Privacy policy
What data we process, why, how long we keep it and how you use your rights.
1. Who is responsible for your data
The data controller is the company below. The controller decides why and how the data is used.
Who runs Proofen
- Company: ClearSecurity Vision S.R.L.
- Company registration number (CUI): 32776248
- Registered office: Feleacu village, Feleacu commune, no. 24/F, Cluj county, Romania
- Trade register: J2014000420120 (old format: J12/420/2014)
- VAT: the company is not registered for VAT. VAT is collected by Paddle, which resells Proofen as the Merchant of Record.
- Contact: contact@proofen.app
For any question about your data, you can contact us at contact@proofen.app. We reply within one month at most.
The data your company enters into the app belongs to your company: the profile, the documents and the evidence log. For that data your company decides, and we process it on its behalf.
For your Proofen account, the waiting list, statistics and e-mails, we are the controller. For the data your company enters into the app, we are the company’s processor. For payments, Paddle is a separate controller, not our sub-processor.
For that data, the rules between your company and us are set out in the data processing agreement, an annex to the terms.
Read the data processing agreement.
2. What data we process and why
| Data | Purpose | Lawful basis | How long we keep it |
|---|---|---|---|
| Account: e-mail, password (kept only as a cryptographic hash) and the setup of your two-step sign-in. | So you can sign in and so we can protect your account. | Contract (point b) | As long as the account exists. After deletion, they are deleted from the app at once and from backups within 30 days. |
| Organisation and company profile: name, country, CUI, your answers, the company's public data from the Romanian tax authority (ANAF). | To generate the company's documents. | Contract (point b) | As long as the organisation exists in the app, plus 30 days in backups. |
| Generated documents, their fingerprints and the evidence log: the action, the time, the account, the IP address and the browser. | Evidence for audits, which your company needs. | Contract and your company's legitimate interest in keeping evidence (points b and f) | As long as the organisation exists. Once recorded, a log entry can't be changed or deleted in the app. If you delete your account, the records linked to your account remain in the company's log. |
| Waiting list: e-mail, language and what you are interested in. | To tell you when we launch. | Your consent, given by confirming the e-mail (point a) | Until you withdraw consent. In any case, no later than 12 months after launch we automatically delete the whole list. If you do not confirm the address, we delete it after 30 days. |
| Orders: what you bought, the price, the Paddle transaction code, the organisation. | To provide access to what you paid for. | Contract and legal obligations (points b and c) | As long as the organisation exists. Paddle issues and keeps your invoice. We keep our own accounting records, for example Paddle’s payout statements, as long as accounting law requires (quote below). |
| E-mails we send: sign-in links, account and waiting-list confirmations. | Operating the account and the waiting list. | Contract or consent (point b or a) | Resend keeps the content, delivery data and logs for 30 days, in the US. |
| Technical errors: the type of error, the page and the browser. Before sending, we replace company and document codes, and the secret part of links, with neutral values (pseudonymisation). We do not send the e-mail address, the IP address or the content of forms. | Fixing errors quickly. | Our legitimate interest (point f) | 30 days, at Sentry, in its EU region (Frankfurt). |
| Anti-abuse counters: a fingerprint of the IP address, computed with a secret key, and the number of attempts. Forms that send an e-mail also count by a fingerprint of the e-mail address. The IP address and the e-mail address themselves are not stored here. | To stop attacks, for example too many sign-in requests. | Our legitimate interest (point f) | Usually one hour; 25 hours at most. |
| Visit statistics: the step (for example, "opened a kit"), the page, the name of the site you came from, the country and the day. | To see where visitors stop and what we can make clearer. | Our legitimate interest (point f) | 13 months. They hold no cookies, no IP address and no identifier, so we cannot recognise you from them. |
| Cloudflare Web Analytics statistics: the page, the site you came from, the country, the browser and how long the page takes to load. | To see which pages people read and how fast they load. | Our legitimate interest (point f) | No cookies and no identifiers. Cloudflare keeps the full data for 7 days, then only a sample of about 10%. Cloudflare does not publish how long it keeps the sample. |
“Processing shall be lawful only if and to the extent that at least one of the following applies: (a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes; (b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; (c) processing is necessary for compliance with a legal obligation to which the controller is subject; […] (f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”
Regulation (EU) 2016/679 (GDPR), Article 6(1), excerpt (eur-lex.europa.eu)
What this means for your company: Each row in the table has one of these bases. The letters in the "Lawful basis" column point to them.
“Registrele de contabilitate obligatorii și documentele justificative care stau la baza înregistrărilor în contabilitatea financiară se păstrează în arhiva persoanelor prevăzute la art. 1 timp de 5 ani calculați de la data de 1 iulie a anului următor celui încheierii exercițiului financiar în care au fost întocmite, inclusiv pentru statele de salarii.”
What this means for your company: Paddle sells and invoices, so Paddle keeps the invoice and the payment data. We keep the records behind our own company’s accounts, for example Paddle’s payout statements. The period is 5 years from 1 July of the year after the financial year closes.
If your browser sends the "Do Not Track" or "Global Privacy Control" signal, we do not include you in the statistics.
“In addition to the information referred to in paragraph 1, the controller shall, at the time when personal data are obtained, provide the data subject with the following further information necessary to ensure fair and transparent processing: […] (e) whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the data subject is obliged to provide the personal data and of the possible consequences of failure to provide such data; (f) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.”
Regulation (EU) 2016/679 (GDPR), Article 13(2)(e) and (f), excerpt (eur-lex.europa.eu)
What this means for your company: To have an account, your e-mail address is required: without it we cannot enter into the contract. You provide company data as needed; without it we cannot generate the documents. We make no automated decisions about you and create no profiles.
3. Providers that process data on our behalf
| Provider | What it does | Where the data is |
|---|---|---|
| Supabase (Supabase Pte. Ltd., Singapore) | Database and account sign-in. | Frankfurt, Germany (EU). |
| Cloudflare (Cloudflare Inc., US) | Hosts the website and the app, stores the files (Cloudflare R2) and forwards e-mail sent to contact@proofen.app. Through Cloudflare Web Analytics it counts visits, without cookies. | Files: in the EU jurisdiction of Cloudflare R2. Web requests pass through the Cloudflare data centre closest to you. |
| Resend (Plus Five Five, Inc., US) | Sends all e-mails, including sign-in links. | US. Resend sends e-mail from its EU region (eu-west-1, Ireland), but stores all data in the US. |
| Fly.io (US) | Turns documents into PDF files. It receives only the data that appears in the document, for example the company name, and returns the file. Other profile data, such as the contact person, is not sent. | Amsterdam, the Netherlands (EU). The working files are deleted right after conversion. |
| Paddle (Paddle.com Market Limited, United Kingdom; for buyers in the US, Paddle.com Inc.) | Takes payments, issues invoices and calculates VAT, only once payments are switched on. It does not process data on our behalf: for payment data, Paddle is a separate controller, under Paddle's policy. | Paddle.com Market Limited is in the United Kingdom; for buyers in the US, Paddle.com Inc. Paddle may transfer the data onwards between its entities, under Paddle's policy (standard contractual clauses). |
| Sentry (Functional Software Inc., US) | Monitors technical errors. It does not receive the IP address, and company and document codes are removed from page addresses and messages. | Error events: Sentry’s EU region (Frankfurt). Our account and Sentry organisation settings: US. |
“Because our business is international, we transfer Personal Data among the various Paddle entities, and to third parties who Process Personal Data on our behalf as noted in Section E above, in connection with the purposes set out in this Notice. […] Otherwise, if we transfer Personal Data from the UK/EEA to countries not deemed to be in an Adequate Jurisdiction, we use Standard Contractual Clauses and other appropriate safeguards.”
Paddle, Privacy Notice, section F, last updated 16 March 2026 (paddle.com/legal/privacy)
What this means for your company: For payment data, Paddle itself decides where to transfer it, between its entities and to its providers. Outside the United Kingdom and the European Economic Area it uses standard contractual clauses.
4. Transfers outside the European Union
The database is in Frankfurt (Supabase), files are in the EU jurisdiction of Cloudflare R2, and PDF conversion runs in Amsterdam (Fly.io). Some data does leave the European Union, though:
- E-mail: Resend stores the content, delivery data and logs in the US. This does not depend on the region it sends from.
- Technical errors: Sentry keeps error events in Frankfurt. Our account and Sentry organisation settings are in the US, though.
- Payments: Paddle.com Market Limited is in the United Kingdom. For buyers in the US, the seller is Paddle.com Inc., in the US.
- Supabase is a Singapore company, and Cloudflare, Fly.io and Sentry are US companies. They may have technical access from outside the Union, for example for support. At Supabase, access may come from Singapore or the US, under standard contractual clauses.
For each provider, the transfer relies on the mechanisms in the table below, set out in the provider's data processing agreement. The standard contractual clauses are those of European Commission Implementing Decision (EU) 2021/914.
| Provider | Transfer mechanism | Document, checked on 29 September 2026 |
|---|---|---|
| Supabase | Standard contractual clauses. For the United Kingdom, also the addendum of the British data protection authority. | Supabase's data processing addendum, version 1 of 1 August 2026. |
| Cloudflare | Certification under the EU-US Data Privacy Framework, plus standard contractual clauses. | Cloudflare's agreement, version 6.4, effective from 3 April 2026. |
| Resend | Certification under the EU-US Data Privacy Framework, plus standard contractual clauses. | Resend's agreement, last updated 31 December 2025. |
| Fly.io | Certification under the EU-US Data Privacy Framework, with the extension for the United Kingdom. | Fly.io's data processing agreement, pre-signed by Fly.io and active once we sign it too (Fly.io compliance page). Fly.io's policy for the EU-US Data Privacy Framework, effective from 18 August 2025. |
| Sentry | Certification under the EU-US Data Privacy Framework. If the certification no longer applies, standard contractual clauses. | Sentry's agreement, version 5.1.0, effective from 29 May 2024. It applies once we accept it electronically. |
| Paddle | Standard contractual clauses (module two), and for the United Kingdom, the British addendum. For the United Kingdom itself, the adequacy decision below. | Paddle's addendum, last updated 1 February 2023. It is the version published on 29 September 2026. |
- Supabase's agreement
- Cloudflare's agreement
- Resend's agreement
- Fly.io's compliance page, with the data processing agreement
- Fly.io's Data Privacy Framework policy
- Sentry's agreement
- Paddle's agreement
Paddle.com Market Limited is in the United Kingdom. The European Commission decided that the United Kingdom protects data adequately. In December 2025, the Commission extended that decision:
“This Decision shall expire on 27 December 2031, unless extended in accordance with the procedure referred to in Article 93(2) of Regulation (EU) 2016/679.”
What this means for your company: Data can go to Paddle, in the United Kingdom, without a separate authorisation, at least until 27 December 2031.
5. Your rights
- To find out what data we hold about you and get a copy.
- To correct wrong data.
- To ask for your data to be deleted.
- To ask for restriction of processing.
- To receive your data in a structured format and to transmit it to another controller.
- To object to processing based on our legitimate interest.
- To withdraw your consent at any time, for example for the waiting list.
How to exercise your rights: on the Account page you can download your account data in one file or delete your account. The company's evidence log is exported from the Evidence page, by the roles allowed to do so, and documents are downloaded from the Documents page. If you are the only owner of an organisation, request its closure at contact@proofen.app; we will close it and delete the account within 30 days. For any other request, you can contact us at the same address.
6. Complaints
“Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation.”
Regulation (EU) 2016/679 (GDPR), Article 77(1) (eur-lex.europa.eu)
What this means for your company: You can lodge a complaint with a data protection authority. In Romania, it is ANSPDCP.
ANSPDCP (the Romanian data protection authority): B-dul G-ral. Gheorghe Magheru 28-30, sector 1, postcode 010336, Bucharest, Romania. E-mail: anspdcp@dataprotection.ro. Website: dataprotection.ro.
Please contact us first. Many requests can be resolved directly.
7. How we protect the data
Each organisation has access only to its own data, through rules enforced in the database. Connections are encrypted. Backups are encrypted and deleted after 30 days.
8. Children
Proofen is intended for companies. We do not intentionally collect data about children.
9. Changes
When we change this policy, we also update the version date shown at the start of the document. If the change is significant, we notify you by e-mail.