1. Roles and scope
The customer is controller and the Scopevra operator is processor for customer account, workspace and opportunity data processed to provide the service. Each party remains responsible for data it controls independently.
Baseline Article 28 terms for customers using Scopevra to process personal data.
The customer is controller and the Scopevra operator is processor for customer account, workspace and opportunity data processed to provide the service. Each party remains responsible for data it controls independently.
Scopevra processes data only on documented customer instructions, the agreement and applicable law. Access is limited to authorized persons subject to confidentiality obligations.
Controls include HTTPS transport, managed identity, verified email, role-based tenant isolation, PostgreSQL row-level security, audit records, bounded uploads, signed billing webhooks, rate limiting and monitored production endpoints.
The current production provider list, processing purposes, roles and transfer notes are published at /legal/subprocessors. Scopevra reviews every material change and gives advance notice where practical unless urgent security or legal action requires otherwise.
Scopevra assists with data-subject requests, security assessments and legally required breach notifications without undue delay. Privacy requests go to privacy@scopevra.com; security reports go to security@scopevra.com.
At termination, customer data is returned or deleted according to documented retention, backup ageing and legal obligations. Deletion requests are recorded and auditable.
Applicable transfer safeguards and provider terms govern international processing. Reasonable compliance information is available on request; on-site audits require advance agreement and appropriate confidentiality.