Data Processing Addendum
This Data Processing Addendum (“DPA”) supplements the agreement entered into between the Client identified in the Order Form and Scope Inspection Ltd (“Scope”) for the provision of the Scope Service, comprising the terms of service at getscope.ai/terms and any Order Form or such other terms as the parties may agree (the “Agreement”), in relation to the transfer and processing of Covered Data in connection with the provision of the Scope Service.
1. Definitions
1.1 Capitalised terms used but not defined within this DPA will have the meaning set forth in the Agreement. The following capitalised terms are defined as follows:
“Adequate Jurisdiction” means the UK, EEA or a country/territory deemed to provide adequate protection for individuals’ rights, as set out in (a) the Data Protection Act 2018 or regulations made by the UK Secretary of State, and (b) for Data Subjects in the EEA, a European Commission decision.
“Anonymised Data” means data created using Covered Data that cannot reasonably be linked to such Covered Data, directly or indirectly.
“Applicable Data Protection Laws” means all applicable laws relating to privacy, confidentiality or security of Personal Data, including the GDPR and the US Data Protection Laws.
“Approved Addendum” means the template addendum, version B.1.0 issued by the UK Information Commissioner under S119A(1) Data Protection Act 2018 and laid before UK Parliament on 2 February 2022, as revised per Section 18.
“CCPA” means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended, including its implementing regulations and the California Privacy Rights Act of 2020.
“Controller Purposes” means (a) internal R&D to develop, test, improve and alter the functionality of the Scope Service and ML model performance; (b) creating anonymised datasets for training or evaluation of the Scope Service; and (c) administering the Client’s relationship with Scope.
“Covered Data” means Personal Data that is (a) contained in the Client Data and the Outputs; or (b) obtained, developed, produced or otherwise Processed by Scope or its agents/subcontractors to provide the Scope Service, as described in Schedule 1.
“Data Subject” means a natural person whose Personal Data is Processed.
“EEA” means the European Economic Area.
“GDPR” means Regulation (EU) 2016/679 (the “EU GDPR”) or, where applicable, the “UK GDPR” as defined in section 3 of the Data Protection Act 2018.
“Personal Data” means any data that (a) is linked or reasonably linkable to an identified/identifiable natural person; or (b) is otherwise “personal data,” “personal information,” “personally identifiable information,” or similarly defined data under Applicable Data Protection Laws.
“Processing” means any operation performed on Personal Data, whether by automated means. “Process”, “Processes” and “Processed” are interpreted accordingly.
“Prohibited Personal Data” means (a) special-category data under Article 9 GDPR (racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, criminal convictions); (b) biometric identifiers/templates; (c) financial information (incl. cardholder/authentication data under PCI DSS); (d) personally identifiable financial information under the Gramm-Leach-Bliley Act 1999; (e) national identification numbers (SSNs, SINs, driver’s licence/passport numbers, etc.); (f) information relating to individuals under 13; (g) education records under FERPA 1974; (h) protected health information under HIPAA.
“Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to Covered Data.
“Standard Contractual Clauses / SCCs” means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914.
“Sub-processor” means a Processor appointed by another Processor to Process Personal Data on its behalf.
“US Data Protection Laws” means all applicable US federal and state data-protection laws, including the CCPA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Utah Consumer Privacy Act, and Connecticut Senate Bill 6.
1.2 The terms “controller”, “processor”, “business” and “service provider” have the meanings given to them in the Applicable Data Protection Laws.
2. Interaction with the Agreement
2.1 This DPA is incorporated into and forms an integral part of the Agreement. This DPA supplements and (in case of contradictions) supersedes the Agreement with respect to any Processing of Covered Data.
3. Role of the Parties
The parties acknowledge and agree that: save as set out in paragraph 3(b), Scope acts as a processor or service provider and Client acts as a controller or business; and for the purposes of the GDPR, Scope acts as a controller with respect to any Processing of Covered Data for the Controller Purposes.
4. Processing of Personal Data
4.1 The details of the Processing (subject matter, nature, purpose, categories of Personal Data and Data Subjects) are described in the Agreement and Schedule 1.
4.2 Scope shall comply with its obligations under Applicable Data Protection Laws and any Processing restrictions in the Agreement, and only Process Covered Data for the Controller Purposes, and otherwise on behalf of and under the Controller’s instructions unless required by UK law (in which case Scope shall inform the Client before Processing, unless prohibited on important grounds of public interest). The Agreement and this DPA constitute the Client’s instructions; the Client may issue further written instructions.
Without limiting the foregoing, Scope is prohibited from: selling Covered Data or making it available to third parties for valuable consideration; sharing it with third parties for cross-context behavioural advertising; retaining, using or disclosing it for any purpose other than the specified business purposes; retaining, using or disclosing it outside the direct business relationship; and combining it with Personal Data received from another person or collected from its own interaction with the Data Subject.
4.5 Scope will provide Client with information to conduct and document required data protection assessments, and promptly inform Client if an instruction infringes Applicable Data Protection Laws.
5. Client Obligations
5.1 Client shall comply with its obligations as a controller/business, including: providing information to Data Subjects regarding the Processing of their Covered Data as required; and obtaining valid consents from Data Subjects where required for lawful Processing. Client shall not include any Prohibited Personal Data in the Client Data. Scope will not be liable for any loss caused (in whole or in part) by the Client’s failure to comply with these obligations.
6. Confidentiality and Disclosure
6.1 Scope shall limit access to Covered Data to personnel with a business need, and ensure such personnel are subject to obligations at least as protective as this DPA and the Agreement, including duties of confidentiality.
7. Sub-processors
7.1 Scope may Process Covered Data anywhere it or the Authorised Sub-processors maintain facilities, subject to this paragraph 7.
7.2 Client grants Scope general authorisation to engage the Sub-processors listed in Schedule 3 (the “Authorised Sub-processors”).
7.3 Scope shall enter into written agreements with each Authorised Sub-processor imposing data protection obligations no less protective than Scope’s, and remains liable for their compliance.
Scope shall provide at least thirty (30) days’ notice of proposed changes to the Authorised Sub-processors. Client may object in writing within thirty (30) days (an “Objection”). The parties shall work in good faith to resolve any Objection within thirty (30) days; failing resolution, Client may terminate the affected portion of the Agreement. If Scope cannot evidence a new sub-processor’s compliance, it shall refrain from engaging it.
8. Data Subject Rights Requests
8.1 Scope will notify Client without undue delay of any request from a Data Subject to assert their rights (a “Data Subject Request”).
8.2 Other than for Processing for the Controller Purposes, Client has sole discretion in responding and Scope shall not respond, save to advise the Data Subject that the request has been forwarded to Client.
8.3 Scope will provide reasonable assistance for Client to fulfil its obligations.
9. Security
9.1 Scope will implement and maintain appropriate technical and organisational measures to ensure the security of Covered Data, including protection against unauthorised or unlawful Processing and accidental loss, destruction or damage.
9.2 Scope shall account for the nature, scope, context and purpose of Processing and associated risks.
9.3 The Provider shall implement and maintain the following security measures:
Regular encrypted backups of all Customer Data with secure off-site storage;
Industry-standard encryption for Customer Data, both at rest and in transit;
Up-to-date malware and virus protection systems across all relevant infrastructure components; and
Regular security awareness training for all personnel with access to Customer Data, covering data protection, security best practices, and threat identification.
9.4 The Provider shall review and update these security measures at least annually to ensure they remain appropriate and effective.
10. Information and Audits
10.1 Scope shall notify Client promptly if it can no longer meet its obligations under Applicable Data Protection Laws.
10.2 Client may take reasonable steps to ensure Scope uses Covered Data consistently with Client’s obligations, and upon reasonable notice, to stop and remediate unauthorised use.
11. Security Incidents
11.1 Scope shall notify Client in writing without undue delay, and in any event within forty-eight (48) hours, of any Security Incident.
11.2 Scope shall take reasonable steps to contain, investigate and mitigate the incident and provide timely information (nature, mitigation measures, investigation status).
11.3 Scope shall provide reasonable assistance with Client’s investigation and notification obligations.
11.4 Notification/response shall not be construed as an acknowledgement of fault or liability.
12. Term, Deletion and Return
12.1 This DPA commences on the Commencement Date and, notwithstanding termination of the Agreement, remains in effect until Scope’s deletion or anonymisation of all Covered Data.
12.2 If requested by Client within fifteen (15) days of expiry (the “Retention Period”), Scope shall provide a copy of all Covered Data in a commonly used format (or self-service download); on expiry of the Retention Period, Scope shall delete all copies other than data Processed for the Controller Purposes.
13. International Transfers of Personal Data
13.1 Scope shall not transfer Covered Data outside the UK unless the recipient is in an Adequate Jurisdiction, or the transfer is governed by an agreement incorporating standard data protection clauses approved under Section 119A of the Data Protection Act 2018 and, for EEA Data Subjects, the SCCs. The Approved Addendum applies to transfers from Scope to Client where the Client is not in an Adequate Jurisdiction. Execution of the Agreement has the same effect as signing the Approved Addendum.
14. Anonymised Data
If Scope receives Anonymised Data from or on behalf of Client, Scope shall take reasonable measures to ensure the information cannot be associated with a Data Subject; publicly commit to Process the deidentified data solely in deidentified form and not attempt reidentification; and contractually obligate any recipients to comply with these requirements and Applicable Data Protection Laws.
15. General
15.1 The parties certify that they understand the requirements in this DPA and will comply with them.
15.2 The parties agree to negotiate in good faith any amendments required in connection with changes in Applicable Data Protection Laws.
Schedule 1: Details of Processing
Authorised Users; End Customers (individual purchasers, subscribers or other consumers of the Controller’s goods and services)
Name and contact details (email, phone); role and position at Client; content of communications from Personnel to Scope (incl. IT support requests/responses); data relating to the Authorised User’s use of the Scope Service (incl. log data)
None
Continuous
Collection, storage, deletion, rectification, aggregation
Provision of the Scope Service: receiving and processing AI Inputs and generating and providing access to Outputs
The duration of the Agreement
Schedule 2: Approved Addendum
Scope Inspection Ltd. Contact person: Jonathan Low
The Client (as identified in the Order Form). Contact person: the Client Contact identified in the Order Form
4
Yes
Yes
No
Not applicable
Not applicable
Yes
Annex 1A: List of Parties; Annex 1B: Description of Transfer (per Schedule 1)
Neither Party
Schedule 3: Authorised Sub-processors
Description of Processing
Document Storage and Processing
Document Storage and Processing
Document Processing
Document Processing