Data Processing Agreement
Last updated 24 August 2026
This agreement applies where Scaleur LLC (“Scaleur”, the processor) processes personal data on behalf of a customer (the controller) through the service. It forms part of our Terms of Service, and applies automatically — you do not need to sign a separate copy, though we will sign one on request.
1. Roles
You are the controller of personal data about your prospects, leads and contacts. We are the processor, acting on your documented instructions — which are: provide the service described in the Terms, and nothing else. We are the controller only for account data about the individuals who sign in to Scaleur, covered by our Privacy Policy.
2. What we process
- Subject matter and duration: providing the service, for as long as your account is active plus the deletion window in section 8.
- Nature and purpose: storing and organising prospect records; placing calls and sending messages you initiate; scheduling meetings; recording objective call outcomes; producing reports.
- Categories of data subject: your prospects, leads and customers; your own team members.
- Categories of personal data: names, email addresses, phone numbers, timezone, notes and pipeline history; call metadata and, where you enable it, call recordings; message content; meeting attendance; payment amounts and status. We do not receive card or bank details.
- Special category data: not requested, and not to be uploaded to Scaleur.
3. Our obligations
- Process personal data only on your documented instructions, including for transfers, unless law requires otherwise — in which case we will tell you first unless that law forbids it.
- Ensure everyone authorised to process the data is bound by confidentiality.
- Implement appropriate technical and organisational measures (section 9).
- Assist you, taking into account the nature of processing, with data subject requests, security, breach notification, and impact assessments.
- Make available the information needed to demonstrate compliance with these obligations.
4. Sub-processors
You give general authorisation for us to use sub-processors. The current list is published in our Privacy Policy. We will give at least 30 days’ notice before adding or replacing one, and you may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected service and receive a pro-rata refund of prepaid fees. We remain liable to you for a sub-processor’s performance.
5. Data subject requests
The service lets you access, correct, export and delete records yourself. If a data subject contacts us directly about your data, we will refer them to you rather than respond on your behalf, and we will help you respond where you ask.
6. Personal data breach
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a breach affecting personal data we process for you — with what we know about the nature of the breach, the categories and approximate number of records involved, the likely consequences, and the measures taken. We will not notify your data subjects on your behalf without your instruction.
7. International transfers
We process data in the United States. Where you transfer UK or EEA personal data to us, the parties rely on the UK Addendum and the EU Standard Contractual Clauses (controller-to-processor, Module Two), which are incorporated by reference, with this agreement supplying the details required by their annexes.
8. Return and deletion
You may export your data at any time while the account is active. On termination we keep it for 30 days so you can retrieve it, then delete it — including from backups on their ordinary rotation — except where law requires us to retain records. We will confirm deletion in writing on request.
9. Security measures
- Encryption of personal data in transit and at rest.
- Access to each customer's data restricted to that customer's workspace, enforced automatically on every release rather than by convention.
- Authentication through a dedicated identity provider; no passwords stored by us.
- Credentials for connected services stored server-side and never returned to a browser.
- Automated monitoring of service health, with alerting to the operator.
- Regular backups, and a documented restore procedure.
- Least-privilege access for personnel, removed when no longer needed.
10. Audit
On reasonable written notice, and no more than once a year unless a regulator or a breach requires otherwise, we will provide information reasonably necessary to demonstrate compliance with this agreement, and cooperate with audits carried out at your cost, in a way that does not compromise other customers’ confidentiality.
11. Liability
Liability under this agreement is subject to the limitations in the Terms of Service, except where applicable data protection law does not permit that.
Contact
Data protection enquiries: support@scaleur.com