Legal

Data Processing Addendum

How SalesProof processes personal data on behalf of customers.

Version v1.1 · Effective 8 September 2026

This Data Processing Addendum (“DPA”) is entered into by and between the customer identified in the applicable order form, checkout session, or account registration (“Customer”, “you”, “Controller”) and Habami Limited, a company registered in England and Wales, trading as SalesProof (“SalesProof”, “we”, “Processor”).

This DPA supplements and forms part of the SalesProof End User Licence Agreement (the “Agreement”) and applies whenever SalesProof processes Personal Data on Customer’s behalf in connection with the SalesProof platform and related services (the “Service”). Capitalised terms not defined in this DPA have the meaning given in the Agreement. The current version of this DPA is published at https://salesproof.io/dpa; the version number and effective date appear at the top of this document.

By accepting the Agreement, Customer and SalesProof also agree to the terms of this DPA.

1.Definitions

  • “Applicable Data Protection Law” means all data protection and privacy laws applicable to the processing of Personal Data under this DPA, including the UK General Data Protection Regulation and the UK Data Protection Act 2018 (“UK GDPR”), and, where applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”).
  • “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Personal Data Breach” have the meanings given in Applicable Data Protection Law.
  • “Customer Personal Data” means Personal Data processed by SalesProof on behalf of Customer in connection with the Service, including Candidate Data as defined in the Agreement and Personal Data relating to Customer’s authorised users.
  • “Sub-processor” means any third party engaged by SalesProof to process Customer Personal Data in connection with the Service, as listed in Annex 3.
  • “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as may be amended, replaced or superseded.
  • “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner’s Office under s.119A(1) of the UK Data Protection Act 2018, as may be revised.

2.Scope and Roles

With respect to Customer Personal Data, Customer is the Controller (or, where Customer processes such data on behalf of its own customers or group companies, a Processor) and SalesProof is a Processor acting on Customer’s documented instructions.

Annex 1 describes the subject matter, duration, nature and purpose of processing, the categories of Data Subjects, and the categories of Personal Data processed under this DPA.

3.SalesProof’s Obligations

SalesProof shall:

  • process Customer Personal Data only on Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by law applicable to SalesProof, in which case SalesProof shall (where legally permitted) inform Customer of that legal requirement before processing;
  • ensure that persons authorised to process Customer Personal Data are subject to an appropriate obligation of confidentiality;
  • implement appropriate technical and organisational measures as described in Annex 2;
  • comply with the conditions in Section 4 (Sub-processing) before engaging another processor;
  • taking into account the nature of the processing, assist Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of Customer’s obligation to respond to requests to exercise Data Subject rights, as further described in Section 5;
  • assist Customer in ensuring compliance with its obligations under Applicable Data Protection Law relating to the security of processing, notification of Personal Data Breaches, and data protection impact assessments, taking into account the nature of processing and the information reasonably available to SalesProof;
  • at Customer’s election, delete or return all Customer Personal Data after the end of the provision of the Service, as described in Section 7, except to the extent applicable law requires SalesProof to retain some or all of the Customer Personal Data;
  • make available to Customer information reasonably necessary to demonstrate compliance with this DPA, as further described in Section 8.

4.Sub-processing

Customer authorises SalesProof to engage the Sub-processors listed in Annex 3 to process Customer Personal Data in connection with the Service.

SalesProof will impose data protection terms on each Sub-processor that provide at least the same level of protection for Customer Personal Data as this DPA, to the extent applicable to the nature of the service provided by that Sub-processor.

If SalesProof intends to engage a new Sub-processor, or replace an existing one, it will give Customer at least thirty (30) days’ prior notice (which may be given by email to Customer’s registered account email address and/or by posting an updated sub-processor list at https://salesproof.io/privacy or such other URL as SalesProof notifies to Customer). Customer may object to the new Sub-processor on reasonable data-protection grounds within that notice period. If the parties cannot resolve the objection, Customer’s sole remedy is to terminate the affected part of the Service without penalty.

SalesProof remains liable to Customer for the acts and omissions of its Sub-processors to the same extent SalesProof would be liable if performing the services of each Sub-processor directly under this DPA.

5.Assistance with Data Subject Rights

Taking into account the nature of the processing, SalesProof shall assist Customer, insofar as possible, by appropriate technical and organisational measures, for the fulfilment of Customer’s obligations to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law (including access, rectification, erasure, restriction of processing, data portability and objection).

If SalesProof receives a request directly from a Data Subject in respect of Customer Personal Data, SalesProof will not respond to that request substantively (save to acknowledge receipt) and will, without undue delay, inform Customer of the request and direct the Data Subject to Customer, unless legally required to respond directly.

6.Personal Data Breach Notification

SalesProof shall notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

Such notification will describe, to the extent reasonably available to SalesProof at the time: (a) the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and Customer Personal Data records concerned; (b) the likely consequences of the Personal Data Breach; and (c) the measures taken or proposed to address the Personal Data Breach, including measures to mitigate its possible adverse effects.

SalesProof will cooperate with Customer and provide reasonable assistance requested by Customer to investigate, mitigate and remediate the Personal Data Breach.

7.Deletion and Return of Data

Upon termination or expiry of the Agreement, or upon Customer’s written request, SalesProof shall, at Customer’s election, delete or return all Customer Personal Data within thirty (30) days, except to the extent Applicable Data Protection Law requires SalesProof to retain some or all of the Customer Personal Data, in which case SalesProof will isolate and protect that data from further processing and delete it once the applicable retention requirement lapses.

8.Audit and Compliance

SalesProof shall make available to Customer the information published on SalesProof’s Trust Centre as evidence of the technical and organisational measures described in Annex 2.

SalesProof does not currently hold an independent third-party security audit report (such as a SOC 2 Type II report), and does not offer on-site inspection or third-party-conducted audits under this DPA.

Upon Customer’s reasonable written request, no more than once in any twelve (12) month period, SalesProof will complete and return a written response to a standard security questionnaire (such as a SIG Lite, CAIQ, or Customer’s substantially equivalent form) summarising the technical and organisational measures in place, within twenty (20) business days of receipt. This questionnaire response is SalesProof’s sole audit-related commitment under this DPA — no on-site inspection, third-party-conducted audit, or independent audit report is offered.

9.International Data Transfers

The Service is primarily hosted and Customer Personal Data is primarily processed within the European Economic Area (specifically, Ireland — AWS/Supabase region eu-west-1), as further described in Annex 3.

Where Customer Personal Data is transferred to, or remotely accessed from, a country that Applicable Data Protection Law does not recognise as providing an adequate level of protection — including transfers to Sub-processors incorporated in the United States — such transfer shall be governed by the UK Addendum and/or the Standard Contractual Clauses (Module Two: Controller to Processor, or Module Three: Processor to Processor, as applicable to the parties’ respective roles), which are incorporated into this DPA by reference and completed as set out in Annex 4, together with any supplementary measures reasonably required to ensure an essentially equivalent level of protection.

Where a Sub-processor participates in a legally recognised adequacy decision, certification, or equivalent transfer mechanism, that mechanism may be relied upon in place of, or in addition to, the mechanism above.

10.Security Measures

SalesProof shall implement and maintain the technical and organisational security measures described in Annex 2, and shall not materially decrease the overall security of the Service during the term of the Agreement.

11.Liability

Each party’s liability arising out of or in connection with this DPA, whether in contract, tort or otherwise, is subject to the limitations and exclusions of liability set out in the Agreement, which apply in aggregate to liability under the Agreement and this DPA and not separately or in addition.

12.Term

This DPA takes effect on the date Customer accepts the Agreement and remains in effect for as long as SalesProof processes Customer Personal Data on Customer’s behalf. Sections 6 (Breach Notification), 7 (Deletion and Return), 8 (Audit and Compliance), 9 (International Data Transfers), 11 (Liability), 14 (Governing Law) and Annex 4 survive termination or expiry of the Agreement.

13.Order of Precedence

This DPA forms part of, and is incorporated by reference into, the Agreement. In the event of a conflict between this DPA and the Agreement concerning the processing of Personal Data, this DPA prevails to the extent of the conflict. In all other respects, the Agreement remains in full force and effect.

14.Governing Law and Jurisdiction

This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising out of or in connection with it, consistent with the Agreement.

15.Acceptance and Execution

This DPA is accepted electronically when Customer accepts the Agreement at account registration, at checkout, or by an authorised user clicking to accept within the Service. SalesProof records the accepting user, the Customer workspace, the DPA version accepted and the time of acceptance, and will provide a copy of that record to Customer on request.

Electronic acceptance is sufficient to bind both parties. Where Customer’s internal procurement process requires a countersigned copy, either party may sign below (including by electronic signature) and the DPA so signed shall be identical in effect to the electronically accepted version; in the event of any inconsistency, the version accepted electronically most recently in time prevails.

A countersignature block is included in the downloadable PDF version for customers whose procurement process requires it.

Annex 1.Details of Processing

Subject matter

Provision of the SalesProof sales-hiring assessment platform, including candidate assessments, AI-assisted scoring and analysis, Interview Intelligence, coaching feedback, SalesProof Pulse assessments (formerly named Promotion Readiness), and related reporting, to Customer.

Duration

For the term of the Agreement, and thereafter as set out in Section 7 of this DPA.

Nature and purpose of processing

  • Hosting, storage and secure transmission of Customer Personal Data;
  • Delivery of candidate assessments and capture of candidate responses;
  • AI-assisted scoring, behavioural intelligence, integrity/authenticity analysis, and Interview Intelligence analysis;
  • Generation of reports, dossiers, comparisons and coaching feedback;
  • Account administration, billing, and customer support;
  • Security, fraud prevention, and compliance with legal obligations.

Categories of Data Subjects

  • Candidates invited by Customer to complete an assessment;
  • Customer’s authorised users (employees, contractors and workspace members).

Categories of Personal Data

  • Identity and contact data: name, email address, job title, company name;
  • Assessment data: written responses, audio recordings, interview transcripts, CV/resume information, Interview Intelligence submissions, behavioural and assessment outputs;
  • Account data: credentials, role, billing and subscription information;
  • Technical/usage data: IP address, device and browser information, platform activity logs.

Special categories of data

SalesProof does not intentionally collect special category data (as defined in Article 9 GDPR). Customer must not submit special category data via free-text or file-upload fields within the Service.

Annex 2.Technical and Organisational Measures

This annex has been reviewed and confirmed by SalesProof’s founder, who is also the individual responsible for the Service’s security architecture, as an accurate description of the technical and organisational measures in place as of the date of this DPA.

  • Encryption of Customer Personal Data in transit (TLS) and at rest within the underlying hosting infrastructure;
  • Logical separation of Customer workspaces, enforced via row-level, workspace-scoped access controls;
  • Role-based access controls restricting administrative functions to authorised personnel;
  • Data-minimisation and no-training-use restrictions applied to AI model providers. Zero-data-retention configuration is applied, and has been verified with the provider, for AI-assisted scoring, Interview Intelligence and coaching inference (OpenRouter) and for the Ask SalesProof conversational agent (ElevenLabs). Zero-data-retention and EU/UK data residency are not currently available for the candidate cold-opener speech-to-text transcription flow (ElevenLabs), under which candidate voice audio is processed and retained in the United States under that Sub-processor’s standard retention terms and the transfer mechanism in Section 9 and Annex 4;
  • Confidentiality obligations imposed on personnel with access to Customer Personal Data, limited on a need-to-know basis;
  • Change-management and code-review practices applied to systems affecting scoring integrity and data handling;
  • Backup and business-continuity measures provided by underlying infrastructure providers (see Annex 3).

Annex 3.Authorised Sub-processors

Supabase, Inc.

Purpose

Database, authentication, file storage, and edge-function hosting for the Service

Location of processing

EU (eu-west-1, Ireland)

Amazon Web Services, Inc.

Purpose

Underlying cloud infrastructure (compute and storage) on which Supabase operates

Location of processing

EU (eu-west-1, Ireland)

OpenRouter, Inc.

Purpose

AI model routing/inference gateway for AI-assisted scoring, Interview Intelligence, and coaching features

Location of processing

United States (routing entity); model inference via a verified endpoint configured in the EU (eu-west-1) where supported

ElevenLabs, Inc.

Purpose

Conversational voice AI (Ask SalesProof) and speech-to-text transcription (candidate cold-opener response)

Location of processing

United States (global estate; account not provisioned for EU/UK data residency as of the date of this DPA)

Lovable Labs Incorporated

Purpose

Application development and hosting platform

Location of processing

United States (incorporated entity). Confirmed via Lovable’s own Privacy Policy: international transfers rely on EU SCCs (Module 2) + the UK IDTA + the Swiss Addendum, applicable regardless of plan tier; raw/identifiable data is not used for AI training.

Stripe Payments Europe, Ltd.

Purpose

Payment processing for Customer subscription and billing data

Location of processing

EEA/UK (account is GB-domiciled; Stripe Payments Europe, Ltd. confirmed as the contracting entity)

Annex 4.International Transfer Mechanism

Where Section 9 of this DPA applies, the Parties agree that the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (“UK Addendum”), issued by the Information Commissioner’s Office, is incorporated into and forms part of this DPA by reference, with Customer as the data exporter and SalesProof (and, where applicable, the relevant Sub-processor) as the data importer.

Tables 1 to 3 of the UK Addendum are populated by reference to Annexes 1 to 3 of this DPA. For Table 4, either Party may end the UK Addendum as set out in Section 19 of the linked Approved EU SCCs.

Where a Sub-processor is established outside the UK and the EEA, the Standard Contractual Clauses (Module Two or Module Three, as applicable), as most recently issued by the European Commission, are incorporated by reference on equivalent terms, completed by reference to Annexes 1 to 3 of this DPA.