Privacy notice · Version 1.9
A plain-language guide to the details
Privacy notice
A clear guide to how ScopeProof collects, uses and protects personal information when you use our website and privacy-request service.
A quicker read
Start with the essentials.
Use the section guide to jump around, or open only the parts you need. The complete document is below.
Your control
Access · correct · erase
You may have rights over the information we hold about you.
Our approach
No selling or ad profiles
We use request information to provide the service, not to build advertising profiles.
Clear timelines
Retention by record
Each major record type has a standard retention period.
Full privacy notice
13 of 13 sections open
ScopeProof is a product of Kovar Ltd. In this notice, “ScopeProof”, “we”, “us” and “our” refer to Kovar Ltd. Our business correspondence address is 64 Lime Tree Road, Nottingham, NG15 6AL, United Kingdom.
Company number: 14623518. Registered in: England and Wales. Registered office: 64 Lime Tree Road, Nottingham, NG15 6AL, United Kingdom.
We are the data controller for the personal information we use to operate your account, provide the ScopeProof service, administer billing, keep the service secure and respond to enquiries. Our ICO registration number is ZC231883. Registration is not an ICO endorsement of the service.
Privacy questions and rights requests are handled by our privacy contact at [email protected].
We collect information directly from you, create information when you use the service, and may receive information from a service provider or an organisation responding to a request.
- Account information: your full legal name, email address, password hash, account creation date and email-verification status.
- Authentication and security information: session records, verification and password-reset records, and information needed to protect the account. We do not store your password in readable form.
- Permission records: the authority document you review and sign, its version and integrity hash, signing and expiry times, authentication method, revocation history, and the email address, IP address and browser information recorded with the signed authority.
- Request information: the type of data-protection request you select, the organisation or route selected, information you provide to help identify your records, the request text, delivery status and related activity history.
- Responses and evidence: the sender, subject, message identifiers, timestamps, content and technical metadata of responses received through a correlated service email route. Raw inbound email may be retained securely as evidence.
- Billing information: your plan, Stripe customer and subscription identifiers, payment status and invoice information. Stripe handles payment-card details; ScopeProof does not store your full card number.
- Enquiries and rights requests: support-ticket subjects, messages, status and read history, and information you include when contacting us about privacy or a complaint.
- Essential technical information: the necessary session and cross-site request-forgery cookies described below. We do not use ScopeProof account information for targeted advertising.
Please provide only information necessary to identify the relevant record. Do not enter identity documents, health information, biometric identifiers, criminal-offence information or other highly sensitive material in the request fields. The standard service is not designed to collect it. If a controller requires sensitive evidence, we must first agree a separate secure process and identify the additional legal condition needed to handle it. Your authority to send an ordinary request is not consent to every possible use of sensitive information.
- To create and operate your account and provide the service. This is necessary to take steps at your request and perform our contract with you.
- To verify email ownership, authenticate users and protect accounts. Authentication needed to provide your account is based on contract; additional abuse and fraud prevention is based on our legitimate interests in protecting users and the service.
- To prepare, send and monitor a request when you authorise it. This is necessary to provide the service you ask for. Every request combines erasure with an objection to future direct marketing and advertising, related profiling and sharing for marketing, and withdrawal of marketing consent previously given to the selected organisation. There is no option to omit that marketing objection. We send those instructions under your signed authority. The receiving organisation is independently responsible for compliance and may retain minimal suppression information only to prevent renewed marketing, not to keep using your data for marketing or advertising. This is not consent to marketing from ScopeProof.
- To preserve permission, delivery and evidence records. This supports our legitimate interests in demonstrating what was authorised, handling disputes and maintaining a reliable audit trail.
- To process subscriptions and payments. This is necessary to perform the billing contract and comply with accounting, tax and financial obligations.
- To maintain security, reliability and service operations. This is based on our legitimate interests in keeping the service safe, available and properly administered.
- To respond to legal requests, complaints and rights requests. Handling statutory rights requests and data-protection complaints is based on legal obligation. Routine support is based on contract; keeping proportionate evidence to establish, exercise or defend claims is based on our legitimate interests.
Account details and the minimum identifying information for a selected route are needed to provide that part of the service. Without them we may be unable to open an account or submit the request. Additional identifying information is optional unless the selected controller needs it to find your record.
We do not sell personal information. We do not use your request information to build advertising profiles. If we ever ask for consent for optional processing, we will explain that processing separately and you may withdraw consent at any time.
Service providers, their support teams and receiving organisations may process information outside the UK. A UK storage region does not by itself prevent overseas access or onward transfers. Where a restricted international transfer is required, we use an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to standard contractual clauses, or another lawful safeguard available under UK data-protection law. You can contact us for details and a copy of the relevant safeguards, with confidential information redacted where necessary.
We keep personal information only for as long as it is needed for the purpose collected, to meet a legal or accounting requirement, or to establish, exercise or defend legal claims. The standard database cleanup runs daily, and the support-ticket worker checks its closure and retention rules more frequently. Records become eligible at the times below and are removed in the next successful cleanup. Storage-provider expiry runs separately. This is the standard schedule; infrastructure settings and any exceptions must be verified before production use:
Retention schedule 1.6 · effective 24 September 2026 · next review 24 September 2027
| Record | Standard retention |
|---|---|
| Email delivery and do-not-send records | Delivery-event records are removed 90 days after receipt. Provider-message references on do-not-send records are cleared after 90 days from the last suppression event. We retain a minimal address hash, reason and dates while needed to prevent unwanted or undeliverable messages, including after account deletion; continued need is reviewed at least annually. These restrictions do not automatically expire. |
| Unverified accounts | Normally deleted 30 days after creation if the account remains unverified and active. |
| Account and profile | Kept while your account is active. Successful account deletion removes your live account, profile, sessions, tokens, signed authorities, requests, dispatches, linked notices and replies, support tickets and messages, and local subscription state. The separate records and copies below can remain for their stated periods. |
| Verification, password-reset and session records | Verification and password-reset token records are removed when used or during cleanup after expiry. Sessions normally expire after 12 hours; expired session records are purged 30 days after expiry. |
| Permission and authority records | Normally 2,190 days (approximately six years) after revocation, or after a calendar expiry for older authorities, to evidence authority and handle disputes. Successful account deletion removes the live authority sooner. An authority to send requests continues until you revoke it or your paid plan ends. An authority verification link expires 365 days after signing. |
| Requests, dispatches and activity history | Normally 1,095 days (approximately three years) after the last update to a request whose status is deletion confirmed, controller refused or cancelled. Dependent dispatch and activity records are removed with it. Active requests remain while they are being handled. |
| Broker reply notices | Reply routes normally expire 365 days after creation. This allows delayed replies to be received. It is a separate clock from the authority to send requests. Expired routing and token records are eligible for deletion 30 days later, but remain while an inbound message references them. |
| Inbound controller replies | Readable database previews are cleared after 30 days from receipt. Private raw email, including attachments, is scheduled to expire from active object storage after 30 days; storage expiry is asynchronous. In a versioned store, an older version can remain for a further 30 days after becoming non-current. Sender, subject, status, identifiers, storage references and evidence hashes remain for 1,095 days from receipt. Subject lines can contain personal information. Successful account deletion removes linked live database records sooner, but does not immediately erase stored email objects. |
| Quarantine and manual review | Quarantine metadata is kept for 365 days from quarantine; the raw email follows the inbound storage schedule. Resolved manual-review items, notes and action history are kept for 730 days after resolution. Open reviews remain while needed; this does not extend the life of the underlying email or quarantine record. |
| Operational and security records | Operational events are normally kept for 90 days from the event; resolved alerts for 90 days after resolution. Security-audit records are kept for 730 days from the event and may retain account references and security fingerprints after account deletion. Active alerts remain while needed. |
| Billing and webhook records | Local subscription state remains while your account is active. Webhook idempotency records remain for 730 days from receipt, including after account deletion. Payment, invoice and accounting records held outside the application follow the relevant provider and legal requirements; deleting your account does not delete Stripe’s records. |
| In-app support tickets | Tickets remain available while open. When we reply and are waiting for your response, a ticket closes automatically after seven days without a further reply from you. Closed tickets, their messages and notification records are normally deleted 12 months after closure, or sooner after successful account deletion. A documented legal hold pauses this cleanup until the hold is released. |
| Other support, privacy enquiries and complaints | Enquiries sent outside the in-app ticket system are kept while we handle the matter and, after closure, only while needed to demonstrate the response, meet a specific legal duty or handle a reasonably anticipated dispute. We consider the nature of the matter and applicable claim periods, review continued need, and delete unnecessary attachments sooner. These mailbox records are separate from broker replies and are not subject to the application’s 30-day preview cleanup. |
| Sign-in passkeys | If you add a passkey, we keep its public key, an encrypted credential record, when it was added and when it was last used. It stays until you remove it, reset your password (which removes all passkeys), or delete your account. We never receive your fingerprint, face data or device PIN. Expired passkey sign-in challenges are eligible for cleanup 24 hours after expiry. |
| Admin security records | Expired MFA challenges are eligible for cleanup 24 hours after expiry; used recovery-code hashes after 30 days from use. Active passkeys, TOTP state and unused recovery codes remain while needed for administrator access. |
| Backups, logs and provider copies | Our deployment policy requires rolling backups of no more than 35 days and application logs of no more than 30 days. These periods depend on the hosting and logging configuration. Provider queues, mailboxes and diagnostic copies have separate deletion settings and do not disappear when a live account is deleted. Contact us for the periods and safeguards applicable to a particular provider copy. |
Account deletion requires password confirmation and successful handling of any active subscription or in-flight delivery. If it fails, the account may remain and we will explain the next step. It cannot recall a request already sent or erase a receiving organisation’s own records. You can also request erasure by contacting us; a technical problem with account deletion does not remove your statutory rights.
We may preserve a limited, separately controlled copy where necessary for a specific legal obligation, complaint or legal claim. We record the reason, restrict access and review continued need; this is not a blanket extension for all account data. Any necessary preservation must be arranged before normal deletion; keeping a complaint open does not itself preserve every underlying message. Backup copies are restricted from routine use and, if restored, must have applicable deletions reapplied before normal processing resumes.
We use measures designed to protect personal information, including password hashing, secure and time-limited sessions, access controls, least-privilege administration, cross-site request-forgery protection, rate limiting, integrity checks for authority records, correlated evidence records and security auditing. Access is limited to the people and systems that need it. No online service can guarantee absolute security.
Depending on the circumstances and the lawful basis, you may have the right to:
- ask for a copy of the personal information we hold about you;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information when there is no good reason for us to keep it;
- ask us to restrict how we use information in certain circumstances;
- object to processing based on our legitimate interests, including the right to object to direct marketing; and
- receive information you provided to us in a structured, commonly used and machine-readable format where the right to data portability applies.
Your right to object: you can object to processing based on legitimate interests for reasons relating to your situation. We must then stop unless we demonstrate overriding compelling grounds or need the information for legal claims. An objection to direct marketing is absolute; we do not use your request information for direct marketing.
If we rely on consent for a particular use, you can withdraw that consent at any time. Withdrawal does not affect processing that took place before withdrawal or processing based on another lawful basis.
Send a request to [email protected]. We may ask for information to confirm your identity or authority to protect someone else’s information. We normally respond free of charge, without undue delay and within one calendar month. If necessary identity information is needed, we will ask promptly and explain how it affects the deadline. Where the law permits, we may extend the period by up to two further months because of complexity or the number of requests, and will tell you why within the initial month. Any pause to clarify an access request will be used only where legally permitted. If we refuse a request or lawfully charge a fee, we will explain the reasons and your complaint rights.
We do not use personal information to make automated decisions that produce legal or similarly significant effects, and we do not create advertising profiles. The service may use rules to organise request statuses or classify an inbound controller response. An ambiguous response is sent for human review, and a classification that a controller has confirmed deletion is evidence of what the controller said, not independent proof that deletion occurred.
ScopeProof is intended for people aged 18 or over managing their own personal data and is not directed to children. If you believe a child has provided personal information to us, please contact us so we can review and delete it where appropriate.
We may update this notice when our service, processing activities or legal obligations change. We will publish the updated version on this page and change the “Last updated” date. If a change is significant, we will draw it to account holders’ attention where appropriate.
For privacy questions, rights requests or complaints, contact Kovar Ltd at [email protected].
To make a data-protection complaint, email [email protected] with a description of the concern and how we can contact you, or write to the correspondence address above. You do not need a particular form. We will acknowledge your complaint within 30 days, make appropriate enquiries without undue delay, keep you informed of progress and tell you the outcome without undue delay.
We want to resolve concerns directly. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection.
Still have a question?
Our privacy contact can help with rights requests, complaints or questions about this notice.