1. Our role
ProofPost acts as controller for account, billing, website, and support information. When processing reviews, connected-platform data, or publishing content on a customer’s instructions, ProofPost may act as that customer’s processor. The customer remains responsible for its own notices, lawful basis, and instructions.
2. Data protection principles
We aim to process data lawfully, fairly, and transparently; collect it for specified purposes; minimise what we use; keep it accurate; retain it only as needed; and protect its confidentiality, integrity, and availability.
3. Individual rights
Eligible individuals can request access, correction, erasure, restriction, portability, or object to processing, and can withdraw consent. Requests may be sent to hello@proofpost.pro. We respond within the time required by applicable law—generally one month under GDPR—subject to identity verification and lawful extensions.
4. Processors and transfers
We assess service providers for appropriate privacy and security commitments and put processor terms in place where required. International transfers use a recognised safeguard such as adequacy decisions or approved contractual clauses. A current subprocessor list and data processing addendum will be made available before serving business customers that require them.
5. Security and incidents
Controls are selected according to risk and may include access restriction, encryption in transit, logging, backups, vulnerability management, and staff or contractor confidentiality. We assess suspected personal-data breaches and notify affected customers or authorities where law requires it.
6. Complaints and regulator
Please contact us first so we can help. You may also complain to the data protection authority where you live or work, or where an alleged infringement occurred. ProofPost’s lead supervisory authority will be identified when its legal establishment is finalised.