ProofPost Back to ProofPost

DATA PROTECTION

Data protection

Our controller and processor roles, privacy safeguards, and individual rights.Last updated 29 August 2026

1. Our data-protection roles

PrimoDevStudio is controller for ProofPost account administration, service security, support, website, and subscription-status data. When a business customer instructs ProofPost to import, transform, store, or publish reviews or other personal data, that customer is normally the controller and ProofPost acts as its processor.

Customers are responsible for their own privacy notices, lawful basis, connected-account permissions, review reuse, and instructions to ProofPost.

2. Data-protection principles

We process personal data lawfully, fairly, and transparently; use it for specified purposes; limit collection to what is needed; support accuracy; retain it only for justified periods; and apply safeguards appropriate to the risk.

3. Processors and independent controllers

Core providers include Supabase for authentication, database, and storage; Vercel for hosting and delivery; and Sentry for privacy-filtered error monitoring. Google Analytics is used for website measurement only after analytics consent. Connected review, commerce, and social providers process data when a customer authorises them.

Dodo Payments acts as Merchant of Record and an independent controller for buyer, payment, tax, fraud, refund, and transaction-compliance data. Its handling is described in the Dodo Payments Privacy Policy.

4. International transfers

Service providers may process data in multiple countries. Where data-protection law requires a transfer safeguard, we use an adequacy decision, approved standard contractual clauses, or another legally recognised mechanism and apply supplementary safeguards where appropriate.

5. Security and incidents

Measures include least-privilege access, encryption in transit, managed authentication, separation of public and private credentials, monitoring, backups, dependency maintenance, and incident response. We investigate suspected personal-data breaches and notify affected controllers, individuals, or authorities within legally required periods where notification is required.

6. Individual requests

Requests for access, correction, erasure, restriction, portability, objection, or consent withdrawal can be sent to hello@proofpost.pro. We ordinarily respond within one month where GDPR applies, subject to identity verification, lawful extensions, and permitted exceptions.

If the request concerns data controlled by a ProofPost customer, we will direct it to that customer or assist the customer with its response.

7. Complaints and business enquiries

You may complain to the data-protection authority where you live or work, or where an alleged infringement occurred. Business customers can contact hello@proofpost.pro for processor terms, security information, or assistance with a data-protection assessment.

ProofPostOperated by PrimoDevStudio
PrivacyTermsRefundsCookiesData protection
Questions? Email us