Scalebiz

Privacy policy

Scalebiz processes information about your company so it can tell you which grants, tenders, investors, loans and guarantee schemes you actually qualify for. This page explains exactly what we hold, why, and what you can do about it.

Version 1.1 · 16 August 2026

1. Who is responsible for your data

The data controller is Robert Grabarević, a sole trader registered in Serbia and trading as Scalebiz, at Primorska 37, Subotica. Registration number 68456479, tax number 115555768.

For anything about your data, write to hello@scalebiz.app. We answer within one business day and, on formal requests under the GDPR, within one month.

We are established outside the European Union. Because we offer this service to businesses in the EU, the GDPR applies to us in full under Article 3(2) and we hold ourselves to it.

2. What we collect

When you create an account

  • Email address and a password, which is never stored in readable form.
  • Your name, if you give it.
  • The date you signed up and when you last used the service.

Your business profile — the part that drives everything

  • Company name, country of registration and legal form.
  • Industry, activity codes and focus areas.
  • Company stage, number of employees and revenue band.
  • Which markets you want searched, which funding types you want, and the amount you need.

These are business facts rather than personal ones, but for a sole trader they can also identify a person — so we treat the whole profile as personal data.

What you do in the product

  • Opportunities you save, shortlist or move through your pipeline, with the amounts and outcomes you record.
  • Notes you write on an item.
  • Your questions to the assistant and the answers it gave, including which sources each answer used.
  • Whether you marked an answer as helpful, and any comment you added.
  • Counts of how often you use features, so plan limits can be applied.

Consent records

When you agree to something — these terms, or receiving email — we record what you agreed to, which version, when, and the IP address and browser the agreement came from. That record exists so we can prove consent was given, which the GDPR requires of us.

What we do not collect

  • No payment card details. Card data goes straight to Paddle, our payment provider, and never reaches us. We never see or store a card number.
  • No special category data — health, beliefs, political opinions, biometrics.
  • No data about anyone under 18. This is a business product.
  • No advertising or tracking profiles, and we do not sell data to anyone, ever.

3. Why we process it, and on what legal basis

PurposeLegal basis
Running your account and matching your profile against funding programmesPerformance of a contract — Article 6(1)(b)
Answering your questions in the assistantPerformance of a contract — Article 6(1)(b)
Sending the digest and deadline reminders you have not turned offPerformance of a contract — Article 6(1)(b); every channel can be switched off
Keeping the service secure and preventing abuseLegitimate interests — Article 6(1)(f)
Improving how matching and scoring work, using aggregated and anonymised figuresLegitimate interests — Article 6(1)(f)
Marketing email that is not part of the serviceConsent — Article 6(1)(a), withdrawable in one click
Taking payment, issuing invoices and meeting accounting and tax obligationsPerformance of a contract — Article 6(1)(b); legal obligation — Article 6(1)(c)

4. How the matching works, and what it does not decide

Every opportunity is scored against your profile automatically. We think you are entitled to know how, so here it is in full.

First, hard eligibility is checked. If a programme is closed to your country, your company size or your legal form, it is removed entirely and no score is calculated. What passes is then scored out of 100:

  • Geography — 40 points. How well your country and region fit the programme’s coverage.
  • Sector and focus — 30 points. Your activity and keywords against the programme’s theme.
  • Deadline — 20 points. How much realistic time is left to apply.
  • Your preferences — 10 points. The funding types and amounts you asked for.

This is a ranking of public information, not a decision about you. It does not approve or refuse anything, it has no legal effect, and no funder ever sees it. Article 22 of the GDPR — automated decisions that significantly affect a person — does not apply. You can still ask us to explain any individual score, and we will.

5. Artificial intelligence and your data

The assistant sends your question, your business profile and the matching opportunities to OpenAI, which generates the answer. Under the terms that apply to our account, OpenAI does not use this data to train its models and retains it only briefly for abuse monitoring.

We do not train any model on your data, and we never use one customer’s information to answer another customer’s question.

6. Who else touches your data

Each of these works only on our instructions, under a written contract, except where noted.

WhoWhat forWhere
SupabaseDatabase, sign-in, application logicIreland (EU)
OpenAIGenerating assistant answersUnited States
n8n CloudScheduled jobs that collect funding data and send emailEU or US, set by the provider’s data centre
HostingerWebsite hosting and outgoing email for hello@scalebiz.appEU or US, set by the provider’s data centre
Paddle.com Market LtdMerchant of record: taking payment, invoicing and tax. Paddle is the seller for your purchase and decides how it handles your payment data, so for that data it acts in its own right and not only on our instructions.United Kingdom

Where a provider’s data centre sits outside the European Economic Area, the transfer is covered by the safeguards in the next section. We will name the exact region on request, and we will state it here as soon as each provider confirms it in writing.

We update this table before adding anyone new.

7. Sending data outside the EU

Your data leaves the European Economic Area in two ways: it goes to the United States when the assistant generates an answer, and it reaches us in Serbia when we operate the service. Neither transfer is covered by a general adequacy decision, so both rely on the European Commission’s Standard Contractual Clauses together with technical measures — encryption in transit and at rest, and access limited to what a task requires.

You can ask us for a copy of these arrangements at any time.

8. How long we keep things

WhatHow long
Your account and business profileUntil you delete the account
Assistant conversationsUntil you delete the account. Hiding a conversation removes it from your list but keeps it readable to you.
Saved opportunities and pipelineUntil you delete them, or the account
Usage counts12 months
Consent records3 years after the consent ends, as evidence
Invoices and accounting recordsAs long as tax law requires

When you ask us to delete your account, the request is recorded and everything is erased within 30 days. The delay exists so a mistaken or unauthorised deletion can be undone, and you can cancel the request yourself during that window.

9. Your rights

Under the GDPR you can ask us to:

  • Show you everything we hold about you.
  • Correct anything wrong — most of it you can edit yourself in your profile.
  • Delete your data.
  • Hand it over in a machine-readable file, or send it to another provider.
  • Restrict what we do with it while a dispute is open.
  • Object to processing we base on legitimate interests.
  • Withdraw consent at any time, without affecting what was lawful before.

Two of these you can do yourself, immediately, without asking us: export everything and delete your account, both from your account settings. For the rest, write to hello@scalebiz.app.

If you think we have handled your data badly, you can complain to the data protection authority in the EU country where you live or work, or to Serbia’s Commissioner for Information of Public Importance and Personal Data Protection. We would rather you told us first, but that is your right and it is not conditional on anything.

10. Cookies and what your browser stores

Signing in stores a session token in your browser. Without it you would be signed out on every click, so it is strictly necessary and needs no consent.

There is no analytics on this site. We do not run Google Analytics or any comparable tool, we set no advertising cookies, and we build no profile of your visit. That is why you are not asked to accept cookies — there is nothing to accept. If we ever add analytics, we will ask first and this section will say so before it runs.

One exception remains: inside the signed-in application, the code library that talks to our database is loaded from a public code network, so that network sees the request and therefore your IP address. It receives nothing else — no page, no account, no content. We are moving it onto scalebiz.app as well.

11. Keeping it safe

  • Everything is encrypted in transit and at rest.
  • Database rules make it impossible for one account to read another’s rows — enforced by the database itself, not by application code.
  • Passwords are hashed and never visible to us.
  • Access to production is limited to what a task requires.

No system is perfect. If a breach ever puts your rights at risk, we will notify the supervisory authority within 72 hours and tell you without undue delay.

12. Changes to this policy

If we change something that matters, we will email you before it takes effect and raise the version number at the top. Small corrections are published here with a new date.

Operator Robert Grabarević, sole trader registered in Serbia, trading as Scalebiz Primorska 37, Subotica, Serbia Registration number 68456479 · Tax number 115555768 hello@scalebiz.app