Privacy policy

Last updated: July 2026

This policy explains what personal data we collect through this website, why we collect it, and the rights you have over it. The short version: we collect only what you give us, we use no tracking cookies, and we delete your data when you ask.

Who we are

Valor Consulting (“Valor Consulting”, “we”) operates this website and provides Azure cost-optimization and cloud-governance services. For anything in this policy, write to contact@valor-co.com.

What we collect

  • Contact form details — name, work email, company, role, optional phone number, and anything you write in the message field.
  • Funnel and scenario selections — the answers you pick in the 2-minute check and the scenario tool (spend band, environment shape, priorities). They travel with your enquiry so our reply is actually useful.
  • Uploaded documents — Azure cost exports and related files you choose to share through the secure, NDA-gated upload.
  • Usage analytics — first-party only. We record the pages you visit, the page that referred you, a device profile (browser, operating system, device type, screen and viewport size, language, timezone) and your IP address, linked to a visitor identifier stored in your browser’s local storage. No cookies are set, no advertising identifiers are used, and nothing follows you across other sites.
  • Email engagement — for the transactional emails we send you (a booking confirmation, a reply, a document you asked for), we may record whether the message was opened and which links in it you clicked, with the time, your IP address and browser. This is first-party and uses no cookies; we use it only to confirm our emails are reaching you and working. You can ask us to stop this and to delete these records at any time.

Why we collect it, and on what legal basis

  • Answering your enquiry and running the free savings check — steps taken at your request before a contract (GDPR Art. 6(1)(b)).
  • Delivering a signed engagement — performance of a contract (Art. 6(1)(b)).
  • Understanding how the site is used and improving it — legitimate interest (Art. 6(1)(f)). The analytics stay first-party: they are never sold, never used for advertising, and never combined with third-party profiles. You can object at any time, and we will delete your record.
  • Anything beyond the above — consent (Art. 6(1)(a)), which you can withdraw at any time.

We do not sell personal data, and we do not use it for advertising.

How long we keep it

  • Enquiry and contact data — for the life of the conversation plus a reasonable follow-up period. Deleted on request, at any time.
  • Usage analytics — held on a rolling roster of recent visitors, so older records drop off automatically as new visits arrive. Deleted on request, at any time.
  • Uploaded documents — stored outside the public uploads directory and access-logged while they exist; deleted when the engagement ends or on request, whichever comes first.
  • Analytics — aggregate only; it contains no personal data to delete.

Who processes it

We keep the list short, and disclose it here by category:

  • Hosting & infrastructure — this website and its data, in an EU data centre.
  • Transactional email delivery — booking confirmations, enquiry notifications and our replies.
  • Productivity & meetings suite — our internal email, documents and the video platform scoping calls run on.

The current list of named providers is available on request — write to contact@valor-co.com. A data processing agreement is in place with each processor. Sub-processors used inside a client engagement are listed in the DPA — see NDA & DPA documents.

International transfers

The site and your data are hosted in the EU. If a transfer outside the EEA ever becomes necessary, we will rely on recognised safeguards such as the EU Standard Contractual Clauses.

Your rights

Under the GDPR you can:

  • Request access to the personal data we hold about you.
  • Have it corrected or completed.
  • Have it erased.
  • Receive it in a portable, machine-readable format.
  • Object to, or restrict, processing based on legitimate interest.

You can also lodge a complaint with your local supervisory authority. We would prefer you raise it with us first — most requests are straightforward and resolved quickly.

Privacy requests

Email contact@valor-co.com with the subject “Privacy request” · Mon–Fri 08:00–17:00 CET. We confirm receipt as soon as we have seen it.

If we contacted you and you never contacted us

Sometimes we write to somebody who has not been in touch with us first. Where that happens we did not get your details from you, so this section says where they came from and what you can do about it. It is here because Article 14 of the GDPR requires it.

Where your details came from

From publicly available business sources: the Norwegian Register of Business Enterprises and the Central Coordinating Register for Legal Entities (Brønnøysundregistrene), your own company’s public website, and public professional profiles. We record which of these each detail came from, and when, on the record itself.

What we hold, and why

Business contact details in a professional capacity — name, role, work email or work telephone, and the company you work for. We hold them for one purpose: to ask whether reducing your organisation’s Azure spend is worth a conversation.

Our legal basis is legitimate interests, Article 6(1)(f). The interest is finding organisations that would benefit from work we do. We have carried out and written down a balancing test weighing that interest against your interests, and you may ask us for it.

How long we keep it

Until you tell us to stop, or until the record has gone a year without any contact from either side, whichever comes first. Then it is deleted.

Your right to object

You can tell us to stop at any time, and we will. No reason is needed and nothing is asked in return. Reply STOP to any email from us, or write to contact@valor-co.com. We will stop contacting you and delete the record unless we are required to keep something to show that you asked.

You also have the right to ask what we hold, to have it corrected, to have it erased, and to complain to the Norwegian Data Protection Authority (Datatilsynet).

We have not bought a list, and we do not sell or share these details with anyone.