Privacy Policy
Last updated: July 2026
1. Overview
ScoopVault is a product of CERTISYT GROUP LTD (“ScoopVault”, “we”, “our”, or “us”), a private limited company registered in England and Wales, company number 17238897, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Certisyt Group Ltd is registered with the UK Information Commissioner’s Office (ICO) under registration reference ZC190180. ScoopVault provides an AI-assisted eDiscovery and investigation platform for organisations using Google Workspace. This Privacy Policy explains how we collect, access, process, store, protect, and delete information when the ScoopVault service is used at app.scoopvault.io.
ScoopVault is designed for enterprise legal, compliance, HR, security, and internal investigation workflows. We process customer data only to provide, secure, maintain, and support the service requested by the authorised tenant organisation.
2. Our Role
For Google Workspace content and investigation data processed on behalf of a customer organisation, the customer organisation is generally the data controller and ScoopVault acts as a data processor or service provider. We process that data only in accordance with the customer organisation's instructions, the applicable agreement, and this Privacy Policy.
For account administration, security, billing, product operations, and service communications, ScoopVault may act as an independent controller of limited business contact and usage data.
3. Data We Access
ScoopVault accesses Google Workspace data solely on behalf of the authorised tenant organisation and only to the extent required to provide the requested eDiscovery, investigation, review, reporting, and audit functionality.
- Google Vault export data: We access Vault matters and create exports on the tenant's behalf, then retrieve the export files (email messages and attachments) from the Google-managed storage bucket where Vault writes them, to execute authorised searches and investigation jobs. We do not access live Gmail mailboxes or Google Drive.
- Google account identity: We collect account identifiers such as email address, display name, and authentication metadata during OAuth login so that we can create accounts, enforce access controls, and maintain audit trails.
- Investigation records: We store matter records, search jobs, exports, findings, reports, user actions, audit events, system logs, and related metadata generated through use of the service.
We do not access Google Workspace data beyond the OAuth permissions granted by the authorised tenant organisation and the functional scope required to provide the service.
4. Google API Limited Use
ScoopVault's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace data obtained through Google APIs is used only to provide and improve user-facing eDiscovery, investigation, reporting, evidence management, and audit functionality requested by the authorised tenant organisation.
We do not use Google Workspace data obtained through Google APIs for advertising, unrelated analytics, user profiling, sale to third parties, or training general-purpose AI models.
5. How We Use Data
We use customer data and account data for the following purposes:
- Executing authorised eDiscovery searches and investigation workflows
- Retrieving, indexing, reviewing, and exporting relevant Google Workspace records
- Generating AI-assisted summaries, risk findings, timelines, narratives, and investigation reports
- Producing evidence packages, audit trails, and defensibility records
- Maintaining tenant isolation, role-based access control, authentication, and security monitoring
- Providing customer support, service administration, and operational communications
- Monitoring service reliability, usage limits, system errors, abuse, and security events
- Complying with legal, regulatory, contractual, and security obligations
We do not sell customer data. We do not use customer data for advertising. We do not use customer investigation data for purposes unrelated to the service requested by the customer organisation.
6. AI Processing
ScoopVault uses AI providers to support investigation analysis, summarisation, risk identification, question answering, and report generation. Where AI analysis is enabled, relevant excerpts, metadata, summaries, documents, prompts, and outputs may be transmitted to the AI provider solely to generate the requested investigation output.
AI-assisted analysis is not enabled by default. Where it is enabled for an authorised tenant, ScoopVault accesses Claude models through Google Cloud (Vertex AI); Google provides the managed AI inference service. Anthropic is the publisher/licensor of the Claude models and, under this approved route, does not receive ScoopVault investigation content, prompts or outputs directly. Exact and Connected search do not use an AI model.
We do not permit customer investigation data, Google Workspace content, email exports, Drive files, prompts, summaries, reports, or AI outputs to be used to train third-party AI models, except where expressly agreed in writing by the customer organisation.
AI outputs are assistive and may be incomplete or inaccurate. Customers remain responsible for human review, legal judgement, compliance decisions, and final use of any investigation output.
7. Data Storage and Security
We apply technical and organisational safeguards designed to protect customer data against unauthorised access, disclosure, alteration, and loss. These safeguards include:
- Encryption in transit using TLS; encryption at rest on all production storage
- Tenant-level data isolation and access controls
- Role-based permissions for users and administrators
- Secure OAuth authentication with Google Workspace
- Short-lived access tokens and controlled session handling
- Restricted database, cache, and infrastructure access
- Firewall controls and network segmentation for production services
- Automated daily encrypted off-server backups; the backup decryption key is never stored on any server
- Audit logging for administrative, investigation, authentication, and AI-related actions
- Operational monitoring for failures, abnormal usage, and security-relevant events
Production storage is encrypted at rest using platform-managed encryption provided by our cloud infrastructure provider. Backups are additionally encrypted with public-key encryption before leaving the production environment, and the private key required to decrypt them is never stored on any server.
No system can be guaranteed to be completely secure. Customers are responsible for ensuring that their own administrators, users, Google Workspace configuration, OAuth permissions, and internal investigation processes are appropriately controlled.
8. Data Retention and Deletion
Investigation data, indexed content, exported records, AI-generated findings, reports, matter metadata, and related audit records are retained while the customer account is active unless the customer deletes them earlier or a different retention period is agreed in writing.
Following account termination, ScoopVault retains customer investigation data for up to 30 daysto support customer transition, legal hold, dispute resolution, compliance, and recovery requirements. After this period, customer investigation data is deleted or anonymised from active production systems unless continued retention is required by law, contract, security investigation, dispute, or legitimate audit obligation.
Backup copies remain for up to 14 days after deletion from active systems and are removed through the normal backup rotation cycle. Where technically feasible and commercially reasonable, we will assist customers with export or deletion requests before termination.
9. Third-Party Services and Subprocessors
ScoopVault uses carefully selected third-party service providers and subprocessors to provide infrastructure, authentication, AI analysis, email delivery, monitoring, and operational support. These may include:
- Google Workspace APIs: for Vault, Vault-export retrieval, and account identity access
- Resend: for transactional email delivery, including team invitations, account notifications, and support-request delivery
- Google Cloud Platform: production hosting, storage, and processing (London region, United Kingdom); and, where and when AI-assisted analysis is enabled for a tenant, managed AI inference using Claude models through Google Cloud (Vertex AI)
- Hetzner: encrypted backup object storage (Finland, EU)
Anthropic is the publisher/licensor of the Claude models used for AI-assisted analysis, where and when that capability is enabled. Anthropic is not a subprocessor for this Service: under the approved Google Cloud managed route, prompts and responses submitted for AI-assisted analysis are not shared with Anthropic, and Anthropic does not receive investigation content, prompts or outputs directly.
Data shared with subprocessors is limited to what is necessary to provide the requested service function. Where subprocessors process data outside the United Kingdom or European Economic Area, we use appropriate contractual, technical, and organisational safeguards where required by applicable law.
10. Customer Responsibilities
Customer organisations are responsible for ensuring that their use of ScoopVault has an appropriate lawful basis, internal authorisation, and governance process. This includes responsibility for deciding which users, custodians, matters, searches, exports, and documents are in scope for each investigation.
Customers are also responsible for responding to data subject requests, employee notices, legal holds, regulatory obligations, works council requirements, and other obligations that apply to their use of Google Workspace data.
11. Data Subject Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, object to, or export personal data. Where ScoopVault processes personal data on behalf of a customer organisation, requests relating to investigation data should normally be directed to that organisation.
If we receive a request relating to customer-controlled data, we may refer the request to the relevant customer organisation or assist the customer in responding, subject to the applicable agreement and legal requirements.
12. Security Incidents
If we become aware of a security incident affecting customer data, we will investigate promptly and notify affected customer organisations without undue delay where required by law or contract. We will provide information reasonably available to us to help customers meet their own notification, investigation, and mitigation obligations.
13. Business Contact and Usage Data
We may process limited business contact, account, and usage data, including names, work email addresses, tenant identifiers, login events, feature usage, billing status, support requests, and security logs. We use this data to administer accounts, provide support, secure the service, manage contracts, improve reliability, and communicate with customers about the service.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify tenant administrators of material changes by email or in-product notice where appropriate. The updated policy will apply from the effective date stated in the notice or on this page.
15. Contact
For privacy-related questions, requests, or security concerns, contact Certisyt Group Ltd (trading as ScoopVault) at: privacy@scoopvault.io