Skip to main content
Platform Review
PricingSign in
← Scape assessment

Scape procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Scape
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tiersunknown“ security@scape.app Data Protection Officer (DPO): dpo@scape.app”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ Every Sub-processor is bound by DPAs ensuring that Customer Data never leaves the EU, and furthermore AI Sub-processors are bound to strict retention limits: they process Customer Data only to return results, and retain nothing beyond short, time-limited trust and safety windows. Furthermore Scape is certified to SOC 2 Type II and ISO 27001, and our processing of Personal Data complies with the GDPR and relevant Data Protection Laws. We undergo independent third-party audits annually and current certifications and reports are available in the Scape Trust Center. All personnel undergo background checks, sign confidentiality agreements, and complete security training. We run centralized logging, monitoring, and incident-response procedures, and perform regular security reviews and vendor due diligence.”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ Scape is operated from Stockholm, Sweden. We do not transfer Customer Data outside the EU. When you connect a third-party service and direct the assistant to use it, content is exchanged with that service on your instruction. The connected service processes that content under its own terms and privacy policy and may be located outside the EU. Where Analytics Data or Authentication Data (OAuth tokens) is processed by a Sub-processor outside the EEA, UK, or Switzerland (for example, payment or error-monitoring providers), that transfer relies on:”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ If you are in the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local data protection authority, including the Swedish Authority for Privacy Protection (IMY).”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ Analytics Data is retained for up to ninety (90) days unless required by law for longer.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ We may terminate or suspend your account, or any portion of the Services, immediately and without notice if we reasonably believe you have violated these Terms or engaged in fraudulent, abusive, or unlawful activity. We may otherwise terminate your account or discontinue the Services for convenience by providing you with at least thirty (30) days' advance notice. Effect of termination. Upon termination, your right to access the Services ends immediately. For thirty (30) days following termination, you may request an export of Your Content in a commonly used, machine-readable format. We will delete or anonymize Your Content within thirty (30) days of termination, or within ten (10) days of your export request if later, except where retention is required by law or as set out in our DPA. If you request an export, we will provide it before deletion. You remain responsible for all fees and charges incurred up to the date of termination. Provisions that by their nature should survive termination (including intellectual property rights, disclaimers, limitations of liability, indemnification, and governing law) will continue in effect.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersmedium“ We retain Personal Data only as long as necessary to fulfill the purposes outlined in this Policy or as required by applicable law, including to: Provide and improve the Service; Meet legal, regulatory, and accounting obligations;”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersmedium“ Enforce agreements. Audio recordings of meetings are deleted immediately after transcription is complete and are not stored by Scape beyond that point. Meeting transcripts and summaries are retained as part of your Customer Data until you delete your account. Analytics Data is retained for up to 90 days as described in Section 3.6. Content from connected third-party services that appears in your assistant conversations is retained as part of your account data until you delete the conversation or your account. Records of your approvals of actions on connected services are retained for sixty (60) days. When you disconnect a service, we delete the stored credentials for that service; content already part of your conversation history remains until deleted as described above. When you delete your account, we only retain the Covered Data as long as necessary to fulfill the purposes outlined in this Privacy Policy or as required by applicable Data Protection Law. To request account deletion, contact us at security@scape.app . Standard account deletion is free of charge. Where you request manual data export or bespoke deletion work that materially exceeds our standard process and requirements by law, we may charge reasonable, documented costs, except where prohibited by applicable law.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ Payment is processed by Stripe. Stripe collects your voluntarily provided payment-card information necessary to process your payment. We do not store full payment-card numbers. Stripe's use of your information is governed by Stripe's Privacy Policy.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ We may disclose Personal Data when we believe in good faith that disclosure is required to: Comply with a valid legal process or governmental request (for example, a subpoena, court order, or law-enforcement demand); Investigate, prevent, or respond to fraud, security incidents, or other wrongdoing; Protect the rights, property, or safety of Scape, our users, or the public. Unless legally prohibited, we will notify the affected customer before producing Personal Data in response to a legal request. Disclosures will be limited to the minimum necessary and will challenge requests that are unlawful, overbroad, or inconsistent with applicable Data Protection Laws.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ The Services may interoperate with third-party products and services, including your email and calendar providers and other services you choose to connect, such as workspace, project-management, and communication tools ("Third-Party Services"). Each Third-Party Service is governed by that third party's own terms and privacy policy, for which we are not responsible. When you enable an integration, you authorize us to access and transmit Your Content to and from the relevant Third-Party Service as necessary to provide that integration. Any action that creates or changes data in a Third-Party Service is performed only after you approve that specific action. Some integrations connect through open protocols such as the Model Context Protocol ("MCP"); where you configure a custom or unlisted server, you are solely responsible for that server, including its security and its handling of Your Content. We may suspend or disable an integration at any time, including where we believe it poses a security risk. Where the Services access Google user data, our access to, use, and transfer of that data complies with the Google API Services User Data Policy, including its Limited Use requirements, as further described in our Privacy Policy. You may also authorize third-party applications, such as AI assistants, to access your Scape data through Scape's MCP interface. Any such access occurs under a grant you control and can revoke at any time in your settings, and the third-party application's use of Your Content is governed by that application's own terms.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ When you use Scape's meeting features, we collect: During the meeting: audio recordings (microphone and system audio, no video or screen capture) After the meeting: transcripts generated from those recordings, and meeting summaries All audio recordings are deleted after the transcript is generated. Transcription and all related AI processing are performed entirely within the EU. Our transcription and AI Sub-processors process your audio and transcripts solely to return your result, are contractually prohibited from using them to train their models, and do not retain content beyond the processing of your request and any short, time-limited retention a provider requires for trust and safety review.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ Sub-processors are bound by data-protection terms and may only process Personal Data to provide the Service on our behalf. We inform you of any addition or replacement of a Sub-processor by updating our Sub-processor list, available in the Scape Trust Center: https://trust.scape.app/subprocessors . Where we act as your processor, your right to object to a new Sub-processor and the applicable timeline are set out in our DPA.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow“ We share data only as necessary to operate Scape: To Sub-processors and AI Sub-processors for hosting, database, LLM inference, transcription, web search, etc.; Your organization or team, if you use Scape in a team environment. Your administrator may have access to your account-level data and settings; Legal or regulatory authorities, if required by law (see Section 10, Investigations and Legal Disclosures); Business transfers, as described in Section 9 below; With your consent, when you explicitly approve an action. We do not sell your Personal Data, and we do not share it for cross-context behavioral advertising. Our marketing website uses a Google Ads conversion-measurement Cookie only to measure our own ad performance, and only if you accept it via our Cookie banner. We do not share your Customer Data with advertisers.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, or sale of some or all of our assets, your Personal Data may be transferred or disclosed in connection with the transaction, subject to a confidentiality agreement. We will use reasonable efforts to notify you before your Personal Data becomes subject to a different Privacy Policy.”Captured 2026-09-25Open source →Finding permalink →
Tier differencesAll applicable tiersmedium“ You may use the Services under a free or paid plan, as described on the Site. Paid plans are billed in advance on a monthly or annual basis and renew automatically until canceled. Payment is processed by Stripe, our third-party payment processor. By providing payment information, you agree to be bound by Stripe's terms in addition to these Terms. We rely on Stripe's records for payments, invoicing, and account balances, and you agree that those records are authoritative absent manifest error. Subscription fees are non-refundable except where required by law. We may change subscription fees with reasonable advance notice. Fees are exclusive of taxes, and you are responsible for any taxes, duties, or government charges that apply, other than taxes based on our income. To cancel a monthly plan, you may do so at any time through your account or by contacting invoice@scape.app . The cancellation takes effect at the end of the then-current billing period. To cancel an annual plan, you must provide written notice at least thirty (30) days before the renewal date. We may suspend access for non-payment after reasonable notice.”Captured 2026-09-25Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.