Osiris Scout
SupportLog inStart workspace
Privacy

Privacy notice

This notice explains how Osiris Systems Limited handles account, workspace, evidence, billing and product-usage information in Scout.

Effective 3 August 2026 · Version 2026-08-03-draft

Legal review required before productionThis implementation is a complete operational draft. Counsel and the service owner must approve the liability cap, retention schedule, processor register and transfer safeguards before launch.
Make a privacy requestOpen Support

Controller and contact

Osiris Systems Limited is the controller for Scout account and service data. Company number 14900922; registered office 115 New Bridge Street, Newcastle Upon Tyne, United Kingdom, NE1 8ST. Privacy questions and rights requests can be sent to hello@osirissystems.co.uk with the subject “Privacy request”.

Information we collect

We process account identity and contact details; workspace membership and preferences; company profiles and uploaded evidence; opportunity decisions, notes and application drafts; billing status and Stripe references; security and technical logs; support correspondence; and limited page or interaction events. Public opportunity records generally come from the named public source rather than from the customer.

Purposes and legal bases

We use account, workspace and billing data to provide the contracted service; security logs and abuse controls for our legitimate interests in protecting Scout and its users; billing records to meet legal obligations; optional product communications with consent where required; and support or product-usage information for our legitimate interests in resolving problems and improving the service. We balance those interests against user rights and provide an objection route.

AI processing

When AI assessment is enabled, relevant opportunity text and selected company context may be sent to the configured AI provider to produce fit analysis or drafting assistance. Users must review outputs and should not upload special-category, confidential or personal information unless their organisation has a lawful reason and authority to process it. Scout does not use automated assessment to make legally binding decisions about individuals.

Processors and recipients

The service is designed to use Vercel for the web application, DigitalOcean for backend hosting and storage, Stripe for subscription billing, OpenAI for configured AI functions, and the configured transactional-email provider for account messages. Professional advisers or authorities receive information only where needed for legal, security or compliance purposes. The final deployment register must confirm the exact providers before production launch.

International transfers

Some providers may process information outside the United Kingdom. Before production use, each transfer must be covered by an adequacy regulation or an approved transfer mechanism such as the UK International Data Transfer Agreement or UK Addendum, together with a documented transfer-risk assessment where required.

Retention and deletion

Workspace content is retained while the account is active and for the closure period needed to provide an export and complete deletion. Contract, invoice and payment records may be retained for up to six years where required. Security logs, support records, analytics events, uploaded documents and backups must follow the approved production retention schedule; the exact periods and automated deletion evidence must be confirmed before launch.

Browser storage and analytics

Scout uses essential cookies for authenticated sessions and security, plus browser local storage for interface preferences, cached session display and safe local draft recovery. Limited first-party usage events help determine whether setup and core workflows are completed. Non-essential analytics or marketing storage must not be enabled without the consent controls required by law.

Uploaded evidence documents

Owners and admins can upload supported evidence files. Files are size- and format-checked, security-scanned where configured, and text is extracted for company assessment context. Authorised workspace users can access the files. Customers should remove material that is no longer needed and avoid uploading secrets, payment-card data or information they are not authorised to share.

Your rights

Depending on the circumstances, individuals can ask for access, correction, deletion, restriction, portability or objection, and can withdraw consent without affecting earlier lawful processing. We may need to verify identity and can retain information where a legal exception applies. Send requests to hello@osirissystems.co.uk; we normally respond within one month.

Complaints and changes

Contact us first so we can investigate. You may also complain to the UK Information Commissioner’s Office at ico.org.uk. We will identify the effective version of this notice and communicate material changes through the service or account contact where appropriate.

Osiris Scout
TermsPrivacyRefundsSupport