Privacy Policy
Effective date: 2026-02-12 · Version: v1.3.2026-02-12
1. Scope
This policy explains how Proofound collects, uses, stores, and protects personal information across account creation, matching, verification, moderation, and support. Processing is performed under applicable privacy laws, including GDPR and ePrivacy rules.
2. Data We Process
- Account records: email, display name, authentication identifiers.
- Profile information: expertise, projects, preferences, and verification status.
- Operational records: moderation reports, consent records, security and audit logs.
- Optional analytics events: telemetry only when analytics consent is granted.
3. Legal Bases and Consent
We process data based on contract performance, legitimate interests, and explicit consent where required. Non-essential analytics are disabled by default and only enabled after affirmative cookie consent. Consent can be changed at any time in cookie settings.
4. Data Minimization and Security
We apply data minimization by default and use access controls, encryption in transit, and row-level security for protected tables. Where telemetry is retained, personal identifiers are hashed or omitted.
5. International Transfers
If personal data is processed outside your region, we rely on approved transfer mechanisms and contractual safeguards required by law.
6. Retention and Deletion
Account deletion requests are executed immediately. Associated data is deleted or anonymized according to technical and legal constraints. We retain only what is required for security, compliance, or legal obligations.
7. Your Rights
- Access and export your personal data.
- Correct inaccurate information.
- Request deletion of your account and personal data.
- Withdraw optional processing consent, including analytics.
- Object to certain processing where applicable by law.
8. Contact
For privacy requests or questions, contact privacy@proofound.com.
9. Processors and Operational Accountability
We rely on vetted subprocessors for hosting, authentication, email delivery, and observability. Access is restricted by role, reviewed periodically, and monitored through audit controls. When processor lists or handling practices change in ways that materially affect users, we update this policy and related notices.