Overview

Valkurai is a financial governance layer for AI agents. It evaluates payment requests before they reach a payment rail. Valkurai is not a payment processor. It does not store payment card numbers, bank account details, or any financial account credentials. The personal information Valkurai collects is limited to what is necessary to operate the service.

1. Who this policy applies to

This policy applies to:

This policy does not apply to the end users of AI agents — Valkurai does not collect information about the people on whose behalf agents act. Valkurai's contract is with the Operator.

2. What information Valkurai collects

2.1 Account and registration information

2.2 Transaction data

2.3 Approval and decision data

This information is the EU AI Act Article 9 compliance evidence. It is stored in the immutable audit log and retained for 10 years.

2.4 Technical and usage data

3. How Valkurai uses your information

PurposeLawful basisData used
Providing the Service — evaluating transactions, sending notifications, storing audit recordsContract (necessary to perform the service)All categories in clause 2
Improving the Service — updating rule engine patterns, improving intent classification accuracyLegitimate interest / Consent (ToS clause 9)Aggregate, anonymised transaction data only
Compliance — responding to regulatory requests, OAIC notificationsLegal obligationAs required by the specific obligation
Security — detecting abuse, investigating incidentsLegitimate interestAPI request metadata, transaction patterns
Billing and account managementContractEmail address, billing information

4. Who Valkurai shares information with

Valkurai does not sell personal information. Valkurai shares information only as follows:

RecipientWhat is sharedWhyBasis
Amazon Web Services (AWS) ap-southeast-2All Valkurai dataInfrastructure provider — compute, storage, AI inference, email, SMS, notificationsAWS Data Processing Addendum. AWS SOC 2 Type II certified. Data does not leave ap-southeast-2 at Phase 1.
Stripe Payments Australia Pty LtdamountCents, currency only. No personal data. No card data.Payment execution rail on SAFE outcomesStripe's own terms and Privacy Policy. Stripe is an independent data controller for payment data.
BrevoOperator email address, registration metadataOperator onboarding and marketing email sequences onlyBrevo Data Processing Agreement. EU-based processor.
Regulatory authoritiesAs legally requiredLegal obligationPrivacy Act s16B, court order

5. Data retention

Data categoryRetention periodReason
Transaction audit records (TX)10 years from creationEU AI Act Article 9(9) and Australian financial record retention
Approval records10 years from creationEU AI Act Article 9 attribution evidence
Account information (email, phone)Duration of relationship + 2 yearsNotification obligations and account recovery
Billing records7 yearsTax and accounting requirements
API request logs (CloudWatch)2 yearsSecurity investigation and operational troubleshooting
Idempotency records24 hoursFunctional only — duplicate request prevention

Account closure, data export and erasure

When you close your Valkurai account, your API and dashboard access is revoked immediately. Transaction and approval audit records are retained for 10 years as required by EU AI Act Article 9(9). Within 7 days of closure, a presigned export URL is generated for a complete archive of your audit records. After this window, no further export is provided.

After the 7-day export window closes, approved_by email addresses in approval records are replaced with a one-way PBKDF2-SHA256 hash. This satisfies EU AI Act Art. 9(7) attribution requirements while minimising retained personal data.

Right to erasure (GDPR Art. 17): Submit requests to legal@valkurai.com. During the 10-year retention period, erasure of audit records is refused under Art. 17(3)(b) (legal obligation) and Art. 17(3)(e) (legal claims). A written response stating the legal basis is provided within 30 days.

6. Security

7. Your rights

RightHow to exercise itResponse time
Access — request a copy of personal information Valkurai holds about youEmail privacy@valkurai.com with your account email30 days
Correction — request correction of inaccurate personal informationEmail privacy@valkurai.com with details of the correction required30 days
Deletion — request deletion of your personal informationEmail privacy@valkurai.com. Note: audit log records are retained for 10 years.30 days
Withdraw consent — withdraw consent to Aggregate Data use (ToS clause 9)Email privacy@valkurai.com. Effective prospectively from date of receipt.Acknowledged within 5 business days
Complaint — lodge a complaint about our privacy practicesEmail privacy@valkurai.com first. If unresolved within 30 days, contact OAIC at oaic.gov.au.30 days for internal review

8. Notifiable Data Breaches

If Valkurai becomes aware of a data breach likely to result in serious harm, Valkurai will notify affected individuals as soon as practicable and notify the OAIC within 72 hours where the breach affects 5,000 or more Australians or is otherwise required by the NDB scheme. A summary will be published on status.valkurai.com.

Note on key storage and breach impact: because Valkurai uses zero-knowledge key storage, a breach of the DynamoDB table does not expose usable Agent Keys. A breach would expose transaction records, approval records, and email addresses.

9. Cookies and website data

10. Children's privacy

The Service is not directed at children under 18. Valkurai does not knowingly collect personal information from children. Contact privacy@valkurai.com if you believe a child has provided personal information.

11. Changes to this policy

Valkurai may update this policy from time to time. Material changes will be notified to Operators by email at least 14 days before the change takes effect.

Privacy contact

Privacy enquiriesprivacy@valkurai.com
OrganisationTech Compass Pty Ltd (ABN 31 632 578 342), trading as Valkurai
Address103/2 Furzer St, Phillip ACT 2606, Australia
OAICoaic.gov.au — 1300 363 992