Get started →
Legal · DPA

Data Processing Agreement.

Effective 12 May 2026 Last updated 12 May 2026 Operated from Australia Version 1.0

This Data Processing Agreement (“DPA”) governs how Scoutr processes Personal Data on behalf of customers when acting as a Processor under the GDPR, UK GDPR, and analogous data protection laws. It applies automatically to all customers whose use of Scoutr causes Personal Data of EU, UK, or other regulated data subjects to be processed. If you need a separately countersigned copy for your records, email us.

Template notice. This DPA is a starting template that reflects standard GDPR Article 28 requirements. Enterprise customers with specific compliance regimes (HIPAA, FedRAMP, ISO 27001 audit trails, sector-specific rules) should request a tailored version. We recommend you have your own counsel review this document before signing.

01 · Preamble

Preamble.

This DPA forms part of the agreement between Scoutr (“Processor”) and the customer (“Controller”) for the use of the Scoutr platform (the “Service”). It sets out the terms on which Scoutr processes Personal Data on the Controller's behalf and reflects the parties' agreement with regard to the processing of Personal Data, in line with the requirements of Article 28 of the GDPR.

In the event of any conflict between this DPA and the Terms of Service, this DPA prevails with respect to the processing of Personal Data.

02 · Definitions

Definitions.

Capitalised terms used but not defined in this DPA have the meaning given in the GDPR. The following terms have the following meanings:

Controller
The Customer, as the entity that determines the purposes and means of the processing of Personal Data.
Processor
Scoutr, as the entity that processes Personal Data on behalf of the Controller.
Personal Data
Any information relating to an identified or identifiable natural person, processed by Scoutr on behalf of the Controller in the context of the Service.
Data Subject
The identified or identifiable natural person to whom Personal Data relates.
Sub-processor
A third party engaged by Scoutr to process Personal Data on behalf of the Controller. The current list is in Section 8.
Data Protection Laws
The GDPR (Regulation EU 2016/679), the UK GDPR, the Data Protection Act 2018 (UK), the Australian Privacy Act 1988, and any other applicable data protection laws.
Personal Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
Standard Contractual Clauses
The standard contractual clauses approved by the European Commission under Decision 2021/914 for the transfer of Personal Data outside the EEA, including any addenda required by the UK ICO.
03 · Scope & roles

Scope and parties.

This DPA applies whenever Scoutr processes Personal Data as a Processor on behalf of the Controller in connection with the Service. The Controller acts as the data controller and the Processor as the processor, as those terms are defined under Data Protection Laws.

Each party will comply with its respective obligations under Data Protection Laws. The Controller is responsible for the lawfulness of the Personal Data it provides to the Processor and for ensuring an appropriate legal basis for the processing.

What this means in practice for Scoutr. The Personal Data Scoutr processes on the Controller's behalf is limited. It primarily comprises the Controller's own account information (name, email, account credentials) and any input the Controller provides to the Service. Scoutr does not process Personal Data of the Controller's customers or end-users as part of its standard service.

04 · Processing details

What we process, and why.

Subject matter

The processing of Personal Data necessary to provide the Service to the Controller, as described in the Terms of Service.

Duration

For the duration of the Controller's subscription or use of the Service, plus the retention periods set out in Section 13 (Deletion & return) and our Privacy Policy.

Nature and purpose

To provide consumer intelligence reports, to operate the Controller's account, to deliver subscribed reports and notifications, to support the Controller, and to detect fraud and abuse.

Categories of Data Subjects
  • The Controller's authorised account users (typically the business owner, employees, contractors)
  • Individuals who contact Scoutr on behalf of the Controller (e.g. via support email)
Categories of Personal Data
  • Identification data: name, email address
  • Authentication data: hashed password, session identifiers
  • Account metadata: subscription status, billing identifiers (no card data — see below)
  • Usage data: log files, IP addresses, device and browser information, pages visited
  • Communications: any content the Controller sends to Scoutr support

Payment card data is processed by Stripe Inc. as an independent controller for that limited purpose. Scoutr does not access, store, or process payment card numbers.

05 · Instructions

Controller instructions.

Scoutr will process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by law to which Scoutr is subject. Where such legal obligation arises, Scoutr will inform the Controller of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest.

The Controller's instructions are documented in:

  • This DPA and any amendments to it
  • The Terms of Service and any subsequent agreed-upon written instructions
  • Configuration choices the Controller makes within the Service (e.g. which URLs to track, which sub-processors to permit)

Scoutr will inform the Controller without undue delay if, in its opinion, an instruction infringes Data Protection Laws.

06 · Confidentiality

Confidentiality.

Scoutr ensures that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to Personal Data is restricted to personnel who require such access for the performance of their duties.

07 · Security

Technical and organisational measures.

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, Scoutr implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption in transit — TLS 1.2+ for all communications between the Controller and the Service
  • Encryption at rest — for stored account data and Personal Data within the Service
  • Password protection — passwords stored using industry-standard one-way hashing (PBKDF2-HMAC-SHA256, 10,000 iterations); plain-text passwords are never stored or accessible
  • Access control — principle of least privilege; access to production systems is limited to personnel who need it
  • Authentication — account lockout after repeated failed attempts; secure session management
  • Network security — firewalls, intrusion detection, and secure infrastructure provided by AWS
  • Logical separation — per-tenant logical separation of data within shared infrastructure
  • Backup and recovery — encrypted backups with documented recovery procedures
  • Vulnerability management — regular review of dependencies and prompt patching of known vulnerabilities
  • Personnel — all personnel with access to Personal Data are bound by confidentiality obligations

The current technical and organisational measures will be updated as the state of the art evolves. Scoutr reserves the right to make commercially reasonable changes to these measures, provided the level of security is not materially diminished.

08 · Sub-processors

Sub-processors.

The Controller provides general written authorisation for Scoutr to engage Sub-processors to assist in the provision of the Service. Scoutr will impose data protection terms on each Sub-processor that are no less protective than those set out in this DPA, and remains fully liable to the Controller for the performance of any Sub-processor's obligations.

Current Sub-processors

As of the effective date of this DPA, Scoutr engages the following Sub-processors:

Amazon Web Services
Hosting & storage. Provides cloud infrastructure, encrypted storage, and compute for the Service.
United States
Stripe
Payment processing. PCI DSS Level 1 certified payment processor. Acts as an independent controller for payment card data.
United States / Ireland
Anthropic
AI synthesis. Processes scraped public consumer content to generate report intelligence. Account-level Personal Data is not transmitted.
United States
Google LLC
Analytics. Google Analytics 4 for anonymised site usage measurement.
United States
Meta Platforms
Advertising measurement. Meta Pixel and Conversions API for ad attribution. Hashed identifiers only.
United States / Ireland
Google Workspace
Transactional email. Sends account notifications, reports, and receipts via SMTP.
United States
Third-party platforms you connect (data sources, not sub-processors)

When the Controller chooses to connect an external account they own — such as TikTok, Meta (Instagram or Facebook), Shopify, Klaviyo, or Mailchimp — that platform acts as an independent data controller of the source data and as a data source to Scoutr, not as a sub-processor. Scoutr receives data from the platform under the Controller's authorisation (typically via OAuth), and processes that data within the sub-processors listed above. The Controller can revoke the connection at any time, and we will delete data received from that platform within 30 days of revocation.

Notice of changes

Scoutr will notify the Controller of any intended changes concerning the addition or replacement of Sub-processors at least 14 days in advance by updating this list and notifying the Controller's account email. The Controller may object to such changes on reasonable data protection grounds within 14 days of notice. If the Controller objects and the parties cannot agree on a resolution, the Controller may terminate the affected portion of the Service.

09 · Data subject rights

Data subject rights.

Taking into account the nature of the processing, Scoutr will assist the Controller, by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests from Data Subjects exercising their rights under Data Protection Laws.

If Scoutr receives a request from a Data Subject to exercise such rights in respect of Personal Data processed on behalf of the Controller, Scoutr will:

  • Promptly forward the request to the Controller
  • Not respond to the request directly without the Controller's prior written authorisation, except to confirm receipt or to direct the Data Subject to the Controller
  • Provide reasonable assistance to the Controller in responding, on commercially reasonable terms
10 · Breach notification

Personal Data Breaches.

Scoutr will notify the Controller without undue delay, and in any case within 72 hours after becoming aware of a Personal Data Breach affecting the Controller's Personal Data. The notification will include, to the extent known at the time:

  • The nature of the breach, including categories and approximate number of Data Subjects and records affected
  • The likely consequences of the breach
  • The measures taken or proposed to address the breach and mitigate its possible adverse effects
  • Contact details for further information

If full information is not available within 72 hours, Scoutr will provide initial information within that window and supplement it as additional details become available. The Controller is responsible for any notifications it must make to supervisory authorities and affected Data Subjects under Data Protection Laws.

11 · DPIAs & audits

DPIAs and audits.

Data Protection Impact Assessments

Where required under Article 35 of the GDPR, Scoutr will provide reasonable assistance to the Controller with any data protection impact assessments, taking into account the nature of the processing and the information available to Scoutr.

Audit rights

Scoutr will make available to the Controller all information necessary to demonstrate compliance with Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

The parties agree that audit rights will, in the first instance, be satisfied by Scoutr providing:

  • This DPA and updated versions of it
  • Documentation of technical and organisational measures (Section 7 above)
  • The list of Sub-processors and their relevant compliance certifications
  • Responses to written audit questionnaires from the Controller, on commercially reasonable terms

On-site audits may be requested by the Controller in case of a substantiated suspicion of non-compliance or following a confirmed Personal Data Breach. On-site audits will be conducted during business hours, with no less than 30 days' written notice, no more than once per 12-month period (except in case of breach), and at the Controller's expense. The auditor will sign a customary non-disclosure agreement before any audit.

12 · International transfers

International transfers.

Scoutr is operated from Australia. Personal Data may be transferred to and processed in countries other than the country in which the Controller is established, including Australia and the United States.

Where Personal Data of Data Subjects in the EEA, the United Kingdom, or Switzerland is transferred to a third country that is not the subject of an adequacy decision, Scoutr will ensure such transfers are protected by appropriate safeguards, including:

  • The Standard Contractual Clauses adopted by the European Commission
  • For UK transfers, the UK International Data Transfer Addendum issued by the ICO
  • For Swiss transfers, the FDPIC-approved version of the Standard Contractual Clauses

The Standard Contractual Clauses are incorporated into this DPA by reference and apply to relevant transfers, with the following selections:

  • Module Two (Controller to Processor) applies between the Controller and Scoutr
  • Module Three (Processor to Sub-processor) applies between Scoutr and its Sub-processors
  • Clause 7 (docking clause) is included
  • Clause 9, Option 2 (general written authorisation) applies, with a 14-day notice period for new Sub-processors
  • Clause 11 — the optional independent dispute resolution mechanism does not apply
  • Clause 17 — these clauses are governed by the law of Ireland
  • Clause 18 — disputes are resolved before the courts of Ireland

Australia is recognised as providing an appropriate level of data protection under the Australian Privacy Act 1988, which contains substantially similar principles to the GDPR for the categories of Personal Data processed under this DPA.

13 · Deletion

Deletion and return.

At the choice of the Controller, Scoutr will delete or return all Personal Data to the Controller after the end of the provision of services relating to the processing, and delete existing copies, unless storage is required by applicable law.

Specifically:

  • On termination of the Controller's account, account-related Personal Data is retained for 30 days to allow the Controller to export data, then deleted
  • The Controller may request earlier deletion at any time by contacting hello@scoutr.world
  • Backup copies are retained for the duration of the standard backup cycle (no longer than 35 days) and overwritten in the normal course of operations
  • Records required to be retained for legal, tax, or accounting reasons (such as transactional receipts under Australian tax law) are retained only for the period legally required and securely deleted thereafter
14 · Liability

Liability.

Each party's liability arising out of or in connection with this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations of liability set out in the Terms of Service.

Nothing in this DPA limits or excludes either party's liability for matters that cannot be excluded under applicable law, including liability under Article 82 of the GDPR.

15 · Term

Term and termination.

This DPA is effective from the date the Controller first uses the Service or from a later effective date specified at the top of this document, whichever is later, and continues for as long as Scoutr processes Personal Data on behalf of the Controller.

Termination of the underlying agreement does not affect any provisions of this DPA which by their nature should survive termination, including provisions relating to confidentiality, liability, and the deletion or return of Personal Data.

16 · General

General provisions.

Order of precedence

If there is any conflict between this DPA and any other agreement between the parties (including the Terms of Service), this DPA prevails to the extent of the conflict in matters concerning the processing of Personal Data. Where the Standard Contractual Clauses are incorporated, those clauses prevail over this DPA in case of any conflict.

Severability

If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions remain in full force and effect.

Updates to this DPA

Scoutr may update this DPA from time to time to reflect changes in Sub-processors, security measures, or applicable law. Material changes will be notified to the Controller at least 30 days in advance via the account email address. Continued use of the Service following the effective date constitutes acceptance of the updated DPA.

Governing law

This DPA is governed by the laws of Australia, except that the Standard Contractual Clauses are governed as set out in Section 12.

17 · Contact

Questions, signatures, requests.

For DPA-related questions, requests for a countersigned copy, sub-processor objection notices, or audit requests, contact us at the email below.

Scoutr — Data Protection contact

DPA enquiries · hello@scoutr.world

We aim to respond to DPA enquiries within 5 business days, and to formal data protection notices within the timelines required by law.

Need a countersigned copy?

Email us with your company details and we'll send a signed PDF you can countersign and return.

Request signed copy