PRIVACY POLICY · 13 SEPTEMBER 2026
Your project.
Handled with care.
Controller
Kevin Gerock – Prooflode, sole proprietor / Einzelunternehmer, Strausberger Platz 7, 10243 Berlin, Germany. Privacy contact: privacy@prooflode.com. Phone: +49 8151 9727144.
Information and purposes
We process the work email and business-contact details you submit with a fit inquiry, together with public URLs and the project information you provide, to assess fit and respond about an accepted project. Once a project is accepted, we process the signed-in account identifier, complete production brief, delivery and support records to administer the contract and protect project access. Stripe Checkout, when enabled, collects billing identity, address, country and applicable tax identifiers. We do not receive full card details.
Precontract and contract processing relies on GDPR Article 6(1)(b) where applicable. Correspondence with agency employees or representatives may instead rely on legitimate interests under Article 6(1)(f). Legal recordkeeping uses Article 6(1)(c); security and proportionate abuse prevention use Article 6(1)(f). No marketing consent is bundled with purchasing.
Public pages and AI-assisted production
The free checker inspects public HTML without running scripts. It requests no email and makes no language-model call. Paid production sends buyer-query context and, for editorial drafting, the client’s public name, service, buyer, market, verified facts and scoped page text to the OpenAI Responses API. Agency contact details, billing identity, account identifiers and internal acceptance notes are excluded. Requests set store:false; this does not promise zero provider retention.
Do not submit passwords, sensitive or confidential material, customer lists or unnecessary personal data. Client exports omit supplier notes, reviewer contact details, API usage/costs and provider request IDs while retaining source evidence and material limitations. A named reviewer must approve delivery.
Providers and transfers
The implementation uses OpenAI Sites and its Cloudflare hosting/database infrastructure, ChatGPT sign-in for protected project access, the OpenAI API, Stripe for checkout and invoices when enabled, Brevo for transactional email, Migadu for human correspondence and AWS Route 53 for domain DNS. Short project emails link to protected deliveries rather than including client reports. Brevo is not used for newsletters or marketing tracking.
Authentication and payment providers may also act under their own terms. No EU-only processing or zero-retention assurance is made.
Retention and access
Application cleanup removes unpurchased fit inquiries and incomplete production briefs after 30 days. Released evidence and operational measurements are removed after 90 days, subject to documented payment or dispute holds. Accounting records and necessary correspondence are retained separately for the applicable statutory periods. Provider-side retention must be configured separately.
Projects require sign-in and server-side ownership checks. The real-company demonstration additionally requires the named-operator allowlist, even if marketing pages later become public. API measurement records contain usage, estimates and status rather than keys or full request bodies.
Cookies and analytics
Authentication uses necessary platform session mechanisms. Abuse prevention uses a daily salted network-address hash with short-lived limits. Aggregate daily event counts have no persistent visitor identifier. Prooflode adds no Meta Pixel, Hotjar, Google Ads tracking, nonessential marketing cookies or cross-site fingerprinting.
Your rights
Subject to legal conditions, request access, correction, erasure, restriction or portability; object to legitimate-interest processing; or withdraw consent where used. Contact privacy@prooflode.com. You may complain to the Berlin Commissioner for Data Protection and Freedom of Information or another competent supervisory authority, including at your habitual residence or workplace.