Data processing

Your clients' data is here because you put it here. This sets out what happens to it and who is answerable for what.

Last updated 17 August 2026

Draft — not in effect

This document has not been reviewed by a lawyer and does not yet govern anything. It is published for review only. Nothing in DashProposal currently asks you to agree to it.

Who is responsible for what

For data about your clients, you decide what is collected and why. DashProposal stores and processes it on your instructions and does not use it for its own purposes.

Your client never creates an account. Their agreement is with you, not with DashProposal, which is why requests about their data are answered through you.

Needs legal wording

The controller and processor definitions, the term, and what happens to data when the agreement ends.

What is processed

Client names, email addresses and notes. Proposal contents. Signature records, which include the signer's name, email, IP address, the consent wording shown, a document fingerprint and a trusted timestamp. Engagement events showing when a proposal link was opened and which sections were viewed.

Sub-processors

Every third party involved, and what each one receives.

ServicePurposeWhat it receivesRegion
SupabaseDatabase and account authenticationAll stored data, including proposals, signatures and account detailsUnited States (us-east-1)
CloudflareHosting and content deliveryRequests to the site, including IP address and browser detailsGlobal edge network
AnthropicDrafting a first version of a proposalClient name, project description, target price and timeline. Only when AI drafting is used, which is optional per proposal.United States
ResendSending email, including signed agreement copiesRecipient email address and the contents of the message or attachmentUnited States
FreeTSATrusted timestamps proving when a document was signedA SHA-256 hash of the document only. The document itself is never sent and cannot be reconstructed from the hash.Germany

AI drafting is optional on every proposal. Turning it off means no client detail reaches Anthropic at all.

Needs legal wording

Notice period before a sub-processor is added or replaced, how objections are handled, and the transfer mechanism for data leaving its region.

Security measures

Every database table denies access by default, and rows are reachable only through the account that owns them. Administrative access requires a second factor and is recorded in an audit log.

Signed agreements are fingerprinted with SHA-256 and timestamped, so any later alteration is detectable. The full list is on the security page.

An open question you need to answer

Needs legal wording

Do signed agreements survive account deletion?

A signed agreement is evidence of a contract between you and your client. If deleting your account erases it, your client loses their proof of a deal they were party to and never agreed to give up. If it survives, data is being kept after someone asked for erasure.

Both positions are defensible and they cannot both be taken. This is a decision about the product, not a wording choice, and the terms, the privacy policy and the deletion feature all have to agree with whichever is chosen.

The rest

Needs legal wording

Breach notification timescales, audit rights, deletion and return of data on termination, and any standard contractual clauses required for international transfers.