Skip to main content
Platform Review
PricingSign in
Scenario assessment

Scenario procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Scenario
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow For personal data transferred from the European Economic Area (“EEA”), United Kingdom, and Switzerland to the United States, Scenario relies on the following transfer mechanisms: Data Privacy Framework. Once certified, we will rely on our certification under the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF as described in Section 4. Standard Contractual Clauses (SCCs). Where required, we enter into the European Commission’s Standard Contractual Clauses (as adopted under Implementing Decision 2021/914) with our customers and partners to provide appropriate safeguards for international data transfers. For transfers from the United Kingdom, the International Data Transfer Addendum issued by the UK Information Commissioner supplements the SCCs.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmediumScenario is based in the United States and processes personal data on servers located in the United States (hosted on AWS in US regions). If you are accessing our Services from outside the United States, please be aware that your personal information will be transferred to, stored, and processed in the United States.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Scenario collects and processes personal data from individuals in the European Union, United Kingdom, and Switzerland as described in Section 1 and Section 2 of this Privacy Policy. We may disclose personal information to the categories of third parties and sub-processors described in Section 3 for the purposes stated there. Individuals have the right to access their personal data as described in Section 6. We may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. Upon certification, Scenario’s DPF participation will cover non-human-resources data only.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmedium To the extent that Scenario processes personal data on your behalf in connection with your use of the Platform, the parties may enter into a Data Processing Agreement (“DPA”). Enterprise customers may request a DPA as part of their MSA. For self-service customers, Scenario’s standard DPA (available upon request at privacy@scenario.com . ) applies where required by applicable data protection law.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow When we transfer personal data received under the DPF to third parties, we do so only for the purposes described in this Privacy Policy and under contracts that require the third party to provide the same level of protection as the DPF Principles require. We enter into data processing agreements with our sub-processors that restrict their use, retention, and disclosure of personal data. Scenario remains liable under the DPF Principles if a third party that we have engaged to process personal data on our behalf processes that data in a manner inconsistent with the DPF Principles, unless we can prove that we are not responsible for the event giving rise to the damage.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Scenario Inc. is committed to complying with the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF”) as set forth by the U.S. Department of Commerce. Scenario intends to self-certify under these frameworks; upon certification, our participation will be listed at dataprivacyframework.gov. This Section 4 describes how Scenario adheres to the DPF Principles with regard to the processing of personal data received from the European Union, the United Kingdom (and Gibraltar), and Switzerland. If there is any conflict between the terms in this Privacy Policy and the DPF Principles, the DPF Principles shall govern.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow For complaints concerning personal data transferred from the United Kingdom under the UK Extension to the EU-U.S. DPF, Scenario has committed to cooperate and comply with the advice of the UK Information Commissioner’s Office (“ICO”). This dispute resolution mechanism is provided at no cost to you. Cooperation with the Swiss Federal Data Protection and Information Commissioner (FDPIC) For complaints concerning personal data transferred from Switzerland under the Swiss-U.S. DPF, Scenario has committed to cooperate and comply with the advice of the Swiss Federal Data Protection and Information Commissioner (“FDPIC”). This dispute resolution mechanism is provided at no cost to you.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Scenario commits to resolve complaints about our collection or use of your personal information transferred to the United States pursuant to the applicable DPF. EU, UK, and Swiss individuals with inquiries or complaints regarding this Privacy Policy should first contact Scenario at privacy@scenario.com .Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow If you are located in the European Economic Area (“EEA”), the United Kingdom, or Switzerland, the following additional provisions apply to our processing of your personal data under the General Data Protection Regulation (“GDPR”) and equivalent UK and Swiss legislation.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow When we transfer personal data to sub-processors located outside the EEA, UK, or Switzerland, we ensure that appropriate safeguards are in place through contractual protections requiring the sub-processor to protect personal data to a standard consistent with the DPF Principles and applicable data protection law.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Scenario is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (“FTC”). The FTC has jurisdiction over Scenario’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Scenario Inc. is the data controller for personal data we collect directly from you (e.g., account information, usage data). When we process personal data on behalf of our enterprise customers, we act as a data processor under our Data Processing Agreement with the customer.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Trust Center: trust.scenario.com . This Privacy Policy is effective as of February 23, 2026.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmediumYour Content and Generated Assets are stored in cloud infrastructure located in the United States unless otherwise specified in your plan or MSA. By using the Platform, you consent to the transfer and processing of your data in the United States, subject to Scenario’s compliance with applicable data protection laws.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Pursuant to Article 27 of the GDPR, Scenario has appointed the following representative in the European Union for data protection matters: DataRep — The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland. Email: scenario@datarep.com. Online request: www.datarep.com/data-requestCaptured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Scenario is SOC 2 Type II certified, demonstrating our commitment to maintaining rigorous security controls. Our current SOC 2 Type II audit report is available through our Trust Center at trust.scenario.com. We implement and maintain appropriate technical and organizational measures to protect your personal information, including: Encryption in Transit. All data transmitted between clients and Scenario’s systems is encrypted using TLS 1.2 or higher. Encryption at Rest. Personal data stored by Scenario is encrypted at rest using AES-256 encryption. Access Controls. Role-based access controls limit access to personal data to authorized personnel on a need-to-know basis. Multi-factor authentication is required for administrative and privileged access to production systems. Infrastructure Security. All production systems are hosted on Amazon Web Services (AWS) infrastructure in US regions. AWS data centers maintain ISO 27001, SOC 1, SOC 2 Type II, and SOC 3 certifications. Workspace Isolation. Each customer’s workspace is logically isolated from other customers’ workspaces within the platform. Monitoring and Logging. Access and activity logs are maintained for systems processing personal data. Vulnerability Management. Regular vulnerability scanning and penetration testing of production systems. Incident Response. Documented security incident response and escalation procedures. While we implement industry-standard security measures, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security of your data.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Personal data transferred from the EEA, UK, or Switzerland to Scenario in the United States is protected by the transfer mechanisms described in Section 5, including Standard Contractual Clauses and, once certified, our DPF certification.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow If we are unable to resolve your complaint directly, Scenario has committed to cooperate and comply with the advice of the panel established by the EU data protection authorities (“DPAs”) with regard to unresolved complaints concerning personal data transferred from the EU under the EU-U.S. DPF. This independent dispute resolution mechanism is provided at no cost to you.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersmedium We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including to provide our Services, comply with legal obligations, resolve disputes, and enforce our agreements. Specifically: Account Data. Retained for the duration of your account and for 90 days thereafter to allow for account reactivation, after which it is deleted unless retention is required by applicable law. Usage Data. Retained in identifiable form for up to 24 months, after which it is aggregated or deleted. Aggregated or pseudonymized usage data may be retained indefinitely for analytics purposes. Payment Data. Transaction records retained as required by tax and financial regulations (typically 7 years). Full payment card details are not stored by Scenario — they are handled by Stripe. Generated Content. Your generated assets, prompts, and related content are retained in your account for as long as your account is active, and deleted within 60 days after account termination, unless otherwise required by law or agreed upon with enterprise customers. Support Communications. Retained for up to 24 months after the support case is closed to provide continuity and improve our support quality, after which they are deleted or anonymized. When personal data is no longer needed, we securely delete or anonymize it in accordance with our data retention and deletion procedures.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersmedium During the thirty (30) day post-termination period, you may export Your Content and Generated Assets through the Platform’s standard export tools or by contacting support@scenario.com . Scenario is not obligated to maintain or provide your data after this period.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tierslow Upon termination of your account: Your license to access and use the Platform terminates immediately; Scenario will make Your Content and Generated Assets available for export for a period of thirty (30) days following the effective date of termination, after which Scenario may permanently delete your data; You remain liable for any outstanding fees or obligations incurred prior to termination; Sections of these Terms that by their nature should survive termination will survive, including but not limited to Sections 4 (Intellectual Property), 10 (Disclaimers), 11 (Limitation of Liability), 12 (Indemnification), 15 (Governing Law), and 16 (General Provisions).Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tierslowSupport Communications. Retained for up to 24 months after the support case is closed to provide continuity and improve our support quality, after which they are deleted or anonymized.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersmedium Scenario limits the personal data we collect and process to what is relevant for the purposes of processing. We do not process personal data in a way that is incompatible with the purposes for which it was collected or subsequently authorized by the individual. We take reasonable steps to ensure that personal data is reliable for its intended use, accurate, complete, and current. We retain personal data in a form that identifies or renders an individual identifiable only for as long as it serves the purpose(s) for which it was collected or subsequently authorized, consistent with the DPF Principles.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow We do not sell your personal information. We share personal information only in the following circumstances:Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Infrastructure & Hosting Amazon Web Services (AWS) Cloud infrastructure, hosting, storage, and compute Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium We may receive information about you from third-party services you use to interact with our platform (e.g., identity providers for single sign-on) or from publicly available sources.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow We may share your personal information with third parties when you have given us your explicit consent to do so.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium We may disclose your personal information if required to do so by law, or if we believe in good faith that such disclosure is necessary to: (a) comply with a legal obligation, court order, or lawful request by public authorities, including to meet national security or law enforcement requirements; (b) protect and defend our rights or property; (c) prevent or investigate possible wrongdoing; or (d) protect the personal safety of users or the public.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow We engage third-party service providers to perform functions on our behalf. These providers process personal information only as necessary to provide their services to us, under contracts that require them to protect your information consistent with this Privacy Policy and applicable law. Our current sub-processors include:Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow A current list of our sub-processors is maintained at trust.scenario.com. We notify customers of changes to our sub-processor list in accordance with our Data Processing Agreement.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium AI Model Providers Fal, Replicate, Meshy, Tencent Cloud, Vidu, Freepik, Hitem3D, Photoroom AI asset generation capabilities Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow When Scenario processes personal data on behalf of our enterprise customers, we act as a “service provider” under the CCPA. In that capacity, we process personal information solely on behalf of and under the instructions of the business customer, and we do not sell or share such personal information.Captured 2026-06-07Open source →Finding permalink →
Tier differencesFreemediumScenario reserves the right to impose additional restrictions on Free Tier accounts, including but not limited to rate limits, feature restrictions, and content retention limits.Captured 2026-06-07Open source →Finding permalink →
Tier differencesFreelowFree Tier: A limited plan that provides a daily allocation of Compute Units at no charge. The Free Tier is subject to usage limits, feature restrictions, and fair use policies as described on our pricing page.Captured 2026-06-07Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.