Data Protection Overview

Valority Technologies Ltd.

Document version 2.0 | Update date: January 2026

We at Valority Technologies Ltd. ("Company," "Valority," "our" or "we") believe in the importance of complying with applicable data protection regulations ("Data Protection Regulations").

Data Protection Regulations set out rules and standards for the use and handling of personal data belonging to identifiable individuals (i.e., "data subjects" or "consumers") ("Personal Data") by organizations. The laws apply to all sectors, both public and private, and to electronic and many paper records.

The EU General Data Protection Regulation ("GDPR") set out a worldwide standard for processing Personal Data. The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act ("CCPA/CPRA"), provides California residents with additional privacy rights. At Valority, we aim to provide our services ("Services") in compliance with all applicable Data Protection Regulations, including, as applicable and without limitation, the GDPR, UK GDPR, and CCPA/CPRA.

For this purpose, we have appointed a data protection officer ("DPO") to help ensure compliance with applicable Data Protection Regulations. We further pay close attention (with the assistance of our legal counsel) to regulatory guidance and make changes as necessary to maintain our compliance.

Please be advised that this overview is not legal advice for your company to use in order to comply with applicable Data Protection Regulations. It provides background information to help you better understand how we, at Valority, have addressed important legal points with respect to data privacy.

What has Valority done to comply with applicable Data Protection Regulations?

  • We appointed a DPO.
  • We continuously review our security measures to ensure any personal data we collect and process is adequately protected.
  • We maintain a Privacy Notice and a CCPA Privacy Notice, both prominently displayed on our website, which explain our commitment to the GDPR and CCPA/CPRA, are transparent about how we use Personal Data, and tell individuals how to exercise their rights.
  • We execute with our customers, vendors, service providers and partners Data Processing Agreements ("DPAs") which incorporate, where required, Standard Contractual Clauses ("SCCs").
  • We continuously update our contracts with third-party vendors to ensure they comply with applicable Data Protection Regulations.
  • We maintain a formal process allowing individuals to exercise their rights and allowing the Company to fulfill those requests.
  • We implement and maintain security procedures and technical safeguards as further explained in our Security Policy.

What Personal Data will Valority collect in connection with your engagement with us?

We may collect the Personal Data of your personnel and Authorized Users, including their names, work email addresses, and access authorizations to the Services (i.e., username and password). We use this information to: (i) provide the Services; (ii) administer your account and transactions; (iii) identify users you authorize to access the Services; (iv) resolve disputes and support issues; and (v) respond to your questions and comments.

What Personal Data is Processed through Luke (our Services)?

Luke is a cloud-based AI decision engine for marketing and growth teams. The Customer connects its enterprise and marketing systems (for example: CRM, advertising platforms, web and product analytics, data warehouses, and marketing platforms), and Luke ingests and analyzes that data to produce insights, forecasts, and recommended actions ("Output").

With respect to data processed on the Customer's behalf, the Customer is the Controller and Valority is the Processor, processing such data solely on the Customer's instructions and the applicable DPA. Processing takes place in Valority's cloud environment, hosted with reputable cloud service providers. The data Luke processes on the Customer's behalf consists primarily of aggregated and metric marketing and performance data. To the extent Personal Data is present, it is limited to Customer personnel contact details and online or customer identifiers contained in the connected systems. Luke does not process audio or video recordings or Special Categories of Personal Data.

The following is a high-level flow of Luke's processing activities:

  1. The Customer connects authorized data sources or uploads data to the Services.
  2. Luke's semantic layer maps the connected data to the Customer's business concepts, KPIs, and domain knowledge.
  3. Luke executes governed, multi-step analytical workflows to diagnose drivers, detect patterns, and test hypotheses.
  4. Luke generates insights, forecasts, and recommended actions (Output), with explanations.
  5. Output is presented to the Customer's Authorized Users for human review and decision. Luke is an auxiliary, decision-support system and does not autonomously execute business decisions on the Customer's behalf.

We may access Personal Data processed through the Services where necessary to provide the Customer with support. We do not monitor the data the Customer uploads to or connects with the Services; it is the Customer's responsibility to ensure that any sensitive or special-category data is shared in compliance with applicable Data Protection Law.

AI and model usage

Valority does not use Customer Data or Customer Content processed through the Services to train, fine-tune, or improve general-purpose artificial intelligence or machine learning models, except where explicitly agreed in writing by the Customer or where required to provide the Services (e.g., model evaluation, security, or compliance). Luke's self-learning operates on the Customer's own domain knowledge and accumulated organizational context to improve Output for that Customer. Valority may also develop, retain, and use generalized knowledge, know-how, methodologies, analytical and recommendation templates, problem-to-solution patterns, guardrails, roles, and configurations derived from providing and improving the Services ("Service Learnings"), and may apply Service Learnings across its customers and to improve the Services, provided that Service Learnings do not incorporate, contain, reveal, or enable the identification of any Customer Data, Customer Content, or Customer Confidential Information, and do not identify any customer or individual. Valority may also use aggregated and de-identified data, which does not identify any individual, to operate, secure, and improve the Services.

Additional information regarding our compliance

Technical, organizational and security standards. The Company has conducted data mapping and implemented internal technical and organizational measures to safeguard against unauthorized access to Personal Data and to respond to security incidents. More information is in our Security Policy.

Employee training. We provide annual employee training and maintain an employee security policy guiding how employees access and manage Personal Data securely. Employees with access to Personal Data are subject to confidentiality obligations and a screening process applicable per regional law.

Retention. We retain Personal Data for as long as necessary to provide the Services or as required under applicable law, and in any event no longer than twelve (12) months following termination, unless required by law. Customer Data is deleted or returned on termination in accordance with the DPA.

Continuity plan. We maintain an internal disaster recovery and business continuity policy to enable us to continue providing the Services and to guide our response in the event of a security incident.

User rights. Data Protection Regulations provide individuals with various rights regarding their Personal Data depending on jurisdiction, which may include (without limitation) the rights to access, rectify, erase, restrict, object, port, and opt out, all as further explained in our Privacy Notice and CCPA Notice. A data subject can contact our DPO at privacy@valority.ai or complete our Data Subject Action Request form (Appendix A) and send it to privacy@valority.ai.

Transferring of Personal Data. Valority is established in Israel, which benefits from a European Commission adequacy decision for transfers of Personal Data from the EEA. Where Personal Data is transferred to a country that is not subject to an adequacy decision, Valority relies on approved transfer mechanisms such as the EU Standard Contractual Clauses (2021/914), the UK International Data Transfer Addendum, and the Swiss addendum, with supplementary measures where required. Valority signs DPAs incorporating these mechanisms with its customers, vendors, service providers, and partners as necessary.

Appendix A – Data Subject Action Request

To submit a request to exercise individual rights under the Data Protection Laws, please complete this form and send it to our privacy team at: privacy@valority.ai. Upon receipt, we will process it and respond within the timelines required under applicable Data Protection Laws.

For the purpose of this form, "Data Protection Laws" means any applicable data, privacy and security regulations that apply in your jurisdiction, including, without limitation and solely where applicable, the GDPR, UK GDPR, and CCPA/CPRA.

Please provide accurate information so we can contact you:

Full Name:
Email Address:
Phone Number (optional):

Are you the Data Subject?

☐ I am the Data Subject requesting action.

☐ I am not the Data Subject; I am acting on behalf of the Data Subject and enclose written authority.

What is your relationship with us?

☐ Customer    ☐ Service provider    ☐ Employee    ☐ Visitor of our website    ☐ Other

Please check the applicable right(s):

☐ Right to access

☐ Right to rectification

☐ Right to erasure

☐ Right to restrict processing

☐ Right to be informed of why and how we process your information

☐ Right to data portability

☐ Right to receive a copy

☐ Right to object

☐ Right not to be subject to decisions based solely on automated decision-making

☐ Right to opt-out

☐ Do not sell or share my personal information

Substantiate the request — please provide additional detail (relevant dates, references, etc.):

The personal data required by this form is necessary to enable Valority Technologies Ltd. and its affiliated companies ("Company") to process your request and is subject to our Privacy Policy. The information will be used only to identify the personal data you are requesting and to respond to your request. If additional information is needed to verify your identity, we will contact you. Any identification documents should be sent through secure means and as photocopies or scanned images (do not send originals).

Please note that if the requested information reveals details about another person, we will seek that person's consent before disclosure. Where disclosure would adversely affect the rights and freedoms of others, we may be unable to disclose it, in which case you will be informed with reasons. Information covered by legal privilege cannot be disclosed.

What happens next? If your request is valid, we will acknowledge it in writing, provide a reference number, and begin processing. If we cannot identify you, we will request additional information. In most circumstances we provide the requested information free of charge, but may charge a reasonable fee where a request is repetitive, manifestly unfounded, or excessive, or for further copies of the same information.

Document version 2.0 | Update date: January 2026