YOUR PRIVACY MATTERS

Privacy Policy

Learn how Smart Asset Management protects your privacy and handles your personal data.

Last updated: 25 September 2026

1. Information We Collect

When you use Smart Asset Management (SAM), we may collect the following types of information:

  • Account Information: Name, email address, and profile information when you create an account
  • Usage Data: Information about how you use our application, including features accessed and actions performed
  • Technical Data: IP address, browser type, device information, and operating system
  • Communication Data: Messages you send through our contact forms or support channels
  • Device & Licence Data: When you use the SAM desktop apps (Scout, Bridge, Forge, Swatch), we collect a hardware identifier (HWID) and device name to enforce per-licence device limits, plus operation counts for usage limits. The HWID is a one-way SHA-256 hash of your device components — we do not store raw hardware serial numbers or MAC addresses, and it cannot be reverse-engineered or used to track you outside the SAM ecosystem.
  • Payment Data: Billing is handled by Stripe. We do not see or store your full card number — Stripe provides us with a customer ID, subscription status, and the last 4 digits / card brand for display only.

2. How We Use Your Information

We use the collected information for the following purposes:

  • To provide and maintain our services
  • To authenticate your identity and manage your account
  • To improve our application and user experience
  • To respond to your inquiries and provide customer support
  • To send important updates about our services
  • To detect and prevent fraud or security issues

3. Legal Basis for Processing (UK GDPR Article 6)

Under the UK GDPR, we must have a lawful basis for processing your personal data. The table below sets out each processing purpose and the legal basis we rely on:

  • Account creation & authentication: Contract performance (Art. 6(1)(b)) — necessary to provide you with the service you signed up for.
  • Subscription billing & payment processing: Contract performance (Art. 6(1)(b)) — necessary to fulfil your subscription agreement.
  • Customer support & communications: Contract performance (Art. 6(1)(b)) — necessary to respond to your requests and manage your account.
  • Service improvement: Legitimate interests (Art. 6(1)(f)) — our legitimate interest in understanding aggregate usage and improving our products. We do not use web analytics, advertising, or tracking cookies.
  • Security, anti-piracy & fraud prevention: Legitimate interests (Art. 6(1)(f)) — protecting our service and intellectual property from fraud, piracy, and abuse, including device-locking via a hashed hardware identifier (HWID) and IP-based rate limiting. We have completed a Legitimate Interests Assessment for this processing and do not repurpose this data for advertising or profiling.
  • Marketing emails & newsletters: Consent (Art. 6(1)(a)) — only sent with your explicit opt-in consent. You can withdraw consent at any time via Account Settings or the unsubscribe link.
  • Financial record-keeping: Legal obligation (Art. 6(1)(c)) — required to comply with UK tax and accounting regulations (7-year retention).
  • Responding to legal requests: Legal obligation (Art. 6(1)(c)) — necessary to comply with court orders or regulatory requirements.

4. Data Sharing & Third Parties

We do not sell, trade, or rent your personal information to third parties. We may share information in the following limited circumstances:

  • Service Providers: Trusted third-party services that help us operate our platform
  • Legal Requirements: When required by law, regulation, or legal process
  • Security: To protect our rights, privacy, safety, or property
  • Business Transfers: In connection with a merger, sale, or transfer of assets

5. Your Rights Under UK GDPR

Under the UK General Data Protection Regulation (UK GDPR) and applicable UK data protection laws, you have the following rights regarding your personal data:

  • Right of Access (Article 15): You can request a copy of all personal data we hold about you. Use the data export feature in your Account Settings to download your data instantly.
  • Right to Rectification (Article 16): You can request correction of inaccurate or incomplete personal data through your Account Settings or by contacting us.
  • Right to Erasure (Article 17): You can request deletion of your personal data. Use the account deletion feature in Account Settings, or contact us. Account deletion is immediate; cascaded data (profile, licences, devices) is removed at the same time. Backups containing your data are overwritten within 30 days. Records we must retain by law (financial records, fraud-prevention logs) are kept for the legally required period and then deleted.
  • Right to Restriction (Article 18): You can request that we restrict processing of your personal data in certain circumstances, such as while we verify the accuracy of your data.
  • Right to Data Portability (Article 20): You can request your data in a structured, commonly used, machine-readable format (JSON). Use the data export feature in Account Settings.
  • Right to Object (Article 21): You can object to processing of your personal data for direct marketing purposes. Unsubscribe from newsletters via Account Settings at any time.

To exercise any of these rights, use the self-service features in your Account Settings or submit a request via our contact form (/contact). We will respond within 30 days.

6. Cookies

We use only essential cookies, for authentication and session management (powered by Supabase). We do not use analytics, advertising, or third-party tracking cookies. See our Cookie Policy for details.

  • Essential Cookies: Required for authentication and session management. These cannot be disabled without breaking core functionality.

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:

  • Account Data: Retained while your account is active. Deleted within 30 days of account deletion request.
  • Subscription & Billing Data: Retained for 7 years after subscription ends to comply with UK financial record-keeping regulations.
  • Usage Data: Operational usage such as download counts used for limit enforcement. Anonymised after 12 months; aggregated statistics may be retained indefinitely.
  • Support Communications: Retained for 2 years after last contact to provide continuity of support.
  • Device Identifiers: Cleared immediately upon account deletion or device removal from your account.
  • Security & Connection Logs: IP addresses used for rate limiting are stored only transiently in short-lived, hashed form. Server connection/security logs containing IP addresses are deleted or anonymised within 90 days.

8. International Data Transfers

Some of our service providers are based outside the United Kingdom (such as in the United States or the European Union). When your data is transferred internationally, we ensure appropriate safeguards are in place:

  • Adequacy Decisions: Where possible, we transfer data to countries that the UK government has determined offer an adequate level of data protection (such as the EU/EEA).
  • Standard Contractual Clauses (SCCs): For transfers to countries without an adequacy decision (such as the United States), we rely on UK-approved Standard Contractual Clauses or the UK International Data Transfer Agreement (IDTA) with our service providers.
  • Security Measures: Our international sub-processors are vetted to ensure they implement robust technical and organisational measures, such as SOC 2 compliance, data encryption, and strict access controls.

We only transfer personal data to countries or organisations that provide an adequate level of protection or where appropriate safeguards are in place.

9. Sub-Processors

We use third-party service providers (sub-processors) to help deliver our service. To simplify compliance and transparency, we group our sub-processors into the following categories:

  • Cloud & Database Hosting: Providers that host our application, database, and content delivery network.
  • Payment Processing: Secure payment gateways used to handle subscriptions and invoicing.
  • Email Communications: Services used to send transactional emails (receipts, security alerts) and marketing emails (if you have opted in).
  • Security & Performance Monitoring: Tools used for API rate limiting, error tracking, and maintaining application stability.
  • Analytics: Services used to analyze aggregate website usage and improve user experience.

A complete and current list of our specific sub-processors is available upon request by contacting our support team.

10. Data Protection Contact

The data controller is Scalefoundry Ltd, a company registered in England and Wales (company number 17457352), with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. For any data protection queries, concerns, or to exercise your UK GDPR rights, contact our data protection team:

Submit data protection requests via our contact form at /contact, selecting “Privacy / Data Protection” as the topic. We aim to respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.

11. Children’s Privacy

Our services are not intended for children under the age of 16 in the EU or 13 in the UK. We do not knowingly collect personal information from children under these ages. If we become aware that we have collected personal information from a child under the applicable age, we will take steps to delete such information promptly.

12. Data Breaches

We maintain technical and organisational measures to protect your data. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the UK Information Commissioner’s Office (ICO) within 72 hours of becoming aware of it, as required by UK GDPR Article 33. Where the breach is likely to result in a high risk to you, we will also notify you without undue delay.

13. Automated Decision-Making

We do not use your personal data for automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you (UK GDPR Article 22).

14. Governing Law

This Privacy Policy and our data protection practices are governed exclusively by the laws of the United Kingdom, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We do not represent that this policy complies with the specific data protection laws of other jurisdictions. By using our services, you acknowledge that your personal data will be processed in accordance with UK law.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically for any changes.

16. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk if you are unsatisfied with our response:

We will respond to privacy-related inquiries within 30 days of receipt.