Privacy & Security

Last updated: 26 June 2026

GDPR Statement

Hello Proposals is committed to protecting personal data and respecting the rights of individuals under the EU General Data Protection Regulation (GDPR) and the UK GDPR. This statement explains the roles we hold, the lawful bases on which we process personal data, the principles we follow, and the rights available to individuals.

Our roles: controller and processor

  • As a controller, Hello Proposals (ABN 26 607 818 682) determines how and why we process the personal data of our account holders, for example the name, email address, and company details you give us when you create and run your account.
  • As a processor, we process personal data on behalf of our account holders when their clients interact with a proposal, for example a name, email address, signature, or form response submitted through a shared proposal. In that case the account holder is the controller, and we process that data only on their documented instructions and to provide the service.

Lawful bases for processing (Article 6)

We rely on the following lawful bases:

  • Performance of a contract — to create your account, provide the proposal builder, host and share your proposals, and process the features you use.
  • Legitimate interests — to secure the service, prevent abuse, debug and improve the product, and provide analytics to account holders about their own proposals, balanced against the rights and freedoms of the individuals concerned.
  • Consent — where you opt in to optional communications, such as a newsletter. Consent can be withdrawn at any time.
  • Legal obligation — to keep records we are legally required to retain, for example for tax and accounting.

The principles we follow (Article 5)

We process personal data in line with the GDPR principles:

  1. Lawfulness, fairness and transparency.
  2. Purpose limitation — collected for specified, explicit, and legitimate purposes.
  3. Data minimisation — limited to what is necessary for those purposes.
  4. Accuracy — kept accurate and, where necessary, up to date.
  5. Storage limitation — kept only for as long as necessary.
  6. Integrity and confidentiality — protected with appropriate security (see the Data Security statement).
  7. Accountability — we take responsibility for, and can demonstrate, our compliance.

Your rights

Individuals whose personal data we process have the following rights:

  • The right to be informed about how their data is used (through this statement and our privacy notice).
  • The right of access to the personal data we hold about them.
  • The right to rectification of inaccurate or incomplete data.
  • The right to erasure ("right to be forgotten") in the circumstances the law allows.
  • The right to restrict processing in certain circumstances.
  • The right to data portability — to receive their data in a structured, commonly used, machine-readable format.
  • The right to object to processing based on legitimate interests, and to direct marketing at any time.
  • Rights in relation to automated decision-making and profiling. We do not make decisions that produce legal or similarly significant effects based solely on automated processing.

How to exercise your rights

To exercise any of these rights, contact us at info@helloproposals.com.au (or through Contact Support in the app). We will respond without undue delay and within one month of receiving your request. Where a request is complex or there are several requests, we may extend this by up to two further months and will tell you, with reasons, within the first month. We do not charge a fee unless a request is manifestly unfounded or excessive.

Where we act as a processor (data submitted by an account holder's own clients), we will refer the request to the relevant account holder, who is the controller, and assist them in responding.

International data transfers (Chapter V)

Personal data is currently stored and processed in Australia. Australia is not covered by an EU adequacy decision, so where we transfer the personal data of individuals in the EEA or the UK to Australia, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK Addendum / International Data Transfer Agreement where applicable), together with any additional measures needed to protect the data. A copy of the relevant safeguards is available on request.

Retention

We keep personal data only for as long as necessary for the purposes described here or as required by law, and then delete or anonymise it. Account data is retained for the life of the account and for a limited period afterwards; proposal interaction data is retained for the account holder while their account is active.

Complaints

If you have a concern about how we handle personal data, please contact us first so we can help. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EEA or UK country where you live, work, or where the issue occurred.

Contact

Hello Proposals (ABN 26 607 818 682), 136 Bushlands Rd, Bororen, QLD 4678, Australia. Privacy contact: info@helloproposals.com.au.


Data Privacy Statement

This statement explains what personal data Hello Proposals collects, why, and who we share it with. It complements the GDPR statement above.

What we collect

  • Account data — your name, email address, and optional profile and company details (such as job title, company name, address, and tax identifier) that you provide.
  • Content you create — your proposals, brand profiles, templates, and the text, images, and pricing within them.
  • Client interaction data — when you share a proposal, we record activity such as views, time spent, page completion, signatures, and any form or newsletter submissions your clients make through the proposal.
  • Billing data — your plan, subscription status, and billing history. Card payments are handled by Stripe; we do not collect or store full card numbers (see Data Security).
  • Technical data — limited information needed to run and secure the service, such as session and device information and basic logs.

How we use it

We use personal data to provide and secure the service, to deliver the features you use (including AI generation, e-signatures, analytics, and integrations), to take payment, to respond to support requests, and to meet our legal obligations. We do not sell personal data, and we do not use the content of your proposals to train third-party AI models.

Who we share it with (subprocessors)

We use a small number of trusted service providers to run Hello Proposals, each processing personal data only as needed to provide their service to us. We list them here by role; a current, named list of subprocessors is available on request:

RolePurposeLocation
Cloud hostingApplication hosting and deliveryAustralia (current region)
Managed databasePrimary data storageAustralia (current region)
Payment processingCard payments (PCI-DSS Level 1)Global
Email deliveryTransactional and notification emailGlobal
Realtime serviceLive signing notificationsGlobal
AI processingAI proposal generationGlobal

We share personal data with these providers under data processing terms, and otherwise only where required by law or to protect our rights.

Cookies and sessions

We use a signed session token to keep you logged in and essential cookies to operate the service. We do not use third-party advertising cookies.

Your choices

You can update your profile and many settings directly in your account. To exercise your data protection rights, see "Your rights" in the GDPR statement above.


Data Security Statement

We take the security of your data seriously and build on infrastructure from established, independently audited providers. This statement describes the measures in place today; we review and improve them as the product grows.

Hosting and data residency

  • The application runs on established cloud infrastructure, currently in a single Australian region. As we launch in other countries we may add regions, and we will update this statement.
  • Data is stored in a managed Postgres database in an Australian region. The database is not currently read-replicated, so your data stays within that single region.
  • Our infrastructure providers maintain recognised security certifications such as SOC 2 and/or ISO 27001.

Encryption

  • In transit: all traffic is served over HTTPS using TLS.
  • At rest: data stored in our database and hosting platform is encrypted at rest by our infrastructure providers.

Authentication

  • Sign-in is passwordless. We use one-time magic links and signed session tokens (JWTs). We never store account passwords, which removes a major class of credential risk.
  • API keys for integrations are stored hashed, never in plain text, and can be revoked at any time.

Payments

  • Card payments are processed by Stripe, a PCI-DSS Level 1 certified provider. Card details are entered directly with Stripe; Hello Proposals never sees or stores full card numbers. We store only the references (such as customer and subscription identifiers) needed to manage your plan.

Access control and isolation

  • Data is scoped to your account and workspace, and access is restricted on a least-privilege basis.
  • Internal access to production systems is limited to the people who need it to operate and support the service.

Backups and resilience

  • Our managed database provider performs automated backups with point-in-time recovery, supporting recovery in the event of a failure.

Reporting a vulnerability

If you believe you have found a security issue, please contact us at info@helloproposals.com.au. We welcome responsible disclosure and will work with you to investigate and resolve genuine issues promptly.