Privacy Policy

This Privacy Policy explains how Scopeward handles personal data when you use the website, assessment, checkout and workspace.

Scopeward · scopeward.eu · app.scopeward.eu · Version 1.0 · Last updated: 12 September 2026

Effective date: 12 September 2026

Data controller and operator: J. B. Nielsen T., trading as Scopeward · Vestaveien, 1476 Rasta, Norway

Privacy requests: privacy@scopeward.eu. You can also use hello@scopeward.eu.

1. Our role

We control processing for accounts, public-site operation, paid access, security, support and our legal duties.

For personal data in your organisation's workspace, we act on its instructions as processor, or subprocessor if it acts for someone else. It chooses the purposes and lawful basis. Section 5 of the Terms of Service contains the processing terms.

Paddle is an independent controller for its sale and payment processing. Its Privacy Policy applies to that processing. We never receive card details.

2. Information and purposes

InformationSource and purpose
Email address, organisation name, declared use and account preferencesSupplied by you for sign-in, administration and service emails. No passwords are used.
Time and version of terms acceptanceCreated at checkout to record which terms were accepted.
Marketing email choice, choice time, policy version and withdrawal timeSupplied by you at checkout and in account settings. It is optional and does not affect a purchase.
Assessment answers, product description and versioned resultSupplied by you and generated by the service to run and save the assessment. Anonymous unpurchased assessments use an unguessable access link.
Purchase and subscription references, amount, status and paid-until dateReceived from Paddle to manage access, cancellations, refunds and disputes.
Product facts, obligations, notes, drafts, evidence, incident timelines and release recordsSupplied by you to provide the workspace. Release captures and print snapshots preserve selected record metadata at a point in time. Evidence bytes are stored outside the database on the server's disk.
Public status-pack settings and aggregate view countSupplied or enabled by the workspace owner to publish the selected product records at an unguessable URL. Successful ordinary page views increment one aggregate count; no visitor identity or per-view record is stored.
SBOM component names, versions and package URLsSupplied by upload or CI submission for vulnerability matching. Source code is never uploaded or read.
Vulnerability reports and optional reporter contact detailsSubmitted by third-party reporters through your intake form for your organisation to handle. An acknowledgement is sent.
Audit events: time, actor, action and detailsCreated as a signed workspace history. The actor can be your email address or a system role.
Hashed sign-in, session and email-change tokensCreated for authentication.
Rate-limit keys and server access logsDevice and request information used for operation and abuse prevention. Access logs include IP address, URL, time and browser information. Rate-limit keys can include IP addresses, emails or assessment references. The vulnerability-report form hashes reporter IP addresses.
Checkout-interest emailSupplied by you for a one-time notification when checkout opens.
Support and privacy correspondenceYour email, message, attachments and our response, used to handle and document your request.
Optional product researchWith your permission, result, sample, comparison and checkout events are linked to a completed purchase using a random tab identifier and a SHA-256 assessment reference. These records are pseudonymous, not anonymous. They contain no answers, email, raw assessment access link, IP address, browser details or uploaded content. Separately, we count SBOM rejection categories and voluntarily submitted colleague-role categories without account or workspace identifiers.

Business records can contain other people's personal data. Supply only what is needed. Do not upload secrets, unrelated personal data, special-category data such as health information, or criminal-offence data.

No language model is used in the service. The classification engine applies a versioned ruleset without network calls, randomness or a current-clock lookup. Outputs concern products, not decisions about individuals. Nobody checks customers' answers as an assessment service.

Processing we controlGDPR Article 6 basis
Accounts, sign-in, paid access, service emails and routine supportContract, Article 6(1)(b), where you personally contract with us; otherwise legitimate interests, Article 6(1)(f), in serving your organisation.
Acceptance records, security, abuse prevention and necessary diagnosticsLegitimate interests, Article 6(1)(f), in documenting agreements and protecting the service.
Privacy requests and legally required financial recordsLegal obligation, Article 6(1)(c).
Minimal record of completed privacy requests or a specific legal claimLegitimate interests, Article 6(1)(f), in documenting our response or establishing and defending the claim.
Requested checkout-opening notificationPre-contract steps at your request, Article 6(1)(b).
Optional CRA guidance and product-update emailsConsent, Article 6(1)(a). You may withdraw it at any time without affecting the earlier processing.

We consider necessity and people's rights when relying on legitimate interests. You can object. Your organisation determines the lawful basis for personal data we process on its instructions.

Optional page-to-purchase measurement relies on your consent and is disabled until you choose Allow measurement. You can withdraw and delete that journey using the on-page control. We use non-identifying SBOM rejection counts and voluntary role-category feedback to improve the service. No colleague is contacted; no free-text role or email is collected.

4. Providers and destinations

Provider or recipientWhat it handlesLocation
ScalewayApplication, database and evidence disk. Processor or subprocessor, depending on the data.Paris, France
Scaleway Object StorageDatabase and evidence backups encrypted on our server before upload. Processor or subprocessor.Paris, France
Scaleway Transactional Email (TEM)Application emails: addresses, subject, message content, delivery information and technical logs. Processor or subprocessor. Alerts and reminders carry no product, component or vulnerability detail; weekly summaries carry counts only.Paris, France
Proton MailContact mailboxes, including hello@scopeward.eu and privacy@scopeward.eu, correspondence, attachments and mail metadata. Processor or subprocessor.Switzerland, Germany or Norway, under Proton's published policy
PaddlePayment and billing as independent controller. We send item/price details and an internal purchase reference; Paddle returns buyer email and purchase status.See Paddle's Privacy Policy

Public vulnerability-data sources

These sources supply public datasets for matching on our Paris server. They do not receive customer workspace content or act as workspace-data subprocessors in this configuration.

SourceData flowSource location
OSV public data, downloaded from Google-hosted storageScheduled public dataset downloads. No customer SBOM, package URL, version, account, organisation, product or workspace identifier is sent. The download host receives our server's IP address and ordinary request metadata.US-based service; downloads are not a promise of EEA-only routing or logging.
CISA Known Exploited Vulnerabilities catalogueScheduled download of the public catalogue. No customer content or customer-specific query is sent. The download host receives our server's IP address and ordinary request metadata.US government source; downloads are not a promise of EEA-only routing or logging.

Website certificates

The checked-in deployment uses Caddy to request and renew HTTPS certificates automatically through ACME. Certificate issuance and renewal disclose our domain names and ordinary technical connection records to the active certificate authority. Public certificates are recorded in Certificate Transparency logs and can be accessed worldwide. We do not send customer workspace content to the certificate authority.

The certificate authority receives the public domain names and ordinary connection information needed to issue and renew certificates. The active issuer is identified in the public certificate presented by the website.

Network recipients can see our server's connection information. Email delivery also involves the recipient's chosen mail provider.

The public site can load Plausible page-view analytics only when the operator explicitly configures it; the signed-in application never loads it. The repository configures no external error-reporting service. New processing providers will be disclosed before use, with any required notice and authorisation.

Evidence: File bytes stay on the application server's disk during normal use and are served to the signed-in workspace owner. Encrypted backups include them. This is not a statement that infrastructure providers hold no copies.

Local vulnerability matching: Customer package identifiers and versions are compared with the downloaded datasets on our application server in Paris. Matching does not contact OSV, CISA or another external package-query service, including when a local match is unavailable. Private package identifiers can still be sensitive: supply only what is needed and do not include secrets or unrelated personal data. Public-dataset downloads are independent of customers' uploads, subscriptions and scan results.

Access and legal requests: Authorised operator access is limited to operation, security, requested support or legal duties. The incident feature files nothing with authorities. This does not prevent a disclosure required by binding law.

5. International transfers

Primary application storage is in Paris. Our operator is in Norway. Proton's published mail locations include Switzerland, which has an EU adequacy decision.

Local vulnerability matching does not transfer customer SBOMs or package identifiers to OSV or CISA. Downloading their public datasets still exposes our server's connection metadata to the download hosts. Public certificate records are distributed internationally. We do not claim that every provider, network route or item of metadata remains within the EEA.

Where a provider processes personal data outside the EEA, we use an applicable adequacy decision or the provider's contractual transfer safeguards, together with additional safeguards where required. Contact the privacy address for the safeguard relevant to a particular provider.

Contact the privacy address for information about applicable safeguards. Paddle controls its own payment-related transfers.

6. Retention and deletion

DataRetention
Anonymous, unpurchased assessmentsDeleted 30 days after creation.
Purchased assessments, workspaces, evidence, incident records, SBOM data, vulnerability reports and audit eventsRetained while you keep the workspace, including read-only access. A deletion request disables access immediately and provides a 14-day restoration period. Live workspace content is then deleted within 30 days, except for the limited records described below.
Account profileKept while the account exists. A deletion request disables the account immediately and provides a 14-day restoration period. Profile data is then deleted or anonymised within 30 days, except where a limited record must be retained for an identified legal purpose.
Acceptance, organisation declarations and purchase recordsKept for five years after the end of the financial year in which the transaction occurred, where needed for accounting, tax, contract or dispute records. A specific legal claim or authority instruction may require a longer, documented hold. Workspace content is not retained merely because a purchase record must be kept.
Authentication dataSign-in links expire after 15 minutes, email-change tokens after 24 hours and sessions after 30 days. A scheduled job deletes expired records.
Rate-limit recordsDeleted after 24 hours.
Access logsRotated at least daily and deleted after no more than 90 days, unless a specific security incident requires a shorter isolated extract to be retained for investigation. Public status-pack requests are excluded from access logs.
Checkout-interest emailsDeleted after 365 days. The address is used only for the requested checkout-availability message unless separate marketing consent is recorded.
Marketing email consentKept until withdrawal. A minimal withdrawal record is retained with the purchase record under the agreement-record period selected below.
Public status-pack aggregate countKept with the workspace until the workspace deletion schedule applies. Disabling or rotating the link does not reset the count.
BackupsEncrypted backups use 14 daily, 8 weekly and 12 monthly snapshots. Deleted live data can remain in restricted backups for up to 12 months and is not restored to ordinary use.
TEM message content, delivery logs and blocked-address recordsMessage content is retained only for delivery processing. Delivery logs and blocked-address records follow Scaleway's applicable service retention and are removed when no longer needed for delivery, abuse prevention or a legal obligation.
Routine support correspondence in ProtonDelete within 12 months after resolution. Keep only separately necessary records of an identified legal duty or claim.
Privacy-request correspondenceRemove unnecessary content and identity-verification material on completion. Keep a minimal record of the request, dates, decision and response for three years after completion, then delete it unless a specific legal hold applies.
Product-research eventsDeleted from the live database after 90 days, or earlier for linked journey events when you use Stop measurement and delete this journey. A withdrawal marker is retained for up to 90 days to prevent delayed events from recreating a deleted journey. Unlinked rejection and role-category counts cannot be retrieved by account. Restricted backups follow the backup schedule above.

These periods are maximums unless a shorter period is required by law or the information is no longer needed for its stated purpose.

A signed, append-only audit trail is not exempt from erasure. Workspace deletion must include it. Adding a correction does not erase personal data in the original entry. Recovery windows must not delay an erasure or deletion instruction requiring earlier action.

Backups awaiting expiry must remain outside ordinary use. Before restoring service from a backup, apply relevant deletions and expiry decisions, including those made after the snapshot.

A legal hold must be limited to necessary records, documented and reviewed. Delete the records when its reason ends. Cancelling Paddle billing and deleting an account are separate actions. Paddle retains its own purchase records independently.

7. Security

The described controls include row-level tenant isolation, HTTPS, single-use emailed sign-in links with hashed tokens, owner-only evidence access and an Ed25519-signed, hash-chained workspace audit trail. Backup files are encrypted before upload when the backup process is deployed.

The deployed infrastructure places Docker data, including the database and evidence volume, on a LUKS2-encrypted host volume. A signature does not establish that an entry is true. Report security concerns through our security disclosure page or hello@scopeward.eu.

8. Your rights

Depending on the circumstances, you can request access, correction, erasure, restriction or portability. You can object to legitimate-interest processing. Where consent applies, you can withdraw it without affecting earlier lawful processing.

Write to privacy@scopeward.eu, or hello@scopeward.eu as a fallback. We may request necessary identity verification. We respond within one month; if a lawful extension is needed, we explain it within that month. Rights have conditions and exceptions.

For data controlled by your organisation, contact it; we assist under the processing terms. For Paddle-controlled information, contact Paddle.

You can complain to Datatilsynet in Norway, or another competent EEA authority, including where you live, work or an alleged infringement occurred.

Email is needed to sign in; answers are needed for a result. Omitting workspace content limits its corresponding feature.

9. Cookies and updates

The signed-in application uses the necessary cra_session cookie, marked HttpOnly, Secure and SameSite=Lax, for up to 30 days. The public site uses no tracking cookies. Optional Plausible page-view analytics can run only when explicitly configured and does not run in the signed-in application. Public status-pack routes are excluded from Caddy access logs and store only an aggregate successful-view count. In-progress quiz answers use browser session storage. Paddle's checkout has its own cookie and privacy information.

When optional product research is enabled, your choice is stored for the browser tab in session storage. Only after you opt in do we store a random tab identifier and hashed assessment reference there. The research log stays on our existing application database; no additional analytics provider receives it. Consent applies to this tab and does not carry across devices. Ordinary operational access logs remain separate.

Published revisions identify a version and effective date. Material changes receive 30 days' email notice. Changes to subprocessors also follow the processing terms. A policy update is not consent to a new purpose.

Privacy Policy