Privacy Policy
Version: 2026-04-24
Effective: 2026-04-24
Controller: XSCALER LTD, trading as xScaler Labs.
Registered in England and Wales, company number 17048353.
Registered office: C/O Wis Accountancy, 4 Imperial Place, Maxwell Road,
Borehamwood, Hertfordshire, WD6 1JN, United Kingdom.
Contact: [email protected]
Supervisory authority: Information Commissioner's Office, United Kingdom
— https://ico.org.uk/
1. Who we are
XSCALER LTD, trading as xScaler Labs, operates the xScaler platform: a multi-tenant observability service for cloud workloads. We act as a controller of your account, billing, and audit data, and as a processor of the metrics and logs your tenants send us.
2. What data we process
| Category | Examples | Source | Lawful basis | Retention |
|---|---|---|---|---|
| Account data | email, display name, password hash, identity-provider sub | you, at signup | contract (Art. 6(1)(b)) | until account deletion + 30-day grace + max 7-day backup window |
| Organisation data | org name, plan, region, members | org owner / admin | contract | same as account data |
| Billing data | Stripe customer id, subscription status, invoice metadata | Stripe (sub-processor) | contract; legal obligation for invoice records | tax retention period of the controller's jurisdiction (typically 7 years) |
| Telemetry data | metrics, traces, logs your tenants send | your systems via remote-write | contract (you, the customer, are the data controller of the workload data; xScaler is the processor) | per-plan, configurable from your settings; 90 days by default, up to 1 year on Enterprise |
| Audit data | who did what in the portal | the platform | legitimate interest (Art. 6(1)(f)) — security, fraud, contract enforcement | 2 years from event |
| Support data | ticket subjects, bodies, attachments, email | you, when you write to support | contract; legitimate interest | per Zoho Desk DPA |
| Consent data | which document version, granted/withdrawn timestamps, hashed IP, user-agent | the platform | legal obligation (Art. 7(1) — proof of consent) | as long as the user account exists, plus statute-of-limitation buffer |
| Marketing-email opt-in | granular consent flag | you, at signup or in settings | consent (Art. 6(1)(a)) | until withdrawn |
We do not process special-category data (Art. 9). Do not place such data into telemetry payloads.
3. Where data lives
- Primary database (account, billing, audit, consent): AWS RDS PostgreSQL,
region
eu-west-1(Ireland). - Telemetry storage: AWS S3 + Mimir, region of the tenant
(
euw1,aps1, etc.). Cross-link: the regions reference enumerates every region. - Authentication: AWS Cognito, in the region configured for your tenant.
- Backups: RDS PITR with a 7-day window.
Data does not transfer outside the EEA except through:
- Stripe (US + EU; SCCs in their Cardholder Data Agreement).
- Cognito (per region).
- Zoho Desk (per their DPA).
- Amazon SES (per region).
The full sub-processor list is at xscalerlabs.com/sub-processors.
4. Your rights (Arts. 15–22)
You can exercise all of the following from your account at
https://portal.xscalerlabs.com/settings/account:
- Access (Art. 15): "Download my data" produces a machine-readable bundle of your account, organisation memberships, audit events, consent history, API keys, and invitations.
- Rectification (Art. 16): "Profile" lets you change your display name and email. Email changes go through a confirmation link sent to the new address.
- Erasure (Art. 17): "Delete my account" schedules deletion. A 30-day grace period protects against fraudulent or accidental requests; you can cancel at any point within the grace window. After 30 days the deletion becomes irreversible. Data is also removed from backups as the 7-day PITR window rolls forward; we do not selectively rewrite backups.
- Portability (Art. 20): the data export bundle is the deliverable. JSON, schema versioned.
- Restriction (Art. 18) and objection (Art. 21): contact [email protected].
- Automated decision-making (Art. 22): we do not make decisions producing legal effects against you using solely automated processing.
If you are an account holder of a customer organisation and you request erasure while you remain the sole owner of an organisation, the platform will refuse and direct you to either transfer ownership or delete the organisation first. This is a contract-basis carve-out under Art. 6(1)(b) — you cannot erase yourself out of an obligation to settle billing.
5. Cookies and similar technologies
We use a minimum set of strictly necessary cookies:
__session— your portal session (JWE).oidc_*— short-lived (10 min) cookies during the SSO callback flow.
We do not use analytics, advertising, or marketing cookies in the portal.
The marketing site at xscalerlabs.com is a separate property; consult the
notice on that site if/when applicable.
6. Marketing communications
We do not send marketing emails by default. If you opt in (during signup
or from your account settings), you can withdraw at any time:
Settings → Account & privacy → Consents → Withdraw.
Alert emails about your tenants are contract-basis (Art. 6(1)(b)) and are not marketing. They cannot be disabled through the marketing-consent flag; they are managed separately under "Notification preferences".
7. Sub-processors
See xscalerlabs.com/sub-processors. We give 30 days notice before adding a new sub-processor or replacing an existing one.
8. Security
TLS 1.2 or later for data in transit, AES-256 at rest for the primary database and for object storage. Role-based access control in the portal, MFA on every operator account, and just-in-time short-lived AWS sessions rather than long-lived production keys. Application workloads run in a private VPC with public ingress only at documented edge points, and tenants are isolated at both the metrics and the database layer. Administrative actions are written to an audit log retained for 2 years.
The full list of technical and organisational measures is Annex II of our data processing addendum, which we provide on request to [email protected].
9. Breach notification
If a personal data breach occurs and is likely to result in a risk to your rights, we notify the supervisory authority within 72 hours of becoming aware of it (Art. 33), and notify you without undue delay if the risk is high (Art. 34).
10. Changes to this policy
When we update this document, we publish the new file with the updated date and bump the version constants in the product code. The next time you sign in to the portal, you will be prompted to re-accept the current versions. Withdrawing acceptance directs you to delete your account, since acceptance of the privacy policy is a contract-basis prerequisite for using the service.
11. Contact
[email protected] — for any privacy question, request, or complaint. You can also lodge a complaint directly with the Information Commissioner's Office: https://ico.org.uk/make-a-complaint/.