WorkspaceEngineAPIUse CasesPerspectives
DocsJoin The Pilot List
← Back To Home

Updated6 October 2026

Security And Data Handling

How website registrations are handled, how API access is controlled and what to agree before sharing customer data.

On This Page

  1. Using This Website
  2. Pilot-List Information
  3. Workspace And API Access
  4. API Access Controls
  5. Property Data And Agentic Analysis
  6. API Retention And Customer Records
  7. Evaluating Valtaic For Your Organisation
  8. Report A Security Concern

Using This Website

The pilot-interest form asks for contact details, not property documents or customer datasets. The public product demonstrations use illustrative data.

Our approach is to minimise personal information, limit its use to the purpose for which it is collected and restrict access to those who need it. The Privacy Policy explains the website’s data handling and your rights.

Pilot-List Information

The registration form is processed on the server. It validates submitted contact details and includes basic controls to reduce automated submissions. The public form does not query or display the pilot-interest list.

We use registration information to manage pilot interest and related correspondence. We do not sell it or use it for third-party advertising. Service providers may process it on our behalf for the purposes described in the Privacy Policy.

Our retention policy is 12 months from signup or the last direct pilot-related contact, unless you ask for earlier removal or another lawful retention need applies. General broadcast emails do not extend this period. Email hello@valtaic.io to leave the list, request deletion or exercise your data-protection rights.

Workspace And API Access

Live pilot access is arranged separately. Before sharing customer information, contact us to agree the use case, access arrangements, permitted data and any required data-processing terms.

Keep API credentials in your backend systems, not in public browser code. Do not send passwords, API keys, identity documents or tenant and borrower records to the general enquiry address.

API Access Controls

The Property Valuation API requires a key associated with an active account. Access is limited by the credential’s permissions and the account’s enabled products and plan. Each data product has its own access requirements.

  • Scoped access: valuation, development valuation and stored-property-data permissions are separate.
  • Usage boundaries: plans define request, valuation-unit, batch-size and concurrent-request limits.
  • Credential management: issue separate keys to independent systems and revoke exposed credentials. Rotate a key by introducing its replacement before removing the old one.

Read Authentication, Plans & Usage for integration requirements and Compliance & Assurance for the valuation service’s validation, governance and intended-use guidance.

Property Data And Agentic Analysis

Valtaic develops its valuation models internally. Model development is separate from the infrastructure used to store registrations, send emails or deliver the service.

A property address, a portfolio record and a conversation can contain personal or commercially sensitive information. Use only data you are entitled to submit, and agree the permitted scope before connecting customer records.

Before using Agentic Analysis with confidential information, agree the permitted context, processing locations, access, retention and deletion arrangements, and any use of information for model improvement. Contact us to establish the arrangements for your pilot before submitting sensitive records.

For API valuations, stored-data access is an explicit request option that also requires the relevant permission. Preserve the valuation’s release reference and result status for your own review; a referral, rejection or failed result must not be treated as an accepted estimate.

API Retention And Customer Records

Asynchronous valuation-job status and results have a seven-day retrieval window. That window describes availability through the API; retention of service logs, identity records, backups and customer-held copies is addressed separately in the applicable processing arrangements.

Agree the required retention and deletion arrangements for your deployment, including the handling of requests from individuals and any records your organisation must keep. The API data-protection guidance explains these responsibilities. The pilot-list retention period in the Privacy Policy applies to website registrations.

Evaluating Valtaic For Your Organisation

Before an organisational pilot, confirm the arrangements for your proposed deployment with us:

  • The information involved, its purpose, lawful basis and the parties’ controller or processor roles.
  • Authorised users, API credential handling and access removal.
  • Hosting locations, service providers and safeguards for international transfers.
  • Retention and deletion across the service, logs, backups and relevant provider copies.
  • Incident reporting contacts, communication responsibilities and any required processing agreement.

Specific controls, service levels and processing commitments belong in the applicable service agreement. For a regulated valuation workflow, also review the valuation-use guidance against your organisation’s requirements.

Report A Security Concern

Email hello@valtaic.io with “Security” in the subject and a description of the affected page or behaviour. Please leave credentials and other people’s personal information out of the initial message; we can agree a suitable way to share sensitive evidence.

Do not access, alter or test data or systems without permission.

Platform

Market DataPortfolios & AssetsAutomated ResearchAgentic Analysis

Resources

Property ValuationAPI QuickstartAPI AuthenticationDeveloper Resources

Company & Legal

About ValtaicSecurity & DataPrivacy PolicyWebsite Terms

Residential Property Intelligence

hello@valtaic.io

© 2026 Valtaic Ltd · No. 17413209

Registered in England and Wales.