Data processing
Your clients' data is here because you put it here. This sets out what happens to it and who is answerable for what.
Last updated 17 August 2026
Draft — not in effect
This document has not been reviewed by a lawyer and does not yet govern anything. It is published for review only. Nothing in DashProposal currently asks you to agree to it.
Who is responsible for what
For data about your clients, you decide what is collected and why. DashProposal stores and processes it on your instructions and does not use it for its own purposes.
Your client never creates an account. Their agreement is with you, not with DashProposal, which is why requests about their data are answered through you.
Needs legal wording
The controller and processor definitions, the term, and what happens to data when the agreement ends.
What is processed
Client names, email addresses and notes. Proposal contents. Signature records, which include the signer's name, email, IP address, the consent wording shown, a document fingerprint and a trusted timestamp. Engagement events showing when a proposal link was opened and which sections were viewed.
Sub-processors
Every third party involved, and what each one receives.
| Service | Purpose | What it receives | Region |
|---|---|---|---|
| Supabase | Database and account authentication | All stored data, including proposals, signatures and account details | United States (us-east-1) |
| Cloudflare | Hosting and content delivery | Requests to the site, including IP address and browser details | Global edge network |
| Anthropic | Drafting a first version of a proposal | Client name, project description, target price and timeline. Only when AI drafting is used, which is optional per proposal. | United States |
| Resend | Sending email, including signed agreement copies | Recipient email address and the contents of the message or attachment | United States |
| FreeTSA | Trusted timestamps proving when a document was signed | A SHA-256 hash of the document only. The document itself is never sent and cannot be reconstructed from the hash. | Germany |
AI drafting is optional on every proposal. Turning it off means no client detail reaches Anthropic at all.
Needs legal wording
Notice period before a sub-processor is added or replaced, how objections are handled, and the transfer mechanism for data leaving its region.
Security measures
Every database table denies access by default, and rows are reachable only through the account that owns them. Administrative access requires a second factor and is recorded in an audit log.
Signed agreements are fingerprinted with SHA-256 and timestamped, so any later alteration is detectable. The full list is on the security page.
An open question you need to answer
Needs legal wording
Do signed agreements survive account deletion?
A signed agreement is evidence of a contract between you and your client. If deleting your account erases it, your client loses their proof of a deal they were party to and never agreed to give up. If it survives, data is being kept after someone asked for erasure.
Both positions are defensible and they cannot both be taken. This is a decision about the product, not a wording choice, and the terms, the privacy policy and the deletion feature all have to agree with whichever is chosen.
The rest
Needs legal wording
Breach notification timescales, audit rights, deletion and return of data on termination, and any standard contractual clauses required for international transfers.