Trust and data protection

Service providers supporting ScopeWorth.

See each provider’s purpose, processing location, and applicable activation conditions.

Roster review version 2026-10-03. Conditional entries are not a claim of active Customer Content processing. Stripe’s separate billing role is identified below.

Provider roster

Microsoft Azure

Entity
Microsoft Ireland Operations Limited, with Microsoft Corporation and applicable affiliates
Purpose
API, workers, database, queues, storage, secrets and monitoring
Data
Customer Content and operational metadata; shared account, directory and billing metadata
Location
Assigned production data plane: Central US or North Europe (Ireland), including regional database backups, storage, queues and telemetry. Shared identity and billing control plane and the single staging environment: Central US.
Status
Business account and accepted Microsoft Customer Agreement verified. Production Ireland is a permanent regional environment; workspace access requires its active immutable pin and accepted readiness checks.
Safeguards
Incorporated Microsoft DPA, private regional database, encryption and applicable transfer provisions. Regional storage does not imply EU-only processing by every provider.

Cloudflare

Entity
Cloudflare, Inc.
Purpose
Edge routing, CDN, WAF, website hosting, forms and spam protection
Data
Traffic and request metadata; website lead submissions in D1
Location
Global edge network; website lead storage has separate configuration
Status
Business account acceptance and current DPA reviewed; staging routing and access controls verified.
Safeguards
Edge access controls, incorporated provider DPA and applicable Data Privacy Framework or contractual transfer provisions.

Stripe

Entity
Stripe Payments Europe, Limited and Stripe Technology Europe, Limited, as applicable
Purpose
Separate billing, checkout and subscriptions processing
Data
Billing contact, account and transaction metadata; not general delivery evidence
Location
Provider processing locations vary with the contracted service
Status
Business account acceptance and service terms reviewed. Production billing and Managed Payments depend on their separate commercial activation.
Safeguards
Service-specific controller/processor roles, Stripe DPA and data-transfer terms. Stripe is not a universal Customer Content subprocessor.

Resend

Entity
Plus Five Five, Inc. (Resend)
Purpose
Transactional email, lifecycle notices and report delivery
Data
Recipient addresses, message content and delivery metadata
Location
Primarily United States
Status
Business account and account-signed DPA verified. Controlled Gmail and Outlook delivery and signed callbacks tested on staging.
Safeguards
Provider DPA and applicable contractual transfer provisions; signed callbacks and bounded encrypted mail queues. Account-termination deletion is separate from individual-message retention.

PostHog EU

Entity
PostHog, Inc.
Purpose
Analytics where configured; website analytics is separate from Customer Content
Data
Usage events, identifiers and opted-in contact profiles
Location
European Union service endpoint; support and onward processing have separate provider terms
Status
Signed business DPA verified. Product analytics depend on feature configuration.
Safeguards
Event minimization, IP discard in the reviewed project, website consent controls and signed DPA. The configured 30-day replay retention is not a retention limit for every analytics event.

OpenAI

Entity
OpenAI Ireland Ltd. for the reviewed EEA business customer
Purpose
Optional AI-assisted report narratives and estimate review
Data
Feature inputs, validated report facts and prompts
Location
Reviewed staging project uses Global residency and Standard Retention
Status
Business service terms and incorporated DPA reviewed. Staging credential and disabled sharing verified; production AI is unconfigured.
Safeguards
No general-purpose model training without explicit opt-in; reviewed sharing settings disabled; Responses callers set store: false. Standard provider retention is not zero retention or EU-only processing.

Anthropic

Entity
Applicable Anthropic contracting entity must be verified before activation
Purpose
Optional AI Q&A, grouping and narratives
Data
Feature inputs and prompts
Location
Provider location and transfer safeguards must be established before activation
Status
Conditional and unconfigured in staging and production. Account terms and settings must be verified before Customer Content processing.
Safeguards
No activation until processing, training, retention and transfer requirements are verified.

Changes and objections

The published DPA requires at least 30 calendar days’ direct notice to organization owners and administrators before a new or replacement provider processes Customer Content. Notices identify purpose, data, locations, safeguards and the proposed effective date. Owners and admins can record reasonable data-protection objections in organization settings or write to privacy@scopeworth.app. Unresolved objections require mitigation before disputed processing; the applicable agreement addresses termination of the affected service and proportionate refunds.

Website marketing and customer-selected vendors

LinkedIn advertising measurement is website marketing processing described in the Privacy Policy; it is not used for Customer Content. Source systems a customer connects and report recipients it chooses are customer-selected parties, rather than ScopeWorth’s subprocessors.

Last reviewed: 3 October 2026