Data Processing Addendum

This Data Processing Addendum (“DPA”) supplements the agreement entered into between the Client identified in the Order Form and Scope Inspection Ltd (“Scope”) for the provision of the Scope Service, comprising the terms of service at getscope.ai/terms and any Order Form or such other terms as the parties may agree (the “Agreement”), in relation to the transfer and processing of Covered Data in connection with the provision of the Scope Service.

1. Definitions

1.1 Capitalised terms used but not defined within this DPA will have the meaning set forth in the Agreement. The following capitalised terms are defined as follows:

  • “Adequate Jurisdiction” means the UK, EEA or a country/territory deemed to provide adequate protection for individuals’ rights, as set out in (a) the Data Protection Act 2018 or regulations made by the UK Secretary of State, and (b) for Data Subjects in the EEA, a European Commission decision.

  • “Anonymised Data” means data created using Covered Data that cannot reasonably be linked to such Covered Data, directly or indirectly.

  • “Applicable Data Protection Laws” means all applicable laws relating to privacy, confidentiality or security of Personal Data, including the GDPR and the US Data Protection Laws.

  • “Approved Addendum” means the template addendum, version B.1.0 issued by the UK Information Commissioner under S119A(1) Data Protection Act 2018 and laid before UK Parliament on 2 February 2022, as revised per Section 18.

  • “CCPA” means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended, including its implementing regulations and the California Privacy Rights Act of 2020.

  • “Controller Purposes” means (a) internal R&D to develop, test, improve and alter the functionality of the Scope Service and ML model performance; (b) creating anonymised datasets for training or evaluation of the Scope Service; and (c) administering the Client’s relationship with Scope.

  • “Covered Data” means Personal Data that is (a) contained in the Client Data and the Outputs; or (b) obtained, developed, produced or otherwise Processed by Scope or its agents/subcontractors to provide the Scope Service, as described in Schedule 1.

  • “Data Subject” means a natural person whose Personal Data is Processed.

  • “EEA” means the European Economic Area.

  • “GDPR” means Regulation (EU) 2016/679 (the “EU GDPR”) or, where applicable, the “UK GDPR” as defined in section 3 of the Data Protection Act 2018.

  • “Personal Data” means any data that (a) is linked or reasonably linkable to an identified/identifiable natural person; or (b) is otherwise “personal data,” “personal information,” “personally identifiable information,” or similarly defined data under Applicable Data Protection Laws.

  • “Processing” means any operation performed on Personal Data, whether by automated means. “Process”, “Processes” and “Processed” are interpreted accordingly.

  • “Prohibited Personal Data” means (a) special-category data under Article 9 GDPR (racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, criminal convictions); (b) biometric identifiers/templates; (c) financial information (incl. cardholder/authentication data under PCI DSS); (d) personally identifiable financial information under the Gramm-Leach-Bliley Act 1999; (e) national identification numbers (SSNs, SINs, driver’s licence/passport numbers, etc.); (f) information relating to individuals under 13; (g) education records under FERPA 1974; (h) protected health information under HIPAA.

  • “Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to Covered Data.

  • “Standard Contractual Clauses / SCCs” means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914.

  • “Sub-processor” means a Processor appointed by another Processor to Process Personal Data on its behalf.

  • “US Data Protection Laws” means all applicable US federal and state data-protection laws, including the CCPA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Utah Consumer Privacy Act, and Connecticut Senate Bill 6.

1.2 The terms “controller”, “processor”, “business” and “service provider” have the meanings given to them in the Applicable Data Protection Laws.

2. Interaction with the Agreement

2.1 This DPA is incorporated into and forms an integral part of the Agreement. This DPA supplements and (in case of contradictions) supersedes the Agreement with respect to any Processing of Covered Data.

3. Role of the Parties

The parties acknowledge and agree that: save as set out in paragraph 3(b), Scope acts as a processor or service provider and Client acts as a controller or business; and for the purposes of the GDPR, Scope acts as a controller with respect to any Processing of Covered Data for the Controller Purposes.

4. Processing of Personal Data

4.1 The details of the Processing (subject matter, nature, purpose, categories of Personal Data and Data Subjects) are described in the Agreement and Schedule 1.

4.2 Scope shall comply with its obligations under Applicable Data Protection Laws and any Processing restrictions in the Agreement, and only Process Covered Data for the Controller Purposes, and otherwise on behalf of and under the Controller’s instructions unless required by UK law (in which case Scope shall inform the Client before Processing, unless prohibited on important grounds of public interest). The Agreement and this DPA constitute the Client’s instructions; the Client may issue further written instructions.

Without limiting the foregoing, Scope is prohibited from: selling Covered Data or making it available to third parties for valuable consideration; sharing it with third parties for cross-context behavioural advertising; retaining, using or disclosing it for any purpose other than the specified business purposes; retaining, using or disclosing it outside the direct business relationship; and combining it with Personal Data received from another person or collected from its own interaction with the Data Subject.

4.5 Scope will provide Client with information to conduct and document required data protection assessments, and promptly inform Client if an instruction infringes Applicable Data Protection Laws.

5. Client Obligations

5.1 Client shall comply with its obligations as a controller/business, including: providing information to Data Subjects regarding the Processing of their Covered Data as required; and obtaining valid consents from Data Subjects where required for lawful Processing. Client shall not include any Prohibited Personal Data in the Client Data. Scope will not be liable for any loss caused (in whole or in part) by the Client’s failure to comply with these obligations.

6. Confidentiality and Disclosure

6.1 Scope shall limit access to Covered Data to personnel with a business need, and ensure such personnel are subject to obligations at least as protective as this DPA and the Agreement, including duties of confidentiality.

7. Sub-processors

7.1 Scope may Process Covered Data anywhere it or the Authorised Sub-processors maintain facilities, subject to this paragraph 7.

7.2 Client grants Scope general authorisation to engage the Sub-processors listed in Schedule 3 (the “Authorised Sub-processors”).

7.3 Scope shall enter into written agreements with each Authorised Sub-processor imposing data protection obligations no less protective than Scope’s, and remains liable for their compliance.

Scope shall provide at least thirty (30) days’ notice of proposed changes to the Authorised Sub-processors. Client may object in writing within thirty (30) days (an “Objection”). The parties shall work in good faith to resolve any Objection within thirty (30) days; failing resolution, Client may terminate the affected portion of the Agreement. If Scope cannot evidence a new sub-processor’s compliance, it shall refrain from engaging it.

8. Data Subject Rights Requests

8.1 Scope will notify Client without undue delay of any request from a Data Subject to assert their rights (a “Data Subject Request”).

8.2 Other than for Processing for the Controller Purposes, Client has sole discretion in responding and Scope shall not respond, save to advise the Data Subject that the request has been forwarded to Client.

8.3 Scope will provide reasonable assistance for Client to fulfil its obligations.

9. Security

9.1 Scope will implement and maintain appropriate technical and organisational measures to ensure the security of Covered Data, including protection against unauthorised or unlawful Processing and accidental loss, destruction or damage.

9.2 Scope shall account for the nature, scope, context and purpose of Processing and associated risks.

9.3 The Provider shall implement and maintain the following security measures:

  1. Regular encrypted backups of all Customer Data with secure off-site storage;

  2. Industry-standard encryption for Customer Data, both at rest and in transit;

  3. Up-to-date malware and virus protection systems across all relevant infrastructure components; and

  4. Regular security awareness training for all personnel with access to Customer Data, covering data protection, security best practices, and threat identification.

9.4 The Provider shall review and update these security measures at least annually to ensure they remain appropriate and effective.

10. Information and Audits

10.1 Scope shall notify Client promptly if it can no longer meet its obligations under Applicable Data Protection Laws.

10.2 Client may take reasonable steps to ensure Scope uses Covered Data consistently with Client’s obligations, and upon reasonable notice, to stop and remediate unauthorised use.

11. Security Incidents

11.1 Scope shall notify Client in writing without undue delay, and in any event within forty-eight (48) hours, of any Security Incident.

11.2 Scope shall take reasonable steps to contain, investigate and mitigate the incident and provide timely information (nature, mitigation measures, investigation status).

11.3 Scope shall provide reasonable assistance with Client’s investigation and notification obligations.

11.4 Notification/response shall not be construed as an acknowledgement of fault or liability.

12. Term, Deletion and Return

12.1 This DPA commences on the Commencement Date and, notwithstanding termination of the Agreement, remains in effect until Scope’s deletion or anonymisation of all Covered Data.

12.2 If requested by Client within fifteen (15) days of expiry (the “Retention Period”), Scope shall provide a copy of all Covered Data in a commonly used format (or self-service download); on expiry of the Retention Period, Scope shall delete all copies other than data Processed for the Controller Purposes.

13. International Transfers of Personal Data

13.1 Scope shall not transfer Covered Data outside the UK unless the recipient is in an Adequate Jurisdiction, or the transfer is governed by an agreement incorporating standard data protection clauses approved under Section 119A of the Data Protection Act 2018 and, for EEA Data Subjects, the SCCs. The Approved Addendum applies to transfers from Scope to Client where the Client is not in an Adequate Jurisdiction. Execution of the Agreement has the same effect as signing the Approved Addendum.

14. Anonymised Data

If Scope receives Anonymised Data from or on behalf of Client, Scope shall take reasonable measures to ensure the information cannot be associated with a Data Subject; publicly commit to Process the deidentified data solely in deidentified form and not attempt reidentification; and contractually obligate any recipients to comply with these requirements and Applicable Data Protection Laws.

15. General

15.1 The parties certify that they understand the requirements in this DPA and will comply with them.

15.2 The parties agree to negotiate in good faith any amendments required in connection with changes in Applicable Data Protection Laws.

Schedule 1: Details of Processing

Categories of Data Subjects

Categories of Data Subjects

Authorised Users; End Customers (individual purchasers, subscribers or other consumers of the Controller’s goods and services)

Categories of Personal Data

Categories of Personal Data

Name and contact details (email, phone); role and position at Client; content of communications from Personnel to Scope (incl. IT support requests/responses); data relating to the Authorised User’s use of the Scope Service (incl. log data)

Special categories of Personal Data

Special categories of Personal Data

None

Frequency of transfers

Frequency of transfers

Continuous

Nature of the Processing

Nature of the Processing

Collection, storage, deletion, rectification, aggregation

Purposes of the Processing

Purposes of the Processing

Provision of the Scope Service: receiving and processing AI Inputs and generating and providing access to Outputs

Retention period

Retention period

The duration of the Agreement

Schedule 2: Approved Addendum

Exporter

Exporter

Scope Inspection Ltd. Contact person: Jonathan Low

Importer

Importer

The Client (as identified in the Order Form). Contact person: the Client Contact identified in the Order Form

Module

Module

4

Module in operation

Module in operation

Yes

Clause 7 (Docking Clause)

Clause 7 (Docking Clause)

Yes

Clause 11 (Option)

Clause 11 (Option)

No

Clause 9a (Prior/General Authorisation)

Clause 9a (Prior/General Authorisation)

Not applicable

Clause 9a (Time period)

Clause 9a (Time period)

Not applicable

Data from Importer combined with data collected by Exporter?

Data from Importer combined with data collected by Exporter?

Yes

Appendix Information

Appendix Information

Annex 1A: List of Parties; Annex 1B: Description of Transfer (per Schedule 1)

Which Parties may end this Addendum (Section 19)

Which Parties may end this Addendum (Section 19)

Neither Party

Schedule 3: Authorised Sub-processors

Name of Sub-processor

Name of Sub-processor

Description of Processing

Google Cloud

Google Cloud

Document Storage and Processing

Amazon Web Services

Amazon Web Services

Document Storage and Processing

Anthropic

Anthropic

Document Processing

Microsoft Azure

Microsoft Azure

Document Processing