Compliance & Data Collection
Last updated: 11 May 2026
This page is a plain-English overview of how PROOFsure handles data, which laws we operate under, and the controls we put in place. It is a summary — the binding documents are the Privacy Policy and the Terms of Service.
1. Frameworks we work to
- UK GDPR and the Data Protection Act 2018 — for personal data.
- Privacy and Electronic Communications Regulations (PECR) — for cookies and direct marketing.
- Consumer Rights Act 2015 and Consumer Contracts Regulations 2013 — for fairness of terms (we trade B2B; see Terms §4).
- HMRC record-keeping rules — 6 years retention of accounting records.
- PCI-DSS — handled on our behalf by Stripe (Level 1).
2. What data we collect, at a glance
| Category | Examples | Why |
|---|---|---|
| Account | Email, password hash, business name | Provide the Service (contract) |
| Job content | Job title, line items, photos, customer details you enter | Generate reports/invoices on your instruction |
| Billing | Stripe customer ID, plan, status | Take subscription payments (contract + legal) |
| Technical | IP, device, error logs | Security, debugging (legitimate interests) |
3. How data flows
When you upload a photo to a job, the data path is:
- Your device sends the file over HTTPS (TLS 1.2+) to our storage in the EU.
- The image is stored encrypted at rest in our EU-hosted file storage (Supabase, Frankfurt).
- For AI drafting, the image plus your job context is sent over HTTPS to Google's Gemini API via the Lovable AI Gateway. Transfer to the United States is covered by UK IDTA + SCCs. Google does not train on API data, and the gateway operator processes the request only to route it.
- The draft text comes back to our server and is saved against your job in the EU database.
- You review and edit the draft. Nothing is shared with your customer until you press send.
4. Where data lives
- Database, auth, file storage: Supabase (EU — Frankfurt, Germany).
- AI processing: Lovable AI Gateway (EU) routing to Google LLC (United States).
- Payments: Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (United States).
5. Security controls
- HTTPS everywhere; HSTS enabled.
- Passwords stored as salted hashes; we never see them.
- Row Level Security on every database table — accounts cannot see each other's data.
- Principle of least privilege for service credentials and API keys.
- Encryption at rest for storage and database backups.
- Time-limited signed URLs for photo access.
- Automatic session expiry and password-reset flows.
- Error monitoring with PII redaction.
6. Sub-processor list
- Supabase — hosting, database, auth, storage. EU.
- Lovable AI Gateway / Google — AI photo analysis and report drafting (Gemini API). EU gateway, US model host (UK IDTA in place).
- Stripe — payments. EU/US.
We will give at least 30 days' notice before adding a new sub-processor that materially changes how your data is handled.
7. Your rights, in one place
- Export your jobs and reports from your account at any time.
- Delete a job, an attachment or your whole account from settings.
- Email hello@proofsure.co.uk for access, rectification, restriction, objection or any other request under UK GDPR.
- Complain to the ICO at ico.org.uk if you are not satisfied with our response.
8. AI & accuracy claims
We describe the AI feature as assistive. It produces a draft. Every report you send is reviewed and approved by you. We do not claim that AI output is accurate, complete or suitable for any purpose without your review. This is a deliberate choice to keep responsibility for the final document where it belongs — with you, the qualified business issuing it.
9. Marketing claims on our website
We aim to keep marketing copy honest and within the Advertising Standards Authority's CAP Code:
- "In minutes" / "60 seconds" refers to typical end-to-end report generation time when you have photos and job details ready; it is not a guaranteed service level.
- Any testimonials shown are from real customers and held on file.
- Pricing shown excludes VAT unless stated. Trial periods, refund rules and cancellation are described in the Terms.
10. Reporting a vulnerability
If you believe you have found a security issue, please email security@proofsure.co.uk (or hello@proofsure.co.uk if that address is not yet provisioned). Please do not publicly disclose the issue until we have had a reasonable opportunity to fix it.
This document is provided for transparency and to meet our obligations under UK GDPR and the Data Protection Act 2018. It is not a substitute for independent legal advice for users. Questions? Email hello@proofsure.co.uk.