Scalebiz

Data processing

Most customers never need this page. It matters if you are an adviser putting a client’s information into Scalebiz, or if your own compliance team needs a written processing agreement on file.

Version 1.1 · 16 August 2026
Operator Robert Grabarević, sole trader registered in Serbia, trading as Scalebiz Primorska 37, Subotica, Serbia Registration number 68456479 · Tax number 115555768 hello@scalebiz.app

Which role applies to you

Scalebiz sits in one of two positions, and which one depends on what you put in.

Your own company data — we are the controller

When you enter your own business profile, we decide how that information is used, so we are the controller. The privacy policy governs it, and no separate agreement is needed.

Your clients’ data — we are the processor

When you enter information about a client business — by using your account on someone else’s behalf — you are the controller and we are your processor. Article 28 of the GDPR requires a written agreement between us, and the terms below are that agreement.

1. Subject and duration

We process personal data only to provide Scalebiz to you, for as long as your account is open, plus the deletion period below.

2. What is processed

Categories of dataCategories of people
Business identification and registration details · sector and activity codes · size, stage and financial bands · funding needs and preferences · contact email · notes, pipeline entries and recorded outcomes · questions put to the assistant Owners, directors and employees of the client businesses whose details you enter

No special category data is required by Scalebiz, and you should not enter any. If you do, you remain responsible for having a lawful basis for it.

3. Our obligations

  • We process only on your documented instructions. Using the product is an instruction; anything else you send us in writing.
  • If a law requires us to process beyond your instructions, we tell you first unless that law forbids it.
  • Everyone with access is bound by confidentiality.
  • We apply the security measures set out below.
  • We help you answer requests from individuals, and help with impact assessments and consultations, taking into account what we can actually see.
  • We tell you about a personal data breach without undue delay, with what we know at the time.

4. Subprocessors

You consent to us using the following, and we tell you at least 30 days before adding another:

WhoWhat forWhere
SupabaseDatabase, authentication, application logicIreland (EU)
OpenAIGenerating assistant answersUnited States
n8n CloudScheduled data collection and outgoing emailEU or US, set by the provider’s data centre
HostingerWebsite hosting and mail for hello@scalebiz.appEU or US, set by the provider’s data centre

Client data you enter is never sent to our payment provider. Payment data is handled separately and is described in the privacy policy.

If you object to a new subprocessor on reasonable data protection grounds, tell us within those 30 days and we will look for an alternative. If there is none, you may cancel without penalty and receive a refund for the unused period.

5. Transfers outside the EEA

Data reaches the United States (OpenAI) and Serbia (us). Both rely on the European Commission’s Standard Contractual Clauses, module three where applicable, together with encryption in transit and at rest and access limited to what a task requires. A copy is available on request.

6. Security measures

  • Separation between accounts enforced by the database itself. Every table carries rules that make one account’s rows unreadable to another, so a mistake in application code cannot leak data across customers.
  • Encryption in transit (TLS) and at rest.
  • Passwords hashed, never stored or visible in readable form.
  • Least privilege — each part of the system holds only the access its job needs, and the key that can bypass database rules never reaches a browser.
  • Backups held by our database provider, restorable to a point in time.
  • Logging of administrative access and scheduled jobs.

7. Helping individuals exercise their rights

If a person whose data you entered contacts us directly, we will not answer on your behalf. We will pass the request to you without undue delay and help you respond. Export and deletion are available to you in the product without needing us.

8. Deletion and return

On request, or when your account closes, we delete the personal data we process for you within 30 days, including from backups as they cycle out. Before that, you can export everything in a machine-readable file. Anything we must keep by law is kept only for that purpose and only for as long as required.

9. Audit

We will answer reasonable written questions about this agreement and provide what documentation we have. For an on-site audit we ask for 30 days’ notice, no more than once a year unless a regulator requires it, and that you cover the reasonable cost.

10. Liability

The liability terms in the terms of service apply to this agreement too, except where the GDPR provides otherwise.

Getting a signed copy

Many compliance teams need a countersigned document rather than a web page. Write to hello@scalebiz.app and we will send one, with your company’s details filled in, usually the same day.