Valata Index

Privacy Policy

Last updated 29 September 2026

The short version

1. Who we are, and which of us is responsible

This policy is issued by Lyve Wyre Group Limited (company number 13966596), registered in England and Wales at 17 Ringshall, Berkhamsted, Hertfordshire, HP4 1ND. Contact us about anything in this policy at info@valata-index.com.

Our role depends on which data it is, and the split is deliberate:

DataWho decides why it is heldOur role
Your name, email, password and sign-in historyWe do — it is our account system and our security modelController
Which reports we email you, and our delivery recordsWe doController
Your organisation’s members, their roles and its invitationsYour organisationProcessor
What your organisation exports, and how it then uses itYour organisationProcessor
The market data itselfUs — but it is not personal data, so no role arises—

Where we act as a processor, we do so under a data processing agreement with your organisation, and everyone holding a seat under that organisation is covered by it. Where we act as a controller, this policy is the basis on which we hold your data, and you can exercise every right in section 9 directly against us.

2. What this policy covers

ProductWhat it isAccount?
Valata Index (app.valata-index.com)The licensed B2B web applicationYes — named users within an organisation
Valata Index (iOS app)The free public preview, games market onlyNo — no sign-in, no account

There is one product. A vertical — music, games, film, books — is a licence your organisation holds, not a separate application.

3. The data we publish is about works and companies, not people

The index values games, music releases, films and books — information about creative works and the companies behind them, drawn from public sources. Valuations, tiers, activity scores and history are not personal data and are not covered by the rest of this policy.

Where a work is associated with a named individual — a recording artist, an author — we hold only what is published about the work: its title, category, and publicly reported measures of attention. We do not build profiles of those individuals, and they are not our customers or our users.

4. What the web application collects

Account and organisation

WhatWhy we need itLawful basis
Email addressTo create and secure your account, sign you in, reset your passwordContract
PasswordTo sign you in. Stored only as a salted hash — we never see itContract
Your nameTo identify you to colleagues in your organisation and on audit recordsContract
Organisation and your role in it (owner, admin or member)To decide what you can see and changeContract
The licences held by your organisationTo decide which markets and what depth of history you can accessContract

Usage

WhatWhy we need itLawful basis
A record of each API call made with your organisation’s key — time, vertical, and which keyTo enforce the per-day call limits your licence tier sets, and to bill accuratelyContract; legitimate interests (billing integrity, abuse prevention)
Exports you generate (what was exported, when, by whom)To provide the export, and to answer questions about who took what dataContract; legitimate interests (security)
Weekly report records and whether they were emailedTo send the report and avoid sending it twiceContract

If you ask for access before you have an account

WhatWhyLawful basis
The email address and details you type into the request-access formOnly to respond to your requestLegitimate interests (responding to an enquiry you initiated)
An invitation you are sent by an organisation ownerTo let you join that organisationContract

What we do not collect

We do not collect or process, in either product: your location; your contacts, photos, calendar, microphone or camera; any advertising identifier; or any special-category data. We do not track you across other apps or websites, and we do not sell personal data to anyone.

5. Emails we send you

If your organisation holds a licence, we email a weekly market report every Monday to the members of your team, with the full report attached as a PDF. This is part of the service your organisation is paying for.

Each email carries an unsubscribe link, and you can turn these off in your profile without affecting your access to the application.

6. The free mobile preview

The iOS preview app shows the games market only. It has no account, no sign-in, and collects nothing about you. It reads market data through a shared, scoped key that is the same for every install and is not linked to you or your device.

Apple may collect information about your download and use of the app under its own privacy policy, which we do not control.

7. Who processes data on our behalf

ProcessorWhat they handleWhere
SupabaseDatabase, sign-in, file storage and server functions — everything in your accountEU
CloudflareDNS and traffic in front of our servicesGlobal network
ResendSending your weekly report, including your email address and the attached PDFEU / US
AppleDistributing the preview app through the App StoreGlobal

Each acts as our processor under contract and may only use your data to provide their service to us. Where a processor is outside the UK or the EEA, the transfer is made under the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, which is the safeguard UK GDPR Article 46 requires.

8. How long we keep things

We keep personal data about a named user for twelve (12) months after their last activity, and then we delete it in full.

The twelve months runs from the last time that person signed in or used the service. When it expires we delete their user record, their sign-in history, their usage and export records, and the record of the reports we sent them. If a person leaves the organisation, or the organisation’s licence ends, the same twelve months runs from that point.

If you ask us to delete sooner, we will remove your personal records within 30 days. An organisation’s administrator can also remove a member at any time, which starts the same clock immediately.

Usage and billing records

API usage is metered, and that record is also what sits behind an organisation’s invoices. It records which key made a call, not which person — there is no individual attached to it — so it is an accounting record of your organisation rather than personal data about you.

WhatHow long
Your personal account and sign-in records12 months after your last activity, then deleted
The per-call usage and billing record, which identifies the key and the organisation but no individual72 months, so the accounting record survives for its statutory period

The free mobile preview is unaffected by all of this: it has no account and we hold nothing about the people who use it.

9. Your rights

Under UK GDPR you can ask us to: give you a copy of your personal data; correct it; delete it; restrict or object to how we use it; or send it to another provider. You can withdraw consent where we rely on it, and complain to the Information Commissioner’s Office.

Ask us at info@valata-index.com. We will respond within one month. Where we act as a processor (section 1), we will pass your request to your organisation and help them answer it, because the decisions about that data are theirs.

10. Changes to this policy

We will update this page when what we do changes, and change the date at the top. Where a change materially affects how we use your personal data, we will tell you by email before it takes effect.

11. Contact

Lyve Wyre Group Limited
17 Ringshall
Berkhamsted
Hertfordshire HP4 1ND
England
info@valata-index.com