Data Processing Agreement
DraftLast updated: 16 August 2026
This agreement sets out the terms on which pro-posal.io processes personal data on behalf of its customers. It forms part of the Terms of Serviceand constitutes the written contract required by Article 28 of the UK GDPR. It applies to every customer on acceptance of those terms and requires no separate signature. Where a customer's own client requires an executed copy, one will be provided on request to darren@pro-posal.io.
1. The parties and their roles
You (the customer) are the controller. You decide what personal data goes into the service and why.
We (pro-posal.io, operated by [LEGAL ENTITY NAME, COMPANY NUMBER AND REGISTERED ADDRESS TO BE COMPLETED BEFORE LAUNCH]) are the processor. We act only on your instructions.
We are a separate controller for your own account and billing data. That is covered by our Privacy Policy, not by this agreement.
2. What we process, and for how long
- Subject matter: providing proposal software that lets you build, send, track and record acceptance of proposals.
- Duration: for as long as your subscription is active, plus the deletion period in section 9.
- Nature and purpose: storing, organising, displaying, transmitting, backing up and deleting the content you put into the service, and generating analytics about how your proposals were read.
- Categories of data subject: your staff, and the clients and contacts you send proposals to.
- Types of personal data: names, email addresses, job titles, phone numbers, photographs, company and venue details, the content of proposals and messages, proposal engagement records (opens, section view times, browser type and a hashed IP address), and acceptance records (typed name, drawn signature, timestamp and selected options).
- Special category data: the service is not designed for it and you should not put it in. If you do, you remain responsible for having a lawful basis under Article 9.
3. Our obligations
We will:
- process personal data only on your documented instructions, which include your use of the service and its settings, unless we are required to do otherwise by law, in which case we will tell you first unless the law forbids it;
- ensure everyone authorised to access the data is bound by confidentiality;
- apply the technical and organisational measures in section 5;
- respect the conditions in section 4 for engaging sub-processors;
- help you respond to requests from individuals exercising their rights, using the tools in the product where possible and otherwise on request;
- help you with security, breach notification, impact assessments and consultations with the regulator, taking into account what we know and what you do not;
- delete or return the data at the end of the service as set out in section 9;
- make available the information needed to demonstrate compliance with Article 28, and allow audits as set out in section 10;
- tell you promptly if we think an instruction from you breaches data protection law.
4. Sub-processors
You give us general authorisation to use the following sub-processors:
- Supabase, database, authentication and file storage.
- Vercel, application hosting and delivery.
- Amazon Web Services, media storage and encrypted backups, London region (eu-west-2).
- Stripe, subscription billing and payments.
- Resend, transactional email.
- Anthropic, the optional AI draft assistant, and only for customers who use it.
We impose the same data protection obligations on each, and we remain fully liable to you for their performance. We will give you at least 30 days' notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within that period and we will work with you to find an alternative; if we cannot, you may cancel without penalty and receive a pro-rata refund of any prepaid fees.
Current RMS is not a sub-processor. It is your own system, which you connect and control, and your use of it is governed by your agreement with them.
5. Security measures
- All data encrypted in transit using TLS, and at rest by our hosting providers.
- Passwords stored only as one-way hashes; we cannot see or recover them.
- Tenant isolation enforced at the database level and re-checked on every application route.
- Role-based access inside your account, with owner, manager and team member permissions.
- Secrets, including integration API keys, never sent to a browser.
- Rate limiting on sign-in, registration and password reset, and lockout after repeated failed attempts on password-protected proposals.
- Proposal viewers' IP addresses stored only as one-way hashes.
- Optional password protection and expiry dates on individual proposals.
- Encrypted nightly database backups, retained for 7 days.
- Dependency and platform security reviews on a documented monthly and quarterly schedule.
6. Personal data breaches
We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your data. The notice will describe what happened, the categories and approximate number of people and records involved as far as we know them, the likely consequences, and what we are doing about it. We will keep you updated as we learn more. Notifying your regulator and the people affected remains your decision as controller, and we will give you what you need to make it.
7. Individuals exercising their rights
You can access, correct, export and delete data yourself inside the application. If someone contacts us directly about data you control, we will not respond substantively; we will tell them to contact you and forward the request promptly. Where you need help we cannot provide through the product, we will assist at no charge for reasonable requests.
8. International transfers
Data is held in the United Kingdom and the European Economic Area wherever the provider offers it. Some sub-processors, including Stripe, Resend and Anthropic, are based in the United States. Those transfers rely on appropriate safeguards, normally the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. We will not transfer your data outside the UK or EEA without such a safeguard in place.
9. Deletion and return
You can export your proposals as PDFs at any time while your subscription is active. When your subscription ends, your account is scheduled for permanent deletion 30 days later, and a daily job then removes the company and all its data. Encrypted backups containing the data expire automatically within a further 7 days. If you want earlier deletion, ask and we will carry it out.
10. Audit
On reasonable written notice, and no more than once a year unless a regulator or a breach requires otherwise, we will provide the information reasonably needed to demonstrate compliance with this agreement and answer a security questionnaire. Where an on-site audit is genuinely required, we will cooperate, at your cost, at a time that does not disrupt the service.
11. Liability and precedence
The limitations of liability in the Terms of Service apply to this agreement. If there is any conflict between this agreement and the Terms of Service on the processing of personal data, this agreement takes precedence.
12. Changes
We may update this agreement to reflect changes in the service or the law. We will change the "last updated" date and tell customers by email about significant changes. We review it against what the software actually does at least every three months.
Contact
Questions, signed copies, or security questionnaires: darren@pro-posal.io.