Before
Start without sensitive documents.
Five to ten representative questions are enough to start the pre-audit. No internal document is required to begin: an excerpt of the questionnaire is enough.
Privacy
At each stage, your team keeps control of what is shared, validated, and sent.
The dossier in 4 stages
Before
Five to ten representative questions are enough to start the pre-audit. No internal document is required to begin: an excerpt of the questionnaire is enough.
Before sharing anything sensitive
Before any sensitive supporting evidence or before a Full dossier, an agreement can frame the sharing, at the request of your chief information security officer, your data protection officer, or ahead of the project.
During
The items you send are used only to prepare the dossier concerned. Isolated storage, access limited to the people assigned, deletion on simple request.
Before the final send
Prova prepares. Your team remains the final sender to your customer. No answer goes out without your review. You decide what goes out, to whom, and when.
Your personal data
This information supplements the terms of sale and specifies how your data is processed.
Prova uses the following sub-processors:
| Provider | Role | Data location | Safeguard for transfers outside the EU |
|---|---|---|---|
| Anthropic Ireland, Limited | Preparation of the answers | United States | Standard contractual clauses, module 3 |
| Vercel | Hosting of the Site and storage of uploaded documents | Frankfurt, Germany | Data Privacy Framework |
| Neon | Database | Frankfurt, Germany | Data Privacy Framework |
| Stripe | Payment processing | United States | Data Privacy Framework |
| IONOS | Business email | Germany | Not applicable |
| Amplitude | Audience measurement of the Site's public pages | European Union | Data Privacy Framework |
Prova has concluded with each of these providers a data processing agreement compliant with Article 28 of the GDPR.
Prova informs the client of any addition or replacement of a sub-processor at least thirty days before it takes effect. The client may object to it for a legitimate reason.
Stripe acts as an independent controller for payment data, under its own policy.
Any transfer of data outside the European Union is governed by a mechanism compliant with Chapter V of the GDPR, in particular the standard contractual clauses of the European Commission or an adequacy decision. The details appear in the table above.
Prova is the controller for the data it collects on its own account:
| Processing | Legal basis | Retention period |
|---|---|---|
| Order management | Performance of the contract | The duration of the contractual relationship, then 5 years in archiving |
| Invoicing | Legal obligation | 10 years (Article L. 123-22 of the French Commercial Code) |
| Accounting | Legal obligation | 10 years (Article L. 123-22 of the French Commercial Code) |
| Customer relations | Performance of the contract | The duration of the relationship, then 3 years after the last contact |
| Pre-audit requests | Legitimate interest | 3 years from the last contact, if the request does not proceed |
| Site audience measurement | Consent | 13 months for trackers, 25 months for the data collected |
Every data subject has a right of access, rectification, erasure, restriction, objection, and portability.
Any request may be sent to admin@getprova.fr.
Every data subject has the right to lodge a complaint with the Commission nationale de l'informatique et des libertés.
Unless the “Always Ready” offer is subscribed to, the documents provided by the client and the deliverables are deleted ninety days after the delivery of the dossier, or on the client's written request at any time.
For these documents, Prova acts as a processor, on the client's instructions (Article 14 of the terms of sale), and not as a controller as for the data above.
The full contractual details appear in the terms of sale.
No sensitive document is required for the pre-audit. Any further sharing is framed afterward, if needed.
Policy updated July 2026 · quarterly review