⚠️ Draft — not yet legally binding
This document is an internal first draft awaiting review and approval by ScaleLogix AI's CTO and legal counsel. It describes how the product works today, but it has not been reviewed by a lawyer and must not be relied on as a binding agreement or as a complete statement of your rights. Sections still needing a business or legal decision are marked ⚠️ REVIEW below.
Privacy Policy
What ScaleLogix AI collects, why we collect it, who we share it with, and the choices you have.
Last updated: August 26, 2026Version privacy-2026-08-26
1. About this policy
This policy explains what personal data ScaleLogix AI handles, why we handle it, who we share it with, and what choices you have. It covers the ScaleLogix AI OS platform — the marketing site, the AI Revenue Audit funnel, the agency dashboard, the client portal, and the AI voice, chat, website, and outreach services delivered through them.
The platform is sold to agencies, which in turn serve their own business clients, which in turn serve consumers. Because a single record can belong to any of those layers, section 2 sets out who is responsible for what before the rest of the policy describes the data itself.
⚠️ Review
Confirm the contracting legal entity (registered company name, company number, and registered address) that publishes this policy, and whether a Data Protection Officer, an EU representative, or a UK representative must be named here. None of these are stated anywhere in the product today.
2. Who controls which data
ScaleLogix AI OS is multi-tenant. Data sits at one of four levels, and the responsible party differs at each:
| Layer | Example data | Who decides how it is used |
|---|---|---|
| ScaleLogix platform | Your login, your organisation record, billing, support history, security logs | ScaleLogix AI, as controller |
| Agency organisation | Agency staff accounts, agency branding, agency workspace settings | ScaleLogix AI, as controller, for account administration |
| Agency’s business clients | Client company records, contacts, projects, installed packages | The agency, as controller. ScaleLogix processes on its instructions |
| End consumers | Callers, website chat visitors, leads, appointment bookers | The agency and its client, as controllers. ScaleLogix processes on their instructions |
In plain terms: for your own ScaleLogix account we decide how data is used. For the customer and consumer data you load into or generate through the platform, youdecide, and we act on your instructions. If you are a consumer who spoke to an AI voice agent or filled in a form on a business's website, the business you contacted is your first point of contact — see section 12.
⚠️ Review
This is the controller/processor split the architecture implies, but it is not yet backed by a signed Data Processing Agreement. Decide whether ScaleLogix offers a DPA (and standard contractual clauses) to agency customers, and link it here. Do not claim a DPA is available until one exists.
3. What we collect
Account and organisation data
Authentication is handled by Supabase Auth, which stores your email address, your name, and your credentials. Alongside it we store your organisation record (billing and contact email, contact phone), your role and workspace memberships, and pending invitations.
Access requests
The platform is invite-only. When you ask for access we collect your name, email address, phone number, company, your message, your answers to the qualifying questions, and — for abuse prevention on a public, unauthenticated form — your IP address and browser user agent.
AI Revenue Audit
The audit funnel collects business-profile answers (industry, business model, team size, lead sources, current CRM, and the obstacles you describe in your own words), your business name, and an email address if you ask for the results. It also stores the AI-generated report produced from those answers.
Customer and consumer data you bring
Operating the platform means storing data about your clients and their customers on your behalf:
- Client records — company name, contact name, email, phone, industry, website, location, and your own notes.
- Calls — caller name, email, and phone number; the full transcript; an AI summary; a sentiment rating; a link to the recording; and any structured fields the agent extracted from the conversation. See section 4.
- Appointments — contact name, email, phone, and the booked time.
- Leads — name, email, phone, company, industry, location, the source channel, and the complete original payload received from the lead source.
- Website chat— the visitor's name where given, and the full text of the conversation, which may contain whatever the visitor chooses to type.
Technical and security data
We record IP address, user agent, and referrer when an embedded analytics dashboard is opened, so that access to a client's reporting can be audited after the fact. We use IP addresses transiently to rate-limit requests. Where you give marketing consent we store the IP address and user agent as proof of that consent, and we keep a delivery ledger of transactional emails that records the subject line but never the message body.
⚠️ Review
Note for counsel: a website chat transcript and a voice transcript are free-text fields. A consumer can volunteer health, financial, or other special-category data into them, and nothing in the product prevents it. Decide whether this policy needs an explicit special-category statement and whether agencies must be contractually barred from using the agents in regulated contexts (health, credit, legal) without additional controls.
4. Voice calls are recorded and transcribed
Calls handled by a ScaleLogix AI voice agent are recorded and transcribed. The voice service is provided by Retell AI, which captures the audio, produces the transcript, and analyses the conversation. After a call ends, Retell sends us the transcript, an AI-generated summary, a sentiment rating, a link to the recording it hosts, and any details the agent captured — typically the caller's name, email address, phone number, and whether an appointment was booked. We store those on the relevant workspace record. The audio itself remains hosted by Retell; we store the link to it.
Retell supports masking personal details in stored records, and the platform default is post-call redaction, applied by Retell before the record is retained. An operator can change that setting per agent, and turning it off means raw, unmasked transcripts are retained.
⚠️ Review
Call-recording consent is jurisdiction-specific — several US states require all-party consent, and the EU and UK require a clear notification at the start of the call. The product does not currently force a recording disclosure into the agent's opening script, and nothing verifies that one is present. Decide (a) whether ScaleLogix mandates a recording disclosure in every deployed agent, (b) how that obligation is allocated between ScaleLogix, the agency, and its client, and (c) the wording this policy should use. This is the single highest compliance exposure on the page.
5. CRM, calendar, and appointment data
GoHighLevel is the system of record for contact and appointment data. The agency connects its own GoHighLevel account, and the platform writes into it rather than replacing it. Specifically:
- Contact details captured on a call or in chat — name, email address, phone number — are created or updated as GoHighLevel contacts.
- Call outcomes are written onto the GoHighLevel contact record as custom fields: booking status, sentiment, recording URL, call summary, and the full transcript. The platform creates those fields automatically if they do not already exist.
- Appointment bookings made by an AI agent send the contact's full name, email address, phone number, preferred time, and time zone into the client's GoHighLevel calendar.
Because the GoHighLevel account belongs to the agency, data written there is governed by the agency's own agreement with GoHighLevel and by the agency's own retention settings — not by ours. The same applies to the separate analytics database provisioned in the agency's own infrastructure, which holds a second copy of call, appointment, and chat records.
⚠️ Review
Operational fact worth surfacing to customers and to counsel: the same consumer's call and contact data ends up in threesystems — the ScaleLogix platform database, the agency's own analytics database, and the client's GoHighLevel account — each with different retention and access characteristics. A deletion request satisfied in one is not satisfied in the others. Decide how this policy describes that, and whether ScaleLogix commits to propagating deletions.
6. AI processing
Several features send content to large language models operated by third parties.
- AI assistant— the in-app and Slack assistant runs on Anthropic's Claude models. It can use tools that read contacts, conversations, calendars, and call records, which means the personal data those tools return becomes part of the prompt sent to Anthropic.
- Website builder — your business description, brand details, uploaded imagery, and the text of your conversation with the builder are sent to Claude to generate and revise the site.
- AI Revenue Audit — your intake answers are sent to Claude to produce the report.
- Document summarisation — text extracted from documents you upload for summarisation is sent to Claude.
- Knowledge base search — knowledge-base content is converted into embeddings by OpenAI and stored as vectors in Pinecone, using API keys the agency supplies from its own accounts.
Anthropic is accessed under ScaleLogix's own account. OpenAI and Pinecone are accessed under the agency's account, using credentials the agency provides.
⚠️ Review
Do not publish a claim about model training until it is verified. This policy must state whether content sent to Anthropic is excluded from model training and whether any zero-retention arrangement is in place — both are terms of the commercial agreement with Anthropic, not properties of this codebase, and neither has been confirmed. The same question applies to OpenAI, where the agency, not ScaleLogix, holds the account and therefore the terms.
7. Sub-processors and service providers
We use the providers below to run the platform. The final column matters: where the account holder is the customer, you have connected your own account, you hold the relationship with that provider, and their terms — not ours — govern what happens to the data there.
| Provider | Purpose | Data it can receive | Account holder |
|---|---|---|---|
| Supabase | Primary database, authentication, file storage | All platform data, including account and consumer records | ScaleLogix |
| Vercel | Hosting for the platform, generated sites, and dashboards | Request data, generated site content | ScaleLogix |
| Anthropic | Claude models behind the assistant, website builder, and audit | Prompt content, which can include contact and call data | ScaleLogix |
| Retell AI | Voice agents, call recording, transcription, analysis | Call audio, transcripts, caller details, knowledge-base text | ScaleLogix or customer |
| GoHighLevel | CRM, calendar, and messaging system of record | Contacts, appointments, call transcripts and recordings | Customer |
| n8n | Workflow automation between the platform and your tools | Whatever the deployed workflows carry, including contact data | ScaleLogix or customer |
| Stripe | Subscription payments | Billing contact and payment details, collected by Stripe | ScaleLogix |
| Upstash | Redis cache and rate limiting | Short-lived cached responses, IP-derived rate-limit keys | ScaleLogix |
| Sentry | Error monitoring | Error reports and, on error, session replays. See section 9 | ScaleLogix |
| Resend | Transactional email delivery | Recipient address, subject, message body | ScaleLogix |
| GitHub | Source storage for generated websites | Generated site code and content | ScaleLogix |
| OpenAI | Text embeddings for knowledge-base search | Knowledge-base content | Customer |
| Pinecone | Vector storage for knowledge-base search | Knowledge-base content and its embeddings | Customer |
| Google Drive | Per-workspace shared document folders | Files you upload through the platform | Customer |
| Slack | Workspace notifications and the assistant in Slack | Notification content, messages sent to the assistant | Customer |
| Instantly | Cold email campaign monitoring and control | Read access to campaign and lead data in your account | Customer |
| HeyReach | LinkedIn campaign monitoring and control | Read access to campaign and lead data in your account | Customer |
Two clarifications, because both are commonly assumed and neither is accurate. There is no Google Calendar integration — all calendar functionality runs through GoHighLevel. The Instantly and HeyReach integrations are read-and-control only: the platform reads campaign statistics and can start or pause a campaign, but it does not push prospect lists into either service.
⚠️ Review
Decide the sub-processor change policy: whether this list is contractually binding, whether customers get advance notice of additions, how much notice, and whether they may object. Also confirm that a signed data processing agreement is in place with each provider in the ScaleLogix column before this table is published as a compliance statement.
9. Analytics and error monitoring
We use Sentry to detect and diagnose faults. When an unhandled error occurs, Sentry receives the error, a stack trace, and context about what the application was doing. Sentry is not configured to attach IP addresses or cookies to those reports.
In production, when a session encounters an error, Sentry also captures a replay of that session — a reconstruction of what was on screen around the failure. Ordinary sessions are never recorded; only sessions that hit an error are.
⚠️ Review
Engineering decision required before publishing, not just a wording decision. Error-triggered session replay is enabled for every production session that errors, and there is no custom scrubbing filter on outbound error events. A replay captured on a workspace page can therefore contain a customer's contacts, call transcripts, or leads as they appeared on screen. Either add masking and a scrubbing hook before this policy goes live, or have counsel approve the disclosure as written and confirm Sentry is covered by a data processing agreement.
10. How we protect data
Access to customer data is enforced on the server by role, not merely hidden in the interface, and the database applies row-level security so one tenant cannot read another's records. Third-party credentials you store with us — API keys and tokens for your own CRM, voice, and automation accounts — are encrypted at rest with AES-256-GCM. Sensitive actions such as deployments, credential changes, and dashboard access are recorded in an audit trail. Requests are rate-limited, and production and non-production environments are kept separate.
No system is perfectly secure. You are responsible for keeping your own credentials safe and for removing access promptly when a team member leaves.
⚠️ Review
We maintain an internal SOC 2 control matrix and engineer against it, but do not state or imply a completed SOC 2 attestation on this page unless a report has actually been issued. Confirm the current status and the exact permitted wording. Also confirm whether a breach notification commitment and timeframe should appear here.
11. How long we keep data
We keep account and organisation data for as long as your account is open. Operational records — calls, transcripts, appointments, leads, chat conversations, and activity history — are retained so the platform can show you your own history, and are deleted when the workspace they belong to is deleted, which removes the associated records along with it. Billing history is retained separately, because we are required to keep records of transactions.
⚠️ Review
Retention periods have not been set and are deliberately not stated above. The platform performs no automated deletion of calls, transcripts, leads, chat messages, audit submissions, or access logs today — records persist until a workspace is deleted by an administrator. Set an actual retention schedule per data category, implement it, and then state it here. Publishing a specific period before the deletion job exists would be a commitment the product cannot keep. Note also that the access-log table carries a 90-day retention note in its definition that nothing currently enforces.
12. Your rights and choices
Depending on where you live, you may have the right to access a copy of your personal data, to correct it, to delete it, to receive it in a portable format, to object to or restrict certain processing, and to withdraw consent you have given. You will never be treated differently for exercising these rights.
If you are a consumer
If you spoke to an AI voice agent, used a website chat, or submitted a form on a business's website, that business decides how your data is used, and we act on its instructions. Contact that business first. If you contact us instead, we will pass your request to the relevant customer and support them in answering it.
Marketing email
Marketing email requires a confirmed opt-in: ticking a box is treated only as an intent until you confirm from the address itself. Every marketing message carries a one-click unsubscribe, and unsubscribing suppresses that address. Transactional messages — invitations, password resets, and service notifications — are not marketing and are sent as part of operating your account.
⚠️ Review
There is no self-service data export and no self-service account deletion in the product. Deletion is currently a manual, administrator performed workspace deletion, and an export would have to be assembled by hand. Before publishing, decide: which privacy frameworks we commit to (GDPR, UK GDPR, CCPA/CPRA, others), the intake channel for a rights request, the response deadline we commit to, the identity-verification step, and who fulfils a request that spans the agency, the client, and GoHighLevel. Then state that process here concretely.
13. International transfers
Our providers operate internationally, so your data may be processed outside the country where you are located.
⚠️ Review
Confirm the hosting region of the primary database and of the platform deployment, then state the transfer mechanism relied on — Standard Contractual Clauses, the EU-US Data Privacy Framework, the UK extension, or another basis — for each provider in section 7. Do not publish this section as a single vague sentence; it is one of the first things an enterprise buyer's security review will ask about.
14. Children
ScaleLogix AI OS is a business tool. It is not directed at children and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
⚠️ Review
Confirm the age threshold to state (13 under COPPA, 16 in parts of the EU) for the markets we sell into.
15. Changes to this policy
We will update this policy as the product changes. Every version carries a dated identifier, shown at the top and bottom of this page, which is recorded alongside your acceptance so it is always possible to establish which wording applied at a given time. Where a change materially affects your rights, we will give notice before it takes effect.
⚠️ Review
Decide the notice mechanism and period for a material change — in-app notice, email to account administrators, or both — and how many days before the change takes effect.
16. Contact us
If you have a question about this policy, or wish to exercise a right described in section 12, get in touch and we will respond.
⚠️ Review
Insert the privacy contact address and postal address here. A dedicated mailbox is strongly preferred over an individual's address, since it is published permanently and must survive staff changes. Confirm also whether a supervisory-authority complaint route needs to be named for EU and UK users.
Document version privacy-2026-08-26. This identifier is recorded alongside your acceptance so we can show you exactly which wording you agreed to.