Proof & Trust Back to home

Legal

Privacy Policy

How Proof&Trust collects and processes personal data in connection with our supply-chain risk-assessment platform, website and related services.

Last updated: 15 June 2026 GDPR · UK GDPR · Swiss FADP Controller: Proof&Believe LLC

This Privacy Policy explains how Proof&Believe LLC ("we," "us," "our") collects and processes personal data in connection with our supply chain risk-assessment platform and related website and services (the "Services"). It is written to meet the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss FADP.

This policy pairs with our Terms of Service and our Data Processing Agreement (DPA). Please read the section "Our two roles" below — it determines which document governs which data.

01Who we are and how to contact us

Controller: Proof&Believe LLC, 30 N Gould St Ste N, Sheridan, WY 82801, United States.

Privacy contact: info@proofandtrust.com

02Our two roles

We process personal data in two distinct capacities:

  • As a controller, for personal data relating to our website visitors, prospects, the staff and administrators of our business customers, billing contacts, newsletter recipients, and people who contact our support team. This policy covers that processing.
  • As a processor, for the data our business customers upload into the platform — including information about their own suppliers, vendors and third-party contacts ("Customer Data"). For that data, the customer is the controller and we act only on their documented instructions. That processing is governed by our DPA, not by this policy, and questions about it should be directed to the customer in the first instance.

03Personal data we collect

Depending on how you interact with us, we may process:

  • Account and identity data — name, business email, job title, employer, username, and credentials.
  • Billing data — billing contact, billing address, VAT/tax identifiers, and transaction records (card details are handled by our payment processor; we do not store full card numbers).
  • Usage and technical data — IP address, device and browser characteristics, operating system, language, referring URLs, log data, and information about how you use the Services.
  • Communications data — the content of emails, support tickets, and forms you submit.
  • Marketing data — your preferences for receiving communications from us.

We collect this data directly from you, automatically through your use of the Services, and occasionally from third parties such as our customers (who provide their staff's contact details), business partners, and public sources.

Special category data: We do not intentionally collect special category data (Article 9) about visitors, prospects, or customer staff. Any sensitive or criminal-offence data that may arise within the platform during supplier screening is Customer Data processed under the DPA.

04How we use personal data and our legal bases

We process personal data only where we have a lawful basis under Article 6 GDPR:

Where we rely on legitimate interests, we have balanced those interests against your rights and can provide details of that assessment on request. Where we rely on consent, you may withdraw it at any time (see Section 9).

05Cookies and tracking

We use only strictly necessary cookies to operate and secure the Services. Under the ePrivacy rules these are exempt from consent, so we do not use a cookie consent banner. We do not use analytics, advertising, or tracking cookies. Full details, including the specific cookies we set, are in our Cookie Policy.

06Who we share personal data with

We share personal data only as needed and under appropriate safeguards, with:

  • Processors and sub-processors acting on our behalf — for example hosting, infrastructure, payment processing, email delivery, and customer support tools. They process data under written contracts that meet Article 28 GDPR. A current list of our sub-processors is available on request by contacting us.
  • Professional advisers such as lawyers, auditors and accountants, bound by confidentiality.
  • Authorities and regulators where required by law or to protect our rights.
  • Acquirers in connection with a merger, financing, acquisition or sale of assets, subject to this policy.

We do not sell personal data.

07Where we process your data, and international access

Data residency

All customer data is stored and processed on servers located in Frankfurt, Germany, within the EU. We do not host or store customer data outside the EEA.

Two points of non-EU involvement apply, and we disclose them openly:

  • Operating entity (United States). Proof&Believe LLC is incorporated in the United States. We do not transfer customer data to the US for storage or processing. However, as the entity that operates and controls the Services, we may in principle be subject to lawful access requests under US law in respect of data we control. We mitigate this through encryption, access controls and key management, and we will assess and, where appropriate, challenge any request that conflicts with EU law.
  • Maintenance access from outside the EU. A limited number of technical personnel located in European countries outside the EU may hold administrative access to the hosting environment for maintenance and support. This access is restricted, logged, and subject to confidentiality and security controls. Where the relevant country benefits from a European Commission adequacy decision (such as the United Kingdom or Switzerland), access relies on that decision; where it does not, access is covered by Standard Contractual Clauses and supplementary measures following a transfer impact assessment.

You can request details of these measures by contacting us.

08How long we keep personal data

We keep personal data for as long as the customer relationship is active. When a customer cancels or the contract otherwise ends, we delete or irreversibly anonymise all personal data relating to that customer following the 30-day data-export window described in our Terms of Service, except:

  • Billing, invoicing and tax records, which we are legally required to retain for the statutory period under applicable tax and accounting law; and
  • data we must keep to comply with a legal obligation or to establish, exercise or defend legal claims.

Marketing data is kept until you withdraw consent or object. Security and system logs are kept only as long as needed to operate and protect the Services.

09Your rights

Subject to applicable law, you have the right to:

  • access the personal data we hold about you;
  • request rectification of inaccurate data;
  • request erasure ("right to be forgotten");
  • request restriction of processing;
  • data portability — receive your data in a structured, machine-readable format;
  • object to processing based on legitimate interests, and to object to direct marketing at any time;
  • withdraw consent at any time, without affecting prior lawful processing;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you (see Section 10).

To exercise any right, contact info@proofandtrust.com. We will respond within one month, as required by law, and may need to verify your identity. There is normally no charge.

If your data is processed by us as a processor (Customer Data in the platform), please direct your request to the relevant customer, who is the controller; we will assist them in responding.

Right to complain: You may lodge a complaint with a supervisory authority — in the EU, the data protection authority of your country of residence, work, or the place of the alleged infringement; in the UK, the Information Commissioner's Office (ICO); in Switzerland, the FDPIC. We would, however, appreciate the chance to address your concerns first.

10Automated decision-making

Our website and account processing do not involve decisions about you based solely on automated processing that produce legal or similarly significant effects. The platform itself generates automated risk assessments from Customer Data; where this involves personal data, the relevant customer (as controller) is responsible for ensuring appropriate human oversight under Article 22 GDPR.

11Children

The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe we have done so, contact us and we will delete it.

12Changes to this policy

We may update this policy from time to time. We will post the updated version with a revised "Last updated" date and, where changes are material, provide additional notice. Continued use of the Services after the effective date constitutes awareness of the updated policy.

13Contact us

Proof&Believe LLC
30 N Gould St Ste N
Sheridan, WY 82801
United States
info@proofandtrust.com