Data Processing Addendum
Last updated June 24, 2026
If you handle other people's data through Purrposal, this explains how we process it on your behalf, who our sub-processors are, and how deletion works.
Roles
When you use Purrposal to build proposals, you are the data controller for the information you put in, your prospect details, your client list, the content you write. Purrposal is the data processor: we process that information only to provide the service to you, and only on your instructions.
What we process for you
The agency and prospect details you enter, the public website content we read when you paste a URL, the proposals you generate, and the engagement events recorded when a proposal you share is viewed. We process this to generate, store, serve, and measure your proposals, nothing else.
Sub-processors
We use a small set of infrastructure providers to run the service: Vercel (hosting), Supabase (database and authentication), OpenAI (drafting proposal copy from the public content you provide), a rendering service (capturing a public-homepage screenshot), and Razorpay (payments). Each processes data only to deliver its part of the service. If we add or change a sub-processor we will update this page.
Security
Passwords are hashed, sessions use secure http-only cookies, and access to your data is scoped to your account. We use reputable providers with their own security programs and encrypt data in transit.
Deletion and return
You can delete any proposal from your dashboard at any time. On request to hello@purrposal.com we will delete your account and the data we hold for you, and we will export your data to you in a portable format if you ask.
International transfers
Our providers may process data in regions outside your own. Where personal data covered by the GDPR or UK GDPR leaves the EEA or the UK, those transfers rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), or on an adequacy decision for the destination country. By using Purrposal you instruct us to process and transfer data through these providers on that basis.
GDPR Article 28
This addendum is our processor commitment under Article 28 of the GDPR. We process personal data only on your documented instructions, keep the people who handle it bound to confidentiality, help you respond to data-subject requests and to your own security and impact-assessment duties, and apply the security measures described above. We process the data only for the duration of your use of the service plus any short retention needed to provide it.
Breach notification
Speed is the point here. If we become aware of a personal-data breach affecting your data, we will notify you without undue delay, and in any case within 72 hours, with the detail you need to meet your own reporting duties. We will tell you what happened, what data was involved as far as we know it, and what we are doing about it.
Audit
Audits are welcome. On reasonable notice, and no more than once a year unless a regulator or a real incident calls for it, we will give you the information you need to confirm we are meeting this addendum, including our current sub-processor list and a summary of our security measures. Where a deeper audit is required by law, we will arrange one that does not disrupt the service or expose other customers' data.
Contact
For a signed copy of this addendum, a list of sub-processors, or any data-processing question, email hello@purrposal.com.
Questions about this page? Email hello@purrposal.com.