Data Processing Addendum
The terms that apply when Prooflytics processes personal data on behalf of your workspace. This addendum forms part of the Terms of Use for every customer to whom the GDPR or equivalent law applies.
Roles
For personal data inside your workspace — the records your connected sources sync, the visitors your tracking records, the contacts your CRM holds — you are the controller and Prooflytics is the processor. For the account data we need to run the relationship itself (your login, billing contact, product usage), Prooflytics is an independent controller, as described in the Privacy Policy.
Our processor commitments (Article 28(3) GDPR)
Documented instructions
We process personal data in your workspace only to provide the service you configured — syncing the sources you connected, producing the analytics and reports you requested — and on your documented instructions, including with regard to transfers, unless EU or member-state law requires otherwise (in which case we inform you before processing, unless that law forbids it).
Confidentiality
Access to customer data is limited to persons who need it to operate the service, and every such person is bound by a contractual or statutory duty of confidentiality.
Security
We implement the technical and organisational measures described on our Security page — encryption in transit, encrypted credential storage, workspace-scoped access controls, audit logging — and review them as the service evolves. See /security for the current description.
Sub-processors
We engage the sub-processors listed below under a general written authorisation. Each is bound by data-protection obligations no less protective than these terms. We update the list on this page before adding a vendor that touches customer data; if you object to an addition on reasonable data-protection grounds, you may terminate the affected service and we refund any prepaid fees for the unused period.
Data-subject rights
Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in fulfilling your obligation to respond to data-subject requests — access, rectification, erasure, restriction, portability, objection. Requests reaching us directly about your workspace are forwarded to you.
Assistance with security, breach notification and DPIAs
We assist you in ensuring compliance with Articles 32-36 GDPR: we notify you without undue delay after becoming aware of a personal-data breach affecting your workspace, with the information we have, and we provide reasonable assistance for data-protection impact assessments concerning the processing we perform.
Deletion and return
When your workspace is deleted, we delete the personal data we process on your behalf, except where EU or member-state law requires storage. Billing records are retained per legal retention duties. The deletion mechanics are described on the Security page.
Audit and information
We make available the information necessary to demonstrate compliance with these obligations, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — scoped and scheduled reasonably, at your cost, no more than once per year absent a supervisory-authority requirement or a breach.
International transfers
Some sub-processors below are established in, or process data in, the United States or other third countries. Transfers rest on the safeguard each vendor operates for its customers — the EU-U.S. Data Privacy Framework where the vendor is certified, and the European Commission's Standard Contractual Clauses incorporated in the vendor's own data-processing terms otherwise. Each vendor's current mechanism is stated in its own legal documentation, linked below; we do not restate certification statuses we do not control.
Authorised sub-processors
The same list as /subprocessors, with each vendor's own terms as the authority on where and how it processes:
| Vendor | Purpose | Vendor terms |
|---|---|---|
| Clerk | Authentication, workspace and team management | clerk.com/legal |
| Stripe | Subscription billing and payments | stripe.com/legal |
| Vercel | Application hosting and delivery | vercel.com/legal |
| Inngest | Background job scheduling | inngest.com/terms |
| Cloudflare | File storage for generated reports | cloudflare.com/trust-hub |
| Nango | Connector infrastructure for the integration catalogue | nango.dev/legal |
| Anthropic | Language-model processing for briefings and the assistant | anthropic.com/legal |
| Apify | Competitor advertising research (no customer personal data) | apify.com/terms |
| Resend | Transactional email delivery | resend.com/legal |
| Sentry | Error monitoring | sentry.io/legal |
| PostHog | Product analytics | posthog.com/terms |
Questions and signed copies
For a countersigned copy of this addendum, a sub-processor objection, or any data-protection question, write to privacy@prooflytics.io. We respond within 30 days.