Privacy Policy (continued)
This page is part 2 of our Privacy Policy and covers sections 8 to 18. Read part 1 (summary and sections 1 to 7).
8. Payments
Your Scope subscription. Stripe processes subscription payments. Card details are sent directly to Stripe and we do not receive full card numbers. [CONFIRM] Stripe's privacy policy applies to its processing: https://stripe.com/privacy
Payments your clients make to you. Client payments are processed by Stripe through the Scope user's own connected Stripe account. Stripe receives the payer's card and payment details as its own controller under its terms and privacy policy. We receive payment status and limited details needed to show invoices as paid or unpaid. We do not hold the funds. Client payments are available to businesses in Australia, the UK and New Zealand. [CONFIRM: live]
9. Who we share information with
We do not sell personal information, and we do not share it for other companies' own marketing.
We share personal information with:
Service providers (subprocessors) who help us run Scope, such as hosting, database and file storage, media processing, AI and transcription, email delivery, payments, analytics, error monitoring and customer support. They may only use it to provide services to us. The current list, with what each does and where it processes data, is at [PLACEHOLDER: /legals/subprocessors]. [PLACEHOLDER: describe how customers can be notified of changes, for example an email list]
People you choose to share with: your team members, and your clients through portals, share links, proposals, contracts and invoices. Anyone with a share link can view what it shares until you revoke it. Portfolio pages you publish are public.
[v3 addition, 7 Oct 2026] The public, through portfolio pages. Portfolio pages you publish can be seen by anyone and may be indexed and cached by search engines until you unpublish them, and removal from search results can take time. [CONFIRM: whether portfolio pages can be set to noindex] [LAWYER TO CONFIRM]
[v3 addition, 7 Oct 2026] Signing provider, if any. [PLACEHOLDER: name the Scope Sign provider here and on the subprocessors page, or delete this bullet if Scope Sign is fully in-house.]
Integrations you connect: for example Google or Microsoft calendars, and Stripe.
Professional advisers (lawyers, accountants, auditors) under confidentiality.
Authorities, where the law requires it or to protect the rights, property or safety of users, the public or us.
A buyer or successor if our business is sold or merged, who must handle it in line with this policy.
10. International transfers
We are based in Australia. Our service providers may store or process personal information in [PLACEHOLDER: countries, for example Australia, the United States, the United Kingdom and the European Union]. The subprocessors page shows the location for each provider.
When personal information leaves Australia, we take reasonable steps so that recipients handle it consistently with the Australian Privacy Principles (APP 8). When UK personal information is transferred outside the UK to a country without UK adequacy regulations, we use the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism. For New Zealand personal information, we disclose it overseas only where IPP 12 allows, for example where the recipient is subject to comparable safeguards. [Lawyer to confirm mechanisms per provider; UK to Australia transfers need a mechanism because Australia does not have UK adequacy.]
11. How long we keep information
Information | How long |
|---|---|
Account information | While your account is active, then [PLACEHOLDER: e.g. 90 days] after closure |
Workspace content, including client data, files and media | While your workspace is active. After cancellation, [PLACEHOLDER: e.g. 30 days] to export, then deleted within [PLACEHOLDER: e.g. 90 days], including from backups |
Audio recordings | [PLACEHOLDER] |
Transcripts and AI outputs | Until you delete them, or with workspace content |
Signed contracts and signing certificates | Until you delete them, or with workspace content. You should download copies you need to keep |
Billing and tax records | [PLACEHOLDER: e.g. 7 years] as required by tax law |
Support conversations | [PLACEHOLDER: e.g. 3 years] |
Website analytics | [PLACEHOLDER] |
Security logs | [PLACEHOLDER: e.g. 12 months] |
We may keep information longer where the law requires it or to resolve disputes. When information is no longer needed, we delete or de-identify it.
12. Security and data breaches
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, change or disclosure. These include keeping each workspace's data separate, controlling access by account and project, giving clients access only to the project and sections a user shares, and using access tokens for portal and share links that users can revoke. [PLACEHOLDER: add only other measures that are in place and can be evidenced, for example encryption in transit.]
No system is completely secure. Please use a strong password, keep it private, and revoke share links you no longer need.
If a data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. Where UK data is affected, we will notify the Information Commissioner's Office within 72 hours where required, and affected individuals where the risk is high. Where New Zealand data is affected and the breach has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected people as soon as practicable. Where we act for a Scope user, we will tell that user without undue delay so they can meet their own obligations.
To report a security concern: hello@heyscope.io.
13. Your rights
13.1 Everyone
You can ask us to:
give you access to the personal information we hold about you;
correct information that is wrong, out of date or incomplete;
delete your information or close your account;
give you a copy of information you provided, in a common format;
stop sending you marketing.
Many changes can be made directly in Scope, for example in [PLACEHOLDER: Settings]. Otherwise, email hello@heyscope.io. We may need to verify your identity. There is no fee, unless the law allows one for an unusual or repeated request. If we refuse a request, we will tell you why and how to complain.
13.2 Australia
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). [Lawyer to confirm whether Scope is covered or exempt as a small business, and whether to comply voluntarily or opt in.] We aim to respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: www.oaic.gov.au.
13.3 United Kingdom
You also have the right to object to processing based on legitimate interests, to restrict processing, to withdraw consent at any time, and not to be subject to solely automated decisions with legal or similarly significant effects. We respond within one month, which can be extended in some cases. You can complain to the Information Commissioner's Office: ico.org.uk.
13.4 New Zealand
You can ask to access and correct personal information under the Privacy Act 2020 (IPPs 6 and 7). We respond within 20 working days. You can complain to the Office of the Privacy Commissioner: privacy.org.nz.
13.5 Information in a Scope user's workspace
If your request concerns information a Scope user controls (section 7), we will refer it to them or help them respond.
14. Marketing
We send marketing emails only where the law allows: with your consent, or about similar products if you are a customer and have not opted out. Every marketing email has an unsubscribe link. Service messages (such as receipts, trial reminders, security alerts and signing requests) are not marketing and will still be sent while you have an account. We follow the Spam Act 2003 (Cth), the UK Privacy and Electronic Communications Regulations and the New Zealand Unsolicited Electronic Messages Act 2007.
15. Cookies
We use cookies and similar technologies on our website and in the Scope web app. Non-essential cookies are used only with your consent where the law requires it. See our Cookie Policy: [PLACEHOLDER: /legals/cookie-policy]. [PLACEHOLDER: whether we honour Global Privacy Control signals.]
16. Children
Scope is a business service for people aged 18 or over. We do not knowingly collect personal information from children. If you think a child has given us personal information, contact us and we will delete it. Scope users must not use Scope to collect children's information unless they have a lawful basis and any required parental consent.
17. Changes to this policy
We will post updates on this page and change the "Last updated" date. If we make a material change, we will tell account holders by email or in Scope before it takes effect. [PLACEHOLDER: link to previous versions]
18. Contact
[PLACEHOLDER: company legal name]
ABN [PLACEHOLDER]
[PLACEHOLDER: address]
Privacy: hello@heyscope.io