Legal

Privacy Policy

Last updated: 8 August 2026 · Version 1.0

About this Policy

This Policy explains how Scalelist collects, uses and protects personal data. It addresses two audiences:

Leads, individuals whose professional contact details are held in Scalelist’s database. If you have received a communication and wish to know why Scalelist holds your details, please refer to Sections 3 and 6. You may exercise your rights at any time, including the right to object and the right to erasure, at scalelist.com/privacy-request. No account is required.

Users. B2B customers who subscribe to Scalelist’s platform and services. Where Scalelist processes data on your behalf, the terms of that processing are set out in our Data Processing Agreement.

This Policy is incorporated by reference into Scalelist’s Terms of Service and General Conditions of Sale, which Users accept upon subscribing to the platform.

1. IDENTITY AND CONTACT DETAILS OF THE DATA CONTROLLER

Scalelist is a service operated by TGID Export Pte. Ltd., a company incorporated in Singapore.

TGID Export Pte. Ltd.
21 Collyer Quay, #02-01, Singapore 049320
UEN: 201903371H

In this Policy, “Scalelist”, “we” and “us” refer to TGID Export Pte. Ltd.

For any questions or requests relating to the processing of your personal data, you may contact us at:
Email: privacy@scalelist.com

2. SCOPE AND APPLICABILITY OF THIS POLICY

Audiences covered by this Policy

This Policy addresses two distinct audiences, each with different rights and obligations:

Leads, individuals whose professional contact details are held in Scalelist’s database, whether collected from publicly available sources, sourced from third-party data providers, or derived by inference. Leads are data subjects within the meaning of the GDPR and are entitled to the rights described in Section 10 of this Policy.

Users. B2B Customers who subscribe to Scalelist’s platform and services.

Role of Scalelist

Scalelist acts as a Data Controller for:

  • The creation and management of User accounts;
  • The constitution and maintenance of its own professional contact database (the “Lead Database”), and the supply of data from that database to Users;
  • Website visitors and marketing contacts.

In these activities, Scalelist independently determines the purposes and means of processing and bears full responsibility for compliance with applicable data protection law.

Scalelist acts as a Data Processor within the meaning of Article 28 of the GDPR for the enrichment of contact data submitted by Users, which it carries out on behalf of and on the instructions of the User. The User acts as data controller in respect of such data and is solely responsible for ensuring that its use of the enriched data complies with applicable data protection law. The processing of User-submitted data in the context of the enrichment services is further described in the Data Processing Agreement.

3. DATA SOURCES

Scalelist collects and processes personal data from the following sources:

Directly collected data

When Users interact with Scalelist’s website and/or create a User account on Scalelist’s platform.

Publicly available professional sources

Scalelist may collect a Lead’s professional contact information from publicly accessible sources, including professional directories, company websites, and other open professional databases publicly available.

Third-party data providers

Scalelist sources a Lead’s contact data from third-party data providers. These providers are contractually required to ensure that their own data collection practices comply with applicable data protection law, including the GDPR where relevant.

Inference

Where Scalelist has established the email address format associated with a company domain, for example that a given domain uses the format first.last@, it may generate the likely address for an individual at that domain and verify its deliverability before returning it. Address formats of this kind relate to organisations and not to identified or identifiable individuals.

User-submitted data

When Users submit their own contact data to the platform for enrichment purposes, such data is transmitted to Scalelist solely for the performance of the enrichment services. Scalelist processes such data as a data processor acting on the User’s instructions.

Scalelist does not incorporate User-submitted contact records into the Lead Database, and does not make them available to any other User. From the performance of the enrichment services, Scalelist retains only the email address format associated with a company domain, as described above. The processing of User-submitted data is further described in the Data Processing Agreement.

4. PROCESSING ACTIVITIES

The following table sets out the personal data processing activities carried out by Scalelist as data controller.

ProcessingData subjectsCategories of Personal DataLegal BasisData SourceRetention Period
Constitution and maintenance of the Lead Database, and supply of data from that database to UsersLeadsFull name, job title, seniority and function, company name, company domain, industry and size, professional email address, professional phone number, professional profile URL, locationLegitimate interestPublicly available professional sources, third-party data providers, inference24 months since the last verification
User account creation and platform access managementUsersUser name, professional email address, company name, job title, billing information, login credentials (hashed), platform usage logsPerformance of contractDirectly collected from the User at sign-up and during use of the platformDuration of the contractual relationship + 24 months from termination
Billing and payment processingUsersBilling details, transaction recordsPerformance of contract; legal obligationDirectly collected from the UserAs required by applicable tax and accounting law
Platform analytics and service improvementUsersUsage data, behavioural analytics, feature interaction logsConsent, in respect of cookies and similar technologies; legitimate interest, in respect of server-side usage dataPlatform logs generated by User interactions12 months from collection, and then anonymised
Marketing and commercial prospectingProspective UsersProfessional contact detailsLegitimate interest; consent where required by applicable lawDirectly collected; publicly available professional sources24 months from last interaction
Customer supportUsersContents of enquiries and correspondencePerformance of contract; legitimate interestDirectly collected from the User24 months
Legal compliance, fraud prevention and enforcement of rightsUsers and LeadsUser and Lead data as necessary, on a case-by-case basisLegal obligationAll internal data sourcesAs required by applicable law

Payment card details are processed directly by Scalelist’s payment provider and are not stored by Scalelist.

Where Scalelist relies on legitimate interest as the legal basis for processing, it has carried out a balancing assessment for each relevant processing activity, weighing its own commercial interests against the interests, rights and fundamental freedoms of the individuals concerned.

In Singapore, Scalelist relies on the business contact information provisions of the Personal Data Protection Act 2012 in respect of professional contact information.

5. RETENTION

In addition to the retention periods set out in Section 4 above, the following periods apply:

DataRetention Period
Contact data submitted by Users, and enriched resultsDuration of the User’s account. Deleted on the User’s instruction, or within 60 days of termination of the account
Email address formats associated with company domainsRetained without limitation of time. Such formats relate to organisations and not to identified or identifiable individuals
Enrichment audit log, recording the date, source and outcome of each lookup24 months
Conversation history generated by the Leads Finder feature12 months from last activity
Suppression list entriesFor as long as necessary to give effect to the objection

Where an individual exercises the right to erasure, Scalelist retains the minimum record of the request necessary to demonstrate that it has acted upon it and to prevent the data being reintroduced, in accordance with Article 17(3)(b) of the GDPR.

6. INFORMATION PROVIDED TO LEADS

Where personal data is not obtained from the data subject, Article 14 of the GDPR requires the controller to provide the information set out in that Article.

Scalelist does not contact individuals whose data is held in the Lead Database, and the provision of individual notice to each such individual would involve disproportionate effort within the meaning of Article 14(5)(b) of the GDPR. Scalelist accordingly makes the required information publicly available through this Policy, and has implemented the following measures:

  • This Policy is published at a permanent and publicly indexed address;
  • A removal form is maintained at scalelist.com/opt-out, through which any individual may request erasure of their data and object to its processing, without holding an account. The other rights described in Section 10 may be exercised by writing to privacy@scalelist.com;
  • A suppression list is maintained, so that an individual who has objected is not reintroduced into the Lead Database by any subsequent collection;
  • Users are required, under the Data Processing Agreement, to identify Scalelist as a source when requested to do so by a recipient of their communications.

7. USE OF ARTIFICIAL INTELLIGENCE

Artificial intelligence models are used only in the Leads Finder feature of the platform. They are not used in the Email Finder, the Phone Finder, bulk enrichment, or the Scalelist API.

In the Leads Finder feature, a model converts a User’s description of a target audience, expressed in natural language, into structured search criteria. No contact records are transmitted to the model for this purpose; results are produced by Scalelist’s own systems and by its data providers.

Where a User submits a request concerning the contents of a list held in their account, such as a request to analyse or summarise the leads it contains, professional contact data from that list may be transmitted to the model provider to the extent necessary to respond to the request. Such data is processed on an inference-only basis: it is not retained by the model provider once the response has been generated, and is not used for any other purpose.

Scalelist does not use data submitted by Users, or data held in the Lead Database, to train, fine-tune or evaluate machine learning models, and does not permit its model providers to do so.

8. RECIPIENTS AND DISCLOSURES

Personal data processed by Scalelist may be disclosed to the following categories of recipients:

Users, B2B Customers subscribing to Scalelist’s platform. Upon receipt of data from the Lead Database, each User acts as an independent data controller and is solely responsible for ensuring that its use of such data complies with applicable data protection law. The obligations of Users in this capacity are set out in the Data Processing Agreement.

Scalelist internal teams. Access to personal data within Scalelist is restricted to authorised personnel on a need-to-know basis, including sales, operations, customer support and technical teams, all of whom are bound by appropriate confidentiality obligations.

Sub-processors. Scalelist engages third-party service providers to support its operations, in the following categories:

  • contact data providers, for the resolution of lookups that Scalelist cannot resolve from its own systems;
  • email verification providers, for the confirmation of deliverability;
  • cloud hosting and database infrastructure providers;
  • billing and payment processors;
  • artificial intelligence model providers, subject to Section 7;
  • customer relationship management, communication and support tools;
  • professional advisers, including legal, accounting and audit.

Sub-processors are bound by contractual obligations equivalent to those set out in this Policy. The list of Scalelist’s published sub-processors, and the categories of data providers engaged in the performance of the enrichment services, are set out at scalelist.com/sub-processors.

The identity of Scalelist’s data providers, and the order in which they are engaged, constitutes confidential information and a trade secret of Scalelist. The complete nominative list of such providers, including the location and applicable transfer mechanism of each, is available to Users upon written request to privacy@scalelist.com, within five business days, subject to the execution of a non-disclosure agreement.

Competent authorities. Scalelist may disclose personal data to law enforcement agencies, regulators, courts or other public authorities where required to do so by applicable law, or where necessary to establish, exercise or defend legal claims. Such disclosures are carried out on a case-by-case basis and limited to what is strictly necessary.

Acquirers or successors. In the event of a merger, acquisition, restructuring or sale of assets, personal data may be transferred to the relevant acquiring entity, subject to equivalent data protection commitments being put in place prior to any such transfer.

9. INTERNATIONAL DATA TRANSFERS

Scalelist is established in Singapore and processes data on infrastructure that may be located outside the European Economic Area.

Accordingly, transfers of personal data from and to the EEA are carried out on the basis of the Standard Contractual Clauses (SCCs) adopted by the European Commission on 4 June 2021 (Commission Implementing Decision 2021/914), as follows:

  • Module 1 (Controller to Controller): applicable to transfers of Lead data between Scalelist and its third-party data providers acting as independent data controllers, in both directions, and to the supply of Lead data to Users established in the EEA.
  • Module 2 (Controller to Processor): applicable to (i) transfers of personal data from EEA-based Users to Scalelist in the context of the enrichment services, and (ii) transfers of personal data from Scalelist to sub-processors located in third countries without an adequacy decision.

Where the recipient is established in the United Kingdom, the UK International Data Transfer Addendum applies in addition.

Where Scalelist’s sub-processors are located in countries other than Singapore that do not benefit from an adequacy decision, equivalent transfer mechanisms under Article 46 of the GDPR are put in place prior to any such transfer.

Data subjects and Users may request a copy of the applicable Standard Contractual Clauses by contacting Scalelist at privacy@scalelist.com.

10. RIGHTS OF DATA SUBJECTS

EU residents whose personal data is processed by Scalelist enjoy the following rights under the GDPR:

Right of access. You have the right to obtain confirmation as to whether personal data concerning you is being processed, and if so, to receive a copy of that data and information about how it is used.

Right to rectification. You have the right to request the correction of inaccurate personal data or the completion of incomplete data held about you.

Right to erasure. You have the right to request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected or where you have withdrawn consent.

Right to limit the processing. You have the right to request that processing of your personal data be limited in certain circumstances.

Right to data portability. Where processing is based on consent or on the performance of a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used and machine-readable format.

Right to object. You have the right to object at any time to the processing of your personal data where that processing is based on legitimate interest, including for direct marketing purposes. Where you exercise this right, Scalelist will remove your data from the Lead Database and record your details on its suppression list, so that your data is not reintroduced by any subsequent collection.

Right not to be subject to automated decision-making. You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects concerning you. Scalelist does not carry out automated decision-making.

Individuals in Singapore benefit from equivalent rights of access and correction under the Personal Data Protection Act 2012, and may withdraw consent where processing is based upon it.

How to exercise your rights

You may exercise any of the above rights at scalelist.com/privacy-request or by contacting Scalelist at privacy@scalelist.com. No account is required.

We will acknowledge receipt of your request as soon as possible and, if it is admissible, we will provide you with the requested information or implement the rights invoked within one month. This period may be extended by a further two months where the request is complex or where a large number of requests are received, in which case you will be informed of the extension and the reasons for it. No charge applies unless a request is manifestly unfounded or excessive.

Scalelist may request information necessary to verify your identity, solely in order to confirm that it is acting upon the data of the correct individual. Such information is deleted once the request has been closed.

Right to lodge a complaint

If you consider that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority in the EU Member State of your habitual residence, place of work or place of the alleged infringement. In Singapore, complaints may be addressed to the Personal Data Protection Commission. In the United Kingdom, complaints may be addressed to the Information Commissioner’s Office.

11. HOW DOES SCALELIST PROTECT YOUR DATA?

Scalelist implements appropriate technical and organisational measures to ensure the security, confidentiality and integrity of your data and to protect it against accidental or unlawful destruction, accidental loss, damage, modification, disclosure or unauthorised access, as well as against any other form of unlawful processing.

By way of example, and without this list being exhaustive, we maintain:

  • encryption of personal data in transit and at rest;
  • an authentication system protecting access to Scalelist platform accounts, and hashing of login credentials;
  • role-based access control, limiting access to those employees and processors of Scalelist who need to know it by reason of their duties, and who are subject to strict confidentiality obligations;
  • audit logging of access to personal data;
  • separation of development and production environments;
  • rate limiting and access controls on public interfaces;
  • data minimisation by design: contact data is masked by default and is disclosed only upon an explicit, individually authorised and logged action by a User;
  • measures ensuring the ongoing confidentiality, integrity, availability and resilience of our processing systems and services;
  • the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident.

A detailed schedule of these measures may be obtained by Users on request at privacy@scalelist.com and will be provided within five business days.

We regularly carry out security checks and may in this regard temporarily suspend our services in case of suspicion or detection of a security breach. If you have any concerns about the security of your data, you may contact us at privacy@scalelist.com.

In the event of a personal data breach likely to result in a risk to the rights and freedoms of individuals, Scalelist will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR.

Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, Scalelist will also notify the affected data subjects directly, in accordance with Article 34 of the GDPR. In the context of professional contact data processed for B2B prospecting purposes, such high risk will be assessed on a case-by-case basis, taking into account the nature and volume of the data affected and the likelihood of harm to the individuals concerned.

12. COOKIES AND TRACKING TECHNOLOGIES

Scalelist’s website and platform use cookies and similar tracking technologies. Full details of the categories of cookies used, their purposes, and how to manage your preferences are set out in our Cookie Policy.

You may withdraw your consent or modify your preferences at any time by clicking on Cookie Settings, available at the bottom of every page.

13. MINORS

Scalelist’s services are intended for professional use. Scalelist does not knowingly process personal data relating to persons under the age of 18. Should you consider that Scalelist holds such data, please contact privacy@scalelist.com and it will be deleted.

14. POLICY CHANGE AND UPDATE

We periodically review this Policy to ensure compliance and keep it up to date with the applicable data protection regulations.

Where a change materially affects the manner in which personal data is processed, Scalelist will inform account holders in advance by email and will update the version and date indicated at the top of this Policy.

Before browsing, we invite you to refer to the latest version of the Policy. You can find out if there have been any changes since your last visit by checking the date at the top of the page.

Scalelistprivacy@scalelist.com