Data Protection Complaints

If you think Proof has not handled personal information properly, tell us.

You do not need legal language. Explain what happened and what concerns you.

Version 1.0Effective 27 August 2026Last reviewed 27 August 2026PROOF AG LTD

Make a complaintPrivacy rights

You can complain to Proof if you believe we have not handled personal information in accordance with data-protection law.

You do not need to quote legislation or use legal terminology.

Tell us what happened, why you are concerned and what you would like us to look at.

We will acknowledge your complaint within 30 days, investigate it without undue delay, keep you informed where necessary and explain the outcome.

1. Who can make a complaint?

You may make a complaint if you believe Proof has mishandled:

  • your personal information; or
  • the personal information of someone you are authorised to represent.

You may complain whether you are:

  • a website visitor;
  • job applicant;
  • farmer;
  • contributor;
  • agronomist;
  • researcher;
  • organisation user;
  • customer contact;
  • person identified in a Proof Record;
  • another person whose personal information Proof handles.

You do not need to have a Proof account.

2. What counts as a data-protection complaint?

A data-protection complaint is a concern that Proof may not have complied with data-protection law in the way it handled personal information.

Examples include concerns that Proof:

  • collected information unfairly;
  • did not explain clearly how information would be used;
  • used information for an unexpected purpose;
  • disclosed information to the wrong person;
  • kept information for too long;
  • failed to keep information sufficiently secure;
  • published personal information incorrectly;
  • failed to apply a permission correctly;
  • failed to respond properly to a privacy-rights request;
  • did not correct inaccurate personal information appropriately;
  • did not deal properly with an objection or deletion request;
  • made personal information available through an inappropriate Proof Record view;
  • allowed a privacy or re-identification risk to arise.

You do not need to know which law or legal provision may have been breached.

3. What is not necessarily a data-protection complaint?

Some concerns are better handled through another Proof process.

I think Proof mishandled my personal information

Data Protection Complaint

Examples: unexpected use, inappropriate disclosure, security, retention, privacy-request handling.

Make a complaint

I want Proof to do something with my personal information

Privacy Request

Examples: access, correction, deletion, restriction, objection, portability.

Make a privacy request

I think something in a Proof Record is wrong

Proof Record Enquiry

Examples: authority, factual content, provenance, attribution, Addendum, public redaction.

Raise a Record Enquiry

Privacy-rights request

Use a Privacy Request if you want Proof to:

  • give you a copy of your personal information;
  • correct personal information;
  • delete information where the right applies;
  • restrict processing;
  • consider an objection;
  • provide portable information.

Route: /legal/privacy-website#exercise-your-rightsor, for platform information,/legal/privacy-platform#exercise-your-rights.

Proof Record enquiry

Use a Proof Record Enquiry where the issue concerns:

  • factual content in a record;
  • contributor authority;
  • provenance;
  • attribution;
  • an Addendum;
  • funding or conflict disclosure;
  • a public redaction;
  • misuse of a Proof Record.

Route: /legal/proof-record-rules#record-enquiries

Security concern

Use the Security and Responsible Disclosure route for a suspected:

  • vulnerability;
  • unauthorised access;
  • data exposure;
  • permission-system failure;
  • security weakness.

Route: /legal/security

4. One issue can use more than one process

A complaint can also contain:

  • a privacy-rights request;
  • a Proof Record Enquiry;
  • a security incident;
  • another legal or contractual concern.

You do not need to submit the same facts repeatedly.

Proof will identify the different parts and handle them under the appropriate processes.

Where the data-protection part can be resolved before another part of a wider complaint, Proof will not unnecessarily delay the data-protection outcome while waiting for the wider issue.

5. How to make a complaint

You can complain electronically using thecomplaint form below.

You can also email ct@proof.ag with the subjectData protection complaint.

Or write to:

PROOF AG LTD
Grosvenor House
11 St Pauls Square
Birmingham
England
B3 1RB

You may also raise a complaint verbally or through another reasonable channel.

Proof will not reject a genuine data-protection complaint solely because you did not use our preferred form.

Make a data-protection complaint

Is private information currently exposed or is unauthorised access still happening?

Report an urgent security concern

This does not prevent the same issue also being treated as a data-protection complaint.

Data protection complaintReviewed by a person
Are you complaining about your own information?

If we need sensitive supporting information, we may ask you to provide it using a more appropriate method.

Proof will use the information you provide to investigate and respond to your data-protection complaint, maintain an appropriate complaint record and meet its legal obligations. Read theWebsite, Enquiries and Recruitment Privacy Notice orProof Platform Privacy Notice, depending on the information involved.

This form is protected by Cloudflare Turnstile, which checks your browser and network to prevent automated abuse. It loads only when this form is used. See our Cookie and Storage Notice.

6. Complaints received through another channel

A complaint may arrive through:

  • a general Contact form;
  • ordinary email;
  • a member of the Proof team;
  • telephone;
  • a meeting;
  • social media;
  • another reasonable communication channel.

Proof staff must recognise the complaint and route it into the data-protection complaints process.

If a complaint arrives through an insecure channel such as social media, Proof may ask you to continue the conversation through a more secure method.

You should not post private farm information, identification documents or other sensitive information publicly in order to make a complaint.

7. What to include

Providing the following information can help us investigate:

  • your name;
  • your contact details;
  • what happened;
  • when it happened;
  • what personal information was involved;
  • why you believe there is a problem;
  • any relevant Proof Record ID, account or correspondence;
  • the outcome you are seeking;
  • relevant supporting material.

You do not need to provide information that is unrelated to the complaint.

8. Do not send unnecessary sensitive material

Do not send through the initial public complaint form:

  • passports;
  • driving licences;
  • bank information;
  • raw private farm files;
  • exact field boundaries;
  • confidential legal documents;
  • special-category personal information;

unless that information is necessary to explain the complaint.

Where Proof genuinely needs sensitive supporting material, we may provide a more appropriate secure method.

9. Complaining on behalf of another person

You may complain for another person where you are authorised to act for them.

Proof may ask for proportionate evidence of authority.

This might include:

  • a signed authority;
  • power of attorney;
  • professional authority;
  • another appropriate form of authorisation.

Proof will not disclose the other person’s private information until satisfied that you are entitled to receive it.

If Proof already has enough evidence of your authority, we will not ask for unnecessary additional proof.

10. Identity checks

Proof may need to confirm your identity before disclosing personal information or taking an action that could affect another person’s rights.

We will request only what is reasonably necessary.

We will not automatically ask every complainant for formal identity documents.

Where Proof already has enough information to establish identity, we will not request additional information merely as a procedural barrier.

11. What happens when we receive your complaint?

The process is:

Receive

We identify the complaint and preserve the information relevant to it.

Acknowledge

We confirm that we have received it, within 30 days.

Investigate

We identify the issues and any outcome you are seeking, and make appropriate enquiries. Where necessary, we take immediate steps to reduce an ongoing privacy or security risk.

Keep you informed

If the investigation cannot be completed promptly, we keep you informed without undue delay.

Outcome

We explain what we found and the outcome.

Correct and learn

We consider whether a change is required to prevent the problem recurring.

12. Acknowledgement

Proof will acknowledge receipt of your data-protection complaint within 30 days.

We will normally acknowledge it sooner.

The acknowledgement may include:

  • confirmation that we received the complaint;
  • a summary of our understanding;
  • a point of contact;
  • any information we reasonably need;
  • what will happen next.

If we can fully investigate and respond within the acknowledgement period, we may provide the acknowledgement and final outcome together.

13. When the 30-day period starts

For internal compliance purposes, Proof treats the statutory acknowledgement period as beginning the day after the complaint is received.

If the final day falls on a weekend or public holiday, the applicable legal timing rules are followed.

Proof will maintain arrangements so complaints are not missed because of:

  • holidays;
  • staff absence;
  • changes in personnel.

14. Investigation begins before acknowledgement

Proof does not wait up to 30 days before starting work.

The obligation to investigate begins when the complaint is received.

Where the complaint indicates an urgent:

  • privacy risk;
  • continuing disclosure;
  • security issue;
  • safeguarding concern;
  • ongoing unauthorised access;

Proof will consider immediate protective action.

15. Understanding the complaint

Where necessary, Proof may ask you to clarify:

  • what happened;
  • which use of information concerns you;
  • which records or interactions are involved;
  • what outcome you would like.

Clarification is intended to help us investigate properly.

It must not be used to create unnecessary delay.

16. How we investigate

Depending on the complaint, Proof may:

  • review correspondence;
  • review account information;
  • review Proof Records;
  • review permissions;
  • review access logs;
  • review audit history;
  • review public views;
  • review system logs;
  • review data flows;
  • review consent or permission records;
  • review supplier information;
  • review contracts;
  • speak with relevant personnel;
  • speak with another controller or processor;
  • inspect security events;
  • compare what happened with Proof’s policies and applicable law.

The investigation must be proportionate to:

  • seriousness;
  • complexity;
  • scale;
  • potential harm;
  • continuing risk.

17. Fair investigation

Proof will investigate complaints:

  • fairly;
  • accurately;
  • objectively;
  • proportionately.

Where a complaint concerns a decision made by a particular person, Proof should avoid having that person act as the sole final reviewer where a reasonable alternative is available.

Commercial importance must not determine the complaint outcome.

A complaint involving:

  • a major customer;
  • investor;
  • commercial partner;
  • senior employee;
  • accredited contributor;

is subject to the same privacy rules.

18. Protecting people while we investigate

Proof may take temporary steps before reaching a final decision.

Depending on the risk, these may include:

  • restricting access;
  • disabling a permission;
  • suspending a public view;
  • applying temporary redaction;
  • preserving relevant logs;
  • securing an account;
  • suspending an integration;
  • preventing further disclosure;
  • isolating affected information.

Temporary protective action is not necessarily a finding that the complaint is upheld.

19. Preserving evidence

Proof will preserve information reasonably necessary to understand what happened.

We must not clean or rewrite the audit trail before the complaint has been investigated.

Relevant evidence may include:

  • access logs;
  • permission states;
  • record versions;
  • emails;
  • system events;
  • publication history;
  • redactions;
  • security logs.

This reflects Proof’s broader rule that corrections should preserve an intelligible history rather than hide what happened.

20. Involving another organisation

A complaint may concern activity involving:

  • a customer;
  • farm;
  • research organisation;
  • software provider;
  • programme sponsor;
  • processor;
  • joint controller;
  • another controller.

Proof may need to obtain information from that organisation.

We will share only information reasonably necessary to investigate and will respect applicable confidentiality and data-protection obligations.

21. Where Proof is a processor

Where Proof is processing personal information solely on behalf of another controller:

  • Proof will identify the relevant controller;
  • pass the complaint to that controller where appropriate;
  • assist it in investigating;
  • provide relevant information as required by the applicable Data Processing Agreement.

The controller remains responsible for complying with its statutory complaints duties for processing for which it is controller.

Proof will not use processor status as a reason to ignore a complaint received by us.

22. Joint controllers

Where Proof and another organisation are joint controllers, the parties must follow their documented arrangement for handling complaints.

The complainant should not be disadvantaged because more than one controller is involved.

Where applicable, the statutory timing runs from receipt of the complaint by the relevant joint-controller arrangement, rather than being reset each time the complaint is passed internally.

23. Investigation time

Data-protection law requires Proof to investigate and respond without undue delay.

There is not a general rule that every complaint must receive a full outcome within 30 days.

The time required may depend on:

  • complexity;
  • number of issues;
  • period covered;
  • technical investigation;
  • involvement of third parties;
  • potential harm;
  • information needed from the complainant.

Proof will not use complexity as an excuse for unjustifiable delay.

Straightforward complaints should be resolved promptly.

24. Keeping you informed

If the investigation cannot be completed promptly, Proof will keep you informed without undue delay.

Updates may explain:

  • that the investigation remains open;
  • why additional time is required;
  • any information still needed;
  • a reasonable expected next update or completion point;
  • who to contact.

Proof does not need to disclose:

  • security-sensitive details;
  • another person’s private information;
  • legally privileged material;
  • confidential investigative information;

merely to provide a progress update.

25. Possible outcomes

A complaint may be:

Upheld

Proof concludes that the complaint is correct in whole or in substantial part.

Partly upheld

Some issues are upheld and others are not.

Not upheld

Proof concludes that its handling complied with the applicable requirements.

Unable to determine

There is insufficient reliable information to establish what occurred.

Referred

Another controller, regulator or process is responsible for all or part of the issue.

The label matters less than a clear explanation of what Proof found.

26. Corrective action

Where appropriate, Proof may:

  • correct personal information;
  • delete personal information where legally required;
  • restrict processing;
  • change a permission;
  • revoke access;
  • apply redaction;
  • remove public content;
  • issue an Addendum;
  • correct a privacy notice;
  • update a process;
  • change a retention rule;
  • change access controls;
  • retrain personnel;
  • amend a contract or supplier arrangement;
  • fix software;
  • improve monitoring;
  • change a Proof Record workflow;
  • report a breach;
  • take disciplinary or accreditation action.

The remedy depends on the issue and applicable law.

27. Complaints involving a published Proof Record

If a complaint concerns personal information in a public redacted view of a Proof Record, Proof may need to consider both:

  • data-protection law; and
  • the Proof Record Rules.

Possible action may include:

  • temporary restriction;
  • redaction;
  • correction through Addendum;
  • exceptional legal removal.

Proof’s principle of preserving historical evidence does not override an applicable legal right.

28. Final response

Once the investigation is complete, Proof will communicate the outcome without undue delay.

The response should explain:

  • what we understood the complaint to be;
  • what we investigated;
  • the relevant facts;
  • our conclusion;
  • whether the complaint is upheld;
  • material corrective action;
  • any outstanding matter;
  • what you can do if you remain dissatisfied.

Where appropriate, we will respond to individual complaint points separately.

29. Limits on what we can disclose

A final response may not include information that Proof is not lawfully entitled to disclose.

This may include:

  • another person’s personal information;
  • confidential farm information;
  • legally privileged information;
  • security-sensitive material;
  • another organisation’s confidential information.

Where information is withheld, Proof should explain the position as far as it lawfully can.

30. If you disagree with our outcome

You may contact Proof and explain:

  • which part you disagree with;
  • why;
  • any relevant new information.

Where appropriate, Proof may arrange an internal review.

You are not required to use an internal review before complaining to the Information Commissioner’s Office.

31. Complaining to the ICO

You may complain to the Information Commissioner’s Office about Proof’s use of personal information.

You do not lose your right to complain to the Information Commissioner because you complained to Proof first.

The ICO recommends that people normally give the organisation an opportunity to deal with the complaint first, but you may approach the ICO at any time.

Make a complaint to the ICO

Proof will cooperate with the ICO where required.

32. Court and other rights

Using this complaints procedure does not remove any legal right you may have.

Depending on the circumstances, you may also have rights to:

  • enforce a data-protection right through the courts;
  • seek compensation where the legal requirements are met;
  • use another regulator or complaint scheme;
  • pursue another contractual or legal remedy.

Proof cannot provide you with independent legal advice about those options.

33. Complaints involving other laws

A complaint may involve data protection and another issue such as:

  • employment;
  • discrimination;
  • contract;
  • intellectual property;
  • professional conduct;
  • agronomy;
  • security.

Proof will identify and handle the data-protection aspect under this Procedure.

Another process may apply to the other issues.

Where the data-protection part can be resolved sooner, Proof will not delay it merely to conclude every other issue at the same time.

34. No retaliation

Proof will not disadvantage someone merely because they:

  • make a data-protection complaint in good faith;
  • exercise a privacy right;
  • report a security concern;
  • question how their information is being used.

This does not prevent Proof from taking proportionate action concerning:

  • abusive conduct;
  • threats;
  • fraud;
  • deliberate misuse;
  • knowingly false allegations made for an improper purpose.

The substance of a genuine complaint must still be considered.

35. Accessibility

Proof will make reasonable efforts to ensure this complaints process is accessible.

You may ask to communicate through an alternative reasonable format.

For assistance, email ct@proof.ag with the subjectAccessible complaint support.

Proof will consider relevant equality and accessibility obligations when deciding how to communicate.

36. Children

Although Proof’s services are primarily intended for professional adult users, children have data-protection rights.

If a complaint relates to a child:

  • Proof will use language appropriate to the circumstances;
  • assess whether the child can exercise the relevant right themselves;
  • verify parental or representative authority where necessary;
  • prioritise an urgent safeguarding concern.

37. How Proof records complaints

Proof maintains an internal complaints record.

It may include:

  • complaint reference;
  • date received;
  • complainant;
  • relevant account or record;
  • issues raised;
  • acknowledgement date;
  • investigator;
  • information reviewed;
  • progress communications;
  • outcome;
  • corrective action;
  • closure date;
  • lessons learned.

Complaint records are access-controlled.

They are not part of any Proof Record or public view.

38. Retention

Proof retains complaint records only for as long as reasonably necessary.

As a general operational rule, complaint records may normally be retained for up to six years after closure where necessary to:

  • demonstrate how the complaint was handled;
  • comply with legal obligations;
  • establish or defend legal claims;
  • identify recurring compliance issues.

Information that is not required for those purposes should be deleted earlier.

Longer retention requires a documented reason.

This must remain consistent with the relevant Proof Privacy Notice and retention schedule.

39. Learning from complaints

Proof should review complaints for:

  • recurring issues;
  • permission failures;
  • redaction problems;
  • misleading interfaces;
  • security weaknesses;
  • unclear privacy information;
  • supplier problems;
  • training gaps;
  • weaknesses in the Proof recording standard.

A complaint should not simply be closed and forgotten where it reveals a systemic problem.

Where appropriate, Proof should change:

  • the product;
  • policy;
  • standard;
  • training;
  • supplier;
  • contract;
  • process.

40. Contact

ComplaintsEmail ct@proof.ag · subjectData protection complaint
Privacy requestsEmail ct@proof.ag · subjectPrivacy request
Security concerns/legal/security
Postal addressPROOF AG LTD
Grosvenor House
11 St Pauls Square
Birmingham
England
B3 1RB
Company number17211914
ICO registrationZC145363
Material changesVersion 1.0 · initial publication · no previous versions.
Accessible formatsContact ct@proof.ag if you need this procedure in another accessible format.