GDPR Article 13 notice

Privacy Policy

This notice explains how SCALEUP.report processes personal data in the current product stack. Controller identity details are marked as placeholders until the operating legal entity is final.

Last updated: June 20, 2026

1. Controller

The controller for this service is [TBD: legal name and legal form], registered at [TBD: registered address]. The authorised representative is [TBD: managing director / authorised representative].

You can contact us at hello@scaleup.report.

2. Data categories, purposes, and legal bases

Contact by email link

When you use the contact mailto link, your message is sent through your own email client to hello@scaleup.report. We process the sender address, message content, timestamps, and any information you choose to include to respond to your inquiry and keep an engagement record. The legal bases are Article 6(1)(b) GDPR where the inquiry relates to a contract or pre-contractual steps, and Article 6(1)(f) GDPR for our legitimate interest in responding to business inquiries.

Authentication and account access

For invited users, we process account data, sign-in identifiers, membership context, authentication events, and a strictly necessary JWT session cookie to provide secure access and maintain the signed-in session. The legal bases are Article 6(1)(b) GDPR for providing the service and Article 6(1)(f) GDPR for security, fraud prevention, and auditability.

Product and AI-assisted report workflows

We may process engagement inputs, company context, uploaded or generated report materials, prompts, model outputs, review notes, and operational logs to create and manage SCALEUP.report deliverables. Where AI drafting helpers are used, the processing supports report generation and quality review. The legal bases are Article 6(1)(b) GDPR for service delivery and Article 6(1)(f) GDPR for maintaining reliable, auditable product operations.

3. Recipients and processors

  • Vercel: hosting, deployment, and runtime infrastructure. Processing may involve US transfer -> SCCs and equivalent contractual safeguards.
  • Neon: managed Postgres database storage for application records and audit data.
  • LiteLLM/AI provider: AI gateway and model processing for drafting and review assistance where enabled in the product workflow.

SMTP/email sending is not yet enabled in the application. The current public contact flow uses a mailto link rather than an application-operated email sending provider.

4. International transfers

Some processors, including hosting and AI infrastructure, may process personal data in the United States or make it accessible from the United States. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the European Commission Standard Contractual Clauses (SCCs) and supplementary measures where required.

5. Retention

We retain engagement, account, authentication, and audit records for 5 years after the relevant engagement or account relationship ends, unless a longer period is required by law or a shorter period is appropriate for a specific operational record.

6. Your rights

Subject to the conditions in the GDPR, you have the right to request access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. You also have the right to lodge a complaint with a competent supervisory authority.

7. Cookies

The current application uses an auth session cookie only. This JWT session cookie is strictly necessary to keep invited users signed in and to protect private application areas. We do not use analytics or marketing cookies in the current public scaffold.

8. Automated decision-making

We do not use solely automated decision-making, including profiling, that produces legal effects or similarly significant effects for individuals. AI-assisted drafting, where used, supports human review and report preparation.