Privacy

Privacy Policy

Formation respects your privacy and is committed to handling information responsibly. This page sets out how Formation collects, uses, discloses, retains, and protects information across its websites, applications, software, services, and related communications.

Effective Date: July 21, 2026Last Updated: July 21, 2026

Scope Tennis Inc., a Delaware corporation doing business as Formation.ai (“Formation.ai,” “Scope,” “we,” “us,” or “our”), respects your privacy and is committed to handling information responsibly. This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you visit tryformation.ai, access app.tryformation.ai, or otherwise interact with our websites, applications, software, services, and related communications (collectively, the “Services”). Formation.ai provides a business-to-business commercial intelligence platform. Our Services help sports organisations and other business customers organise, analyse, and report on aggregated commercial, sponsorship, audience, ticketing, media, and social-media performance data.

1. Scope of This Privacy Policy

This Privacy Policy applies to:

This Privacy Policy does not apply to third-party websites, platforms, or services that operate under their own privacy policies.

  • Visitors to our public website;
  • Authorised users of the Formation.ai application;
  • Representatives of customers, prospective customers, suppliers, and business partners;
  • Individuals who contact us or request support; and
  • Information processed through integrations used to provide the Services.

2. Our Role

Depending on the circumstances, Formation.ai may act in different capacities.

Information relating to our customers and users

Formation.ai acts as a controller or business when we determine why and how personal information is processed, including account administration, security, customer communications, service improvement, and our own business operations.

Customer data processed through the Services

When a customer provides information to Formation.ai or connects a third-party data source for analysis through the Services, the customer generally determines the purposes for which that information is processed. In those circumstances, the customer acts as the controller or business, and Formation.ai acts as its processor or service provider. Our processing of customer data is also governed by our agreement with the relevant customer, including any applicable data processing agreement.

3. Information We Collect

Formation.ai is designed primarily to process aggregated business and performance data rather than consumer-level personal information. We may nevertheless collect or process the following limited categories of personal information.

A. Account and authentication information

When an authorised user accesses the application, we may process:

Authentication may be managed by a third-party identity provider. Formation.ai does not receive or store a user’s full password from that provider.

  • Name;
  • Business email address;
  • Employer or organisation;
  • User, organisation, and workspace identifiers;
  • Account role and access permissions;
  • Authentication records;
  • Login dates and times; and
  • Information needed to secure and administer the account.

B. Technical and usage information

When someone uses the Services, we may automatically collect:

We use this information to operate, secure, troubleshoot, and improve the Services.

  • IP address;
  • Browser and device type;
  • Operating system;
  • Application events and activity logs;
  • Pages or features accessed;
  • Request timestamps;
  • Error, diagnostic, and performance information;
  • Security and authentication events; and
  • Cookie or similar technology identifiers where applicable.

C. Communications and support information

If you communicate with us, we may collect:

  • Your name and contact information;
  • The organisation you represent;
  • The contents of your request or message;
  • Support correspondence;
  • Feedback; and
  • Related records needed to respond to you.

D. Customer-provided business data

Customers may provide or connect data such as:

Customers are responsible for ensuring that they have the right to provide this information to Formation.ai. Formation.ai does not require customers to provide individual ticket-buyer records, direct consumer identifiers, or other unnecessary consumer-level information. Customers should not upload sensitive personal information or individual-level personal information unless expressly agreed in writing.

  • Sponsorship rights and deliverables;
  • Partner and sponsor information;
  • Event and matchday information;
  • Media exposure and placement records;
  • Campaign and activation information;
  • Aggregated ticketing or attendance data;
  • Aggregated audience and engagement metrics;
  • Commercial performance information;
  • Reports, spreadsheets, presentations, and supporting documents; and
  • Other business information selected by the customer.

E. Social-media integration data

A customer may authorise Formation.ai to connect to its owned or managed social-media accounts through official platform APIs. Depending on the platform and permissions granted, we may process:

engagement metrics;

These integrations are intended to retrieve read-only performance data relating to customer-owned accounts. Formation.ai does not intentionally retrieve or analyse:

Although social-media performance metrics are generally stored and analysed in aggregated form, certain account names, public content, administrator details, identifiers, or authentication credentials may constitute personal information under applicable law. A customer can revoke Formation.ai’s access through the relevant platform or by contacting us.

  • Social-media account and page identifiers;
  • Account name and public profile information;
  • Connected-account status;
  • Post or content identifiers;
  • Publication timestamps;
  • Content type and associated metadata;
  • Aggregated views, reach, impressions, likes, comments, saves, shares, and
  • Aggregated account or follower counts;
  • Historical metric snapshots;
  • API synchronisation status and error records; and
  • OAuth tokens or similar credentials needed to maintain the authorised connection.
  • Private direct messages;
  • Passwords for social-media accounts;
  • Individual follower profiles;
  • Lists identifying people who viewed or engaged with content;
  • Personal audience profiles; or
  • Data from accounts that the customer has not authorised Formation.ai to access.

F. Information from third parties

We may receive information from:

  • The organisation that invited you to use the Services;
  • Authentication and identity providers;
  • Social-media platforms connected by a customer;
  • Hosting, security, and technical service providers;
  • Business partners;
  • Publicly available business sources; and
  • Other parties acting at your or a customer’s direction.

4. How We Use Information

We may use information to:

or security threats;

We do not use customer data to make decisions that produce legal or similarly significant effects concerning individual consumers. We do not sell customer data or personal information for money. We do not use customer-provided confidential information or connected social-media data for third-party advertising.

  • Provide, operate, and maintain the Services;
  • Create and administer user accounts and workspaces;
  • Authenticate users and manage permissions;
  • Import, organise, and analyse customer-authorised data;
  • Generate answers, calculations, reports, and business insights;
  • Synchronise authorised social-media performance data;
  • Maintain historical performance snapshots;
  • Map performance data to events, campaigns, rights, or commercial assets;
  • Provide customer support;
  • Communicate about accounts, security, service changes, and transactions;
  • Monitor performance and troubleshoot errors;
  • Protect the Services, customers, and users against unauthorised access, fraud, abuse,
  • Enforce our agreements and policies;
  • Improve and develop the Services;
  • Comply with legal obligations; and
  • Establish, exercise, or defend legal claims.

5. Legal Bases for Processing

Where the European Economic Area or United Kingdom data-protection laws apply, we rely on one or more of the following legal bases:

Performance of a contract

We process account and service information when necessary to provide the Services or take requested steps before entering into a contract.

Legitimate interests

We may process information where necessary for legitimate business interests, including:

We consider the nature of the information, the impact of the processing, and the rights of affected individuals before relying on legitimate interests.

  • Operating and improving the Services;
  • Managing customer relationships;
  • Providing support;
  • Protecting our systems and users;
  • Preventing fraud and misuse;
  • Understanding service performance; and
  • Conducting ordinary business administration.

Compliance with legal obligations

We may process information when necessary to comply with applicable legal, regulatory, accounting, tax, or law-enforcement requirements.

Consent

Where required, we rely on consent, including for certain optional cookies, communications, or account integrations. You may withdraw consent at any time, although withdrawal does not affect processing that occurred before consent was withdrawn.

6. How We Disclose Information

We may disclose information in the following circumstances.

A. Service providers

We use service providers to support functions such as:

These providers may process information only as necessary to provide their services to Formation.ai and subject to applicable contractual and confidentiality obligations. Our current technology infrastructure may include providers such as Microsoft Azure, Clerk, GitHub, n8n, database and storage providers, and artificial-intelligence service providers.

  • Cloud hosting and computing;
  • Database hosting;
  • File storage;
  • Authentication;
  • Application deployment;
  • Workflow automation;
  • Monitoring and security;
  • Email and business communications;
  • Artificial-intelligence infrastructure;
  • Data analysis; and
  • Customer support.

B. Customers and authorised users

Information contained within a customer workspace may be accessible to that customer’s authorised users according to their assigned roles and permissions.

C. Customer-authorised integrations

When a customer connects a third-party platform, information may be exchanged with that platform as necessary to authenticate the connection, retrieve authorised data, or maintain the integration. Use of third-party platforms remains subject to their own terms and privacy policies.

D. Legal and safety disclosures

We may disclose information when we reasonably believe it is necessary to:

  • Comply with law, regulation, legal process, or a governmental request;
  • Enforce our agreements;
  • Protect the rights, property, or safety of Formation.ai, our customers, users, or others;
  • Detect or prevent fraud, abuse, or security incidents; or
  • Establish, exercise, or defend legal claims.

E. Corporate transactions

Information may be disclosed as part of a merger, financing, acquisition, reorganisation, sale of assets, bankruptcy, or similar corporate transaction, subject to appropriate confidentiality protections.

F. At your or the customer’s direction

We may disclose information where an authorised person or customer instructs or authorises us to do so.

7. Artificial Intelligence and Automated Analysis

Formation.ai uses automated systems and artificial-intelligence technologies to help customers search, summarise, analyse, and report on authorised business data. Outputs may be generated from:

Formation.ai may transmit relevant portions of a request and supporting data to contracted artificial-intelligence infrastructure providers where needed to generate a response. We apply contractual, technical, and organisational controls intended to limit provider use of customer data. However, customers should not submit personal, sensitive, or confidential information that is unnecessary for the requested analysis. AI-generated responses may be incomplete or inaccurate and should be reviewed by an appropriate person before being relied upon for significant business decisions.

  • Customer-provided documents and structured data;
  • Aggregated performance metrics;
  • Social-media API data;
  • Sponsorship, event, and exposure records;
  • Calculation methodologies; and
  • Other authorised business sources.

8. Cookies and Similar Technologies

Our public website and application may use cookies, local storage, or similar technologies that are necessary to:

Where we use non-essential analytics or advertising cookies, we will provide any consent choices required by applicable law. You may be able to control cookies through your browser settings. Disabling necessary cookies may prevent parts of the Services from functioning correctly.

  • Authenticate users;
  • Maintain sessions;
  • Remember settings;
  • Protect the Services;
  • Prevent fraud;
  • Measure technical performance; and
  • Diagnose errors.

9. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, comply with contracts, resolve disputes, enforce agreements, maintain security, and satisfy legal obligations. Retention periods depend on factors such as:

Account and authentication records are generally retained while the relevant account or customer relationship remains active and for a reasonable period afterward. Customer data is retained in accordance with the applicable customer agreement and may be deleted or returned following termination, subject to backup cycles, legal requirements, and legitimate security or recordkeeping needs. OAuth tokens and integration credentials are retained only while needed to maintain the authorised connection and may be deleted or invalidated when the integration is disconnected. Aggregated or de-identified information that can no longer reasonably identify an individual may be retained for analytics, research, service improvement, benchmarking, or other lawful business purposes.

  • The duration of the customer relationship;
  • Customer instructions;
  • The type and sensitivity of the information;
  • Operational and security requirements;
  • Backup and disaster-recovery cycles;
  • Applicable limitation periods; and
  • Legal, tax, accounting, and regulatory obligations.

10. Data Security

We use administrative, technical, and organisational safeguards designed to protect information against accidental or unlawful destruction, loss, alteration, disclosure, or access. These safeguards may include:

No method of transmission or storage is completely secure. We therefore cannot guarantee absolute security. Users are responsible for protecting their login credentials, using secure devices, and promptly notifying us of suspected unauthorised access.

  • Access controls and role-based permissions;
  • Authentication controls;
  • Encryption in transit;
  • Encryption or protected storage for credentials and tokens;
  • Segregated customer workspaces;
  • Logging and monitoring;
  • Restricted administrative access;
  • Secure cloud infrastructure;
  • Backup and recovery procedures; and
  • Security review and testing.

11. International Data Transfers

Formation.ai is operated by a United States company and uses service providers that may process information in the United States, the European Economic Area, the United Kingdom, or other countries. As a result, information may be transferred to or accessed from a country whose data-protection laws differ from those in your jurisdiction. Where required by law, we use recognised safeguards for international transfers, which may include:

You may contact us for additional information about the safeguards applicable to a particular transfer.

  • Adequacy decisions;
  • Standard contractual clauses;
  • The United Kingdom International Data Transfer Addendum or equivalent safeguards;
  • Data processing agreements; and
  • Supplementary technical and organisational measures.

12. Your Privacy Rights

Depending on your location and applicable law, you may have the right to:

These rights may be limited or subject to exceptions under applicable law. Where we process personal information solely on behalf of a customer, we may refer your request to that customer or ask you to submit the request directly to the customer. To exercise a privacy right, contact us using the information in Section 17. We may need to verify your identity and authority before completing a request. You will not be discriminated against for exercising a privacy right.

  • Request access to personal information we hold about you;
  • Request correction of inaccurate information;
  • Request deletion of personal information;
  • Request restriction of processing;
  • Object to certain processing;
  • Request a portable copy of certain information;
  • Withdraw consent where processing is based on consent;
  • Opt out of certain sales, sharing, targeted advertising, or profiling;
  • Appeal a decision concerning a privacy request; and
  • Lodge a complaint with a data-protection authority.

13. California Privacy Information

California residents may have rights under the California Consumer Privacy Act, as amended, subject to statutory thresholds, exceptions, and limitations. The categories of personal information we may collect include:

We collect and use these categories for the business and commercial purposes described in this Privacy Policy. Formation.ai does not sell personal information for monetary consideration. Formation.ai does not knowingly sell or share the personal information of individuals under 16 years of age. To the extent Formation.ai engages in activity legally defined as “sharing” for cross-context behavioural advertising, California residents may opt out by contacting us or using any privacy-control mechanism we make available. Formation.ai will honour legally recognised browser-based opt-out preference signals where required and technically applicable.

  • Identifiers;
  • Internet or electronic network activity;
  • Professional or employment-related information;
  • Commercial and customer-account information;
  • Communications with Formation.ai; and
  • Inferences relating to the use, security, or performance of our Services.

14. European Economic Area and United Kingdom Rights

Individuals located in the European Economic Area or United Kingdom may have rights under the GDPR or UK GDPR, including rights of access, rectification, erasure, restriction, objection, and data portability. Where processing is based on legitimate interests, you may object to that processing based on your particular circumstances. You may lodge a complaint with the supervisory authority in the country where you live, work, or believe a violation occurred. Individuals in the United Kingdom may contact the Information Commissioner’s Office. Formation.ai is a United States company. Where legally required, we will appoint an EU or UK representative and publish the relevant representative’s contact information in this Privacy Policy.

15. Children’s Privacy

The Services are intended for businesses and authorised business users. They are not directed to children under 13, and we do not knowingly collect personal information directly from children under 13. The Formation.ai application should be accessed only by individuals authorised by a customer organisation and legally capable of entering into the applicable agreement. If you believe a child has provided personal information to us, contact us so that we can investigate and take appropriate action.

16. Third-Party Services

The Services may contain links to or integrations with third-party websites, applications, and platforms. Formation.ai does not control those third parties and is not responsible for their privacy, security, or data-handling practices. You should review the applicable third-party privacy policy before providing information or enabling an integration. Disconnecting an integration from Formation.ai does not necessarily delete information retained independently by the relevant third-party platform.

17. Contact Us

Questions, concerns, and privacy requests may be sent to: Scope Tennis Inc. d/b/a Formation.ai [Street Address] [City, State, ZIP Code] United States Privacy email: [privacy@tryformation.ai or other designated address] General website: tryformation.ai Application: app.tryformation.ai For privacy requests, please include enough information for us to understand the request and identify the relevant account or customer relationship. Do not send passwords, authentication tokens, or other sensitive credentials by email.

18. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our Services, technology, legal obligations, or business practices. When we make changes, we will revise the “Last Updated” date above. Where required by law, we will provide additional notice or obtain consent before material changes take effect. Your continued use of the Services following the effective date of an updated Privacy Policy is subject to the updated policy, except where applicable law requires a different form of notice or consent.