1. Who is responsible
Proposa is operated by Manuel De Ceglie in Italy. For privacy questions, data requests, or a copy of the operator's full legal and postal details, contact manuel@getproposa.app.
When a Proposa customer enters information about their own clients, that customer generally decides why and how that information is used. In that context, the customer is the controller and Proposa processes the data to provide the service.
2. Data we process
- Account and authentication data, such as email address, name, user and workspace identifiers, and session information.
- Workspace content, including company settings, client details, proposals, prices, terms, messages, activity events, uploaded documents, and generated files.
- Billing data, including Stripe customer, subscription, price, invoice, payment status, and transaction identifiers. Proposa does not receive complete card details.
- Support and transactional communications, including the email address, request content, delivery status, and information needed to investigate a problem.
- AI input and output when an AI feature is used, including briefs, pasted text, relevant proposal history, and extracted document text.
- Technical and usage information, such as browser session identifiers, page activity, device or referral information, logs, and consent choices.
3. Why we use data
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide and secure Proposa | Account, workspace, session and activity data | Performance of the contract; legitimate interests in security and reliability |
| Process subscriptions | Billing identifiers, plan and invoice status | Performance of the contract; legal obligations |
| Send service messages and answer support | Contact details, message content and delivery logs | Performance of the contract; legitimate interests |
| Run optional AI features | Content deliberately submitted to the feature and relevant workspace context | Performance of the requested service |
| Measure product and website use | Pageview and technical analytics data | Consent where required |
| Prevent abuse and comply with law | Account, security, transaction and audit information | Legal obligations; legitimate interests |
4. Providers and recipients
Proposa uses specialist providers only where needed to operate the service. The current technical stack includes WorkOS for authentication, Convex for application data and file storage, Stripe for billing, Resend for email delivery, Google Gemini for optional AI processing, and Vercel for hosting and analytics.
With analytics consent, Proposa may also load Google Analytics, Umami, and Vercel Analytics. More detail is available in the Cookie & Analytics Notice.
Data may also be disclosed to professional advisers, authorities, or another party to a corporate transaction when legally necessary and subject to appropriate safeguards.
5. International transfers
Some providers may process information outside Italy or the European Economic Area. Where data protection law requires it, transfers rely on an adequacy decision, contractual safeguards such as the European Commission's standard contractual clauses, or another lawful transfer mechanism.
6. How long data is kept
Proposa keeps account and workspace data while the account is active and for the time reasonably needed to provide the service, resolve disputes, prevent abuse, comply with tax or legal duties, and maintain proportionate backups. Retention depends on the data category and the reason it is held rather than one period for every record.
When an account or content is deleted, it is removed from active use according to the service workflow. Residual copies may remain temporarily in protected backups or where law requires continued retention. Support requests can be used to ask for deletion or more detail about a specific category.
7. Your choices and rights
Send a request to manuel@getproposa.app. Proposa may need to verify identity and clarify the request before acting.
- Ask for access to or a copy of personal data.
- Ask to correct inaccurate or incomplete data.
- Ask for deletion or restriction where the legal conditions apply.
- Object to processing based on legitimate interests.
- Withdraw consent for future analytics processing at any time.
- Ask for portable data where the right applies.
- Complain to the Italian data protection authority or the competent authority where you live.
8. Security, children, and changes
Proposa uses access controls, authenticated workspaces, tokenized client links, encrypted provider connections, and operational safeguards intended to protect information. No online service can promise absolute security; report a suspected issue promptly through Support.
Proposa is a business tool and is not directed to children. Do not use the service to collect children's data unless you have a lawful, appropriate reason and the necessary permissions.
This policy may change when the product, providers, law, or data practices change. The effective date and version above identify the current notice. Material changes will be communicated through an appropriate product or email notice where required.