Legal

Data Processing Agreement

This Data Processing Agreement outlines customer and processor responsibilities when Proposal Core processes personal information for a customer workspace.

Last updated: July 24, 2026

Roles

The customer is the controller or responsible party for personal information added to its Proposal Core workspace.

Proposal Core acts as a processor or operator when it processes personal information on the customer's behalf to provide the service.

Customer responsibilities

  • Use Proposal Core only for lawful business purposes.
  • Ensure that customer content can legally be uploaded, stored, shared and processed.
  • Give clear instructions for processing personal information.
  • Manage user access, roles, invitations and workspace permissions.
  • Respond to data subject requests where the customer controls the relevant data.

Proposal Core responsibilities

  • Process customer personal information only to provide, secure, maintain and support the service.
  • Use reasonable technical and organizational security measures.
  • Limit access to customer data to personnel and providers who need access for service delivery.
  • Maintain confidentiality obligations for people who access customer data.
  • Support customer requests where technically and commercially reasonable.

Security measures

Security measures include authenticated access, organization scoping, role-based permissions, server-side authorization checks, HTTPS in production, security headers, audit records for important events and controlled use of service credentials.

Additional infrastructure safeguards depend on the configured hosting, Supabase and monitoring providers.

Subprocessors

Proposal Core may use subprocessors for hosting, database, authentication, storage, email, payments, analytics, monitoring and optional AI features.

The current subprocessor summary is listed on the Subprocessors page.

Breach communication

If Proposal Core becomes aware of a confirmed personal information breach affecting customer data, it will notify affected customers without undue delay after assessing the nature and scope of the incident.

The notice will include available information about the incident, affected data, mitigation steps and recommended customer actions where applicable.

Data deletion and return

Customers may request deletion or export assistance for workspace data by contacting privacy@proposal-core.com.

After termination or deletion, customer data may remain in backups, logs or records for a limited period where required for security, legal, tax, accounting or operational purposes.

International transfers

Customer data may be processed outside South Africa by Proposal Core subprocessors. Proposal Core uses service provider agreements and operational controls intended to support lawful transfers.

Customer instructions

The customer instructs Proposal Core to process personal information as needed to provide the service, support users, secure the platform, process payments, send notifications and perform related product operations.

Additional written instructions can be discussed for enterprise customers where they are compatible with the product and applicable law.