Effective Date: 1st September 2025
This Privacy Policy explains how Miss Candy Campbell, trading as “ScaleDPS (Digital Profit Strategies)” ("ScaleDPS", "we", "us", "our") collects, uses, shares and protects personal data when you visit our website, contact us, or use our services.
1) Who we are (Data Controller)
- Controller: Miss Candy Campbell (sole trader), trading as ScaleDPS (Digital Profit Strategies).
- Location: Remote consultancy based in Hertfordshire, United Kingdom.
- Postal correspondence: Available on request. We also accept service of statutory data-protection notices by email at [email protected].
- Data protection contact: [email protected]
- ICO registration number: ZC001936.
- We are subject to the UK GDPR and the Data Protection Act 2018.
We have not appointed a statutory Data Protection Officer.
Future-proofing: If ScaleDPS ceases to have a UK establishment but continues offering services to UK individuals, we will appoint a UK GDPR Representative and update this policy with their contact details.
2) What data we collect
We collect the following categories of personal data:
- Identity & contact data: name, email address, phone number, job title, organisation, country.
- Business context data: project requirements, scopes of work, messages and meeting notes.
- Technical data: IP address, device/browser type, pages visited, time on site, referring URLs (via privacy‑respecting analytics and cookies – see Cookies).
- Marketing preferences: newsletter opt‑ins/opt‑outs and engagement.
- Billing & contract data (if you become a customer): invoicing details, payment confirmations, contract metadata. Payments are processed by third‑party processors (we don’t store full card details).
- AI/LLM interaction data (where relevant): prompts, instructions, inputs you provide; generated outputs; evaluation datasets you authorise; system logs/metadata (timestamps, model IDs) necessary to deliver AI‑assisted services.
We do not intentionally collect special‑category data (e.g., health, biometrics) or children’s data. Please do not send such data to us; if received inadvertently, we will delete it and ask you not to resend.
3) How we use your data (purposes & legal bases)
Respond to Enquiries & Provide Proposals
- Examples: Contact form replies, discovery calls, proposals, statements of work
- Legal Basis:
*Legitimate interests (to respond and run our business)
*Pre-contract steps / contract
Deliver Services
- Examples: Configuration, implementation, support, project communications, AI-assisted delivery
- Legal Basis: Contract
Improve Site & Services
- Examples: Analytics, troubleshooting, security monitoring, service improvement using aggregate/anonymised data
- Legal Basis: Legitimate interests (to keep services secure and effective)
AI Operations
- Examples: Prompts/inputs/outputs you authorise to use AI features; logging metadata to operate models
- Legal Basis:
*Contract
*Legitimate interests (to operate secure, effective services)
Marketing (B2B)
- Examples: Occasional updates about services, event invitations
- Legal Basis: Legitimate interests (B2B direct marketing); opt-out available at any time
Compliance & Record-Keeping
- Examples: Tax records, invoices, AML/KYC where required
- Legal Basis: Legal obligation
Consent-Based Activities
- Examples: Non-essential cookies, certain email marketing
- Legal Basis: Consent (where required)
4) Cookies & analytics
We use essential cookies for site functionality and may use non‑essential cookies/analytics to understand performance. Where required, we’ll ask for your consent via a banner. You can change your preferences at any time. See our Cookie Notice for details of specific cookies and durations. [link/placeholder]
5) Who we share data with (recipients)
We share personal data only with trusted providers who act under contract as our processors (or, occasionally, independent controllers):
- Hosting & infrastructure: Google Cloud Platform and Cloudflare (via GoHighLevel). Data may be processed in the US and other jurisdictions with appropriate safeguards (e.g., Standard Contractual Clauses).
- Productivity & communications: Email, calendar, and video meeting tools (e.g., Google, Microsoft, Zoom).
- CRM & marketing automation: GoHighLevel; email delivery providers (e.g., Mailgun, SendGrid).
- AI/LLM services: Model/API providers used to deliver AI solutions (e.g., OpenAI or similar), strictly under customer instructions and agreements. We do not permit client content to be used to train public foundation models.
- Analytics: Privacy-respecting analytics tools (e.g., Plausible, Fathom) or Google Analytics (if used, with consent as required).
- Payments & billing: Stripe or equivalent; accounting tools (e.g., Xero, QuickBooks).
- Professional services: Insurers, accountants, legal advisors (where reasonably necessary).
Where providers collect aggregate or de-identified telemetry to maintain their services, we require contractual assurances that such data cannot be reverse-engineered to identify you or your users.
We require processors to protect data, use it only on our instructions, and delete/return it at contract end.
6) International transfers
Some providers may process data outside the UK. Where this happens, we use approved safeguards such as:
- UK adequacy decisions (including the UK–US Data Bridge for certified organisations), and/or
- Standard Contractual Clauses with the UK Addendum.
Contact us for details of the specific mechanisms in place for your data.
7) How long we keep data (retention)
We retain personal data only as long as necessary for the purposes above:
- Enquiry emails & proposals: up to 24 months after last contact if no contract follows.
- Contract/Project files: 6 years after contract end (tax/legal defence).
- Marketing lists: until you unsubscribe or inactivity is detected (periodic hygiene).
- AI prompts/outputs: default 30–90 days (up to 180 days if a project requires longer).
- Access & security logs: 12 months.
- Cookie/analytics data: per the durations in our Cookie Notice.
We securely delete or anonymise data once retention periods expire.
8) Your rights (UK GDPR)
You have the right to access, rectify, erase, restrict processing, object (including to marketing), and data portability where applicable. You can exercise rights by emailing [email protected]. We aim to respond within one month; this may be extended by up to two months for complex requests.
Where we rely on consent, you may withdraw it at any time.
You also have the right to complain to the Information Commissioner’s Office (ICO): ico.org.uk / 0303 123 1113. We’d appreciate the chance to resolve concerns first.
9) Security
We implement appropriate technical and organisational measures, including: multi‑factor authentication, access controls, encryption in transit, patching, least‑privilege access for staff/contractors, and regular backups. No system is 100% secure, but we work to protect your data continuously.
If we become aware of a personal data breach likely to result in a risk to individuals, we will assess promptly and notify the ICO within 72 hours where required, and affected individuals when legally required.
10) Responsible AI & automated decision‑making
We do not conduct solely automated decisions that have legal or similarly significant effects. Where we use AI to assist with triage or drafting, outputs are reviewed by a human before any material decision is taken. We aim to use AI responsibly, minimise data used, and prefer privacy‑preserving configurations.
11) Third‑party links
Our site may link to third‑party websites. Their privacy practices are outside our control; please review their notices.
12) Contact us
Questions or requests about this Policy or your data? Email [email protected]
Postal correspondence can be requested by email. Please note we are a remote consultancy currently operating internationally.
13) Changes to this Policy
We may update this Policy from time to time. Material changes will be highlighted on this page and, where appropriate, notified by email. Please check back periodically.
Global support for real estate founders with AI strategy and systems.
© 2025 Scale DPS. All rights reserved.
Terms of Service | Privacy Policy | About Us | Contact Us | Powered by AI. Built with GoHighLevel.
LinkedIn
Instagram