Information We Collect
Account and Registration Data
When you create a ScopeBase.AI account, we collect your name, company name, email address, phone number, business address, and password (stored as a salted hash). We also collect your NAICS codes, certifications (DBE, WBE, MBE, HUB, VetHUB, SDVOSB, 8(a), HUBZone, ACDBE), and UEI/SAM.gov registration details as part of your contractor profile.
Platform Usage Data
We collect data generated through your use of the platform, including RFP documents you upload, proposal sections and project data you create, subcontractor outreach activity, teaming arrangements, bid/no-bid decisions, and cost estimates.
Email Intelligence Data (KKAI)
If you enable the KKAI email integration, we process inbound procurement-related email messages from your designated procurement inbox. See Section 3 for full details.
Payment and Billing Data
Payment processing is handled by Stripe, Inc. We do not store full credit card numbers. We retain billing records including subscription tier, payment history, and invoice data.
Technical and Usage Data
We automatically collect IP addresses, browser type, operating system, pages visited, session duration, and error logs for security monitoring and service improvement.
Single Sign-On (SSO) Data
If you sign in using Microsoft Entra ID (Azure Active Directory), we receive your name, email address, and Microsoft account identifier from Microsoft. We do not receive your Microsoft password.
How We Use Your Information
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Providing the ScopeBase.AI platform | Account data, project data, RFP uploads | Contract |
| AI-powered RFP analysis and proposal drafting | RFP documents, past performance, company profile | Contract |
| Subcontractor matching and outreach | NAICS codes, certifications, project requirements | Contract |
| Email procurement intelligence (KKAI) | Designated procurement inbox (with your authorization) | Contract |
| Billing and subscription management | Payment data, subscription tier | Contract |
| Security and fraud prevention | IP addresses, session data, login activity | Legitimate Interest |
| Platform improvement and model training | Anonymized, aggregated usage data only | Legitimate Interest |
| Legal compliance and recordkeeping | Account and transaction records | Legal Obligation |
We do not use your proposal content, RFP documents, or procurement strategy data to train AI models without your explicit written consent. Anonymized, aggregated platform usage patterns (not document content) may be used to improve ScopeBase.AI features.
Email Intelligence — KKAI Integration
What KKAI Accesses
When you authorize KKAI integration, we access inbound email messages in your designated procurement inbox. We read, parse, and classify emails to identify solicitation notices, pre-solicitation announcements, sources-sought requests, RFP amendments, and award notifications from federal agencies, state purchasing portals, and cooperative contract distributors.
What KKAI Does Not Access
- We do not access emails outside the designated procurement inbox you specify
- We do not access sent mail, drafts, contacts, calendar, or any folder you have not authorized
- We do not store the full content of email messages — we extract and store only the procurement-relevant structured data (solicitation number, deadline, agency, NAICS codes, opportunity type)
- We do not share your email content with third parties
Data Retention for KKAI
Extracted procurement opportunity data is retained for the duration of your subscription plus 90 days. Raw email message content is not retained — only the structured data extracted from each message is stored.
Revoking KKAI Access
You may revoke KKAI access at any time from your account settings. Revoking access immediately stops all email processing. Previously extracted structured data remains in your account until deleted.
AI-Generated Content and Intellectual Property
ScopeBase.AI uses AI models to generate proposal drafts, technical approach sections, management plans, past performance narratives, compliance matrices, and cost estimates. The following applies to all AI-generated content produced by the platform:
Ownership
AI-generated content produced using your firm's data (past performance, capability statements, key personnel profiles, and RFP documents you upload) is owned by you. VeAssis LLC does not claim ownership of proposal content generated on your behalf.
Review Responsibility
All AI-generated proposal sections are presented for your review and approval before submission. You are responsible for reviewing, modifying, and approving all content before use in any proposal or procurement submission. VeAssis LLC does not guarantee the accuracy, compliance, or competitiveness of AI-generated content.
No Cross-Client Use
Your proposal content, RFP documents, and procurement strategy data are never used in generating content for other clients. Client data is strictly isolated by tenant within the ScopeBase.AI platform.
Data Sharing and Third Parties
We do not sell, rent, or trade your personal data or business information. We share data only in the following limited circumstances:
| Recipient | Purpose | Data Shared |
|---|---|---|
| Stripe, Inc. | Payment processing | Billing and subscription data |
| Anthropic PBC | AI model inference (Claude API) | Document content for processing — subject to Anthropic's data handling policies |
| OpenAI | AI model inference (select features) | Document content for processing — subject to OpenAI's data handling policies |
| DocuSign | LOI document signing | LOI document content and signatory information |
| Microsoft | SSO authentication and (if purchased via Marketplace) subscription management | Authentication tokens and subscription status |
| Law enforcement or regulators | Legal obligation | Minimum required by applicable law or court order |
All third-party service providers are contractually required to handle data in accordance with applicable privacy laws and may not use your data for their own purposes.
Data Retention
We retain your data for the following periods:
- Account data: Duration of subscription plus 90 days after cancellation, then deleted upon request or automatically within 180 days
- Project and proposal data: Duration of subscription plus 90 days
- RFP documents uploaded: Duration of subscription plus 90 days
- KKAI extracted opportunity data: Duration of subscription plus 90 days
- Billing and transaction records: 7 years (required for tax and legal compliance)
- Security and access logs: 90 days
You may request early deletion of your data at any time by contacting [email protected]. Deletion requests are processed within 30 days, subject to legal retention requirements.
Data Security
We implement industry-standard security measures to protect your data:
- All data in transit is encrypted using TLS 1.2 or higher
- Passwords are hashed using bcrypt with per-user salts — plaintext passwords are never stored
- Access tokens are JWT-based with 1-hour expiration and secure, HttpOnly cookie storage
- The platform is protected by Cloudflare CDN with DDoS mitigation, WAF, and HSTS preload
- Database access is restricted to application-layer connections — no public database endpoints
- Multi-factor authentication is available for all accounts and required for administrator access
- Security headers including CSP, X-Frame-Options, and X-Content-Type-Options are enforced on all endpoints
In the event of a data breach affecting your information, we will notify affected users within 72 hours of discovery as required by applicable law.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
| Right | Description | How to Exercise |
|---|---|---|
| Access | Request a copy of the personal data we hold about you | Email [email protected] |
| Correction | Request correction of inaccurate or incomplete data | Account settings or [email protected] |
| Deletion | Request deletion of your data (subject to legal retention requirements) | Email [email protected] |
| Portability | Request your data in a structured, machine-readable format | Email [email protected] |
| Objection | Object to processing based on legitimate interests | Email [email protected] |
| Restriction | Request restriction of processing while a dispute is resolved | Email [email protected] |
We respond to all rights requests within 30 days. Requests may be subject to identity verification. Texas residents may also contact the Texas Attorney General's office regarding privacy rights under the Texas Data Privacy and Security Act (TDPSA).
Microsoft Marketplace Customers
If you subscribed to ScopeBase.AI through the Microsoft Commercial Marketplace, the following additional terms apply:
- Microsoft shares your name, email address, company name, and subscription details with VeAssis LLC for fulfillment purposes
- Your subscription is managed jointly by Microsoft (billing and entitlement) and VeAssis LLC (platform access and service delivery)
- Microsoft's privacy policies apply to the purchase transaction and Microsoft account authentication. ScopeBase.AI's privacy policy applies to your use of the platform after authentication
- You may manage your subscription through either the Microsoft Azure portal or directly through your ScopeBase.AI account settings
Government Contractor Data Handling
ScopeBase.AI serves organizations that compete for government contracts. We recognize that procurement strategy, teaming arrangements, proposal content, and cost estimates may constitute sensitive business information. We treat all such data as confidential business information and apply the following protections:
- Your proposal content and procurement strategy data are never shared with other clients or used to generate content for competitors
- Subcontractor outreach data and teaming arrangements are visible only to your account users
- Cost estimates, pricing strategies, and bid/no-bid decisions are not disclosed to any third party
- RFP documents and solicitation materials are stored encrypted and accessible only to your account
ScopeBase.AI does not currently hold FedRAMP authorization. Organizations subject to DFARS 252.204-7012 (Safeguarding Covered Defense Information) or handling Controlled Unclassified Information (CUI) should review their contractual obligations before uploading CUI to the platform.
Cookies and Tracking
ScopeBase.AI uses the following cookies and local storage:
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| access_token | Authentication session | 1 hour | Essential |
| sub_access_token | Subcontractor session | 1 hour | Essential |
| oauth_state | Microsoft SSO CSRF protection | 10 minutes | Essential |
| cf_clearance | Cloudflare security verification | 1 year | Essential |
We do not use advertising cookies, cross-site tracking, or analytics platforms that share data with third parties. Essential cookies cannot be disabled as they are required for the platform to function.
Children's Privacy
ScopeBase.AI is a business-to-business platform intended for use by organizations and business professionals. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided us with personal data, please contact [email protected] and we will delete that information promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email at the address associated with your account and by posting a notice on the ScopeBase.AI platform at least 14 days before the changes take effect.
Continued use of ScopeBase.AI after the effective date of a revised Privacy Policy constitutes your acceptance of the changes. If you do not agree to the revised policy, you may cancel your subscription before the effective date.
The version history of this policy is maintained and available upon request.
Contact Us
For privacy inquiries, data rights requests, or questions about this policy:
VeAssis LLC — Privacy Contact
Email: [email protected]
Mailing Address: VeAssis LLC, 110 N IH 35, Ste 315 #3295, Round Rock, TX 78681
Schedule a Call: calendar.app.google/nZu7eLfuZVjD31Nz9
Response time: within 5 business days for general inquiries, within 30 days for data rights requests.
VeAssis LLC is a certified DBE, WBE, MBE, HUB, and ACDBE small business operating in 40+ jurisdictions. EIN: 93-1970104 | UEI: M3V5YJJ62QL5