Provenly — Terms of Service
Version: v1
Effective date: 16 July 2026
1. Who we are
Provenly is operated by Matthew McAllen, a sole trader trading as Provenly.
| Contact | hello@provenly.co.uk |
| ICO registration reference | ZC195864 |
| Address for legal notices | Provided in the copy of these terms held by each customer, and available on request from hello@provenly.co.uk. |
In these terms, "we", "us" and "Provenly" mean Matthew McAllen trading as Provenly. "You" and "your" mean the business that has opened an account.
2. What Provenly does
Provenly is a health and safety compliance platform. It lets a business upload health and safety documents, share them with its employees, record that those employees have read and understood them, and produce evidence of that record.
The purpose of the service is to create a defensible evidence trail. Records of acknowledgement are written to an append-only, tamper-evident audit log, and cannot be altered by anyone using your account.
3. Your account
Opening an account. The person who signs up must be authorised to open the account on behalf of the business and to accept these terms on its behalf. By signing up, they confirm that they are.
Roles. Accounts have five roles: account owner, manager, employee, auditor, and (on our side) super-admin. The account owner controls who is invited and what they can do.
Security. Two-factor authentication is required for account owners, managers and auditors before they can use the platform's management interfaces. You are responsible for keeping account credentials secure and for actions taken under your account. Tell us promptly at hello@provenly.co.uk if you believe an account has been compromised.
Employees. You decide who your employees are, what documents they see, and what they are asked to acknowledge. You are responsible for the accuracy of the information you enter about them.
4. Your data, and who controls it
You control your employees' data. In data protection terms, you are the controller of your employees' personal data and we are your processor. You decide what is done with that data; we act on your instructions. The terms governing that relationship are set out in Schedule 1 (Data Processing Agreement), which forms part of these terms.
We control your account holders' data. For the personal data of the people who hold accounts with us — your account owner, managers and auditors — we are the controller, because we decide how to run and secure the service. How we handle that data is explained in our Privacy Notice.
Your documents remain yours. You keep all rights in the documents you upload. We do not claim ownership of them, and we do not use them to train artificial intelligence models.
5. What you must not do
You must not use Provenly to:
- upload anything unlawful, or anything you do not have the right to upload;
- upload special category data (health, biometric, racial or ethnic origin, religious belief, trade union membership, sexual orientation, political opinion) without a lawful basis for it, and without telling us;
- attempt to access another business's data, or to circumvent the platform's security or audit controls;
- attempt to alter, delete or falsify an acknowledgement record or audit log entry;
- upload malicious code, or use the service to attack or overload it.
We may suspend an account that breaches this section.
6. Pilot phase — availability and known limitations
This section is deliberately blunt. We would rather over-disclose than under-disclose.
During the pilot phase:
- The platform is in active development. Features may change and bugs may exist. We are working with a small number of businesses precisely so that problems surface with us rather than with a paying customer.
- The service is provided free of charge. No fees are payable for the pilot.
- There is no service level agreement. We do not guarantee uptime, availability or response times, and we do not promise the service will be uninterrupted or error-free.
- A formal third-party penetration test has not yet been carried out. We have completed our own security testing, but the platform has not been independently penetration tested. That test is scheduled before we take our first paying customer. You should factor this into your own risk assessment before uploading data.
- Some data-handling operations are performed manually by us, rather than by a self-service function in the platform. These are identified in Schedule 1 §8.4 and §11. They are performed on your written instruction and within the time limits stated. This is a limitation of a pilot-stage product, and we would rather you knew.
- We may change or withdraw features as the product develops. Where a change materially affects you, we will tell you.
None of this reduces our data protection obligations in Schedule 1. Those apply in full.
7. Fees
The service is free during the pilot phase. If we introduce charges, we will give you at least 30 days' notice before any fee applies to your account, and you may close your account before it does.
8. Ending the agreement
You may close your account at any time by telling us at hello@provenly.co.uk.
We may end this agreement by giving you 30 days' notice, or immediately if you materially breach these terms.
Getting your data out. After closure we will return or delete your employees' personal data in accordance with Schedule 1 §11 — the choice is yours, and we act on your written instruction.
What survives. Sections 9 (intellectual property), 10 (liability) and 12 (governing law), and Schedule 1 §11 (end-of-contract data handling), survive the end of this agreement.
9. Intellectual property
We own the platform, its software, its design and its branding. You own your documents and your data. Neither of us gains rights in the other's property by using the service.
You may not copy, reverse-engineer or resell the platform.
10. Liability
What we do not limit. Nothing in these terms limits or excludes our liability for:
- death or personal injury caused by our negligence;
- fraud or fraudulent misrepresentation;
- anything else that cannot lawfully be limited or excluded.
What we do limit. Subject to the above, and because the service is provided free of charge during the pilot:
- our total liability to you, for all claims arising out of or in connection with this agreement, is limited to £100;
- we are not liable for indirect or consequential loss, loss of profit, loss of business, loss of goodwill, or loss of anticipated savings;
- we are not liable for loss or corruption of data to the extent it results from your own acts or omissions, or from your failure to keep your own records.
Your own compliance remains yours. Provenly is a tool for producing evidence. It does not discharge your legal duties under health and safety law, and it is not a substitute for competent health and safety advice. You remain responsible for the adequacy of your own risk assessments, policies and training.
This limit is low, and we are telling you so plainly. It is low because the service is free and provided by a sole trader. If that is not acceptable to you, do not accept these terms.
11. Changes to these terms
We may change these terms. When we do, we publish a new version with a new version number and effective date.
For material changes we will give you at least 30 days' notice by email to your account owner and ask you to accept the new version. We keep a record of which version you accepted and when, and you can view the version you accepted from your account settings at any time.
Where a change is required by law and cannot wait, we may make it sooner, and will tell you why.
12. General
Governing law. These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Whole agreement. These terms, together with Schedule 1 and Schedule 2, are the whole agreement between us.
Order of precedence. If Schedule 1 conflicts with the main body of these terms, Schedule 1 prevails on anything to do with personal data.
No transfer. You may not transfer your rights under this agreement without our written consent.
Complaints. If you have a complaint about how we handle personal data, contact us at hello@provenly.co.uk. We will acknowledge it within 30 days and tell you the outcome. You may also complain to the Information Commissioner's Office (ico.org.uk).
Schedule 1 — Data Processing Agreement
This Schedule is the written contract required by Article 28(3) of the UK GDPR. It applies whenever we process personal data on your behalf. It forms part of the Terms of Service and is accepted at the same time.
1. Roles
- You (the customer) are the controller. You determine the purposes and means of processing your employees' personal data.
- We (Provenly) are the processor. We process that data on your behalf, on your instructions.
If we ever determine the purposes and means of processing for ourselves, we act as a controller for that processing. Section 12 discloses the one situation where this occurs.
2. Subject matter of the processing
Hosting a health and safety compliance platform, and creating and preserving a tamper-evident record of your employees' acknowledgement of health and safety documents.
3. Duration of the processing
For as long as you have an account, and afterwards only as set out in §11.
4. Nature and purpose of the processing
Nature: collection, storage, organisation, retrieval, transmission by email, and — on your instruction — anonymisation, export and deletion.
Purpose: enabling you to demonstrate that you shared health and safety information with your employees, and that they read and understood it, so that you can defend a claim or answer a regulator.
5. Types of personal data
- Employee name (legal name and display name)
- Employee email address (work or, with the employee's confirmation, personal)
- Employment start date and tracking start date
- Group and role membership
- Acknowledgement records: timestamps, the document version acknowledged, IP address, browser user-agent, and whether the document was opened
- Login timestamps and IP addresses
- Any personal data that appears inside the documents you choose to upload
6. Categories of data subject
Your employees, and the individuals who hold accounts with us on your behalf (your account owner, your managers, and any auditor you invite).
7. Your obligations and rights as controller
You must:
- have a lawful basis for the processing you instruct us to carry out (typically your legitimate interests as an employer in demonstrating health and safety compliance — we provide a template legitimate interests assessment);
- tell your employees that you are using Provenly, and give them the privacy information the UK GDPR requires;
- ensure the personal data you upload is accurate and limited to what is needed;
- not upload special category data unless you have a lawful basis for it under Article 9 and you have told us;
- give us instructions that are lawful.
You may:
- instruct us in writing on how to process the data;
- object to a new sub-processor (§9);
- ask us for the information you need to satisfy yourself that we are meeting our Article 28 obligations, and audit us (§13);
- choose whether we return or delete the data at the end (§11).
8. Our obligations as processor
8.1 We process only on your documented instructions
We process personal data only on your documented instructions, including in relation to any transfer of personal data outside the UK, unless UK law requires us to do otherwise — in which case we will tell you before we process, unless the law prevents us from telling you.
Your instructions are: these terms, the settings you choose in the platform, and anything you tell us in writing (including by email).
If we think an instruction breaches data protection law, we will tell you.
8.2 Confidentiality
Everyone we allow to process your personal data is bound by a duty of confidence. Today, the only person with access is Matthew McAllen. If that changes, anyone who gains access will be under a written duty of confidence before they do.
8.3 Security
We implement appropriate technical and organisational measures under Article 32.
Measures we implement in the platform:
- Tenant isolation enforced at the database level by row-level security, so that one customer's data cannot be reached from another customer's account. This is covered by an integration test suite which we run before each release.
- Two-factor authentication is required for account owners, managers and auditors before they can reach the platform's management interfaces. It is optional for employees.
- Password strength requirements — a minimum of twelve characters with mixed case, a digit and a symbol — and a check against publicly known breached passwords. Only the first five characters of a one-way hash of the password are ever sent for that check; the password itself never leaves the platform. Where the breach-checking service is unavailable, the password is accepted on the strength rules alone.
- An append-only, tamper-evident audit log. Entries are hash-chained: they cannot be deleted or truncated by anyone, and any alteration is detectable by recomputing the chain. We provide an integrity-verification function which recomputes and validates it.
- Acknowledgement records cannot be altered or deleted by any user of your account — this is enforced by the database itself, not by the application. They can be changed only by our backend service credential, and only to carry out an anonymisation or erasure that you have instructed (§8.4).
- Documents are never publicly accessible. They are served only through time-limited signed links that expire after 30 minutes.
- Sessions expire after 60 minutes of inactivity.
Measures provided by our sub-processors, on which we rely:
- Encryption of data in transit (TLS) and at rest for the database and for uploaded files. These are platform properties of Supabase and Vercel (Schedule 2) rather than controls we implement ourselves.
- Rate limiting on authentication, provided by our authentication platform.
What we log, stated precisely. Every change to your data is written to your audit log. Among reads, we log super-admin access to your content (§12), the generation of audit reports, and exports. We do not log every read — for example, an employee opening a document is recorded on the acknowledgement record itself rather than as a separate audit entry, and routine list and dashboard views are not logged. We would rather tell you exactly what the log contains than let you assume it contains more.
We keep these measures under review and may change them, provided the level of protection is not reduced.
8.4 Assisting you with your employees' rights
Taking into account the nature of the processing, we help you respond to your employees' requests to exercise their rights.
- Access and portability. The platform exports everything held about a named employee — their record, their memberships, every acknowledgement request and record, and their audit entries — as a machine-readable file, from the employee's page, in minutes.
- Rectification. A manager can correct an employee's name, employment start date and email address from within the platform. Changes are recorded in your audit log with the before and after values. Other corrections are made by us on your written instruction.
- Erasure. The platform anonymises an employee: the personal data on their account record is removed. The legal name captured on each acknowledgement record is retained, as evidence that a named individual acknowledged a named document at a stated time.
Why we retain it, plainly. Article 17(3)(e) of the UK GDPR permits personal data to be retained where it is necessary for the establishment, exercise or defence of legal claims. An acknowledgement record with the name removed proves nothing, and the whole purpose of this platform is to give you evidence you can rely on years later. If you need the name removed from the acknowledgement records as well, tell us in writing — we will do it, and we will confirm to you first, in writing, that doing so destroys the evidentiary value of those records permanently.
- Objection and restriction. You decide whether to uphold an objection; we act on your instruction.
Operations we perform manually. Complete erasure of an employee from the acknowledgement records, and any operation not listed above, is carried out by us directly rather than by a function in the platform. We will complete any such instruction within 30 days of receiving it in writing, and confirm to you when it is done.
8.5 Assisting you with your wider obligations
Taking into account the nature of the processing and the information available to us, we assist you with:
- keeping personal data secure;
- notifying personal data breaches — we will tell you without undue delay and in any event within 48 hours of becoming aware of a breach affecting your data, with the information you need to notify the ICO within your own 72-hour deadline;
- notifying your employees of a breach where required;
- carrying out data protection impact assessments;
- consulting the ICO where required.
9. Sub-processors
You give us general written authorisation to engage the sub-processors listed in Schedule 2.
If we want to add or replace a sub-processor, we will tell you at least 30 days before they start processing your data. You may object within that period by writing to hello@provenly.co.uk, setting out your reason. If we cannot resolve your objection, you may terminate this agreement without penalty, and we will handle your data under §11.
We remain liable to you for the acts and omissions of our sub-processors as if they were our own.
We put a written contract in place with every sub-processor, imposing data protection obligations that offer an equivalent level of protection to those in this Schedule.
10. International transfers
All personal data we process for you is stored and processed in the United Kingdom or the European Economic Area, as set out in Schedule 2.
We will not transfer your personal data outside the UK without your prior written authorisation. If we ever need to, we will put a valid transfer mechanism in place (such as the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses), carry out a transfer risk assessment, and tell you first.
11. End of contract
When this agreement ends, at your choice, we will either return all the personal data we hold for you, in a machine-readable export, or delete it.
You tell us which, in writing, within 30 days of the agreement ending. If you do not tell us, we retain the data for 30 further days — so that you do not lose it by oversight — and then contact you again before doing anything.
We perform this manually, and we are telling you so. The platform does not currently have a one-click "export everything" or "delete everything" function. We carry out the export or the deletion ourselves, and we will complete it within 30 days of your written instruction, confirming to you when it is done. This is a limitation of a pilot-stage product. It does not reduce your right to choose, or our obligation to act.
What deletion means, and what it cannot undo. Deletion removes your employees' personal data and your documents. Audit log entries are, by design, append-only and cannot be deleted — this is the property that makes them evidence. Where you instruct deletion, we remove the personal data those entries refer to, so that the remaining entries no longer identify anyone. We will explain precisely what will remain, in writing, before we act.
We delete existing copies unless UK law requires us to keep them. Data held in our database provider's encrypted backups is put beyond use immediately and is removed in the ordinary course of their backup cycle.
A note on retention, because it matters for this product. Health and safety claims can arise decades after exposure — occupational disease claims commonly surface 10 to 30 years later. Your acknowledgement records are the evidence you would rely on. If you instruct us to delete, that evidence is destroyed and cannot be recovered. Many customers will prefer to export and retain the evidence themselves, or to keep the account open. The choice is entirely yours — we simply want you to make it with your eyes open.
12. Our access to your data for support
Provenly's super-admin (currently Matthew McAllen only) can read your data in order to support you.
- The software provides no super-admin function that modifies your content. There is no administrative feature to edit, add to, or remove your documents, employees, or acknowledgement records.
- Your audit log cannot be deleted or truncated by anyone, including us, and any alteration to it is detectable by recomputing its hash chain.
- Acknowledgement records cannot be altered by any user of your account.
- When a super-admin views your content — your documents, employees or groups — that access is written into your own audit log before the content is shown, and you can see it.
Stated honestly: administrative lookups of account metadata (for example, finding a user by email address in order to help with a login problem) are not individually logged. We are telling you this rather than letting the statement above imply more than it should.
Where we use this access to support you, we act as your processor on your instruction. Where we use it to keep the platform secure and working, we act as a controller for that limited purpose, on the basis of our legitimate interest in operating a secure service.
13. Audits and inspections
We will give you all the information you reasonably need to satisfy yourself that we are meeting our obligations under Article 28 and this Schedule.
In practice, and proportionately for a service of this size: we will respond to your written questions, provide our security documentation, and share the results of our testing. That is normally sufficient.
If it is not, you — or an auditor you appoint, who must be independent and bound by confidentiality — may audit us. We ask for 30 days' notice; no more than once a year unless there has been a breach or the ICO requires it; and that the audit is conducted so as not to disrupt the service or compromise other customers' confidentiality.
14. Liability under this Schedule
The liability provisions in §10 of the Terms of Service apply to this Schedule.
Nothing in this Schedule limits either party's liability to a data subject or to the ICO under the UK GDPR — those liabilities are set by law, not by contract.
Schedule 2 — Sub-processors
These are the third parties who process your personal data on our behalf. This list is current as at the effective date above. We give you 30 days' notice before adding or replacing any of them (Schedule 1 §9).
| Sub-processor | What they do | Where your data is processed |
|---|---|---|
| Supabase | Database, user authentication and file storage. Holds all employee records, documents, acknowledgement records and audit logs. | United Kingdom — London (eu-west-2) |
| Vercel | Application hosting. Runs the platform's code and its scheduled jobs, and processes data in transit as you use the service. | United Kingdom — London (lhr1) |
| Resend | Sends transactional email — invitations, acknowledgement requests, password resets. Receives employee names and email addresses. | European Economic Area — Ireland (eu-west-1) |
One qualification on Vercel's row, disclosed for completeness. The platform's application code, its scheduled jobs and all data at rest are in the locations above. One thin routing layer — the code that directs each request to the right page — runs on Vercel's global edge network at the point nearest the person making the request. It stores nothing there: no personal data is written, retained or logged outside the locations in this table.
One further outbound connection, disclosed for completeness. When a password is created or changed, the platform checks it against Have I Been Pwned, a public breached-password service. Only the first five characters of a one-way hash are sent, which cannot identify the password or the person, and no account details accompany the request. No personal data leaves the platform, so this service is not a sub-processor — but we would rather list it than have you discover it.
We do not use AI on your data. No document text, employee data or acknowledgement record is sent to any artificial intelligence provider. No such capability exists in the platform. If we ever introduce one, it will require your explicit opt-in, and this list will be updated with 30 days' notice.
Accepting these terms
The account owner accepts these terms — including Schedule 1 and Schedule 2 — when they create the account.
We record which version you accepted, and when. You can view the exact version you accepted at any time from your account settings.
End of Provenly Terms of Service v1.