Scalyn Privacy Policy
How Postly Technologies, Inc. handles personal data when you use Scalyn.
1. Scope, Company, and Our Role
This Privacy Policy explains how Postly Technologies, Inc. collects, uses, discloses, and protects personal data when you visit https://scalyn.app, create or use a Scalyn account, connect third-party services, contact us, or otherwise use the Service.
We generally act as controller or business for account, website, billing, support, security, and product-usage data. For Customer Content and personal data you direct us to process about your audience, contacts, customers, or end users, your organization is generally the controller or business and we act as processor or service provider. Your organization’s privacy notice governs its processing; contact that organization first to exercise rights concerning data it controls.
2. Personal Data We Collect
- Account and identity: name, email, profile image, authentication provider identifiers, password hash, verification status, roles, organization, workspace, preferences, and account recovery information.
- Commercial and billing: plan, trial, add-ons, usage, invoices, transaction status, tax and billing details. Payment card data is generally processed directly by our payment providers.
- Device, usage, and security: IP address, browser, device, operating system, language, time zone, referring URLs, pages and features used, clicks, timestamps, logs, diagnostics, cookies, fraud signals, and approximate location derived from IP.
- Customer Content: posts, drafts, prompts, generated output, media, links, templates, notes, schedules, files, recipient or audience information, instructions, and other data you submit.
- Communications: support requests, surveys, feedback, preferences, marketing interactions, call or meeting details, and correspondence.
- Connected-service data: LinkedIn account or organization identifiers, profile or page details, authorization tokens, permitted publishing resources, posts, media, scheduling status, and analytics returned under the permissions you grant.
3. Sources of Personal Data
We collect data directly from you, your organization and administrators, your browser or device, connected services you authorize, payment and authentication providers, service providers, integrations, referrals, and publicly available sources where permitted. We may derive insights such as feature adoption, risk indicators, campaign performance, or aggregated usage statistics from those sources.
4. LinkedIn and OAuth Data
When you connect LinkedIn, Scalyn receives authorization tokens and the account, organization, publishing, media, and analytics data allowed by the scopes you approve. Scalyn uses that data to display eligible destinations, publish at your direction, synchronize status, and provide requested analytics.
We access only permissions you authorize and use connected-service data to authenticate the connection, display authorized resources, perform actions you request, synchronize status, provide analytics, troubleshoot, secure the integration, and comply with law. We do not sell connected-account content or use it for targeted advertising. Disconnecting stops new access but does not immediately remove data already needed for records, security, backups, or legal compliance.
Where we receive information from Google APIs, our use and transfer of that information adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not used for advertising, sold to data brokers, or used to train generalized AI or machine-learning models.
5. How We Use Personal Data
- Provide, configure, authenticate, synchronize, personalize, and support the Service and connected integrations.
- Process instructions, publish or schedule authorized content, generate requested output, operate collaboration tools, and provide analytics.
- Administer trials, subscriptions, add-ons, usage limits, invoices, payments, taxes, and account communications.
- Detect, investigate, and prevent fraud, spam, abuse, security incidents, unlawful conduct, and violations of our Terms.
- Monitor reliability, debug errors, improve usability and performance, develop features, and create aggregated or de-identified insights.
- Respond to support and rights requests, send service notices, and—where permitted—send product news or marketing you can opt out of.
- Comply with law, enforce agreements, establish or defend legal claims, protect rights and safety, and complete corporate transactions.
6. Legal Bases for Processing
Where GDPR, UK GDPR, or similar law applies, we rely on one or more of the following:
- Contract: processing needed to provide the Service, fulfill requests, and administer the account.
- Legitimate interests: securing and improving the Service, preventing abuse, supporting users, operating our business, and communicating about relevant services, balanced against your rights.
- Consent: optional cookies, certain marketing, connected-service permissions, or other processing where consent is requested. You may withdraw consent prospectively.
- Legal obligations and vital interests: tax, accounting, sanctions, law-enforcement response, safety, and other mandatory processing.
7. Customer-Controlled Audience and End-User Data
Customers may submit or connect personal data about other people. We process that data under the customer’s instructions to provide the Service. Customers must have a lawful basis, deliver required privacy notices, respect consent and opt-out signals, limit collection, and respond to their data subjects. We do not independently determine the customer’s campaign audience or message content.
Customers control their LinkedIn content, audiences, and engagement practices and must provide any notices required for tracking, lead data, employee advocacy, or campaign measurement.
9. AI Features and Model Providers
When you use AI features, we process prompts, selected Customer Content, settings, and outputs to provide the requested feature, enforce safety controls, troubleshoot, and measure performance. Authorized AI providers may process this data as our service providers under contractual restrictions. Do not submit unnecessary sensitive personal data. Unless we clearly disclose otherwise and obtain any required permission, we do not use Customer Content or connected-service user data to train general-purpose models for unrelated customers.
11. Data Retention and Deletion
We retain personal data only as long as reasonably necessary for the purposes described, including while an account is active and afterward for account recovery, customer-directed retention, backups, security, fraud prevention, billing, tax and audit records, dispute resolution, enforcement, and legal obligations. Retention depends on data type, sensitivity, contractual requirements, connected-service rules, and applicable limitation periods.
When retention is no longer justified, we delete, aggregate, or de-identify data. Deletion from encrypted backups and distributed systems may occur on a delayed cycle. Disconnect integrations and export needed content before closing an account.
12. Security
We use administrative, technical, and organizational safeguards designed to protect personal data, such as access controls, encryption in transit, credential protections, logging, monitoring, backups, and incident response appropriate to risk. No method is completely secure. You are responsible for strong credentials, appropriate roles, endpoint security, safe API-key handling, and promptly reporting suspected compromise to [email protected].
13. International Data Transfers
We and our service providers may process data in the United States and other countries that may have different data-protection laws. Where required, we use recognized safeguards such as adequacy decisions, standard contractual clauses, the UK addendum, or another lawful transfer mechanism, together with supplementary measures where appropriate.
14. Your Privacy Rights
Depending on your location and our role, you may have rights to:
- Know or access personal data and receive information about categories, sources, purposes, and recipients.
- Correct inaccurate data, delete data, or restrict processing.
- Receive portable data and object to processing based on legitimate interests or direct marketing.
- Withdraw consent without affecting prior lawful processing.
- Opt out of qualifying sale, sharing, targeted advertising, or profiling, where applicable.
- Appeal a denied request and complain to a competent privacy regulator.
Submit requests to [email protected]. We may verify identity and authority and may deny or limit requests where law permits. Authorized agents may submit requests with legally sufficient authorization. We will not discriminate against you for exercising rights.
15. Regional Disclosures
EEA, UK, and Switzerland: You may contact your local supervisory authority and may object to direct marketing at any time. Where we process data for a customer, that customer is normally responsible for your request.
United States: The categories collected are described in Section 2; sources in Section 3; purposes in Section 5; and recipients in Section 8. We may collect identifiers, commercial information, internet activity, approximate geolocation, professional information, customer content, and inferences. We do not knowingly sell or share personal data of people under 18. We use sensitive information, such as account credentials, only for permitted operational purposes and do not use it to infer characteristics.
16. Service Messages and Marketing Preferences
We send transactional messages necessary for security, authentication, billing, requested workflows, policy updates, and support. You cannot opt out of essential service messages while maintaining an account. You may opt out of marketing using the unsubscribe or “Manage preferences” link in product emails or by contacting us. We may retain a suppression record so we can honor the choice.
17. Children’s Privacy
The Service is not directed to children under 18, and we do not knowingly collect their personal data for our own purposes. If you believe a child provided personal data, contact us. Customers must not use the Service to process children’s data unless they have all legally required authority, notices, consents, and safeguards.
18. Automated Processing
We may use automated systems for security, spam and abuse detection, feature recommendations, scheduling suggestions, and AI output. We do not use account data to make solely automated decisions that produce legal or similarly significant effects about you. Customers are responsible for any decisions they make using Service output.
19. Third-Party Sites and Services
The Service may link to or integrate with third parties. Their privacy practices apply once you interact directly with them. Review their notices and permission screens. We are not responsible for third-party privacy, security, content, or availability.
20. Changes and Contact
We may update this Policy to reflect product, legal, or operational changes. We will post the updated date and provide additional notice or request consent where required. Material changes apply prospectively from their effective date.
Privacy questions and requests may be sent to [email protected]. Identify Scalyn, your account or organization, your country or state, and the request. Website: https://scalyn.app.