Mosaic Suite Privacy Policy
This Privacy Policy explains how Scalemind AI Ltd. ("we", "us", or "Scalemind") collects, uses, shares, and protects your personal information when you use Mosaic Suite. This policy has been designed to comply with the EU General Data Protection Regulation (GDPR) and ISO 27001:2022 information security standards.
1. Data Controller
Scalemind AI Ltd. acts as the Data Controller for personal data processed through Mosaic Suite. If you use our platform on behalf of an organisation that has a separate agreement with us, that organisation may be the Data Controller, and we act as a Data Processor under the terms of the applicable Data Processing Agreement (DPA).
2. What Data We Collect
We collect the following categories of personal data:
- Account Information: Name, email address, hashed password, profile image, and organisation name provided at registration.
- Social Media Data: Access tokens, profile metadata, Page/Organisation IDs, and post content obtained from connected third-party platforms (currently LinkedIn and Twitter/X, with Facebook/Instagram availability depending on workspace setup).
- User-Generated Content: Brand voice definitions, product catalogues, company knowledge base entries, media uploads, and content you compose or that our AI generates on your behalf.
- Usage Data: Interaction logs, feature usage analytics, device information, IP address, and browser/app version.
- Payment Data: If applicable, handled by our PCI-DSS compliant payment processor. We do not store raw card details.
3. Legal Basis for Processing
Under GDPR Article 6, we process your data on the following bases:
- Contract Performance (Art. 6(1)(b)): To provide the Mosaic Suite service you signed up for.
- Legitimate Interest (Art. 6(1)(f)): To improve our platform, prevent fraud, and analyse usage patterns in an aggregated and anonymised manner.
- Consent (Art. 6(1)(a)): For optional analytics cookies and marketing communications. You may withdraw consent at any time.
- Legal Obligation (Art. 6(1)(c)): To comply with applicable laws and regulations.
4. How We Use Your Data
- To operate, maintain, and improve Mosaic Suite's features including AI content generation, scheduling, and analytics.
- To connect your social media accounts and publish content on your behalf with your explicit authorisation.
- To send transactional notifications (e.g., post published, campaign complete).
- To provide customer support and respond to enquiries.
- To detect and prevent security incidents in accordance with our ISO 27001 ISMS.
5. Data Sharing & Third Parties
We do not sell your personal data. We may share data with the following categories of processors:
- Infrastructure Providers: Cloud hosting and database services (all EU-based or with Standard Contractual Clauses in place).
- AI Model Providers: Prompts may be sent to LLM providers for content generation. We strip personally identifiable information from prompts wherever possible. Refer to our AI Usage Policy for details.
- Social Media APIs: Content that you approve for publishing is sent to connected platform APIs where available (currently LinkedIn and Twitter/X; Facebook/Instagram may use manual posting flows) under each platform's own privacy terms.
- Analytics Providers: Aggregated, anonymised usage data only – subject to your cookie consent.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. Upon account deletion, we will erase or anonymise your data within 30 days unless a longer retention is required by law. Backups containing deleted data are automatically purged within 90 days.
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of Access (Art. 15): Request a copy of all data we hold about you.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete data.
- Right to Erasure (Art. 17): Request deletion of your account and associated data ("Right to be Forgotten").
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to Restrict Processing (Art. 18): Limit how we use your data in certain circumstances.
- Right to Object (Art. 21): Object to processing based on legitimate interest.
- Right to Withdraw Consent (Art. 7(3)): Withdraw any previously given consent at any time.
To exercise any of these rights, please contact our Data Protection Officer at info@scalemindai.com. We will respond within 30 days.
8. Data Security (ISO 27001)
We implement technical and organisational security measures in accordance with ISO 27001:2022, including:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256).
- Role-Based Access Controls (RBAC) enforced at application and infrastructure levels.
- Regular penetration testing and vulnerability assessments.
- Incident Response procedures with defined escalation paths.
- Continuous monitoring and audit logging of all administrative access.
9. International Transfers
Where we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place through Standard Contractual Clauses (SCCs) or adequacy decisions as approved by the European Commission.
10. Cookies
We use essential cookies required for the platform to function and optional analytics cookies subject to your consent. You can manage your cookie preferences at any time through the cookie banner or your account settings. Refer to our cookie banner for detailed information.
11. Data Breach Notification
In the event of a data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay, in accordance with GDPR Articles 33 and 34.
12. Contact & Supervisory Authority
For any privacy-related questions, contact our Data Protection Officer at info@scalemindai.com.
You also have the right to lodge a complaint with your local Data Protection Authority (DPA). For the UK, this is the Information Commissioner's Office (ICO).