Who we are and who is responsible for your data
Proof by Broadable™ is a product of CodEye Technologies Pvt Ltd, a company incorporated in India. References to "we," "us," or "Proof" in this Privacy Policy refer to CodEye Technologies Pvt Ltd, operating the Proof by Broadable™ product at proof.broadable.com.
For the purposes of the General Data Protection Regulation (GDPR) and other applicable privacy laws, CodEye Technologies Pvt Ltd is the data controller for personal data collected through Proof. Our registered business address and contact details are available on request by emailing [email protected].
This policy applies to:
- Visitors to proof.broadable.com and broadable.com
- Registered users and paying customers of Proof
- Anyone whose testimonial data is collected through Proof-powered collection forms or widgets
If you are a testimonial submitter (someone who submitted a review through a form created by a Proof customer), the business that collected your testimonial is the data controller for that specific data. Please contact them directly with questions about how they handle it.
What personal data we collect and why
We collect different types of data depending on how you interact with Proof. Here is a clear breakdown:
- Full name
- Email address
- Password (hashed, never stored in plain text)
- Business or brand name (optional)
- Profile photo (optional)
- Name on payment method
- Billing address and country
- Purchase amount and date
- Payment method type (e.g., card, PayPal)
- Card data is held exclusively by Paddle and never stored on our servers
- Text, star ratings, and written testimonials you collect
- Video testimonials uploaded by submitters
- Name, role, and company of testimonial authors
- Platform metadata from imported reviews (e.g., Google, G2)
- IP address (anonymised after 30 days)
- Browser type and operating system
- Pages visited and features used within the dashboard
- Session duration and click events (aggregate, not individual tracking)
- Error logs for debugging purposes
We do not collect sensitive personal data such as health information, religious beliefs, political opinions, racial or ethnic origin, or biometric data.
How we use your personal data
We use the data we collect for the following purposes only:
The legal basis for processing your data
Under GDPR, we must have a lawful basis for each processing activity. Here is the basis we rely on for each purpose:
| Purpose | Legal basis | Notes |
|---|---|---|
| Providing the Proof service | Contract performance | Necessary to fulfil the agreement you entered when purchasing Proof. |
| Payment processing | Contract performance | Required to complete your purchase and issue refunds when applicable. |
| Account communications | Contract performance | Transactional emails about your account are sent without separate consent. |
| Product improvement analytics | Legitimate interests | Improving the product is in both our and your interest. Data is anonymised wherever possible. |
| Marketing emails | Consent | Sent only with your explicit opt-in. Withdrawal of consent is possible at any time via the unsubscribe link. |
| Legal obligations | Legal obligation | Retaining billing records, responding to lawful authority requests, and tax compliance. |
| Fraud prevention and security | Legitimate interests | Protecting our systems and users from fraud, abuse, and security threats. |
Who we share your data with
We share your personal data only with the service providers necessary to operate Proof, and only to the extent required for them to perform their specific function. We do not sell data, and we do not allow any third party to use your data for their own marketing purposes.
Cookies and tracking technologies
We use cookies and similar technologies to operate the Proof platform. Here is a clear summary of what we use and why:
Essential cookies (always active)
These cookies are necessary for Proof to function. They maintain your login session, remember your preferences within the dashboard, and protect against cross-site request forgery (CSRF). You cannot opt out of these without disabling the service entirely.
Functional cookies (optional)
These cookies remember your settings and preferences such as language, dashboard layout preferences, and notification settings. They are not used for tracking or advertising.
Analytics cookies (optional, privacy-respecting)
We use minimal, privacy-respecting analytics to understand how Proof is used at an aggregate level. These do not track individuals across other websites. You can opt out of these via your account settings or by using a browser extension that blocks tracking scripts.
We do not use advertising, retargeting, or third-party tracking cookies. For full details, see our Cookie Policy.
How long we keep your data
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Here is our standard retention schedule:
| Data type | Retention period | Reason |
|---|---|---|
| Account data | Duration of active account + 90 days post-deletion | Allows account recovery if deletion was accidental. Permanently deleted after 90 days. |
| Testimonial content | Duration of active account | Core product data. Deleted with account unless exported by the user before deletion. |
| Billing records | 7 years from transaction date | Required by Indian tax law and international accounting standards. |
| Support correspondence | 3 years from last interaction | Necessary to resolve recurring issues and ensure service continuity. |
| IP addresses (server logs) | 30 days, then anonymised | Used for security and debugging only. Anonymised to prevent individual identification. |
| Analytics data | 13 months, then aggregated | Standard analytics retention. Aggregated data is retained indefinitely in anonymised form. |
| Marketing consent records | Until consent is withdrawn + 3 years | Required to demonstrate legal basis for communications. |
When you close your account or request deletion, we will permanently delete or anonymise your personal data within 90 days, except where legal obligations require us to retain billing records for longer.
Your rights over your personal data
Depending on your location, you have several rights over your personal data. We honour all of these rights for all users globally, regardless of jurisdiction:
To exercise any of these rights, email us at [email protected] with "Data Rights Request" in the subject line. We will respond within 30 calendar days. We may ask you to verify your identity before processing sensitive requests.
How we protect your data
We take security seriously. The measures we have in place include:
No system is 100% secure. While we implement industry-standard protections, we cannot guarantee absolute security. We encourage you to use a strong, unique password for your Proof account and enable two-factor authentication when available.
Contact us about privacy
If you have any questions about this Privacy Policy, want to exercise your data rights, or wish to raise a concern about how we handle your personal data, please contact us:
Privacy questions and data requests
We respond to all privacy-related emails within 72 hours (business days). Data subject requests are completed within 30 days per GDPR requirements.
We reserve the right to update this Privacy Policy at any time. When we make material changes, we will notify active users by email and update the "Last updated" date at the top of this page. Your continued use of Proof after a policy update constitutes acceptance of the revised terms. For historical versions of this policy, contact [email protected]. This policy is governed by the laws of India, without prejudice to your rights under applicable data protection legislation in your country of residence.