Who is responsible
Proofenary is operated by Vantivio Ltd, which is the data controller for the account, provider and evidence information described in this notice. Questions or privacy-rights requests can be sent to jnorman@vantivio.co.uk.
Charges and VAT
Provider membership and Proofenary transaction fees are supplied by Vantivio Ltd, UK VAT registration GB 522 6050 28. Prices shown excluding VAT have VAT added at the applicable rate. VAT is recorded by Vantivio Ltd and shown separately on the relevant Stripe invoice or receipt.
Information we collect
- Account details such as your name, email address and sign-in identifiers.
- Provider, subscription and payout-account status. Card and bank details are collected and held by Stripe rather than Proofenary.
- Proof Passport drafts, submitted evidence, review notes and publication decisions.
- Publicly listed business contact details used for relevant corporate outreach, including the supplier, contact name, work email, framework listing and source webpage.
- Basic technical and security information needed to operate the service, such as access logs, device/browser information and authentication cookies.
- Messages you choose to send to the Proofenary team.
Why we use it
We use personal information to create and secure accounts, provide provider services, manage subscriptions and transaction fees, review and publish evidence, respond to enquiries, prevent misuse and meet accounting or legal obligations. We rely on performance of our agreement with you, our legitimate interests in operating and protecting Proofenary, legal obligations, and consent where an optional use specifically asks for it.
Relevant business outreach
We may contact incorporated suppliers using business details they have published in an official procurement directory. Our purpose is to invite relevant suppliers to present a measurable customer outcome for review. We rely on legitimate interests after considering the relevance of the message, the limited business information used and the recipient’s reasonable expectations. Each message identifies Proofenary, explains why the organisation was contacted and provides a direct way to object. If you object or ask us to stop, we retain the minimum information needed on a suppression list so that we do not contact you again.
What becomes public
Drafts and review notes remain private. When an authorised reviewer publishes a Proof Passport, its provider organisation, outcome, evidence organisation, method, source description, context and limitations become publicly searchable. Do not submit personal, confidential, patient or special-category information in evidence fields.
Service providers
We use specialist providers for authentication, payments and payouts, hosting, security, database, business email and evidence-catalogue infrastructure. This currently includes Clerk, Stripe, Vercel, Supabase, Google Workspace and Sanity. They process information under their own security and privacy commitments. Where information is processed outside the UK, we use our providers’ recognised transfer safeguards.
How long we keep it
We retain account and evidence records while an account or publication remains active and for a reasonable period afterwards for security, dispute and audit purposes. Financial records may be kept for the period required by law. We delete or anonymise information when it is no longer needed, subject to legal and evidential requirements.
Your choices and rights
You may ask for access to your information, correction, deletion, restriction, portability or to object to particular uses where those rights apply. You may also complain to the UK Information Commissioner’s Office. The ICO provides current guidance on accessing your information and making a complaint.
Changes to this notice
We will update this page when the service or its use of information changes materially. Important changes will be brought to registered users’ attention where appropriate.