ScopePilot logo

GDPR Art. 28

Sub-processors

This page lists every vendor ScopePilot engages to process customer personal data, the purpose of that processing, where they host, and the safeguards in place for any transfer outside the EEA. Each provider is bound by a Data Processing Agreement (DPA) and, where applicable, the European Commission's Standard Contractual Clauses.

Last updated: 29 June 2026.

Core sub-processors

Engaged for every ScopePilot customer to deliver the core service.

ProviderPurposeData processedHosting regionTransfer mechanismLegal
Supabase, Inc.Primary database, authentication, file storage, realtimeAccount data, briefs, proposals, uploads, auth tokensEU (Ireland, eu-west-1)Data stays in EU — no international transfer for primary storage
Cloudflare, Inc.CDN, edge runtime (Workers), DDoS protection, DNSHTTP request metadata, IP address, response cacheGlobal edge networkSCCs (EU Commission Module 2) + DPA
Lovable ABApplication hosting platform and deploymentApplication bundles, environment configurationEU / USSCCs + DPA
Paddle.com Market LimitedMerchant of Record — payments, subscriptions, tax, invoicingBilling name, email, address, payment method, invoicesUK / EU / USSCCs + DPA. Paddle acts as independent controller for billing data.
Resend, Inc.Transactional email delivery (auth, brief-ready, invites)Recipient email, subject, message body, delivery metadataEU / USSCCs + DPA
Google LLC (Gemini API)AI generation for briefs, proposals, and add-onsPrompt content derived from project inputsEU endpoint where available, otherwise USSCCs + DPA via Google Cloud. Prompts and outputs are NOT used to train Google models.

Optional sub-processors (customer-initiated integrations)

Engaged only if you connect the corresponding integration from Settings. Data is only sent to these providers for the export actions you trigger.

ProviderPurposeData processedHosting regionTransfer mechanismLegal
Notion Labs, Inc.Export briefs/proposals to a customer-connected Notion workspaceOAuth token, page IDs, brief content the customer chooses to exportUSSCCs + DPA
Google LLC (Drive API)Export briefs/proposals to a customer-connected Google DriveOAuth token, exported document contentEU / USSCCs + DPA
HubSpot, Inc.Push project/brief data to a customer-connected HubSpot CRMAPI token, contact/deal payloads the customer chooses to syncEU / USSCCs + DPA
monday.com Ltd.Push project data to a customer-connected monday.com boardAPI token, board/item payloadsEU / USSCCs + DPA
Atlassian (Trello)Push project data to a customer-connected Trello boardAPI token, board/card payloadsEU / USSCCs + DPA
ClickUp (Mango Technologies, Inc.)Push project data to a customer-connected ClickUp workspaceAPI token, task/list payloadsUSSCCs + DPA

Analytics & cookies

ScopePilot does not load third-party analytics or tracking scripts until a visitor opts in via the cookie banner. When analytics providers are enabled they will be added to the list above with the same disclosures. See our privacy policy for cookie details.

Change notifications

We notify customers by email at least 30 days before adding or replacing a sub-processor that handles customer personal data. To subscribe to change notices or request our counter-signed DPA, email privacy@scopepilot.ie.

This page is maintained by the ScopePilot team to answer common privacy and processing questions. It is not a regulatory certification — for legal advice, consult your DPO or counsel.