Privacy.
Scoper Pty Ltd (ABN 24 624 594 583) · Last updated: 2026-07-16
Scoper helps organisations assess and document their information-security compliance. We take privacy seriously — it’s the nature of what we do. This policy explains, in plain English, what personal information we collect, why, who we share it with, how we use AI, where your information goes, and the choices and rights you have. It is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
If you have any questions, contact us at hello@scoper.io.
The short version
- We collect only what we need to run the service and talk to you.
- Your documents and account data are stored in Australia (Sydney).
- We use AI to analyse the documents you give us. No AI provider is permitted to use your data to train its models, and a human always reviews and can override what the AI produces.
- Some processing happens with trusted providers in the United States (AI analysis and email). We tell you exactly which, and what they receive.
- We never sell your personal information.
- You can access, correct, or delete your information, and complain if you think we’ve got it wrong.
1. Who this policy applies to
This policy covers personal information we handle about:
- Visitors to our website and people who request a demo;
- Users of the Scoper platform (the people at our customer organisations who hold accounts); and
- Individuals whose personal information may appear inside the documents a customer uploads (for example, a staff name in an access-control list or training record).
Scoper is a business-to-business service. The Scoper platform itself is provided to organisations under a separately signed Master Services Agreement, which governs how we process customer data as part of delivering the service.
2. Being anonymous or using a pseudonym
Where it’s lawful and practicable, you can deal with us anonymously or under a pseudonym — for example, when asking a general question. In practice we can’t provide the Scoper platform without an account, and we can’t run a tailored demo without knowing who you are and how to reach you.
3. The personal information we collect
Account and user information. Name, work email address, the organisation you belong to, your role, and authentication details (we store passwords only in hashed form).
Demo-request information. When you fill in our demo intake form: name, work email, company name, role (optional), company size, industry, audit deadline, prior compliance experience, and a free-text description of your needs. We also capture marketing source parameters (UTM) and a hashed form of your IP address for rate-limiting and abuse detection.
Documents you upload. The policy and compliance documents you give us to analyse. These are primarily about your organisation, but may contain personal information (such as employee names or records). We treat them accordingly.
Usage and assessment information. The assessments, findings, and outputs Scoper generates from your documents, and records of how you use the product.
Technical and log information. Standard server and security logs (such as timestamps, request metadata, and coarse device/browser information) needed to operate, secure, and troubleshoot the service.
We do not seek to collect sensitive information (as defined in the Privacy Act) and ask that you don’t upload it unless it’s genuinely required for your compliance work.
4. How we collect it
- Directly from you — when you create an account, request a demo, upload documents, or contact us.
- Automatically — through your use of the platform and website (usage and technical/log information).
- From a service you connect — if you choose to connect Google Drive, we read only the specific files you select. We never access your wider Drive.
Where it’s reasonable and practicable, we collect personal information directly from the individual concerned.
5. Why we use it
We use personal information to:
- provide, operate, secure, and support the Scoper platform;
- analyse the documents you give us and generate compliance assessments (see §6, How we use AI);
- respond to demo requests and brief our team before a demo;
- communicate with you about the service, including service and security notices;
- bill for the service (when paid plans are active);
- improve our product, and — where permitted — our sales and marketing; and
- meet our legal and regulatory obligations.
We use personal information only for these purposes, or for a directly related purpose you’d reasonably expect, unless you consent otherwise or the law allows it.
6. How we use AI
AI is core to how Scoper works, so we want to be clear about it.
What the AI does. Scoper uses AI to read the documents you upload, index them for retrieval, and assess them against information-security controls, producing draft findings and suggestions.
Which providers, and what they receive.
- Anthropic (United States) analyses excerpts of your documents that are included in analysis requests.
- Voyage AI (United States) converts your document text into a mathematical index (“embeddings”) so we can retrieve the right passages.
Your data is not used to train AI models. Neither provider is permitted to train its models on your data. Voyage does not retain your text after processing, and Anthropic does not retain the conversation content for the features we use. The full, current list is on our subprocessors page.
A human is always in the loop. The AI produces decision support, not decisions. You and your team review every result and can accept, edit, or override it. Scoper does not use AI to make automated decisions that produce legal, or similarly significant, effects on individuals. Because of this, the new Australian transparency requirements for automated decision-making (commencing 10 December 2026) are not expected to apply to the Scoper service; if that ever changes, we will update this section and tell you what it means.
AI has limits. AI-generated output can contain errors and is provided to support your judgement — it is not legal advice and is not a guarantee of certification or compliance.
7. Who we share it with
We don’t sell your personal information, and we don’t share it for others’ marketing.
We use a small set of trusted providers (“subprocessors”) to run the service — for hosting, storage, AI analysis, and email. Each receives only what it needs. The complete list — what each provider does, what data it receives, and where it operates — is kept current on our subprocessors page.
We may also disclose personal information where we’re required or permitted by law (for example, to comply with a lawful request), or to protect our rights, users, or the security of the service.
8. Sending information overseas
Your documents and account data are stored in Australia (in Supabase’s Sydney region). Some processing necessarily happens overseas:
- AI analysis (Anthropic, Voyage AI) takes place in the United States — relevant excerpts of your documents are sent there for processing as described in §6.
- Transactional email (Resend) is handled in the United States.
- Our application host (Vercel) runs compute in Sydney; Vercel Inc. is a US company.
Before disclosing personal information to an overseas recipient we take reasonable steps to ensure it’s handled consistently with the APPs, including contractual protections and the no-training and limited-retention terms described above. The countries in which recipients are likely to be located are Australia and the United States.
9. The marketing website
Separately from the product, our marketing site (scoper.io) uses Plausible for privacy-friendly analytics (no cookies, no personal identifiers, EU-hosted) and Calendly for demo bookings (the name and email you provide when booking). It does not run advertising trackers.
10. How we keep it secure
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure, including:
- encryption of your data in transit and at rest;
- storage in Australia with access restricted on a need-to-know basis;
- authentication, access logging, and tenant isolation so each customer’s data is separated; and
- ongoing security practices aligned with the information-security standards our own product helps customers meet.
No method of transmission or storage is completely secure, but we work continuously to protect your information and to detect and respond to risks.
11. Direct marketing and your choices
We may send you information about Scoper that’s relevant to you. You can opt out of marketing communications at any time — use the unsubscribe link in any marketing email, or email hello@scoper.io — and we’ll stop. We don’t provide your personal information to third parties for their own direct marketing.
12. Cookies
We use cookies and similar technologies that are strictly necessary to run the platform — for example, to keep you signed in and to keep the service secure. Our marketing analytics (Plausible) does not use cookies. You can control cookies through your browser, though disabling necessary cookies will stop parts of the platform from working.
13. Accessing and correcting your information
You have the right to ask for a copy of the personal information we hold about you, and to ask us to correct it if it’s wrong or out of date. Email hello@scoper.io. We’ll respond within a reasonable time (and within any period required by law), and we’ll verify your identity first. There’s no fee to ask; if a request requires substantial work we’ll tell you about any reasonable cost before proceeding. If we can’t give you access or make a correction, we’ll explain why in writing.
14. How long we keep it
We keep personal information only for as long as we need it:
- While your account is active — for as long as you use the service.
- After your account closes, or you ask us to delete your information — we delete or de-identify it within 30 days, except where we’re required to keep certain records longer by law (for example, financial or tax records).
- Backups — residual copies in encrypted backups are cycled out within 90 days.
When information is no longer needed and we’re not required to keep it, we securely delete or de-identify it.
15. If something goes wrong (data breaches)
We comply with the Notifiable Data Breaches scheme under the Privacy Act. If a data breach is likely to result in serious harm to anyone whose information we hold, we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law.
16. Complaints
If you think we’ve mishandled your personal information or breached the APPs, please tell us first so we can put it right: email hello@scoper.io with the details. We’ll acknowledge your complaint, investigate, and respond within a reasonable time.
If you’re not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):
- Web: oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
17. Children
Scoper is a business service intended for use by organisations and their staff. It is not directed at, or intended for, individuals under 18, and we don’t knowingly collect their personal information.
18. Changes to this policy
We may update this policy from time to time to reflect changes to the service or the law. We’ll change the “last updated” date above, and for significant changes we’ll take reasonable steps to let customers know. Please check back periodically.
19. Contact us
Scoper Pty Ltd (ABN 24 624 594 583)
Privacy enquiries: hello@scoper.io