Privacy

Privacy notice

What personal data ValoraHR holds, who is responsible for it, and what happens to it — in plain language.

Who is responsible

ValoraHR is an HR system provided by Techvora. When an organisation uses ValoraHR to manage its employees, candidates and contractors, that organisation is the data controller: it decides what is recorded and why. Techvora acts as its processor, holding and processing the data on the organisation's instructions to provide the service.

Techvora is the controller for the small amount of data it uses to run its own business: demo requests made on this site, and the account and subscription details it needs to provide and bill for the service.

If you work for a company that uses ValoraHR

Your employer decides what information is held about you and how long it is kept. For questions, corrections or requests about your records, contact your employer's HR team first. You can update some of your own details and download a copy of your own data yourself from your profile in ValoraHR.

What is held

Accounts: your name, email address, a bcrypt hash of your password, whether two-factor authentication is on, and your active sessions with the device's browser description. IP addresses are stored only as keyed pseudonyms, not as addresses.

HR records, as your organisation chooses to use them: work and employment details, personal and emergency contact information, leave, documents, training, reviews, goals, onboarding and offboarding tasks, and recruitment and interview records.

Demo requests: the name, work email, company, company size and message you send us.

Audit trail: who changed what and when. It names the fields that changed, never their values.

Cookies

ValoraHR uses only the cookies it needs to work: one that keeps you signed in, one that remembers which organisation you last opened, and short-lived ones during sign-in and two-factor set-up. There are no advertising or analytics cookies.

Where it is stored, and who else is involved

Data is stored in the European Union (AWS eu-west-1, Ireland). Techvora uses these subprocessors to provide ValoraHR:

  • Supabase — managed PostgreSQL database and private file storage, EU region.
  • Vercel — application hosting, served from its Dublin region.
  • Postmark — delivery of transactional email such as password resets and invitations, only where email sending is configured.

Techvora does not sell or rent personal data, and does not use HR records for advertising or to train models.

How long it is kept

HR records are kept for as long as the organisation keeps them. Organisations can set retention periods in ValoraHR: for the audit trail, for leavers' personal information, and for candidates, whose details are anonymised automatically once the retention period after their last application has passed, unless they agreed to be kept on file.

Ended sessions and expired sign-in links are deleted automatically after 30 days; read notifications after 180 days. When an organisation's subscription lapses, its records are not deleted — they stay readable. When an organisation closes its account, Techvora deletes the organisation and everything it holds after the agreed export period.

Your rights

Under data protection law you can ask for access to, correction of, or erasure of your personal data, object to or restrict its processing, and ask for a portable copy. For HR records, make these requests to the organisation that employs you. For demo requests or your ValoraHRaccount itself, contact Techvora through techvora.net. You also have the right to complain to your data protection authority; in Ireland, that is the Data Protection Commission.

How the service is secured is described on the security page.