Prooflytics
— Legal

Data Processing Addendum

The terms that apply when Prooflytics processes personal data on behalf of your workspace. This addendum forms part of the Terms of Use for every customer to whom the GDPR or equivalent law applies.

Roles

For personal data inside your workspace — the records your connected sources sync, the visitors your tracking records, the contacts your CRM holds — you are the controller and Prooflytics is the processor. For the account data we need to run the relationship itself (your login, billing contact, product usage), Prooflytics is an independent controller, as described in the Privacy Policy.

Our processor commitments (Article 28(3) GDPR)

Documented instructions

We process personal data in your workspace only to provide the service you configured — syncing the sources you connected, producing the analytics and reports you requested — and on your documented instructions, including with regard to transfers, unless EU or member-state law requires otherwise (in which case we inform you before processing, unless that law forbids it).

Confidentiality

Access to customer data is limited to persons who need it to operate the service, and every such person is bound by a contractual or statutory duty of confidentiality.

Security

We implement the technical and organisational measures described on our Security page — encryption in transit, encrypted credential storage, workspace-scoped access controls, audit logging — and review them as the service evolves. See /security for the current description.

Sub-processors

We engage the sub-processors listed below under a general written authorisation. Each is bound by data-protection obligations no less protective than these terms. We update the list on this page before adding a vendor that touches customer data; if you object to an addition on reasonable data-protection grounds, you may terminate the affected service and we refund any prepaid fees for the unused period.

Data-subject rights

Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in fulfilling your obligation to respond to data-subject requests — access, rectification, erasure, restriction, portability, objection. Requests reaching us directly about your workspace are forwarded to you.

Assistance with security, breach notification and DPIAs

We assist you in ensuring compliance with Articles 32-36 GDPR: we notify you without undue delay after becoming aware of a personal-data breach affecting your workspace, with the information we have, and we provide reasonable assistance for data-protection impact assessments concerning the processing we perform.

Deletion and return

When your workspace is deleted, we delete the personal data we process on your behalf, except where EU or member-state law requires storage. Billing records are retained per legal retention duties. The deletion mechanics are described on the Security page.

Audit and information

We make available the information necessary to demonstrate compliance with these obligations, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — scoped and scheduled reasonably, at your cost, no more than once per year absent a supervisory-authority requirement or a breach.

International transfers

Some sub-processors below are established in, or process data in, the United States or other third countries. Transfers rest on the safeguard each vendor operates for its customers — the EU-U.S. Data Privacy Framework where the vendor is certified, and the European Commission's Standard Contractual Clauses incorporated in the vendor's own data-processing terms otherwise. Each vendor's current mechanism is stated in its own legal documentation, linked below; we do not restate certification statuses we do not control.

Authorised sub-processors

The same list as /subprocessors, with each vendor's own terms as the authority on where and how it processes:

VendorPurposeVendor terms
ClerkAuthentication, workspace and team managementclerk.com/legal
StripeSubscription billing and paymentsstripe.com/legal
VercelApplication hosting and deliveryvercel.com/legal
InngestBackground job schedulinginngest.com/terms
CloudflareFile storage for generated reportscloudflare.com/trust-hub
NangoConnector infrastructure for the integration cataloguenango.dev/legal
AnthropicLanguage-model processing for briefings and the assistantanthropic.com/legal
ApifyCompetitor advertising research (no customer personal data)apify.com/terms
ResendTransactional email deliveryresend.com/legal
SentryError monitoringsentry.io/legal
PostHogProduct analyticsposthog.com/terms

Questions and signed copies

For a countersigned copy of this addendum, a sub-processor objection, or any data-protection question, write to privacy@prooflytics.io. We respond within 30 days.