1Roles
This Addendum forms part of the Terms of Service between Scail Capital LLC (“SCAIL”) and the Operator. It applies whenever SCAIL processes personal information about the Operator’s clients.
The Operator is the business / controller. SCAIL is the service provider / processor, acting only on the Operator’s documented instructions — which include the instructions given by using the platform’s features.
2What SCAIL will not do
SCAIL will not:
- Sell or share consumer personal information, as those terms are defined by the CCPA/CPRA.
- Retain, use or disclose it for any purpose other than performing the services — including, for the avoidance of doubt, for our own commercial purposes or advertising.
- Retain, use or disclose it outside the direct business relationship between SCAIL and the Operator.
- Combine it with personal information received from another source, except as permitted to perform the services.
- Permit any subprocessor to use it to train that vendor’s own general-purpose models.
SCAIL certifies that it understands these restrictions and will comply with them.
3Categories of data, and whose
Data subjects: the Operator’s clients and prospective clients; the Operator’s own team members and referral partners.
Categories: identifiers (name, postal and previous addresses, email, telephone, date of birth, last four digits of a Social Security number); financial information (credit reports and scores, tradelines, balances, payment history, collections, public records); commercial information (services purchased, payments); documents uploaded to prove identity or address; correspondence with bureaus, furnishers and the client; and platform usage records.
Some of this is sensitive personal information. It is processed solely to deliver the service the Operator’s client engaged them for, and never to infer characteristics.
4Subprocessors
SCAIL uses the vendors below. Each is bound to obligations no less protective than these, and each receives only what its function requires.
| Subprocessor | Function | Data it receives |
|---|---|---|
| Vercel | Application hosting, edge network, logs | All request data in transit; server logs |
| Supabase | Database, authentication, file storage | All workspace data at rest, including credit reports and documents |
| Anthropic | AI report parsing, analysis, letter drafting, in-app assistant | Credit report contents and account details submitted for processing |
| Stripe | Subscription and payment processing | Operator billing details; consumer payment details where an operator bills clients through the platform |
| Lob | Certified mail printing, dispatch and tracking | Letter contents, consumer name and mailing address |
| Resend | Transactional email delivery | Recipient email address and message contents |
| Sendblue | SMS / iMessage delivery | Recipient phone number and message contents |
| Twilio | SMS delivery and telephony | Recipient phone number and message contents |
| PDFShift | PDF rendering of letters and analyses | Document contents at render time |
| Calendly | Consultation scheduling, where an operator enables it | Name, email and booking details of people who book |
| ConsumerDirect / SmartCredit | Credit report retrieval, where an operator enables it | Consumer identifiers required to pull a report |
| ElevenLabs | Voice synthesis, where an operator enables it | Text submitted for narration |
| Calendar and Gmail integration, where an operator connects it | Calendar and mail data the operator authorises |
The vendors marked “where an operator enables it” receive nothing unless that feature is switched on in the workspace.
Changes. We will give at least 30 days’ notice before adding a subprocessor that processes consumer data, by email to the account address and by updating this page. An Operator who reasonably objects on data-protection grounds may terminate the affected service and receive a pro-rated refund of prepaid fees.
5Security
Encryption in transit and at rest. Row-level tenant isolation enforced in the database, so one workspace cannot read another’s records. Stored third-party credentials encrypted under a separate key. Role-based access, least privilege, and audit logging of privileged actions. Access to production limited to personnel who need it.
6Breach notification
SCAIL will notify the Operator without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting that Operator’s data, with the nature of the breach, the categories and approximate number of records affected, likely consequences, and the measures taken. SCAIL will assist the Operator in meeting its own notification obligations. Consumer notification is the Operator’s to make, because the Operator holds the consumer relationship.
7Assistance with consumer rights
Consumers direct their access, correction and deletion requests to the Operator. SCAIL provides the tools to view, export, correct and delete records within a workspace, and will assist the Operator where a request cannot be fulfilled through the product. If a consumer contacts SCAIL directly, SCAIL will refer them to the Operator and notify the Operator promptly.
8Return and deletion
The Operator may export its data at any time while the workspace is active. On termination, data is retained for 30 days for export or reactivation, then deleted from production systems; encrypted backups age out within 90 days. SCAIL will confirm deletion in writing on request, except where retention is required by law.
9Audit
On reasonable written request, and no more than once a year, SCAIL will provide the information necessary to demonstrate compliance with this Addendum, including a summary of its security controls and any third-party attestations it holds.
10Not a consumer reporting agency
SCAIL is not a consumer reporting agency and does not furnish information to consumer reporting agencies. It transmits disputes and correspondence prepared and sent by the Operator. Obligations under the Fair Credit Reporting Act arising from those disputes rest with the Operator.