Legal

Privacy

How personal data is processed for the website and dashboard.

Published: 13 September 2026

1. Who is responsible

The controller responsible for the processing described in this policy is:

Scalerail Solutions UG (haftungsbeschränkt)
Hohenzollernstr. 20
80801 München, Germany

For privacy questions or requests concerning your personal data, contact hello@scalerail.de.

This policy covers our website, dashboard, package services, and related customer communications. It also explains where we process information on behalf of a customer rather than for our own purposes.

2. Website and service operation

When you access our website or services, we and our hosting providers process technical information such as your IP address, requested resource, access time, browser or client information, and request or error details.

We use this information to deliver content, operate the service, investigate faults, and protect accounts and infrastructure against misuse.

The legal basis is our legitimate interest in providing a secure and reliable service under Article 6(1)(f) GDPR. Where processing is necessary to provide a service you have contracted for personally, Article 6(1)(b) GDPR also applies.

3. Accounts and workspaces

We process account details, including your name, email address, account identifiers, authentication and session information, workspace memberships, and access permissions. Depending on the features you use, this may also include profile information, invitations, and information supplied through an organization's sign-in or directory service.

We receive this information from you, your workspace administrator, or a sign-in provider connected to your account. We use it to authenticate users, administer workspaces, manage access, and provide the requested service.

Workspace administrators can access information needed to manage their workspace, such as members' identities, roles, and access permissions. Your organization's own privacy arrangements may also apply to its administration of your account.

The legal basis is Article 6(1)(b) GDPR where you are personally party to the service agreement. For users acting on behalf of an organization, we rely on our and the organization's legitimate interests in administering the business relationship and controlling access under Article 6(1)(f) GDPR.

4. Packages and repository content

Packages and associated metadata may contain personal data, such as author or maintainer names and email addresses. We process this information as needed to store, index, and distribute packages and provide repository functionality.

Information may come from customer uploads or publicly available package repositories. Content in public repositories can be accessed and downloaded by others. Access to private repositories is controlled through workspace and repository permissions. Removing public content cannot recall copies already obtained by others.

Where we process personal data in customer content solely on a customer's instructions, the customer determines the purposes of that processing and we act as a processor under the applicable data processing agreement. Requests concerning that content should normally be directed to the customer; we assist where required.

For processing we undertake as controller to operate public package indexes and distribution, we rely on our legitimate interest in making software packages and their attribution information available under Article 6(1)(f) GDPR.

5. Subscriptions and payments

We process billing contact information, customer and subscription identifiers, invoice information, and payment status to administer paid services and meet accounting obligations.

We use Stripe to process payments and manage subscriptions. Payment details are entered directly through Stripe's hosted services rather than our application. We receive the billing and transaction information needed to administer the customer relationship; our application does not collect full payment-card numbers or security codes.

Stripe also processes transaction and device information for its own purposes where applicable, including security, fraud prevention, compliance with financial obligations, and improving its services. Stripe's roles and processing are explained in its Privacy Policy.

Our legal bases are Article 6(1)(b) GDPR for contracts with individual customers, Article 6(1)(f) GDPR for administering relationships with organizational customers, and Article 6(1)(c) GDPR for statutory accounting and tax obligations.

6. Inquiries and customer communications

When you contact us, we process your contact details, message, and any business information you choose to provide, such as company name, team size, or the subject of your inquiry. We also process submission references, timestamps, and correspondence needed to handle the request.

Inquiries are handled by Scalerail through our business email and communication services. We use the information to respond, provide support, and manage the related customer relationship. Required and optional form fields are identified on the form.

The legal basis is Article 6(1)(b) GDPR for requests relating to a contract with you or steps you ask us to take before entering one. Otherwise, we rely on our legitimate interest in responding to inquiries and maintaining business relationships under Article 6(1)(f) GDPR. Statutory recordkeeping obligations may also require processing under Article 6(1)(c) GDPR.

7. Analytics and browser storage

Cloudflare Web Analytics

We use Cloudflare Web Analytics to understand website usage and performance. It measures information such as page visits, referrers, browser and device characteristics, and page-loading performance.

According to Cloudflare, this service does not use cookies or local storage for analytics and does not track individuals across its customers' websites. We use the resulting statistics to improve our website, not to build advertising profiles. The legal basis is our legitimate interest in understanding and improving website performance under Article 6(1)(f) GDPR.

More information is available in Cloudflare's Web Analytics documentation and Privacy Policy.

Functional cookies and storage

The dashboard and authentication services use cookies or similar mechanisms to maintain sessions and protect the sign-in process. Blocking these mechanisms may prevent sign-in or authenticated features from working. Authentication information expires or is renewed according to the applicable session settings.

The dashboard also stores the selected sidebar state in a cookie for up to seven days. You can remove cookies through your browser settings.

Storage or access that is strictly necessary to provide a service you expressly request is based on the exception in Section 25(2) TDDDG. Where other storage or access requires consent, it must be based on consent under Section 25(1) TDDDG. The GDPR legal bases for any associated personal-data processing are described in the relevant sections above.

8. Recipients and international transfers

We use service providers for hosting and infrastructure, authentication, communications, payments, and operational support. They receive the information necessary for their respective services. Providers processing personal data on our instructions are engaged under applicable data processing arrangements. Some providers, particularly payment providers, also act as controllers for their own purposes.

Information may also be disclosed to professional advisers or public authorities where necessary to meet legal obligations or establish, exercise, or defend legal claims. Workspace administrators and recipients of public repository content receive information as described above.

Our providers and their subprocessors may process data outside the European Economic Area, including in the United States. Where a transfer is covered by an applicable European Commission adequacy decision, we rely on that decision. Otherwise, we use appropriate safeguards, including the European Commission's standard contractual clauses and any necessary supplementary measures.

You can contact hello@scalerail.de for information about the safeguards applicable to your data and how to obtain a copy, subject to necessary protection of confidential information.

9. How long we retain information

Retention depends on the purpose of the information and any obligations that continue after that purpose ends:

  • Account and workspace information: retained as needed to provide and administer the account or workspace. Closing an account may leave records needed to resolve outstanding matters or meet legal obligations. Canceling a paid subscription does not itself close a workspace or request deletion.
  • Inquiries and correspondence: retained while handling the request and any related customer relationship, and afterward where necessary for applicable business-record obligations or legal claims.
  • Billing and accounting records: retained for the statutory periods applicable to the particular record under German commercial and tax law. Those requirements can continue after account closure.
  • Technical logs: retained for the period needed to investigate errors, security incidents, or misuse, taking account of the nature of the record and applicable provider retention settings. Records relevant to an unresolved incident or legal claim may be retained for that purpose.
  • Repository content: retained while needed to provide the repository service or, where we act as processor, according to the customer's instructions and applicable agreement.
  • Backups: deleted information may remain in protected backup copies until those copies expire or are replaced under the applicable backup cycle.

When the relevant purposes and retention obligations end, we delete or anonymize personal data. You can contact us for information about the retention applicable to a particular record or to request deletion where the legal conditions are met.

10. Providing information and automated checks

Browsing public pages does not require an account. Account, access, and billing information is necessary to provide the corresponding services. If required information is not supplied, we may be unable to create an account, process a payment, or answer an inquiry. Optional information is not required to use the core service.

We use automated checks for authentication, access permissions, subscription status, and service security. Payment providers may also apply automated payment and fraud checks. You can contact us about a rejected payment or restricted access.

11. Your rights

Subject to the applicable legal conditions, you may request access to your personal data, correction, erasure, restriction of processing, and data portability.

Where processing is based on Article 6(1)(f) GDPR, you have the right to object on grounds relating to your particular situation. You may object to processing for direct marketing at any time.

Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.

Send requests to hello@scalerail.de. We may request information reasonably necessary to verify your identity. We normally respond within one month; where a lawful extension is necessary, we will explain it within that period.

You may lodge a complaint with a data protection supervisory authority, particularly in the country of your habitual residence, workplace, or the alleged infringement. For our company in Bavaria, the relevant authority is the Bavarian State Office for Data Protection Supervision (BayLDA).

12. Updates

We may update this policy to reflect changes in the service or applicable requirements. The publication date identifies this version. Where a change requires additional notice or consent, we will provide that notice or obtain consent as required.