Legal
GDPR & your data
ProOnboard is built so you can onboard clients in the EU and UK without a compliance headache.
Controller and processor
You are the controller of the client data you collect through ProOnboard. We are your processor and only handle that data on your documented instructions — which, in practice, means running the features you use.
Lawful basis
For your own account data we rely on performance of a contract. For the client data you collect, you choose the lawful basis — usually contract or legitimate interest — and we give you the tools to describe it in your welcome message.
Data subject rights
- Access: export a client's answers, files and history from their detail page.
- Rectification: edit any client record or resubmitted answer at any time.
- Erasure: deleting a client removes their record, submissions and uploaded files.
- Portability: exports are plain, machine-readable files.
- Objection and restriction: pause an onboarding by changing its status.
If a request reaches us directly, we forward it to you rather than acting on your clients' data ourselves.
Sub-processors
We use a small number of infrastructure providers for hosting, database, file storage and transactional email. We keep a current list and will give notice before adding a new one.
International transfers
Where data leaves the EEA or UK, transfers are covered by Standard Contractual Clauses and the UK Addendum.
Breach notification
If we become aware of a personal data breach affecting your workspace, we will notify you without undue delay and within 72 hours, with what we know and what we are doing about it.
Data processing agreement
Need a signed DPA? Email privacy@proonboard.com and we'll send one over.