Trust Center
TRUST CENTER
How we protect your data
Scalantec builds and runs go-to-market systems for B2B companies. That work touches business contact data, and our clients' CRMs. This page sets out what we do to protect it, what we rely on our providers for, and what we do not have yet.
Entity: Scalantec GmbH, Berlin · HRB 277771 B
Last updated: 25 September 2026
Owner: Nicolas Schell, Managing Director
AT A GLANCE
Cloud-native
No servers, data centre or network of our own. Everything runs on vetted SaaS providers with their own certifications.
Business contacts only
Names, roles, companies, work emails and engagement data. No special categories, no consumer data.
MFA everywhere
Named accounts, least privilege, access reviews twice a year, same-day revocation when someone leaves.
48-hour notice
Affected clients hear from us within 48 hours of a confirmed personal data breach, as written into our DPA.
ARCHITECTURE AND DATA
A small team on managed platforms
Scalantec is a small team. We run no on-premise infrastructure. Client data lives on the platforms listed under sub-processors, each of which encrypts data in transit and at rest under its own published standards. We act as the access and orchestration layer on top.
For outbound and RevOps engagements we process business contact data of a client's target accounts: name, job title, company, business email and phone, LinkedIn profile, and the replies and meetings that result. We do not process special categories of personal data, and we do not process consumer data.
Work inside your CRM stays in your CRM. Where an engagement runs in a client's own HubSpot, Salesforce or Clay account, our team works under named user access that the client grants and can revoke. That data is not copied into a Scalantec-controlled system.
SECURITY CONTROLS
What is in place, and what is not
Status as of September 2026. "Via provider" means the control exists at the platform level of the sub-processor that holds the data, and we inherit it rather than operate it ourselves.
Multi-factor authentication (In place)
Enforced on every business account that supports it, and enabled on client-granted logins wherever the client's settings allow.
Named accounts, no shared logins (In place)
One account per person on every system. Initial credentials are sent through a separate channel and reset on first login.
Least privilege and access reviews (In place)
Minimum access per role. Rights reviewed at least twice a year and on every role change. Dormant accounts disabled.
Offboarding (In place)
Access to all company and client systems revoked the same day, starting with email, source control and client-facing tools.
Credential handling (In place)
Passwords in a password manager. API keys and tokens only in local environment files or a secrets manager. An automated pre-push scanner blocks credentials from reaching our shared repository.
Endpoint security (In place)
Full-disk encryption, automatic OS and application updates, screen lock and built-in malware protection on every device used for client work. Not yet a written device standard, and no central MDM.
Encryption in transit and at rest (Via provider)
TLS in transit and encryption at rest on every platform that holds client data. We manage no encryption keys of our own.
Logging and audit trail (In place)
Platform-level logs on each core tool (Google Workspace admin console, GitHub audit log, activity logs of list and campaign tools). No unified SIEM across tools.
Backups and recovery (Via provider)
Backups and disaster recovery under each provider's published service levels. We hold no self-hosted system whose failure could cause loss of client data.
Penetration testing and vulnerability scanning (Via provider)
We operate no infrastructure to test. Provider reports (for example SOC 2 Type II) are available on request where the provider shares them.
Security awareness training (Partial)
Credential handling, MFA and data handling are covered at onboarding and in our policies. No certified, continuous training programme yet.
Background checks (Not in place)
No third-party screening provider. Hiring relies on reference checks and work samples. Everyone signs confidentiality obligations that survive their engagement.
24/7 staffed incident hotline (Not in place)
Incidents can be reported by email at any time. Anything flagged urgent goes to the Managing Director immediately; everything else is triaged the next business day (CET).
POLICIES
Seven written policies, one owner
Approved by the Managing Director on 18 September 2026, communicated to the whole team, reviewed at least annually (next review September 2027). Full texts are shared with clients and prospects on request.
Information Security Policy (v1.0)
Least privilege, no local secrets, cloud-native operation, MFA, and how incidents and AI use tie into the other policies.
Access Control Policy (v1.0)
Named accounts, least privilege by default, client system access, same-day offboarding, reviews twice a year.
Data Protection Policy (v1.0)
GDPR principles, controller and processor roles, sub-processors, retention, data subject requests, international transfers.
Incident Response Policy (v1.0)
Reporting channel, triage, containment, assessment, client notification timelines, post-incident review.
Password and MFA Policy (v1.0)
MFA on every account, unique credentials, password manager, environment-file-only handling of API keys enforced by a scanner.
Third-Party and Supply Chain Policy (v1.0)
Due diligence before any tool is added, the current sub-processor list, annual review.
AI Usage Policy (v1.0)
Approved tools via commercial API only, no client data in consumer-tier tools, human review before anything reaches a client, no fabricated content.
GDPR AND DATA PROCESSING
You are the controller, we are the processor
For every client engagement the client is the controller and Scalantec the processor under Art. 28 GDPR. We sign our standard Data Processing Agreement (Version 1.0) before processing starts, or complete the client's own template. It contains the processing description, our technical and organisational measures and the sub-processor list as annexes.
Instructions: We process only on documented instructions. If an instruction looks unlawful, we say so and pause.
Breach notification: Without undue delay and within 48 hours of becoming aware of a personal data breach affecting client data.
Sub-processor changes: Notice at least 14 days before a change. Clients may object on data protection grounds within 14 days.
Retention and deletion: Data is kept for the engagement. After it ends we return or delete it at the client's choice, and delete within 30 days if we hear nothing.
Data subject requests: Requests that reach us are forwarded to the controller without delay. Requests about our own processing are answered within statutory timelines.
International transfers: Only under Standard Contractual Clauses, the EU-U.S. Data Privacy Framework or an adequacy decision, as listed per sub-processor below.
Audits: Written self-assessment, policies and provider reports first. On-site or remote audit once a year with 30 days' notice, and whenever a supervisory authority requires it.
Data protection contact: datenschutz@scalantec.com. See also our Privacy Policy and Terms and Conditions (§ 15).
SUB-PROCESSORS
Where client data can be processed
All platforms that can hold or process client personal data on our behalf. Tools a client licenses in its own account (its CRM, its own Clay workspace) are the client's processors, not ours. Reviewed at least annually and whenever a tool is added or removed.
Clay Labs Inc. (New York, USA)
Purpose: Building and enriching target-account and contact lists, where the work runs in our own Clay workspace.
Location: USA
Transfer mechanism: EU Standard Contractual Clauses
EmailBison Inc. (Toronto, Canada · SOC 2 Type II)
Purpose: Email outreach platform: sequences, sending, deliverability, reply tracking.
Location: USA, Germany, Finland, Sweden
Transfer mechanism: EU Standard Contractual Clauses; Canada adequacy decision
Outbox Labs Inc. (Zapmail) (Delaware, USA · operations in Bengaluru, India)
Purpose: Provisioning and management of sending mailboxes and domains.
Location: USA, India
Transfer mechanism: EU Standard Contractual Clauses
HeyReach Inc OÜ (Estonia · operations in Skopje, North Macedonia)
Purpose: LinkedIn outreach automation: connection requests, messages, reply tracking.
Location: USA (AWS)
Transfer mechanism: EU-U.S. Data Privacy Framework or EU Standard Contractual Clauses
Supabase Pte. Ltd (Singapore)
Purpose: Database for campaign tracking and reporting.
Location: EU, Ireland (AWS eu-west-1)
Transfer mechanism: EU Standard Contractual Clauses; data stored in the EU
Google Ireland Limited, Google Workspace (Dublin, Ireland)
Purpose: Business email, calendar and file storage for client communication and working files.
Location: EU and USA
Transfer mechanism: EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses
Anthropic Ireland Limited, Claude (Dublin, Ireland; processing by Anthropic, PBC, USA)
Purpose: AI-assisted drafting, classification and research via API. API data is not used for model training.
Location: USA
Transfer mechanism: EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses
OpenAI Ireland Ltd (Dublin, Ireland; processing by OpenAI OpCo, LLC, USA)
Purpose: AI-assisted drafting and classification via API. API data is not used for model training.
Location: USA
Transfer mechanism: EU Standard Contractual Clauses
INCIDENT RESPONSE
How an incident is handled
Report a suspected incident to nicolas.schell@scalantec.com at any time. Urgent reports are escalated to the Managing Director immediately, regardless of the hour. Scalantec has had no confirmed security incident or data breach to date.
Triage. Confirm scope: which system, which data, how many people affected.
Contain. Revoke or rotate the affected credential or account access immediately.
Assess. Establish whether client or personal data was exposed.
Notify. Affected clients within 48 hours of a confirmed personal data breach, and within any shorter period their contract requires. Critical cases get same-day notice that an investigation is under way.
Remediate and review. Fix the root cause and record what happened and what changed as a result.
BUSINESS CONTINUITY
Outages delay delivery, they do not lose data
We do not maintain a formal business continuity or disaster recovery plan, and we say so in questionnaires. With no owned infrastructure, our continuity risk is the availability of the SaaS platforms we work in. Client work and account access live in shared cloud tools rather than with one person, so another team member can pick up active work with minimal handover. A prolonged outage of a core tool would delay delivery; it would not cause loss of client data, which stays on the provider's platform under its own recovery arrangements.
AI USAGE
AI drafts, people decide
We use Anthropic Claude and OpenAI models through commercial API accounts whose terms exclude training on submitted data. Free or consumer-tier AI tools are never used with client or personal data. Anything AI-assisted that reaches a client, from outbound copy to reports, is reviewed by a team member first. AI is not used to make unsupervised decisions about a client's data or systems, and nothing AI-suggested is presented as fact without a real source.
CERTIFICATIONS AND ASSURANCE
No certificate of our own, and we say so
Scalantec holds no ISO 27001 or SOC 2 certification. For a team of our size with no infrastructure of its own, our assurance rests on three things: the written policies above, the controls in the table, and the independent certifications of the providers that actually hold the data (SOC 2 Type II and ISO 27001 as published by each provider). We complete customer security and NIS2 supplier questionnaires on request and answer them honestly, including the gaps.
REQUEST DOCUMENTS
What we can send you
Data Processing Agreement, Version 1.0 (Word and PDF)
Full policy set, seven documents
Technical and organisational measures (DPA Annex 2)
Current sub-processor list with transfer mechanisms
Completed NIS2 supplier security questionnaire
Provider certifications and reports, where the provider shares them
Send your questionnaire or request the documents
Security and data protection questions go straight to the Managing Director. Replies within one business day.
Button: Request documents (links to nicolas.schell@scalantec.com)
CHANGELOG
25 Sep 2026: First publication. Policy set v1.0 approved 18 September 2026. Data Processing Agreement v1.0 published. Sub-processor list reviewed.
