ProofEU was built from day one for European companies subject to the General Data Protection Regulation. Here is exactly what we do — and don't do — with your data.
Database: Turso SQLite Cloud, Dublin (Ireland) region (EU). No automatic replication to servers outside the EEA.
Application server: Vercel Edge Network, with Dublin (Ireland) as the preferred region. European requests are processed in Europe.
File storage: No user files stored outside the EEA. Project logos are hashed and stored in the Dublin (Ireland) database.
In transit: TLS 1.3 on all connections (HTTPS enforced, HSTS enabled).
At rest: AES-256 encryption of the Turso database at the disk level.
Passwords: Hashed with bcrypt (cost factor 12). Never stored in plain text.
Tokens: Collection and access tokens are cryptographically random UUID v4 values.
ProofEU only collects the data necessary to run the service (data minimization):
No third-party tracking cookies. No Facebook/Google pixel. No external behavioral analytics tool.
ProofEU honors all rights granted by the GDPR (Art. 15 to 22):
As a processor of your customer data (the testimonial authors), ProofEU provides a Data Processing Agreement (DPA) compliant with Article 28 of the GDPR.
This agreement defines our obligations as a processor, the security measures implemented, and the procedures in case of a data breach.
Download the DPAProofEU relies on the following sub-processors, all GDPR-compliant:
| Sub-processor | Purpose | Region |
|---|---|---|
| Turso (ChiselStrike) | Cloud SQLite database | Dublin (Ireland), EU |
| Vercel Inc. | Application hosting | Dublin (Ireland), EU (preferred) |
| Lemon Squeezy | Payment (merchant of record) | EU |
For any question about data protection, contact us at privacy@proofeu.com. We commit to responding within 72 hours.