Legal

Privacy Policy

Last updated: March 2026

1. Who We Are

ScopeLock (“we”, “us”, “our”) operates the ScopeLock platform, a software tool for creating and managing Statements of Work. This Privacy Policy explains what personal data we collect, why we collect it, and your rights regarding that data.

2. Data We Collect

We collect the following categories of personal data:

CategoryExamplesCollected from
Account dataName, email address, agency nameRegistration / OAuth
Project dataClient name, client email, project details, SOW contentYou enter it
Signing audit dataSigner name, email, IP address, browser/OS (user agent), timestamp, signature hashAutomatically at time of signing
Usage dataPages visited, features used, error logsAutomatically via server logs

3. Why We Collect It

We process personal data for the following purposes:

  • Service delivery — to provide, maintain, and improve the platform
  • Contract audit trail — IP address, user agent, and timestamp at signing are recorded to create a tamper-evident audit trail for dispute resolution
  • Fraud prevention — to detect and prevent unauthorized or fraudulent use of the Service
  • Communications — to send transactional emails (SOW confirmations, team invites, signing notifications)
  • Legal compliance — to comply with applicable laws and respond to lawful requests

Our legal basis for processing is: contract performance (account and project data), legitimate interests (audit trail, fraud prevention, security), and legal obligation (compliance, record retention).

4. Data Retention

  • Signing audit records (name, email, IP, user agent, hash) — retained for a minimum of 7 years from the date of signing, to cover the standard statute of limitations period for contract disputes
  • Account data — retained for the duration of your account, plus 90 days after deletion to allow for recovery
  • Project and SOW data — retained for the duration of your account; you may delete projects at any time
  • Usage logs — retained for 90 days

5. Data Sharing

We share personal data only in the following circumstances:

  • Service providers — we use third-party services to operate the platform (database hosting, email delivery, payment processing). These providers act as data processors and are contractually bound to protect your data.
  • Legal requirements — we may disclose data if required by law, court order, or other legal process.
  • Dispute resolution — signing audit data may be shared with relevant parties (e.g., legal counsel) in the event of a contract dispute.

We do not sell, rent, or trade personal data to any third party for marketing purposes.

6. Your Rights (GDPR)

If you are located in the European Economic Area, you have the following rights:

  • Access — request a copy of the personal data we hold about you
  • Correction — request correction of inaccurate data
  • Deletion — request deletion of your data. Note: signing audit records for active contracts may be retained to fulfil our legal obligations
  • Portability — receive your data in a machine-readable format
  • Objection — object to processing based on legitimate interests
  • Restriction — request restriction of processing in certain circumstances

To exercise these rights, contact us at privacy@scopelock.app. We will respond within 30 days.

7. Your Rights (CCPA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and sell
  • Request deletion of your personal information
  • Opt out of the sale of personal information — we do not sell personal information
  • Non-discrimination for exercising your rights

8. Cookies & Tracking

ScopeLock uses essential cookies required for authentication (session cookies) and basic functionality. We do not use advertising trackers or third-party analytics cookies that track you across websites.

9. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), encrypted storage, access controls, and audit logging. No system is 100% secure; we encourage you to use a strong, unique password for your account.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email at least 30 days before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.

11. Contact

For privacy-related questions or to exercise your rights, contact us at: privacy@scopelock.app