ScopePilot logo
← Back to home

Privacy Notice

Last updated: 7/30/2026

1. Who we are

ScopePilot is a product operated by NovaPath Digital. NovaPath Digital is the data controller for all personal data processed through ScopePilot.

2. Data we collect

  • Account data: name, email, login credentials, agency name and logo.
  • Project data: client names, project types, brief answers and generated briefs you create.
  • Communications: support messages and email preferences.
  • Usage data: pages viewed, features used, device and browser info, IP address, approximate location.
  • Cookies: essential cookies for authentication and session, optional analytics cookies.

3. How we use it

  • To create your account and provide the service (legal basis: contract).
  • To generate briefs via AI providers on your behalf (legal basis: contract).
  • To send transactional emails about your account and briefs (legal basis: contract).
  • To secure the service, prevent fraud, and debug issues (legal basis: legitimate interests).
  • To improve the product and understand usage in aggregate (legal basis: legitimate interests).
  • To comply with legal obligations (legal basis: legal obligation).

4. Who we share data with (sub-processors)

We use the following sub-processors to operate ScopePilot. Each is bound by a Data Processing Agreement and, where data leaves the EEA, by Standard Contractual Clauses.

  • Supabase (EU/Ireland) — database, authentication, file storage.
  • Cloudflare (global edge) — CDN, edge runtime, DDoS protection.
  • Paddle (UK/EU/US) — Merchant of Record for payments, subscription management, tax, and invoicing. Paddle is an independent controller for billing data.
  • Resend (EU/US) — transactional email delivery.
  • Google (Gemini API) (EU endpoint where available, otherwise US) — AI brief & proposal generation. Prompts and outputs are not used to train models.
  • Lovable (EU/US) — hosting platform and deployment.

An always-current list lives on our Security page. We notify customers by email at least 30 days before adding or replacing a sub-processor.

We may also share data with professional advisers (legal, accounting) and with authorities when required by law.

5. International transfers

Customer content (briefs, proposals, files, account data) is stored on EU-region infrastructure. Where a sub-processor above operates outside the EEA (e.g. Cloudflare edge nodes, Resend US region, Google US fallback), transfers rely on the European Commission's Standard Contractual Clauses (Module 2 / Module 3 as appropriate) together with technical safeguards (encryption in transit and at rest). A Transfer Impact Assessment is available on request.

6. Retention

We keep personal data for as long as your account is active and as needed to provide the service. After account closure we permanently delete or anonymize your data within 30 days, except where retention is required by law (e.g. tax records).

7. Your rights

Depending on your location, you may have the right to access, rectify, erase, restrict, or port your personal data, to object to processing, and to withdraw consent. You may also complain to a supervisory authority. We respond to requests within the timeframes required by applicable law (typically one month under GDPR/UK GDPR).

8. Security

We use appropriate technical and organizational measures including encryption in transit, access controls, and least-privilege principles. No system is perfectly secure; please use a strong unique password.

9. Cookies

We use essential cookies required for authentication and session. We may use analytics cookies to understand usage; you can manage cookies through your browser settings.

10. Contact

For privacy questions or to exercise your rights, contact ScopePilot at hello@scopepilot.ie.