PRIVACY

Privacy Policy

Effective date: 28 May 2026

At SCALA MDO we take your privacy seriously. This policy explains what data we collect when you create an account and use the service, why we collect it, how we protect it, and how you can exercise your rights.

01Data Controller

SCALA MDO (hereafter "we", "the Service", or "the Platform") operates this service. We comply with applicable data protection laws including the Turkish KVKK and the EU GDPR. Contact: info@scala-mdo.com.

02Data We Collect

To provide our service we collect: • Account data: name, email, password hashed with PBKDF2-SHA256 (600,000 iterations, per-user salt). Plain passwords are never stored. • Etsy integration: OAuth access and refresh tokens, shop id, shop name. Tokens are encrypted at rest with AES-256-GCM. • Billing: Paddle customer id, subscription id, plan + status, current period end. Card details are NEVER seen or stored by SCALA MDO — they go straight to Paddle. • Two-factor authentication: TOTP secret, hashed recovery codes. • Content: images you upload to AI modules, listing drafts you generate, newsletter content you compose. • Activity logs: login timestamps, IP addresses, user-agent, critical actions (audit log). • Preferences: language, theme, sidebar favourites, sign-in preferences.

03How We Use the Data

We process the data we collect only for: • Connecting to your Etsy shop and performing listing read/write operations. • Running AI modules (SEO, pricing, image analysis, social media planning) and showing you recommendations. • Keeping your account secure (brute-force protection, anomaly detection, session management). • Subscription billing and plan management (through Paddle). • Improving the service and diagnosing technical issues (Sentry error tracking). • Meeting legal obligations (tax, KVKK, GDPR). We do NOT use your data for ads, profiling, or sale to third parties.

04Legal Basis

We rely on the following legal bases (GDPR Article 6, KVKK Article 5): • Performance of a contract: account, subscription, billing, Etsy integration, AI services. • Legitimate interest: security (rate-limit, brute-force, audit log), error monitoring, fraud prevention. • Consent: marketing communications are sent ONLY to people who have explicitly opted in; having made a purchase is not, by itself, consent. Every marketing email carries a one-click unsubscribe link, and consent can be withdrawn at any time. • Legal obligation: tax records, lawful investigative requests.

05Third-Party Sub-Processors

To deliver the service we use the following third parties: • Paddle (United Kingdom / US) — Merchant of Record handling payment processing, subscription management, VAT-compliant invoicing and the hosted customer portal. Card data is processed only by Paddle; SCALA MDO does not see it. • Google Gemini (Google LLC, US) — AI text and image analysis. Only the data you submit for that particular AI request is processed; not used for training (per Gemini API enterprise policy). IMPORTANT: when you use certain modules (review analysis, customer responses, loyalty, B2B, chatbot, etc.), the personal data of YOUR CUSTOMERS that you import from Etsy (names, emails, review and message text) is transmitted to Google Gemini solely to fulfil that request. If you do not want this data sent to the AI, do not use those modules. • Etsy, Inc. (US) — Shop data, listings, messages. Etsy's own privacy policy applies. • Sentry (US) — Production error tracking only. Sensitive data is masked. • Zoho Mail (Zoho Corporation, India/US) — System notifications and transactional email via SMTP. Zoho's own privacy policy applies. All sub-processors are bound by appropriate data processing agreements (DPAs). You are the "data controller" for your customers' personal data; SCALA MDO acts only as a "data processor" on your behalf and uses the sub-processors above. It is your responsibility to have the legal basis (e.g. informing your customers) required to process this data.

06Data Retention

• Active account data: retained while your account is active. • Audit log: last 5,000 entries per user, last 50,000 entries system-wide (older entries automatically purged). • After account deletion: all personal data is permanently deleted within 30 days. Records required by law (e.g. tax invoices under Turkish tax code) are retained for 5 years. • Backups: automatically deleted after 90 days. • Paddle invoices: Paddle's own retention policy applies (typically 7 years for tax compliance).

07Security Measures

We use technical measures aligned with OWASP 2023 standards: • Password hashing: PBKDF2-SHA256, 600,000 iterations, per-user salt • Etsy OAuth tokens: AES-256-GCM encrypted at rest • Session verification: HMAC-SHA256 with crypto.timingSafeEqual (timing-safe) • Two-factor authentication (TOTP): optional but recommended • Brute-force protection: temporary account lockout after 5 failed attempts • HTTPS/TLS enforced, HSTS preload active • Content-Security-Policy, sameSite=lax cookie, X-Frame-Options DENY • Independent security audit: 36 of 37 findings resolved (see /security) Full security architecture: /security.

08Cookies and Local Storage

SCALA MDO uses only strictly necessary cookies: • scala_session (httpOnly, sameSite=lax): session authentication. 30-day TTL. • scala_lang: language preference. Stored in your browser only. • etsy_state, etsy_cv: transient during Etsy OAuth flow (10 minutes), deleted on completion. • localStorage: sidebar favourites, onboarding progress and other preferences. Never sent to the server. We do NOT use third-party analytics or advertising cookies. As such no consent banner is shown — explicit consent is not required for strictly necessary cookies (GDPR Article 7).

09Your Rights under KVKK (Turkey)

As a Turkish citizen or resident, you have the following rights under KVKK (Law No. 6698), Article 11: • Be informed whether your personal data is being processed • Receive information about the purposes of processing • Know third parties to whom your data has been transferred (domestically or abroad) • Request correction of incomplete or inaccurate data • Request erasure or destruction within the framework of KVKK Article 7 • Request that corrections, erasures or destructions be communicated to third parties • Object to results produced by automated analysis • Claim compensation for damages arising from unlawful processing To exercise these rights: info@scala-mdo.com.

10Your Rights under GDPR (EU)

As an EU resident you also have the following rights under GDPR Articles 15-22: • Right of access (Article 15): receive a copy of your data (Account → Settings → GDPR Export). • Right to rectification (Article 16) • Right to erasure / "right to be forgotten" (Article 17) • Right to restriction of processing (Article 18) • Right to data portability (Article 20): download your data in structured (JSON) format. • Right to object (Article 21) • Rights relating to automated decision-making and profiling (Article 22) • Right to lodge a complaint with an EU member state data protection authority Requests: info@scala-mdo.com.

11Children's Privacy

SCALA MDO is not designed for individuals under 18 years of age. If we learn that a person under 18 has provided data we will delete it as soon as possible.

12Changes to This Policy

We may update this policy from time to time. For material changes we'll notify the email address on your account or publish a visible notice in the Service. The effective date is shown at the top of the page.

13Contact

For privacy questions or rights requests: Email: info@scala-mdo.com Security disclosure: info@scala-mdo.com Response time: within 30 calendar days (48 hours for urgent security matters).