Privacy Policy

Version 2026-09-30 · Last updated: September 30, 2026

1. Who we are and what this policy covers

This Privacy Policy explains how Guiding Innovators GmbH, the company operating the ScaleXB brand (“ScaleXB”, “we”, “us”, “our”), processes personal data in accordance with the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (Datenschutzgesetz, DSG) and the Austrian Telecommunications Act (TKG 2021).

It covers the following services (together, the “Services”):

  • the public website scalexb.com: including the contact form, blog and interactive demos;
  • the ScaleXB application at plus.scalexb.com (the “App”), used by companies, fund managers and their teams (“Customers”) to structure, run and administer private capital raises;
  • the investor portal and the embeddable investment widget that a Customer can place on its own website or branded investor app (the “Investor Portal”), through which investors and prospective investors (“Investors”) register, complete identity verification, subscribe and manage their holdings.

By registering for the App you are asked to confirm that you have read this Privacy Policy. This confirmation is an acknowledgement under Articles 13 and 14 GDPR; it is not the legal basis for our processing, which is set out in section 5.

2. Controller and contact

Guiding Innovators GmbH
Salzgries 21/16, 1010 Vienna, Austria
Commercial register: FN 536594 i, Commercial Court of Vienna (Handelsgericht Wien)
Email for privacy matters: legal@scalexb.com

We have not appointed a statutory data protection officer because we are not required to do so under Article 37 GDPR. All privacy requests are handled by our legal team at the address above.

3. Our role: controller or processor

ScaleXB acts in two different capacities, and your rights differ depending on which applies.

3.1 ScaleXB as controller. We are the controller for personal data relating to:

  • visitors of scalexb.com and people who contact us or book a diagnostic call;
  • Customer users: the people who register an account in the App, are invited to a Customer’s team, or otherwise represent a Customer (contract data, account data, billing, support, security logs);
  • our own commercial relationships with partners, referrers, affiliates, law firms in the Legal Hub marketplace and other service providers.

3.2 ScaleXB as processor for our Customers. When a Customer uses the App or the Investor Portal to collect and manage data about its Investors, CRM contacts, marketing audiences, shareholders and website visitors, the Customer is the controller and ScaleXB processes that data as the Customer’s processor under Article 28 GDPR, on the Customer’s documented instructions and under the data processing agreement that forms part of our Terms of Service.

If you are an Investor, a shareholder or a contact of a company that uses ScaleXB, that company is responsible for informing you about its processing and for answering your data protection requests. You can still contact us; we will forward your request to the relevant Customer and assist them in answering it.

4. What personal data we process

4.1 Website visitors (scalexb.com)

  • Server and security logs: IP address, date and time of the request, requested page, referrer URL, browser and operating system, transferred data volume. Logs are kept by our hosting provider for security and troubleshooting.
  • Contact form: name, email address, company (optional), the category of your inquiry, your message and your consent confirmation. Messages are delivered by email to the inbox responsible for the category you select.
  • Diagnostic call booking: the details you give us when booking a call (name, email, company, description of your raise) and the notes we take during the call.
  • Referral and partner codes: if you reach scalexb.com through a partner or refer-a-friend link, the code from the link is stored in your browser (see section 9) and handed to the App if you register, so that the referring partner can be credited.

4.2 Customer users of the App

  • Account data: first name, last name, email address, password (stored only as a salted hash by our identity provider), nickname, time zone, language, role and permissions within the Customer’s team, the tenant(s) you belong to.
  • Security data: two-factor authentication secret (TOTP) if you enable it, one-time codes sent for sensitive actions, session and refresh tokens, IP address, device and browser information, login history and an audit trail of actions taken in the App (who changed what and when).
  • Contract and billing data: company name, registered address, VAT number, billing contact, subscription tier, add-ons, usage-based fees (for example the number of identity checks or signed documents), invoices and payment status. Card or bank details are collected directly by our payment provider; we only receive a payment reference.
  • Legal acceptance records: the version of the Terms of Service and of this Privacy Policy you accepted, with the timestamp of acceptance.
  • Support and communications: messages exchanged with our support team, in-app notifications, and your notification preferences.
  • Wallet data: if you connect or create a blockchain wallet in the App (for example an embedded wallet, MetaMask, WalletConnect, Coinbase Wallet, Freighter or another Stellar wallet, or the Concordium browser wallet), the public wallet address and the public transaction history associated with it. We never receive your private keys or seed phrases.
  • AI assistant conversations: if you use the in-app AI assistant, the messages you type, the conversation history of the session and the data the assistant retrieves from your tenant to answer you (see section 8).

4.3 Investors and contacts of our Customers (processed on behalf of the Customer)

  • Identity and contact data: salutation, first and last name, email address, mobile number, postal address, date of birth, gender, nationality, language, account type (individual or company) and, for companies, legal name, registration number, tax ID, industry and beneficial owners.
  • Identity verification (KYC/AML) data: images of identity documents (front and back), selfie and liveness check, face-match and document validity results, proof of address, phone and email verification, sanctions and politically exposed person (PEP) screening results, commercial register extracts and ownership structure. This data is collected by the identity verification provider the Customer has activated (see section 6) or by ScaleXB’s native verification module.
  • Investment and financial data: subscription orders, investment amounts, payment references, bank details (account holder, bank name, IBAN, BIC, securities account number), wallet addresses, token holdings, distributions, interest and dividend payments, withholding tax data, tax certificates and tax residency.
  • Documents and signatures: subscription agreements, term sheets, information documents and other documents provided to or signed by an Investor, including e-signature audit trails.
  • Governance and communication data: votes and consents in investor votings, messages exchanged with the Customer through the message centre, proposals and announcements.
  • CRM and marketing data: contact details, lifecycle stage, source, activities, meeting notes, email opens and clicks, consent status (granted, revoked, pending double opt-in), consent method and source, unsubscribe and bounce records.
  • Referral, affiliate and giveaway data: referral codes, referred contacts, rewards, commissions, claim codes and payout details.
  • Investor Portal analytics: a pseudonymous visitor identifier, session and event data, approximate location (country, region, city derived from the IP address), device type, traffic channel, referrer domain and campaign parameters (UTM). A Customer may choose to link visitor data to known Investor accounts in its own tenant.

5. Purposes and legal bases

We process personal data for the following purposes and on the following legal bases under Article 6 GDPR:

  • Providing the website and keeping it secure (server and security logs): Art. 6(1)(f), legitimate interest in a secure, working website.
  • Answering inquiries and diagnostic call requests (contact form and booking data): Art. 6(1)(b), pre-contractual steps at your request; Art. 6(1)(f) for general inquiries.
  • Creating and administering Customer accounts and providing the App (account, security, legal acceptance and support data): Art. 6(1)(b), performance of the contract with the Customer.
  • Two-factor authentication, one-time codes, audit trail and fraud prevention (security data): Art. 6(1)(f), legitimate interest in account security; Art. 6(1)(c) where record keeping is legally required.
  • Invoicing, payment collection and accounting (contract and billing data): Art. 6(1)(b) and Art. 6(1)(c), Austrian tax and accounting law (BAO, UGB).
  • Processing Investor and contact data for our Customers (all data in section 4.3): we act as processor on the Customer’s instructions (Art. 28). The Customer’s own legal bases are typically Art. 6(1)(b) (subscription contract), Art. 6(1)(c) (anti-money-laundering, securities and tax law) and Art. 6(1)(a) (marketing consent).
  • Crediting referral partners and affiliates (referral and partner codes): Art. 6(1)(f), legitimate interest in running partner programmes; Art. 6(1)(b) towards the partner.
  • Product news and marketing emails to Customer users (name, email, company): Art. 6(1)(a), consent, or § 174 TKG 2021 for existing customers, with an opt-out in every email.
  • AI assistant (conversation and retrieved tenant data): Art. 6(1)(b), a feature of the contracted Service that you choose to invoke.
  • Website statistics and advertising measurement on scalexb.com (pseudonymous online identifiers, IP address, device and browser data, pages visited, referrer, campaign parameters): Art. 6(1)(a), consent through the cookie banner, together with § 165(3) TKG 2021 for the cookies themselves. You can withdraw consent at any time under "Cookie settings" in the footer; withdrawal does not affect processing before it.
  • Improving and securing the Services, aggregated statistics (usage data, pseudonymised where possible): Art. 6(1)(f), legitimate interest in developing and protecting our product.
  • Establishing, exercising or defending legal claims; responding to authorities (any of the above, as necessary): Art. 6(1)(f) and Art. 6(1)(c).

Where we rely on legitimate interests we have balanced them against your interests and fundamental rights. You may object to such processing at any time (section 11).

6. Recipients and sub-processors

We share personal data only where necessary to provide the Services, where you or the Customer have asked us to, or where we are legally required to. Our service providers act on our instructions under data processing agreements.

6.1 Providers we use for all Customers

  • Amazon Web Services EMEA SARL: hosting of the App and Investor Portal, databases, file storage (S3), identity service (Cognito), key management, email delivery infrastructure. EU data centres; EU standard contractual clauses and the EU-US Data Privacy Framework for support access.
  • Netlify, Inc.: hosting and content delivery of scalexb.com. USA with EU edge locations; EU-US Data Privacy Framework and standard contractual clauses.
  • Resend, Inc.: transactional emails (account, one-time codes, notifications) and delivery of contact form messages. USA; EU-US Data Privacy Framework and standard contractual clauses.
  • Magic Labs, Inc.: embedded blockchain wallets and email one-time-code login for the Investor Portal. USA; standard contractual clauses.
  • Google Ireland Ltd. (Google Fonts): delivery of web fonts; Google receives the IP address of the requesting browser. EU / USA; EU-US Data Privacy Framework.
  • Google Ireland Ltd. (Google Tag Manager, Google Analytics, Google advertising tags): only if you consent in the cookie banner. Loads the tags on scalexb.com and measures site usage and, if you allow marketing, advertising performance. IP addresses are shortened by Google Analytics in the EU before storage. Google LLC in the USA may access the data; EU-US Data Privacy Framework and standard contractual clauses.
  • komoot GmbH (Photon): address autocomplete when entering postal addresses in the App. Germany.
  • thirdweb, Inc. and public blockchain node operators: reading from and submitting transactions to the Ethereum, Polygon, Avalanche, Stellar and Concordium networks. USA / decentralised; only public wallet addresses and transaction data are transmitted.
  • WalletConnect Foundation: relaying wallet connection sessions when you connect an external wallet. Switzerland; adequacy decision.
  • MoonPay and Transak: optional fiat-to-crypto on-ramp inside the Investor Portal; each is an independent controller for its own KYC. UK / USA; adequacy decision and standard contractual clauses.
  • Payment providers (Stripe Payments Europe Ltd. or Checkout.com), collection of subscription fees and, where activated, Investor payments. Ireland / UK; independent controllers for payment data.

6.2 Integrations a Customer can activate. The App lets each Customer connect additional services under its own contracts and credentials. When a Customer activates such an integration, the Customer decides which data flows to it and is the controller for that transfer. Currently available integrations include:

  • Identity verification and screening: Sumsub, iDenfy, Shufti Pro, OpenSanctions.
  • Custody and wallets: Fireblocks, Fireblocks Non-Custodial Wallet, Magic Link.
  • Payments: Stripe, Checkout.com.
  • E-signature: DocuSign, or ScaleXB’s native signing module.
  • Email and notifications: Resend, the Customer’s own SMTP server, Firebase Cloud Messaging.
  • Storage: Google Drive.
  • AI providers: Anthropic (Claude), OpenAI (ChatGPT), Google (Gemini), used with the Customer’s own API keys for the AI assistant and automations.
  • Regulated tied-agent services: MFC Service Group, under a separate agreement between the Customer and that provider.

6.3 Other recipients

  • Law firms and advisors in the Legal Hub marketplace: if a Customer requests a proposal or purchases a document from a law firm listed in the App, the Customer’s request and contact details are forwarded to that firm, which acts as an independent controller.
  • Referral partners and affiliates: receive aggregated statements about the customers or investors they referred; they do not receive Investor identity documents.
  • Our professional advisors: lawyers, auditors, tax advisors, bound by professional secrecy.
  • Authorities: courts, supervisory authorities, the Financial Market Authority (FMA), tax authorities and law enforcement where we are legally obliged to disclose.
  • Successors: in the event of a merger, acquisition or transfer of the ScaleXB business, the acquiring entity, under the same commitments.

7. Blockchain networks

Tokenised instruments issued through ScaleXB are recorded on public, distributed ledgers (currently Ethereum, Polygon, Avalanche, Stellar and Concordium, depending on the Customer’s configuration). Wallet addresses, token balances and transfers written to such a ledger are public, replicated across many independent nodes worldwide and cannot be altered or deleted by ScaleXB or anyone else.

We never write names, identity documents or other directly identifying data to a blockchain. Only a wallet address and transaction data are written. The link between a wallet address and a person is held off-chain in the Customer’s tenant and remains subject to the rights described in section 11. Please consider this before choosing to connect a wallet whose address is already publicly associated with you.

8. AI assistant and automated decision-making

The App contains an optional AI assistant that can answer questions about your tenant and, if you ask it to, create or update objects such as offerings and widgets. To do this it processes your messages together with data from your tenant (for example the list of your offerings). Conversations are processed by an AI model provider: either a provider the Customer has connected with its own API key, or ScaleXB’s default provider. We do not use your conversations to train models, and we contractually require our providers not to do so.

In accordance with Article 50 of Regulation (EU) 2024/1689 (the EU AI Act), we inform you that the assistant is an AI system and that its answers are AI-generated content. The AI features of the Platform are not high-risk AI systems under Annex III of the AI Act. Identity verification uses one-to-one biometric verification to confirm that a person is who they claim to be; it is not remote biometric identification within the meaning of the AI Act. Biometric data processed for this purpose is special category data under Article 9 GDPR and is processed on the basis of the Investor’s explicit consent obtained by the verification provider and the Customer’s anti-money-laundering obligations.

ScaleXB does not make decisions with legal or similarly significant effects on individuals solely by automated means. Identity verification and sanctions screening produce automated results (for example a face-match score or a screening hit), but the decision to accept or reject an Investor is taken by the Customer’s compliance staff, who can review the evidence and override the result.

9. Cookies and browser storage

On scalexb.com we use Google Tag Manager, Google Analytics and Google advertising tags only after you consent in the cookie banner. Until you decide, none of these tools is loaded and no data is sent to Google by them. You can change or withdraw your choice at any time under "Cookie settings" at the bottom of every page. We use the following storage:

  • scalexb_consent (scalexb.com, cookie): stores your choice in the cookie banner and when you made it. 12 months. Strictly necessary.
  • _ga, _ga_<ID> (scalexb.com, cookies set by Google Analytics): distinguish visitors and sessions for statistics. Up to 24 months. Only with consent to "Statistics".
  • _gcl_au and other Google advertising cookies (scalexb.com): link visits to ad clicks to measure advertising. Up to 90 days. Only with consent to "Marketing".
  • scalexb_referral / scalexb-referral (scalexb.com, cookie and local storage): remembers the refer-a-friend code from the link you arrived with so the referrer can be credited. 12 months.
  • scalexb_partner_id / scalexb-partner-id (scalexb.com, cookie and local storage): remembers the partner code from the link you arrived with and passes it to the App on signup. 12 months.
  • Session, access and refresh tokens (App, local storage): keep you logged in and authenticate API requests. Until logout or token expiry.
  • sidebar:state, darkMode, i18nextLng, product-tour (App, cookie and local storage): interface preferences such as sidebar position, colour theme, language and whether you completed the product tour. 12 months or until cleared.
  • Chatbot session id (App, local storage): keeps your AI assistant conversation together within a session. Until cleared.
  • Visitor identifier (Investor Portal, set by the Customer’s portal): pseudonymous first-party analytics for the Customer operating the portal. As configured by the Customer.

If you withdraw consent, we delete the Google cookies set on scalexb.com and stop loading the tags from the next page view. Google Analytics data is kept for 14 months and then deleted automatically.

The referral and partner cookies are set only when you arrive through a link that carries such a code. Under § 165(3) TKG 2021, storage that is strictly necessary to provide a service you have requested does not require consent. Where a Customer adds its own cookies or tracking to its Investor Portal, the Customer is responsible for obtaining any required consent.

10. Retention

We keep personal data only as long as needed for the purpose it was collected for, and then delete or anonymise it. Typical periods:

  • Website server logs: up to 30 days, unless needed to investigate a security incident.
  • Contact form and call inquiries: 12 months after our last exchange, unless a customer relationship follows.
  • Customer accounts and tenant data: for the duration of the subscription. After termination, the Customer has 30 days to export its data; we delete or anonymise the tenant within 90 days after termination, except for data we must keep under statutory retention duties.
  • Free-trial tenants that are not converted: deleted 90 days after the trial ends.
  • Contract, invoice and accounting records: 7 years from the end of the calendar year (§ 132 Federal Fiscal Code, BAO; § 212 Commercial Code, UGB), longer while relevant to pending proceedings.
  • Investor KYC/AML records held for a Customer: according to the Customer’s instructions and its own statutory duties; under the Austrian Financial Markets Anti-Money Laundering Act (FM-GwG) and comparable EU rules this is generally 5 years after the end of the business relationship, extendable to 10 years.
  • Legal acceptance records and audit trail: for the life of the account plus the general limitation period of 3 years, or 30 years for records evidencing securities subscriptions where the Customer instructs us to keep them.
  • Marketing consent and unsubscribe records: a hashed form of the email address of anyone who unsubscribed or was erased is kept indefinitely so that the opt-out continues to be honoured. The hash cannot be reversed to the address.
  • Security logs of the App: 12 months.
  • Blockchain records: permanent, as explained in section 7.

11. Your rights

Under Articles 15 to 22 GDPR you have the right to:

  • obtain confirmation whether we process your data, and a copy of it (access);
  • have inaccurate data corrected and incomplete data completed (rectification);
  • have your data deleted where there is no longer a lawful basis to keep it (erasure);
  • have processing restricted while a dispute about accuracy or lawfulness is resolved;
  • receive the data you gave us in a structured, commonly used, machine-readable format and have it transmitted to another controller (portability);
  • object at any time to processing based on legitimate interests, and to direct marketing without giving reasons;
  • withdraw a consent at any time, without affecting the lawfulness of processing before withdrawal.

To exercise these rights, email legal@scalexb.com. We may ask you to verify your identity. We respond within one month; this can be extended by two further months for complex requests, in which case we will tell you. Requests are free of charge unless they are manifestly unfounded or excessive.

If you are an Investor or contact of one of our Customers, please direct your request to that Customer where possible. If you contact us instead, we will forward it and support the Customer in answering.

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence or place of work. The authority responsible for us is:

Österreichische Datenschutzbehörde
Barichgasse 40-42, 1030 Vienna, Austria
Phone: +43 1 52 152-0 · Email: dsb@dsb.gv.at
www.dsb.gv.at

12. International transfers

Our primary hosting is located in the European Union. Some of the providers listed in section 6 are established in the United States, the United Kingdom or Switzerland, or may access data from there for support. Transfers to the UK and Switzerland are covered by European Commission adequacy decisions. Transfers to the USA rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission’s standard contractual clauses supplemented by technical measures such as encryption in transit and at rest. You can request a copy of the relevant safeguards from legal@scalexb.com.

13. Security

We apply technical and organisational measures appropriate to the risk, including: encryption of data in transit (TLS) and at rest; encryption of integration credentials and API keys with a managed key management service; role-based access control and tenant isolation in the App; optional two-factor authentication and one-time codes for sensitive actions; multi-person approval flows for critical changes; audit logging; short-lived pre-signed URLs for document upload and download; IP allow-listing for API access; regular backups; and a documented incident response process. If a personal data breach is likely to result in a risk to you, we will notify the competent authority within 72 hours and inform you or the responsible Customer without undue delay.

14. Children

The Services are directed at businesses and at adults who are eligible to invest. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with data, contact us and we will delete it.

15. Obligation to provide data

You are not legally obliged to provide personal data to us. However, we cannot create an account, answer an inquiry or provide the Services without the data marked as required in the respective form. For Investors, applicable anti-money-laundering law requires the Customer to verify identity before accepting a subscription, so identity data cannot be omitted.

16. Changes to this policy

We may update this Privacy Policy when our Services, our providers or the law change. The current version is always published at scalexb.com/privacy with its version number and date. If a change materially affects how we process data of registered App users, we will notify them by email or in the App and, where required, ask them to acknowledge the new version at their next login. Earlier versions are available on request.

17. Contact

Guiding Innovators GmbH · Salzgries 21/16, 1010 Vienna, Austria · legal@scalexb.com

See also our Terms of Service and Imprint.