Privacy Policy
Zimbs Valetex Advisory is committed to protecting the privacy of your financial and personal data. This Privacy Policy outlines our data handling practices for our valuation platform and corporate website.
Data Collection
We collect information you provide directly to us when creating an account, including identifying information and sensitive financial data such as capitalization tables, company financials, and personnel equity grants. We also collect usage data, device information, and log data automatically when you interact with our platform.
Data Usage
The sensitive financial data uploaded to our platform is used strictly and exclusively for generating your valuation reports, OPM allocation run-throughs, and compliance documents. We do not sell your cap table data to third parties, nor do we train public AI models on your private financial statistics.
Third-Party Processing
We may utilize secure, SOC-2 compliant third parties (like AWS for hosting) to process your data, but these parties are bound by strict confidentiality and data processing agreements (DPAs). We carefully vet all sub-processors and maintain an up-to-date list available upon request.
Data Security
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. We implement strict tenant isolation, role-based access controls, and maintain complete immutable audit trails. Our infrastructure undergoes regular penetration testing and security audits by independent third parties.
Data Retention & Deletion
We retain your data for the duration of your active subscription and for a reasonable period thereafter for legal and compliance purposes. Upon written request, we will permanently delete all your financial data from our systems within 30 business days, subject to applicable legal retention requirements.
Cookies & Analytics
We use essential cookies to maintain session state and platform functionality. We may use privacy-respecting analytics to understand platform usage patterns. We do not use third-party advertising trackers. You may configure your browser to reject non-essential cookies at any time.
Your Rights
You have the right to access, correct, export, or delete your personal data at any time. For enterprise accounts, data access requests should be directed through your designated account administrator. We respond to all verified data subject requests within 30 days.