Privacy policy
The short version: your documents are evidence, not data. They are processed to produce your report, kept for 30 days unless you delete them sooner, and never used to train models.
1. Who is responsible
The controller of your personal data is FUNNELD LTD, 82A James Carter Road, Mildenhall, IP28 7DE, United Kingdom, Companies House no. 14582937 ("Funneld", "we"), which operates the ProofVerity service at proofverity.com and analyze.proofverity.com. Questions about this policy: contact@proofverity.com.
2. What we collect
- Account data: name, email address, organisation, password hash, plan and billing history.
- Content you submit: documents, images and URLs you send for analysis, and the reports we produce from them.
- Usage data: pages visited, features used, browser and device type, approximate location derived from IP address, error logs.
- Payment data: handled by our payment processor. We receive the last four digits of a card, its expiry and the billing address; we never store full card numbers.
- Support data: messages you send us and the context needed to answer them.
3. Why we use it, and on what basis
- To provide the service, produce reports and bill you: performance of a contract.
- To keep the service secure, prevent abuse and fix errors: legitimate interest.
- To measure which pages and features help, through anonymous analytics: consent, given or refused in the cookie banner.
- To meet accounting, tax and legal obligations: legal obligation.
- To send product news: consent, withdrawable in every email.
We do not sell personal data, we do not use submitted content to train or fine-tune models, and we do not build advertising profiles.
4. How long we keep it
- Submitted documents and images: 30 days from analysis, then deleted. You can delete them earlier from your history.
- Reports: for as long as your account is active, unless you delete them.
- Account data: for the life of the account and 30 days after closure.
- Invoices and billing records: 6 years, as UK accounting law requires.
- Usage logs: 12 months.
5. Who we share it with
Sub-processors that host, store, send email and take payments on our behalf, under written contracts and only for the purposes above; professional advisers where needed; and authorities when the law requires it. Documents submitted for analysis are processed in the region you choose (EU or UK by default) and are not shared with third parties beyond hosting.
6. International transfers
Where data leaves the UK or the EEA, we rely on adequacy decisions or the UK International Data Transfer Agreement and EU Standard Contractual Clauses, with additional safeguards where appropriate.
7. Your rights
Under the UK GDPR and, where applicable, the EU GDPR you can ask for access, rectification, erasure, restriction, portability and object to processing based on legitimate interest, and withdraw consent at any time. Write to contact@proofverity.com; we answer within one month. You can also complain to the Information Commissioner's Office (ico.org.uk) or to your local supervisory authority.
8. Security
Data is encrypted in transit (TLS 1.2 or higher) and at rest. Access is restricted by role, logged and reviewed. Documents are processed in isolated workers and purged on the schedule above. If a breach affects your data we will notify you and the relevant authority without undue delay, as the law requires.
9. Children
The service is not directed at children under 16. Educational institutions that submit student work do so as controllers of that data under their own agreements with us.
10. Changes
We will post any changes here and, if they are material, tell you by email or in the product before they take effect.