Privacy Policy

Last Updated: 5 April 2026

1. Who We Are (Data Controller)

Scopit ("we", "us", "our") is the data controller responsible for your personal information.

This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to:

  • Contractors — trade professionals who use Scopit to manage change orders (data collected directly from you, Art. 13 GDPR).
  • Clients — your clients whose contact details are entered by a contractor and who receive approval links (data we receive about you indirectly, Art. 14 GDPR).
  • Waitlist users — people who sign up to hear about Scopit before launch.

2. Contractors — Data We Collect About You

When you create an account and use Scopit, we collect the following personal data:

Account & profile data

  • Name and email address (from your Google account via OAuth)
  • Phone number and company name (if you add them to your profile)
  • Company logo (if uploaded)
  • Timestamp of when you accepted this Privacy Policy

Project and change order data

  • Project names, addresses, and financial values
  • Change order titles, descriptions, pricing, and status history
  • File attachments you upload (photos, PDFs)

Communication and activity data

  • Records of email and SMS notifications sent through the platform
  • Authentication session tokens (stored securely, managed by Supabase)

Why we process it and on what legal basis

PurposeLegal basis (Art. 6 GDPR)
Providing and operating the service (authentication, project management, change orders)Art. 6(1)(b) — performance of a contract with you
Sending email and SMS notifications about your change ordersArt. 6(1)(b) — performance of a contract
Maintaining notification delivery logs for service reliabilityArt. 6(1)(f) — our legitimate interest in operating a reliable service
Complying with legal obligations and resolving disputesArt. 6(1)(c) — legal obligation / Art. 6(1)(f) — legitimate interest

3. Clients — Data We Hold About You

If a contractor has entered your contact details into Scopit and sent you a change order for approval, we hold data about you. We did not collect this data directly from you — your contractor provided it in the course of their business relationship with you.

Data we hold about clients

  • Your name, email address, and/or phone number (entered by the contractor)
  • Records of approval decisions you made (approved, rejected, or no response)
  • Your IP address at the time you responded to an approval request
  • Timestamps: when you first viewed the approval page, when you responded
  • Any comment you provided when rejecting a change order

Why we process it and on what legal basis

PurposeLegal basis (Art. 6 GDPR)
Sending you the change order approval link by email or SMSArt. 6(1)(f) — legitimate interest of the contractor in managing their project; we act as facilitator
Recording your approval or rejection decisionArt. 6(1)(f) — legitimate interest in creating a reliable audit trail for contractual dispute protection
Recording your IP address and decision timestampArt. 6(1)(f) — legitimate interest in verifying the authenticity of approval decisions and preventing fraud

Legitimate interest balancing: We have assessed that our legitimate interest in maintaining a verifiable audit trail does not override your interests or fundamental rights. The data collected is proportionate (limited to what is necessary for dispute protection), you would reasonably expect an approval link to generate a record of your response, and retaining IP addresses is limited to 2 years. You have the right to object — see Section 7.

4. Waitlist Signups

If you signed up for our waitlist, we hold your name, email address, and trade. We process this on the basis of your consent (Art. 6(1)(a) GDPR) to receive updates about Scopit's launch. You can withdraw consent at any time by emailing support@scopit.co. Withdrawal does not affect the lawfulness of processing before withdrawal.

5. Who We Share Your Data With

We do not sell your personal data. We share data only with the following processors, each under a Data Processing Agreement (DPA):

ProcessorPurposeData sharedLocationTransfer safeguard
SupabaseDatabase, authentication, file storageAll personal data described in this policyEU / US (AWS)DPA with Standard Contractual Clauses
ResendTransactional email deliveryEmail address, name, change order title, approval URLUSDPA with Standard Contractual Clauses
TwilioSMS deliveryPhone number, change order title, approval URLUSDPA with Standard Contractual Clauses

Where data is transferred outside the UK or EEA (e.g., to the US), we rely on the International Data Transfer Agreements (IDTAs) / Standard Contractual Clauses (SCCs) approved by the relevant supervisory authority. Copies of these agreements are available on request from our DPO.

6. How Long We Keep Your Data

DataRetention periodReason
Contractor account & project dataUntil account deletion is requestedNecessary for service provision
Approved/rejected change order records7 years from project completionUK limitation period for contract disputes; tax/accounting records
Client IP address in approval records2 years from decision date, then permanently deletedDispute verification window; data minimisation after that
Unused/expired approval tokens90 days after expiryNo further purpose after expiry
Notification delivery logs1 yearOperational debugging; no long-term need
Waitlist signups12 months, or until consent is withdrawnConsent-based; purpose expires at launch

When a contractor deletes their account, we delete or anonymise all associated data. Where legal retention obligations apply (e.g., approved change order records), contractor identifying information is replaced with "[Deleted User]" and only the financial/approval record is retained.

7. Your Rights

Under the UK GDPR and EU GDPR, you have the following rights. To exercise any of them, contact our DPO at fabien@lerad-ai.com. We will respond within 30 days.

  • Right of access (Art. 15) — Request a copy of the personal data we hold about you. Contractors can export their data directly from Settings → Export my data.
  • Right to rectification (Art. 16) — Request correction of inaccurate or incomplete data.
  • Right to erasure / "right to be forgotten" (Art. 17) — Request deletion of your data. Contractors can delete their account from Settings → Delete my account. Clients should email the DPO. Note: we may retain certain data where legally required (e.g., approved change order records for tax purposes).
  • Right to restriction of processing (Art. 18) — Request that we limit how we use your data while a dispute about its accuracy or lawfulness is resolved.
  • Right to data portability (Art. 20) — Receive your data in a structured, machine-readable format. Contractors can export a full JSON data package from Settings → Export my data.
  • Right to object (Art. 21) — Object to processing based on legitimate interest (Art. 6(1)(f)). We will cease processing unless we can demonstrate compelling legitimate grounds.
  • Right to withdraw consent — Where processing is based on consent (waitlist), you can withdraw at any time by emailing support@scopit.co.
  • Right to lodge a complaint — You have the right to complain to a supervisory authority. In the UK: the Information Commissioner's Office (ICO). In the EU: the supervisory authority in your member state.

8. Cookies

We use only strictly necessary cookies to manage your authenticated session. These cookies are required for the service to function and are exempt from consent requirements under the Privacy and Electronic Communications Regulations (PECR). We do not use analytics, advertising, or tracking cookies. No cookie consent banner is required.

9. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on you (Art. 22 GDPR).

10. Security

We implement appropriate technical and organisational measures to protect your data, including:

  • Encryption in transit (TLS/HTTPS) for all data
  • Row-Level Security (RLS) policies so contractors can only access their own data
  • Cryptographically strong (256-bit) one-time approval tokens with 7-day expiry
  • Secure, httpOnly session cookies for contractor authentication
  • Hardware-backed secure storage for session tokens on mobile devices
  • Rate limiting on all sensitive endpoints

11. Changes to This Policy

We may update this policy from time to time. When we do, we will update the "Last Updated" date at the top of this page and, where changes are material, notify you by email.

12. Contact Us