Data processing agreement
Last updated: 2026-08-20
Parties
Processor: Davide Grasböck
Address: Hirschstettner Straße 63, 1220 Vienna, Austria
Email: support@scalebrowser.net
This agreement is between you as the controller and us as the processor, under Art. 28 GDPR. It takes effect when you subscribe and applies for as long as your subscription runs. Where it and our terms of service disagree on the handling of personal data, this agreement wins.
You do not have to sign anything for it to apply. If your organisation needs a signed copy on its own paper, write to support@scalebrowser.net and we will sign yours.
What we actually process for you
Almost nothing, and that is a property of how the product is built rather than a promise. Scalebrowser runs on your own machine. The browser profiles, the cookies and passwords inside them, the pages an agent visits and the screenshots it takes are written to your disk and never sent to us. We operate no hosted browsers, so there is no copy of any of it on our side to lose.
One feature is the exception, and it is the whole subject of this agreement: profile sync. If you turn it on, your installation encrypts each profile on your device and uploads only the result. We store that ciphertext so your other machines can fetch it.
Subject, nature, purpose and duration
Subject and nature: storing and returning encrypted profile data. Purpose: making your own profiles available on your other installations. Duration: as long as your subscription runs, plus the deletion window below.
Categories of data: whatever you chose to put into a profile, which we can neither read nor categorise. Categories of data subjects: the people whose data you decided to keep in a profile. Because we only ever hold ciphertext, both categories are yours to determine and yours to know.
We cannot read it, and that is structural
The encryption key is generated on your device and derived from your passphrase. It is never transmitted, never held in your browser and never stored by us. What reaches our servers is the ciphertext and a sequence number that tells your machines which version is newest.
The practical consequence cuts both ways and you should know the second half before you rely on the first. We cannot hand your data to anyone, including an authority that asks, because we cannot decrypt it. For the same reason we cannot recover it for you if you lose both your passphrase and your recovery key.
Instructions
We process the data only on your documented instructions, including on transfers to a third country, unless the law obliges us otherwise. Your instructions are the settings you choose in the product and anything you send us in writing. We will tell you if we believe an instruction breaches data protection law.
In practice there is little to instruct: we cannot read the data, so the operations available to us are storing it, returning it to your machines and deleting it.
Confidentiality
Everyone we allow near the systems is bound to confidentiality and is briefed on their duties under the GDPR. Today that is one person, named in the imprint. If that changes, this sentence changes with it.
Security of processing (Art. 32)
The measures we take, stated concretely enough that you can check them:
- Profile data is encrypted on your device with XChaCha20-Poly1305 before it is uploaded, under a key we never hold
- Every connection to our servers runs over TLS; plain HTTP is redirected, not served
- Passwords in your account are stored as a hash, never in a form that can be turned back into the password
- Your account can require a second factor or a passkey, and sensitive actions ask you to confirm your identity again
- Backups are encrypted and kept at a different provider than the servers, so one lost account cannot take both
- Error reports carry no identifier at all: no account id, no email, no IP address, removed before sending and again on arrival
- Administrative access to the servers is by key, not by password, and is limited to the people named above
Sub-processors
You give general authorisation for the sub-processors below. Each is bound by a data processing agreement with terms no weaker than these.
- Contabo GmbH, Munich, Germany: the servers, the application database and the error collector we run ourselves. Located in the EU.
- Cloudflare, Inc., United States: DNS, TLS, inbound email, and the object storage that holds the encrypted sync data and the encrypted backups.
- Amazon Web Services, Inc., United States: outbound transactional email only, sent from the eu-central-1 region.
- Stripe, Inc., United States: payments, invoicing and subscription state.
We will tell you before we add or replace one, with at least 30 days notice by email. If you object on reasonable data-protection grounds within that time and we cannot resolve it, you may cancel your subscription with effect from the day the change takes effect, and we refund the unused part of the period you already paid for.
Transfers outside the EU
Three of the four are US companies. Where data reaches a third country, the transfer runs on the EU standard contractual clauses of Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), together with the additional measures below. The sync data reaching Cloudflare is encrypted before it leaves your device, so what crosses the border is ciphertext we cannot read ourselves.
The additional measure that matters most here is not organisational: for the sync data the encryption happens before the transfer and the key stays with you, so an authority in the receiving country can compel the ciphertext and nothing else. For the remaining services no browsing content, no profile and no password ever reaches them.
Helping you with your own duties
If a data subject asks you for access, correction, deletion or portability, we help you answer within your deadline. For the sync data the honest help is narrow: we can confirm what exists and delete it, but we cannot search inside it or produce a readable copy, because it is encrypted against us.
We also help you with your obligations under Art. 32 to 36, in particular by telling you without undue delay, and at the latest within 48 hours, if we become aware of a breach affecting your data. That message will say what happened, what is affected and what we did about it, rather than only that something happened.
Deletion and return
When your subscription ends, you may export your data from the product for 30 days. After that we delete it from the live systems. Encrypted backups are kept for 35 days, so a copy can survive in them for that long after the deletion before the rotation passes over it. We keep nothing beyond that, except where the law requires it, which for us means invoices and only invoices.
Deleting your account triggers the same path, with the same 30-day window during which the account can still be restored.
Proof and audits
You may satisfy yourself that we comply. Ask us in writing and we answer with the information you need, including which sub-processors hold what. If that is not enough for your own obligations, you or an auditor you appoint may inspect, at your cost, with reasonable notice, during business hours and no more than once a year unless something specific gives you reason.
Liability and governing law
Liability follows the section on liability in our terms of service, and Art. 82 GDPR applies regardless of it. Austrian law governs this agreement, without prejudice to the GDPR itself.