GDPR Commitment
Last updated: 26 August 2026
This page summarises how Scopra Ltd (company number 16879091) meets its obligations under UK GDPR and, where applicable, EU GDPR when processing the personal data our customers store in the Scopra platform. It should be read with our Terms & Conditions (which contain our binding processor commitments) and our Privacy Policy (which covers data we control, such as account and website data).
1. Controller and processor roles
Scopra's customers — the consultancies and agencies that run their business on the platform — decide what project, client, timesheet, resourcing, and billing data to store and why. For that data ("Customer Data"), the customer is the controller and Scopra is the processor. For account, billing, and website data, Scopra is the controller (see the Privacy Policy).
2. Our processor commitments
For personal data within Customer Data, we commit to the obligations set out in Article 28 UK GDPR, as incorporated in our Terms. In summary, we:
- process Customer Data only on the customer's documented instructions, as expressed through the Terms and the customer's use of the platform;
- ensure everyone we authorise to access Customer Data is bound by confidentiality;
- apply appropriate technical and organisational security measures (section 4 below);
- engage sub-processors only under contracts imposing materially equivalent obligations, and remain responsible for their performance (section 5);
- assist customers with data subject requests, security, breach notification, and data protection impact assessments, as reasonably required;
- notify the customer without undue delay on becoming aware of a personal data breach affecting Customer Data, with the information needed for the customer's own notification duties; and
- delete or return Customer Data at the end of the agreement: export is available for 30 days after a subscription ends, and Customer Data is deleted from production systems within 90 days thereafter, unless law requires retention.
A signed data processing agreement reflecting these commitments is available on request from [email protected].
3. Supporting data subject rights
Where an individual (for example, a customer's employee or client) exercises UK GDPR rights in respect of Customer Data, the request belongs to the customer as controller. The platform's export, correction, and deletion features let customers action most requests directly; where they cannot, we assist on request within a reasonable time.
If a data subject contacts us directly about Customer Data, we will refer them to the relevant customer and notify that customer, rather than acting on the request ourselves.
4. Security measures
Our measures include:
- Encryption of data in transit (TLS) and at rest;
- Access control — role-based access, least-privilege administration, and multi-factor authentication for administrative access;
- Environment separation between production and non-production systems, with Customer Data not used in development or testing;
- Backups taken regularly and tested, to support recovery from loss or corruption;
- Logging and monitoring of production access and security events;
- Personnel measures — confidentiality obligations and data protection awareness for everyone with access;
- Vulnerability management — dependency and patch management, and a responsible disclosure route published in our security.txt.
We review these measures regularly and strengthen them as the platform and threat landscape evolve.
5. Sub-processors
We use a small number of vetted providers — for hosting and infrastructure, payment processing, email delivery, and support tooling — to run the platform. Each is engaged under a written contract with data protection obligations materially equivalent to our own. A current list, including processing locations, is available on request from [email protected], and customers can ask to be notified of changes so they can raise reasonable objections before a new sub-processor handles their Customer Data.
6. International transfers
We aim to keep Customer Data in the United Kingdom or the European Economic Area. Where any processing takes place outside the UK, it is protected by an adequacy decision or appropriate safeguards — the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses — together with any supplementary measures needed.
7. Breach response
We maintain an incident response process covering identification, containment, assessment, and remediation. If a personal data breach affects Customer Data, we notify the affected customer without undue delay, share what we know as the investigation develops, and support the customer's ICO (or other regulator) notification if one is required.
8. Questions
For our data processing agreement, sub-processor list, security questionnaires, or anything else data-protection related: [email protected], or write to Scopra Ltd, 24 Burford Court, Rances Lane, Wokingham, England, RG40 2LJ.