Compliance Center
This page is maintained by ScaleLens AI Technologies to answer common security, privacy, and compliance questions about ScaleLens AI. It is app-owned editable content, not an independent certification.
Last updated: 7/27/2026
Privacy
ScaleLens AI Technologies is the data controller for personal data processed via the Service. We process account data, scan inputs (URLs you submit), scan outputs, support correspondence, telemetry, and payment metadata only for the purposes of providing and securing the Service. We do not sell personal data and we do not use customer content to train third-party AI models.
Full details — categories, legal bases, retention, international transfers — are in our Privacy Policy.
Data Processing Addendum (DPA)
For customers acting as data controllers under GDPR / UK GDPR who need a signed DPA to govern ScaleLens AI's processing of personal data on their behalf, we provide a standard DPA incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable.
- Roles: customer is controller; ScaleLens AI is processor for content you submit for scanning and for account telemetry tied to your tenancy.
- Sub-processing: we maintain the subprocessor list below and notify customers of material changes.
- Security: technical and organisational measures as described in the Security section below.
- International transfers: EU SCCs / UK IDTA, plus a transfer impact assessment on request.
- Sub-processor audits: annual review and on reasonable request.
Request the executable DPA by emailing legal@scalelensai.com with your legal entity name and contracting jurisdiction.
Subprocessors
ScaleLens AI uses the following subprocessors to deliver the Service. We notify customers of material changes via this page; if you would like email notifications, request inclusion in our subprocessor change list at privacy@scalelensai.com.
| Subprocessor | Purpose | Data categories | Region |
|---|---|---|---|
| Supabase (hosting, database, auth) | Application database, authentication, storage, edge functions. | Account data, scan inputs/outputs, audit logs. | United States / EU (multi-region) |
| Cloudflare (edge, CDN, Workers) | Edge compute, TLS termination, DDoS protection, static delivery. | IP address, request metadata, in-transit traffic. | Global edge |
| Paddle.com Market Ltd | Merchant of Record: checkout, billing, tax, invoicing, subscription management, refunds. | Billing name/address, email, payment metadata (no card data stored by us). | United Kingdom / EU / US |
| Resend | Transactional email delivery (verification, completion, alerts). | Recipient email, message content, delivery metadata. | United States / EU |
| Google AI (via managed gateway) | AI inference for audit generation. | Public page content submitted for analysis. No training on customer data. | United States / EU |
| OpenAI (via managed gateway) | AI inference for audit generation. | Public page content submitted for analysis. No training on customer data. | United States |
| Firecrawl | Fetching publicly accessible pages users submit for scanning. | Target URLs and rendered HTML. | United States |
Security
- Encryption in transit: TLS 1.2+ enforced on every public endpoint via Cloudflare.
- Encryption at rest: managed database and storage volumes encrypted with AES-256.
- Access control: Row-Level Security on every customer-facing table; admin actions gated by a separate
user_rolestable and security- definer functions; least-privilege service-role usage. - Auditability: every admin action (force-ship, fix delivery, role changes) is recorded in
admin_audit_logwith idempotency keys. - Secrets: webhook secrets, API keys, and signing tokens stored in secure server-only stores; never exposed to client bundles.
- SSRF protection: the scanner validates target URLs (public DNS only, no private/loopback ranges) before fetching.
- Webhook verification: Paddle and connector webhooks are signature-verified with timing- safe comparison.
- Monitoring: connector health pings, implementation-shipping workers, and webhook delivery rates are continuously monitored with admin alerts on failure.
- Backups: managed point-in-time recovery on the primary database.
Report a vulnerability: security@scalelensai.com. We acknowledge reports within two business days.
Payment regions & Merchant of Record
Paddle.com Market Ltd is the Merchant of Record for every ScaleLens AI order. Paddle handles checkout, billing, currency conversion, sales tax / VAT / GST, invoicing, refunds, and chargeback management on our behalf.
- Supported regions: Paddle supports buyers in 200+ countries; local payment methods and currencies are presented automatically at checkout.
- Tax compliance: Paddle calculates, collects, and remits VAT (EU/UK), GST (AU/NZ/IN/CA), US sales tax, and equivalent indirect taxes where required.
- PCI DSS: card data is handled exclusively by Paddle's PCI DSS Level 1 environment. ScaleLens AI never receives or stores raw card numbers.
- Invoices & receipts: issued by Paddle and available via paddle.net.
- Refunds: governed by our Refund Policy (30-day money-back guarantee) and processed through Paddle.
- Sanctioned regions: purchases from regions under applicable sanctions (e.g. those restricted by UK / EU / US OFAC programs) are blocked at checkout by Paddle.
AI use & content
- AI audits are generated by Google and OpenAI models through a managed gateway. Customer content is not used to train third-party foundation models.
- Outputs are advisory. For regulated industries (health, finance, legal), human review is required before publishing AI-suggested copy.
- Acceptable-use and takedown procedures are described in our Terms of Service.
Your rights
Subject to applicable law (GDPR, UK GDPR, CCPA/CPRA and equivalents), you may request access, rectification, erasure, restriction, portability, or object to processing, and withdraw consent where processing relies on it. We aim to respond within one month. Submit requests to privacy@scalelensai.com.
Contact
- Privacy & DPA requests: privacy@scalelensai.com
- Security disclosures: security@scalelensai.com
- Legal / contracts: legal@scalelensai.com
- Billing (via Paddle): paddle.net
