Privacy

Privacy Policy

How we handle your personal data at Proofo — what we collect, why, who we share it with, and the control you keep over it.

Last updated: 1 July 2026

The short version

We collect the minimum we need to run Proofo: your account details, the agreements you create, and basic technical data. We don't sell your data. Deal content is stored to provide the service and is protected with encryption in transit and at rest. You can access, export, or delete your data at any time.
01

Who is responsible for your data

This policy applies to proofo.app and related services (the "Service"), operated by Proofo s.r.o. ("Proofo", "we", "us"). For personal data we process about you as an account holder or visitor, Proofo is the data controller.

Controller vs. processor for deal content

When you create an agreement and invite someone to sign, you decide what information goes into it. For that content and any counterparty details you add, you act as the controller and Proofo acts as a processor handling the data on your instructions to deliver the Service.
02

The data we collect

Data you provide

  • Account data — name, email address, and (if you enable SMS verification) a phone number.
  • Agreement content — the terms, template fields, party names, and signatures you and your counterparties add to a deal.
  • Signature data — the drawn signature image and the verification event (e.g. one-time code confirmation) used to seal a deal.
  • Support and feedback — messages you send us.

Data collected automatically

  • Technical data — IP address, browser and device type, and approximate location derived from your IP.
  • Usage and audit data — actions taken on a deal (created, viewed, signed, sealed) with timestamps, kept as part of the tamper-evident audit trail.
  • Cookies and similar technologies — see the Cookies section below.
03

How and why we use your data

We only use your personal data where the law gives us a valid basis to do so:

  • To provide the Service — creating, delivering, signing, and sealing agreements, and generating PDF receipts. Legal basis: performance of a contract.
  • Security and integrity — verifying signers, preventing abuse and fraud, and maintaining the audit trail. Legal basis: legitimate interests and legal obligation.
  • Communication — sending transactional notices such as signing requests and sealed-deal confirmations. Legal basis: performance of a contract.
  • Improvement and analytics — understanding how the Service is used so we can improve it. Legal basis: consent or legitimate interests.
  • Legal compliance — meeting accounting, tax, and other legal requirements. Legal basis: legal obligation.

We do not sell your personal data, and we do not use the content of your agreements to build advertising profiles.

04

Service providers we share data with

We rely on a small set of trusted providers (sub-processors) to run Proofo. They may process personal data on our behalf under contractual data-protection terms, and only as needed to deliver their part of the Service:

  • Supabase — authentication, database, and file storage.
  • Vercel — application hosting and performance analytics.
  • Resend — delivery of transactional emails.
  • Twilio — delivery of SMS one-time codes (only if you use SMS verification).
  • Upstash — rate limiting and abuse protection.

We may also disclose data where required by law, to protect our legal rights, or in connection with a merger or acquisition (in which case we'll notify you).

05

International transfers

Some of our providers process data outside the European Economic Area. Where that happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision, so your data keeps an equivalent level of protection wherever it is processed.

06

How long we keep it

We keep personal data only for as long as we need it for the purposes above. In practice:

  • Account data — for as long as your account is active, then deleted or anonymised after closure (subject to legal retention periods).
  • Sealed agreements — retained so both parties keep access to their proof, within the history window of your plan, unless you delete them earlier.
  • Records we must keep by law — e.g. invoices, kept for the period required by tax and accounting rules.
07

How we protect it

We use encryption in transit (HTTPS) and at rest, access controls, rate limiting, and the SHA-256 sealing that makes tampering with a completed deal detectable. No online service can guarantee absolute security, but we work to protect your data with measures appropriate to its sensitivity. If a breach affects your rights, we'll notify you and the relevant authority as required by law.

08

Your rights (GDPR)

If you are in the EEA or UK, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent at any time. To exercise any of these, email privacy@proofo.app — we respond within the statutory time limits.

You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz).

09

US state privacy rights

If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect and how we use it, to request deletion or correction, and to opt out of the "sale" or "sharing" of personal information. We do not sell personal information. We will not discriminate against you for exercising these rights. Send requests to privacy@proofo.app.

10

Cookies

We use a small number of cookies and similar technologies. You can manage your choices at any time through the cookie banner. We group them into:

  • Strictly necessary — required to sign you in and keep the site working. These can't be switched off.
  • Analytics — help us understand usage so we can improve. Optional.
  • Marketing — used to measure and improve any campaigns. Optional.
11

Children

Proofo is not intended for anyone under 18, and we don't knowingly collect data from children. If you believe a minor has given us personal data, contact us and we'll delete it.

12

Changes to this policy

We may update this policy as the Service evolves or the law changes. We'll revise the "last updated" date above and, for material changes, give you notice through the Service or by email.

Questions about this page? Reach us at support@proofo.app or visit our contact page.