Who we are.
Scalable S.L. ("Scalable", "we") is a Spanish limited company headquartered at Calle Serrano 41, 28001 Madrid, registered with the Madrid Mercantile Registry under CIF B-87.432.198. We are the data controller for our marketing site, our dashboard, and our employment data. For your customer data — the workloads, logs, and databases you run on our platform — you are the controller and we are the processor, governed by the Data Processing Agreement (DPA) included in our Terms.
EU representative · Art. 27 GDPR
Scalable EU Privacy GmbHKöpenicker Str. 154
10997 Berlin · Germany
Data Protection Officer
Anna Hofstetterprivacy@scalable.systems
PGP fingerprint: 4F9A · 8E10 · 22BC · 6D31
What we collect.
We collect three categories of data, and only these three. If we ever introduce a fourth, we'll bump this policy's major version and email every account holder thirty days before the change takes effect.
| Category | Examples | Source | Required? |
|---|---|---|---|
| Account data | Email, hashed password, org name, billing address, VAT ID | You, at sign-up | Yes |
| Usage data | Deploy events, region pinning, build logs, dashboard clicks | Your interaction with the platform | Yes |
| Telemetry | Browser, OS, IP (truncated to /24), referrer | Your browser, on dashboard pages only | Optional |
| — Customer data — | Anything you push to or run on the platform. We're the processor; the DPA governs. | ||
We collect the minimum needed to run the platform, send you a bill, and keep you logged in. Your code and your customers' data are yours; we just run them where you tell us to.
Why we collect it.
Account data is how we know who's logged in and who to bill. Usage data is how we tell you what you deployed last Tuesday and how it's behaving. Telemetry is how we find bugs in the dashboard. We do not — at any point — use any of this to train models, profile users, or sell to anyone outside the sub-processor list in §5.
Legal basis under GDPR.
- Performance of contract (Art. 6(1)(b)) — for everything required to run your account and deliver the service you signed up for.
- Legitimate interest (Art. 6(1)(f)) — for fraud prevention, security monitoring, and aggregate, non-identifying product analytics. You can object at any time.
- Legal obligation (Art. 6(1)(c)) — for tax records, AML screening (where applicable), and lawful disclosure to authorities.
- Consent (Art. 6(1)(a)) — for the optional dashboard telemetry and for any marketing email beyond the one-time onboarding sequence.
Sub-processors.
Our sub-processor list is a single, versioned, public document. It lives at scalable.systems/legal/subprocessors and is updated under change control. We will give every account at least thirty days' written notice before adding or changing any sub-processor, and you may object in writing — in which case we'll either find a workaround or terminate the affected service with a pro-rata refund.
| Sub-processor | Purpose | Region | DPA |
|---|---|---|---|
| Hetzner Online GmbH | Primary EU compute & storage | DE / FI | Signed |
| Amazon Web Services | Optional US/AP compute (BYOC) | US / SG / SA | SCCs |
| Google Cloud Platform | Optional BYOC, Vertex inference | US / EU | SCCs |
| Stripe Payments Europe | Card & SEPA processing | IE | Signed |
| Postmark | Transactional email | US | SCCs |
| Plausible Insights | Cookieless web analytics | EE | Signed |
| Sentry GmbH | Error monitoring (truncated PII) | DE | Signed |
International transfers.
Account data and EU-pinned customer data stay in the European Economic Area, full stop. If you opt into a non-EU region (e.g. us-east, ap-southeast) we transfer the data necessary to operate that region under EU Standard Contractual Clauses (2021/914) with supplementary measures: end-to-end encryption, key custody in the EU, and contractual challenge of any government access request.
If you pick an EU region, your data never leaves the EU. If you pick a US region, you've made that choice — but the keys still live with us in Madrid.
How long we keep it.
- Account data — for the lifetime of your account, plus 90 days after deletion (so you can change your mind), plus the minimum window required by Spanish tax law (6 years for invoices and books).
- Usage data — 30 days for build logs, 90 days for deploy events, 13 months for aggregated billing metrics.
- Telemetry — 14 days. Then deleted, not anonymised.
- Customer data — only as long as you tell us to. Delete a project, and we hard-delete from primary storage in 24h, from backups in 35 days.
Your rights.
Under GDPR (and most analogous regimes) you have the right to access, rectify, erase, restrict, port, and object. We've built every one of these into the dashboard so you don't need to email a lawyer to exercise them.
- Access & portability — Settings → Privacy → Export. JSON within minutes, large exports within 30 days.
- Erasure — Settings → Privacy → Delete account. Acted on within 24h. Confirmed by signed receipt.
- Object & restrict — Reply to any onboarding email or write to privacy@scalable.systems.
- Complaint — You may lodge one with the Spanish AEPD, or your local EU DPA, at any time.
Security, in one paragraph.
Signed audit log, MFA enforced for all employees with production access, hardware-backed key custody (Yubico + AWS CloudHSM), TLS 1.3 in transit, AES-256 at rest, code signed via Sigstore, and a public bug bounty paying up to CHF 25,000 per critical report. Reports go to security@scalable.systems; PGP key on the same page as this policy.
Children.
Scalable is a B2B platform for professional developers. We do not knowingly process the data of anyone under 16. If you believe we have, write to privacy@scalable.systems and we will delete the account within 24 hours.
Changes to this policy.
Material changes (new sub-processor, new data category, new retention period) trigger a new major version, a 30-day notice email to every account, and a banner in the dashboard. Cosmetic changes (typos, formatting) bump the minor version with no email, but every diff is published at github.com/scalable/legal with a signed commit hash.
How to reach us.
For privacy questions, complaints, or requests: privacy@scalable.systems. For security disclosures: security@scalable.systems. For everything else, the addresses below. We answer privacy mail within five working days, security mail within twenty-four hours, and breach notifications within seventy-two hours of detection — by contract, not by promise.
Controller — Spain
Scalable S.L.Calle Serrano 41
28001 Madrid · Spain
privacy@scalable.systems
EU Representative — Germany
Scalable EU Privacy GmbHKöpenicker Str. 154
10997 Berlin · Germany
eu-privacy@scalable.systems