentials

Production deployments are expected to use encrypted network transport. Credentials and application secrets are kept outside public source content and are managed through environment or infrastructure controls. Passwords are handled through the platform authentication system rather than stored as readable application data.

Logging and audit records

Operational and security activity may be recorded to support accountability, troubleshooting, abuse prevention and incident investigation. Access to logs is restricted according to operational responsibilities.

Backups and recovery

Production infrastructure should use managed backup and recovery controls appropriate to the deployed service tier. Backup access and retention are limited according to operational and security requirements.

Incident response

Suspected security and personal-data incidents are assessed, contained and investigated. Where applicable law requires notification to regulators or affected individuals, notifications will be made within the legally required timeframe.

Processors and subprocessors

Infrastructure and service providers are selected for operational need and are expected to maintain appropriate safeguards. Valtoroq evaluates providers and applicable transfer or processing terms before relying on them for production personal data.

Retention and deletion

Data is retained only for legitimate service, contractual, security and legal purposes. Account closure, customer instructions, contractual terms and legal requirements may affect the time required to delete or anonymize specific records.

Data-subject requests

Requests relating to access, correction, deletion, restriction, portability, objection or consent withdrawal can be submitted through the Contact page or to [email protected]. Identity may need to be verified before a request is fulfilled.

Customer responsibilities

Customers remain responsible for configuring access appropriately, managing their users, determining the customer content entered into Valtoroq, and meeting legal obligations that apply to their own processing activities.