Regarding the ISMS Scope Document, For the location, we are a remote company with a virtual address, we have an address for our data center, and if we should include it. Also, what should we exclude? we give laptops to our employees
Considering that, for certification purposes, you need to define at least one physical location which belongs to the organization. This one can be the address of the CEO's home, or some office rented by the organization for administrative purposes(like the company HQ).
Since you are a remote company, you should define your scope in terms of the data you want to protect (i.e., the physical data center should be excluded, but the data hosted in this data center should be included) and exclude all remote sites.
These articles will provide you with further explanation of ISMS scope definition: