Truvaldi

Privacy Policy

Effective date: May 1, 2026

Last updated: May 10, 2026

1. Introduction

Truvaldi ("we," "us," or "our") operates the website truvaldi.com and provides AI-powered tools, websites, chatbots, and automation systems for service businesses. This Privacy Policy describes how we collect, use, disclose, and protect information when you visit our website, use our interactive tools, or engage us for services. By using our website, you consent to the practices described in this policy.

2. Information We Collect

Information you provide. When you fill out our contact form, request an AI Growth Audit, or engage with our interactive tools (quizzes, calculators, matchers, assessments), we may collect: your name, email address, phone number, business name, business type, job title, and information about your business needs. Tool submissions may include responses to assessment questions and self-reported business data.

Information collected automatically. We collect standard web analytics data including pages visited, time on site, referral source, browser type, device type, IP address, and approximate geographic location. We use this data to understand how visitors use our website and to improve our services.

AI chatbot interactions. Conversations with our AI chatbot are processed in real time and are not stored on our infrastructure after the session ends. We do not use chatbot interactions for AI model training.

3. How We Use Your Information

We use the information we collect to: respond to your inquiries and deliver requested services; generate AI Growth Audit roadmaps; improve our website, tools, and services; send project-related communications; comply with legal obligations; and protect against fraud and unauthorized access. We do not sell, rent, or trade your personal information to third parties for marketing purposes.

4. Data Sharing & Third-Party Services

We may share information with the following categories of third-party service providers, solely for the purpose of operating our business:

  • Cloudflare — Hosting, CDN, DNS, DDoS protection, Workers AI inference, and web analytics.
  • Anthropic (Claude) — AI model provider for content generation and tool logic. Data is not used for model training per our agreement.
  • OpenAI (GPT) — AI model provider for chatbot and classification tasks. Data is not used for model training per our API agreement.
  • Meta (Llama via Workers AI) — Open-weight AI models running on Cloudflare's edge network. No data leaves the Cloudflare network.
  • GitHub — Source code hosting and CI/CD. No customer data is stored in repositories.
  • Google Fonts — Font delivery. Subject to Google's privacy policy.

We may also disclose information if required by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. All data in transit is encrypted with TLS 1.3. Our infrastructure is hosted on Cloudflare, which provides enterprise-grade security, DDoS protection, and Web Application Firewall (WAF) protection. Our engineering team oversees security architecture for all systems. For a detailed description of our security practices, see our Security & Compliance page.

6. Data Retention

Contact form submissions and project-related communications are retained for the duration of the business relationship and for a reasonable period thereafter (typically 24 months) for follow-up and record-keeping purposes. Web analytics data is retained in aggregate form. AI chatbot conversations are not retained after the session ends. You may request deletion of your personal information at any time by contacting us at hello@truvaldi.com.

7. Cookies & Tracking

Our website may use first-party cookies for analytics purposes and to improve your browsing experience. We do not use third-party advertising cookies or cross-site tracking pixels. You can control cookie settings through your browser preferences. Disabling cookies will not affect the core functionality of our website or interactive tools.

8. HIPAA — Healthcare Engagements

For healthcare client engagements involving Protected Health Information (PHI), Truvaldi operates as a Business Associate under HIPAA. We offer a Business Associate Agreement (BAA) for all HIPAA-regulated engagements. Patient-facing tools on our website (quizzes, matchers, assessments) are designed to collect general inquiry data — not PHI — by default. For client-deployed tools that handle PHI, data handling, encryption, and access controls are governed by the terms of the BAA and the specific project agreement. AI model providers used in HIPAA engagements are contractually prohibited from using patient data for model training.

9. CCPA/CPRA — California Residents

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: You may request deletion of your personal information, subject to certain legal exceptions.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising.
  • Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise these rights, contact us at hello@truvaldi.com. We will verify your identity before processing your request. We will respond within 45 days as required by law.

10. GDPR — European Residents

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) provides you with the following rights:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your data under certain conditions.
  • Right to Restrict Processing: Request limitation of how we process your data.
  • Right to Data Portability: Request your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests.

Legal basis for processing: We process personal data based on legitimate interest (responding to business inquiries), consent (where explicitly provided), and contractual necessity (delivering services you have engaged us for). Data controller: Truvaldi, hello@truvaldi.com. To submit a Data Subject Access Request (DSAR), contact us at hello@truvaldi.com. We will respond within 30 days as required by law.

11. Children's Privacy

Our website and services are not directed to individuals under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under the applicable age, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at hello@truvaldi.com.

12. Breach Notification

In the event of a data breach involving your personal information, we will notify affected individuals and relevant regulatory authorities within 72 hours of becoming aware of the breach, as required by applicable law. Notification will include the nature of the breach, the categories of data affected, and the measures taken to address it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be noted with a revised "Last updated" date at the top of this page. We encourage you to review this page periodically. Continued use of our website after changes constitutes acceptance of the updated policy. A history of prior versions is available upon request.

14. Contact

For questions about this Privacy Policy, to exercise your privacy rights, or to submit a data subject request, contact us at:

Truvaldi
Email: hello@truvaldi.com
Website: truvaldi.com/contact

T

Truvaldi

AI assistant

Online
T

Hey — I'm Truvaldi's AI assistant. Ask me anything about our services, tools, pricing, industries, or process.