Privacy Policy – Validora AI

Last updated: 2026-02-17 | Version: 1.0

1. Who we are

Controller: Laura Otto Solutions
Gijsbrecht van Aemstelstraat 26, 2026 VH Haarlem, The Netherlands
Registration (KvK): 94716501
VAT: NL005104012B61
Website: https://validora-ai.com
Support: lauraottosolutions@gmail.com

2. Eligibility

You must be at least 16 years old to use Validora AI. We do not knowingly collect personal data from individuals under 16.

3. Overview

Validora AI is a SaaS web application that provides AI-powered market research insights. We process personal data to operate the service, process payments, and improve our product. We do not use your content (e.g., business ideas, prompts) to train AI models.

4. What personal data we process

4.1 Account and authentication

Email address, password (hashed; we never store plain text), account creation date, subscription status. Retention: Duration of account plus 1 year after closure.

4.2 Service usage and content

Content you submit (business ideas, prompts) to generate insights; usage counts. This content is sent to our AI provider (OpenAI) for processing. OpenAI does not use it to train models (API default). Retention: Content is processed in real time; we do not store prompt content long-term.

4.3 Subscription, billing and administration

Name, email, invoicing details (via Stripe), payment status, subscription plan. Retention: 7 years (Dutch statutory).

4.4 Support and communications

Support request content, contact details, attachments. Retention: 2 years tickets; 90 days attachments.

4.5 Website usage and cookies

Strictly necessary cookies: session, security. Consent typically not required.
Analytics cookies: Google Analytics. Where required by law (e.g. EEA), we obtain your consent before activating analytics. You can manage or withdraw consent via our cookie banner or browser settings.
Marketing cookies: We do not use these.

5. Legal bases

Performance of contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f)); Consent (Art. 6(1)(a)) for analytics.

6. Sharing with third parties

OpenAI (AI processing), Stripe (payments), Railway (hosting, Amsterdam-West, EEA), BrightData (web scraping for competitor analysis), Google Analytics (with consent). We enter data processing agreements with these providers.

7. International transfers

User content is sent to OpenAI (US); DPA and SCCs apply. Google Analytics (US) processes data with consent. We implement appropriate safeguards where required.

8. Your rights

Under the GDPR you have rights to access, rectification, erasure, restriction, objection and data portability. Submit requests via lauraottosolutions@gmail.com.

9. Complaints

You may lodge a complaint with your supervisory authority (e.g., Autoriteit Persoonsgegevens in the Netherlands).

10. Right of withdrawal (paid subscriptions)

If you purchase a paid subscription, you have a 14-day right to withdraw without reason. By requesting immediate access to digital content (e.g., premium features after payment), you consent to performance starting before the withdrawal period ends and acknowledge that you will lose your right to withdraw once you have started using the premium content. If you do not use the premium features within 14 days, you may still withdraw and receive a full refund. See our Terms of Sale for details.

← Back to Validora