Controller at a glance
- Controller
- Scaleo Solutions s.r.o.
- ID / VAT No.
- 276 34 051 · CZ27634051
- Registered office
- V přístavu 1585/10, 170 00 Prague, Czech Republic
- Commercial Register
- Municipal Court in Prague, file No. C 120368
- Contact
- info@scaleo.ai
- Supervisory authority
- Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7 — uoou.gov.cz, tel. +420 234 665 111
00Introduction
About Scaleo. We are Scaleo Solutions s.r.o., ID No.: 276 34 051, VAT No.: CZ27634051, with its registered office at V přístavu 1585/10, 170 00 Prague, Czech Republic, registered in the Commercial Register maintained by the Municipal Court in Prague under file No. C 120368 (“we”, “us”, “our”). We operate an online marketplace that connects Advertisers and Affiliates with integrated features of the SaaS platform, which enables Advertisers and Affiliates to structure, monitor, analyze, and manage affiliate marketing data and campaigns (“Platform”). More information on how the platform works is available on our website located at www.scaleo.ai (“Website”).
Capitalised terms. Capitalised terms not defined in this document have the meanings given to them in the Advertiser Terms or Affiliate Terms, as relevant to your role (“Agreement”). Where the same term is defined in multiple documents, the definition in this Policy prevails.
This Policy. This Policy applies to situations where we act as the Controller (mostly when you use the Platform, visit our Website, or communicate directly with us). This Policy applies to every natural person who (a) creates an account on the Platform, whether as an Advertiser or an Affiliate, and (b) any visitor who merely browses the Website. This Policy also explains how you can object to certain uses of information about you and how you can access and update certain information about you. If you do not agree with this Policy, please do not access or use our Website or Platform.
Our Role. The Platform supports the following privacy-related roles:
- Scaleo acts as Controller for limited purposes, specifically, account registration, billing, and compliance data necessary to operate the Platform.
- When an Advertiser enters into a service agreement with an Affiliate, and the Affiliate submits lead or conversion data about an end customer to the Platform, the Affiliate and Advertiser act as independent or joint Controllers, or Controller-Processor of that end-customer data. In this case, Scaleo acts only as a Processor on behalf of the Advertiser, strictly following their instructions based on the Advertiser Terms. Please refer to our Data Processing Agreement embedded into the Advertiser Terms for more information about our processor role.
Contact. You can contact us at any time by email info@scaleo.ai or by sending notice to V přístavu 1585/10, 170 00 Prague, Czech Republic.
Updates. We will provide at least 30 days’ prior notice of material changes via Website banner or by sending email notice. Any non-material changes shall be implemented without communication.
01Definitions
“Agreement” has a meaning ascribed in the “Capitalised terms” section above.
“Controller” means the entity which determines the purposes and means of the Personal Data processing.
“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
“Personal Data” means any information about the natural person that can either directly identify them or possibly identify them indirectly with the use of other Personal Data we have available about the User.
“Policy” means this Privacy Policy.
“Platform” has a meaning ascribed in the “About Scaleo” section above.
“Processor” means a third party we engage to support the operation of the Platform, such as cloud service providers, security vendors, or other technology partners who assist us in delivering and protecting our services. These entities may process personal data that users have provided to us, but only based on our documented instructions and subject to strict contractual obligations under a data processing agreement (DPA).
“Supervisory Authority” means the Office for Personal Data Protection, which can be contacted at uoou.gov.cz/en and Pplk. Sochora 27, 170 00 Praha 7, the Czech Republic, or by dialing tel. +420 234 665 111.
“User”, “you” or “your” means the natural person to whom the Personal Data is related, our potential or existing customer (Affiliate or Advertiser using our marketplace), visitor of our Website, or communication counterparty.
“We”, “us”, “our” means Scaleo Solutions s.r.o. as defined in the “About Scaleo” section above.
“Website” has a meaning ascribed in the “About Scaleo” section above.
02Personal data and purposes of processing
User of the Website. When you are browsing or using our Website, the following Personal Data may be processed by us:
| Legal basis | Purpose | Retention term | Personal data |
|---|---|---|---|
| ConsentArticle 6.1 a) GDPRor Legitimate interest — Article 6.1 f) GDPR | Provision of the basic functions of our Website, analytics, improvements of our Services etc., with the help of cookies. | The period of processing varies depending on the cookie type. See our cookie policy for more information. | IP address, the date and time of the visit, operation system, language settings, history of behavior on the Website, data concerning mobile phone etc. |
| Legitimate interestArticle 6.1 f) GDPR | Defending against and tracing attacks by hackers, protecting our Website. | The IP addresses are stored for no more than 1 month. | We store the IP addresses of all users who access our Website. The logs created are only used to monitor security breaches. |
| Steps prior to entering into a contractArticle 6.1 b) GDPR | Processing of the User’s data when he/she completes our contact form on the Website or provides Personal Data otherwise. | Closed inquiries are deleted regularly, but no later than 3 years of the date of the inquiry. |
|
User of the Services. If the User chooses to enter into a contract with us on behalf of a legal entity he/she duly represents and use our Platform, we will process the User’s Personal Data only to the extent necessary to provide the Services in accordance with the Affiliate Terms or Advertiser Terms:
| Legal basis | Purpose | Retention term | Personal data |
|---|---|---|---|
| Performance of the contractArticle 6.1 b) GDPR | Conclusion and execution of the Agreement to start using the Services to the fullest extent. Creation and maintenance of the Master Account in the extent necessary to provide all the features of the Service. Provision of any other agreed upon Services (e.g., dealing with service requests). | For the term of the Agreement and for one month afterwards, to let you export data from the Master Account. |
|
| Legal requirementsArticle 6.1 c) GDPR | We must process Personal Data when the law requires us to do so. This concerns mainly accounting and tax regulations. | For the period required by the legislation (Czech Accounting Act §31 normally requires retention for 10 years from the end of the financial year in which the tax/accounting event occurred). |
|
| Legitimate interestArticle 6.1 f) GDPR | Where we believe it is necessary to protect our legal rights, interests and the interests of others, we may use the Personal Data in connection with legal claims, compliance, regulatory or audit functions. | For a period of up to 3 years, which corresponds to the longest statute of limitations period, unless a dispute started. |
|
The Controller does not knowingly process any special categories of Personal Data.
03Processing activities
Processors. We only engage verified Processors with whom a written agreement has been concluded, ensuring that they offer at least the same level of guarantees as those provided to the User as per this Policy. We use mainly the following service providers and partners:
- Third-party service providers. We use third-party service providers to provide us with Website and Platform development, hosting, maintenance, backup, storage, payment processing, analysis, marketing, and other services. If a service provider needs to access information about you to perform services on our behalf, they do so under close instruction from us, including appropriate security and confidentiality procedures designed to protect your information.
- Consultants. We may use consultants who help us in the areas of taxes, accounting, law or other areas.
A list of our Processors is available on request.
Employees and contractors. We may make the User’s Personal Data available to its employees and contractors who provide services related to the processing of Personal Data as described herein.
Legal obligations. We may disclose Personal Data to third parties, other than the Processors mentioned above, if required by law or in response to lawful requests from public authorities or pursuant to a court order in connection with legal proceedings.
Transfers outside the EEA. We may transfer Personal Data to recipients, including our Processors and service providers, located outside the European Economic Area. In all such cases, we ensure that appropriate safeguards are in place to provide a level of data protection essentially equivalent to that within the European Union. Where the European Commission has not issued an adequacy decision for the recipient country pursuant to Article 45 GDPR, we rely on appropriate safeguards under Article 46 GDPR, including the European Commission’s Standard Contractual Clauses (SCCs), supplemented as necessary with additional technical and organisational measures.
No minors. Our services are intended exclusively for business use by individuals aged 18 or older. We do not knowingly collect personal data from minors, and we implement access restrictions accordingly. If we become aware that we have received Personal Data from a child or minor without parental or legal consent, appropriate steps will be taken to promptly delete such information.
04Security measures
We implement commercially reasonable technical, administrative, and organizational measures to protect the Users’ Personal Data from loss, misuse, unauthorized access, disclosure, alteration, or destruction. However, as no method of data transmission is 100% secure or error-free, we advise you to exercise caution when deciding which Personal Data to share.
Technical measures.
- HTTPS and encryption. We use a secure HTTPS protocol, and all data transfers are encrypted using SSL/TLS.
- Backup. Daily backups of all data and files are performed.
- Data center. The Platform operates on AWS, a leader in physical and software security, with regular stress and penetration tests to ensure resilience.
- Updates. Regular infrastructure updates are performed.
- Application security. Access is secured by unique usernames and passwords, with options for 2FA and customizable permissions for data access.
- Other security measures. Additional hardware, software, and procedural measures are implemented to enhance data security.
Organizational measures.
- Confidentiality. All employees are bound by confidentiality obligations.
- Staff training. Our employees receive regular training on Personal Data protection and security protocols.
- Data processing logging. We log access to Personal Data, including any changes or deletions, with a retroactive record of 30 days.
- Access control. Only authorized personnel can access Personal Data, within their specific scope of responsibility.
- Safe storage. Passwords are stored securely in a separate environment with access logs.
- Transfer control. Measures are in place to protect Personal Data from unauthorized access during transfer or storage.
- Internal audit. Regular audits can be conducted to minimize Personal Data processing and ensure appropriate security measures are maintained.
05Rights of the data subjects
Rights description. The Users have the following rights concerning the processing of the Personal Data:
- Access to the Personal Data. The User may request information on whether the Personal Data is processed by the Controller, and upon such request, the Controller must also provide access to that Personal Data.
- Correction. The User may request the correction of inaccurate Personal Data or the completion of incomplete Personal Data held by the Controller.
- Right to erasure (right to be forgotten). Under certain conditions, the User may request the erasure of their Personal Data or the restriction of its processing. The Controller is obliged to comply with such requests where applicable.
- Right to restrict. If the User believes that the Controller is processing their Personal Data incorrectly, whether regarding the reasons for processing or the scope of the Personal Data being processed, the User is encouraged to contact the Controller.
- Right to data portability. Upon the User’s request, the Controller will provide the Personal Data that the User has supplied in a structured, commonly used, and machine-readable format for transfer to another controller.
- Right to lodge a complaint. If the User believes that their Personal Data is being processed unlawfully, they have the right to lodge a complaint with the Supervisory Authority.
- Right to withdraw consent. Only applies to the situations where consent is given. If the User changes their mind, they may inform the Controller at any time. Consent to the processing of the Personal Data for marketing and commercial purposes can be revoked at any time without affecting the lawfulness of processing based on the consent before its withdrawal.
- Right to object. The User has the right to object to the processing of their Personal Data when it is based on the Controller’s legitimate interests. This objection can be made by sending an email to the Controller’s contact address. The Controller will investigate the objection and provide a response within one month of receiving the request.
The Controller will not process Personal Data using automated individual processing that would have legal effects on the User as a data subject or affect the User in a similarly significant way.
Execution of rights. You may contact us to exercise the aforesaid rights by using the contact details provided in this Privacy Policy. To help us process your request efficiently, please include your full name and contact details. If necessary, we may ask for additional information to verify your identity and ensure the security of your data. Please note that submitting this request on behalf of another person will require provision of a document proving authority.
Response times. We aim to respond to all valid requests within 30 days of receipt. If your request is complex or we receive multiple requests, we may extend this period by an additional 30 days. In such cases, we will notify you of the extension and explain the reasons for the delay. We provide responses to most requests free of charge. However, if a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee or refuse to process the request.