Procurement
Data processing addendum
Last updated September 1, 2026
This addendum applies only when an order form incorporates it. The customer acts as controller and Phronetos acts as processor for personal data submitted to Proof. The signed order form controls if it conflicts with this page. Each party should have counsel review the agreement for its jurisdiction and use case.
Processing details
Proof processes account details, workspace membership, operational feedback, reporter contact details, page context, screenshots, decision records, and service logs. Data subjects may include customer staff, contractors, and authorized reporters. Processing supports service delivery, security, support, export, and deletion for the subscription term and agreed recovery period.
Documented instructions and confidentiality
Phronetos processes personal data only on the customer's documented instructions, including the order form and configured product actions, unless applicable law requires otherwise. Authorized personnel must protect the data as confidential.
Security
Phronetos maintains safeguards appropriate to the processing risk. These include tenant scoping, access controls, encrypted transport, managed encryption at rest, scoped and hashed project keys, private evidence access, append-only case events, dependency review, backup, and recovery testing.
Subprocessors
The customer gives general authorization to use subprocessors needed to operate Proof. Phronetos will bind each subprocessor through written data-protection obligations no less protective than the applicable obligations in this addendum and remains responsible for its processing performance. Phronetos will provide notice of material additions or replacements through the designated customer contact. The order form defines the notice period and objection process.
Requests, incidents, and assistance
Phronetos will reasonably assist the customer with data-subject requests, security assessments, impact assessments, regulator consultation, and confirmed personal-data incidents, taking account of the nature of the processing and available information. Phronetos will notify the customer without undue delay after confirming an incident affecting customer personal data.
Return, deletion, and audit evidence
The customer can request an export during the service term. At termination, Phronetos will return or delete customer personal data according to the order form, except where law requires retention. Phronetos will provide information reasonably needed to demonstrate these commitments. Any inspection must protect other customers, security, and confidential information.
International transfers
The order form identifies approved hosting locations and any required transfer mechanism. Standard contractual clauses or another lawful safeguard must be executed before a restricted transfer begins.
Contact
Request a signed addendum and deployment-specific subprocessor schedule from legal@phronetos.com. Production processing remains blocked until that schedule is complete.