ScopeGov← Back to home
Legal · DPA

Data Processing Addendum

Last updated: [DATE OF PUBLICATION] · Effective on publication

Draft for internal review. This follows the standard controller/processor shape (roughly GDPR Art. 28-style) that most agency customers with EU or UK clients will expect to see. It is not legal advice, and the audit-rights, breach-notification-window, and SCC-annex sections need a lawyer’s pass — particularly if you plan to sign this bilaterally with enterprise customers rather than publishing it as a standard addendum.
On this page
  • 1. Parties & scope
  • 2. Roles
  • 3. Details of processing
  • 4. Processing on instructions
  • 5. Confidentiality
  • 6. Security measures
  • 7. Subprocessors
  • 8. Data subject requests
  • 9. Breach notification
  • 10. Return & deletion
  • 11. Audit rights
  • 12. International transfers
  • 13. Precedence

1. Parties & scope

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“Controller,” “you”) and Saltern Studio Ltd., operating as ScopeGov (“Processor,” “we”). It applies whenever we process personal data on your behalf as part of the service — most commonly, data about your clients and their signers that you enter into ScopeGov.

2. Roles

You act as Controller for the personal data of your own team, your clients, and their representatives that you submit to ScopeGov. We act as Processor with respect to that data, and as independent Controller only for the limited account and billing data described in our Privacy Policy that we need to run our own business relationship with you.

3. Details of processing

CategoryDetail
Subject matterProvision of the ScopeGov scope-governance platform
DurationTerm of the underlying Terms of Service, plus retention period on termination
Nature of processingStorage, retrieval, AI-assisted drafting and classification, transmission (e.g. email, signing portal), deletion
Categories of dataNames, emails, and correspondence of client contacts and signers; SOW, change order, and invoice content; agency team account data
Categories of data subjectsYour team members; your clients’ contacts and authorized signers

4. Processing on instructions

We process personal data only on your documented instructions — which include the instructions built into your configuration of the service (for example, forwarding a thread to Guardian, or inviting a named signer) — unless required to do otherwise by law, in which case we’ll notify you first where legally permitted.

5. Confidentiality

We ensure that anyone we authorize to process personal data is under an obligation of confidentiality, whether contractual or statutory.

6. Security measures

We maintain technical and organizational measures appropriate to the risk, including row-level database access control per workspace, isolation of sensitive workspace secrets from general application access, encryption in transit, and two-factor authentication enforced for governance-level permissions. Full detail is on our Security page.

7. Subprocessors

You authorize the subprocessors listed in our Privacy Policy. We’ll give notice before adding a new subprocessor that will handle personal data in scope of this DPA, so you can object on reasonable data-protection grounds. Notice method: [email list / changelog page].

8. Data subject requests

If we receive a request from one of your clients or their signers to exercise a data-subject right, we’ll forward it to you promptly rather than responding directly, since you control the underlying relationship. We’ll give you reasonable assistance to respond, including through the export and deletion tools built into the product.

9. Breach notification

We’ll notify you without undue delay, and in any case within [72 hours] of becoming aware, of any confirmed breach affecting personal data we process on your behalf, with the information reasonably available to us at that time.

10. Return & deletion

On termination, you can export your workspace’s content before it’s deleted on the schedule described in our Privacy Policy, unless we’re required to retain a copy by law.

11. Audit rights

On reasonable written notice, and no more than once per 12 months absent a specific security concern, we’ll provide the information reasonably necessary to demonstrate compliance with this DPA — [specify: questionnaire response, summary report, or on-site/remote audit terms].

12. International transfers

Where personal data is transferred outside your jurisdiction to a subprocessor listed above, we rely on that provider’s Standard Contractual Clauses or an equivalent recognized transfer mechanism. [Attach SCC annex / transfer impact assessment reference if required].

13. Precedence

This DPA forms part of, and is incorporated into, our Terms of Service. In the event of a conflict specific to data protection, this DPA controls.

ScopeGov is operated by Saltern Studio Ltd., Nairobi, Kenya.
PrivacyTermsDPASecurityCookies