1. Data Controller & Processor Roles
Under GDPR Article 28, Valorenode LDA (NIPC registered in Portugal) acts as a Data Processor on behalf of Customer organizations (Data Controllers). Our autonomous AI engine processes review data exclusively within the instructions documented in this DPA and the applicable Master Service Agreement.
2. Portuguese Registry Framework
Valorenode is registered with the Comissão Nacional de Proteção de Dados (CNPD), Portugal's supervisory authority under GDPR. Our EU establishment ensures that all primary data processing occurs within the European Economic Area, with subprocessors limited to those providing adequate safeguards under Article 46 transfer mechanisms.
- Primary data residency: EU-West (Frankfurt) with Portuguese legal entity
- DPO contact: dpo@valorenode.com
- CNPD registration reference available upon request under NDA
3. Processing Purposes & Legal Basis
We process personal data solely for: (a) review ingestion and normalization, (b) AI-assisted response drafting, (c) analytics and reporting, and (d) compliance audit logging. Legal bases include legitimate interest (Art. 6(1)(f)) for B2B review management and contractual necessity (Art. 6(1)(b)) for platform delivery.
4. Data Subject Rights
Valorenode provides tooling for Controllers to fulfill data subject requests including access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), and portability (Art. 20). Our platform supports automated erasure cascades that purge review records, AI conversation history, and associated audit metadata within 30 days of a verified request.
5. Subprocessor Governance
All subprocessors are listed in our Subprocessor Registry (/legal/subprocessor-list). Customers receive 30-day advance notice of subprocessor changes. Current primary subprocessors include Supabase (EU-hosted database), OpenAI (sandboxed API gateway with store:false), Resend (transactional email), and Stripe (billing ledger).