Skip to content

Data Processing Agreement

How we handle personal data you put into your workspace

Last updated 10 September 2026

1. When this applies

This agreement applies where you put personal data into your Scoperva workspace. For that data you are the controller and we are your processor, and this document is the Article 28 agreement between us. It forms part of the terms of service.

For data we hold about you as our customer — your account, your email, our billing records — we are the controller, and the privacy policy governs that instead.

2. What is not covered yet

Scoperva is being built to research companies and, in time, to work with business contact data obtained from third-party providers. That is a different processing activity from the one this agreement covers, and the controllership position for it has not been settled.

None of it is live. When it is, this agreement will be extended before the processing starts. We would rather leave the gap visible than paper over it.

3. Scope of processing

ItemDetail
Subject matterProviding the Scoperva service to you
DurationFor as long as your account exists, plus the deletion period in section 8
Nature and purposeStoring, organising, retrieving and displaying the data you enter, so the service can function
Types of dataWhatever you choose to enter — typically business contact details and notes about companies and people you deal with
Categories of data subjectYour staff, and the business contacts you record

4. Our obligations

  • We process personal data only on your documented instructions. Using the service is such an instruction. If the law requires us to do otherwise, we will tell you first unless prohibited.
  • Everyone with access is bound by confidentiality obligations.
  • We apply appropriate technical and organisational measures — see section 6.
  • We assist you, so far as we reasonably can, with data subject requests, impact assessments and consultations with regulators.
  • We make available the information you need to demonstrate our compliance, and allow audits on reasonable notice.

5. Sub-processors

You give us general authorisation to use the sub-processors listed on the sub-processors page. We will give you at least 30 days' notice before adding one, so you can object. Each is bound by terms no less protective than these, and we remain responsible to you for their performance.

6. Security

Measures currently in place, in proportion to a service at this stage:

  • Encryption in transit and at rest.
  • Row-level security in the database, so a workspace's data is isolated from every other workspace at the data layer rather than in application code.
  • Role-based access control within a workspace.
  • Multi-factor authentication available on accounts.
  • Least-privilege access for our own staff, and audit logging.
  • Data held in the European Union.

7. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with the detail you need to meet your own notification duties.

8. Return and deletion

You can export or delete your data at any time from within the service. When your account closes, we delete your data within 30 days, except where the law requires us to keep it. Backups are purged on their own cycle, within 90 days.

9. International transfers

Data is stored in the European Union. Where any transfer outside the UK or EEA occurs, it is covered by an adequacy decision or standard contractual clauses.

10. Contact

privacy@scoperva.com