# ScopeWorth Data Processing Agreement Version 1.0. Status: draft for legal review. This version is not executed and must not be published or offered for acceptance in production until legal review is complete and the document manifest marks it `published`. ## 1. Parties and structure 1.1 This Data Processing Agreement ("DPA") is entered into between the customer organization that accepts it in the ScopeWorth product ("Customer") and ScopeWorth, Goudenregenstraat 190, 2565 GC Den Haag, the Netherlands, registered with the Netherlands Chamber of Commerce (KvK) under number 42167762, VAT number 564426970B01 ("ScopeWorth"). 1.2 This DPA forms part of the agreement under which ScopeWorth provides its delivery-analytics service to the Customer (the "Agreement"). The US State Privacy Addendum in `us-state-privacy-addendum.md` forms part of this DPA to the extent a US state privacy law applies to the processing. Where this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA prevails. Where the Standard Contractual Clauses apply, they prevail over both. 1.3 Privacy questions, requests and subprocessor objections go to privacy@scopeworth.app. Security reports and incident communications go to security@scopeworth.app. ScopeWorth has not appointed a data protection officer; its founder is the responsible privacy contact. ## 2. Definitions "Customer Personal Data" means personal data that ScopeWorth processes on the Customer's behalf in providing the service. "Customer Content" means all data the Customer or its authorized users submit to, or connect to, the service. "Data Protection Law" means the GDPR (Regulation (EU) 2016/679), the UK GDPR, the Dutch GDPR Implementation Act and, where applicable, the US state privacy laws named in the US State Privacy Addendum. "Personal Data Breach", "controller", "processor", "data subject" and "processing" have the meanings given in the GDPR. "Standard Contractual Clauses" or "SCCs" means the clauses annexed to Commission Implementing Decision (EU) 2021/914. ## 3. Roles 3.1 The Customer acts either as a controller of Customer Personal Data, or as a processor acting on behalf of its own client. ScopeWorth acts as the Customer's processor or, where the Customer is itself a processor, as its subprocessor. The Customer confirms that it has the authority of any controller it acts for to instruct ScopeWorth under this DPA. 3.2 ScopeWorth acts as an independent controller only for personal data it processes for its own purposes: account administration and authentication, billing, fraud prevention and security of the service, and compliance with its legal obligations. This DPA does not govern that processing; ScopeWorth's privacy notice does. 3.3 Source systems the Customer connects (for example Jira, GitHub or Google Calendar) and report recipients the Customer selects are chosen and authorized by the Customer. They are not ScopeWorth's subprocessors. ## 4. Instructions 4.1 ScopeWorth processes Customer Personal Data only on the Customer's documented instructions. The Agreement, this DPA and the Customer's use and configuration of the service (including the connections it authorizes and the reports it generates or sends) are the Customer's complete instructions at the time of signature. 4.2 ScopeWorth will inform the Customer if, in its opinion, an instruction infringes Data Protection Law, unless the law prohibits such information. 4.3 ScopeWorth will not use Customer Content to train general-purpose machine learning models, and will not permit its AI subprocessors to do so. Customer Content is processed by AI subprocessors only to deliver the features the Customer uses, within the per-feature controls the service provides. ## 5. Confidentiality ScopeWorth ensures that every person it authorizes to process Customer Personal Data is bound by confidentiality and has access only to the extent needed to provide, secure and support the service. ## 6. Security ScopeWorth implements the technical and organizational measures in Annex II. ScopeWorth may update those measures, provided the overall level of protection does not decrease. ## 7. Subprocessors 7.1 The Customer gives ScopeWorth general written authorization to engage subprocessors. The subprocessors engaged at the date of this version are listed in Annex III and in the versioned public list at https://scopeworth.app/subprocessors. 7.2 ScopeWorth will give the Customer at least 30 calendar days' notice before a new or replacement subprocessor begins processing Customer Personal Data. Notice is sent directly to the Customer's owners and administrators in the service and by email, and the public list is updated with a new version. The notice identifies the provider, the processing purpose, the data concerned, the processing locations, the safeguards and the intended effective date. 7.3 During the notice period the Customer may object on reasonable data-protection grounds by writing to privacy@scopeworth.app. ScopeWorth will consider the objection in good faith and seek an alternative or mitigation. If the objection is not resolved before the effective date, ScopeWorth will not send that Customer's data to the disputed provider, and the Customer may terminate the affected service without penalty and receive a proportionate refund of unused prepaid fees for it. 7.4 ScopeWorth imposes data-protection obligations on each subprocessor that are no less protective than this DPA, and remains responsible to the Customer for each subprocessor's performance. ## 8. International transfers 8.1 Where processing involves a restricted transfer under Data Protection Law, the parties rely on the SCCs: Module 2 where the Customer is a controller, and Module 3 where the Customer is a processor or ScopeWorth transfers to a subprocessor. For those SCCs, Clause 7 (docking) applies, Clause 9 option 2 (general authorization, 30 days) applies, Clause 11 optional language does not apply, Clause 17 selects the law of the Netherlands and Clause 18 selects the courts of the Netherlands. The annexes of this DPA complete the SCC annexes. 8.2 For restricted transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner applies, completed with the information in this DPA. 8.3 ScopeWorth relies on the EU-US Data Privacy Framework for a US recipient only after verifying that recipient's active certification covers the processing. ScopeWorth itself is not certified under the Data Privacy Framework. ## 9. Assistance 9.1 Taking into account the nature of the processing, ScopeWorth assists the Customer by appropriate technical and organizational measures in responding to data subject requests. The service provides a full workspace export and workspace deletion. ScopeWorth forwards to the Customer, without undue delay, any request it receives from a data subject about Customer Personal Data, and does not respond to it except on the Customer's instructions. 9.2 ScopeWorth provides reasonable assistance with the Customer's security, breach-notification, data protection impact assessment and prior-consultation obligations, taking into account the information available to it. ## 10. Personal Data Breaches 10.1 ScopeWorth will notify the Customer without undue delay and, in any event, within 24 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data, or sooner where required by applicable law. ScopeWorth will provide the information reasonably available at the time of the initial notice and supplement it without undue delay as further information becomes available. 10.2 Notice goes to the Customer's designated incident contact or, if none is designated, to its organization owners. ScopeWorth takes reasonable steps to contain and remediate the breach. The Customer remains responsible for any notice it owes to a supervisory authority, its own clients or data subjects. ## 11. Return and deletion 11.1 During the Agreement the Customer can export its workspace data in the service at any time. 11.2 When a workspace or organization is deleted, the service locks it immediately and permanently deletes its data from ScopeWorth's active database and storage after a 30-day grace period, during which the owner can export or cancel. Database backups are not edited; deleted data leaves them as they expire, within 14 days. Deleted storage objects remain recoverable by ScopeWorth for up to 7 days before they are purged. If a backup must be restored, ScopeWorth will reapply recorded deletions before the restored data becomes accessible. 11.3 ScopeWorth may retain data where Union or Member State law requires it, and retains minimal evidence of this DPA's acceptance as described in section 13. ## 12. Audits ScopeWorth makes available the information necessary to demonstrate compliance with this DPA. The Customer may, at most once in any 12-month period (or after a Personal Data Breach, or where a supervisory authority requires it), audit ScopeWorth's compliance on 30 days' written notice, during business hours, subject to reasonable confidentiality obligations and without access to other customers' data. Each party bears its own audit costs unless the audit reveals a material breach of this DPA by ScopeWorth. ## 13. Term and evidence 13.1 This DPA applies for as long as ScopeWorth processes Customer Personal Data under the Agreement. 13.2 ScopeWorth records the accepting organization, the accepting user and their role, the method and time of acceptance, and the exact version and content hash of the accepted document set. ScopeWorth keeps this minimal evidence for seven calendar years after the organization is deleted or the Agreement ends, whichever is later, unless a documented legal hold applies. It is not used for any other purpose. ## 14. Liability Each party's liability under this DPA is subject to the limitations of liability in the Agreement, except where Data Protection Law does not permit such a limitation. ## 15. Governing law and jurisdiction This Agreement is governed by the laws of the Netherlands. Disputes between the parties are subject to the exclusive jurisdiction of the competent courts of The Hague, the Netherlands, subject to mandatory applicable law and the rights and jurisdiction provisions of the applicable Standard Contractual Clauses and UK Addendum. ## Annex I — Description of processing - **Data exporter:** the Customer, as identified at acceptance. - **Data importer:** ScopeWorth, as identified in section 1.1. - **Categories of data subjects:** the Customer's personnel and contractors, the Customer's clients and their contacts, and other individuals named in the Customer's connected sources. - **Categories of personal data:** names, business email addresses, user identifiers from connected tools, work-item, code-change, calendar and communication metadata and content the Customer connects, time and cost records, and data in reports the Customer creates. - **Sensitive data:** none intended. The Customer should not connect sources that contain special-category data. - **Frequency:** continuous, for the duration of the Agreement. - **Nature and purpose:** collecting, normalizing, storing, analyzing and reporting delivery evidence so the Customer can measure the cost, scope and value of delivery work, including optional AI-assisted features. - **Retention:** as in section 11 and the plan's data window. - **Subprocessor transfers:** as in Annex III. - **Competent supervisory authority:** the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), unless Clause 13 of the SCCs requires otherwise. ## Annex II — Technical and organizational measures - **Tenant isolation:** every workspace row carries its workspace identifier and PostgreSQL row-level security restricts each request to one workspace. - **Data location:** each workspace is pinned at creation to a regional cell; its database and storage stay in that cell. ScopeWorth currently operates a United States cell, and offers a European Union cell where it is available. - **Encryption:** TLS for data in transit; provider-managed encryption at rest; connector credentials sealed with AES-256-GCM under a key ring held by the application. - **Access control:** role-based access in the product; administrative access to production infrastructure restricted to authorized ScopeWorth personnel through Azure role-based access control. - **Accountability:** an append-only audit trail of security-relevant and administrative actions in each workspace. - **Availability and recovery:** point-in-time database backups kept for 14 days in production, and a restore procedure that reapplies recorded deletions before restored data is exposed. - **Deletion:** a 30-day grace period followed by an automated purge, with a deletion record kept outside the database so a restore cannot bring deleted data back. - **Provider access:** on disconnection or deletion, ScopeWorth revokes its access at providers that support revocation and tells the Customer where the Customer must revoke access itself. - **Vulnerability and incident handling:** reports to security@scopeworth.app, and the breach notice in section 10. ## Annex III — Subprocessors The versioned public list at https://scopeworth.app/subprocessors is authoritative. At the date of this version it names: | Subprocessor | Purpose | Data | Location | | --------------- | --------------------------------------------------------------------- | ---------------------------------------------------------- | ----------------------------- | | Microsoft Azure | Hosting: API, workers, database, queues, storage, secrets, monitoring | All Customer Content | The workspace's regional cell | | Cloudflare | Edge routing, CDN and web application firewall | Traffic and request metadata | Global edge network | | Stripe | Billing, checkout and subscriptions | Billing contact and account data | United States | | Resend | Transactional email, lifecycle notices and report delivery | Recipient addresses, message content and delivery metadata | United States | | PostHog (EU) | Product analytics, where enabled | Product usage events | European Union | | OpenAI | AI report narratives, where enabled | Validated report facts and prompts | United States | | Anthropic | AI features such as Q&A, grouping and narratives, where enabled | Feature inputs and prompts | United States | Drafting note, to be removed before execution: each entity, role, location, agreement, transfer mechanism and activation status must be verified before this version is published. A provider that is not active at publication must be marked conditional or removed. Publication is also gated on the deletion ledger and restore procedure described in section 11.2 and Annex II being live and rehearsed (SCO-593, SCO-594), and on verifying the no-training commitment in section 4.3 against the AI providers' terms and settings.