Data processing agreement
Last updated 2 September 2026
When you send a proposal through Closewatch, you decide who receives it and why, and we record how they read it on your behalf. In UK and EU data protection law that makes you the controller and us the processor. These are the terms of that arrangement, and they apply to every account without needing to be signed separately.
Who is who
You are the controller of the personal data your recipients generate. Closewatch is your processor and acts only on your instructions, which are: host the proposal you upload, serve it to whoever holds the link you created, and report back how it was read. Uploading a proposal and creating a share link is how those instructions are given.
For your own account — your email, your name, your billing details — we are the controller, and the privacy policy covers that half.
What is processed, and for how long
Categories of data subject: the people you send proposals to, and anyone they forward one to.
- The recipient name and email address you type when creating a link.
- When a link was opened, for how long, and which pages were read.
- Whether the document was downloaded or printed.
- A first-party cookie identifying the browser, so a return visit is not counted as a new reader.
- A hashed IP address, the country and city its network resolves to, and the browser, operating system and device type.
Processing lasts as long as your account does. Twelve months after a visit we strip the hashed IP address, the city and the referring link from it automatically. Delete a proposal and everything recorded against it goes with it; close your account and all of it does.
Sub-processors
These companies process the data because they run parts of the service. We will tell account holders before adding another, in time to object.
- Supabase — database, authentication and file storage.
- Cloudflare — application hosting and delivery.
- Resend — notification email, where enabled.
- Stripe — payment processing for account holders on a paid plan. It never receives reader data.
- Google — only where an account holder chooses to sign in with Google.
Security and confidentiality
- Proposal files are held in private storage and reached only through short-lived signed links.
- Every table is protected by row-level security, so one account cannot read another account’s rows.
- IP addresses are hashed with a secret salt before they are stored, and never kept in the clear.
- Share links carry an unguessable token, expire on a set date, and can be revoked at any time.
- Anyone with access to production data is bound to keep it confidential.
Helping you meet your own obligations
If one of your recipients asks you for their data, or asks you to delete it, write to us and we will find or remove the visits behind that share link. You can also revoke a link yourself at any moment, which stops any further recording immediately.
If personal data in our care is exposed, we will tell affected account holders without undue delay and with what we know at the time, so you can meet your own reporting deadline.
Where the data sits
Our sub-processors operate globally, so data may be processed outside the country it was collected in. Each of them offers standard contractual clauses for those transfers, and we rely on them.
Audit, and the end of the arrangement
On request we will answer reasonable questions in writing about how the data is handled, and share what our sub-processors publish about their own controls. When your account closes we delete the data rather than return it, unless you ask for an export first.
Signing it
These terms apply to every account as part of the terms of service, so there is nothing to countersign for them to bind us. If your client needs a copy on their own paper, write to us and we will sign yours.
Questions about anything here? Email hello@getclosewatch.com.