Data processing summary
Last updated: 18 August 2026
This page summarises how FirmProof processes data on your firm's behalf, for procurement and DPIA purposes. The short version: we process your account details and snapshots of your firm's public website pages — never client-matter data — using the subprocessors below. Full detail is in the Privacy Notice. Codable Labs Limited is registered with the UK Information Commissioner's Office — ICO registration reference ZC223489.
Subprocessors
| Subprocessor | Role | Region |
|---|---|---|
| Supabase | Database, authentication and file storage for account data and scan evidence | UK (London — AWS eu-west-2) |
| Stripe | Payment processing and subscription billing | EU / US (global payments infrastructure) |
| Resend | Transactional email — alerts and monitoring statements | EU |
| Cloudflare | DNS, TLS termination, network security and content delivery | Global edge network |
| Anthropic | AI processing used solely as an additional accuracy gate on scan findings (public page excerpts only; may downgrade a result to human review or confirm a 'no issue detected' with quote-verified page evidence — never creates findings) and for the in-dashboard support assistant on paid plans. API data retained by Anthropic up to 30 days | US (API) |
Security summary
- Tenant isolation: every table is protected by row-level security (RLS), so one firm's data is not queryable from another firm's session — and the isolation is exercised by automated tests, not just configured.
- Encryption: in transit (TLS on every connection, including scanner traffic) and at rest (managed database and storage encryption).
- Minimal surface: the scanner reads public pages only; there are no credentials to your systems anywhere in ours. Card data never touches our infrastructure — payment details go directly to Stripe.
- Retention: scan evidence is held on a rolling basis for the period the firm's plan provides — 12 months, 3 years or 6 years — and deleted automatically by a scheduled job once it passes that window. Account data is deleted within 30 days of account deletion.
Requesting a signed DPA
If your firm's procurement or COLP process needs a signed data processing agreement, we have a standard DPA incorporating the compulsory UK GDPR article 28(3) terms — documented instructions, confidentiality, the security measures above, data-subject-request and breach-notification assistance, deletion or return on exit, and audit rights. Email support@firmproof.co.uk with your firm name and we'll send it for countersignature. DPA signatories are notified by email at least 30 days before we add or replace a subprocessor, with the opportunity to object.
See also: Terms of Service · Privacy Notice