Data Protection & Security

The technical measures PropFlow uses to protect your data.

What is implemented, which sub-processors are involved, and how a security incident would be handled.

Active & Compliant

This policy is maintained dynamically and is binding worldwide. Last updated: June 18, 2026.

Legal Overview
SECTION 01

1. Security Framework

The measures below are what PropFlow implements to protect data in transit, at rest, and during processing. Each is a statement about this system, not a certification.

SECTION 02

2. Technical Security Measures

Data in transit: HTTPS is enforced on every route, with HTTP Strict Transport Security set by the application. Billing webhooks are verified against the provider signature before they are accepted.

Data at rest: the database and file storage are managed by Supabase and encrypted at rest by that service. Document files are reachable only through an authenticated PropFlow route, never by public URL. Passwords are handled by Clerk and never stored by PropFlow. Secrets are held as encrypted environment variables and are not committed to the repository.

Access controls: Row-Level Security (RLS) on all database tables — every query is scoped to workspace_id, preventing cross-tenant data access. Clerk-managed JWTs validated on every protected route. Privileged route guards enforce workspace membership before any write. Principle of least privilege enforced per user role.

HTTP security headers: X-Frame-Options: DENY (clickjacking), X-Content-Type-Options: nosniff (MIME sniffing), X-XSS-Protection: 1; mode=block, Referrer-Policy: strict-origin-when-cross-origin, Permissions-Policy restricts camera, microphone, geolocation, and payment.

Rate limiting and abuse prevention: write APIs are rate-limited, public endpoints (contact, newsletter, assistant) are rate-limited per IP, and Cloudflare Turnstile is used on sensitive unauthenticated forms. Multi-factor authentication is available on workspace sign-in.

SECTION 03

3. Sub-Processors

Supabase — database and file storage.

Clerk — authentication and identity.

Stripe — subscription billing.

Vercel — application hosting.

Resend and Brevo — email delivery.

OpenAI — the in-product assistant. Do not enter sensitive personal data in chat.

Sentry — error monitoring.

Each publishes its own security and compliance documentation. Contact us for the current list and the data-processing terms that apply.

SECTION 04

4. Data Retention

Workspace data is retained while the subscription is active.

PropFlow does not automatically delete your data when a subscription lapses or is cancelled.

The retention schedule that will apply after a subscription ends is being finalised and will be published here before it takes effect.

To ask about exporting or deleting your data at any time, contact us.

SECTION 05

5. Data Breach Response

Step 1 — Containment: isolate affected systems, revoke compromised credentials, preserve evidence.

Step 2 — Assessment: determine the scope, the categories of data affected, how many people are impacted, and the likelihood of harm.

Step 3 — Regulator notification: notify the relevant authority where the law that applies requires it.

Step 4 — Notifying people: where a breach poses a high risk, notify affected workspace administrators and, where applicable, the people concerned.

Step 5 — Remediation and documentation: implement fixes, record what was done, and update the internal breach register.

SECTION 06

6. Operator Responsibilities

Workspace operators are responsible for ensuring that personal data entered into the platform is collected and processed lawfully where they operate. That includes obtaining the consents they need from tenants and applicants, giving those people appropriate privacy notices, configuring access controls, telling PropFlow promptly about any security incident, and not uploading special-category data without a clear legal basis.

SECTION 07

7. Questions

For data protection enquiries, contact us at propflowhq.com/contact.

If you are unsatisfied with our response, you may be able to complain to the data protection authority for your country.

Data Protection & Security Policy | PropFlow