Quick Summary: We only collect essential data to provide our service, process payments securely, and comply with legal requirements. We delete uploaded files immediately after processing and don't sell your data to anyone.
1. Data Controller
ScaleJet AI
DPO Contact: support@scalejet-ai.com
2. Data We Collect
Essential Service Data
- Account Information: Email address, name, encrypted password
- Usage Data: Transformation recipes, file processing history (file names only, not contents)
- Technical Data: IP address (for security), browser type, session data
Payment & Fraud Prevention
- Transaction Data: Payment history, billing information (processed by Stripe)
- Fraud Prevention: Payment attempt patterns, IP geolocation for suspicious activity detection
Data We DON'T Collect
- Contents of your CSV files (deleted immediately after processing)
- Tracking cookies or advertising data
- Social media connections
- Personal data beyond what's necessary for service provision
3. Legal Basis for Processing (GDPR Article 6)
- Contract Performance: Processing your data to provide transformation services
- Legitimate Interest: Fraud prevention, service security, system optimization
- Legal Obligation: Tax records, anti-money laundering compliance
- Consent: Marketing communications (opt-in only)
4. Data Retention
- Uploaded Files: Deleted within 1 hour of processing completion
- Account Data: Retained while account is active + 30 days after deletion
- Transaction Records: 7 years (UK/EU legal requirement for tax purposes)
- Security Logs: 90 days maximum
- Session Data: 30 days or until logout
5. Data Sharing
We share data only when necessary:
- Payment Processing: Stripe (PCI DSS compliant) for transactions
- AI Processing: OpenAI for code generation (no personal data, anonymized requests)
- Legal Requirements: Law enforcement if legally required
- No Marketing/Advertising: We never sell or share data for marketing purposes
6. International Transfers
Data may be processed outside the UK/EU by our service providers:
- OpenAI (USA): Standard Contractual Clauses, no personal data transferred
- Stripe (USA): Adequacy decision for payment processing
- All transfers include appropriate safeguards under GDPR Article 46
7. Your Rights (GDPR/UK GDPR)
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Delete your account and associated data
- Portability: Export your recipes and usage data
- Object: Opt-out of marketing communications
- Restrict Processing: Limit how we use your data
- Withdraw Consent: For consent-based processing
To exercise these rights, email: info@scalejet-ai.com
We'll respond within 30 days (1 month) as required by GDPR.
8. Security Measures
- End-to-end encryption for file uploads
- Secure password hashing (bcrypt)
- User optional 2FA
- Regular security audits and penetration testing
- Strict security policy with data protection in mind
- Access controls and audit logging
- Immediate file deletion after processing
9. Cookies
We use only essential cookies:
- Session Management: Keep you logged in securely
- Security: Prevent CSRF attacks and unauthorized access
- Functionality: Remember your preferences
No tracking, advertising, or analytics cookies are used.
10. Children's Privacy
Our service is not intended for users under 16. We don't knowingly collect data from children under 16. If you believe we have collected such data, please contact us immediately.
11. Data Breach Notification
In the event of a data breach affecting your personal data, we will:
- Notify relevant supervisory authorities within 72 hours
- Inform affected users without undue delay if high risk is involved
- Provide clear information about the breach and steps being taken
12. Contact & Complaints
Privacy Concerns / Data Protection Officer: info@scalejet-ai.com
General Support: support@scalejet-ai.com
You have the right to lodge a complaint with supervisory authorities:
- UK: Information Commissioner's Office (ICO) - ico.org.uk
13. Changes to This Policy
We may update this policy to reflect service changes or legal requirements. We'll notify users of material changes via email or prominent notice on our website.
14. Automated Decision Making
We use automated systems for:
- Fraud detection (you can request human review)
- AI-powered data transformations (user-initiated)
- No automated profiling or decisions that significantly affect you
Questions? Our privacy team is here to help. Email privacy@scalejet-ai.com for any questions about how we handle your data.
Document Version: 1.0 | Last Review: September 2025