Privacy Policy

Last updated: 26 August 2026

This privacy policy explains how Scopra Ltd (company number 16879091, registered office 24 Burford Court, Rances Lane, Wokingham, England, RG40 2LJ — "Scopra", "we", "us") collects and uses personal data when you visit our websites, register for or use the Scopra platform, or communicate with us. Questions and requests: [email protected].

1. The two roles we play

We are the controller of personal data about visitors to our websites, people who register or hold accounts, billing contacts, and people who contact us. This policy covers that data.

We are a processor of personal data contained in the project, client, timesheet, resourcing, and billing records our customers store in the Scopra platform ("Customer Data"). For that data, our customer is the controller and its own privacy notices apply; we process it only under our Terms & Conditions and as described in our GDPR commitment. If you are an employee or client of a Scopra customer and have questions about data held in their workspace, please contact that organisation.

2. Personal data we collect

  • Account and registration data — name, work email address, company name, role, password (stored hashed), and workspace settings.
  • Billing data — billing contact details, subscription and invoice history, and VAT details. Card payments are handled by our payment processor; we do not store full card numbers.
  • Usage data — log and device information generated when you use the platform (IP address, browser type, pages and features used, timestamps), used for security, support, and service improvement.
  • Communications — messages you send us, including support requests and sales enquiries.
  • Website analytics — our marketing website uses Plausible, a privacy-focused analytics service that does not use cookies and does not track individuals across sites. We see aggregate page statistics only.

We do not intentionally collect special category data, and the Service is not directed at children: it is for business use by people aged 18 or over.

3. Why we use it and our lawful bases

Purpose Lawful basis
Providing the platform, managing accounts and subscriptions Performance of a contract
Billing, accounting, and tax records Legal obligation; contract
Security, fraud prevention, and service integrity Legitimate interests
Support and responding to enquiries Contract; legitimate interests
Improving the Service using aggregate usage information Legitimate interests
Service emails (billing, security, material changes) Contract; legal obligation
Marketing emails about Scopra Consent, or legitimate interests for existing customers with an opt-out in every message

Where we rely on legitimate interests, we have balanced those interests against your rights and will not use your data where our interests are overridden by them.

4. Who we share it with

  • Service providers (sub-processors) — hosting, infrastructure, email delivery, payment processing, and support tooling providers who process data on our instructions under contract. A current list is available on request from [email protected].
  • Professional advisers — accountants, insurers, and lawyers where reasonably necessary.
  • Authorities — where required by law, regulation, or court order.
  • Business transfers — a buyer or prospective buyer in connection with a sale, merger, or reorganisation of our business, under confidentiality obligations.

We do not sell personal data.

5. International transfers

We aim to keep personal data in the United Kingdom or the European Economic Area. Where a provider processes data outside the UK, we rely on an adequacy decision or appropriate safeguards such as the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses.

6. How long we keep it

  • Account data: for the life of the account and up to 12 months after closure, except where a longer period is required for the purposes below.
  • Billing and tax records: 6 years, as required by UK law.
  • Support communications: up to 24 months after resolution.
  • Customer Data: retained per our Terms — export is available for 30 days after your subscription ends, and Customer Data is deleted from production systems within 90 days thereafter, except where law requires retention.

7. Security

We use appropriate technical and organisational measures to protect personal data, including encryption of data in transit, access controls and least-privilege administration, environment separation, and regular backups. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you and the regulator where the law requires.

8. Your rights

Under UK GDPR you have rights to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing is based on consent. To exercise any right, email [email protected]; we respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk), though we would welcome the chance to resolve any concern first.

9. Cookies

Our marketing website does not use advertising or cross-site tracking cookies; analytics are cookieless (see section 2). The Scopra platform uses strictly necessary cookies to keep you signed in and secure. If we introduce non-essential cookies in future, we will ask for consent first.

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email or in-app notice. The "Last updated" date at the top shows the current version.