For security, privacy, and procurement teams. This Trust Center documents how Scalable (Machete Marketing Germany GmbH) protects customer data. It is provided for vendor due diligence and is shared on a confidential basis.
What's inside
- Security — hosting and data residency (EU/Frankfurt), encryption in transit and at rest, tenant isolation, technical and organizational measures (Art. 32 GDPR), and the certifications we inherit from our infrastructure providers.
- Sub-processors — the complete, named list of every sub-processor, the data each handles, processing location, and transfer safeguard. We give 30 days' advance notice of changes.
- AI & data processing — which providers process which inputs, our commitment that customer data is never used to train models, transfer safeguards, and our EU AI Act posture.
- Data Processing Agreement — our Art. 28 GDPR DPA template, including the EU Standard Contractual Clauses and annexes (processing description, TOMs, sub-processor list).
Key commitments
- No model training. We never use your data, or the personal data within it, to train or fine-tune AI models.
- EU data residency. Account and customer data are stored in the EU (Supabase, Frankfurt).
- First-party AI APIs. We call Google, OpenAI, and Anthropic directly under enterprise/no-training terms, with zero- or limited-retention modes where available.
- Transparent sub-processors. A full, named list is maintained and provided on request; we notify customers before adding or replacing one.
Requests
- Signed DPA: email legal@scalable.so with your legal entity name and we will provide a DPA for countersignature.
- Security questionnaires (SIG / CAIQ / custom): we are glad to complete them and to enter an NDA — contact legal@scalable.so.
- Anything else: legal@scalable.so.
This Trust Center is confidential and intended for the recipient's vendor-assessment use. Please do not redistribute publicly.