Your account and your CRM:
two distinct uses.
BCB CORP manages data relating to its website and its relationship with you. For data stored in a customer’s CRM, that customer determines the purposes of processing and BCB CORP acts as a processor.
Data controller
For the processing activities described as being carried out by Scale Operator as a controller, the data controller is BCB CORP, a French simplified joint-stock company (société par actions simplifiée) with share capital of €1,000, whose registered office is at 50 avenue des Champs-Élysées, 75008 Paris, France, registered with the Paris Trade and Companies Register under number 928 917 343.
For any questions or requests relating to personal data: [email protected].
Scope and respective roles
This policy applies to visitors to scale-operator.com, people who contact BCB CORP, its prospects, customers and authorised users of the Scale Operator platform.
BCB CORP’s own data processing. BCB CORP acts as a controller when managing its website, enquiries, marketing, accounts, subscriptions, billing, support, security and legal obligations.
Data entered into the CRM by a customer. Scale Operator customers determine why and how they use the data of their prospects, customers, employees or other contacts. They therefore act as controllers. BCB CORP acts as a processor, following their instructions to provide the Service. Individuals should primarily exercise their rights with the business that entered their data into the CRM.
Data we may collect
Depending on your relationship with Scale Operator and the features you use, the following categories of data may be processed:
- identity, contact details, company, job title and country;
- account identifiers, permissions, preferences and login history;
- contractual information, subscriptions, invoices, payment status and transaction identifiers;
- support requests, appointments, business communications and form responses;
- technical data such as IP address, browser, device, logs, pages viewed and security events;
- CRM data imported or collected by customers: contacts, opportunities, notes, forms, calendars, emails, text messages, social messages, call metadata and, where lawfully enabled, recordings or transcripts;
- identifiers and data from authorised integrations with Meta, WhatsApp, Instagram or other connected services.
Data comes directly from you, from the organisation that gives you access to the Service, from customers using their CRM, from integrations you authorise and from technical providers necessary to operate the Service.
Purposes and legal bases
BCB CORP processes the data necessary to:
- respond to enquiries and take pre-contractual steps: at your request before entering into a contract;
- create accounts, provide the platform and support, and manage subscriptions: performance of a contract where you are a party to it; for users and contacts at a customer organisation, the legitimate interest in providing and administering the service requested by that organisation;
- issue invoices, maintain accounting records and meet regulatory requirements: compliance with a legal obligation;
- secure accounts, prevent fraud, maintain the Service and defend legal rights: the legitimate interests of BCB CORP and its users;
- send business customers marketing information about similar services: legitimate interest, with the right to object at any time;
- send marketing communications where consent is required: your consent;
- run automations and communications configured in a customer’s CRM: the customer determines the applicable legal basis; BCB CORP acts as a processor on the customer’s documented instructions.
Where providing data is mandatory to create an account, process a payment or provide the Service, failure to provide it may prevent a subscription or your request from being fulfilled.
Website, forms and marketing
When you visit the website, book an appointment, complete a form or contact Scale Operator, BCB CORP uses the information you provide to respond, assess your enquiry, arrange communications and manage commercial follow-up.
You can object to direct marketing at any time using the unsubscribe link in emails or by writing to [email protected]. Minimal information may be retained on a suppression list to ensure that your choice continues to be respected.
Accounts, access and use of the Service
Account data is used to create and administer customer workspaces, authenticate users, assign permissions, provide requested features, assist with migration and handle support requests.
Technical and security logs may be used to detect unusual access, prevent abuse, resolve incidents and maintain the integrity of the platform.
Payments and billing
Payments are processed by Stripe. BCB CORP receives the information necessary to monitor a transaction, such as the payer’s identity, billing details, amount, currency, payment status, payment method type and transaction identifier.
BCB CORP does not directly receive or store full payment card details. Stripe processes this information under its own terms and privacy policy.
Data processed in customer CRMs
The platform relies in particular on GoHighLevel / LeadConnector infrastructure. Depending on the customer’s choices, it may process contact details, communications, appointments, opportunities, forms, emails, text messages, calls, WhatsApp or Instagram messages, recordings and automations.
The customer is responsible for the lawfulness of collecting, importing, segmenting, marketing to, recording calls involving and otherwise using this data. The customer must inform the individuals concerned, select an appropriate legal basis, comply with direct marketing rules and define a proportionate retention period.
BCB CORP does not use a customer’s CRM data for its own marketing. It may access that data only where necessary to configure, migrate, maintain or secure the service, assist the customer, or comply with the law. Processing on behalf of the customer must be governed by a data processing agreement that complies with Article 28 of the GDPR. This privacy notice does not replace that agreement. Contact us to obtain the applicable contractual documents.
Communications and AI features
Communication features may rely on GoHighLevel / LeadConnector and connected operators and platforms, including Meta, WhatsApp and Instagram. Messages and their metadata may pass through these services for delivery and association with the relevant contact record.
Where calls are recorded or transcribed, the customer enabling the feature must check the applicable law, inform participants in advance and obtain their consent where required.
If artificial intelligence features are enabled, the submitted content, messages or transcripts needed for the feature may be processed to generate requested responses, summaries or actions. The customer must inform individuals about the actual uses and put appropriate safeguards in place for any automated decisions. Providers, retention periods and conditions governing data reuse depend on the features enabled and the applicable agreements.
Cookies and similar technologies
Cookies or similar technologies may be used to perform functions necessary for the requested service, such as authentication, session management or remembering a choice. Whether an exemption from consent applies depends on their purpose and actual configuration.
Technologies that require consent must remain disabled until you accept them. Where a choice is offered, refusing must be as easy as accepting, and you must be able to withdraw your consent at any time.
Recipients and service providers
Data is accessible, within the scope of their duties, to authorised BCB CORP personnel and to providers necessary to deliver the Service. The main categories or entities currently used are:
- GoHighLevel / LeadConnector: CRM infrastructure, automations, communications and hosting of platform functionality;
- Stripe: payments, billing and fraud prevention;
- Meta, WhatsApp and Instagram: messaging integrations enabled by customers in their CRM environment;
- advisers, accountants, authorities, courts or legally authorised bodies where disclosure is necessary or mandatory.
These providers receive only the information necessary to perform their tasks. Some may also act as independent controllers for their own obligations or services; their privacy policies then apply in addition to this policy.
International transfers
Some providers or companies within their groups are established outside the European Economic Area or use infrastructure located there, including in the United States. Data may therefore be transferred to, or accessed from, those countries.
Where the GDPR applies, these transfers are governed by a recognised mechanism: an adequacy decision, certification under the EU–US Data Privacy Framework where applicable, or European Commission standard contractual clauses and, where necessary, supplementary measures.
You may request information about the countries involved and applicable safeguards, as well as a copy of those safeguards, by contacting [email protected]. Any redactions needed to protect trade secrets or third-party data must not prevent you from understanding the safeguards provided.
Data retention
Data is retained for a period proportionate to its purpose, then deleted, anonymised or archived with restricted access where a legal obligation or the defence of legal rights justifies doing so:
- account and service data: for the duration of the contractual relationship, then for the periods necessary to handle account closure, backups, complaints and legal obligations;
- accounting documents and invoices: ten years from the end of the relevant financial year;
- data of prospects with no contractual relationship: up to three years from collection or the last contact initiated by the prospect, unless the prospect objects earlier;
- requests to exercise rights: for the time needed to handle them, then archived to demonstrate compliance with obligations;
- technical and security logs: for a limited period appropriate to prevention, incident detection and evidential needs;
- CRM data: according to the instructions and retention periods defined by the customer acting as controller, subject to applicable backup constraints and legal obligations.
Security and confidentiality
BCB CORP implements technical and organisational measures proportionate to the risks to protect data against loss, alteration, disclosure, unauthorised access or use. These include permission management, authentication, logging, secure communications, backups and the use of providers offering appropriate safeguards.
No system is entirely risk-free. Anyone who suspects an incident can report it immediately to [email protected].
Your rights
Subject to the conditions set out in applicable law, you may request access to your data, its rectification or erasure, restriction of processing or data portability, or object to processing based on legitimate interests. You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Where French law applies, you also have the right to give instructions about what should happen to your data after your death. For its own processing activities, BCB CORP does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you.
To exercise your rights, write to [email protected] specifying your request and providing the information needed to identify the data concerned. Proof of identity will only be requested if there is reasonable doubt about your identity. A response will be provided within one month of receipt of the request. This period may be extended by a further two months due to the complexity or number of requests; you will then be informed within the first month, together with the reasons for the extension.
If your request concerns data entered by a customer into its CRM, contact that customer first. BCB CORP will assist the customer where necessary.
You may lodge a complaint with the CNIL or the competent supervisory authority, in particular in the place of your habitual residence, place of work or place of the alleged infringement.
Minors, contact and updates
Scale Operator is intended for businesses and individuals with legal capacity to enter into contracts. BCB CORP does not intentionally collect data directly from minors. If you believe a minor has provided us with information inappropriately, please contact us so that we can investigate.
This policy may change to reflect changes to the Service, providers or applicable regulations. The version published on this page is the applicable version. In the event of a material change, BCB CORP uses reasonable means to notify the individuals concerned where required.
[email protected]