Scalr Data Sharing Agreement

Scalr Data Sharing Agreement

Scale Holdings Ltd trading as Scalr. Effective 1 September 2026.

This agreement covers how we handle personal data about your members. It is short on purpose, but it is a full processor agreement under Article 28 of the UK GDPR.

It applies between Scale Holdings Ltd, company number 14591454, registered office 124 City Rd, London, EC1V 2NX ("Scalr", "we", "us") and the studio or group subscribing to the Scalr service ("you").

You accept it when you tick the acceptance box at checkout, because it is incorporated into the Scalr Terms and Conditions at https://www.wearescalr.com/scalr-terms-conditions/. Your acceptance is complete at checkout; at onboarding we ask you to confirm a few specifics, which does not create a second agreement.


1. Who is responsible for what

1.1 You are the controller of your member data. You decide why it is used and you are responsible for the lawful basis, the privacy notice given to members, and any consents needed.

1.2 We are your processor. We only use member data to run the service for you, on your instructions.

1.3 Where we handle data for our own purposes, such as your staff account details, our billing records and our own marketing to you, we act as controller for that limited data. Our privacy policy at https://www.wearescalr.com/scalr-privacy-policy/ covers it.

1.4 Your booking system provider (Mindbody, TeamUp, ABC Glofox, bsport, or others) and your own Meta and WhatsApp business accounts are your suppliers, not ours. Your instruction to us to connect to them is your authority for us to read data from them and send messages through them on your behalf.


2. What we process, and for how long

The detail is in Annex 1. In summary: we process behavioural data about your members, taken from your booking system, from leads you capture through Meta, and from notes your staff add in Scalr, in order to predict churn, improve lead to member conversion, produce insight for you, and send member messages in your name where you enable that.

We process this data for as long as your subscription is running, and then for the short wind down period in clause 8.


3. What you must do

3.1 Make sure you have a lawful basis to share member data with us, and that your privacy notice tells members that a third party engagement provider is used.

3.2 Only give us instructions that are lawful.

3.3 Health related data. You may end up sharing health related information with us in two ways. First, notes your staff add in Scalr about a member, which can include injuries, rehabilitation, pregnancy, mobility or other medical context. Second, the names of your classes and services, which can imply health status, for example pre natal, post natal, rehabilitation or back care. Both are special category data under Article 9 of the UK GDPR and need a higher standard of care from both of us. We do not read note fields from your booking system.

Before you add health related information, you must:

  • (a) have a valid Article 9 condition;
  • (b) keep a record of that consent that you can produce on request;
  • (c) make clear in your privacy notice that health related information is recorded and shared with an engagement provider, and what it is used for; and
  • (d) tell us promptly if a member withdraws consent or objects, so that we can exclude or delete their health related data.

We will process health related data only for the purposes in Annex 1, apply the additional safeguards in Annex 2, and will not include it in the aggregated benchmarks described in clause 4.6 or in cross customer model improvement under clause 4.7.

3.4 Impact assessment. Because health related data is involved, you should complete a data protection impact assessment before onboarding. We will give you what you need for it.

3.5 Where you use the messaging features, the messages go out in your name and you are the sender. You are responsible for the lawful basis or consent needed to contact members on that channel, for accurate contact details, and for honouring opt outs.

3.6 Tell us promptly if you receive a member request or a regulator query that involves data we hold for you.


4. What we will do

4.1 Instructions. We process member data only on your documented instructions. Those instructions are this agreement, the Terms and Conditions, the settings you choose in the service, and any further written instruction you give us. If we think an instruction breaks data protection law, we will tell you.

4.2 People. Everyone at Scalr who can access member data is bound by confidentiality obligations and is trained on handling personal data. Access is limited to those who need it.

4.3 Security. We keep the security measures set out in Annex 2, appropriate to the risk, as required by Article 32.

4.4 Member requests. If a member contacts us directly with a data protection request, we will pass it to you and will not respond on your behalf. We will help you respond to access, deletion, correction, objection and portability requests, at no extra charge for reasonable volumes.

4.5 Assessments. We will give you reasonable help with data protection impact assessments and any consultation with the Information Commissioner, so far as it relates to our processing.

4.6 No secondary use. We do not sell member data, and we do not use it for our own purposes, except that we may create aggregated, anonymised statistics and benchmarks that cannot identify you, your sites or any individual. We may keep and use those after you leave.

4.7 Model improvement. We may use member data to run and improve the models we operate for you. Where we use it to improve models used across our customer base, we do so only in aggregated or anonymised form, and we exclude health related data from that use.

4.8 Automated decisions. We do not use health related data to take decisions that produce legal or similarly significant effects for a member without human involvement. Scores and flags are generated automatically, but you decide how they are acted on, and a member may ask for human review through you.


5. Sub processors

5.1 You give us general authorisation to use sub processors. The current list is in Annex 3.

5.2 We will give you at least 14 days notice by email before we add or replace one. If you have a reasonable data protection objection, tell us within that period and we will work with you to resolve it. If we cannot, you may cancel your subscription without penalty and we will refund any fees paid for a period after cancellation. Objections should be sent to hello@wearescalr.com.

5.3 Every sub processor is bound by data protection terms at least as strict as these. We remain responsible to you for what they do.


6. Data breaches

6.1 If we become aware of a personal data breach affecting your member data, we will tell you without undue delay and in any event within 72 hours of becoming aware of it.

6.2 We will tell you what happened, which data and roughly how many people are affected, the likely consequences, and what we are doing about it. Where we do not have all of that immediately, we will send what we have and follow up.

6.3 You are responsible for deciding whether to notify the Information Commissioner or your members. We will give you the information and support you reasonably need to meet your 72 hour deadline. We will not notify your members or the regulator on your behalf unless you ask us to in writing.


7. Where data is held and transferred

7.1 Member data is stored in the United Kingdom, in the AWS London region and in MongoDB Atlas pinned to the London region. Workflow orchestration runs on an EU hosted n8n Cloud instance.

7.2 Where a sub processor is located outside the UK, we put in place a valid transfer mechanism, being the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. The sub processors located outside the UK are listed in Annex 3.


8. When you leave

8.1 You can export your data, or ask us for a copy in a common machine readable format, at any time while your subscription is active and for 30 days after it ends.

8.2 After that 30 day window we will delete or irreversibly anonymise member data within a further 30 days, and instruct our sub processors to do the same.

8.3 Backups roll off on our normal backup cycle. Point in time restore covers 7 days and snapshots are retained for 30 days, after which member data is gone from backup. Until then backups stay encrypted and are not used for any other purpose.

8.4 We may keep data where the law requires us to, and we may keep aggregated anonymised data as described in clause 4.6.

8.5 We will confirm deletion in writing if you ask.


9. Checking we are doing this properly

9.1 On request we will give you the information you reasonably need to show that we are meeting this agreement, including a completed security questionnaire and any certifications or test reports we hold.

9.2 You may audit us once in any 12 month period, on 30 days written notice, during business hours, without disrupting our operations, and subject to confidentiality. We may satisfy an audit request by providing the material in 9.1 first.

9.3 We will allow a further audit if a regulator requires it, or after a personal data breach affecting your data.

9.4 You cover your own audit costs, unless the audit shows a material failure by us, in which case we cover ours and yours.


10. Liability, changes and law

10.1 Liability under this agreement is subject to the limits in the Terms and Conditions at https://www.wearescalr.com/scalr-terms-conditions/.

10.2 If data protection law changes, or a new approved set of clauses is issued, we may update this agreement. Material changes come with at least 30 days notice by email.

10.3 This agreement is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

10.4 If this agreement and the Terms and Conditions conflict on data protection, this agreement applies.


Annex 1. Details of the processing

Subject matter: provision of the Scalr smart engagement service to you.

Duration: the term of your subscription, plus the wind down period in clause 8.

Nature of the processing: collection from your booking system by API, collection of lead form responses from your Meta account, storage, structuring, analysis, scoring and modelling, generation of insight and reports, and where you enable it, sending member messages in your name by SMS, email and WhatsApp and receiving replies.

Purpose of the processing: predicting member churn, improving trial to member conversion, surfacing behavioural insight for your team, and member outreach on your behalf.

Categories of data subject:

  • your current members
  • your trial members, leads and prospects who have enquired or booked
  • your lapsed and former members
  • your staff and instructors, where they appear in booking records or hold a Scalr login

Types of personal data (but not limited to):

  • identifiers: name, member or client ID, email address, mobile number
  • profile metadata: date of birth or age band where held, gender where held, home site, join date, leave date
  • membership metadata: membership or package type, status, start and end dates, freeze and cancellation events
  • behavioural metadata: bookings, attendance, cancellations, no shows, waitlist activity, class and service name, time of day, instructor, site, visit frequency and gaps between visits
  • commercial metadata: revenue, payment status, failed payments, spend banding and package purchases. We do not receive or store card numbers.
  • lead data: responses to lead forms you run on Meta platforms
  • staff notes: free text notes your team records about a member inside Scalr
  • messaging data: SMS, email and WhatsApp messages sent to and received from members in your name, including message content and delivery, open and reply status
  • platform usage: logins and activity of your staff users in Scalr

Special category data (Article 9): health related data, where you record it and have the condition required by clause 3.3. This arises from:

  • free text notes your staff add in Scalr, which may reference injury, rehabilitation, pregnancy, mobility, disability or other medical context
  • class and service names that imply health status, for example pre natal, post natal, rehabilitation or back care

We process this only to tailor risk scoring, insight and messaging for you. It is excluded from aggregated benchmarking and from cross customer model improvement.

We do not read notes or medical fields held in your booking system.

Criminal offence data: none.


Annex 2. Security measures

  • all member data stored in the United Kingdom, in the AWS London region and in MongoDB Atlas pinned to the London region
  • encryption at rest, and TLS 1.2 or above in transit
  • database access restricted by IP access list and SCRAM authentication
  • credentials and secrets held in the n8n encrypted credential manager and AWS Secrets Manager. No credentials in code or in spreadsheets.
  • access to member data restricted to a maximum of four named data officers at Scalr, on a least privilege basis, with access logged
  • individual named accounts, no shared credentials, prompt removal on leaving
  • successful workflow executions are not stored with payloads. Failed executions are retained for 7 days and then deleted automatically.
  • application logs record identifiers, counts and error codes, never message payloads, and are retained for 30 days in the London region
  • failure alerts contain metadata only, being workflow name, site ID, error class, record count and internal ID. No names, email addresses or phone numbers leave the pipeline in an alert.
  • encrypted backups with point in time restore across 7 days and snapshot retention of 30 days, pinned to the same region. No manual exports, local dumps or copies onto laptops. Restores happen in place.
  • no third party business intelligence tool is connected to production. Behavioural metrics are computed inside the database and surfaced in the Scalr application.
  • vendor review before any new sub processor is added
  • documented incident response process with a named owner
  • staff data protection and security training on joining and annually
  • restricted access to health related fields, limited to the named data officers, with access logged
  • health related data excluded from analytics exports, benchmarking datasets and cross customer model training by design

Annex 3. Sub processors

Sub processor What it does Data it touches Location
Amazon Web Services Hosting, compute and secrets management All member data United Kingdom, London region
MongoDB Atlas Database and encrypted backups All member data United Kingdom, London region
n8n Cloud Workflow orchestration between your booking system and Scalr Member data in transit during execution. Failed executions retained 7 days. European Union
Twilio SMS delivery to your members from the Scalr sending number, in your name Member name, mobile number, message content United States, covered by SCCs and the EU US Data Privacy Framework
SendGrid Email delivery to your members, sent from your studio email address Member name, email address, message content United States, covered by SCCs and the EU US Data Privacy Framework
Meta Platforms Lead capture from your lead forms, and WhatsApp business messaging where you link your own account Lead contact details, member mobile number, message content Global
Anthropic Generates outreach message templates. Templates use personalisation tokens that are substituted inside Scalr at send time. None. No member personal data is sent to the model. United States
OpenAI Generates outreach message templates. Templates use personalisation tokens that are substituted inside Scalr at send time. None. No member personal data is sent to the model. United States
Slack Failure alerting None. Alert metadata only, no personal data by design. United States, covered by SCCs and the EU US Data Privacy Framework
Stripe Subscription billing Your business and billing contacts only. No member data. United States
HubSpot Our CRM and marketing Your business contacts only. No member data. United States
Scalr