Privacy Policy
Updated 1 August 2026
07 Privacy Policy
How data is handled in and around Scalegram
7.1 Two Roles
For account data (the Customer's company details, billing records, User accounts, support history and website analytics) we are the controller. For workspace content, above all Lead Data synced from Connected Accounts, captured by bridge pages, or generated by the AI Assistant, the Customer is the controller and we are a processor acting only on the Customer's instructions. A data-processing agreement forms part of these terms for business customers; contact us for a signed copy.
7.2 What We Process
- Account data: names, emails, company details, billing and subscription records, support correspondence.
- Workspace content: Telegram contact profiles and the times they were last in contact, notes, tags, trading-account records the Customer enters or imports, emails captured on bridge pages, and the conversations the AI Assistant itself holds. The Platform keeps no copy of the messages in a Connected Account: there is no message store, and the text of those chats is not written to our systems.
- Chats read but not kept: where a Customer switches on the "Earlier Conversations" option for a bot, the Platform reads that contact's existing chat from the Connected Account at the moment a reply is being composed, so the Assistant answers a long-standing contact in context rather than as a stranger. Those messages are held in memory for that reply only, are sent to the AI provider the Customer has chosen under the Customer's own API key, and are never written to disk by us. The option is off unless the Customer turns it on, and can be turned off at any time.
- Connection credentials: Telegram session data and bot tokens, stored encrypted, never displayed after creation, and deleted when a connection is removed.
- Tracking data: click records for the Customer's tracking links, advertising click identifiers and pixel event logs.
7.3 If You Are a Lead
If your messages or details appear in a Customer's workspace, that Customer decides why and how your data is used; we store and process it on their behalf. To access, correct or delete your data, contact the business you were talking to on Telegram. If you cannot reach them, contact us and we will pass your request to the responsible Customer and assist as the law requires.
7.4 Advertising Platforms and Hashed Data
Where a Customer enables pixel integrations, event data is sent to the chosen platforms (such as Meta, TikTok or Snapchat). Identifiers such as email addresses are hashed before transmission; raw email addresses are not sent to advertising platforms and are not stored in event logs. Advertising click identifiers and browser cookie values are transmitted as the platforms require them, unhashed, because that is the only form in which they can be matched. The Customer is responsible for having a lawful basis, and where required consent, for this tracking.
7.5 Retention, Security and Transfers
Workspace content is retained while the workspace exists, subject to any retention settings the Customer configures, and is deleted after workspace deletion following a short recovery window. Credentials and secrets are encrypted at rest; access is role-restricted and logged. Where data is transferred internationally we use recognised safeguards. We use a small number of sub-processors for hosting, email delivery and payment processing; a current list is available on request.
7.6 Your Rights
Depending on your jurisdiction you may have rights to access, rectify, erase, restrict or port personal data, and to object to certain processing. For account data, contact us directly. For Lead Data, Section 7.3 applies. You may also complain to your data-protection authority.
12 Contact
For any questions about these terms, our policies, or to exercise a data-protection right, please contact us at the address below.
SGHK Softwares Limited
Licence No. 80264490 · D-U-N-S 374223638
Flat 5, 4/F, Won Hing Building, 74–78 Stanley Street, Central, Hong Kong