Legal review draft
Privacy notice
Effective 3 September 2026. How ProofSyncer handles account, document, workflow and security data. This draft is deliberately explicit about current controls and launch dependencies. Qualified legal review remains required before paid general availability.
Who is responsible
ProofSyncer is the service provider. A customer is normally the controller of personal data contained in documents and ProofSyncer acts as its processor for extraction and workflow services. ProofSyncer acts as controller for account, security, billing and service-operation data. The contracting legal entity, registered address and legal/privacy contact must be inserted and approved by counsel before paid general availability.
What we process
Account identifiers, workspace membership and roles, configuration, API and connection metadata, uploaded source documents, extracted fields and evidence, corrections, decisions, usage and audit events, billing references, security events, device/request metadata and technical error records. API keys are hashed; connector destinations and signing secrets are encrypted at rest.
Why and on what basis
Customer document content is processed to perform the service under the customer contract and documented instructions. Account, security, fraud-prevention and service-operation data is processed to perform the contract and for legitimate interests in operating and protecting the service. Billing records are processed to perform the contract and meet legal obligations. Consent is used only where a specific optional feature legally requires it.
AI and subprocessors
Document content is sent server-side to a managed multimodal model for extraction. Hosting, authentication, database, object storage, model, payment and monitoring providers may act as subprocessors. A named subprocessor register, processing locations, transfer safeguards and advance-change notification process must be published before enterprise general availability. ProofSyncer does not use customer documents to make professional decisions on the customer's behalf.
International transfers
Service providers may process data outside the customer's country. Before paid launch, ProofSyncer must document relevant processing locations and the transfer mechanism used, such as an adequacy decision or approved contractual safeguards. Customers should not infer a specific data-residency commitment unless it appears in their order form.
Storage and retention
Workspace owners choose 1, 7, 30 or 90 days for source access. Dedicated S3 configuration can support verified physical deletion and lifecycle controls. In managed storage, ProofSyncer removes application references and signed access but does not claim independently verified byte-level deletion. Extracted results, corrections, decisions and audit records remain until the customer deletes the document or the workspace is closed, subject to legally required billing, security and dispute records. Retention for each operational data class must be finalized with counsel.
Security
Current controls include tenant-scoped authorization, least-privilege roles, secure invitations, hashed API keys, encrypted connector credentials, bounded file validation, local PDF rendering, short-lived source links, same-origin browser protection, rate limits, idempotency, DNS-pinned HTTPS deliveries, signed webhooks and audit history. Security reduces risk but cannot guarantee absolute security.
Your rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, portability or objection and may complain to a supervisory authority. For document data, requests should normally go first to the customer that supplied the document. ProofSyncer will verify identity and assist customer controllers. A public legal/privacy contact and documented request workflow are required before paid launch.
Cookies and service telemetry
The application uses essential session and security storage needed for authentication and service operation. It does not currently describe advertising-cookie use. Any future non-essential analytics or marketing technology must be documented and, where required, presented through a consent mechanism before activation.
Children and sensitive data
The service is intended for business users, not children. Until contractual controls and risk assessments are complete, do not upload special-category personal data, medical records, identity documents, payment-card data, criminal-offence data or legally privileged material.
Incidents and changes
ProofSyncer maintains an internal incident process and will notify affected customer controllers without undue delay after confirming a personal-data breach where contract or law requires it. Material notice changes should be dated and communicated before taking effect.