Terms of Service
Last updated: July 2026
1. Acceptance of Terms
These Terms of Service (“Terms”) govern access to and use of ScoopVault at app.scoopvault.io and any related services, applications, APIs, documentation, reports, exports, and support services (“the Service”). The Service is operated by CERTISYT GROUP LTD, a private limited company registered in England and Wales, company number 17238897, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. ScoopVault is a trading name and product of Certisyt Group Ltd; references to “ScoopVault”, “we”, “our”, or “us” are to Certisyt Group Ltd.
By accessing or using the Service, you agree to these Terms. If you use the Service on behalf of an organisation, you represent that you have authority to bind that organisation to these Terms. In that case, “you” and “Customer” refer to that organisation.
2. Description of Service
ScoopVault is an AI-assisted eDiscovery and investigation platform for Google Workspace. The Service helps authorised organisations search, review, analyse, prioritise, summarise, export, and report on email evidence obtained through Google Vault exports, for legal, regulatory, compliance, HR, security, and internal investigation workflows.
The Service is an investigation and productivity tool. It does not replace legal advice, human review, professional judgement, or the Customer's own legal and compliance obligations.
3. Authorised Use
You may use the Service only for lawful business purposes, in accordance with these Terms, your organisation's policies, applicable laws, and any written agreement between you and ScoopVault.
You must not:
- Access, search, export, or process data that you are not authorised to access
- Use the Service for covert monitoring, unlawful surveillance, harassment, discrimination, retaliation, or abuse
- Use the Service for investigations that lack appropriate legal, HR, compliance, security, or organisational authorisation
- Attempt to bypass authentication, authorisation, audit logging, rate limits, or tenant isolation
- Introduce malware, exploit code, harmful content, or unauthorised automated traffic
- Reverse engineer, decompile, copy, modify, or attempt to extract source code from the Service except where permitted by law
- Resell, sublicense, lease, or provide the Service to third parties without our prior written consent
- Use the Service in a way that could impair, overload, or compromise ScoopVault systems or other customers
4. Customer Responsibilities
Customer is responsible for ensuring that every matter, search, custodian selection, export, Drive review, AI-assisted analysis, report, and investigation performed through the Service has an appropriate lawful basis and internal authorisation.
Customer is responsible for its Google Workspace configuration, OAuth grants, administrator permissions, user access, retention settings, legal holds, data subject rights processes, employee notices, works council obligations, regulatory obligations, and any decision made using Service outputs.
Customer must ensure that only trained and authorised users are permitted to access the Service and that all users comply with these Terms.
5. Google Workspace Data
The Service accesses Google Workspace data through Google APIs: the Google Vault API, to list matters and create exports; read-only Google Cloud Storage access, to retrieve the export files Vault produces; and Google account identity APIs, for sign-in, under OAuth permissions granted by the authorised tenant organisation. The Service does not access live Gmail mailboxes or Google Drive; email evidence enters the Service as point-in-time Google Vault exports.
Customer retains all rights, title, and interest in Customer Data. ScoopVault does not claim ownership of Google Workspace data, investigation data, exported records, uploaded materials, or reports generated from Customer Data.
Customer grants ScoopVault a limited, non-exclusive right to access, process, transmit, store, analyse, display, and export Customer Data solely as necessary to provide, secure, maintain, support, and improve the Service in accordance with these Terms and the applicable agreement.
6. Google API Limited Use
ScoopVault's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide user-facing eDiscovery, investigation, review, reporting, evidence management, and audit functionality requested by the authorised Customer.
ScoopVault does not use Google Workspace data obtained through Google APIs for advertising, unrelated analytics, user profiling, sale to third parties, or training general-purpose AI models.
7. AI-Assisted Outputs
The Service may generate AI-assisted findings, summaries, timelines, risk scores, narratives, recommendations, answers, and reports. These outputs are provided for investigation support only.
ScoopVault does not provide legal advice, legal opinions, privilege determinations, regulatory conclusions, employment advice, or final compliance decisions. Customer must independently verify all AI-assisted outputs before relying on them in legal, regulatory, disciplinary, employment, commercial, or compliance decisions.
AI outputs may be incomplete, inaccurate, or based on limited source material. ScoopVault is not responsible for decisions made without appropriate human review.
8. Data Processing and DPA
Where ScoopVault processes personal data on behalf of Customer, such processing is governed by these Terms, our Privacy Policy, and any applicable Data Processing Addendum or written data processing agreement between the parties.
Customer authorises ScoopVault to use subprocessors as necessary to provide the Service, subject to appropriate confidentiality, security, and data protection commitments.
9. Data Retention and Export
Unless otherwise agreed in writing, Customer Data is retained while the Customer account remains active or until deleted by Customer through available product functionality or a verified support request.
Following account termination, ScoopVault may retain Customer investigation data for up to 30 daysto support transition, recovery, legal hold, compliance, dispute resolution, and audit requirements. After this period, Customer investigation data will be deleted or anonymised from active production systems unless continued retention is required by law, contract, security investigation, dispute, or legitimate audit obligation.
Encrypted backup copies expire from the normal 14-day backup rotation after deletion from active systems. Customer should export required records, reports, evidence packages, and audit material before termination or expiry of the retention period.
10. Account Security
Customer is responsible for maintaining the confidentiality of its accounts, administrator access, Google Workspace permissions, OAuth grants, credentials, and user access controls. Customer is responsible for all activity performed under its accounts.
Customer must notify ScoopVault promptly of any unauthorised access, suspected compromise, security incident, or misuse of the Service.
11. Suspension
We may suspend access to the Service immediately if we reasonably believe that continued access may create a security risk, legal risk, risk to another customer, risk of unauthorised data access, infrastructure risk, violation of these Terms, or material misuse of the Service.
Where practicable, we will provide notice and an opportunity to remediate. However, we may act without prior notice where immediate suspension is reasonably necessary to protect the Service, Customer Data, other customers, or ScoopVault.
12. Confidentiality
Each party may receive confidential information from the other party. Confidential information includes non-public business, technical, security, product, financial, investigation, legal, compliance, and customer information.
Each party will protect the other party's confidential information using reasonable care and will use it only for purposes related to the Service. Confidentiality obligations do not apply to information that is publicly available, independently developed, lawfully received from a third party, or required to be disclosed by law.
13. Intellectual Property
The Service, including its software, workflows, user interface, platform design, scoring logic, prompts, documentation, templates, reports, dashboards, and related technology, is owned by ScoopVault or its licensors. These Terms do not transfer ownership of the Service to Customer.
Customer owns its Customer Data and investigation outputs generated from Customer Data, subject to ScoopVault's ownership of the underlying Service, templates, software, and platform technology.
14. Fees, Plans, and Usage Limits
Access to certain features may be subject to subscription plans, usage limits, AI token limits, job limits, storage limits, or other commercial terms agreed separately with Customer. Customer is responsible for all fees, taxes, and charges associated with its selected plan or order form.
We may enforce reasonable limits to protect service reliability, control AI usage costs, prevent abuse, and maintain fair use across tenants.
15. Beta and Evaluation Features
We may make beta, preview, trial, or experimental features available from time to time. Such features may be incomplete, unsupported, changed, or discontinued at any time. Customer should not rely on beta features for production legal, regulatory, or compliance obligations unless expressly agreed in writing.
16. Disclaimers
The Service is provided on an “as is” and “as available” basis to the maximum extent permitted by law. ScoopVault does not warrant that the Service will be uninterrupted, error-free, or that all investigation outputs will be complete, accurate, or legally sufficient.
Customer is responsible for validating search scopes, query logic, custodians, exports, AI outputs, and final conclusions before using them in legal, regulatory, employment, disciplinary, or compliance matters.
17. Limitation of Liability
To the maximum extent permitted by applicable law, ScoopVault shall not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, including loss of profits, loss of revenue, loss of goodwill, loss of data, business interruption, or failure to meet legal obligations.
Except for liability that cannot be limited by law, ScoopVault's total aggregate liability arising out of or relating to the Service shall not exceed the fees paid by Customer to ScoopVault for the Service during the twelve months preceding the event giving rise to the claim.
18. Indemnity
Customer agrees to defend and indemnify ScoopVault against claims, losses, liabilities, damages, costs, and expenses arising from Customer's unlawful use of the Service, unauthorised access to data, violation of these Terms, violation of applicable law, or use of investigation outputs without appropriate review and authorisation.
19. Termination
Customer may terminate its account in accordance with the applicable order form or written agreement. We may terminate or suspend access for breach of these Terms, non-payment, security risk, misuse, legal requirement, or discontinuation of the Service.
Upon termination, Customer's right to access the Service ends, but provisions relating to confidentiality, intellectual property, customer data, retention, payment obligations, disclaimers, limitation of liability, and governing law will survive.
20. Changes to Terms
We may update these Terms from time to time. We will notify tenant administrators of material changes by email or in-product notice with at least 14 days' notice where practicable. Continued use of the Service after the effective date of updated Terms constitutes acceptance of the updated Terms.
21. Governing Law
These Terms are governed by and construed in accordance with the laws of England and Wales. Subject to any mandatory legal requirements, disputes arising under or in connection with these Terms shall be subject to the exclusive jurisdiction of the courts of England and Wales.
22. Contact
For questions about these Terms, contact Certisyt Group Ltd (trading as ScoopVault) at: legal@scoopvault.io