Privacy Policy | Tscale
Legal · Privacy

Privacy Policy

This policy describes how Tscale collects, uses, discloses, and protects personal information across our website, products, and services. We comply with the EU General Data Protection Regulation (GDPR), the Nigeria Data Protection Regulation (NDPR), and other applicable privacy laws.

01Scope & controller

This Privacy Policy applies to tscale.ai and all Tscale products, services, websites, and applications operated by Tscale Limited (“Tscale”, “we”, “us”, “our”). It describes how we collect, process, store, and protect personal information when you:

  • Visit our website or download materials
  • Sign up for an account, trial, or demo
  • Use Tscale products and services as a customer or end user
  • Apply for a job or partnership with Tscale
  • Contact our support, sales, security, or compliance teams

The data controller for personal information collected through our services is Tscale Limited. Where we process customer data on behalf of a customer (e.g., training data, inference inputs, model artifacts), the customer is the data controller and we act as the data processor under their instructions and our Data Processing Agreement.

Questions about this policy?

Email privacy@tscale.ai or submit a request via our contact form. We respond within one business day.

02Data we collect

We collect personal information in three categories: data you provide, data collected automatically, and data from third parties.

Data you provide

  • Account data — name, email, password (hashed), organization, role, profile photo
  • Billing data — billing address, tax ID, payment method details (processed by our PCI-DSS compliant payment processor — we never store full card numbers)
  • Support data — communications, tickets, screenshots, logs you share with us
  • Customer content — data, prompts, models, and artifacts you upload or generate through our services

Data collected automatically

  • Usage data — pages viewed, features used, API calls made, timestamps, error logs
  • Device data — IP address, browser type, operating system, device identifiers
  • Performance data — load times, crash reports, diagnostic information

Data from third parties

  • Identity verification — for compliance with KYC/AML when required
  • Public sources — business contact information from publicly available sources for B2B sales
  • Partners — referral information when you engage Tscale through a partner

03How we use data

We use personal information for the following purposes:

  • Provide, operate, maintain, and improve our services
  • Process transactions and send billing notifications
  • Authenticate users and prevent fraud and abuse
  • Respond to support requests and communicate with you
  • Send product updates, security alerts, and administrative notices
  • Send marketing communications (where you have opted in or where permitted by law)
  • Comply with legal obligations and enforce our terms
  • Analyze usage to improve product experience and develop new features
No training on your data

Tscale does not train AI models on customer data. Your prompts, inference inputs, fine-tuning data, and model artifacts remain your property and are not used to improve any foundation model.

05Sharing & subprocessors

We do not sell personal information. We share data only with:

  • Subprocessors — vetted service providers that help us operate (hosting, payments, email, support). The current subprocessor list is available under NDA via our trust resources.
  • Customers — when you use our services through an organization, that organization may access data you submit.
  • Legal & safety — when required by law, court order, or to protect rights, property, or safety.
  • Business transfers — in connection with a merger, acquisition, or sale of assets.

All subprocessors are bound by data protection agreements equivalent to the GDPR standard.

06International transfers

Tscale operates from data centers in Lagos, Nigeria by default. When we transfer personal data outside the country of origin, we rely on:

  • Standard Contractual Clauses (SCCs) — for transfers from the EEA, UK, and Switzerland
  • NDPR cross-border transfer requirements — for transfers involving Nigerian data subjects
  • Adequacy decisions — where applicable
  • Customer-directed transfers — when you select a non-default region

You can request a copy of the safeguards we apply to your specific transfer scenario by emailing privacy@tscale.ai.

07Data retention

We retain personal information for as long as needed to provide our services and comply with legal obligations. Specific retention periods:

  • Account data — for the life of your account + 30 days after deletion
  • Billing records — 7 years (tax and accounting obligations)
  • Audit logs — 365 days, then aggregated and anonymized
  • Support tickets — 3 years after last contact
  • Customer content — per your instructions or per the DPA
  • Marketing data — until you opt out, then deleted within 30 days

08Security

We protect personal information using administrative, technical, and physical safeguards designed for the sensitivity of the data. Our security program is independently audited and includes:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Customer-managed keys (CMEK / BYOK) on enterprise plans
  • Access controls with mandatory MFA and least privilege
  • 24/7 SOC monitoring and incident response
  • SOC 2 Type II and ISO 27001 certifications
  • Annual penetration testing by independent third parties

For full security disclosures, see our Trust Center.

09Your rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure — request deletion of your personal data (“right to be forgotten”)
  • Restriction — limit how we process your data
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent
  • Lodge a complaint — with your local data protection authority

To exercise any of these rights, submit a request via our contact form or email privacy@tscale.ai. We respond within 30 days at no cost.

NDPR rights (Nigerian data subjects)

If you are in Nigeria, the NDPR grants you additional rights including the right to data portability, the right to object to automated decision-making, and the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).

10Cookies & tracking

We use cookies and similar technologies on our website. We categorize them as:

  • Strictly necessary — required for the site to function (authentication, security)
  • Performance — anonymized analytics to help us improve the site
  • Functional — preferences such as language and region
  • Marketing — only with your consent, for retargeting and conversion measurement

You can manage cookie preferences at any time via the cookie banner or your browser settings.

11Changes to this policy

We may update this policy from time to time. When we make material changes, we will notify you via email (for account holders) or by posting a prominent notice on our website at least 30 days before the changes take effect. The “Effective” date at the top of this policy indicates when it was last revised.

12Contact us

If you have questions about this policy, want to exercise your rights, or need to contact our Data Protection Officer, use the channels below.

  • Email: privacy@tscale.ai
  • Contact form: tscale.ai/contact
  • Postal: Tscale Limited, Lagos, Nigeria

For security-related disclosures, see our Trust Center or email security@tscale.ai.

Privacy questions or data requests?

Submit a privacy request, exercise your data rights, or ask our Data Protection Officer a question. We respond within 30 days, free of charge.