Privacy Policy
How BeautyScale handles personal data — yours, your team’s, and that of the buyers in our database. Written to be read, not to be survived.
Two different roles. BeautyScale processes personal data in two capacities, and they are governed differently. As a controller, we decide how we handle our own prospects, website visitors and the buyer contacts in our database. As a processor, we handle the data our customers load into their own instance of the Platform, strictly on their instructions and under a separate Data Processing Agreement. This page covers the first role. For the second, the Data Processing Agreement signed with each customer prevails.
1. Who we are
BeautyScale, a division of Greenova Tech LLC, a New Mexico limited liability company, of 8206 Louisiana Blvd NE STE A, Albuquerque, New Mexico 87113, United States (“BeautyScale”, “we”).
For data protection questions, write to privacy@beauty-scale.co. You can also reach us at +33 7 66 36 59 33.
2. What we collect, and why
| Who | What | Why | Legal basis |
|---|---|---|---|
| Website visitors | IP address and browser details, in server logs only | Serving the site and keeping it secure | Legitimate interest. This site sets no cookies and runs no analytics — see the Cookie Policy |
| People who contact us | Name, business email, company, what you wrote | Replying and assessing whether there is a fit | Steps taken at your request before entering a contract |
| Customer users | Name, business email, role, activity in the Platform | Providing, securing and supporting the Platform | Performance of our contract |
| Buyer contacts | Name, job title, employer, business contact details, professional profile | Building the buyer database our customers use to reach retailers and distributors | Legitimate interest — see the Buyer Database Notice |
| Customer data | Whatever the customer loads or connects | Operating the Platform on their instructions | We act as processor, not controller |
3. Where your data is held
The Platform is hosted on Railway, a managed cloud platform, in the United States, with data stored in a managed PostgreSQL database provisioned in that environment. Backups are encrypted.
Where personal data originating in the European Economic Area, the United Kingdom or Switzerland is transferred to the United States, that transfer is governed by the European Commission’s Standard Contractual Clauses, incorporated into our Data Processing Agreement and supplemented by the technical measures described below.
4. Who else touches the data
| Provider | Purpose | Location |
|---|---|---|
| Railway | Application hosting and managed PostgreSQL database | United States |
| Google LLC | OAuth authentication, Gmail API and Google Calendar API — used only to reach the customer’s own Google account, at their election and under their own agreement with Google | United States / global |
We do not sell personal data. We do not share one customer’s data with another, and we do not cross-reference or combine data belonging to different customers — in identified, pseudonymised or anonymised form.
This website itself loads no third-party scripts and no analytics. The only external request it makes is to Google Fonts, which serves the typefaces and, in doing so, receives the visitor’s IP address.
AI features
Parts of the Platform use AI models — drafting campaign sequences, generating commercial documents, summarising exchanges, suggesting next actions. Where such a feature processes customer data, the model provider acts as a sub-processor. That carries three conditions we treat as non-negotiable:
- the provider is named in the sub-processor list of the Data Processing Agreement, and customers receive advance notice before it is added or changed;
- it is contractually barred from using customer data to train or improve its models;
- it holds the data only for as long as the request requires.
5. How we protect it
- Authentication through Google OAuth 2.0. We never store your Google password. Tokens are stored encrypted and are never written to logs in plaintext.
- All data in transit is encrypted using TLS 1.2 or above. Data at rest, including the database and all backups, is encrypted at the storage layer.
- Access to production systems is restricted to named personnel on a least-privilege basis and protected by multi-factor authentication. Access rights are reviewed periodically and revoked on departure or role change.
- Customer data is logically segregated, so that no customer can reach another customer’s data.
- Administrative access to customer data is logged.
- The Platform and its database are operated separately from every other activity of BeautyScale and its group — commercial, distribution, media and investment. No process exists by which customer data passes into any of those activities, and we will not create one.
Our security framework is designed to support SOC 2 and ISO 27001 requirements. We do not currently hold either certification, and we do not claim to.
6. How long we keep it
- Customer data: for the term of the customer’s subscription. On termination the customer has a defined window to export, after which we delete it and instruct our sub-processors to do the same. Encrypted backups are deleted in the ordinary rotation and in any event within 90 days.
- Enquiries: three years from our last exchange, unless a contract follows.
- Buyer contacts: three years from our last meaningful exchange, then reviewed and deleted unless a live commercial relationship justifies keeping the record
- Objection records: kept indefinitely, so that a person who has objected stays excluded even if the database is later re-imported.
7. Your rights
You may request access to your personal data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interest. Where the processing is direct marketing, your objection is absolute — we stop, without weighing our interests against yours.
Write to privacy@beauty-scale.co. We reply within one month. You may also complain to your national supervisory authority.
If your data is in our buyer database, the Buyer Database Notice explains where it came from and how to be removed.
8. Changes
We update this page when our processing changes. The date at the top always reflects the current version. Where a change materially affects customers, we give the notice period set out in their Data Processing Agreement.