1. Our data-protection roles
PrimoDevStudio is controller for ProofPost account administration, service security, support, website, and subscription-status data. When a business customer instructs ProofPost to import, transform, store, or publish reviews or other personal data, that customer is normally the controller and ProofPost acts as its processor.
Customers are responsible for their own privacy notices, lawful basis, connected-account permissions, review reuse, and instructions to ProofPost.
2. Data-protection principles
We process personal data lawfully, fairly, and transparently; use it for specified purposes; limit collection to what is needed; support accuracy; retain it only for justified periods; and apply safeguards appropriate to the risk.
3. Processors and independent controllers
Core providers include Supabase for authentication, database, and storage; Vercel for hosting and delivery; and Sentry for privacy-filtered error monitoring. Google Analytics is used for website measurement only after analytics consent. Connected review, commerce, and social providers process data when a customer authorises them.
Dodo Payments acts as Merchant of Record and an independent controller for buyer, payment, tax, fraud, refund, and transaction-compliance data. Its handling is described in the Dodo Payments Privacy Policy.
4. International transfers
Service providers may process data in multiple countries. Where data-protection law requires a transfer safeguard, we use an adequacy decision, approved standard contractual clauses, or another legally recognised mechanism and apply supplementary safeguards where appropriate.
5. Security and incidents
Measures include least-privilege access, encryption in transit, managed authentication, separation of public and private credentials, monitoring, backups, dependency maintenance, and incident response. We investigate suspected personal-data breaches and notify affected controllers, individuals, or authorities within legally required periods where notification is required.
6. Individual requests
Requests for access, correction, erasure, restriction, portability, objection, or consent withdrawal can be sent to hello@proofpost.pro. We ordinarily respond within one month where GDPR applies, subject to identity verification, lawful extensions, and permitted exceptions.
If the request concerns data controlled by a ProofPost customer, we will direct it to that customer or assist the customer with its response.
7. Complaints and business enquiries
You may complain to the data-protection authority where you live or work, or where an alleged infringement occurred. Business customers can contact hello@proofpost.pro for processor terms, security information, or assistance with a data-protection assessment.