Privacy Policy
How GovScape handles personal data: what we collect, why, who else sees it, how long we keep it, and what you can require us to do about it.
Last reviewed 9 September 2026
Draft — not yet published
This document is complete except for the facts below, which cannot be determined from the application and must be supplied before it is relied on:
- Registered company name of the operating entity
- Companies House company number
- Registered office address
- ICO registration reference (data protection fee)
- A monitored inbox for privacy and data subject requests
- Supabase project region — where the database, logins and uploaded files actually live
- Sentry data residency — currently the US, with AUD-44 open to move it to the EU
- Confirmation that a UK IDTA or SCC addendum is signed with every processor outside the UK
Filling in lib/legal/entity.ts removes this notice from every legal page.
1Who this policy is from, and the two roles we play
GovScape is operated by GovScape (operating entity to be confirmed). This policy covers portal.govscape.app and govscape.app.
We handle personal data in two different capacities, and which one applies changes what you should ask us for.
As a controller. For our own account holders and for people who contact us — your name, your work email address, your sign-in credentials, your enquiry. We decide why and how that data is used, so requests about it come to us directly.
As a processor. For everything you put into the product: your governance records, your uploaded policies, your evidence, and any document content read from systems you connect. Your organisation is the controller of that material and we act on its instructions. If you are an employee of a customer and want your data removed from that content, your own organisation is the right first point of contact, and we will support whatever it decides.
2What we collect
Account and identity
Your email address, a hashed password, your display name, and — where you enable it — your multi-factor authentication enrolment. Sign-in is provided by Supabase; we never see your password.
What you put into the product
- Governance records: controls, policies, risks, exceptions, evidence, AI systems and business processes, including free-text fields where you name an accountable person.
- Files you upload — policy documents as PDF or Word, and evidence as images, PDFs, spreadsheets or text — together with the text extracted from them, which is stored in our database.
- Conversations with the in-product advisor, and briefing notes, including transcripts of recordings you make.
Systems you connect
If you connect a Microsoft 365 environment, we read document metadata from it — file names, paths, sizes, modification dates and the email address of the person who last modified each file — and we download the content of documents selected for review. We do not write anything back into your Microsoft 365 environment, and nothing is read until you have granted consent through Microsoft’s own authorisation flow.
Records of activity
Every change to a governance record is written to an audit log with the identity of who made it, when, and a snapshot of what the record looked like before. Where a change was made by an AI model rather than a person, the log records the model and the person on whose behalf it acted. That separation is deliberate: an audit trail that cannot distinguish a consultant’s decision from a model’s is not evidence of anything.
Technical data
- IP addresses. We do not store raw IP addresses in our database. Where we need to rate-limit a public form or throttle repeated sign-up attempts, we store a hashed form. A raw IP address is briefly held as a rate-limiting key by Upstash and expires with the rate-limit window.
- Error and performance data. When something goes wrong we receive an error report through Sentry. See clause 6.
If you contact us or apply to a programme
Your name, email address, company, phone number where you give it, your message, and a hashed IP address. Partner applications also capture your firm, sector and LinkedIn profile where you provide it.
3Why we are allowed to use it
| What | Lawful basis |
|---|---|
| Running your account and delivering the product | Performance of a contract |
| Content you place in the product | Processed on your organisation’s instructions, under its own lawful basis |
| Security, rate limiting, abuse prevention and audit logging | Legitimate interests — keeping the service available and its records trustworthy |
| Error monitoring and performance measurement | Legitimate interests — diagnosing faults in a service you rely on |
| Replying to an enquiry or an application | Steps taken at your request before entering a contract |
| Keeping records we are required to keep | Legal obligation |
We do not sell personal data, and we do not use it to build advertising profiles.
4Artificial intelligence, and what leaves the product
GovScape uses AI models to read documents and draft governance content. This is the part of the service that moves your data furthest, so it is set out plainly rather than buried in a list of vendors.
- The full text of policy documents you upload is sent to Anthropic for control extraction. It is sent as written. It is not redacted or pseudonymised first, so a policy naming an individual is transmitted naming them.
- Where you connect Microsoft 365, the text of documents selected for review is sent to Anthropic. File names and the email addresses of file owners are stored by us as part of the inventory.
- Advisor conversations and the governance context shown alongside them are sent to Anthropic.
- Audio you record for a briefing is sent to OpenAI to be transcribed. That audio contains the voice of everyone on the call. We do not keep the audio; we keep the transcript, and the transcript is then processed by Anthropic. If you record a meeting, obtaining everyone’s consent to that recording is your responsibility, not ours.
Model output is treated as a suggestion, not a decision. Extracted controls are written with low confidence and attributed to the model in the audit log so a person can review them. No decision producing a legal or similarly significant effect on an individual is made by automated means.
5Who else sees your data
We share personal data with the 7 companies that provide the infrastructure and services behind the product. Each is named, with the specific data it receives and why, on our sub-processor list. That list is checked against the application’s source code automatically, so a new service cannot be added without it appearing there.
Beyond those, we share personal data only where we are legally required to, or where it is necessary to establish or defend a legal claim. If our business is sold or reorganised, data may transfer to the acquiring entity, and this policy binds them until it is replaced by one no less protective.
Transfers outside the United Kingdom
Several of our processors are incorporated in the United States. Where personal data is transferred outside the UK, it must be protected by a transfer mechanism recognised in UK law — the International Data Transfer Agreement, or the EU standard contractual clauses with the UK addendum. We are completing the confirmation of these arrangements with each processor, and until that is complete we say so here rather than assert a safeguard we have not verified.
6Error monitoring and session replay
We use Sentry to find and fix faults. It receives error reports and stack traces, browser console output, and a share of session replays: a reconstruction of what a page looked like and what was clicked on it. Replays are recorded for a small sample of sessions and for every session in which an error occurs.
All text in a replay is masked before it leaves the browser, so the words in your documents are not captured. Images and other media are not masked. Sentry telemetry is routed through our own domain, which means a browser ad-blocker will not prevent it.
If you would prefer not to be included in session replay, tell us at sales@govscape.app and we will exclude your account.
7How long we keep it
We keep account data for as long as the account exists, and content you put into the product for as long as your organisation’s subscription runs. Beyond that, four things are worth stating precisely, because they are the points where general language would be misleading.
- Audit logs are permanent. They cannot be edited or deleted, which is enforced by the database itself rather than by convention — an audit trail that can be amended is not an audit trail. They contain the identity of whoever made each change and a snapshot of the record beforehand. They are removed only when the whole organisation is deleted.
- Deleting a policy or an evidence item deletes the file too. The record and the uploaded file both go. If the storage provider fails at that exact moment the record is still removed, so your access ends either way, and a reconciliation sweep finds and removes any file left behind. If you want confirmation that a specific file is gone, ask us at sales@govscape.app.
- Replacing an evidence document keeps the previous version. Renewing an item stores the new file alongside the old one rather than overwriting it, because the point of a renewal is showing that a control was evidenced continuously — a version history with a hole in it proves less than no history at all. Ask us if you need a superseded version removed.
- Some security records are kept indefinitely. Hashed records of sign-up attempts and the inventory of files seen in a connected environment are retained rather than expired, because a record that disappears is not much use for detecting a pattern.
On termination we will delete or return customer content in line with the data processing agreement.
8Your rights
Under UK data protection law you can ask us to give you a copy of your personal data, correct it, delete it, restrict what we do with it, provide it in a portable format, or stop processing it where we rely on legitimate interests. Where we rely on consent you can withdraw it at any time.
Send requests to sales@govscape.app. We respond within one month. There is currently no self-service export or account-deletion button in the product; requests are handled by our team, and we would rather tell you that than describe a control you would go looking for and not find.
Two limits are worth knowing in advance. Audit records are retained as a matter of legal and contractual obligation and are not deleted on request, although we will restrict their use where the law requires. And where we hold your data as a processor for a customer organisation, we will pass your request to that organisation rather than act on it ourselves.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you raised it with us first.
9How we protect it
- Traffic is encrypted in transit. Application code runs in London, United Kingdom (Vercel region lhr1).
- Access to a customer’s data is scoped to that organisation at the database level, and separately enforced in the application.
- Multi-factor authentication is available and can be required for privileged actions.
- Uploaded files are checked against their actual file signature rather than the type the browser claims, and are stored under paths derived on the server so one customer cannot address another’s files.
- Every change to a governance record is attributed and recorded, including changes made by AI.
10Cookies
We set only the cookies needed to sign you in, keep you signed in, remember which client organisation you are working on, and protect the authorisation flows against forgery. There is no advertising or cross-site tracking cookie, and no third-party analytics. The full list is on the cookies and analytics page.
11Children
GovScape is a business tool and is not directed at anyone under 18. We do not knowingly collect their data.
12Changes, and how to reach us
When we change this policy materially we will tell account holders by email before the change takes effect. The date at the top records when the wording was last reviewed, not when the site was last deployed.
Write to sales@govscape.app for anything in this policy.