Data processing summary
Last updated: 11 August 2026
This page summarises how FirmProof processes data on your firm's behalf, for procurement and DPIA purposes. The short version: we process your account details and snapshots of your firm's public website pages — never client-matter data — using the subprocessors below. Full detail is in the Privacy Notice.
Subprocessors
| Subprocessor | Role | Region |
|---|---|---|
| Supabase | Database, authentication and file storage for account data and scan evidence | EU (Frankfurt) |
| Stripe | Payment processing and subscription billing | EU / US (global payments infrastructure) |
| Resend | Transactional email — alerts and monitoring statements | EU |
| Cloudflare | DNS, TLS termination, network security and content delivery | Global edge network |
Security summary
- Tenant isolation: every table is protected by row-level security (RLS), so one firm's data is not queryable from another firm's session — and the isolation is exercised by automated tests, not just configured.
- Encryption: in transit (TLS on every connection, including scanner traffic) and at rest (managed database and storage encryption).
- Minimal surface: the scanner reads public pages only; there are no credentials to your systems anywhere in ours. Card data never touches our infrastructure — payment details go directly to Stripe.
- Retention: scan evidence is held for 12 months on a rolling basis; account data is deleted within 30 days of account deletion.
Requesting a signed DPA
If your firm's procurement or COLP process needs a signed data processing agreement incorporating the UK GDPR article 28 terms, email dantasdeveloper@gmail.com with your firm name and we'll send one for countersignature. We'll also notify DPA signatories before adding or replacing a subprocessor.
See also: Terms of Service · Privacy Notice