Effective 2026-09-09
This Data Processing Agreement (DPA) is part of the Terms of Service between you and ProofHour. It applies when the material ProofHour handles for you — screenshots, window titles, memos, work records — contains personal data about other people: your clients, their staff, anyone who appears on your screen. For that data, you are the controller and ProofHour is your processor, and this document is the written agreement Article 28 GDPR asks us to have.
For the data about you — your account, your billing — we are the controller, and the privacy policy governs. This DPA is about your clients' side of the record.
The processor is Tolga Çağın, operating ProofHour as a sole trader based in Mersin, Türkiye — the same entity as in the terms. The controller is you, the account holder. Accepting the terms accepts this DPA; there is nothing separate to sign.
Subject matter and nature: storing and displaying your work records; capturing, storing and (where you enable AI summaries) describing screenshots; assembling reports and invoices; emailing reports to the recipients you choose. Purpose: providing ProofHour as configured by you, and nothing else. Duration: for as long as your account exists. Data subjects: your clients, their personnel, and anyone whose information appears on your recorded screen. Categories of data: whatever your screen and your notes contain — typically names, email addresses, correspondence and business documents; potentially anything, which is why the capture controls below matter.
We process on your documented instructions, and in ProofHour the configuration is the instruction: which contract records, which applications are excluded from capture, whether AI summaries run, which captures you delete, what a report includes, and when it is shared. We do not use this data for anything of our own — not analytics, not training, not marketing. If the law ever requires us to process beyond your instructions, we tell you first unless that law forbids it.
Access on our side is limited to the operator named above, for support and operations, under a duty of confidentiality. As the privacy policy discloses, that access happens from Türkiye — see Transfers below.
The measures actually in place, checkable against the product:
You authorise the ones the service is built on:
If we add or replace one, the privacy policy's subprocessor list is updated as a new dated version — that is the notice. If you object, your remedy is the honest one: export your data and close the account, and we make both easy.
If someone whose data appears in your records exercises a GDPR right against you, the tools are already there: search and review your records, delete individual captures, export everything, or erase the account. If a request needs something those tools cannot do, contact us and we will assist within a reasonable time.
If we become aware of a personal data breach affecting your records, we notify you without undue delay with what we know: what happened, what data is affected, and what we are doing about it — so you can meet your own notification duties.
Processing and storage stay inside the EU, as listed above. The one transfer is operator access from Türkiye, which has no EU adequacy decision. For that access, the EU Standard Contractual Clauses (Module Two, controller to processor) are incorporated into this DPA by reference, with you as data exporter and Tolga Çağın as data importer, the annexes populated by the descriptions in this document. This is the section a lawyer should read first, and we say so here rather than pretend otherwise: counsel review of these clauses is still ahead of us.
Export gives you everything in portable form, any time. Deleting your account removes your records — including your clients' data in them — after a seven-day grace period in which the deletion can be cancelled. After that, nothing is retained but what the law requires us to keep, as the privacy policy describes.
On reasonable request we provide the information needed to show this DPA is honoured — this document, the privacy policy, and documentation of the measures above. Anything beyond existing documentation (a bespoke audit, a questionnaire programme) we may charge for at a reasonable rate, because there is one operator and finite hours.
Like every ProofHour legal document, a change means a new dated version at a stable URL; the version you accepted stays readable forever. Material changes are announced the same way as changes to the terms.
Your work documented automatically. Reports and invoices from the same verified record. Keep 100% of what you earn.