Legal
Last updated: August 2026
Draft Template — Not Legal Advice
This is a draft template and has not been reviewed by qualified legal counsel. It must be reviewed and customized by a lawyer before being relied upon or presented to customers as a binding agreement. Do not treat this page as an executed or enforceable contract.
This Data Processing Agreement (“DPA”) forms part of the agreement between ScopeLock (“Processor”, “we”, “us”) and the agency or organisation using the ScopeLock platform (“Controller”, “you”) under our Terms of Service. It applies whenever ScopeLock processes personal data on your behalf in connection with the Service.
The subject matter of this DPA is the processing of personal data by ScopeLock as necessary to provide the Service, including generating Statements of Work (SOWs), transcribing project intake sessions, extracting entities, detecting scope conflicts, and facilitating e-signature and payment workflows. Processing continues for the duration of your account with ScopeLock and for any period afterward during which we retain data under Section 9 (Return and Deletion of Data) or as required by law.
ScopeLock processes personal data to:
Personal data processed under this DPA may relate to:
The categories of personal data processed may include:
The Controller is responsible for ensuring it has a lawful basis to supply any personal data (including any special category data, which should not routinely be included) to ScopeLock for processing.
For the purposes of applicable data protection law (including the GDPR), the Controller is the data controller and ScopeLock is the data processor with respect to personal data processed through the Service on the Controller’s behalf. ScopeLock will:
ScopeLock will provide reasonable assistance to the Controller in responding to requests from data subjects seeking to exercise their rights (access, correction, deletion, portability, objection, or restriction) under applicable data protection law, taking into account the nature of the processing. Where the Controller receives such a request directly, it may forward it to ScopeLock, and we will provide reasonable cooperation to help fulfil it, consistent with our record retention obligations (e.g. signing audit records described in the Terms of Service).
The Controller provides general authorisation for ScopeLock to engage the following categories of sub-processors, each acting under a written agreement that imposes data protection obligations no less protective than those in this DPA:
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Supabase | Database hosting and file storage | All account, project, SOW, and signing audit data |
| Google (Gemini API) | AI-based entity extraction, SOW drafting, and scope conflict detection | Project intake content, transcripts, SOW text |
| Deepgram | Transcription of uploaded audio and video | Audio/video recordings and resulting transcripts |
| Stripe | Subscription billing and deposit payment processing | Billing contact details and payment transaction data |
| Resend | Transactional email delivery | Recipient name and email address |
ScopeLock will notify the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object on reasonable data protection grounds.
Upon termination of the Service, ScopeLock will, at the Controller’s choice, delete or return all personal data processed on the Controller’s behalf, except to the extent retention is required by applicable law or for dispute resolution purposes (such as signing audit records, which are retained for a minimum of 7 years as described in the Privacy Policy).
ScopeLock implements appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, including:
ScopeLock will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and will provide reasonably available information to help the Controller meet any obligation to notify supervisory authorities or affected data subjects.
Where personal data is transferred outside the country or region in which it was originally collected (including to sub-processors listed in Section 8), ScopeLock will rely on appropriate safeguards recognised under applicable data protection law, such as Standard Contractual Clauses, to ensure the transfer is lawful.
ScopeLock will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and will allow for, and contribute to, audits conducted by the Controller or an independent auditor mandated by the Controller, subject to reasonable notice, confidentiality, and no more than once per year absent a legal requirement or actual breach.
Liability under this DPA is subject to the limitations set out in the Terms of Service.
Questions about this DPA or data processing practices can be directed to privacy@scopelock.app.