Why this exists
When you send a proof to your customer, you decide what to send and to whom. That makes you the controller of your customer's data, and it makes us your processor. Article 28 of the GDPR requires a written contract between us for that, setting out what we may do with the data and what we owe you.
This is that contract. You do not need to sign it. It forms part of the Terms of Service and takes effect when you open a workspace — the same arrangement our own suppliers offer us. If you need a countersigned copy for your records, write to support@proofavo.com and we will provide one.
The parties are AGVA-Plusz Bt. (1152 Budapest, Illyés Gyula utca 2-4. A. ép. fszt. 7.; company number 01-06-795468) and the business that opens the workspace.
1. What we process, and why
Subject matter: providing Proofavo — storing artwork, showing it to the people you send links to, collecting their comments, and recording approvals.
Duration: for as long as your workspace exists, plus the retention periods in the Data Retention Policy.
Nature and purpose: storage, display, email delivery of links you ask us to send, and the production of an approval record.
Types of personal data:
- names and email addresses of your customers and their colleagues;
- the text they write — comments, change requests, approval messages;
- whether and when a review link was opened;
- at approval: the IP address and browser user-agent of the person approving, deleted automatically twelve months later.
Categories of data subject: your customers and their staff; your own team members you invite into the workspace.
2. We act on your instructions
We process this data only to provide the service, as described in the Terms and this Addendum, and on your documented instructions. Using the product is an instruction: uploading artwork, sending an invitation, revoking a link.
If we ever believe an instruction breaks data-protection law, we will tell you rather than quietly comply.
We do not sell your data, we do not use it to train anything, and we do not use it for our own purposes.
3. Confidentiality
Everyone with access is bound to confidentiality. Access is limited to the people who need it to run and support the service.
4. Security
The measures are described in full on the Security page, and the substance of them is:
- separation between workspaces enforced by the database, not by application code remembering to ask, and tested by calling every privileged function as an outsider;
- review links stored as a SHA-256 hash, expiring 60 days after last use, and revocable by you at any moment;
- artwork stored privately and served through URLs valid for three minutes;
- encryption in transit throughout, and at rest by our infrastructure providers;
- error reports scrubbed of tokens, links and keys before they leave our servers, with no session recording and no request bodies.
5. Sub-processors
You give us general authorisation to use the sub-processors listed in
Subprocessors.md, which is kept current and public.
We will give you 30 days' notice before adding a new one. If you object on reasonable data-protection grounds within that period, we will discuss it with you; if we cannot resolve it, you may terminate the affected part of the service and we will refund any prepaid amount for time you do not use.
Every sub-processor is bound by obligations no weaker than these.
6. Helping you with your obligations
If one of your customers exercises a right — access, correction, deletion, portability, objection — and asks us instead of you, we will act and tell you that we did, because it may change a record you rely on. If the request needs your decision, we will pass it to you and wait.
If there is a personal data breach affecting your data, we will notify you without undue delay and within 48 hours of becoming aware, with what we know and what we are doing. You remain the one who decides whether to notify the authority and the people affected.
We will help you with data protection impact assessments and prior consultation if you need it, given the information we have.
7. What happens at the end
When your workspace closes, the Data Retention Policy governs. In summary: we delete nothing automatically, artwork is kept for at least twelve months, and approval records are kept indefinitely because they are the evidence the product exists to produce.
You can ask us to delete or return everything at any time, and we will — subject to one honest limit. An approval record cannot be stripped of who approved what without ceasing to be a record of anything. If you ask for that, we will tell you before we do it.
8. Audits
We will give you the information you reasonably need to show that we are meeting these obligations, including answering questions in writing. For an on-site audit, ask; we are a small company and we will agree something proportionate rather than pretend to a process we do not have.
9. Location and transfers
All artwork, proofs, comments and approvals are stored in Ireland and served from Frankfurt — inside the EU, with no transfer to assess.
Two sub-processors are in the United States and receive far less: email addresses and the message text we send on your behalf (Resend), and scrubbed technical error reports (Sentry). Those transfers are covered by the European Commission's standard contractual clauses in our agreements with each of them.
Dodo Payments is not a sub-processor under this Addendum. As merchant of record they are an independent controller of your billing data, and their own privacy policy governs it.
10. Contact
support@proofavo.com — including for anything in this Addendum.