Our practices
How we safeguard your data.
This page combines controls available in Scaalr with the commitments in our Privacy Policy and Terms of Service.
Product control · Privacy Policy §7, §12
Encryption and customer-held keys
The sensitive fields in your books, encrypted with a key only you hold. Scaalr never stores it. On Growth and up, optional field-level protection covers sensitive accounting fields. The secret is derived in your browser, and Scaalr cannot recover it. The full walk-through: Accounting Data Only You Can Unlock.
- Account names, journal-entry descriptions, line notes, manually entered amounts, and bank-reconciliation narrative can be encrypted at rest.
- System-generated amounts stay readable so reports can still total. Any total that includes a manually entered amount stays locked until you enter your secret in the browser.
- Personal data is protected with measures such as encryption in transit and at rest, matched to how it's used.
- International transfers use EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and Swiss-specific provisions, supported by transfer impact assessments.
Privacy Policy §12, §16 · Terms §3
Access controls and permissions
Access to personal data is governed by access minimization and role-based permissions. Account holders are responsible for maintaining the confidentiality of their credentials, and all activity under an account is attributed to that account holder.
- Access minimization and role-based permissions enforced by default.
- Account credential confidentiality required of every user.
Privacy Policy §5(b), §12
Monitoring and incident detection
Scaalr employs logging, monitoring, and network security measures to detect, investigate, and prevent fraud, abuse, and security incidents across the Services.
- Logging and monitoring of service activity.
- Network security measures to protect infrastructure.
- Fraud, abuse, and security incident detection and prevention.
Privacy Policy §15
Breach notification
In the event of a personal data breach, Scaalr follows defined notification timelines. As a controller, the competent supervisory authority is notified within 72 hours under GDPR. As a processor, the client is notified without undue delay. Under PIPEDA, affected individuals and the Privacy Commissioner are notified as required.
- 72-hour supervisory authority notification under GDPR/UK GDPR.
- Processor-to-controller notification without undue delay.
- PIPEDA breach reporting and records maintenance.
Privacy Policy §12, §16
Secure development and privacy by design
Scaalr maintains secure development practices, vulnerability management, and data protection by design and by default. Data protection impact assessments are performed where processing is likely to result in high risk to individuals.
- Secure development practices and vulnerability management.
- Data protection by design and by default.
- Data protection impact assessments (DPIAs) for high-risk processing.
Privacy Policy §4.1, §6(a) · Terms §8
Third-party and payment security
Payment card data is processed by third-party payment processors; Scaalr does not store full card numbers. All service providers and processors are bound by written contracts and process personal data only under Scaalr's documented instructions. Confidentiality obligations govern all information exchanged between parties.
- Scaalr does not store full payment card numbers.
- Service providers bound by written data processing contracts.
- Mutual confidentiality obligations for all parties.