Legal

Data Processing Agreement

Last updated: August 2026

Draft Template — Not Legal Advice

This is a draft template and has not been reviewed by qualified legal counsel. It must be reviewed and customized by a lawyer before being relied upon or presented to customers as a binding agreement. Do not treat this page as an executed or enforceable contract.

1. Introduction

This Data Processing Agreement (“DPA”) forms part of the agreement between ScopeLock (“Processor”, “we”, “us”) and the agency or organisation using the ScopeLock platform (“Controller”, “you”) under our Terms of Service. It applies whenever ScopeLock processes personal data on your behalf in connection with the Service.

2. Subject Matter and Duration

The subject matter of this DPA is the processing of personal data by ScopeLock as necessary to provide the Service, including generating Statements of Work (SOWs), transcribing project intake sessions, extracting entities, detecting scope conflicts, and facilitating e-signature and payment workflows. Processing continues for the duration of your account with ScopeLock and for any period afterward during which we retain data under Section 9 (Return and Deletion of Data) or as required by law.

3. Nature and Purpose of Processing

ScopeLock processes personal data to:

  • Ingest and transcribe project intake materials (audio, video, and documents) supplied by the Controller
  • Extract structured entities (names, deliverables, deadlines, budgets) from that material using AI models
  • Generate, edit, and version Statements of Work and change orders
  • Detect potential scope conflicts against agreed SOW terms (“Scope Police”)
  • Facilitate electronic signature and maintain a signing audit trail
  • Process deposit and subscription payments
  • Send transactional emails related to the above

4. Categories of Data Subjects

Personal data processed under this DPA may relate to:

  • The Controller’s employees, contractors, and team members who use the Service
  • The Controller’s clients and their representatives (e.g. individuals named in SOWs, project intake calls, or signing an SOW)
  • Any other individual whose personal data is included in materials the Controller uploads to the Service

5. Categories of Personal Data

The categories of personal data processed may include:

  • Identity and contact data — names, email addresses, job titles, agency/client names
  • Financial data — project budgets, fees, deposit amounts, and other figures included in SOWs or intake materials (ScopeLock does not directly process or store full payment card numbers; card data is handled by Stripe)
  • Content data — uploaded documents, audio and video recordings, and their transcriptions and derived text
  • Signing audit data — signer name, email, IP address, device/browser information, and timestamp captured at the time an SOW is signed
  • Usage data — account activity and platform interaction logs

The Controller is responsible for ensuring it has a lawful basis to supply any personal data (including any special category data, which should not routinely be included) to ScopeLock for processing.

6. Roles of the Parties

For the purposes of applicable data protection law (including the GDPR), the Controller is the data controller and ScopeLock is the data processor with respect to personal data processed through the Service on the Controller’s behalf. ScopeLock will:

  • Process personal data only on the Controller’s documented instructions, including with regard to transfers, unless required otherwise by law
  • Ensure persons authorized to process personal data are subject to confidentiality obligations
  • Implement appropriate technical and organisational security measures (see Section 8)
  • Assist the Controller in responding to data subject requests and other obligations under Section 7
  • Not engage a sub-processor without prior general or specific authorisation, as described in Section 8

7. Assistance with Data Subject Rights

ScopeLock will provide reasonable assistance to the Controller in responding to requests from data subjects seeking to exercise their rights (access, correction, deletion, portability, objection, or restriction) under applicable data protection law, taking into account the nature of the processing. Where the Controller receives such a request directly, it may forward it to ScopeLock, and we will provide reasonable cooperation to help fulfil it, consistent with our record retention obligations (e.g. signing audit records described in the Terms of Service).

8. Sub-processors

The Controller provides general authorisation for ScopeLock to engage the following categories of sub-processors, each acting under a written agreement that imposes data protection obligations no less protective than those in this DPA:

Sub-processorPurposeData involved
SupabaseDatabase hosting and file storageAll account, project, SOW, and signing audit data
Google (Gemini API)AI-based entity extraction, SOW drafting, and scope conflict detectionProject intake content, transcripts, SOW text
DeepgramTranscription of uploaded audio and videoAudio/video recordings and resulting transcripts
StripeSubscription billing and deposit payment processingBilling contact details and payment transaction data
ResendTransactional email deliveryRecipient name and email address

ScopeLock will notify the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object on reasonable data protection grounds.

9. Return and Deletion of Data

Upon termination of the Service, ScopeLock will, at the Controller’s choice, delete or return all personal data processed on the Controller’s behalf, except to the extent retention is required by applicable law or for dispute resolution purposes (such as signing audit records, which are retained for a minimum of 7 years as described in the Privacy Policy).

10. Security Measures

ScopeLock implements appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, including:

  • Encryption of data in transit (TLS) and at rest
  • Access controls limiting internal access to personal data on a need-to-know basis
  • Audit logging of signing and account activity
  • Use of vetted, reputable sub-processors bound by their own security commitments

11. Personal Data Breach Notification

ScopeLock will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and will provide reasonably available information to help the Controller meet any obligation to notify supervisory authorities or affected data subjects.

12. International Transfers

Where personal data is transferred outside the country or region in which it was originally collected (including to sub-processors listed in Section 8), ScopeLock will rely on appropriate safeguards recognised under applicable data protection law, such as Standard Contractual Clauses, to ensure the transfer is lawful.

13. Audit Rights

ScopeLock will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and will allow for, and contribute to, audits conducted by the Controller or an independent auditor mandated by the Controller, subject to reasonable notice, confidentiality, and no more than once per year absent a legal requirement or actual breach.

14. Liability

Liability under this DPA is subject to the limitations set out in the Terms of Service.

15. Contact

Questions about this DPA or data processing practices can be directed to privacy@scopelock.app.