FiftyProof

FiftyProof · product notice

Privacy, in plain language.

This notice explains the current FiftyProof data flow: what CoLabs.Tech Limited collects, why it is used, which services process it, and how to contact us.

Last updated 24 July 2026

01 · Scope

This notice covers FiftyProof.

FiftyProof is a CoLabs.Tech product operated by CoLabs.Tech Limited. This product notice applies when you use the FiftyProof website, run the free buyer evidence scan, request a sprint fit check, download product material, or use paid checkout. The separate CoLabs.Tech company website has its own company privacy policy.

02 · Data

What FiftyProof collects.

Identity and contact
Name, work email, company, and any optional website or role you provide.
Readiness scan
Eight operational answers, score, readiness band, generated analysis, submission time, and the exact privacy and marketing choices presented to you.
Scope request
Your business event, deadline, system description, blocked question, deal-value band, available inputs, preferred call window, and timezone.
Security and billing
Keyed one-way identifiers used for abuse limits, basic hosting logs, and—if you purchase—Stripe payment and billing identifiers. Full card details stay with Stripe.

Do not submit credentials, source code, customer data, special category data, or confidential evidence through the public scan or scope form.

03 · Purpose

Why the data is used.

Deliver requested services

Create the scan report, respond to a scope request, arrange a call, prepare an agreed sprint, and provide customer support. We rely on our legitimate interests in operating and responding to requests for this B2B service and, where applicable, steps requested before a contract.

Protect the service

Rate-limit abuse, investigate errors, secure the product, and preserve the integrity of consent records. We rely on legitimate interests in operating a safe and reliable service.

Optional marketing

Send occasional Article 50 guidance and FiftyProof product updates only when you select the optional checkbox. This relies on consent, which you can withdraw at any time.

Payments and legal records

Create checkout sessions, reconcile payments, and retain records required for accounting, disputes, or other legal obligations.

04 · AI analysis

Contact data is kept out of the model prompt.

When Anthropic analysis is available, FiftyProof sends only the eight operational answers and the server-calculated readiness result. It does not send your name, email, company, scan ID, or scope-request text. Anthropic drafts a bounded narrative; it does not change the deterministic score or make a legal or similarly significant decision about you.

Anthropic states that standard API inputs and outputs are deleted from its backend within 30 days, subject to stated safety, legal, or separately agreed exceptions. Read the current Anthropic retention notice.

05 · Providers

Services that help run FiftyProof.

Vercel

Website hosting, serverless runtime, and operational request logs.

Privacy

Supabase

Private database storage for leads, scans, consent records, and scope requests.

Privacy

Anthropic

Optional narrative analysis using operational scan answers and the server-calculated result only.

Privacy

Stripe

Payment and billing processing when paid checkout is available. We do not receive full card details.

Privacy

Providers may process data outside the UK. Where required, we rely on the provider’s contractual transfer safeguards and data-processing terms. We do not sell personal data, and FiftyProof does not currently run advertising trackers or browser analytics scripts.

06 · Retention

How long records are kept.

We keep scan, lead, scope-request, and consent records only while they are reasonably needed to deliver and support the requested service, follow up on the request, maintain an accurate consent record, prevent abuse, resolve disputes, and meet accounting or legal obligations. We review records against those purposes and delete or anonymise data when it is no longer needed. Short-lived rate-limit records are used only for service protection.

Contact us if you want us to assess or delete your record sooner. A legal or security reason may require us to retain a limited record for longer, and we will explain that if it applies.

07 · Your rights

You can ask what we hold and how it is used.

Depending on the processing and the law that applies, you may:

  • ask for a copy of personal data we hold about you
  • ask us to correct inaccurate or incomplete data
  • ask us to erase or restrict use of data where the law allows
  • object to processing based on legitimate interests
  • ask for portable data where that right applies
  • withdraw optional marketing consent at any time

Email hello@colabs-tech.com to make a request or withdraw marketing consent. We may need to verify your identity. You can also complain to the UK Information Commissioner’s Office.

08 · Security

Private records stay server-side.

The public browser cannot read FiftyProof lead, scan, consent, or scope-request tables directly. Writes pass through validated, rate-limited server routes, and abuse identifiers are stored as keyed one-way hashes. No internet service is perfectly secure, so the public forms deliberately refuse confidential evidence and credentials.

09 · Changes

We will update this notice when the data flow changes.

The date at the top identifies the current version. If a material change affects data already collected, we will take reasonable steps to bring it to the attention of affected people before the new use begins.

Return to the buyer evidence scan