Legal

    Privacy Policy

    Last updated: September 18, 2026

    This Privacy Policy describes how SCALORME, LDA (“Scalor”) collects, uses and protects the personal data of visitors and clients of the scalor.me website and associated services. We comply with the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and Portuguese Law no. 58/2019.

    1. Data Controller

    The controller of the personal data collected through this website is SCALORME, LDA, with registered office at Rua António Ramalho, n.º 6, R/C Esq., 2745-071 Queluz, Portugal, tax ID (NIPC) 519546741.

    For any question about data protection, or to exercise your rights, you can contact us at [email protected]. We have not appointed a data protection officer, as we are not subject to the obligation in Article 37 GDPR.

    2. Data We Collect

    Data you provide through the contact form: name, company, phone, email and, if you wish, a message. Name, company, phone and email are required for us to answer your request; the message is optional.

    AI maturity assessment data: name, email, company (optional), your answers to the 15 questions and the resulting score per dimension. Answers are scored by fixed rules, in your browser, to show you a maturity level and generic recommendations per dimension; we make no automated decisions with legal or similarly significant effects about you.

    Job application data: name, email, phone, LinkedIn profile, CV link and message.

    Technical data collected automatically: IP address, browser type and operating system, pages visited, date and time of access and traffic source.

    3. Purposes and Legal Basis

    Responding to contact requests and commercial proposals — execution of pre-contractual measures (Article 6(1)(b) GDPR).

    Handling job applications — pre-contractual steps at the candidate’s request (Art. 6(1)(b) GDPR).

    Sending marketing communications and newsletters — consent (Article 6(1)(a) GDPR), which you may withdraw at any time.

    Measuring website traffic and usage (Google Analytics) — consent (Art. 6(1)(a) GDPR), given in the cookie banner and withdrawable at any time under “Cookie preferences” in the footer.

    Compliance with legal, accounting, and tax obligations — Article 6(1)(c) GDPR.

    4. Data Sharing with Third Parties

    We do not sell or rent personal data. We use processors that handle data on our behalf and under our instructions: Supabase Inc. (the database where form submissions are stored, on servers in the European Union, in Frankfurt); Cloudflare, Inc. (website hosting and delivery, security and performance); Google Ireland Ltd. (Google Analytics and Google Tag Manager, only with your consent — see the Cookie Policy).

    All are bound by data processing agreements under Article 28 GDPR. Where transfers outside the European Economic Area occur (Cloudflare and Google, to the United States), they rely on the EU-US Data Privacy Framework adequacy decision and, additionally, on Standard Contractual Clauses approved by the European Commission.

    5. Retention Periods

    Lead data and commercial contacts: up to 3 years after the last contact.

    Active client data: during the contractual relationship and the applicable legal period (up to 10 years for tax purposes).

    Marketing data: until consent is withdrawn.

    Technical logs: up to 12 months.

    Job applications: up to 12 months after the application, unless hired.

    Assessment records with no email attached: up to 12 months.

    6. Your Rights

    You have the right to access, rectify, erase, restrict processing, object to processing, and data portability of your personal data.

    You also have the right to withdraw consent at any time and to lodge a complaint with the National Data Protection Commission (CNPD — www.cnpd.pt).

    To exercise any of these rights, please send an email to [email protected].

    7. Security

    We adopt appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or alteration: encryption in transit (TLS), access controls, audit logs, and periodic security reviews.

    8. Changes to this Policy

    We may update this policy as necessary. The current version is always the one published on this page, with the last update date indicated at the top.