Privacy Policy
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
SCAILE TECHNOLOGIES GmbH
Jungfrauenthal 8
20149 Hamburg
Germany
Represented by its Managing Directors: Simon Wilhelm, August Gutsche, Julius Betzler
Commercial register: Amtsgericht Hamburg, HRB 191310
VAT identification number: DE454457329
E-mail: info@scaile.tech
2. Scope of this policy
This privacy policy applies to the website scaile.tech, including all of its subpages (blog, case studies, pricing, tools, contact).
It does not apply to:
- our SaaS application at app.scaile.to, which is governed separately;
- the processing of content our customers upload into the SaaS application. In that respect our customers are controllers and we act as a processor under Art. 28 GDPR;
- external websites we link to (e.g. LinkedIn, Google Maps). Their content and data processing are the sole responsibility of the respective providers.
3. Your rights
You have the following rights regarding your personal data:
| Right | Legal basis | Substance |
|---|---|---|
| Access | Art. 15 GDPR | Confirmation of whether and which data we process, plus a copy |
| Rectification | Art. 16 GDPR | Correction of inaccurate and completion of incomplete data |
| Erasure | Art. 17 GDPR | “Right to be forgotten”, unless a retention obligation applies |
| Restriction | Art. 18 GDPR | Blocking of processing instead of erasure |
| Data portability | Art. 20 GDPR | Release in a structured, machine-readable format |
| Objection | Art. 21 GDPR | Objection to processing based on legitimate interests |
| Withdrawal of consent | Art. 7(3) GDPR | At any time, with effect for the future |
| Complaint | Art. 77 GDPR | Complaint to a supervisory authority |
An e-mail to info@scaile.tech is sufficient to exercise these rights. No particular form is required and you do not need to give reasons.
Withdrawing your analytics consent: the “Cookie settings” link in the footer of every page reopens the consent dialogue so you can change your choice. Withdrawal takes effect from that moment; the lawfulness of processing carried out beforehand remains unaffected.
Right to object (Art. 21 GDPR). Where we process your data on the basis of our legitimate interests (Art. 6(1)(f) GDPR) — which on this website means the delivery of the site itself, our cookie-free reach measurement and the handling of enquiries — you have the right to object at any time, on grounds relating to your particular situation. An e-mail to info@scaile.tech is enough. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.
The supervisory authority responsible for us:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Straße 22, 7th floor, 20459 Hamburg, Germany
https://datenschutz-hamburg.de
You may alternatively contact the supervisory authority of your habitual residence or place of work.
4. Principles and origin of the data
We process personal data solely in accordance with the GDPR and the German Federal Data Protection Act (BDSG), and collect only what is necessary for the stated purpose.
We do not process special categories of personal data under Art. 9 GDPR via this website, and we carry out no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
There is no statutory or contractual obligation to provide us with data. The website can be used without disclosing personal data. If you do not complete a form, we cannot deliver the associated service (e.g. sending you a report); no other disadvantage arises for you.
We receive your data directly from you (form entries) or, for technical reasons, from your browser when you access a page. We do not process data from public sources or purchased data sets to operate this website.
5. Hosting and delivery of the website (Vercel)
This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. When you access a page, Vercel processes technically necessary access data on our behalf:
- the IP address of the requesting device,
- the date and time of access,
- the requested URL or file and the volume of data transferred,
- the referrer URL (the previously visited page, where transmitted),
- browser type, browser version and operating system (user agent),
- the HTTP status code.
Purpose: delivering the website, ensuring its stability and operational security, defending against attacks and abuse (e.g. denial of service), and diagnosing faults.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in providing our website reliably and securely. A website cannot technically be delivered without processing the IP address.
Retention: access logs are retained by Vercel for a maximum of 30 days and then deleted. We do not evaluate them on a personal basis and do not combine them with other data sources.
Server location and third-country transfer: delivery takes place via edge infrastructure in the EU (Frankfurt am Main region, fra1); data is not permanently stored outside the EU. Access from the United States by Vercel as a US company cannot, however, be ruled out, so a third-country transfer may occur. Vercel Inc. is certified under the EU-U.S. Data Privacy Framework, so transfers to the USA are covered by an adequacy decision of the European Commission pursuant to Art. 45 GDPR. In addition, we have concluded a data processing agreement with Vercel including the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Vercel’s privacy policy: https://vercel.com/legal/privacy-policy
6. Cookies and storage on your device
This website sets no cookies for advertising or tracking purposes when you access a page.
We store only your choice from the consent dialogue, so that we do not have to ask you again on every page view. This is not stored in a cookie but in your browser’s local storage (localStorage):
Exempt from consent — strictly necessary:
| Name | Purpose | Content | Storage period |
|---|---|---|---|
scaile-consent | Storing your choice in the cookie notice | Your choice per category (analytics, external), timestamp, version identifier of the notice | 180 days, then requested again |
Storing this information is strictly necessary in order to provide the service you requested (remembering your privacy choice) and therefore exempt from consent under § 25(2)(2) TDDDG. The entry contains no identifier by which you could be recognised.
Only after your consent (“Accept all” or the analytics toggle):
| Name | Service | Purpose | Storage period |
|---|---|---|---|
rybbit-visitor-id (localStorage) | Rybbit (§ 7.3) | Randomly generated identifier used to recognise returning visits | Until you clear your browser’s local storage |
_ga, _ga_6X7LPM6SQ8 (cookies) | Google Analytics 4 (§ 7.2) | Recognising returning visits, session attribution | No more than 24 months |
If you select “Reject”, none of these entries is set: no analytics service is loaded and no further data is stored on or read from your device.
You can delete cookies and local storage contents at any time in your browser settings and prevent them from being set in future. If you disable storage entirely, we may be unable to save your privacy choice and the notice will reappear on every visit.
7. Web analytics
7.1 Vercel Web Analytics (no consent required, cookie-free)
To measure the reach of our website we use Vercel Web Analytics provided by Vercel Inc. (address in § 5).
The service operates without cookies and without cross-device identifiers. No information is stored on or read from your device, so § 25 TDDDG does not apply and no consent is required. The data processed comprises the page accessed, the referrer, browser type, operating system, device type and the country derived from the IP address — the IP address itself is processed only transiently by Vercel and is not stored. Vercel derives a short-lived hash from this data with no persistent recognition. No user profile is created and you are not recognised across multiple visits.
Purpose: statistical analysis of site usage in order to improve our content and structure.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is designing our offering to meet demand. We deliberately chose a cookie-free, non-profiling method that limits the interference with your rights to what is necessary.
Objection: you may object to this processing at any time at info@scaile.tech (Art. 21 GDPR).
Retention: aggregated statistics for up to 24 months; after aggregation there is no longer any reference to an individual.
7.2 Google Analytics 4 (only with your consent)
In addition we use Google Analytics 4, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).
The service is loaded only after you have allowed analytics in the cookie notice. Without your consent no Google script is loaded and no connection to Google servers is established.
Google Analytics uses cookies and similar identifiers that allow your use of the website to be analysed across multiple page views. The data processed includes in particular:
- pages accessed, time spent and interactions,
- referrer URL and the source of your visit,
- device type, browser, operating system and screen resolution,
- approximate location based on the IP address (country/region),
- a pseudonymous identifier used to recognise returning visits.
We have enabled IP anonymisation: Google Analytics 4 does not log or store full IP addresses; truncation occurs before the data is stored. Our measurement ID is G-6X7LPM6SQ8. Google Signals, advertising features and linking with advertising networks are disabled; we do not use the service for personalised advertising and do not share data for advertising purposes.
Purpose: detailed reach and usage analysis to improve our content and to measure the success of our marketing activities.
Legal basis: your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw it at any time via “Cookie settings” in the footer, without any disadvantage to you.
Third-country transfer: our contractual partner is Google Ireland Limited in the EU. Transfer to Google LLC in the USA cannot, however, be excluded. Google LLC is certified under the EU-U.S. Data Privacy Framework (adequacy decision under Art. 45 GDPR); the EU Standard Contractual Clauses incorporated by Google apply in addition. We have concluded a data processing agreement with Google under Art. 28 GDPR.
Retention: the retention period for user and event data in our Google Analytics account is limited to 14 months, after which the data is deleted automatically. Google Analytics cookies expire after no more than 24 months.
Further information: Google’s privacy policy (https://policies.google.com/privacy) and its notes on data use (https://policies.google.com/technologies/partner-sites).
7.3 Rybbit — self-hosted reach measurement (only with your consent)
In addition we use Rybbit, open-source reach-measurement software that we operate ourselves on our own infrastructure (rybbit.scaile.to). This is not a third-party analytics service: the data is not transmitted to an analytics provider but remains on servers we control in Germany (see § 12).
The service is loaded only after you have allowed analytics in the cookie notice.
The data processed comprises:
- pages accessed including query-string parameters, and the order in which they were accessed,
- referrer URL and the source of your visit,
- browser type, operating system, device type and screen size,
- country and region, derived from the IP address,
- clicks on outbound links (which external address was opened from our site),
- a randomly generated identifier used to recognise returning visits.
Storage on your device: Rybbit uses no cookies. It does, however, store a randomly generated identifier (rybbit-visitor-id) in your browser’s local storage and transmits it with every event so that returning visits can be recognised as such. This identifier is persistent — it remains stored until you clear your browser’s local storage. Because this stores information on your device and is not necessary to operate the website, we obtain your consent for it.
Purpose: statistical analysis of which content is found and read, in order to improve our offering.
Legal basis: your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw it at any time via “Cookie settings” in the footer.
What Rybbit does not do in our configuration: we have disabled session recording (“session replay”, i.e. capturing mouse movements, clicks and page content). Capturing form interactions, copy events and individual button clicks is likewise disabled. We do not build advertising profiles and do not combine the data with data from other sources. On the website, no attribution to a named individual takes place.
No third-country transfer by the analytics service: because we operate Rybbit ourselves, no one outside our company receives the analytics data. The delivery of the script and the transmission of events do, however, pass through a security and delivery service (Cloudflare, see § 12 and § 13).
Retention: event data is deleted automatically after 14 months.
Objection or withdrawal: via “Cookie settings” in the footer. Rybbit additionally respects an opt-out set in your browser; on request we will tell you how to enable this permanently.
8. Appointment booking via Cal.com
On our contact page we offer you the option of booking a meeting directly. For this we use Cal.com provided by Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA.
The booking calendar is loaded as embedded content (iframe) from Cal.com, Inc. servers. The embed is loaded only after you have expressly agreed: in place of the calendar you initially see a placeholder with a notice; only when you actively click it is a connection to Cal.com established. Alternatively, you can reach the calendar via a link that takes you to Cal.com’s own website.
When the calendar loads, your IP address, browser and device data and the page accessed are transmitted to Cal.com, which may set cookies and similar identifiers. If you book an appointment, we additionally process the details you enter (typically name, e-mail address, chosen time and time zone, and any optional free-text information) for the purpose of arranging and holding the meeting.
Purpose: arranging, managing and holding consultation and sales meetings.
Legal basis:
- for loading the calendar and the associated storage on your device: your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG, given by clicking the placeholder;
- for processing the booking data: Art. 6(1)(b) GDPR (performing the meeting you requested, or a step prior to entering into a contract), otherwise Art. 6(1)(f) GDPR based on our legitimate interest in efficient scheduling.
Third-country transfer: Cal.com, Inc. is a US company and is not certified under the EU-U.S. Data Privacy Framework. Transfer to the USA therefore takes place on the basis of the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR, agreed with Cal.com as part of a data processing agreement; we have additionally assessed the risks of the transfer and taken supplementary safeguards into account (encryption in transit and at rest, data minimisation). Despite these measures, it cannot be entirely ruled out that US authorities may access the data under US law and that you may not have legal remedies equivalent to those available in the EU. We inform you of this expressly; your consent to the embed also extends to this transfer (Art. 49(1)(a) GDPR).
Retention: booking data is stored for the duration of the scheduling process and for as long as we need it to document the business approach, but no longer than 24 months after the meeting if no business relationship arises. If a business relationship does arise, the statutory commercial and tax retention periods apply (§ 257 HGB, § 147 AO: six and ten years respectively).
Avoiding the embed: if you would prefer not to connect to Cal.com, simply e-mail us at info@scaile.tech. An appointment can be arranged that way too, with no disadvantage to you.
Cal.com’s privacy policy: https://cal.com/privacy
9. Contacting us by e-mail
If you contact us by e-mail (e.g. at the address info@scaile.tech given on the website), we process your e-mail address, your name and the content you send us in order to answer your enquiry.
Purpose: handling and answering your enquiry and documenting it.
Legal basis: Art. 6(1)(b) GDPR where the enquiry relates to a contract or its preparation; otherwise Art. 6(1)(f) GDPR based on our legitimate interest in dealing appropriately with enquiries addressed to our company.
Retention: we delete your enquiry once it has been dealt with conclusively and no retention obligations apply — as a rule after six months at the latest, and in the case of business-relevant correspondence after expiry of the commercial and tax retention periods (§ 257 HGB, § 147 AO).
Note: an unencrypted e-mail can be read by third parties in transit. For confidential information we will provide a secure transmission channel on request.
10. Health Check (“AI Search Readiness”)
At /tools/health-check we offer a free analysis tool. There you enter the domain of your website and — if you would like the full report — your e-mail address.
The data processed comprises:
- the domain you enter,
- your e-mail address (only if you request the report),
- the results of the automated analysis of the publicly accessible website you specified.
Purpose: producing and sending you the report you requested.
Legal basis: Art. 6(1)(b) GDPR — the processing is carried out at your request in order to provide the free service you asked for.
Service providers involved: the details are stored in a database at Supabase and copied into our self-hosted CRM (Twenty, crm.scaile.tech) so that we can deal with your enquiry. The report is sent via Resend. For the technical checks we retrieve the address you entered through the Google PageSpeed Insights, Chrome UX Report and Google Safe Browsing interfaces, which transmits that address to Google. All of them are listed in § 12.
Disclosure: we do not sell your data and do not pass it on to third parties, other than the processors listed in § 12.
Retention: the domain, e-mail address and report results are deleted once the report has been delivered and any follow-up questions have been resolved, and in any event after 12 months, unless you have consented to further use or a business relationship has arisen.
Note on the analysis: the analysis examines only publicly accessible content of the website you specify. Part of the report is reviewed by a member of our team before it is sent — no decision based solely on automated processing with legal effect under Art. 22 GDPR takes place.
11. External links and embedded content
Links that transmit no data on page load: our website contains links to external services, in particular to our LinkedIn company profile and — on the contact page — to Google Maps for our office locations.
These are plain hyperlinks. No content is loaded from the providers’ servers and no data is transmitted to them unless you click the link. Only when you click do you leave our website; from that point the privacy policy of the respective provider applies, over whose processing we have no influence:
- LinkedIn Ireland Unlimited Company: https://www.linkedin.com/legal/privacy-policy
- Google Ireland Limited: https://policies.google.com/privacy
Share buttons: our blog, case-study and comparison pages carry buttons for sharing an article on LinkedIn, X and Facebook. These are plain links and the icons are stored on our own server — no script from those providers runs on our pages and nothing is transmitted to them until you click. Only when you do are you taken to the provider concerned, where their own privacy policy applies.
Fonts: all fonts we use are served locally from our own server. No connection is made to Google Fonts or any other external font service.
Embedded content: the only active third-party embed is the Cal.com booking calendar described in § 8, which is loaded only after you have given your consent.
11a. Our presence on LinkedIn
We maintain a company page on LinkedIn, operated by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. Visiting our website does not connect you to LinkedIn — see § 11. This section concerns visits to that page.
When you visit our company page, LinkedIn processes your data on its own responsibility and, if you are logged in, can associate the visit with your account. From the resulting statistics ("page insights") we receive only aggregated, anonymous figures — reach, interactions, and coarse categories such as region or industry. We cannot connect them to individuals and have no access to the underlying data.
For the production of those page insights, LinkedIn and we are joint controllers under Art. 26 GDPR (see CJEU, C-210/16). LinkedIn has assumed the primary data protection obligations in its Page Insights Joint Controller Addendum, including responsibility for informing you and for answering requests from data subjects. You can exercise your rights against LinkedIn directly, which is the more effective route because only LinkedIn holds the data.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a public presence and in communicating with interested parties. Where LinkedIn asks you for consent to its own processing, that consent is the basis for it.
LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy
12. Recipients and categories of recipients
Your data is transmitted only to the following recipients:
| Recipient | Role | Purpose | Location / transfer basis |
|---|---|---|---|
| Vercel Inc. | Processor | Hosting, delivery, cookie-free reach measurement | USA / EU edge (fra1); DPF + SCC |
| Google Ireland Ltd. | Processor | Google Analytics 4 (only with consent); technical checks on the domain you enter, via PageSpeed Insights, Chrome UX Report and Safe Browsing (§ 10) | Ireland (EU), possibly USA; DPF + SCC |
| Cal.com, Inc. | Own controller | Appointment booking (only with consent) | USA; consent under Art. 49(1)(a) GDPR |
| Hetzner Online GmbH | Processor | Server operation for our self-hosted reach measurement (Rybbit) | Germany (EU) — no third-country transfer |
| Cloudflare, Inc. | Processor | Delivery and protection of rybbit.scaile.to (defence against attacks) | USA / EU data centres; DPF + SCC |
| Supabase | Processor | Storing enquiries from our free tools (§ 10) | EU region; SCC for access from the USA |
| Twenty CRM | Processor | Our self-hosted CRM at crm.scaile.tech (§ 10) | Germany (EU) — no third-country transfer |
| Resend | Processor | Sending the reports you request (§ 10) | USA; SCC |
| E-mail and IT service providers | Processors | Operating our mailboxes and internal IT | EU |
| Tax advisers, auditors, legal advisers | Own controllers / professionals bound by secrecy | Compliance with statutory obligations | EU |
| Authorities and courts | Own controllers | Only where legally required | EU |
We have concluded agreements under Art. 28 GDPR with all processors. These oblige the service providers to process data only on our instructions and subject to appropriate technical and organisational measures.
Your data is not transmitted to third parties for advertising purposes. We do not sell personal data.
13. Third-country transfers at a glance
Where data is processed outside the EU/EEA, we ensure an adequate level of protection:
| Provider | Country | Basis | Assessment |
|---|---|---|---|
| Vercel Inc. | USA | Art. 45 GDPR (DPF-certified) + SCC as a fallback | Delivered via EU edge; no permanent storage outside the EU |
| Google LLC (behind Google Ireland Ltd.) | USA | Art. 45 GDPR (DPF-certified) + SCC | Contractual partner is the Irish entity; only after consent |
| Cloudflare, Inc. | USA | Art. 45 GDPR (DPF-certified) + SCC | Delivery and protection of rybbit.scaile.to only; the analytics data itself is held by us in Germany |
| Resend | USA | Art. 46(2)(c) GDPR (SCC) | Sends the report you asked for; receives only your e-mail address |
| Cal.com, Inc. | USA | Art. 46(2)(c) GDPR (SCC) + supplementary safeguards; additionally Art. 49(1)(a) GDPR | Not DPF-certified — residual risk of authority access, see § 8; only after consent |
Our self-hosted reach measurement (Rybbit, § 7.3) runs on servers in Germany and therefore constitutes no third-country transfer.
You may request a copy of the Standard Contractual Clauses from us; the DPF certifications can be viewed publicly at https://www.dataprivacyframework.gov/list.
14. Data security
We take appropriate technical and organisational measures under Art. 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. In particular:
- the website is delivered exclusively over HTTPS with TLS encryption; HSTS (
Strict-Transport-Security) is also enabled, so your browser connects only over an encrypted channel; - we use security headers that make common attacks more difficult (
X-Content-Type-Options,X-Frame-Options,Referrer-Policy: strict-origin-when-cross-origin); - a Permissions Policy disables camera, microphone and geolocation access site-wide;
- within our company, access to personal data is limited to those who need it to perform their duties.
Our measures are reviewed and adapted on an ongoing basis in line with technical developments. Please note that despite all measures, data transmission over the internet can have security gaps; absolute protection is not possible.
15. Changes to this privacy policy
We update this privacy policy when our website, the services we use or the legal requirements change. The version available on this page applies. Where material changes affect a consent, we will obtain your consent again.
Version: 9 August 2026