LegalPrivacy Policy v4.2 GDPRArticle 13 / 14 compliant

Your data, in plain words
and fewer of them.

This page explains what data Scalable holds, why we hold it, who else sees it, and how to take it back. It's binding. It's also short on purpose: a privacy policy nobody reads is a privacy policy nobody can hold us to.

Last updated
1 May 2026
Effective
15 May 2026
Previous version
v4.1 · 12 Nov 2025
Reading time
~9 minutes
TL;DR — the seven things

The short version, if that's all you need.

  • We don't sell your data. Ever. No ad networks, no brokers, no "partners."
  • EU residency by default. Your account & logs live in eu-central unless you pick otherwise.
  • You own your customer data. We're the processor, you're the controller. Export, delete, port — one click.
  • One sub-processor list. Public, versioned, with 30-day notice on changes.
  • No tracking pixels on this site. First-party analytics only, no cookies before consent.
  • Encryption end-to-end. At rest (AES-256), in transit (TLS 1.3), in keys (HSM-backed).
  • Breach disclosure within 72h. To regulators and to you. By contract.

Who we are.

Scalable S.L. ("Scalable", "we") is a Spanish limited company headquartered at Calle Serrano 41, 28001 Madrid, registered with the Madrid Mercantile Registry under CIF B-87.432.198. We are the data controller for our marketing site, our dashboard, and our employment data. For your customer data — the workloads, logs, and databases you run on our platform — you are the controller and we are the processor, governed by the Data Processing Agreement (DPA) included in our Terms.

EU representative · Art. 27 GDPR
Scalable EU Privacy GmbH
Köpenicker Str. 154
10997 Berlin · Germany
Data Protection Officer
Anna Hofstetter
privacy@scalable.systems
PGP fingerprint: 4F9A · 8E10 · 22BC · 6D31

What we collect.

We collect three categories of data, and only these three. If we ever introduce a fourth, we'll bump this policy's major version and email every account holder thirty days before the change takes effect.

CategoryExamplesSourceRequired?
Account data Email, hashed password, org name, billing address, VAT ID You, at sign-up Yes
Usage data Deploy events, region pinning, build logs, dashboard clicks Your interaction with the platform Yes
Telemetry Browser, OS, IP (truncated to /24), referrer Your browser, on dashboard pages only Optional
— Customer data — Anything you push to or run on the platform. We're the processor; the DPA governs.
Plain

We collect the minimum needed to run the platform, send you a bill, and keep you logged in. Your code and your customers' data are yours; we just run them where you tell us to.

Why we collect it.

Account data is how we know who's logged in and who to bill. Usage data is how we tell you what you deployed last Tuesday and how it's behaving. Telemetry is how we find bugs in the dashboard. We do not — at any point — use any of this to train models, profile users, or sell to anyone outside the sub-processor list in §5.

Sub-processors.

Our sub-processor list is a single, versioned, public document. It lives at scalable.systems/legal/subprocessors and is updated under change control. We will give every account at least thirty days' written notice before adding or changing any sub-processor, and you may object in writing — in which case we'll either find a workaround or terminate the affected service with a pro-rata refund.

Sub-processorPurposeRegionDPA
Hetzner Online GmbHPrimary EU compute & storageDE / FISigned
Amazon Web ServicesOptional US/AP compute (BYOC)US / SG / SASCCs
Google Cloud PlatformOptional BYOC, Vertex inferenceUS / EUSCCs
Stripe Payments EuropeCard & SEPA processingIESigned
PostmarkTransactional emailUSSCCs
Plausible InsightsCookieless web analyticsEESigned
Sentry GmbHError monitoring (truncated PII)DESigned

International transfers.

Account data and EU-pinned customer data stay in the European Economic Area, full stop. If you opt into a non-EU region (e.g. us-east, ap-southeast) we transfer the data necessary to operate that region under EU Standard Contractual Clauses (2021/914) with supplementary measures: end-to-end encryption, key custody in the EU, and contractual challenge of any government access request.

Plain

If you pick an EU region, your data never leaves the EU. If you pick a US region, you've made that choice — but the keys still live with us in Madrid.

How long we keep it.

  • Account data — for the lifetime of your account, plus 90 days after deletion (so you can change your mind), plus the minimum window required by Spanish tax law (6 years for invoices and books).
  • Usage data — 30 days for build logs, 90 days for deploy events, 13 months for aggregated billing metrics.
  • Telemetry — 14 days. Then deleted, not anonymised.
  • Customer data — only as long as you tell us to. Delete a project, and we hard-delete from primary storage in 24h, from backups in 35 days.

Your rights.

Under GDPR (and most analogous regimes) you have the right to access, rectify, erase, restrict, port, and object. We've built every one of these into the dashboard so you don't need to email a lawyer to exercise them.

  • Access & portability — Settings → Privacy → Export. JSON within minutes, large exports within 30 days.
  • Erasure — Settings → Privacy → Delete account. Acted on within 24h. Confirmed by signed receipt.
  • Object & restrict — Reply to any onboarding email or write to privacy@scalable.systems.
  • Complaint — You may lodge one with the Spanish AEPD, or your local EU DPA, at any time.

Security, in one paragraph.

Signed audit log, MFA enforced for all employees with production access, hardware-backed key custody (Yubico + AWS CloudHSM), TLS 1.3 in transit, AES-256 at rest, code signed via Sigstore, and a public bug bounty paying up to CHF 25,000 per critical report. Reports go to security@scalable.systems; PGP key on the same page as this policy.

Cookies. Three of them.

CookiePurposeLifetimeSet when
__sc_sessionKeeps you logged inSessionYou sign in
__sc_csrfCross-site request forgery defence1 hourEvery request to dashboard
__sc_consentRemembers your cookie choice12 monthsYou click a banner button

That's it. No third-party cookies, no advertising IDs, no fingerprinting, no retargeting pixels. Marketing pages use server-rendered, cookieless analytics (Plausible) hosted in Estonia.

Children.

Scalable is a B2B platform for professional developers. We do not knowingly process the data of anyone under 16. If you believe we have, write to privacy@scalable.systems and we will delete the account within 24 hours.

Changes to this policy.

Material changes (new sub-processor, new data category, new retention period) trigger a new major version, a 30-day notice email to every account, and a banner in the dashboard. Cosmetic changes (typos, formatting) bump the minor version with no email, but every diff is published at github.com/scalable/legal with a signed commit hash.

How to reach us.

For privacy questions, complaints, or requests: privacy@scalable.systems. For security disclosures: security@scalable.systems. For everything else, the addresses below. We answer privacy mail within five working days, security mail within twenty-four hours, and breach notifications within seventy-two hours of detection — by contract, not by promise.

Controller — Spain
Scalable S.L.
Calle Serrano 41
28001 Madrid · Spain
privacy@scalable.systems
EU Representative — Germany
Scalable EU Privacy GmbH
Köpenicker Str. 154
10997 Berlin · Germany
eu-privacy@scalable.systems
Document · privacy-policy@v4.2 Signed commit · 3a8f10d Print as PDF Read the Terms of Service →