I. Introduction
In the following, we provide information about the collection and processing of personal data in the context of the Scale Platform, an AI-powered intelligence platform, including the Max Scale application for Microsoft Teams, and related cloud-based services (the “Service”) provided by Scale Company Oy (“Scale”, “we”, “us”).
Depending on the processing activity, Scale acts either as a Processor or a Controller:
Processor (see Section II)
We process personal data on behalf of your employer (our Customer), who acts as the Controller. Please contact your employer directly for any questions regarding such processing.
Controller (see Section III)
We process personal data for our own business purposes, such as account administration, billing, support, marketing, and website operation.
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal data from children.
This Privacy Policy applies to the following categories of data subjects: users of the Service, Customer personnel whose information appears in uploaded materials, website visitors, Customer representatives, and prospective business contacts.
II. Scale as a Processor
Our platform is provided to companies as an AI-powered intelligence tool. If the Service is made available to you by your employer, your employer is the Controller of your personal data and Scale is the Processor.
Scale processes personal data only under the instructions of the Customer and is not responsible for the Customer’s independent privacy practices.
Scale does not independently determine the purposes or means of processing Customer Data and acts solely on the instructions of the Customer in its role as Processor.
1. Types of Personal Data Processed as a Processor
a) User Profile Data
- Name
- Work email address
- Login credentials managed through our authentication provider
- Usage-lifecycle attributes derived from Service usage (e.g., date of first use)
b) Customer-Uploaded Content
Documents (such as PDFs, spreadsheets, and presentations) that users upload to the platform.
These documents may incidentally contain personal data, such as team member names and email addresses in project files, steering committee decks, or similar materials. Scale does not systematically extract personal data from these documents.
c) Project Data
Team member names and email addresses added to projects by users in connection with project management and collaboration features.
d) Access and Technical Data
- IP address
- Browser type
- Operating system
- Device identifiers
- Date and time of access
- Error logs
- Usage metrics
This information is processed primarily for system stability, service performance, security monitoring, and service improvement.
e) Connected Content-Source Data
Files, pages, and other content the user selects from a connected Google or Microsoft account or another connected third-party content source (see Section II.3).
2. Use of AI
The Service uses artificial intelligence models to analyze Customer-uploaded documents and generate insights and recommendations.
The AI engine is powered by Google Gemini Enterprise Agent Platform by default. Where a Customer configures a third-party AI provider, processing is subject to that provider’s terms.
AI may encounter personal data incidentally present in uploaded documents. It does not extract, profile, or store personal data separately from the documents themselves.
AI processing involves automated analysis of documents that may incidentally contain personal data. The Service is not designed to profile individuals or evaluate personal aspects of data subjects.
AI outputs are advisory only and do not produce legal or similarly significant effects on individuals. All business decisions remain the responsibility of human users at the Customer.
To the extent that such automated analysis could be interpreted as profiling under applicable law, data subjects have the right to object to such processing under GDPR Article 21.
Scale’s default AI provider (Google Gemini Enterprise Agent Platform) is contractually prohibited from using Customer Data to train or optimize its general AI models.
Where the Customer configures a third-party AI provider, the Customer is responsible for reviewing that provider’s data usage terms.
All AI processing occurs within EU infrastructure by default. If a Customer configures a third-party AI provider, processing location is determined by that provider’s terms.
3. Connected Workspace Accounts and Content Sources
Users may connect external content sources to the Service — such as a Google or Microsoft work account, or third-party workspace and knowledge tools (e.g., document and wiki platforms) — and select files, pages, and other content for the Service’s AI features to analyze.
Scale accesses connected-source data only as authorized by the connecting user (through an OAuth authorization or an API key provided by the user, depending on the source), and only reads content the user has chosen to make available. The user can revoke this authorization at any time in the Service, or by revoking the authorization or API key in the provider’s own settings.
Content from connected sources is used solely to provide the Service’s features to the user’s organization — such as analyzing project materials and answering users’ questions — and is processed as Customer Data under this Policy, including by the AI engine described in Section II.2. Anything the Service stores from or about connected content, including temporary copies made during processing, is likewise handled as Customer Data under this Policy’s retention and deletion terms (Section II.4). Connected-source data is not used for advertising, is never used to train or improve generalized AI or machine-learning models, and is not shared with third parties other than the service providers listed in Section IV (Processor role).
The connected providers themselves (e.g., Google, Microsoft, or the third-party tool the user connects) process the content under the Customer’s or user’s own agreements with those providers; Scale accesses these sources on the user’s behalf and does not engage them as sub-processors.
Scale Platform’s use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Scale Platform’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
4. Storage Duration as a Processor
Scale retains Customer Data only as long as necessary to provide the Service and fulfill contractual obligations.
| Data Category | Retention Period |
|---|---|
| Customer Data | Deleted no later than 120 days after contract termination, unless required longer for legal claims |
| User Account Data | Deleted no later than 120 days after contract termination |
| Technical Logs | Deleted within 120 days |
| Product usage events (pseudonymized feature-usage and interaction data) | User-identifying keys are removed (de-identified) or the events are deleted within 120 days of collection; retained thereafter only in de-identified form or as anonymized, aggregated statistics. |
5. Connecting external AI clients (Model Context Protocol)
The Service can be accessed by external AI clients, such as AI assistants or agents, that a user connects via the Model Context Protocol (MCP) or a similar interface. When a user connects such a client and requests data, the Service returns Customer Data (which may include personal data) to that client, at the user’s direction and limited to the data that user is permitted to access in the Service.
Scale exposes this interface but does not control the connected client. That client, and its provider, process the returned data under the Customer’s or user’s own agreement with that provider; Scale does not engage these clients as sub-processors. The Customer is responsible for the client’s data-use terms, including whether the provider may use submitted content to train or improve its models, and for authorizing which of its users may connect such clients. The user or Customer can revoke a client’s access at any time, in the Service or in the client’s own settings. Data returned to a connected client leaves Scale’s EU-based infrastructure only insofar as that client processes it elsewhere, as determined by its provider.
III. Scale as a Controller
Scale acts as the Controller for personal data processed for its own business purposes, including:
- account management
- billing
- communications
- customer support
- marketing
- website operation
1. Categories of Data Processed as a Controller
a) Account and Contact Data
Names, job titles, business email addresses, and Customer billing information.
Payment transactions are processed by Stripe. Scale does not store payment card data directly.
b) Support and Communication Data
Information from support requests, administrative correspondence, or other communications with Scale.
c) Website and Marketing Data
- Newsletter or product update subscription information
- Contact form submissions (name, business email address, company, and the content of your message), together with the IP address, browser identifier and referring page of the submission, which we keep for abuse prevention
- Cookieless website analytics: page URL, referrer, browser, operating system, device type, and approximate location (country, region, city). Your IP address and user agent are used transiently to derive a daily rotating identifier and to determine approximate location; neither is stored.
d) Prospect Data
Contact information of potential business customers, such as:
- names
- job titles
- business email addresses
- company names
These may be collected from public sources or through sales outreach.
Scale processes prospect data based on its legitimate interest in developing business relationships with potential customers. Individuals may object to such processing at any time.
2. Legal Bases for Processing as a Controller
Scale processes personal data under the following GDPR legal bases (Art. 6).
| Purpose of Processing | Legal Basis |
|---|---|
| Providing and administering the Service, including account creation and management | Contract (Art. 6(1)(b)) |
| Customer support and operational communications | Legitimate Interest (Art. 6(1)(f)) |
| Security monitoring and service reliability | Legitimate Interest (Art. 6(1)(f)) |
| Product improvement and operational analytics | Legitimate Interest (Art. 6(1)(f)) |
| Billing, accounting, and compliance with statutory obligations | Legal Obligation (Art. 6(1)(c)) |
| Marketing communications and product updates | Consent (Art. 6(1)(a)) |
| Website analytics (cookieless) | Legitimate Interest (Art. 6(1)(f)) |
Scale’s legitimate interests include:
- operating and improving the Service
- ensuring system security and reliability
- providing customer support
- communicating relevant service updates
- developing business relationships with prospective customers, including limited B2B outreach
- understanding website usage
Data subjects may object to such processing at any time.
3. How We Use Your Information
We use the information we process for the following purposes.
To Provide and Improve the Service
Customer Data enables delivery of the intelligence platform and technical data helps improve system performance and reliability.
For Security and Troubleshooting
We monitor our systems to prevent security incidents and resolve technical issues.
To Communicate With You
We use contact information to send:
- service updates
- support communications
- administrative messages
- marketing communications (where consent has been provided)
To Create Anonymized Insights
We may anonymize and aggregate data to analyze usage trends and improve our product.
This anonymized data cannot identify any individual or company.
Benchmarking features are enabled by default and can be disabled through the Service settings.
4. International Transfers
Scale Company Oy is based in Finland and primarily uses EU-based infrastructure.
Platform data (customer-uploaded content and user accounts) is hosted within the EU on Google Cloud Platform.
Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards including, but not limited to:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- EU-U.S. Data Privacy Framework (DPF) where applicable
5. Storage Duration as a Controller
| Data Category | Retention Period |
|---|---|
| Account and billing data | Stored for the duration of the contractual relationship and thereafter as required by law (e.g., Finnish Accounting Act) |
| Marketing data | Retained until consent is withdrawn or the user opts out |
| Support and communications data | Retained as long as necessary to resolve the issue and for legitimate record-keeping; contact-form submissions are deleted 24 months after they were sent |
IV. How We Share Your Information
We do not sell personal data. Personal data is shared only with trusted service providers who help us operate the Service.
Service Providers Processing Platform Data (Processor Role)
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform (incl. Gemini Enterprise Agent Platform) | Cloud hosting, AI-powered document analysis | EU |
| Auth0 (Okta, Inc.) | Platform authentication | EU |
| Slack (Salesforce, Inc.) | Customer communication channel | EU |
| Brevo (Sendinblue SAS) | Customer communication | EU (France) |
| Stripe Technology Europe, Limited | Payment processing | EU (Ireland) / US |
| Microsoft Ireland Operations Limited | Max Scale application for Microsoft Teams — chat UI and document access | EU (North Europe / West Europe) |
Where the Customer configures enterprise single sign-on (SSO) through their own identity provider (e.g., Microsoft Entra), that provider processes authentication data under the Customer’s own agreement. Scale integrates with customer-configured identity providers but does not engage them as sub-processors.
Stripe processes payment data in the EU (Ireland) and may transfer certain data to the United States for fraud prevention and regulatory compliance purposes, subject to the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. Scale does not store payment card data directly; card data is tokenized and held by Stripe.
Service Providers for Scale’s Own Operations (Controller Role)
| Provider | Purpose | Location |
|---|---|---|
| Google Workspace | Internal email and collaboration | EU |
| Slack (Salesforce, Inc.) | Internal communication | EU |
| Brevo (Sendinblue SAS) | Email marketing | EU |
| Linear | Incident management and product management | EU |
| Zero.inc | CRM | EU |
| Jamie (wespond UG) | AI meeting notetaker | EU |
| Slite (Slite SAS) | Company wiki / knowledge base | EU |
| GitHub | Source code management | US |
| Scytale | Compliance automation | EU |
| Anthropic, PBC | AI-assisted development and internal operations | US |
| Stripe Technology Europe, Limited | Payment processing | EU (Ireland) / US |
| Plausible Insights OÜ | Cookieless website analytics | EU (Germany) |
| Google Cloud Platform (Firebase) | Website hosting, contact and newsletter form submissions | EU |
All providers listed above are bound by data processing agreements.
Personal data may also be disclosed where required by applicable law, regulation, court order, or binding request from a competent authority, or in connection with a merger, acquisition, financing, asset sale, or other corporate transaction, provided appropriate safeguards are implemented.
V. Data Security
Scale implements appropriate technical and organizational measures designed to protect personal data against unauthorized or unlawful access, disclosure, alteration, or destruction. Such measures are intended to ensure a level of security appropriate to the risk, taking into account the nature, scope, context, and purposes of processing, as well as the potential risks to individuals’ rights and freedoms.
Access to personal data is restricted to personnel who have a legitimate business need for such access and who are subject to applicable confidentiality obligations.
Further information regarding Scale’s security practices and controls is available in our Trust Center: https://trust.scale-company.com/
While Scale maintains safeguards designed to protect personal data, no method of transmission over the internet or electronic storage is entirely secure, and absolute security cannot be guaranteed.
VI. Data Protection Officer and Contact
If you have any questions about this Privacy Policy or our data processing practices, please contact:
Data Protection Officer
Scale Company Oy
Business ID: 3193447-1
Fenixinrinne 4 C 34
00580 Helsinki
Finland
Email: gdpr@scale-company.com
VII. Your Rights
As a data subject, you have the following rights under the GDPR (depending on the processing context and legal basis):
| Right | Description |
|---|---|
| Right of access | Obtain confirmation whether your personal data is processed and receive a copy (Art. 15 GDPR) |
| Right to rectification | Correct inaccurate or incomplete personal data (Art. 16 GDPR) |
| Right to erasure | Request deletion of personal data under certain conditions (Art. 17 GDPR) |
| Right to restriction of processing | Request limitation of processing under certain conditions (Art. 18 GDPR) |
| Right to data portability | Receive your personal data in a structured, machine-readable format (Art. 20 GDPR) |
| Right to object | Object to processing based on legitimate interest, including profiling (Art. 21 GDPR) |
| Right to withdraw consent | Withdraw consent at any time where processing is based on consent (Art. 7(3) GDPR) |
For Customer Data processed by Scale as a Processor (e.g., uploaded documents or project data), please contact your employer, who acts as the Controller.
For account, billing, or website data processed by Scale as a Controller, please contact us at gdpr@scale-company.com.
You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) or with the supervisory authority in the EU Member State of your residence or workplace.
VIII. Cookies and Tracking Technologies
Our websites do not use cookies or similar tracking technologies. We do not use advertising, profiling or cross-site tracking cookies anywhere, and we do not sell or share personal data for advertising purposes.
The Service uses a small number of strictly necessary cookies — to keep you signed in, to secure authorization flows when you connect an external content source, and to remember interface preferences. These are required to deliver the Service you have requested and are exempt from consent under applicable e-privacy rules. You can block them in your browser, but the Service will not function.
Website analytics are collected without cookies (see Section IV).
IX. Changes to This Policy
We may update this Privacy Policy from time to time.
If material changes are made, we will notify Customers’ designated administrators by email or through the Service with reasonable advance notice before the changes take effect.
The most recent version will always be available at:
maxscale.ai/privacy.