Skip to content
ProofList

Privacy

Last updated 26 September 2026.

ProofList makes training certificates and emails them to the people who earned them. That means two different kinds of personal data pass through it, with two different people responsible for them, and this page is organised around that difference because nothing else about it makes sense otherwise.

Two roles, briefly

For a trainer’s own account (the email address they sign up with, their business name, their logo), we decide what is held and why. We are the controller, and they ask us directly.

For the participants on a course (the names and addresses a trainer uploads), the trainer decides. They chose to run the course, they hold the relationship, and they decide how long the records last. We only do what their account tells us to. They are the controller and we are their processor, which means a participant asking about their data should ask the trainer who taught them. We help the trainer answer.

Who we are

Dimitris Parperis, established in Cyprus, operating ProofList as an individual. Contact: hello@prooflist.app. The competent supervisory authority is the Office of the Commissioner for Personal Data Protection, Cyprus.

At incorporation this responsibility transfers to the operating company, and this page will be updated to name it.

If you are a trainer

We hold your name, your email address, a hash of your password (never the password itself), the business name certificates are sent from, your brand colour, any logo or certificate design you upload, your templates, and a record of the batches you have sent and what they cost.

We also keep a record of each sign-in session, which includes your IP address and browser user-agent string. That is there so an unfamiliar session can be spotted and ended, it is personal data, and sessions expire after thirty days.

The lawful basis is the contract between us: you asked for an account and this is what running one requires. Where you are on a paid plan we also keep the billing records we are obliged to keep.

We keep all of it until you close your account, which you can do yourself from Settings. That deletes your account, your batches, your participant lists and every certificate file, immediately and irreversibly. The same screen gives you a copy of everything as a file, at any time, without asking us.

Deleting a single batch or template is gentler than that. It goes to Recently deleted, where you can restore it for thirty days and where its data is still held. After thirty days it is purged, with every version of every certificate file.

There is no advertising, no profiling, and no third-party analytics or tracking anywhere in the product or on this site. No data about you is sent to any analytics company. The only cookie is the one that keeps you signed in.

If you received a certificate

Someone ran a course you attended and used ProofList to send you the certificate. They decide what is held about you and for how long. If you want your record corrected or deleted, ask them. They can do both themselves, and they can send you a copy of everything held about you. Replying to the email your certificate arrived in reaches them directly.

What is held is the name printed on your certificate, the email address it was sent to, the course, the dates, and any hours or expiry the trainer recorded. The certificate itself is stored as a PDF file, which has your name on it. We also log that the email was sent, so the trainer can see whether it arrived.

When a trainer erases you, the name and address are replaced everywhere they appear and the certificate file is deleted outright, including every stored version of it. What remains is that a certificate was issued on a date, with nothing in it that identifies you: a training record the trainer may need to keep.

Certificate emails carry no tracking pixel and no tracked links, because they contain no images we add and no links at all. Your address is never sold, shared, added to a mailing list, or used to market anything to you. If a trainer has renewal reminders switched on you may receive one message before your certificate expires; it comes from them, and replying reaches them.

You can also write to us at hello@prooflist.app. We will pass it to the trainer responsible and tell you we have done so. We are not permitted to change their records on our own initiative, but we will not leave you without an answer.

If you joined the waitlist

We hold your email address, the date you submitted it and the date you confirmed it. That is the entire record: no name, no IP address, no cookies, no analytics, and no tracking in the confirmation email. The basis is your consent, and it is used to email you once when the beta opens.

We keep it until the invitations have gone out or until you ask us to remove it, whichever is first. One email is enough and we will not ask why.

What we count

We count how many times each public page is viewed, and which website a visit arrived from. That is the whole of it, and it is stored as a daily total: on this day, this page was viewed this many times, this many of them from that site.

Nothing is stored about the person viewing. No IP address, no browser details, no identifier, no session, and no time more precise than the day. Nothing is written to your device, no script runs in your browser, and no other company is involved. The counting happens on our own server, from a request you were making anyway. There is nothing here that could be traced back to you, including by us.

That is also why we cannot tell you how many visitors we have, only how many views: recognising somebody returning would need a cookie or a fingerprint, which is exactly what this avoids. We would rather have the weaker number.

Where everything lives

Participants’ personal data does not leave the European Union. These are the only companies that process data on our behalf:

WhoWhat they doWhere
ScalingoRuns the application and the databaseParis, France
ScalewayStores logos, designs and certificate PDFsParis, France
BrevoDelivers certificates, reminders and account emailFrance
HetznerHolds an encrypted nightly backup of the database and the filesFalkenstein, Germany
MigaduOur own mailbox, if you write to usSwitzerland

The first four handle everything the product does. Migadu is different and worth being precise about: it runs the mailbox that receives mail sent to us, and no certificate, participant list or account record ever passes through it. Migadu-Mail GmbH is established in Switzerland, which the European Commission recognises as providing an adequate level of data protection. They do not publish which countries their datacentres are in, so if you email us we cannot promise your message is stored inside the EU. Everything the product itself holds is.

The storage holding certificates is private, encrypted at rest, and never served publicly. A certificate is reachable only through a signed link that expires in minutes, or as the attachment on the email it was sent in. Connections to the database are encrypted and the server’s identity is verified.

Every night a copy of the database and of the stored files is encrypted here, before it leaves, and kept at Hetzner in Germany so that losing either of the two companies above does not lose your certificates. Hetzner holds only the encrypted copy and no key to it. Each copy is kept for fourteen days and then removed, so anything erased from the product is gone from every backup within that time, and if a backup ever has to be restored, every erasure made after it was taken is applied again before the product comes back.

Fonts are stored with the application rather than fetched from a font service, so viewing a certificate or this site does not tell anyone else that you did.

Your rights

You can ask for a copy of what is held about you, ask for it to be corrected or deleted, object to how it is used, or withdraw consent where consent is the basis. Trainers can do all of this themselves from Settings. Participants should ask the trainer who ran their course, and we will help if that goes nowhere.

You can also complain to your national data protection authority, or to the Cypriot Office of the Commissioner for Personal Data Protection, which supervises us.

Contact

hello@prooflist.app

Back to the homepage