Data Processing Addendum
Last updated [date — to be confirmed]
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between [Company name — to be confirmed] (“Prooff”, “Processor”) and the customer company using the Service through an Entity (“Customer”, “Controller”).
You do not need to sign this document. It applies automatically to every customer whenever Prooff processes personal data on that customer’s behalf. If your procurement process requires a signed copy on your own paper, write to admin@prooff.app and we will arrange it.
Terms defined in the Terms of Service have the same meaning here. “Personal data”, “processing”, “controller”, “processor”, “data subject” and “supervisory authority” have the meaning given in the EU General Data Protection Regulation (“GDPR”), and equivalent meanings under other applicable data protection law, including the UK GDPR and UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
1. Roles
You control the personal data in your projects; we process it for you. We are a controller only for account and billing data.
1.1 The Customer is the controller of personal data contained in Customer Content. Prooff is the processor of that data.
1.2 Prooff is a controller in its own right for account, subscription, billing, support and security-log data relating to the Customer and its users. That processing is described in the Privacy Policy and is outside the scope of this DPA.
1.3 Each party complies with the data protection law applicable to it. The Customer is responsible for the lawfulness of the data it puts into the Service, including having a lawful basis to collect it and to share it with the project participants it gives access to, and for providing any notices its own data subjects require.
2. Scope of processing
We process your data only on your instructions, never for our own purposes, and never to train AI models.
2.1 Instructions. Prooff processes personal data contained in Customer Content only: (a) on the Customer’s documented instructions — which include these Terms, this DPA, the configuration the Customer chooses in the Service, and the use of the Service by the Customer’s users; and (b) where required by law that applies to Prooff, in which case Prooff will inform the Customer of that requirement before processing, unless the law prohibits it.
2.2 Prooff will tell the Customer if, in its opinion, an instruction infringes applicable data protection law.
2.3 No secondary use. Prooff does not sell Customer personal data, does not use it for its own purposes, does not use it for advertising or profiling, and does not use it to train artificial intelligence models. Aggregated statistics that cannot identify any individual or any customer may be used to operate and improve the Service.
2.4 Details. The subject matter, duration, nature and purpose of the processing, the categories of personal data and of data subjects are set out in Annex I.
3. Confidentiality
Prooff ensures that every person authorised to process Customer personal data is bound by an obligation of confidentiality, is granted access only where necessary for their role, and receives instruction on their obligations.
4. Security
We maintain the measures in Annex II; you remain responsible for who you give access to.
4.1 Prooff implements and maintains the technical and organisational measures set out in Annex II, appropriate to the risk, in accordance with Article 32 GDPR.
4.2 Prooff may update those measures over time, provided the level of protection is not reduced.
4.3 The Customer is responsible for the security decisions within its own control: managing its users, assigning roles and permissions, deciding which project participants receive access, revoking access when people leave, and choosing what data it uploads.
5. Subprocessors
The current list is in Annex III. We give 30 days' notice before adding or replacing one, and you may object.
5.1 Authorisation. The Customer gives general authorisation for Prooff to engage the subprocessors listed in Annex III.
5.2 Terms. Prooff imposes on each subprocessor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for each subprocessor’s performance.
5.3 Changes. Prooff will give the Customer at least 30 days’ notice before adding or replacing a subprocessor, by email to the Entity’s administrators. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected subscription and receive a refund of the unused portion of prepaid fees.
6. Assistance to the Customer
Most data subject requests you can satisfy yourself in the Service; where you cannot, we help.
6.1 Data subject requests. Taking into account the nature of the processing, Prooff assists the Customer with appropriate technical and organisational measures in responding to data subject requests. Most requests can be satisfied by the Customer directly through the Service — it can access, correct, export and delete project content itself. Where it cannot, Prooff assists on request.
6.2 Requests received directly. If Prooff receives a request from a data subject relating to Customer Content, it will not respond on the merits (except to acknowledge and redirect) and will forward the request to the Customer without undue delay.
6.3 Other assistance. Prooff provides reasonable assistance with data protection impact assessments, prior consultations with supervisory authorities, and security obligations under Articles 32–36 GDPR, taking into account the information available to it.
7. Personal data breach
We tell you without undue delay and within 72 hours of becoming aware.
7.1 Prooff notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer personal data.
7.2 The notice will describe, so far as known: the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures taken or proposed, and a contact point for more information. Where full information is not available at once, it is provided in phases without further undue delay.
7.3 Prooff does not notify supervisory authorities or data subjects on the Customer’s behalf unless legally required or asked to do so; that responsibility sits with the Customer as controller.
8. Deletion and return
30 days to export after termination, then deletion; backups expire within 7 days.
8.1 During the subscription, the Customer may export and delete Customer Content through the Service at any time.
8.2 On termination, Customer Content remains available for export for 30 days, after which it is deleted from production systems. Copies in encrypted backups are deleted as those backups expire on their normal rotation (currently within 7 days), during which time they remain protected by this DPA and are not accessed for any purpose other than restoring the Service.
8.3 Prooff retains personal data after termination only where required by law (chiefly invoicing and tax records), for the periods stated in the Privacy Policy.
8.4 On written request, Prooff will confirm deletion.
9. Audit
We share our security documentation, answer a questionnaire once a year, and accept on-site audits where a regulator or an incident requires one.
9.1 Prooff makes available the information reasonably necessary to demonstrate compliance with this DPA, including its security documentation and the reports and certifications of its subprocessors where it is permitted to share them.
9.2 The Customer may, no more than once in any 12-month period, request further information by means of a written security questionnaire, which Prooff will answer within 30 days.
9.3 On-site audits are available only where a supervisory authority requires one or where a documented security incident affecting the Customer has occurred. Such an audit is arranged on at least 30 days’ notice, during business hours, without disrupting the Service or the confidentiality of other customers’ data, at the Customer’s cost, and subject to confidentiality.
10. International transfers
Standard Contractual Clauses (Module Two) and the UK Addendum are incorporated by reference.
10.1 Personal data is processed in the regions listed in Annex III and may be transferred outside the country in which the Customer is established.
10.2 Where the transfer of personal data protected by the EU GDPR to a country without an adequacy decision takes place, the parties agree that the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and apply to that transfer, with:
- the Customer as data exporter and Prooff as data importer;
- Clause 7 (docking) applying;
- Clause 9, Option 2 (general written authorisation) with the notice period in clause 5.3 of this DPA;
- Clause 11 optional redress clause not applying;
- Clause 17: the governing law being the law of the Republic of Ireland;
- Clause 18(b): the courts of Ireland;
- Annexes I, II and III of this DPA populating Annexes I, II and III of the Clauses.
10.3 For personal data protected by the UK GDPR, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies, with Tables 1–4 completed by reference to this DPA and Part 2 Mandatory Clauses incorporated.
10.4 Prooff has equivalent transfer terms in place with each subprocessor listed in Annex III.
11. Liability
Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service. Where the Standard Contractual Clauses apply, nothing in this DPA limits liability towards data subjects to the extent the Clauses prohibit it.
12. General
12.1 This DPA takes precedence over the Terms of Service to the extent of any conflict about the processing of personal data. The Standard Contractual Clauses take precedence over this DPA to the extent of any conflict.
12.2 This DPA is governed by the law and jurisdiction stated in the Terms of Service, except where clause 10 or mandatory law provides otherwise.
12.3 We may update this DPA at any time. The current version is the one published on this page, and the “last updated” date at the top shows when it last changed. Changes to the subprocessor list are notified in advance under clause 5.3.
12.4 If a provision of this DPA is held invalid, the rest remains in force.
Annex I — Details of processing
Subject matter. Provision of the Prooff contracting project portal.
Duration. For the term of the Customer’s subscription, plus the retention periods in clause 8.
Nature and purpose. Hosting, storage, structuring, display, transmission, back-up, and deletion of Customer Content, so that the Customer and the project participants it authorises can collaborate on construction projects; delivery of transactional notifications by email; and, where the Customer chooses to use it, AI processing of uploaded estimate files to convert them into structured data.
Categories of data subjects
- the Customer’s employees, officers and contractors who use the Service;
- the Customer’s own clients and their representatives, invited to a project;
- consultants, subcontractors and site personnel named in project content;
- any individual whose personal data the Customer chooses to include in Customer Content.
Categories of personal data
- identification and contact data: name, email address, telephone number, role, job title, employer, profile photograph;
- authentication data: password hashes, session and sign-in records;
- professional activity data: actions taken in the Service, approvals given, comments, timestamps, and the audit trail;
- content data: any personal data contained in project files, drawings, documents, site photographs, daily reports and messages that the Customer uploads.
Special categories of data. None are required by the Service, and the Terms of Service prohibit uploading them. Site photographs may incidentally show individuals; the Customer is responsible for the lawfulness of what it uploads.
Frequency of transfer. Continuous, for the duration of the subscription.
Annex II — Technical and organisational measures
This annex describes the measures in place today. As clause 4.2 says, they change as the product and the risks around it change, provided the level of protection is not reduced.
Encryption
- Traffic uses TLS 1.2 or higher, including uploads and downloads.
- The database, file storage and backups are encrypted at rest with AES-256.
- Passwords are stored only as salted cryptographic hashes, never in plain text.
Access control and tenant isolation
- Row-level security is enforced in the database itself, so isolation between customer Entities does not depend on application code alone.
- Role-based permissions within each Entity, configurable by its administrators, govern both feature access and visibility of commercial data.
- File access uses signed, time-limited URLs; storage buckets are not publicly listable.
- Access to production is limited to the people who need it, who are bound by confidentiality, and is removed when it is no longer needed.
- Administrative consoles are protected by multi-factor authentication.
Resilience and recovery
- Managed infrastructure operated by the providers listed in Annex III.
- Automated daily database backups with 7 days’ retention, encrypted at rest.
Logging and monitoring
- Authentication and significant application events are logged with actor and timestamp; the audit trail is a product feature and is visible to the Customer.
- Infrastructure and application errors are monitored.
Development practices
- The codebase is version-controlled, and changes are reviewed before release.
- Type checking and linting run as part of the build.
- Dependencies are kept up to date.
- Secrets are held in the hosting platform’s encrypted secret store, never in source control.
Vendor management
- Subprocessors are selected on their security posture and bound by written data protection terms.
- The subprocessor list is kept in Annex III, and changes are notified under clause 5.3.
Incident response
- Security incidents are investigated and remediated, and notified as set out in clause 7.
Annex III — Subprocessors
| Subprocessor | Role | Processing location |
|---|---|---|
| Vercel Inc. (USA) | Application hosting, content delivery, serverless compute | Primary serving region: Mumbai, India; global edge network |
| Supabase Inc. (USA) | Managed database, authentication and file storage | [region — to be confirmed] |
| Resend (USA) | Delivery of transactional email notifications | USA |
| Anthropic PBC (USA) | AI processing of files submitted to the estimate-import feature only; no training on customer content | USA |
The current list is published on this page. Changes are notified under clause 5.3.
Data protection questions, and requests for a signed copy of this DPA, go to admin@prooff.app. Questions about how the product works go to support@prooff.app.
[Company name — to be confirmed], [registered address — to be confirmed]
