Skip to content
valiss AI
EN DA

Trust Center

Who processes data on our behalf, where, under which agreements, and what each of them can document.

Trustbox ApS is the data controller
Valiss AI is operated by Trustbox ApS, CVR 37588822, Lyngbyvej 83 A, 2100 Copenhagen. Questions go to hello@valiss.co.
This site is hosted in the EU
valiss.co runs on Vercel in the Stockholm region. Our own systems and backups are hosted in the EU, and we choose EU regions wherever a provider offers one.
Transfers rest on SCC or the Data Privacy Framework
Where a subprocessor sits outside the EEA, the transfer is covered by the European Commission standard contractual clauses or the EU-US Data Privacy Framework.
A data processing agreement before we start
When we process personal data for a customer, we sign a data processing agreement first. It lists the subprocessors used in that specific solution.

Subprocessors

Every third party that may process personal data when you use this website, order a Signal audit, or run a solution we have built. A customer solution uses only the ones it needs.

22 subprocessors

AI models

Voice and telephony

Hosting and infrastructure

Communication and operations

  • Sends our newsletter and service messages, and email from customer solutions.

    This websiteCustomer solutions
    United States
    Twilio Inc.
    EU entity: Twilio Ireland Limited
    Transfer basis: EU-US Data Privacy Framework
  • Content system behind the Journal on valiss.co and content on customer websites. Content is stored in Belgium.

    This websiteCustomer solutions
    United States · EU data region
    Sanity US Inc.
    EU entity: Sanity AS
    Data stays in the EEA
  • Message channel for notifications and simple bots in customer solutions, only where the customer chooses it.

    Customer solutions
    United Arab Emirates
    Telegram Messenger Inc.
    Transfer basis: standard contractual clauses
    Telegram publishes no data processing agreement. It is used only as a transport channel; the data a bot receives stays in our systems.

Payments

Analytics and marketing

Certifications are those each provider states publicly on its own trust or security page at the time of the last update. Links go to the provider’s own documentation, which may change. The privacy notice describes how we process your data as a visitor or customer; this page lists the providers in use today.

What the certifications mean

A certification says that an independent auditor has checked the provider against a published standard. It does not replace a data processing agreement, but it is the best public evidence of how the provider works.

SOC 2
SOC 2 Type II

An independent audit of security, availability and confidentiality controls over a period of at least six months, under the American AICPA framework.

ISO 27001
ISO/IEC 27001

The international standard for information security management. Certification means an accredited body has audited the provider’s security organisation.

ISO 27017/18
ISO/IEC 27017 and 27018

Extensions of ISO 27001 for cloud services. 27017 covers cloud security controls, 27018 covers protection of personal data in the cloud.

ISO 42001
ISO/IEC 42001

The first international standard for AI management systems: how an organisation governs the development and use of AI responsibly.

EU-US DPF
EU-US Data Privacy Framework

The provider is on the US Department of Commerce list, so personal data can be transferred from the EEA under the European Commission adequacy decision of July 2023.

PCI DSS
PCI DSS

The payment card industry standard for handling card data. Level 1 is the strictest tier, required of the largest payment providers.

CSA STAR
CSA STAR

The Cloud Security Alliance registry, where cloud providers document their controls against the Cloud Controls Matrix.

How we choose and manage subprocessors

  1. 01

    EU first

    Where a provider offers an EU region or EU processing, we use it. This site, our own systems and our backups are in the EU.

  2. 02

    Agreement before data

    We sign the provider’s data processing agreement and check its transfer basis before any personal data flows through it.

  3. 03

    Least access

    A solution gets access only to the systems and fields it needs, and an AI model only sees what the task requires.

  4. 04

    Notice of changes

    When we add or replace a subprocessor, we update this page and the log below. Customers with a data processing agreement are notified as that agreement sets out.

Changes

  • 30 Sep 2026 Trust Center published.

Questions we get

Is our data used to train AI models?

No. We use the AI providers through their business and API terms, where the largest providers state that data sent through the API is not used for training. In valiss.ai, data is never used for training either.

Which subprocessors does our solution use?

Only the ones it needs. A voice agent might use Twilio, Cartesia and one AI model, nothing else. The exact set is listed in your data processing agreement, and you can ask for it at any time.

Can we get a copy of your data processing agreement?

Yes. Write to hello@valiss.co and we send our standard agreement, or we review yours. We reply within one business day.

Where is our data stored?

Our own systems and backups are hosted in the EU. Some providers, such as the AI models, process requests in the United States. That transfer rests on the EU-US Data Privacy Framework or standard contractual clauses, as shown for each provider above.

Need the details for your own review?

We send the data processing agreement, the transfer basis and the subprocessor list for your solution, and answer your security questionnaire.