Privacy Notice

Last updated: 1 August 2026

Alessandro Pappagallo operates ScopeGuard and acts as the data controller for the personal data described below.

1. Who we are

Alessandro Pappagallo decides how and why personal data is processed in ScopeGuard and is therefore the data controller. You can reach us at scopeguardlive@gmail.com.

2. What we collect and why

  • Account data (email address, sign-in identifiers, authentication provider) — to create and secure your account. Legal basis: performance of a contract.
  • Firm settings (firm name, currency, hourly rate, buffer, minimum fee) — to generate your estimates and scope documents. Legal basis: performance of a contract.
  • Quote and scope content you enter, including client names you type — to provide the core service. Legal basis: performance of a contract.
  • Support chat messages — to answer your questions and improve help content. Legal basis: legitimate interests.
  • Usage and technical data (device type, browser, IP address, error logs) — for security, fraud prevention, debugging and product improvement. Legal basis: legitimate interests.
  • Subscription status and payment metadata received from our Merchant of Record — to grant plan access and keep billing records. Legal basis: contract and legal obligation.

We do not require you to upload documents or bank files, and we do not send marketing email unless you separately ask for it.

3. Client names you enter

Quotes may include the name of your own client. You are responsible for having a lawful basis to enter that information; we process it on your instructions to provide the service.

4. Who we share data with

  • Hosting, database and authentication providers that run the application infrastructure.
  • Paddle, our Merchant of Record, for sale of subscriptions, payments, tax compliance, invoicing and subscription management.
  • Our AI provider, which processes support chat messages to generate answers.
  • Professional advisers (legal, accounting) where necessary.
  • Authorities, where required by law.

We do not sell personal data.

5. International transfers

Some providers may process data outside the UK/EEA. Where that happens we rely on adequacy decisions or Standard Contractual Clauses as appropriate safeguards.

6. Retention

Account, quote and scope data is retained while your account is active and for a limited period afterwards so you can reactivate or export it. Support chat history is retained while the account is active. Billing records are kept as long as tax and accounting law requires. After those periods data is deleted or anonymised.

7. Your rights

Depending on where you live, you may have the right to access, rectify, erase, restrict or port your data, to object to processing, and to withdraw consent. You can also complain to your supervisory authority. Write to scopeguardlive@gmail.com; we aim to respond within one month.

8. Security

We apply appropriate technical and organisational measures, including encryption in transit, row-level access controls so each account can only read its own records, and restricted administrative access.

9. Cookies and local storage

We use strictly necessary cookies and browser storage to keep you signed in, remember your language choice and autosave wizard drafts on your device. We do not use advertising cookies. You can clear this data through your browser settings, though the app may stop working correctly without it.