Privacy Policy
How we handle your personal data at Proofo — what we collect, why, who we share it with, and the control you keep over it.
Last updated: 1 July 2026
The short version
Who is responsible for your data
This policy applies to proofo.app and related services (the "Service"), operated by Proofo s.r.o. ("Proofo", "we", "us"). For personal data we process about you as an account holder or visitor, Proofo is the data controller.
- Controller: Proofo s.r.o., Brno, Czech Republic
- Privacy contact: privacy@proofo.app
Controller vs. processor for deal content
The data we collect
Data you provide
- Account data — name, email address, and (if you enable SMS verification) a phone number.
- Agreement content — the terms, template fields, party names, and signatures you and your counterparties add to a deal.
- Signature data — the drawn signature image and the verification event (e.g. one-time code confirmation) used to seal a deal.
- Support and feedback — messages you send us.
Data collected automatically
- Technical data — IP address, browser and device type, and approximate location derived from your IP.
- Usage and audit data — actions taken on a deal (created, viewed, signed, sealed) with timestamps, kept as part of the tamper-evident audit trail.
- Cookies and similar technologies — see the Cookies section below.
How and why we use your data
We only use your personal data where the law gives us a valid basis to do so:
- To provide the Service — creating, delivering, signing, and sealing agreements, and generating PDF receipts. Legal basis: performance of a contract.
- Security and integrity — verifying signers, preventing abuse and fraud, and maintaining the audit trail. Legal basis: legitimate interests and legal obligation.
- Communication — sending transactional notices such as signing requests and sealed-deal confirmations. Legal basis: performance of a contract.
- Improvement and analytics — understanding how the Service is used so we can improve it. Legal basis: consent or legitimate interests.
- Legal compliance — meeting accounting, tax, and other legal requirements. Legal basis: legal obligation.
We do not sell your personal data, and we do not use the content of your agreements to build advertising profiles.
Service providers we share data with
We rely on a small set of trusted providers (sub-processors) to run Proofo. They may process personal data on our behalf under contractual data-protection terms, and only as needed to deliver their part of the Service:
- Supabase — authentication, database, and file storage.
- Vercel — application hosting and performance analytics.
- Resend — delivery of transactional emails.
- Twilio — delivery of SMS one-time codes (only if you use SMS verification).
- Upstash — rate limiting and abuse protection.
We may also disclose data where required by law, to protect our legal rights, or in connection with a merger or acquisition (in which case we'll notify you).
International transfers
Some of our providers process data outside the European Economic Area. Where that happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision, so your data keeps an equivalent level of protection wherever it is processed.
How long we keep it
We keep personal data only for as long as we need it for the purposes above. In practice:
- Account data — for as long as your account is active, then deleted or anonymised after closure (subject to legal retention periods).
- Sealed agreements — retained so both parties keep access to their proof, within the history window of your plan, unless you delete them earlier.
- Records we must keep by law — e.g. invoices, kept for the period required by tax and accounting rules.
How we protect it
We use encryption in transit (HTTPS) and at rest, access controls, rate limiting, and the SHA-256 sealing that makes tampering with a completed deal detectable. No online service can guarantee absolute security, but we work to protect your data with measures appropriate to its sensitivity. If a breach affects your rights, we'll notify you and the relevant authority as required by law.
Your rights (GDPR)
If you are in the EEA or UK, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent at any time. To exercise any of these, email privacy@proofo.app — we respond within the statutory time limits.
You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz).
US state privacy rights
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect and how we use it, to request deletion or correction, and to opt out of the "sale" or "sharing" of personal information. We do not sell personal information. We will not discriminate against you for exercising these rights. Send requests to privacy@proofo.app.
Children
Proofo is not intended for anyone under 18, and we don't knowingly collect data from children. If you believe a minor has given us personal data, contact us and we'll delete it.
Changes to this policy
We may update this policy as the Service evolves or the law changes. We'll revise the "last updated" date above and, for material changes, give you notice through the Service or by email.