GDPR at Scope
The short version of how data protection works here, with links to the detail.
Roles
For your account data, Scope is the controller. For the enquiries your customers send you, you are the controller and Scope is your processor: we act on your instructions, and this page plus the privacy policy and terms together describe that processing.
Where data lives
Your database and photo storage are hosted with Supabase on AWS eu-west-2 (London). Some providers we rely on process limited data outside the UK; those transfers rely on UK adequacy regulations or standard contractual clauses.
Subprocessors
Supabase (database, storage), Vercel (hosting), Stripe (payments), Twilio (numbers and SMS), Upstash (rate limiting), Google (Gmail integration, only if you connect it), OpenAI (email classification), and our transactional email providers. We will update this list before adding a new subprocessor that touches member data.
What you can rely on
- Leads are never resold or shared between members.
- Row-level security separates every tenant in the database.
- Export your data any time; deletion requests honoured within a month.
- Breach notification to affected members without undue delay.
Data processing agreement
If your own compliance process needs a signed DPA, email support@tryscope.co.uk and we will provide one.
End customers
If you sent an enquiry to a tradesperson who uses Scope and want it corrected or deleted, ask them directly, or email us and we will help.