Privacy Policy

Last Updated: 8 February 2026

Scale Platforms Ltd ("we", "us", "our") operates digital applications and services. This Privacy Policy explains how we collect, use, store, and protect your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data Controller

Scale Platforms Ltd
Company No. 17006761
Email: privacy@scaleplatforms.co.uk

2. Data We Collect

2.1 Account Data

DataPurposeLawful Basis
Email addressAccount login, notificationsContract performance
NameDisplay in appContract performance
Auth0 user IDUser identification and data isolationContract performance
Authentication methodPasskey or password loginContract performance

2.2 Receipt Data

DataPurposeLawful Basis
Receipt imagesOCR extraction and record-keepingContract performance
Merchant name and addressExpense categorisationContract performance
Transaction date and timeTax year assignmentContract performance
Line items and pricesCategorisation and totalsContract performance
VAT amountsHMRC self-assessment supportContract performance
Category and HMRC categoryTax reportingContract performance

2.3 Project Data

DataPurposeLawful Basis
Project namesJob costing and organisationContract performance
Client namesJob trackingContract performance
Budget amountsFinancial trackingContract performance

2.4 Budget Data

DataPurposeLawful Basis
Budget names and amountsHousehold spending trackingContract performance
Category limitsSpending alertsContract performance

2.5 Technical Data

DataPurposeLawful Basis
IP addressSecurity, abuse preventionLegitimate interest
Browser/device typeService optimisationLegitimate interest
Application logsDebugging and service reliabilityLegitimate interest

3. How We Use Your Data

We use your data exclusively to:

  1. Provide the service: Process receipt images, extract data via OCR, categorise expenses, and store records.
  2. Authenticate you: Verify your identity via Auth0 to protect your account.
  3. Isolate your data: Ensure you only see your own receipts, projects, and budgets.
  4. Generate reports: Produce CSV exports and summaries for tax returns or household tracking.
  5. Improve the service: Analyse anonymised usage patterns to improve features (no personal data shared).

We do not:

  • Sell your personal data to third parties.
  • Use your data for advertising.
  • Share your receipt images or financial data with anyone.

4. Data Processing and Sub-Processors

We use the following sub-processors to deliver our service:

Sub-ProcessorPurposeData ProcessedLocation
Microsoft AzureCloud hosting, storage, databaseAll service dataUK South (London)
Azure Document IntelligenceOCR receipt scanningReceipt images (processed in-memory, not retained)UK South
Azure OpenAIAI categorisation fallbackReceipt text (processed in-memory, not retained)UK South
Auth0 (Okta)AuthenticationEmail, name, login credentialsEU (UK region)

All sub-processors are bound by data processing agreements. Azure services are configured in the UK South region to maintain UK data residency.

5. Data Storage and Security

5.1 Storage

  • Receipt images: Azure Blob Storage (UK South), encrypted at rest (AES-256), access controlled by user ID prefix.
  • Receipt data: Azure Cosmos DB (UK South), encrypted at rest, partitioned by user for data isolation.
  • Authentication tokens: Stored in browser memory only (not persisted to disk).

5.2 Security Measures

  • All data transmitted over TLS 1.2+.
  • Authentication via Auth0 with JWT tokens (RS256 signed).
  • Managed Identity for service-to-service authentication (no API keys in code).
  • All database queries filtered by authenticated user ID.
  • Passkey support (FIDO2) for phishing-resistant authentication.

6. Data Retention

Data TypeRetention PeriodJustification
Receipt data and imagesUntil you delete them, or account closure + 30 daysHMRC requires 5-year record keeping; we leave retention to you
Account dataUntil account closure + 30 daysContract performance
Application logs30 daysDebugging and operational support
Authentication logs90 days (Auth0)Security monitoring

You can delete individual receipts at any time via the app. Deleted data is permanently removed from our database and blob storage.

7. Your Rights (UK GDPR)

You have the following rights under UK GDPR:

RightHow to Exercise
AccessExport your data via CSV export in the app, or email us
RectificationEdit receipt details directly in the app
ErasureDelete receipts in the app, or request full account deletion
Data PortabilityUse CSV export to download your data
Restrict ProcessingEmail us to restrict processing
ObjectEmail us to object to processing
Withdraw ConsentWhere consent is the basis, withdraw at any time

Contact: privacy@scaleplatforms.co.uk. We respond within 30 days.

8. International Transfers

Your data is processed and stored in the United Kingdom (Azure UK South region). Authentication data is processed by Auth0 in the EU region.

We do not transfer your data outside the UK/EEA. If this changes, we will update this policy and ensure appropriate safeguards (Standard Contractual Clauses or UK adequacy decisions) are in place.

9. Children's Data

Our service is not directed at individuals under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. The "Last Updated" date at the top of this page indicates when the policy was last revised.

11. Complaints

If you are unsatisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

12. Contact Us

For any privacy-related questions or requests:

Email: privacy@scaleplatforms.co.uk