Privacy Policy
Effective 25 September 2026 · Scale With Data, LLC
1. Two different roles
This policy covers two situations that are easy to confuse, so we separate them clearly.
When we are the controller. Information about you as a visitor to this site, or as a user at a customer organization, is data we decide the purposes for. This policy governs it.
When we are the processor. Information about your customers, contacts, leads, and the recordings of calls with them is data we handle on behalf of the business using Pulse. That business decides why it is processed. We act on their instructions. If you are a contact of a Pulse customer and want your data accessed or deleted, please contact that business directly. We will support them in responding.
2. What we collect
2.1 Account and contact information
Name, work email, phone number, company, role, and authentication identifiers. Collected when you request a demo, create an account, or communicate with us.
2.2 Usage and device information
Pages viewed, features used, timestamps, approximate location derived from IP address, browser and device type, and error diagnostics. Used to operate the service, investigate issues, and improve reliability.
2.3 Customer data processed on behalf of our customers
Contact records, lead information, sales records, payment references, calendar events, messages, and call recordings and transcripts. This is processed under the customer's instructions.
2.4 Payment and financial reference data
To verify revenue, we read transaction records from our customers' payment processors. We store transaction identifiers, amounts, currency, status, timestamps, and customer references. We do not receive, store, or process full payment card numbers.
2.5 Google user data
If you connect your own Google account to Pulse CRM, we receive the limited Google user data described in Section 15, which explains what we access, why, and how you can disconnect or ask for deletion.
3. Call recording and transcription
The platform records and transcribes sales calls where a customer enables that capability. Recording laws vary by jurisdiction and several require the consent of all parties.
The business operating the sales floor is responsible for providing the required notice and obtaining the required consent. We provide the tooling, including disclosure and dialing controls, but the legal obligation sits with the customer. Recordings and transcripts are stored encrypted, access controlled to the customer's own organization, and retained as described in Section 9: for the life of the account, except that recordings shorter than a set threshold are not retained. There is no per customer retention setting today, and this policy will not describe one until it exists.
4. How we use information
- To provide, operate, secure, and support the platform
- To reconcile and verify revenue against payment processor records
- To generate analytics, scoring, and coaching output for the customer whose data it is
- To communicate about your account, service changes, and security matters
- To detect, investigate, and prevent fraud, abuse, and security incidents
- To meet legal, tax, and accounting obligations
We do not sell personal information. We do not use customer data to train general purpose AI models, and we do not share one customer's data with another.
5. Aggregate statistics
We publish platform level aggregate figures, including on this website. Those figures are summed across all customer organizations and are constructed so that no individual organization, person, or transaction can be identified or reconstructed from them.
Concretely: we do not publish a figure composed of fewer than five organizations; every published amount is rounded to a coarse step before it leaves our systems, so a single transaction cannot be recovered by watching a total change; figures are reported as at the end of a completed hour rather than the current moment; and where one organization would make up too large a share of a figure, we widen the reporting period until it does not, or we do not publish the figure at all.
6. Legal bases
Where the General Data Protection Regulation or similar law applies, we rely on: performance of a contract, for providing the service; legitimate interests, for security, service improvement, and business communication; consent, where required, for example certain marketing; and legal obligation, for tax and compliance records.
7. Sharing
We share information with sub processors that help us deliver the service, each bound by contract to protect it. Our current sub processors are listed on our Trust and Security page and include cloud hosting, database, authentication, telephony, messaging, and artificial intelligence providers.
Where a customer requires a signed data processing addendum, including standard contractual clauses where applicable, we will enter into one; contact legal@scalewithdata.ai. We give notice before adding a new sub processor that processes customer data.
We may also disclose information where required by law or valid legal process, to protect rights and safety, or in connection with a merger or acquisition, in which case we will give notice before your information becomes subject to a different policy.
8. International transfers
Our legal and billing address is in the United States and our team operates from the United Arab Emirates, and we use infrastructure providers located in other countries, including the United States and the European Union. Where personal data moves across borders we rely on appropriate safeguards, including standard contractual clauses where applicable.
9. Retention
We keep account and contact data while your account is active and for a reasonable period after, to meet legal and accounting obligations.
Customer data is retained for the life of the account. We do not currently offer a per customer retention setting, and we would rather say so than describe a control you cannot use. Several retention jobs do run automatically: internal monitoring and error telemetry are pruned at 90 days, session replays at 30, and completed workflow execution records at 90. To limit storage cost we do not retain call recordings shorter than a set threshold. None of those touch your sales, contact, message or ledger records.
Two ingest logs are also pruned at 90 days, and they are worth describing separately because they are not pure telemetry. The first is the raw delivery log of webhooks we receive from your CRM, which carries a copy of the contact name, email and phone that arrived with each event. The second is the reconciliation trail that records how a sale, call or lead row was checked against its source. Pruning these removes the delivery envelope and the record of the check. It does not remove the underlying sale, contact, call or ledger row, which is retained for the life of the account as described above.
On termination, data is available for export for 30 days and is then deleted or anonymized, except where retention is legally required.
Ledger entries are immutable by design and are not deleted individually. Where erasure of personal data within the ledger is required and lawful, we anonymize the identifying fields while preserving the financial integrity of the record. That anonymization is carried out by our team on request rather than by a self serve feature.
10. Security
Encryption in transit and at rest, envelope encrypted credentials with a per tenant encryption context, least privilege database roles, audit logging, tenant isolation, and a documented recovery drill program with an append only drill log. More detail is on our Trust and Security page.
No system is perfectly secure. If a breach affects your information we will notify you and any required regulator without undue delay.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, and to withdraw consent. To exercise a right regarding data we control, email privacy@scalewithdata.ai. We will respond within the period required by applicable law.
If your data is held by a business using Pulse, contact that business first, since they decide how it is processed.
12. Cookies
We use cookies and similar technologies that are strictly necessary for authentication and security, plus a limited set for analytics that help us understand how the product is used. We do not use advertising cookies on this site or run third party ad tracking on it.
13. Children
The platform is a business tool and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.
14. Changes
We will post any update here with a new effective date, and will give notice of material changes by email or in the platform.
15. Google user data
This section applies when a user at a customer organization connects their own Google account to Pulse CRM. Connecting Gmail is optional. You start it yourself, from Pulse, through Google's own sign in and consent screen, and it covers only the Google account you connect.
15.1 What we access
Pulse asks Google for these permissions, and no others:
- Your Google account email address, so Pulse can show which mailbox is connected and send from it.
- Send email on your behalf. When you send an email from a contact record in Pulse, it is sent through Gmail from your address and appears in your Gmail Sent folder.
- Read your email. Pulse reads recent messages in your Gmail inbox to find replies from contacts in your organization's CRM. The first check looks back no more than 7 days, and each later check reads only mail that arrived since the last successful one.
Pulse does not change, label, archive, or delete any message in your Gmail account, and it does not read your mailbox history beyond that window.
15.2 How we use it
We use Google user data only to provide the CRM email features you can see and use in Pulse: sending email from a contact record, and showing a contact's replies on that contact's record so you and your team can follow the conversation.
When Pulse reads a message, it compares the sender's address with the contacts in your organization's CRM. If the sender matches exactly one contact, Pulse saves that message to the contact's record: the sender, recipient, subject, date, message and thread identifiers, and the body of the message. Attachments are counted but not downloaded. If the sender matches no contact, or more than one, the message is not saved. For email you send from Pulse, we save the recipients, subject, the message you wrote, and whether it was sent.
15.3 What we never do with it
Scale With Data does not sell Google user data, does not use it for advertising, and does not use it to determine creditworthiness or for lending purposes. We do not use Google user data, including data from Google Workspace APIs such as Gmail, to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
Our staff do not read your Google user data unless you or your organization ask us to for support, it is necessary for security purposes such as investigating abuse, or it is required by law.
15.4 Sharing
Messages saved from Gmail are visible only inside your own organization's Pulse account, and we do not share them with other customers. Google user data is stored in our application database and processed by the infrastructure providers that host the service, listed on our Trust and Security page, each bound by contract to protect it. We do not otherwise transfer it, except where required by law or in connection with a merger or acquisition, as described in Section 7.
15.5 Protection
The access and refresh tokens Google issues when you connect are encrypted with AES 256 before we store them, and Pulse refuses to store them at all if that encryption is not available. Saved messages are protected by the safeguards described in Section 10.
15.6 Retention, disconnecting, and deletion
We keep your Google tokens only while your Gmail account is connected. You can disconnect at any time from the Gmail card in Pulse CRM under Data and Sync. Disconnecting deletes the stored tokens immediately, and Pulse can no longer send or read email from that account. You can also remove Pulse's access from your Google Account at myaccount.google.com/permissions.
Messages already saved to contact records stay on those records as part of your organization's CRM history, and are retained and deleted with the rest of your organization's data as described in Section 9. To ask us to delete Google user data we hold, email privacy@scalewithdata.ai.
15.7 Google API Services User Data Policy
Scale With Data's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
16. Contact
Scale With Data, LLC
5830 East 2nd Street, Suite 700
Casper, WY 82609
United States
Operating location: Dubai, United Arab Emirates
Privacy: privacy@scalewithdata.ai
Security: security@scalewithdata.ai