Prooff

Privacy Policy

Last updated [date — to be confirmed]

Draft — not yet in force. Company details are still placeholders.

This policy explains what personal data Prooff collects, why, who we share it with, how long we keep it, and what rights you have.

Prooff is operated by [Company name — to be confirmed], a company registered in [place of registration — to be confirmed] under [licence no. — to be confirmed], with its registered office at [registered address — to be confirmed]. For privacy questions, write to admin@prooff.app.

1. Two different roles we play

We control the data about your account. The data inside your projects belongs to the contractor who invited you — we only process it on their instructions.

This distinction matters, because it determines who is accountable for what.

We are a controller for data about the people and companies who sign up for Prooff — account details, subscription and billing records, support conversations, and security logs. This policy describes what we do with that data.

We are a processor for the personal data inside a customer’s projects — the names, contacts, photographs, documents and messages that a contractor and its project participants put into the workspace. That data belongs to the customer’s Entity, which decides what goes in and who sees it. We process it on that Entity’s instructions, under our Data Processing Addendum.

If you were invited to Prooff by a contractor— for example as a client, a client’s representative, a consultant or a site team member — the Entity that invited you is responsible for that project data. Ask them first about access, correction or deletion of project content; we will help them respond.

2. What we collect

Account and Entity details, billing records, whatever you put into your projects, and technical logs. We never see your card number.

Account data. Full name, email address, phone number (if you provide it), password (stored only as a cryptographic hash — we never see or store it in plain text), your role, your language preference, and whether your account is active.

Entity data. Entity name, logo, contact and address details you enter, subscription plan and status, storage usage, and the settings your administrators configure.

Billing data. Your subscription plan, its status and renewal dates, the billing details you give us, and the invoices and payment records we receive from our reseller. We never see or store your payment card details — subscriptions are sold through Paddle, which collects and holds payment and tax information itself (see clause 5).

Customer Content. Everything you and your project participants put into the workspace: projects, estimates, schedules, daily reports, variations, documents, site photographs, comments and file attachments. This may contain personal data about your staff, your clients and other individuals — you decide what goes in.

Technical data. IP address, browser and device information, and timestamps, recorded in server and security logs; session cookies needed to keep you signed in; and records of significant actions in the Service (who created, changed or approved what, and when) — the audit trail is a core feature of the product.

Communications. Emails and messages you send us, including support requests.

We do not collect data about you from data brokers, and we do not buy contact lists.

3. Why we use it, and our legal basis

Mostly to run the Service you asked for. We do not sell personal data or share it with advertisers.

What we doWhyLegal basis
Create and run your account and EntityTo provide the Service you asked forPerformance of a contract
Host, display and process your projects and filesSameContract (as processor, on the Entity’s instructions)
Send transactional email — approvals, invitations, password resets, notificationsThe Service is built around these notificationsContract
Invoice you and collect paymentTo be paidContract; legal obligation
Keep security, audit and error logsTo protect accounts and data, investigate incidents and fix faultsLegitimate interests (security and integrity of the Service)
Support youTo answer your questionsContract; legitimate interests
Improve the Service using aggregated, non-identifying usage informationTo make the product betterLegitimate interests
Send product announcements about changes that affect youYou need to know about themLegitimate interests
Send marketing email about ProoffTo grow the businessConsent, or legitimate interests where permitted — you can opt out at any time
Comply with tax, accounting and other legal dutiesBecause we mustLegal obligation

We do not sell personal data, we do not share it with advertisers, and we do not use it for automated decision-making that produces legal effects for you.

4. Cookies

Only the cookies needed to sign you in and remember your language. No analytics, no trackers, no consent banner.

Prooff uses only strictly necessary cookies:

CookiePurposeLife
Authentication cookies (sb-…)Keep you signed in and protect the sessionSession / until sign-out or expiry
NEXT_LOCALERemember your languageUp to 1 year

We do not use analytics, advertising, profiling or tracking cookies, and there are no third-party trackers on our site or in the app. That is why you do not see a cookie consent banner. If this ever changes, we will update this policy and ask for your consent before setting any non-essential cookie.

5. Who we share data with

Four infrastructure providers, our payment reseller, and nobody else unless the law requires it.

We do not sell or rent personal data, and we do not disclose it to anyone except:

Infrastructure providers (subprocessors) who help us run the Service. Each is bound by a written contract limiting them to processing data on our instructions and requiring appropriate security. The current list:

ProviderWhat it doesWhere it processes data
Vercel Inc. (USA)Application hosting and content deliveryServing region: Mumbai, India; global edge network
Supabase Inc. (USA)Database, authentication and file storage[region — to be confirmed]
Resend (USA)Delivery of transactional emailUSA
Anthropic PBC (USA)AI processing for the estimate-import feature onlyUSA

The current list is also maintained in our Data Processing Addendum, and we give notice of changes as described there.

Paddle — our reseller, as an independent controller. Paid subscriptions are sold by Paddle.com Market Ltd, which acts as merchant of record. When you buy a subscription, Paddle collects your payment, billing and tax details directly and processes them as a controller in its own right, under its own privacy notice — not on our instructions. We receive from Paddle only what we need to run your subscription: who bought what, the plan, the amount, the status and the invoice. We never receive your full card number.

Your own Entity. If you use Prooff through an Entity, its administrators can see your account details, your role and your activity in the workspace, and can manage or remove your access.

Professional advisers — accountants, auditors and lawyers — bound by confidentiality.

Authorities, where we are legally required to disclose. We will tell you before disclosing your data unless we are legally prohibited from doing so.

A successor, if the business is reorganised, incorporated, merged or acquired. We will notify you, and any successor remains bound by this policy or gives you notice of a replacement before it applies.

6. AI processing

Only the estimate-import feature uses AI. Files sent to it are not used to train models, and the feature is optional.

The estimate-import feature sends the file you upload, and the text extracted from it, to Anthropic PBC so that it can be converted into structured estimate lines.

  • Content sent through this feature is not used to train AI models.
  • The provider retains the content only transiently for abuse monitoring, in accordance with its commercial terms, and then deletes it.
  • The feature is optional. If you do not want your files processed this way, do not use it — write to support@prooff.app if you want it disabled for your Entity.
  • AI output is a draft and can be wrong. Review it before relying on it.

No other part of the Service sends your content to an AI provider.

7. International transfers

We are in the UAE and our providers are in the US, so data crosses borders under Standard Contractual Clauses where the GDPR applies.

We are established in the United Arab Emirates, and our providers are established in the United States and process data in the regions listed in clause 5. Your data will therefore be transferred across borders.

Where personal data protected by the EU or UK GDPR is transferred outside those areas, the transfer is covered by the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), which we have in place with the providers listed above, together with the technical measures described in clause 8. A copy of the relevant transfer terms is available on request to admin@prooff.app.

8. How we protect data

Encryption in transit and at rest, isolation enforced in the database itself, role-based access and daily encrypted backups.

  • Encryption in transit — all traffic uses TLS 1.2 or higher.
  • Encryption at rest — databases, backups and file storage are encrypted with AES-256 by our infrastructure providers.
  • Tenant isolation— access to every row of data is enforced in the database itself by row-level security policies, not only in application code, so one Entity cannot read another’s data.
  • Role-based access — within an Entity, what each person can see and do is governed by the roles and permissions its administrators configure.
  • Passwords are stored only as salted cryptographic hashes.
  • Least privilege internally — only personnel who need production access have it, they are bound by confidentiality, and administrative consoles require multi-factor authentication.
  • Backups — the database is backed up automatically every day, with 7 days of retention, and backups are encrypted.
  • Logging and monitoring of authentication and significant actions.

No system is perfectly secure. We protect your data using current industry-standard practices, keep those measures under review, and improve them as the product and the threats around it change. If a personal data breach occurs, we notify the people and authorities the law requires us to notify.

9. How long we keep data

Your content is kept while you subscribe, with at least 30 days to export it after that. Invoices are kept as long as the law requires.

DataRetention
Account dataWhile your account is active
Customer ContentWhile your subscription is active; available for export for at least 30 days after termination, and may be deleted after that
Deleted content held in backupsUntil the backup expires on its normal rotation (currently within 7 days)
Security and access logsUp to 12 months
Support correspondenceUp to 24 months after the conversation ends
Invoices and accounting recordsAs required by UAE tax and accounting law (currently at least 5 years)
Marketing contact dataUntil you unsubscribe, and then a minimal record so we do not contact you again

When a retention period ends, data is deleted or irreversibly anonymised.

10. Your rights

Access, correction, deletion, portability and objection — write to us and we respond within 30 days.

Subject to the law that applies to you — including the EU/UK GDPR and the UAE Personal Data Protection Law — you may:

  • access the personal data we hold about you;
  • correct it if it is inaccurate;
  • delete it (“right to be forgotten”), where we have no overriding legal ground to keep it;
  • receive a copy in a portable, machine-readable format;
  • restrict or object to processing based on our legitimate interests;
  • withdraw consent at any time where we relied on consent, without affecting processing already carried out;
  • opt out of marketing, by using the unsubscribe link or writing to us;
  • complain to a supervisory authority in your country.

How to exercise them. Write to admin@prooff.app. We will verify your identity and respond within 30 days. If your request concerns content inside a contractor’s project workspace, we are acting as a processor: we will pass the request to that Entity and assist them in answering it.

Deleting an account or an Entity. An Entity administrator can request deletion of the whole Entity from its page in the Service, under “Danger zone”; the request goes to us for review. You can also ask us to delete an account or an Entity at any time by writing to admin@prooff.app. We will confirm the request, delete the data from production systems within 30 days, and the data will disappear from backups as those expire (currently within 7 days). Records we are legally required to keep — chiefly invoices — are retained for the periods in clause 9. Deletion is irreversible: export anything you need first.

11. Children

Prooff is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child’s data has been put into the Service, write to admin@prooff.app and we will remove it.

12. Changes to this policy

We may update this policy at any time. The current version is always the one published on this page, and the “last updated” date at the top shows when it last changed. Please check this page from time to time; continued use of the Service after an update means the updated policy applies to you.

13. Contact

Questions about this policy, or about the data we hold on you, go to admin@prooff.app. Anything about using the product goes to support@prooff.app.

[Company name — to be confirmed]
[registered address — to be confirmed]