Who is responsible
AGVA-Plusz Bt. 1152 Budapest, Illyés Gyula utca 2-4. A. ép. fszt. 7., Hungary Company registration number: 01-06-795468 · EU VAT number: HU27322152 support@proofavo.com
We are established in Hungary, so the GDPR applies to everything described here.
Two different relationships
This is the part most policies blur, and it decides everything else.
If you are a print shop using Proofavo, we are the controller of your account data — your name, your email address, your workspace, your billing status. We decide how that is handled and this policy tells you how.
If you are a print shop's customer who received a review link, we are not your supplier. The shop decided to send you the link; the artwork is theirs; the comment you leave is on their proof. For that review data the shop is normally the controller and we act as their processor — we hold and process it on their instructions. For a narrow slice we are a controller in our own right: the operational data we need to run and secure the service itself, such as server logs, rate-limit counters and abuse prevention. Our lawful basis for that slice is our legitimate interest in keeping the service working and safe.
That matters practically: if you want your review data accessed, corrected or removed, the shop is the right first place to ask, and we will assist them as their processor. You can also write to us directly at support@proofavo.com and we will act, and tell them we did.
What we hold
About account holders
| Data | Why | Lawful basis |
|---|---|---|
| Name, email address, password (hashed) | to give you an account | performance of a contract |
| Workspace name and settings | to run the service | performance of a contract |
| Billing status, plan, subscription identifiers | to know what you have paid for | performance of a contract |
| Support correspondence | to answer you | legitimate interest |
| Questions you type into the in-app help assistant, and its answers | to answer you, and so a person can pick the conversation up if it did not | legitimate interest |
| Application logs and error reports | to keep the service working and diagnose failures | legitimate interest |
We do not hold your payment card details. See "Payments" below.
About reviewers — your customers
| Data | Why |
|---|---|
| Email address | so the shop can send the proof, and so an approval names somebody |
| Name, and the message they type | it is the content of the review |
| Comments and their position on the artwork | it is the content of the review |
| Whether and when a link was opened | so the shop knows the proof arrived |
| At approval: IP address and browser user-agent | so an approval can be evidenced if it is later disputed |
The lawful basis for this processing belongs to the shop, because the shop is the controller: typically the performance of its contract with you, or its legitimate interest in getting your artwork approved on the record. We process it on the shop's instructions. Where we process reviewer data for our own purposes — security logs and abuse prevention — the basis is our legitimate interest in running a safe service.
The IP address and user-agent are deleted twelve months after the approval, automatically. The approval itself — who, which version, its fingerprint, when — is kept for as long as it is needed to prove the approval history of a proof, which may be indefinitely: that record is the product's core purpose, and it is what the shop and you would both rely on if the approval were ever disputed.
We do not use reviewer data for marketing, for profiling, or for tracking across sites, and we send reviewers nothing except the emails the shop asks us to send. The only reviewer data we analyse at all is what abuse prevention needs — for example, counting requests from an address to stop somebody hammering a link.
About people on the waitlist
If you asked to be told when we open, we hold your email address and nothing else — no name, no company, nothing about where you came from. It is stored by Resend, the same provider that delivers the product's email, in an audience kept for that one purpose.
The confirmation screen then asks one optional question about how you send proofs today. That is measurement, not part of this list: whatever you answer is counted anonymously and is never stored beside your address. "About how the site and the product get used", below, says exactly what it holds.
Our own database holds no address from the waitlist. It holds one row per person: a one-way fingerprint of the address — computed with a secret key, so it cannot be turned back into an address or matched against a list of them — and the time you joined. That is there for one reason: the page offers early-access pricing to the first fifty people, and keeping that promise means being able to count them.
The lawful basis is your consent, given by submitting the form, and you can withdraw it at any time: every message we send from that list carries an unsubscribe link, and writing to support@proofavo.com does the same. Withdrawing stops future emails and removes the address and that row; it leaves nothing behind, and it does not affect the lawfulness of anything done while your consent stood. If you later rejoin, you join at the end of the list, because the place you held left with you.
Resend holds the list as our processor, on our instructions and for this one purpose.
We use it to tell you the product is open. Not to sell you anything else, and not shared with anyone.
About how the site and the product get used
We measure which of our own pages are opened, and a short list of actions. On the site: somebody joined the waitlist, asked to be told about product news, or opened the demo. Inside the product: artwork was uploaded, a round was published, a review link was produced, that link was sent to a customer, and a shop recorded an approval its customer had given elsewhere. It tells us where people give up on a screen we built, which is the only reason it exists.
Nothing is stored in your browser for it — no cookie, no local storage, no identifier. Visitors are counted by a hash our processor computes on its own servers from your IP address, your browser's user-agent and the site's hostname, against a random value that changes daily and is then discarded. It cannot be reversed, cannot be matched against another site, and stops identifying anyone after a day. The Cookie Statement sets out the mechanism in full.
What travels with an event is the page's address with identifiers removed —
/app/projects/:projectId, never the project — and never a name, an email
address, a filename, or the content of anything you make or send. Our lawful
basis is our legitimate interest in understanding whether the product works.
And a country, which is not looked up from your address. Each event carries a two-letter country code. Your browser tells every site it loads which time zone it is set to and which languages you read; the country is worked out from that inside your browser, and only the country is sent — the time zone and the language are used and discarded, because either narrows a person further than the country does. It says where your computer's clock is set rather than where you are, there is nothing finer behind it, and nothing finer can be derived from it. The Cookie Statement sets it out in full.
The one thing you can type into it. The confirmation shown after you join the waitlist asks a single question — how you send proofs today — with five answers to choose from, the last of them "something else", and a box for a sentence of your own. Both are optional and ignoring them costs you nothing. What you choose, and the sentence if you write one, arrive as ordinary anonymous measurement: they are not attached to your email address, which is held in a separate list and is not part of this, and there is no profile for them to be attached to. Before a sentence leaves your browser we remove anything shaped like an email address or a phone number, and the box itself stops at 200 characters. It is the only place in the product where something you wrote is measured at all, which is why the box says so.
You can switch it off, and it takes one click. Go to https://proofavo.com/analytics. No account, no form, no email to us, and it takes effect immediately for the browser you press it in. That choice is the one thing the measurement ever stores on your device — it has to be, or it would be forgotten on the next page — and it says nothing except that this browser is not to be counted. Each browser asks separately, and clearing your browsing data forgets it. Writing to support@proofavo.com still works if you would rather.
How long it is kept, and why the answer is unusual. The measurement itself is retained by our analytics processor for as long as our plan with them keeps it — currently up to seven years. That number is longer than anything else in this policy, and it matters less than any of them: the daily value used to compute the hash is destroyed at the end of the day it was used, and the IP address is not stored on the events at all. What remains after that day is a row saying a page was opened, tied to a string nobody — including us and including our processor — can connect back to a person or to another day's visit. There is nothing left in it to delete on your behalf, which is why we do not promise a shorter period we would have no way to enforce.
Reviewers are excluded from this entirely. On a review link the measurement code is not sent to the browser at all, so there is nothing to disable and nothing collected. The same applies to unsubscribe, password-reset and address-confirmation pages.
Who else sees it
Seven companies process data on our behalf, each under a data processing agreement:
| Processor | What it receives | Where |
|---|---|---|
| Supabase — database, authentication, file storage | everything: accounts, proofs, artwork, comments, approvals; from the waitlist, only the fingerprint described above | Ireland (eu-west-1) |
| Fly.io — where the application runs | data in transit while a request is served | Frankfurt, Germany |
| Resend — email delivery, and the waitlist list | recipient address and the message we send; the address of anyone who asked to be told when we open | United States |
| Sentry — error reporting | technical details of a failure | United States |
| Cloudflare (R2) — the artwork's backup copy | the uploaded files, nothing else | European Union |
| PostHog — product analytics | which page was opened, with identifiers stripped from the address, a short list of named actions, and a two-letter country worked out in the browser; nothing from a review link | Frankfurt, Germany |
| Anthropic — the in-app help assistant | the question you type, and facts about your own workspace: your plan, proof names and statuses, version numbers and dates, whether an approval exists and which version it names, review-link state, and whether an email was delivered. Never artwork, never a review link, never your customer's email address | United States |
The six above are processors: they act on our instructions, under data processing agreements. The backup at Cloudflare is a true backup — original artwork files only, written by our backup jobs and read by nothing else in normal operation, encrypted in transit and encrypted at rest by the provider. It is additive rather than a mirror, so a copy can outlive the original; that is deliberate, and it is bounded by the retention promises below.
Your artwork and your customers' data stay in the EU. They live in Ireland and are served from Frankfurt. The two US-based processors receive much narrower things — an email address and the message we send, and a scrubbed error report — and those transfers rely on the European Commission's standard contractual clauses in the agreements we hold with each of them, together with the supplementary measures described here: minimisation of what is sent at all, and scrubbing before an error report leaves our servers. Each provider's own privacy documentation is available on their site.
Our data processing addendum and the current sub-processor list are available on request at support@proofavo.com.
Dodo Payments is different, and the difference matters. They are our merchant of record: when you subscribe, they are the seller. For the payment data they collect from you they are an independent controller in their own right, not our processor — they decide how it is handled, under their own privacy policy, and answer for it directly. We receive back only an identifier and a subscription status. Their policy: https://dodopayments.com/legal/privacy-policy
A tool your workspace connects itself is different again. If your workspace connects Asana from Settings → Integrations, we send workflow data there on your instruction: the proof's name, its version number, what happened and when, and a link back to Proofavo that needs a sign-in. Never the review link, never your customer's name or email, never anything they wrote, and never the artwork. That account is yours and the relationship is between you and them, under their privacy policy; you can disconnect it at any time, and tasks already created stay in your Asana.
Error reports are deliberately restrained: no screen recording, no request bodies, and review links, signed URLs and keys are stripped out before a report leaves our servers.
And us
Sometimes we have to look inside an account ourselves — to find out why a proof will not open, to answer a question you have asked us, or to look into a report of misuse. When we do, four things are true.
We can only read. Our support tools have no way to write to your account. Nothing can be approved, commented on, changed or deleted from them — this is how they are built rather than a rule we ask our staff to follow, so there is no version of it that somebody forgets.
Your artwork is not included by default. A support session shows that a file exists, its name and its size. Opening the file itself is a separate step, is available to fewer people, and is recorded on its own.
It is time-limited and written down. A session lasts thirty minutes and ends by itself. Who opened it, which account, when, and why is kept in a log we cannot edit or delete, for two years.
We tell you. The account's owner receives an email saying that we opened the account, when, and why. The one exception is an investigation into misuse of the service, where telling you at the time would defeat the point — that notice is held back rather than cancelled, and it is sent when the investigation closes. That we did not write to you at the time is itself recorded.
Payments
Dodo Payments acts as merchant of record. They collect and hold card details; we never see them. We hold an identifier that tells us which subscription belongs to which workspace, and its status.
How long we keep things
We keep personal data only as long as the purposes in this policy need it and as the law requires. Set out in full in the Data Retention Policy; in short: your work for as long as your account exists and at least twelve months after a cancellation; approval records for as long as they are needed to preserve the proof history, which may be indefinitely; the approval's network trace for twelve months; application logs and error reports for 30 days; the usage measurement of our own pages for as long as our analytics plan retains it, which is longer but ceases to identify anyone after the day it was collected — see above.
How we protect it
Technical and organisational measures, the short version: data is encrypted in transit everywhere; artwork and review pages are reachable only through short-lived signed URLs and unguessable tokens; production access is limited to the people who operate the service; the database enforces per-workspace isolation at the row level rather than trusting application code; and error reports are scrubbed of tokens, links and keys before they leave our servers. No system is perfectly secure, but the design assumes that and keeps the blast radius of any one failure small.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to processing based on legitimate interest. You can also ask for it in a portable form where the GDPR gives that right. If a processing rests on your consent — the waitlist — you can withdraw it at any time, without affecting what was lawfully done before.
Who to ask depends on which relationship you are in. An account holder writes to us directly. A reviewer — a shop's customer — should normally ask the shop first, because the shop is the controller of the review data; we assist them as their processor, and we act ourselves where the data is ours.
Write to support@proofavo.com. We aim to acknowledge a request within 72 hours, and we will respond within one month, unless the GDPR allows that period to be extended for a complex request — in which case we will say so within the first month.
When you delete your account yourself we send one email to the address it signed in with, confirming what was deleted. It is the only way somebody would learn that a person with access to their signed-in session had done it. Nothing of the address is kept afterwards.
You can delete your account yourself, under Settings → You. If you are the only person in your shop, the shop goes with it: the proofs, the artwork, the comments and the approvals, from our database, from storage and from the backup copy. If colleagues remain, your account and your access go and their work is untouched. It is immediate and there is no undo.
Three things the button will not do, and each says so on the screen rather than failing afterwards: leave a shop with people in it and no Owner, delete a workspace whose subscription the payment provider is still charging, or erase your name from an approval you recorded on a customer's behalf in a shop that is staying — that record may be the only evidence the shop and its customer have of what was agreed. Write to support@proofavo.com in those cases and a person will handle it, including weighing a deletion request against a record somebody else may need.
If you are unhappy with how we have handled your data, contact us first and we will try to put it right quickly. You can also complain to the Hungarian supervisory authority at any time:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) 1055 Budapest, Falk Miksa utca 9-11. naih.hu
Cookies
Proofavo sets one kind of cookie: the session cookie that keeps you signed in. It is strictly necessary, and there is no consent banner because there is nothing to consent to. The usage measurement described above stores nothing on your device unless you switch it off, in which case it keeps that one answer — no cookie, no identifier, nothing that recognises you — and consent under the ePrivacy rules is about reading and writing on your device. There are no marketing pixels and no embedded third-party trackers; the measurement is sent to our own domain and forwarded from our server, so your browser never contacts a third party. If any of that ever changes, a consent mechanism arrives with it. See the Cookie Statement.
Children
Proofavo is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16; if you believe a child's data has reached us, write to support@proofavo.com and we will delete it.
Changes
We will tell account holders before a material change takes effect. The version and date at the top identify this text.