Data processing
Most customers never need this page. It matters if you are an adviser putting a client’s information into Scalebiz, or if your own compliance team needs a written processing agreement on file.
Version 1.1 · 16 August 2026Which role applies to you
Scalebiz sits in one of two positions, and which one depends on what you put in.
Your own company data — we are the controller
When you enter your own business profile, we decide how that information is used, so we are the controller. The privacy policy governs it, and no separate agreement is needed.
Your clients’ data — we are the processor
When you enter information about a client business — by using your account on someone else’s behalf — you are the controller and we are your processor. Article 28 of the GDPR requires a written agreement between us, and the terms below are that agreement.
1. Subject and duration
We process personal data only to provide Scalebiz to you, for as long as your account is open, plus the deletion period below.
2. What is processed
| Categories of data | Categories of people |
|---|---|
| Business identification and registration details · sector and activity codes · size, stage and financial bands · funding needs and preferences · contact email · notes, pipeline entries and recorded outcomes · questions put to the assistant | Owners, directors and employees of the client businesses whose details you enter |
No special category data is required by Scalebiz, and you should not enter any. If you do, you remain responsible for having a lawful basis for it.
3. Our obligations
- We process only on your documented instructions. Using the product is an instruction; anything else you send us in writing.
- If a law requires us to process beyond your instructions, we tell you first unless that law forbids it.
- Everyone with access is bound by confidentiality.
- We apply the security measures set out below.
- We help you answer requests from individuals, and help with impact assessments and consultations, taking into account what we can actually see.
- We tell you about a personal data breach without undue delay, with what we know at the time.
4. Subprocessors
You consent to us using the following, and we tell you at least 30 days before adding another:
| Who | What for | Where |
|---|---|---|
| Supabase | Database, authentication, application logic | Ireland (EU) |
| OpenAI | Generating assistant answers | United States |
| n8n Cloud | Scheduled data collection and outgoing email | EU or US, set by the provider’s data centre |
| Hostinger | Website hosting and mail for hello@scalebiz.app | EU or US, set by the provider’s data centre |
Client data you enter is never sent to our payment provider. Payment data is handled separately and is described in the privacy policy.
If you object to a new subprocessor on reasonable data protection grounds, tell us within those 30 days and we will look for an alternative. If there is none, you may cancel without penalty and receive a refund for the unused period.
5. Transfers outside the EEA
Data reaches the United States (OpenAI) and Serbia (us). Both rely on the European Commission’s Standard Contractual Clauses, module three where applicable, together with encryption in transit and at rest and access limited to what a task requires. A copy is available on request.
6. Security measures
- Separation between accounts enforced by the database itself. Every table carries rules that make one account’s rows unreadable to another, so a mistake in application code cannot leak data across customers.
- Encryption in transit (TLS) and at rest.
- Passwords hashed, never stored or visible in readable form.
- Least privilege — each part of the system holds only the access its job needs, and the key that can bypass database rules never reaches a browser.
- Backups held by our database provider, restorable to a point in time.
- Logging of administrative access and scheduled jobs.
7. Helping individuals exercise their rights
If a person whose data you entered contacts us directly, we will not answer on your behalf. We will pass the request to you without undue delay and help you respond. Export and deletion are available to you in the product without needing us.
8. Deletion and return
On request, or when your account closes, we delete the personal data we process for you within 30 days, including from backups as they cycle out. Before that, you can export everything in a machine-readable file. Anything we must keep by law is kept only for that purpose and only for as long as required.
9. Audit
We will answer reasonable written questions about this agreement and provide what documentation we have. For an on-site audit we ask for 30 days’ notice, no more than once a year unless a regulator requires it, and that you cover the reasonable cost.
10. Liability
The liability terms in the terms of service apply to this agreement too, except where the GDPR provides otherwise.
Getting a signed copy
Many compliance teams need a countersigned document rather than a web page. Write to hello@scalebiz.app and we will send one, with your company’s details filled in, usually the same day.