Proof Rail ← Back to home Request access

Legal

Data Processing Agreement

Last updated 16 September 2026

01

About this agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller", "you") and House of Borel LLC, trading as Proof Rail ("Processor", "we", "us"). It applies where we process personal data on your behalf to provide the Service and reflects the requirements of applicable data-protection laws, including the EU and UK GDPR, the UAE Personal Data Protection Law, and US state privacy laws where they apply.

If you require a countersigned copy for your records, contact legal@proofrail.me.

02

Roles of the parties

For personal data you submit so that we can verify a claim or operate your account, you are the controller and we are your processor. Each party will comply with its obligations under applicable data-protection law.

For our own business records, for example, prospect and billing contacts, we act as an independent controller under our Privacy Policy, not as your processor.

03

Our instructions

We process personal data only on your documented instructions, including the Terms, this DPA, and your configuration and use of the Service, unless law requires otherwise; if it does, we will tell you first unless the law prohibits it. We will inform you if, in our opinion, an instruction infringes applicable data-protection law.

04

Confidentiality

We ensure that the personnel authorised to process personal data are bound by appropriate confidentiality obligations.

05

Security

We implement appropriate technical and organisational measures to protect personal data, described in Annex 2, including encryption in transit and of stored private evidence, cryptographically signed and tamper-evident records, credential and API-key controls, and strict separation of sandbox and live data.

06

Sub-processors

You authorise us to engage the sub-processors listed in Annex 3 to help provide the Service. We impose data-protection obligations on each sub-processor no less protective than this DPA and remain responsible for their performance.

We will give notice before adding or replacing a sub-processor. If you reasonably object on data-protection grounds, we will work with you in good faith to address it.

07

International transfers

Where personal data is transferred across borders, we rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or another lawful mechanism, together with supplementary measures where needed.

08

Assisting you

Taking into account the nature of the processing and the information available to us, we will assist you with responding to data-subject requests, keeping personal data secure, notifying personal-data breaches, and carrying out data-protection impact assessments and any prior consultations.

09

Data-subject requests

If we receive a request from a data subject relating to your data, we will not respond directly except to confirm that the request should be directed to you, and we will pass it on without undue delay.

10

Personal-data breach

We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information reasonably available to help you meet your own notification obligations.

11

Audit

We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits on reasonable notice, no more than once a year unless required by a supervisory authority or following a breach, subject to confidentiality and without disrupting the Service. We may satisfy this through third-party certifications or reports where available.

12

Deletion and return

On termination, we will delete or return the personal data we process on your behalf at your choice, except where retention is required by law or to keep an issued record independently verifiable. Revoking a record is a separate action you can request.

13

Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms. If this DPA conflicts with the Terms on the processing of personal data, this DPA governs. Terms defined in the Terms of Service have the same meaning here.

A1

Annex 1: Details of the processing

Subject matter and duration: verification of claims and operation of the Service, for the term of the Service and as required to keep issued records independently verifiable.

Nature and purpose: verifying submitted claims against evidence standards; issuing and maintaining records; account administration; support; and billing.

Categories of data subjects: your personnel; the individuals, customers, or counterparties named in a claim; and other individuals whose data you choose to submit.

Categories of personal data: names, business contact details, company and role; claim details and supporting evidence you submit; and account and usage data. Do not submit special categories of personal data unless we have separately agreed to it.

A2

Annex 2: Security measures

Encryption of data in transit (TLS) and of stored private evidence (AES-256-GCM); Ed25519-signed, tamper-evident records with an append-only audit history; API-key and credential controls with constant-time verification; strict separation of sandbox and live data; least-privilege access; logging and monitoring; use of vetted sub-processors; and regular review of these measures.

A3

Annex 3: Sub-processors

Fly.io, Inc.: cloud application hosting and the PostgreSQL database that stores service data.

Resend, Inc.: delivery of transactional email (for example, verification and notification emails).

Stripe, Inc.: payment processing and billing, where a paid plan is active.

Google LLC: "Sign in with Google" authentication, for users who choose it (name and email address).

Linear Orbit, Inc.: support and issue tracking for requests you send us.

Hostinger International Ltd.: hosting of the mailboxes that receive email you send us.

Access-request and sales contact details are handled in the internal CRM operated by House of Borel LLC, the company that operates Proof Rail; this is a group system, not a separate third-party sub-processor.

Vendor names and locations may change as the Service develops; the version of this Annex published here is the current list, and we will give notice of changes as set out above.

Back to Proof Rail hello@proofrail.me ↗