Legal
Data Processing Agreement
How Avouro LLC processes personal data in your Scopebond workspace on your behalf, wherever your workspace is.
Version 2026-10-11 · Effective 11 October 2026
This Data Processing Agreement ("DPA") is between Avouro LLC, a Michigan limited liability company, USA ("Avouro"), and the organization that creates or owns a Scopebond Cloud workspace (the "Customer"). It forms part of the agreement under which the Customer uses Scopebond Cloud: our Terms of Service, or a signed order form or Enterprise agreement (the "Agreement"). It applies to every workspace, in every region, whenever Avouro processes Customer Personal Data to provide the Service. The Customer accepts this DPA when it creates a workspace, when it accepts this DPA in the product, or when it signs it.
1. Definitions and roles
- Data Protection Laws means the laws that apply to the processing of Customer Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection of 25 September 2020 ("revFADP"), and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").
- Customer Personal Data means personal data in the content of a Customer workspace that Avouro processes on the Customer's behalf: the records the Customer's agents and computers send, the workspace's members, rules, settings, approvals and audit log, and anything else described in Annex I.
- Service means Scopebond Cloud as described in the Agreement.
- Sub-processor means a third party that Avouro engages to process Customer Personal Data.
- SCCs means the standard contractual clauses for the transfer of personal data to third countries adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- Region means the region a workspace is created in: the United States or, when Avouro offers it, the European Union.
- Terms such as "controller", "processor", "data subject", "personal data", "processing", "personal data breach" and "supervisory authority" have the meanings given in the GDPR.
The Customer is the controller of Customer Personal Data, or a processor acting for its own controller. Avouro is the Customer's processor, or its sub-processor where the Customer is itself a processor. Avouro is a controller for its own account, billing, website and support data; our Privacy Policy covers that processing, and this DPA does not.
2. Scope and instructions
- Avouro processes Customer Personal Data only on the Customer's documented instructions, including for transfers to a third country, unless the law to which Avouro is subject requires otherwise. In that case Avouro tells the Customer of that legal requirement before processing, unless that law prohibits it.
- The Customer's instructions are the Agreement, this DPA and the Customer's use and configuration of the Service: the region it chooses, its rules, the evidence detail level, parameter masking, retention, alert destinations, exports, members and roles, and deletion. Further instructions must be in writing and consistent with the Agreement.
- Avouro tells the Customer promptly if, in its opinion, an instruction infringes Data Protection Laws.
- The subject matter, duration, nature and purpose of the processing, and the types of personal data and categories of data subjects, are set out in Annex I.
- Alerts and exports go where the Customer points them, such as Slack or a webhook. Sending them there is the Customer's instruction; those recipients are not Avouro's Sub-processors.
3. Confidentiality
Avouro ensures that every person it authorizes to process Customer Personal Data is bound by an obligation of confidentiality, by contract or by law, and processes it only as needed to provide, secure and support the Service.
4. Security
- Avouro implements and maintains the technical and organizational measures in Annex II, which are designed to give a level of security appropriate to the risk, as Article 32 GDPR requires.
- Avouro may update those measures as technology and risks change, provided the update does not lower the overall security of the Service.
- The Customer is responsible for its own use of the Service: its sign-in methods, who it invites and in what role, its rules, what its agents send, and the security of its own computers and integrations.
5. Sub-processors
- General authorization. The Customer gives Avouro general written authorization to engage Sub-processors. The Sub-processors in use are those listed in Annex III.
- Notice of changes. Avouro gives at least 30 days' notice before adding or replacing a Sub-processor. It does so by updating the sub-processor page, by emailing everyone subscribed to changes on that page, and by emailing workspace owners.
- Objection. The Customer may object to a new Sub-processor on reasonable data-protection grounds by writing to us within the notice period. The parties will discuss the objection in good faith. If Avouro cannot address it, for example by not using the Sub-processor for the Customer's workspace, the Customer may end the Agreement for the affected workspaces before the change takes effect, and Avouro will refund any fees paid in advance for the period after the end date.
- Flow-down and liability. Avouro engages each Sub-processor under a written contract that imposes data-protection obligations no less protective than this DPA, as Article 28(4) GDPR requires. Avouro remains responsible to the Customer for each Sub-processor's performance of those obligations.
6. Data subject requests
- The Service gives the Customer the means to answer most requests itself: owners and admins can export the audit log, download evidence segments on plans with exports, remove members and delete the workspace, and each person can download their own account data.
- If Avouro receives a request from a data subject about Customer Personal Data, Avouro forwards it to the Customer without undue delay and does not answer it itself, except to tell the person that it has been passed on. Taking account of the nature of the processing, Avouro helps the Customer, by appropriate technical and organizational measures and as far as possible, to respond to requests to exercise data-subject rights.
- Workspace records are signed audit evidence kept on the Customer's instructions. Avouro does not erase or alter an individual record on a data subject's request to Avouro; the Customer decides how to answer. Records leave the Service by the plan's retention, by the Customer's choices and by workspace deletion (section 9).
7. Assistance with compliance
Taking account of the nature of the processing and the information available to it, Avouro helps the Customer meet its obligations under Articles 32 to 36 GDPR: security, personal data breach notification, data protection impact assessments and prior consultation with a supervisory authority. Avouro does so by providing this DPA and its annexes, the Trust page, the page on using Scopebond with your employees with its DPIA template, answers to reasonable security and privacy questions, and, where a supervisory authority asks, the information it needs.
8. Personal data breaches
- Avouro notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Our target is within 48 hours.
- The notice goes to the workspace owners by email and describes, as far as then known: the nature of the breach, including the categories and approximate number of data subjects and of records concerned; the name and contact details of the person at Avouro who can give more information; the likely consequences; and the measures taken or proposed to address the breach and to mitigate its possible adverse effects. Where not all of this is known at first, Avouro provides it in phases without further undue delay.
- Avouro takes reasonable steps to contain and investigate the breach and to reduce its effects, and keeps a record of it.
- The Customer decides whether to notify supervisory authorities and data subjects. Avouro does not notify them on the Customer's behalf unless the Customer asks it to or the law requires it. A notice is not an admission of fault or liability.
9. Deletion and return
- During the term, the Customer can export the audit log at any time and, on plans with exports, download its evidence segments.
- When an owner deletes a workspace, the deletion can be undone for 7 days. After that, Avouro purges the workspace's data, including its evidence segments. Encrypted backups roll off within 30 days. Evidence segments are not included in backups.
- When the Agreement ends, the Customer can export its data for 30 days, as the Terms say. After that, Avouro deletes the Customer's workspaces as described above, unless the law requires Avouro to keep some of the data. Data kept for that reason stays protected by this DPA and is processed only for the purpose the law requires.
- On request, Avouro confirms the deletion in writing.
10. Audits
- Avouro makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR and this DPA. It does so first by documentation: this DPA and its annexes, the Trust page, written answers to a reasonable security questionnaire, and summaries of relevant tests and drills.
- If that documentation is not enough to demonstrate compliance, or a supervisory authority requires it, the Customer may audit Avouro's processing of Customer Personal Data, including by inspection, on these terms: at least 30 days' written notice; no more than once in any 12 months, except after a personal data breach affecting the Customer or at a supervisory authority's request; during business hours and without disrupting the Service; by the Customer or an independent auditor bound by confidentiality who is not Avouro's competitor; limited to Customer Personal Data, without access to other customers' data; and at the Customer's cost, including Avouro's reasonable costs of supporting an on-site audit, which Avouro estimates in advance.
- Avouro tells the Customer promptly if, in its opinion, an audit instruction infringes Data Protection Laws.
11. International transfers
Avouro is in the United States. Customer Personal Data is processed in the United States and wherever Avouro's Sub-processors operate, except as Annex IV commits for workspaces created in the European Union region. Where Data Protection Laws require a transfer mechanism, the following apply and are incorporated into this DPA by reference.
EU Standard Contractual Clauses
- Module 2 (controller to processor) applies where the Customer is a controller, and Module 3 (processor to processor) where the Customer is a processor. The Customer is the data exporter and Avouro the data importer.
- Clause 7: the optional docking clause applies.
- Clause 9: option 2, general written authorization, applies. The time period for notice of changes is 30 days, as section 5 sets out.
- Clause 11: the optional language does not apply.
- Clause 13: the competent supervisory authority is the one set out in Annex I.C.
- Clause 17: option 1 applies; the SCCs are governed by the law of Ireland.
- Clause 18: disputes are resolved by the courts of Ireland.
- Annexes I, II and III of the SCCs are completed by Annexes I, II and III of this DPA.
- For Module 3, Avouro may meet its obligations to inform or notify the controller by informing or notifying the Customer, which passes the information on to its controller.
United Kingdom
For transfers subject to UK data protection law, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0, in force 21 March 2022) applies, completed as follows:
- Table 1 (Parties): the parties, their details and their contacts are as set out in Annex I.A. The start date is the date the Customer accepts this DPA.
- Table 2 (Selected SCCs, Modules and Selected Clauses): the Approved EU SCCs incorporated by this section, Modules 2 and 3, with the elections above.
- Table 3 (Appendix Information): the list of parties and the description of the transfer are in Annex I, the technical and organizational measures in Annex II, and the list of Sub-processors in Annex III.
- Table 4 (Ending this Addendum when the Approved Addendum changes): neither party may end the Addendum under its Section 19.
- Part 2: the Mandatory Clauses of the Approved Addendum, as issued by the Information Commissioner and laid before Parliament under section 119A of the Data Protection Act 2018, apply.
Switzerland
For transfers subject to the revFADP, the SCCs apply with these changes: the Swiss Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority under Clause 13 for those transfers; references to the GDPR are read as references to the revFADP as far as those transfers are concerned; and "Member State" in Clause 18(c) is read so that data subjects in Switzerland can bring claims where they habitually reside. Governing law and the choice of forum otherwise remain as above.
Other safeguards
- The EU–US Data Privacy Framework is not relied on as the only basis for any transfer.
- If Avouro receives a request from a public authority for Customer Personal Data, it reviews the request's legality, challenges it where there are reasonable grounds to do so, discloses no more than the request requires, notifies the Customer unless the law prohibits it, and keeps a record. As of the version date Avouro has received no such request.
- Avouro's transfer impact assessment is available to the Customer on request.
- If the European Commission adopts standard contractual clauses for importers already subject to the GDPR, or the UK or Swiss authorities change their mechanisms, Avouro may update this section to use them, with notice under section 15.
12. CCPA service-provider terms
Where the CCPA applies, Avouro is the Customer's service provider, and the business purpose is providing the Service under the Agreement. Avouro:
- does not sell or share Customer Personal Data, as those terms are defined in the CCPA;
- does not retain, use or disclose Customer Personal Data for any purpose, including a commercial purpose, other than the business purposes specified in the Agreement, or outside the direct business relationship between Avouro and the Customer, except as the CCPA permits;
- does not combine Customer Personal Data with personal information it receives from or on behalf of others, or collects from its own interactions with consumers, except as the CCPA regulations permit;
- complies with the CCPA's applicable obligations and gives Customer Personal Data the level of privacy protection the CCPA requires;
- notifies the Customer if it determines it can no longer meet its obligations under the CCPA; and
- allows the Customer, on notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data, and to ensure Avouro uses it consistently with the Customer's CCPA obligations, including through section 10.
Avouro certifies that it understands these restrictions and will comply with them. The same terms apply where another US state privacy law treats Avouro as the Customer's processor.
13. The Customer's responsibilities
- Lawful processing. The Customer is responsible for having a lawful basis for the processing it instructs, for the accuracy of its instructions, and for its right to send Avouro the data its agents and computers send.
- Region. The Customer chooses the region each workspace is created in and is responsible for that choice. Organizations in the EU/EEA, the United Kingdom or Switzerland should choose the European Union region, which opens soon; until it does, workspaces are created in the United States region. Avouro does not check where the Customer is established and does not restrict the choice. This DPA, including section 11, applies in both regions.
- Its staff. Scopebond records what coding agents do on the computers of the Customer's staff and contractors. The Customer is responsible for informing them about that processing, for any data protection impact assessment, for consulting or reaching agreement with works councils or other employee representatives where the law requires it (in Germany, for example, co-determination under section 87(1) no. 6 of the Works Constitution Act), and for complying with employment law. Our page on using Scopebond with your employees describes what is recorded and who sees it, and includes a DPIA template and a works-council summary.
- Purpose. Scopebond is for governing coding agents and keeping evidence of what they did. The Customer must not use it to evaluate the performance, productivity or behaviour of individual workers, or to make employment decisions about them. The Service offers no per-person productivity scoring.
- What it sends. The Customer must not deliberately send special categories of personal data, or data about criminal convictions and offences, and should keep secrets out of commands, paths and tool arguments, because removing them on the computer is best effort.
- No monitoring by Avouro. Avouro does not monitor how the Customer uses the Service beyond what is needed to operate, secure and support it.
14. Liability
Each party's liability arising out of or in connection with this DPA, including the SCCs as far as the law allows, is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA or the Agreement limits either party's liability to data subjects under the SCCs, or any liability that cannot be limited by law.
15. Term, changes and order of precedence
- This DPA applies for as long as Avouro processes Customer Personal Data, and ends when that processing ends under section 9.
- Avouro may update this DPA. For a material change, Avouro gives workspace owners at least 30 days' notice by email or in the product, and the version and effective date at the top of this page change. Avouro records which version each workspace accepted. Avouro will not lower the protection this DPA gives Customer Personal Data during a paid term without the Customer's agreement.
- If there is a conflict, the SCCs, the UK Addendum and the Swiss changes in section 11 prevail, then this DPA, then the rest of the Agreement. A data processing agreement signed by both parties replaces this DPA for that Customer.
- Questions about this DPA, and notices to Avouro: support@scopebond.com. Security reports: security@scopebond.com.
Annex I · Description of the processing
A. List of parties
| Data exporter | Data importer | |
|---|---|---|
| Name | The Customer, as named in its workspace | Avouro LLC |
| Address | The Customer's address, as given in its workspace or billing details | Michigan, USA |
| Contact | The workspace owners, by the email addresses in the workspace | support@scopebond.com |
| Activities | Using Scopebond Cloud to govern its coding agents and keep evidence of their actions | Providing Scopebond Cloud |
| Role | Controller (Module 2), or processor (Module 3) | Processor (Module 2), or sub-processor (Module 3) |
| Signature and date | Acceptance of this DPA in the product, or signature | Acceptance of this DPA in the product, or signature |
B. Description of the transfer
| Item | Description |
|---|---|
| Categories of data subjects | The Customer's staff and contractors whose computers run coding agents connected to the workspace; the workspace's members and invited people |
| Categories of personal data | Computer names (often a person's name); operating-system user names where they appear inside file paths and working folders (for example as the name of a home folder); the first 64 characters of commands, after secrets are scrubbed on the computer, with a fingerprint of the whole command; file paths; git remote addresses; network hosts and web addresses, with secrets scrubbed; MCP server and tool names (tool arguments only as a fingerprint); timestamps; members' names, email addresses and roles; reasons people type for an override or approval; the workspace audit log. Records never contain file contents or prompts. |
| Special categories | None intended. The Customer must not deliberately send them (section 13). |
| Frequency | Continuous, while the Customer's agents and computers are connected |
| Nature of the processing | Receiving, verifying, storing, indexing and displaying records; evaluating them against the Customer's rules; sending alerts and reports; signing evidence segments; backing up and restoring; exporting and deleting |
| Purpose | Agent governance (checking coding-agent actions against the Customer's rules) and audit evidence (keeping a verifiable record of what was attempted and decided) |
| Retention | By plan, as our Privacy Policy sets out: records are listed in Activity for the plan's retention period, and evidence segments stay until the workspace is deleted; deleted workspaces are purged after 7 days, and backups roll off within 30 days |
| Transfers to Sub-processors | For the same subject matter, nature and duration, as listed in Annex III |
C. Competent supervisory authority
- Where the Customer is established in an EU Member State: the supervisory authority of that Member State.
- Where the Customer is not established in the EU but has appointed a representative under Article 27(1) GDPR: the supervisory authority of the Member State where the representative is established.
- Otherwise: the supervisory authority of the Member State where most of the data subjects whose data is transferred are located; where that cannot be determined, the Irish Data Protection Commission.
- For transfers subject to UK data protection law, the Information Commissioner; for transfers subject to the revFADP, the FDPIC.
Annex II · Technical and organizational measures
Avouro maintains these measures for the Service. Our Trust page describes them for a general reader.
- Encryption in transit. All traffic to the Service uses TLS, and HTTP Strict Transport Security is set for one year, including subdomains.
- Encryption at rest. Workspace databases and evidence storage are encrypted at rest by our hosting provider, Cloudflare. Sign-in tokens from identity providers, and a GitHub token a workspace links, are stored encrypted by the Service.
- Signed evidence. Each record is signed on the computer that made it (Ed25519) and verifies offline against that computer's public key. Evidence segments in the Service are signed with Avouro's segment key, and retired keys are kept so older segments still verify.
- Tenant isolation. Every workspace route checks that the signed-in person belongs to the workspace and holds the permission the action needs. Automated tests try each route with another workspace's credentials and fail the build if any succeeds.
- Least privilege and roles. Workspaces have owner, admin, reviewer, viewer and scoped roles. Viewers and scoped members see secret-like values in record details masked again; scoped members see only the environments granted to them. Avouro staff access production only as their role requires.
- Administrator sign-in. Changes from Avouro's operations console require two-step sign-in and a session verified within the last 15 minutes. Workspace sign-in uses Google, Microsoft, GitHub or the Customer's single sign-on, and sessions last up to 12 hours.
- Data minimization on the computer. The Scopebond hook keeps only the first 64 characters of a command, with a fingerprint of the whole command, and removes common secret shapes from commands, paths and web addresses before signing. Removal is best effort. MCP tool arguments are kept only as a fingerprint, and the operating-system user who approves an override is kept only as a fingerprint. File contents and prompts are never recorded.
- Backups. Workspace databases are backed up every night, encrypted with AES-256-GCM under a key Avouro holds, and kept for 30 days. Restores are rehearsed every month on a scratch database, and a restore honours workspace deletions and personal-data erasures.
- Logging and audit. Privileged actions in a workspace are written to its audit log, which owners and admins can export. Rate limits protect sign-in and the public interfaces.
- Incident response. Written procedures cover leaked credentials, stolen sessions, supply-chain compromise and storage capacity incidents, and personal data breaches are handled as section 8 sets out. Security reports go to security@scopebond.com and are coordinated before disclosure.
- Change control. Every change to the Service goes through a pull request and the full automated test suite before it is merged, and automated scanners check the code and its dependencies. Signing and encryption keys are rotated under a written procedure.
- Vendor management. Avouro engages Sub-processors under written data-protection terms, records what each one processes and where, and reviews them before use and when they change.
Annex III · Sub-processors
The Sub-processors are those listed on our sub-processor page, with the service each provides, the data it processes and where. That list forms this Annex, and section 5 governs changes to it.
Annex IV · EU-region commitments
This Annex applies to workspaces created in the European Union region. Production offers the United States region today; this Annex applies to a workspace from the day the European Union region is offered and that workspace is created in it. For those workspaces, Avouro commits to the following.
- Storage. Workspace content, evidence segments and their backups are stored in the European Union.
- Restore. A restore of an EU-region workspace's data runs on infrastructure in the European Union.
- Email. Workspace email (invitations, alerts, plan notices and monthly reports) is sent through an email-sending region in the European Union. Sign-in email is about a person, not a workspace, and is sent from the United States.
- AI explanation. An AI explanation of records is not offered for EU-region workspaces until an option that processes in the European Union exists and Avouro has given the 30 days' notice of the Sub-processor that section 5 requires.
- Error reporting and analytics. Error reports and product analytics are processed by services hosted in the European Union, and workspace content is kept out of them.
- Central directory. Sign-in, workspace membership and the billing link are held in a central directory in the United States. Their transfer is covered by section 11.
- Customer destinations. Alerts and exports go where the Customer points them (section 2), wherever that is.