Under developmentthis site is a work in progress and the app isn't open for sign-in yet.See what's coming
ScopeSense
Article 28 GDPR

Data Processing Agreement

Last updated 6 Jul 2026

1. Parties

This Data Processing Agreement ("DPA") applies between the Customer (as data controller) and ScopeSense GmbH (i.G.), Berlin, Germany (as data processor), and forms part of the Terms of Service.

2. Subject matter and duration

The processor processes personal data on behalf of the controller solely for the purpose of providing the Service. The DPA applies for as long as the controller has an active ScopeSense subscription.

3. Nature and purpose of processing

Storage and processing of project documents (drawings, specifications, BOQs, vendor quotes), extraction of scope items, gap detection, compliance checks and pricing analytics.

4. Categories of data subjects

  • Employees and authorised users of the Customer.
  • Individuals mentioned in project documents (very limited — typically none).

5. Categories of personal data

  • Contact data (name, email, workplace).
  • Usage data (logs, IP, timestamps).
  • Any personal data incidental to uploaded project documents.

6. Subprocessors

The current list of authorised subprocessors:

  • Hetzner Online GmbH — hosting (Germany).
  • Anthropic PBC — AI processing on API-only basis; no training on customer data.
  • Stripe Payments Europe — billing.
  • Plausible Analytics — usage analytics (EU-hosted).

We notify controllers of new subprocessors at least 30 days in advance.

7. Location of processing

Primary processing takes place in Germany. Anthropic processing may occur in EU or US endpoints; Standard Contractual Clauses (SCCs) are in place.

8. Security measures

  • TLS in transit, AES-256 at rest.
  • Access controls, role-based permissions, MFA for administrators.
  • Regular backups, disaster recovery, incident response plan.
  • Personnel bound by confidentiality agreements.

9. Data subject rights and controller assistance

We assist the controller in fulfilling data-subject rights (access, rectification, erasure, portability) within reasonable time and cost.

10. Termination

Upon termination the processor deletes or returns all personal data within 30 days, unless retention is required by law.