This disclosure explains how Scalable processes data through AI models, which providers receive which inputs, our no-training commitment, transfer safeguards, retention, and our posture under the EU AI Act (Reg. (EU) 2024/1689) and GDPR. It supplements (and does not replace) our Sub-Processor List and Data Processing Agreement.
1. Which AI providers process which inputs
Scalable uses third-party AI providers via their first-party APIs. We send only the data needed to perform the requested task. No customer data is used to train or fine-tune any model.
| Input type | Sent to | Purpose |
|---|---|---|
| Text prompts / instructions | Google (Gemini), OpenAI, Anthropic (Claude) | Language understanding, prompt expansion, generation instructions |
| Product data (titles, attributes, descriptions) | Google (Gemini), OpenAI, Anthropic | Context for copy and image generation |
| Reviews / customer-supplied text | Google (Gemini), OpenAI, Anthropic | Context and content generation |
| Uploaded images (product photos, references) | Google (Gemini), OpenAI, Fal.ai, Kie.ai | Image generation, editing, compositing, upscaling/processing |
| Generated images | Google (Gemini), OpenAI, Fal.ai, Kie.ai | Iterative generation and post-processing |
| Chat messages (in-app AI assistant) | Google (Gemini), OpenAI, Anthropic | Conversational assistance |
- Language generation: Google (Gemini), OpenAI, Anthropic.
- Image generation / editing: Google (Gemini), OpenAI.
- Specialised image generation / processing: Fal.ai, Kie.ai.
We do not send payment card data, and we minimise personal data sent to AI providers. We do not perform biometric identification and do not train on faces.
2. No training / no fine-tuning on customer data
Commitment: Scalable does not use customer data to train or fine-tune any AI model, and instructs all AI providers (as processors under Art. 28 GDPR) to process customer data solely to deliver the requested service. We rely on each provider's enterprise/API terms, privacy mode, and zero/limited-retention options where available.
| Provider | No-training basis | Retention configuration |
|---|---|---|
| Google (Gemini) | No training on our API data; processed under enterprise/API terms | EU data-residency requested where available; default prompt retention configurable on enterprise tiers |
| OpenAI | No training on API / enterprise data by default | Zero/limited data retention used where available |
| Anthropic (Claude) | No training on commercial/API inputs or outputs by default | Zero-data-retention agreement used where eligible |
| Fal.ai | No training per our processing instructions | Confirm provider retention terms |
| Kie.ai | No training per our processing instructions | Confirm provider retention terms |
A provider that re-used customer data for its own purposes (e.g. training its own models) would become an independent controller. Our contractual no-training instruction keeps each AI provider a processor acting on our documented instructions, consistent with Art. 28(3)(a) GDPR and EDPB Opinion 28/2024.
3. Data residency + transfer safeguards for AI processing
- Storage of record: All customer account data and content is stored in Supabase, EU (Frankfurt) region. AI inference involves transient transmission of inputs to the relevant provider for processing; outputs are returned and stored in the customer's account (EU).
- Google (Gemini): US, with EU data-residency regions requested where available. Transfer safeguard: EU-US Data Privacy Framework (DPF) adequacy (Google LLC certified).
- OpenAI: US. Transfer safeguard: EU 2021 SCCs (Module 2/3) + Transfer Impact Assessment; not DPF-certified. Our TIA accounts for US litigation-preservation risk affecting output-log deletion.
- Anthropic (Claude): US. Transfer safeguard: SCCs + TIA; not DPF-certified.
- Fal.ai / Kie.ai: assume US, assume non-DPF → SCCs + TIA.
We retain SCCs in DPF-vendor contracts as a fallback given the pending CJEU appeal of the DPF adequacy decision.
4. Retention of AI outputs
- Generated images and AI outputs are stored in the customer's account (Supabase, EU) until the customer or an authorised user deletes them, or until account deletion.
- On deletion, objects are removed from production storage; backup copies age out per our backup-retention schedule.
- AI-provider-side retention of inputs/outputs is minimised via zero/limited-retention configuration where available (see Section 2).
- Invoices and accounting records are retained for statutory periods under German law (8 years for accounting vouchers/invoices per §257 HGB, §147 AO, §14b UStG as amended by BEG IV; 10 years for trading books and annual financial statements per §257 HGB), separate from AI content.
5. EU AI Act posture (Reg. (EU) 2024/1689)
Scalable's roles:
- Provider of an AI system — we design the UI, generation pipeline, guardrails, and logging, and place the system on the EU market under our brand (even though the underlying model weights are third-party).
- Deployer of upstream general-purpose AI — we use Google / OpenAI / Anthropic / Fal models under our authority in a professional context.
- Not a GPAI provider — we do not retrain models at a scale that would reclassify us (we do not exceed the Commission's one-third-of-original-training-compute threshold; prompt engineering and light configuration do not cross it).
Most generative-image features sit in the limited-risk transparency layer (Art. 50), not high-risk.
Article 50 transparency obligations:
- AI interaction disclosure (Art. 50(1)): Users are informed they are interacting with AI, clearly in the UI.
- Synthetic-content marking (Art. 50(2)): From 2 Aug 2026 (machine-readable marking for pre-existing systems from 2 Dec 2026 under the Digital Omnibus), AI-generated image output must be marked. Our image models (Google, OpenAI) embed C2PA Content Credentials (a signed, machine-readable manifest identifying the content as AI-generated) and a SynthID watermark. We store the model's original output bytes without re-encoding, so these markers are preserved at rest and in standard downloads.
- Provenance preservation: Provenance markers embedded by upstream providers are preserved at rest and in standard (direct, paid) downloads. Some re-encoding steps (marketplace format/aspect presets, the free-plan preview watermark) can drop embedded metadata such as C2PA; the pixel-level SynthID watermark is more robust. Extending metadata preservation across all export paths is on our roadmap.
- Deployer support: Enterprise customers are themselves deployers under Art. 50(4), with their own deepfake/synthetic-content disclosure duties. Exposing a dedicated "AI-generated" flag in API responses to support those duties is on our roadmap.
The AI Act applies without prejudice to GDPR (Art. 50(6)).
6. Human oversight, accuracy, and no automated decisions with legal effect
- Human oversight: Outputs are generated on user request and reviewed by the user before use. Scalable does not auto-publish or auto-distribute AI outputs without user action.
- Accuracy disclaimer: AI-generated text and images may contain errors, artefacts, or inaccuracies. Outputs are creative/assistive aids, not statements of fact, and should be reviewed before commercial use. Customers are responsible for ensuring outputs comply with applicable advertising, IP, and consumer-protection law.
- No Art. 22 automated decisions: Scalable does not make decisions producing legal or similarly significant effects on individuals based solely on automated processing (Art. 22 GDPR). AI features generate content; they do not make eligibility, credit, employment, or comparable decisions about people.
7. DPIA stance
A Data Protection Impact Assessment (Art. 35 GDPR) is a strong candidate for at-scale image processing involving real people (realistic outputs, potential memorisation risk).
- As a processor for our customers' processing, Scalable has no standalone Art. 35 duty for the customer's processing but assists the controller (Art. 28(3)(f)) with the information needed for their DPIA.
- As a controller for our own processing (abuse/safety classifiers, marketing), we assess DPIA need for that processing.
Status (honest):
Current mitigations: no biometric identification, no training on faces, data minimisation, contractual no-training instruction to providers, and EU storage of record. A formal DPIA for at-scale image processing is on our roadmap; this section will be updated with its completion date.
Machete Marketing Germany GmbH (brand: Scalable). legal@scalable.so. Provided for customer due diligence; not legal advice. AI provider terms and DPF certifications must be verified live before reliance.