Privacy Policy
How NOWScale collects, uses, shares and protects personal data — both as a controller of its own customer data and as a processor acting on behalf of business customers.
This Privacy Policy explains how NOWScale LLC (“NOWScale”, “we”, “us”) handles personal data in connection with the NOWScaleplatform, our websites, our API and the related services we provide (together, the “Service”). It is written to be read alongside our Terms of Service and our Cookie Policy.
1. Scope and our role
NOWScale is a business-to-business platform. Our customers are organisations and professionals who connect their social media accounts, upload and adapt video and other media, schedule and publish content, route work through team approval flows, and review cross-platform analytics and revenue attribution. Because of how the Service works, we handle personal data in two distinct capacities, and different parts of this policy apply to each.
1.1 Where we act as a controller
We are a controller — meaning we decide why and how personal data is processed — for the data that relates to our own relationship with you: account registration and login details, workspace and team member records, billing and subscription data, support correspondence, marketing preferences, security and audit logs, and the usage and device data generated when you use the Service. This policy is the primary notice for that processing.
1.2 Where we act as a processor
We are a processor— meaning we act on documented instructions from someone else — for the personal data contained in a customer’s content and in the data pulled from that customer’s connected accounts. That includes information about the customer’s audience and community: commenters, message senders, people appearing in uploaded media, and individuals reflected in audience, engagement, advertising or commerce datasets. In those cases the customer is the controller. They determine what is collected, why, and for how long; we process it to deliver the Service to them.
If you are a member of a customer’s audience, or an employee of a customer, and you want your data accessed, corrected or deleted, please contact that organisation first. We will assist our customer in responding, as required by our data processing terms, but we generally cannot act on such a request without their instruction. If you cannot identify or reach the relevant organisation, contact us at support@nowscale.com and we will try to help.
1.3 Who this policy does not cover
This policy does not cover the social media platforms, analytics providers, advertising networks, commerce systems or payment services you choose to connect. Those services are independent controllers of the data they hold, and their own privacy notices govern their handling of it. Connecting an account authorises us to exchange data with that service on your behalf; it does not place that service under our control.
2. Personal data we collect
2.1 Account and identity data
Name, work email address, password credentials (stored only in hashed form), job title or role, organisation name, profile photo where you supply one, language and time zone preferences, and the authentication method associated with your login.
2.2 Billing and subscription data
Billing contact details, billing address, tax identifiers, plan and entitlement records, invoice and transaction history, and the last four digits and card type or equivalent token returned by our payment provider. Payment card numbers and full financial instrument details are collected and processed directly by a third-party payment processor and are not stored on NOWScale systems.
2.3 Workspace and team member data
Records about the people in a workspace: invitation details, role and permission assignments, approval and review actions, comments left on drafts, assignment and ownership history, and activity timestamps used for audit trails and collaboration features.
2.4 Customer content and uploaded media
Video, audio, images, thumbnails, captions, descriptions, hashtags, scripts, transcripts, brand assets and any other material a customer uploads or generates in the Service, together with the platform variants we produce from it. This content may contain personal data — faces, voices, names and other identifying details of the people who appear in it. Customers are responsible for having a lawful basis and any necessary releases for that material.
2.5 Data from connected platform accounts
When a customer connects an account on a supported platform — including TikTok, Instagram, YouTube, Facebook, LinkedIn, X, Pinterest and Threads — we receive, subject to the scopes granted and each platform’s own rules:
- account and profile information, such as handle, display name, avatar, account type and connected page or channel identifiers;
- audience and follower metrics, typically in aggregate or demographic form as supplied by the platform;
- post and content performance data, such as impressions, reach, watch time, retention curves, saves, shares and click-throughs;
- comments, replies, mentions and direct messages, but only where the customer has enabled the relevant engagement or inbox features and granted the corresponding permissions;
- publishing and scheduling metadata, including post status, errors and platform-side identifiers.
We also hold the access and refresh tokens needed to maintain each connection. Tokens are held in encrypted form and are used only to perform actions the customer has asked for.
2.6 Analytics, advertising, commerce and payment source data
Where a customer connects an analytics, advertising, e-commerce or payment source to enable revenue attribution, we receive data such as campaign and ad set performance, spend, conversion and event data, order and transaction summaries, product catalogue information and referral attribution identifiers. The scope depends entirely on which sources the customer connects and which permissions they grant.
2.7 Usage, device and log data
Pages and features used, actions taken, timestamps, referring pages, IP address, approximate location derived from IP address, browser and operating system, device identifiers, crash and error reports, performance traces, and API request metadata including keys used, rate limit counters and webhook delivery outcomes.
2.8 Cookies and similar technologies
Identifiers set through cookies, local storage, pixels and SDKs. See section 12 and our Cookie Policy.
2.9 Support and other communications
Messages you send us through support channels, email, forms or chat, including attachments, diagnostic information you choose to share, and our records of the response. Where calls or sessions are recorded, we will tell you at the time and seek consent where required.
2.10 Sensitive data
We do not ask for special category data under GDPR Art. 9 (such as data revealing health, race or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation, or genetic and biometric data processed for identification). Customer content may incidentally contain such material because of what a customer chooses to upload; customers should not use the Service to process special category data unless they have satisfied themselves that they have a valid condition for doing so under applicable law.
3. Where the data comes from
- Directly from you — registration, configuration, uploads, billing details, support contact and marketing sign-ups.
- From the organisation you work for — a workspace administrator may create your account, assign your role, or supply your contact details when inviting you.
- From connected platforms and sources — via their APIs, under the authorisation granted during connection.
- Automatically — through your use of the Service, our servers, our API and cookies and similar technologies.
- From service providers — such as our payment processor, fraud and abuse prevention tooling, and infrastructure providers, in each case limited to what is needed to run the Service.
- From public or commercial sources — limited business contact information used for sales and marketing outreach, where permitted by law.
4. How we use personal data and our legal bases
Where the GDPR or UK GDPR applies and we act as a controller, we rely on the legal bases set out below. Where we act as a processor, our customer is responsible for identifying the legal basis for the processing they instruct.
| Purpose | What this involves | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Service | Creating and maintaining accounts, storing and transcoding media, generating platform variants, scheduling and publishing, running approvals, returning analytics. | Performance of a contract (Art. 6(1)(b)); legitimate interests where the user is not the contracting party (Art. 6(1)(f)) |
| Maintaining connected accounts | Holding and refreshing access tokens, syncing profile and performance data, retrying failed publishes. | Performance of a contract (Art. 6(1)(b)) |
| Billing and account administration | Taking payment, issuing invoices, managing plans, collecting unpaid amounts, tax and accounting records. | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting |
| Support and communications | Answering questions, investigating faults, sending service, security and change notices. | Performance of a contract (Art. 6(1)(b)); legitimate interests in supporting our users (Art. 6(1)(f)) |
| Security, fraud and abuse prevention | Authentication, rate limiting, anomaly and abuse detection, audit logging, protecting accounts and infrastructure. | Legitimate interests in securing the Service (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) where applicable |
| Service improvement and troubleshooting | Understanding feature usage, diagnosing errors, measuring performance and reliability. | Legitimate interests in maintaining and improving our product (Art. 6(1)(f)) |
| AI-assisted features | Producing hook and retention analysis, caption suggestions and best-time recommendations at the user’s request. See section 5. | Performance of a contract (Art. 6(1)(b)) |
| Model improvement beyond delivering the feature | Any use of data to improve models beyond producing the requested output. See section 5. | Consent (Art. 6(1)(a)) — opt-in |
| Marketing to business contacts | Product announcements, newsletters and event invitations to business contacts and prospects. | Consent (Art. 6(1)(a)) where required; otherwise legitimate interests in promoting our business (Art. 6(1)(f)) |
| Cookies and similar technologies | Session management, preferences, analytics and, where enabled, advertising measurement. | Consent (Art. 6(1)(a)) for non-essential cookies; legitimate interests (Art. 6(1)(f)) for strictly necessary ones |
| Legal claims and compliance | Responding to lawful requests, enforcing our terms, establishing or defending legal claims. | Legal obligation (Art. 6(1)(c)); legitimate interests in protecting our rights (Art. 6(1)(f)) |
| Corporate transactions | Due diligence and transfer in connection with a merger, financing or sale of assets. | Legitimate interests in corporate activity (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have assessed those interests against your rights and freedoms and concluded that the processing is proportionate. You may ask for a summary of that assessment, and you may object to the processing, using the contact details in section 14.
5. Artificial intelligence and machine learning
The Service includes AI-assisted features such as hook and retention analysis, caption generation and best-time-to-post recommendations. We take a deliberately conservative position on the data used to power them, and we would rather understate than overstate what we do.
- Customer content is not used to train general-purpose or foundation models — whether ours or a third party’s. Content submitted to an AI-assisted feature is processed to produce the requested output for that customer and is not added to a general training corpus.
- Model improvement. Where we work on improving models or features, we use aggregated or de-identified data that is not reasonably capable of identifying an individual or attributing content to a specific customer, or we rely on data a customer has explicitly opted in to share.
- Third-party model providers. Some AI features may be delivered using third-party model providers acting as our subprocessors under written terms. A current list of subprocessors is available on request.
- Human review. We do not routinely read customer content. Limited access may occur to investigate a fault the customer has reported, to respond to a suspected violation of our Acceptable Use Policy, or where the law requires it, and is subject to access controls and logging.
- No solely automated decisions with legal effect.AI outputs in the Service are suggestions and analyses intended to inform a person’s decision. We do not use them to make decisions producing legal effects concerning you or similarly significantly affecting you within the meaning of GDPR Art. 22.
- Accuracy. AI outputs may be incomplete or wrong. Recommendations, predicted performance and generated captions should be reviewed before they are relied on or published.
6. Sharing and disclosure
We share personal data only in the circumstances described below.
6.1 Subprocessors and service providers
We use vendors to provide infrastructure, storage, media processing, email delivery, error monitoring, product analytics, payment processing and support tooling. Each is engaged under written terms that restrict them to processing on our instructions, impose confidentiality and security obligations, and require them to assist with data protection obligations. A current list of subprocessors is available on request.
6.2 Connected platforms, at the customer’s direction
When a customer schedules, publishes or syncs, we transmit the relevant content and metadata to the platforms and sources they have connected. This is done on their instruction, and each receiving platform then handles that data as an independent controller under its own terms.
6.3 Within a workspace
Workspace administrators and other members can see activity, content, comments, approval history and account details associated with the workspace, according to the roles and permissions configured. If you use a work account, your employer may be able to access and control it.
6.4 Professional advisers
Lawyers, auditors, accountants, insurers and similar advisers, where they need the data to advise us and are bound by duties of confidentiality.
6.5 Legal and regulatory requests
We may disclose personal data where we believe in good faith that disclosure is required by applicable law, regulation, legal process or enforceable governmental request, or is necessary to protect the rights, property or safety of NOWScale, our users or the public. We assess such requests, seek to narrow those that are overbroad, and — unless legally prohibited or the request concerns an emergency — will notify the affected customer so they can seek protective relief.
6.6 Corporate transactions
If we are involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be disclosed to counterparties and their advisers under confidentiality obligations, and may transfer as part of the transaction. We will provide notice before personal data becomes subject to a materially different privacy policy.
6.7 We do not sell personal information
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA and comparable US state privacy laws. We have not done so in the preceding twelve months.
We also do not sell or knowingly share the personal information of individuals under 16 years of age.
7. International transfers
NOWScale operates internationally, and personal data may be processed in countries other than the one in which it was collected, including the United States. Those countries may not offer the same level of data protection as your home jurisdiction.
Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on an appropriate safeguard recognised under applicable law. The mechanism we rely on is the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum issued under s.119A of the Data Protection Act 2018 for UK transfers, and the Swiss adaptations where relevant.
Alongside the contractual mechanism we apply supplementary measures such as encryption in transit and at rest, access restrictions and a policy of challenging overbroad government access requests. You may request a copy of the relevant safeguards, with commercially sensitive terms redacted, by writing to support@nowscale.com.
8. Retention
We keep personal data only as long as we need it. Rather than publish fixed periods we cannot honour consistently, we set retention by applying the following criteria:
- how long the data is needed to provide the Service and maintain the account;
- whether the customer has configured a shorter or longer period, or deleted the item themselves;
- statutory retention requirements, particularly for tax, accounting and corporate records;
- limitation periods for legal claims, and whether a claim, dispute or investigation is live or reasonably anticipated;
- the need to keep security, audit and abuse-prevention records long enough for them to be useful;
- the sensitivity of the data and the risk of harm from unauthorised access.
On termination or expiry of a customer’s subscription, we will delete or return customer content and associated personal data within ninety (90) days of the effective termination date, subject to any period the customer has agreed for export, and subject to backup rotation. Data held in encrypted backups persists until those backups expire on their ordinary cycle [TO BE CONFIRMED — insert the actual backup retention cycle], during which it is isolated from active processing and deleted on expiry.
We may retain aggregated or de-identified data that can no longer be associated with an identifiable person for as long as it remains useful.
9. Security
We commit to maintaining technical and organisational measures appropriate to the risk of the processing. These include:
- encryption of personal data in transit over public networks;
- encryption of personal data at rest in our production systems;
- encrypted storage of secrets, including platform access and refresh tokens and API keys;
- role-based access control, least-privilege provisioning, and prompt revocation when access is no longer required;
- multi-factor authentication for administrative and production access;
- logging and monitoring of access to production systems and personal data;
- network segregation, hardened configuration and managed vulnerability patching;
- a documented incident response process covering detection, containment, assessment, notification and post-incident review;
- confidentiality obligations and security awareness training for personnel with access to personal data;
- security requirements imposed on subprocessors through written terms.
These are commitments about how we operate. We make no claim in this policy to hold any particular security certification or attestation.
No system is perfectly secure. You are responsible for keeping your credentials confidential, enabling available account protections, and managing who has access to your workspace. If you believe your account has been compromised, or you have found a vulnerability, contact support@nowscale.com promptly.
10. Your rights
The rights available to you depend on where you live and on whether we act as controller or processor for the data in question. Where we act as a processor, we will refer your request to the relevant customer and assist them in responding.
10.1 EEA, UK and Switzerland
Subject to the conditions in applicable law, you have the right to:
- access the personal data we hold about you and obtain information about how it is processed;
- rectification of inaccurate data and completion of incomplete data;
- erasure of your data in the circumstances set out in Art. 17;
- restriction of processing while a dispute about accuracy or lawfulness is resolved;
- data portability — receiving data you provided in a structured, commonly used, machine-readable format, and having it transmitted to another controller where technically feasible;
- object to processing based on legitimate interests, and to object at any time and without justification to processing for direct marketing;
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
- lodge a complaintwith your local supervisory authority or, in the UK, the Information Commissioner’s Office. We would appreciate the chance to address your concern first.
10.2 United States state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana or another state with a comprehensive privacy law, you may have the right to:
- know what personal information we collect, the categories of sources, the purposes, the categories of third parties we disclose it to, and to obtain a copy;
- delete personal information we have collected from you, subject to statutory exceptions;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information and of targeted advertising — see section 6.7 for our position on this;
- limit the use and disclosure of sensitive personal information to what is necessary to provide the Service;
- opt out of profiling in furtherance of decisions producing legal or similarly significant effects;
- non-discrimination — we will not deny service, charge a different price or provide a lesser quality of service because you exercised a privacy right;
- appeal a decision to refuse a request. To appeal, reply to our decision or write to support@nowscale.com with “Privacy Appeal” in the subject line. We will respond within the period your state’s law allows and, if we deny the appeal, tell you how to contact your state attorney general.
You may use an authorised agent, and we may ask for proof of their authority and verify your identity directly. We honour opt-out preference signals such as Global Privacy Control as described in our Cookie Policy.
10.3 How to exercise your rights and what to expect
Write to support@nowscale.com, or use the in-product privacy controls where available. We will verify your identity — usually by confirming control of the email address on the account, and by asking for further information where the request is sensitive or high risk. We do not collect additional data solely to verify a request beyond what is necessary.
We aim to respond substantively within one month for requests under the GDPR or UK GDPR, extendable by a further two months where a request is complex or numerous, in which case we will tell you within the first month and explain why. For requests under US state laws we aim to respond within 45 days, extendable once by a further 45 days with notice. Requests are free of charge unless manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline, and will explain our reasoning.
11. Children
The Service is a business tool and is not directed to children. You must be at least 16 years old to hold a NOWScale account, and older if the age of digital consent in your country is higher. We do not knowingly collect personal data from children below that age. If you believe a child has provided personal data to us, contact support@nowscale.com and we will delete it promptly.
Customers are responsible for the content they upload, including content featuring minors, and for obtaining any consent required from a parent or guardian.
12. Cookies and similar technologies
We use cookies, local storage and similar technologies to keep you signed in, remember preferences, measure how the Service is used and, where applicable, measure our marketing. Non-essential technologies are set in the EEA and UK only with your consent, and can be declined or withdrawn at any time. Our Cookie Policy sets out the categories used, how long they last, and how to control them.
13. Changes to this policy
We may update this policy as the Service, our practices or the law change. The date at the top of this page shows when the current version took effect. If a change is material — for example a new purpose of processing, a new category of recipient, or a change that reduces your rights — we will give advance notice by email to the address on the account, by an in-product notice, or both, before it takes effect. Continuing to use the Service after a change takes effect means the updated policy applies; where the law requires consent for a change, we will ask for it.
We keep prior versions and will provide one on request to support@nowscale.com.
14. Contact us
For any privacy question, request or complaint, or to exercise a right under section 10:
- Privacy team: support@nowscale.com
- Data protection contact: support@nowscale.com. This mailbox is monitored by the team responsible for data protection.
- Security reports: support@nowscale.com
- Legal notices: support@nowscale.com
- Postal address: NOWScale LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States
NOWScale LLC is formed in Wyoming. This policy is governed by Wyoming, without limiting any mandatory rights you have under the data protection law of your own country.
Questions about this document? Contact support@nowscale.com.