FirmProof
Sign inRun a free scan
Legal · Privacy

Privacy Notice

Last updated: 11 August 2026

In short

We hold very little about you: the email you sign in with, the firm details you give us, snapshots of your firm's public web pages, and a Stripe subscription record. We never see your clients' matter data. Evidence history is kept for 12 months. You have the usual UK GDPR rights, including complaining to the ICO.

Who is responsible

FirmProof is the controller of the personal data described here. Contact for anything in this notice: dantasdeveloper@gmail.com.

What we process, why, and the lawful basis

DataPurposeLawful basis
Account data — your email address (received from Google or Apple when you sign in) and your name if providedCreating and securing your account, service emailsContract (UK GDPR art. 6(1)(b))
Firm details — firm name, website address, SRA number, services offeredConfiguring which checks apply to your siteContract
Public website snapshots — pages, excerpts and findings from the site you nominateRunning the monitoring checks and keeping your evidence historyContract; legitimate interests for the free scan
Billing data — handled by Stripe; we hold subscription status, not card numbersCharging for the subscriptionContract; legal obligation (accounting records)
Usage and security logs — IP address, request metadataKeeping the service secure and rate-limitedLegitimate interests

What we deliberately do not process: client-matter data. The scanner reads only publicly accessible pages of the website you nominate — the same content any visitor sees. Website snapshots may incidentally contain personal data your firm chose to publish (for example solicitors' names on a team page); we hold that only as part of the page snapshot.

How long we keep it

Scan evidence and findings are kept for 12 months on a rolling basis — that period is the product feature (“12-month evidence history”). Account data is kept while your account exists and deleted within 30 days of account deletion, except records we must keep for legal or accounting purposes (held by Stripe or in our accounts). Free-scan results are not stored.

Who processes data for us

  • Supabase (EU region) — database, authentication and storage.
  • Stripe — subscription billing and payments.
  • Resend (EU) — transactional email (alerts, statements).
  • Cloudflare — network security, DNS and content delivery.

Details of roles and regions are on the data processing summary. Where a processor operates outside the UK, transfers rest on UK adequacy decisions or the applicable standard contractual clauses / UK addendum.

Your rights

Under UK GDPR you can ask for access to your data, correction, deletion, restriction of or objection to processing, and portability, and you can withdraw consent where consent is the basis. Email dantasdeveloper@gmail.com and we'll respond within one month. You also have the right to complain to the Information Commissioner's Office: ico.org.uk.

See also: Terms of Service · Data processing summary