Privacy Policy
Last updated: February 2026
1. Data Controller
Scalitt B.V., registered in the Netherlands, is the data controller responsible for the processing of your personal data through our platform at scalitt.com and app.scalitt.com. For questions about this policy or your personal data, contact us at privacy@scalitt.com.
2. Information We Collect
2.1 Account information you provide:
- Name and email address
- Company name and role within your organization
- Password (stored in hashed form)
- Connected email accounts (e.g. Gmail) for sending sequences
2.2 Payment information:
Payment details (credit card, billing address) are processed directly by Stripe and are never stored on our servers. We only store your Stripe customer ID and subscription status.
2.3 Content you create and import:
- Leads and prospect data (names, email addresses, job titles, company information, LinkedIn URLs, phone numbers)
- Email sequences, templates, and sent emails
- Call recordings, transcripts, and coaching analyses
- Pipeline deals, notes, and activity logs
- Ideal Customer Profile (ICP) definitions and search filters
2.4 Automatically collected information:
- IP address and approximate location
- Browser type and operating system
- Session data required for authentication
3. Lead & Prospect Data
Our platform helps you find and engage potential customers. When you use our lead generation features, we retrieve prospect data (such as names, email addresses, job titles, and company information) from third-party data providers, specifically Apollo.io. This data is sourced from publicly available business information. You are responsible for using this data in compliance with applicable laws, including GDPR and applicable anti-spam legislation.
4. How We Use Your Information
- Provide, maintain, and improve our platform
- Process transactions and manage your subscription
- Generate and enrich leads using third-party data providers
- Generate personalized email drafts using AI
- Record, transcribe, and analyze sales calls for coaching purposes
- Score and qualify leads using AI-powered analysis
- Send emails on your behalf through connected email accounts
- Send technical notices, security alerts, and support messages
5. Legal Basis for Processing (GDPR)
We process your personal data on the following legal grounds:
- Contract performance - Processing your account data and providing platform features is necessary to deliver our services under our agreement with you.
- Legitimate interest - Improving our platform, preventing fraud, and ensuring security. For B2B prospecting activities, we rely on the legitimate interest of our customers to conduct business development.
- Consent - Where required, such as for call recording. You can withdraw consent at any time.
- Legal obligation - Retaining transaction records as required by tax and accounting regulations.
6. AI & Automated Processing
Scalitt uses artificial intelligence to power core features of our platform. This includes:
- Email generation - Prospect names, job titles, and company information are sent to AI providers to generate personalized email drafts. You always review and approve emails before they are sent.
- Sales coaching - Call transcripts are analyzed by AI to provide coaching recommendations, sentiment analysis, and conversation scoring.
- Lead scoring - AI evaluates prospect data to suggest which leads are most likely to convert. This scoring is advisory and does not replace human decision-making.
Your data is not used to train AI models. We use AI providers as data processors under strict data processing agreements.
7. Call Recording & Transcription
Our platform supports recording and transcription of sales calls. Call recordings are stored securely in encrypted cloud storage. Transcripts and AI-generated coaching analyses are stored in our database. You are responsible for obtaining appropriate consent from call participants before recording, in accordance with applicable local laws.
8. Data Sharing & Third-Party Processors
We do not sell your personal information. We share data with the following categories of service providers, acting as data processors under data processing agreements:
- Cloud infrastructure providers - for hosting, database, authentication, and file storage
- Stripe - for payment processing
- Lead data enrichment providers - for sourcing publicly available business information
- AI service providers - for email generation, coaching analysis, and lead scoring
- Google (Gmail, Calendar) - for email sending and calendar integration when you connect your account
A complete list of our sub-processors is available on request. Contact us at privacy@scalitt.com.
9. International Data Transfers
Scalitt B.V. is based in the Netherlands (EU). Our service providers are primarily located in the United States. These transfers are safeguarded by Standard Contractual Clauses (SCCs) as approved by the European Commission, or by the EU-U.S. Data Privacy Framework where applicable. You can request a copy of these safeguards by contacting us.
10. Data Security
We implement industry-standard security measures to protect your data. All data is encrypted in transit using TLS and encrypted at rest. Our platform uses multi-tenant architecture with strict data isolation, ensuring your data is never accessible to other customers. Access to production systems is restricted and monitored.
11. Data Retention
- Account data - Retained for the duration of your account. Deleted within 30 days of account closure upon request.
- Lead and prospect data - Retained while your account is active. You can delete individual leads at any time.
- Call recordings and transcripts - Retained while your account is active. You can delete individual recordings at any time.
- Payment records - Retained for 7 years after the transaction as required by Dutch tax law.
- Server logs - Automatically deleted after 90 days.
12. Your Rights
Under the General Data Protection Regulation (GDPR), you have the following rights:
- Access - Request a copy of the personal data we hold about you.
- Rectification - Request correction of inaccurate or incomplete data.
- Erasure - Request deletion of your personal data.
- Restriction - Request that we restrict processing of your data.
- Portability - Receive your data in a structured, machine-readable format.
- Objection - Object to processing based on legitimate interest.
- Withdraw consent - Where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at privacy@scalitt.com. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
13. Cookies
We use only essential cookies required for our platform to function:
- Authentication cookies - To maintain your logged-in session.
- Preference cookies - To remember your settings (e.g. selected views).
We do not use third-party tracking or advertising cookies.
14. Children's Privacy
Our platform is designed for business use and is not intended for individuals under the age of 16. We do not knowingly collect personal data from children.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice on our platform. Your continued use of the platform after changes take effect constitutes acceptance of the updated policy.
16. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:
Scalitt B.V.
Email: privacy@scalitt.com
