Legal & compliance
Data Processing & UK GDPR
Controller/processor roles, processing instructions, sub-processors, breaches and transfers.
- Version
- 1.0
- Effective
- 29 August 2026
- Last updated
- 29 August 2026
Needs legal review: This page sets out the processing terms Scaleify operates to, written so it can be converted into a signed Data Processing Agreement. It has not been reviewed by a qualified UK data protection professional and the Article 28 clauses should be finalised with advice before it is offered as a contract.
1. Purpose of this page
Scaleify is used by UK businesses that handle personal data about their own prospects and contacts. This page explains, in Article 28 structure, how Scaleify processes that data on your behalf under the UK GDPR and the Data Protection Act 2018. It supplements our Privacy Policy and Terms of Service.
2. Controller and processor roles
- Scaleify as controller. Your account, business profile, subscription, credit ledger, support correspondence, security logs and aggregate product-usage records.
- Scaleify as processor, you as controller. Prospect and opportunity records saved into your workspace, contacts and pipeline data, tasks, message drafts and outreach content, team chat messages and attachments, Scaleify AI conversation content, ad-campaign briefs and creative you upload, and anything else you choose to store in the platform.
- Each provider listed in section 7 acts as our sub-processor for the data described there, or as an independent controller where they say so (for example the payment processor for its own compliance obligations).
3. Subject matter, duration, nature and purpose
- Subject matter: providing opportunity discovery, scoring, outreach drafting, CRM pipeline, automation, team collaboration and campaign functionality.
- Duration: for as long as your account is active, plus the retention periods in the Privacy Policy.
- Nature: collection from permitted public sources, storage, organisation, automated analysis using AI models, retrieval, display, transmission and deletion.
- Categories of data subject: your team members, and prospects and business contacts you research or save.
- Categories of personal data: names, usernames and handles, business names, publicly listed email addresses, phone numbers and websites, public post or listing content, pipeline notes and outreach content you create.
- Special category data: Scaleify is not designed for special category or criminal offence data and you must not upload it.
4. Processing instructions
We process customer personal data only on your documented instructions, which consist of these terms, the product settings you choose (searches, Scouts, automations, filters, integrations) and any lawful written instruction you give us in support. We will tell you if, in our view, an instruction breaches data protection law. We do not use customer workspace content to train third-party AI models on our initiative, and we do not sell it.
5. Confidentiality
Access to customer data is limited to people who need it to run and support the platform, under confidentiality obligations. Administrative access is role-gated and verified server-side, and privileged actions are recorded in an audit log.
6. Security measures
- Managed PostgreSQL with row-level security so each workspace can only read its own records.
- Server-side authorisation on every request; entitlements and credit charges cannot be set by the browser.
- Separate role table for privileged access, checked by a security-definer function, never by the client.
- Encryption in transit (HTTPS) and encryption at rest provided by the managed database and storage layers.
- Uploaded files served through short-lived signed URLs rather than public buckets.
- Signature-verified payment webhooks and idempotent handling of billing and credit events.
- Secrets held server-side only; database triggers guard tenant links against tampering.
Needs legal review: Backup frequency, restore testing, formal incident-response timings and any certification claims must be documented and verified before they are stated publicly. Scaleify does not currently claim ISO 27001, SOC 2 or any other certification.
7. Sub-processors
You authorise the sub-processors below. We will give reasonable notice before adding or replacing one, and you may object on reasonable data protection grounds, in which case we will work with you or you may terminate.
- Lovable Cloud (managed Supabase infrastructure) — Application hosting, PostgreSQL database, authentication, file storage. Data: Account, business, opportunity, pipeline, messaging and billing records; uploaded files.
- Cloudflare Workers (edge runtime used by the hosting platform) — Serving the application and running server-side functions. Data: Request metadata including IP address and browser user agent.
- Lovable AI Gateway (routing to Google Gemini and OpenAI models) — Opportunity analysis, message drafting, Scaleify AI chat. Data: The content of the public post or listing being analysed, your business profile context, and prompts you send.
- Stripe — Payment processing, subscriptions, checkout, invoices. Data: Billing email, subscription and payment records. Scaleify never receives or stores full card numbers.. Active only when this integration is configured.
- Tavily, Brave Search, Serper (Google Search API) and the official Reddit API — Searching permitted public indexes for buying-intent signals. Data: Search queries derived from your business profile and Scout configuration. Active only when this integration is configured.
- Google (Sign in with Google) — Optional third-party sign-in. Data: Your Google account email and basic profile, only if you choose that sign-in method. Active only when this integration is configured.
- Transactional email provider — Account, security and service notification emails. Data: Email address and message contents. Active only when this integration is configured.
8. Data subject rights
You control the rights requests of your own contacts and prospects. The product lets you search, edit, export and delete workspace records so you can respond. If a data subject contacts us directly about data held in your workspace, we will not respond substantively on your behalf; we will pass the request to you and help you handle it.
9. Processor assistance
Taking into account the nature of processing and the information available to us, we will assist you with security obligations, breach notification, data protection impact assessments and prior consultation with the ICO where relevant.
10. Personal data breaches
If we become aware of a personal data breach affecting your data we will notify you without undue delay, with the information we hold about what happened, the categories and approximate volume affected, likely consequences and the steps taken. Where we are controller, we will notify the ICO within 72 hours where the breach is notifiable, and affected individuals where the risk is high.
11. International transfers
Some sub-processors operate outside the UK, including in the United States. Transfers rely on UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses, with appropriate supplementary measures. You must not instruct a transfer that would breach UK data protection law.
12. Deletion and return
You can delete workspace records at any time in the product. On termination, and at your choice, we will delete or make available for export the customer personal data we hold as processor, except where we must retain it by law. Backups age out on their normal cycle.
13. Audit and information
We will make available the information reasonably necessary to demonstrate compliance with these processing terms and contribute to audits carried out by you or an auditor you appoint, subject to reasonable notice, confidentiality and not compromising other customers' security.
14. Your obligations as controller
- Have a lawful basis for researching and contacting prospects, and provide any privacy information required.
- Honour objections and opt-out requests you receive, and keep your workspace records accurate.
- Do not upload special category data, or data you are not permitted to process using cloud AI services.
- Comply with electronic-marketing rules and platform terms when you make contact — see the Acceptable Use Policy.
15. Signing a DPA
If your organisation requires a countersigned Data Processing Agreement, request one at [DATA PROTECTION CONTACT EMAIL]. The signed version will follow the structure of this page, with the parties recorded as [LEGAL COMPANY NAME] and your organisation.