Data Processing Addendum
1. Parties & scope
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“Controller,” “you”) and Saltern Studio Ltd., operating as ScopeGov (“Processor,” “we”). It applies whenever we process personal data on your behalf as part of the service — most commonly, data about your clients and their signers that you enter into ScopeGov.
2. Roles
You act as Controller for the personal data of your own team, your clients, and their representatives that you submit to ScopeGov. We act as Processor with respect to that data, and as independent Controller only for the limited account and billing data described in our Privacy Policy that we need to run our own business relationship with you.
3. Details of processing
| Category | Detail |
|---|---|
| Subject matter | Provision of the ScopeGov scope-governance platform |
| Duration | Term of the underlying Terms of Service, plus retention period on termination |
| Nature of processing | Storage, retrieval, AI-assisted drafting and classification, transmission (e.g. email, signing portal), deletion |
| Categories of data | Names, emails, and correspondence of client contacts and signers; SOW, change order, and invoice content; agency team account data |
| Categories of data subjects | Your team members; your clients’ contacts and authorized signers |
4. Processing on instructions
We process personal data only on your documented instructions — which include the instructions built into your configuration of the service (for example, forwarding a thread to Guardian, or inviting a named signer) — unless required to do otherwise by law, in which case we’ll notify you first where legally permitted.
5. Confidentiality
We ensure that anyone we authorize to process personal data is under an obligation of confidentiality, whether contractual or statutory.
6. Security measures
We maintain technical and organizational measures appropriate to the risk, including row-level database access control per workspace, isolation of sensitive workspace secrets from general application access, encryption in transit, and two-factor authentication enforced for governance-level permissions. Full detail is on our Security page.
7. Subprocessors
You authorize the subprocessors listed in our Privacy Policy. We’ll give notice before adding a new subprocessor that will handle personal data in scope of this DPA, so you can object on reasonable data-protection grounds. Notice method: [email list / changelog page].
8. Data subject requests
If we receive a request from one of your clients or their signers to exercise a data-subject right, we’ll forward it to you promptly rather than responding directly, since you control the underlying relationship. We’ll give you reasonable assistance to respond, including through the export and deletion tools built into the product.
9. Breach notification
We’ll notify you without undue delay, and in any case within [72 hours] of becoming aware, of any confirmed breach affecting personal data we process on your behalf, with the information reasonably available to us at that time.
10. Return & deletion
On termination, you can export your workspace’s content before it’s deleted on the schedule described in our Privacy Policy, unless we’re required to retain a copy by law.
11. Audit rights
On reasonable written notice, and no more than once per 12 months absent a specific security concern, we’ll provide the information reasonably necessary to demonstrate compliance with this DPA — [specify: questionnaire response, summary report, or on-site/remote audit terms].
12. International transfers
Where personal data is transferred outside your jurisdiction to a subprocessor listed above, we rely on that provider’s Standard Contractual Clauses or an equivalent recognized transfer mechanism. [Attach SCC annex / transfer impact assessment reference if required].
13. Precedence
This DPA forms part of, and is incorporated into, our Terms of Service. In the event of a conflict specific to data protection, this DPA controls.