AI Agents How It Works Insights Pricing About Log in Sign up

Your data is protected at every layer.

Scaalr implements technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Here is how those commitments translate into practice.

A key only you hold

Optional ledger encryption on Growth and up.

72 hours

Maximum window for notifying the supervisory authority of a personal data breach under GDPR.

By design

Data protection principles embedded into systems from the outset, not bolted on afterward.

How we safeguard your data.

This page combines controls available in Scaalr with the commitments in our Privacy Policy and Terms of Service.

Read our Privacy Policy

Product control · Privacy Policy §7, §12

Encryption and customer-held keys

The sensitive fields in your books, encrypted with a key only you hold. Scaalr never stores it. On Growth and up, optional field-level protection covers sensitive accounting fields. The secret is derived in your browser, and Scaalr cannot recover it.

  • Account names, journal-entry descriptions, line notes, manually entered amounts, and bank-reconciliation narrative can be encrypted at rest.
  • System-generated amounts stay readable so reports can still total. Any total that includes a manually entered amount stays locked until you enter your secret in the browser.
  • Personal data is protected with measures such as encryption in transit and at rest, matched to how it's used.
  • International transfers use EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and Swiss-specific provisions, supported by transfer impact assessments.
Privacy Policy §7

Privacy Policy §12, §16 · Terms §3

Access controls and permissions

Access to personal data is governed by access minimization and role-based permissions. Account holders are responsible for maintaining the confidentiality of their credentials, and all activity under an account is attributed to that account holder.

  • Access minimization and role-based permissions enforced by default.
  • Account credential confidentiality required of every user.
Terms of Service §3

Privacy Policy §5(b), §12

Monitoring and incident detection

Scaalr employs logging, monitoring, and network security measures to detect, investigate, and prevent fraud, abuse, and security incidents across the Services.

  • Logging and monitoring of service activity.
  • Network security measures to protect infrastructure.
  • Fraud, abuse, and security incident detection and prevention.
Privacy Policy §5

Privacy Policy §15

Breach notification

In the event of a personal data breach, Scaalr follows defined notification timelines. As a controller, the competent supervisory authority is notified within 72 hours under GDPR. As a processor, the client is notified without undue delay. Under PIPEDA, affected individuals and the Privacy Commissioner are notified as required.

  • 72-hour supervisory authority notification under GDPR/UK GDPR.
  • Processor-to-controller notification without undue delay.
  • PIPEDA breach reporting and records maintenance.
Privacy Policy §15

Privacy Policy §12, §16

Secure development and privacy by design

Scaalr maintains secure development practices, vulnerability management, and data protection by design and by default. Data protection impact assessments are performed where processing is likely to result in high risk to individuals.

  • Secure development practices and vulnerability management.
  • Data protection by design and by default.
  • Data protection impact assessments (DPIAs) for high-risk processing.
Privacy Policy §16

Privacy Policy §4.1, §6(a) · Terms §8

Third-party and payment security

Payment card data is processed by third-party payment processors; Scaalr does not store full card numbers. All service providers and processors are bound by written contracts and process personal data only under Scaalr's documented instructions. Confidentiality obligations govern all information exchanged between parties.

  • Scaalr does not store full payment card numbers.
  • Service providers bound by written data processing contracts.
  • Mutual confidentiality obligations for all parties.
Terms of Service §8

Have a security question?

If you need more detail about any of the measures above, or want to discuss our Data Processing Agreement, reach out to our team directly.

Get in touch