Privacy Policy
Last updated: 29 April 2026
This privacy policy explains how Scalux ("we", "us", "our") collects, uses, and protects personal data when you visit scalux.ai, engage with our outreach, request a proposal, or work with us as a client.
We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Scalux is a managed paid advertising service for B2B SaaS companies, operated by Scalux Ltd.
For the purposes of UK data protection law, we are the data controller for personal data we collect about website visitors, prospects, and our direct contacts at client companies. When we manage advertising campaigns on behalf of clients, we act as a data processor for personal data within those ad accounts (see Section 9).
If you have any questions about this policy or how we handle your data, contact us at vivek@scalux.ai.
2. Information we collect
2.1 Information you provide directly
When you contact us, request a proposal, book a call, or sign up to receive content, we may collect:
- Your name and job title
- Business email address and phone number
- Company name, website, and size
- Information about your advertising spend, goals, and current setup
- Any other information you choose to share with us during conversations or in documents
2.2 Information collected automatically
When you visit scalux.ai, we may collect:
- IP address and approximate location
- Browser type, device type, and operating system
- Pages visited, time spent, and referral source
- Cookie and similar tracking data (see Section 8)
2.3 Information from third-party sources
For sales and outreach, we use publicly available business data and B2B prospecting tools (such as Apollo and Hunter) to identify decision-makers at companies that match our ideal customer profile. The information we obtain is limited to business contact details — typically name, business email, job title, and company information — sourced from public professional profiles, company websites, and licensed business databases.
2.4 Information we process on behalf of clients
As part of delivering our service, we are granted access to client advertising accounts (Google Ads, LinkedIn Ads, and similar platforms) and analytics tools. These accounts may contain personal data — for example, lead form submissions, customer email lists used for audience targeting, or website visitor data. We process this data only to deliver the contracted service and under the terms of a Data Processing Agreement with each client.
3. Why we collect it and our legal basis
Under UK GDPR, we must have a lawful basis for processing personal data. Our bases are:
- Responding to enquiries and proposal requests
- Legitimate interests / steps taken at your request prior to entering a contract
- Delivering our service to clients
- Performance of a contract
- Sending cold outbound emails to business prospects matching our ICP
- Legitimate interests (B2B marketing to relevant decision-makers)
- Sending marketing communications to existing contacts
- Legitimate interests (with the right to object at any time)
- Operating and improving our website
- Legitimate interests
- Complying with legal, accounting, and tax obligations
- Legal obligation
- Defending against legal claims
- Legitimate interests
Where we rely on legitimate interests, we have carried out a balancing assessment to ensure our interests do not override your rights and freedoms. You can request details of this assessment by contacting us.
You can opt out of marketing communications at any time by replying "unsubscribe" to any email or contacting us directly.
4. How we use your information
We use personal data to:
- Respond to your enquiries and provide information you've requested
- Prepare and deliver proposals, audits, and onboarding materials
- Manage our client relationships and deliver our service
- Send relevant business communications, including outreach to potential customers in our ICP
- Improve our website, content, and service
- Meet our legal and regulatory obligations
We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals.
5. Who we share your information with
We share personal data only where necessary, and only with parties that provide adequate protection. Categories of recipients include service providers (sub-processors) that help us run our business and deliver our service.
We do not sell personal data to anyone.
A current list of sub-processors is available on request.
6. International transfers
Some of our service providers are based outside the UK, including in the United States. Where personal data is transferred outside the UK, we rely on appropriate safeguards such as:
- The UK's adequacy regulations (where the destination country has been recognised as providing adequate protection)
- The UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses
- Other lawful transfer mechanisms recognised under UK GDPR
You can request more information about the specific safeguards in place for any transfer.
7. How long we keep your information
We keep personal data only as long as necessary for the purposes set out in this policy:
- Prospect and outreach data: up to 24 months from last meaningful interaction, unless you object earlier
- Enquiry and proposal data: up to 24 months from the last contact, unless a contract is signed
- Client data: for the duration of the contract and 7 years afterwards (to meet legal, accounting, and tax obligations)
- Website analytics: typically up to 26 months
- Marketing preferences and unsubscribe requests: indefinitely, to ensure we honour your choices
After these periods, we will delete or anonymise the data unless we are required to retain it for legal reasons.
8. Cookies
Our website uses a minimal set of cookies and similar technologies that are strictly necessary to operate the site (for example, to remember basic preferences and ensure pages load correctly). We do not currently run analytics or marketing/advertising cookies on scalux.ai.
If we introduce analytics or marketing cookies in the future, we will update this policy and provide a cookie banner so you can manage your preferences. You can also block or delete cookies at any time via your browser settings; doing so may affect site functionality.
9. Client data and our role as a processor
When you engage Scalux as a client, we typically act as a data processor for any personal data within the advertising accounts and tools we manage on your behalf. In that capacity:
- We process data only on your documented instructions, as set out in our service agreement and a Data Processing Agreement (DPA)
- We apply appropriate technical and organisational measures to protect the data
- We notify you without undue delay if we become aware of a personal data breach
- We assist you in responding to data subject requests where reasonably required
- We delete or return the data at the end of the engagement, unless retention is legally required
A DPA is provided as part of our standard onboarding and is available on request.
10. Your rights
Under UK GDPR, you have the following rights in relation to your personal data:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — ask us to correct inaccurate or incomplete data
- Right to erasure — ask us to delete your data in certain circumstances
- Right to restrict processing — ask us to limit how we use your data
- Right to data portability — receive your data in a structured, commonly used format
- Right to object — object to processing based on legitimate interests, including direct marketing
- Right to withdraw consent — where we rely on consent, you can withdraw it at any time
To exercise any of these rights, email vivek@scalux.ai. We will respond within one month. There is no fee unless your request is manifestly unfounded or excessive.
11. Security
We take the security of personal data seriously. Our measures include:
- Encryption in transit (TLS) and, where appropriate, at rest
- Access controls and strong authentication for systems holding personal data
- Vetting of sub-processors for adequate security and data protection standards
- Regular review of our practices
No system is perfectly secure, but we work to ensure personal data is protected against unauthorised access, loss, or disclosure.
12. Children
Our service is intended for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18.
13. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent version. Material changes will be communicated where appropriate (for example, via email to active clients or a notice on the website).
14. Contact us
For any questions, requests, or complaints about this policy or your personal data:
Email: vivek@scalux.ai
This policy was last reviewed on 29 April 2026.