Privacy Policy
DraftLast updated: 16 August 2026
This policy sets out how pro-posal.io processes personal data, the lawful bases on which it does so, and the rights available to the individuals concerned. It is issued under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
It applies to three groups:
- Customers, being the organisations that subscribe to the software and their personnel.
- Proposal recipients, being the individuals to whom our customers send proposals.
- Website visitors.
1. Identity of the controller
pro-posal.io provides proposal software for audio-visual and live event production companies. The service is operated by [LEGAL ENTITY NAME, COMPANY NUMBER AND REGISTERED ADDRESS TO BE COMPLETED BEFORE LAUNCH] ("we", "us", "our").
Enquiries relating to this policy, and requests to exercise the rights described in section 11, should be addressed to darren@pro-posal.io.
2. Our role
We act in two distinct capacities, and the capacity determines who is accountable for the data concerned.
- As controller, in respect of customer account data, billing data, correspondence and website usage. We determine the purposes and means of that processing, and this policy constitutes the privacy notice for it.
- As processor, in respect of all content a customer places into the service, including proposals, quotations and the details of the recipients to whom they are sent. The customer is the controller of that data and we process it solely on their documented instructions. Those arrangements are governed by our Data Processing Agreement, which forms part of the contract between us.
3. Personal data we process
3.1 Customers
- Account data: first and last name, email address, job title, biography, profile photograph, assigned role, and a one-way hash of the password. Passwords are not stored in a recoverable form.
- Organisation data: company name, subdomain, registered address, company registration number, VAT number, branding assets and contact details.
- Billing data:subscription plan, subscription status, billing email address and the payment provider's identifiers. Card details are entered directly into Stripe's hosted payment fields and are not transmitted to or stored on our systems.
- Integration credentials: where a customer connects Current RMS, the API key and subdomain supplied for that purpose. These are held server-side only and are never transmitted to a browser.
- Security data: the IP address or email address used in sign-in, registration and password reset attempts, together with an attempt count, retained only for the duration of the applicable rate-limiting window.
- Correspondence: support enquiries and fault reports submitted through the application.
3.2 Proposal recipients
This section applies to individuals who receive a proposal but have no account with us. It is linked from the foot of every proposal we deliver.
The organisation that sent the proposal is responsible for it. That organisation prepared its contents, determined that it should be sent, and is accountable for any personal data it contains, including the basis on which that data was obtained and the period for which it is retained. That organisation is the controller; we are the processor and act only on its instructions. We do not use the contents of a proposal for our own purposes, we do not contact recipients in our own right, and we do not disclose proposal data to any third party other than the sub-processors identified in section 7.
The data processed on the sender's behalf comprises:
- Contact and engagement details entered by the sender, such as name, organisation, venue and event particulars.
- Access records:the date and time a proposal is opened, the sections viewed and the duration of each view, the browser user agent, and a one-way hash of the IP address. The address itself is not retained. These records produce the sender's proposal analytics.
- Acceptance records: where a proposal is accepted, the name entered, the signature drawn, the date and time, and the optional items selected. These constitute the record of the agreement reached and are retained for as long as the sender retains the proposal.
- Correspondence: messages sent through the proposal conversation, and any feedback or reason given on declining.
Requests for correction or erasure, and enquiries as to why a proposal was sent, should be directed to the sending organisation, as those matters fall to it to determine. Where a recipient prefers not to approach the sender directly, we will accept the request at darren@pro-posal.io and forward it without delay.
3.3 Website visitors
The public marketing pages, blog and help centre operate without analytics, advertising or social tracking technologies, and set no third-party cookies. Further detail is given in our cookie policy.
4. Purposes and lawful bases
- Performance of a contract: establishing and administering customer accounts, providing the software, processing payment, and issuing service communications such as billing notices and password resets.
- Legitimate interests: maintaining the security and integrity of the platform, preventing misuse, diagnosing faults, and assessing feature usage in order to improve the service. We have balanced these interests against the rights and freedoms of the individuals concerned and consider the processing to be within their reasonable expectations of a subscribed business service.
- Compliance with a legal obligation: retention of billing and taxation records for the periods prescribed by law.
- Consent: where separately requested, for example optional marketing communications. Consent may be withdrawn at any time without affecting the lawfulness of prior processing.
In respect of proposal recipients, the lawful basis is determined by the sending organisation as controller, and will ordinarily be its legitimate interest in responding to an enquiry or quoting for work.
5. Automated decision-making and artificial intelligence
The drafting assistant is an optional feature. No data is transmitted to any artificial intelligence provider unless a customer elects to use it. Where it is used, the customer's instruction and the relevant proposal content are transmitted to Anthropic's application programming interface for the purpose of generating a draft.
Under Anthropic's commercial terms, data submitted through that interface is not used to train its models. We do not carry out automated decision-making producing legal or similarly significant effects, and no profiling is undertaken.
6. Disclosure
We do not sell personal data, we do not disclose it for advertising purposes, and we do not permit our providers to process it for their own purposes. Disclosure is limited to the sub-processors listed in section 7 and to any disclosure required by law.
7. Sub-processors
The following providers process personal data on our behalf. Each receives only the data necessary for its function and is engaged under a written data processing agreement.
- Supabase, database, authentication and file storage.
- Vercel, application hosting and content delivery.
- Amazon Web Services, media storage and encrypted database backups, London region (eu-west-2).
- Stripe, subscription billing and card payment processing.
- Resend, transactional email delivery.
- Anthropic, the optional drafting assistant, and only where a customer uses it.
Current RMS is not a sub-processor. It is a system belonging to the customer, connected and controlled by them, and its use is governed by the customer's own agreement with that provider. We read data from it and, on acceptance of a proposal, record a note against the linked opportunity unless the customer has set the integration to read only.
8. International transfers
Personal data is stored in the United Kingdom and the European Economic Area wherever the provider offers that option, and backups are held in the AWS London region (eu-west-2). Certain providers, including Stripe, Resend and Anthropic, are established in the United States, and data may be processed there. Such transfers are made subject to appropriate safeguards, ordinarily the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses.
9. Retention
- Account and proposal data: retained for the duration of the subscription.
- Following cancellation: the account is scheduled for permanent deletion 30 days after the subscription ends, and is then removed by an automated daily process. The interval allows the customer to reinstate the subscription or export data.
- Backups: encrypted backups are retained for 7 days and expire automatically. Deleted data may therefore persist within a backup for up to that period.
- Billing records: retained for the period required by taxation and accounting law, presently six years.
- Security and rate-limiting records: retained only for the duration of the applicable window.
10. Security
We maintain technical and organisational measures appropriate to the risk, including:
- encryption of data in transit using TLS, and encryption at rest by our hosting providers;
- storage of passwords as one-way hashes only;
- tenant isolation enforced at database level and verified independently on every application request;
- role-based access control within each customer account;
- server-side handling of all secrets, including integration credentials;
- rate limiting of authentication, registration and password reset requests, and lockout following repeated failed attempts against a password-protected proposal;
- storage of proposal recipients' IP addresses as one-way hashes;
- encrypted nightly database backups;
- documented monthly and quarterly security and dependency reviews.
No service can guarantee absolute security. In the event of a personal data breach likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, and will notify affected individuals where the legislation requires.
11. Rights of individuals
Under UK GDPR, individuals have the right to:
- be informed of the processing of their personal data;
- obtain access to that data;
- obtain rectification of inaccurate data;
- obtain erasure of their data;
- restrict processing, and to object to processing carried out on the basis of legitimate interests;
- obtain their data in a structured, commonly used and machine-readable format;
- withdraw consent where consent is the basis of processing;
- lodge a complaint with the Information Commissioner's Office at ico.org.uk.
Requests should be sent to darren@pro-posal.io and will be answered within one month. Where the data concerned was placed into the service by a customer, the request will be referred to that customer as controller, and we will assist them in responding to it.
12. Children
The service is intended for business use and is not directed at persons under the age of 18. We do not knowingly process the personal data of children.
13. Amendments
This policy may be amended from time to time. The date of the current version is shown above, and customers will be notified by email of material changes. The policy is reviewed against the operation of the software not less than quarterly, so that its terms and the conduct of the service remain aligned.