1. Service provider
The intended contracting entity is G5 HOLDING OÜ (registry code 17431342), Keemia tn 7–15, 10616 Tallinn, Estonia, for customers in Estonia. For customers in the United States and Europe outside Estonia, it is BIRCHG5WOLF LLC, 16192 Coastal Highway, Lewes, Delaware 19958, County of Sussex, United States. Your order confirmation must name the applicable entity before a paid contract begins. Other territories are not yet assigned.
Contact both entities about Scly at team@scly.dev. The LLC registration number still requires confirmation. The entity split is the founders’ proposed operating structure; actual privacy responsibilities and any sharing between the two entities must be documented before launch.
2. Our roles
The intended Scly provider named in your agreement controls account administration, service security and its own support and billing records. When Scly processes personal data in your product content, media or instructions solely to carry out your business’s directions, your business normally remains the controller and Scly acts as a processor under a Data Processing Agreement.
Contract geography alone does not determine GDPR roles. The actual decisions, staff access, provider contracts and any sharing between G5 HOLDING OÜ and BIRCHG5WOLF LLC must match the final notice and DPA. An EU representative for the LLC has not been designated in this draft; assess whether designation is required before serving relevant EU customers.
3. Data and sources
The current pilot can process the following data. You provide account and workspace content; connected services and public source pages supply the information requested by your workflows. Avoid including unnecessary personal data.
- Account email, user and workspace identifiers, password hashes and session records. Plain-text account passwords are not kept in the account registry.
- Products, prices, uploaded images and video, prompts, conversations, saved playbooks, teaching examples, source URLs and generated pages, media and creatives. Media may contain faces, voices or other personal data.
- Store domain, platform identifiers, granted permissions and encrypted connection credentials. Scly analytics requests aggregate store or advertising reports when access is available; uploading customer lists is not a required workflow.
- Scheduled work, status events, usage estimates, privacy requests and support correspondence. Operational logs can contain request context or error details; production minimisation and retention still require completion.
- Publicly sourced creator names, handles, captions, footage and URLs when you request content discovery. A public source is not a consent or licensing record.
4. Purposes and lawful bases
For an individual contracting directly with Scly, account access and requested service delivery can rely on contractual necessity. For a business’s employee or representative, necessary account administration, support and security generally rely on legitimate interests in delivering and protecting the business service, subject to a documented balancing assessment. Do not use contractual necessity for someone who is not a party to the contract.
Where applicable, required financial, tax or regulatory records are processed to comply with legal obligations. Optional marketing or non-essential tracking must have a separate valid basis and, where required, prior consent. Neither is implemented in the audited pilot. Processing on a merchant’s behalf follows the merchant’s documented instructions and lawful basis under the DPA.
Providing account identity is needed to sign in. You choose which products, media and instructions to supply; an unavailable connection or missing material can prevent a requested task. Scly does not use the current pilot to make automated decisions about individuals with legal or similarly significant effects.
5. AI, recipients and international processing
Requested AI features can transmit relevant prompts, product facts, playbooks and reference images to the enabled AI service. Production adapters support the OpenAI API and, when configured, Google Gemini image generation. OpenAI response storage is disabled by the adapter, but that setting does not eliminate all provider retention. Provider-specific retention, contracts and transfer locations must be confirmed before production use.
The developer pilot currently uses a local Codex connection linked to the developer’s ChatGPT account. It is a testing configuration, not a promise of production API data handling. Image generation is not active without an image-provider connection. Existing local video rendering is performed by FFmpeg rather than an external video-generation service.
Shopify receives product content and media you approve for publication. Meta can provide advertising-account reporting when configured; the current campaign feature stores drafts and is not a live ad-spend integration. Content discovery contacts source platforms or search services. Their independent services have their own notices.
Access by Scly staff must be limited to authorised service and support purposes. Hosting, payment and support vendors have not yet been selected for production. The provider register lists known integrations and unresolved vendor arrangements. No approved hosting region, all-EU processing, zero-retention status or completed transfer assessment is claimed.
Before any restricted international transfer, document a valid mechanism, such as an applicable adequacy decision or appropriate contractual safeguards and any necessary assessment and supplementary measures. Do not assume that every US provider is covered by an adequacy framework. Verify the specific recipient and scope.
6. Storage, retention and security
The local pilot stores workspace records and file bytes in a persistent database on the developer’s computer. It also creates temporary rendering files, prepared theme files and operational logs. Production hosting and backup arrangements are still being determined.
Sessions expire after seven days. Store-connection state cookies expire after ten minutes. The browser appearance preference remains until changed or browser storage is cleared. Workspace records currently have no automatic retention purge; deletion is handled through a reviewed request. Final retention limits for content, logs, backups, privacy records and legally required financial records must be approved and implemented before launch.
Existing safeguards include individual pilot accounts, workspace-scoped queries, signed sessions, password hashing and encrypted store credentials. These measures do not establish that every file or database is encrypted at rest. Production access controls, backup restoration, monitoring, incident procedures and retention controls are release requirements.
7. Your rights and contact
Where applicable, you may ask for access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Consent, if used for an optional purpose, can be withdrawn without affecting prior lawful processing. Rights depend on the circumstances; a justified legal retention obligation may prevent immediate erasure of particular records.
Use Settings → Privacy & data to download a workspace data copy or record a request. You can also email team@scly.dev without signing in. We may request proportionate verification if necessary. The download is not a complete response covering support emails, provider records, logs or backups; a rights request covers that review too.
The intended response procedure is without undue delay and normally within one month. If a lawful extension is necessary because of complexity or number of requests, explain it within the initial month. There is no routine fee; any lawful exception requires an explanation. If Scly is the merchant’s processor, it assists the merchant in responding rather than deciding independently about its customers.
You may complain to a competent supervisory authority, including the Estonian Data Protection Inspectorate (aki.ee) or the authority where you live or work in the EEA. Contacting Scly first is not a condition of that right.
8. Children and updates
The proposed service is for adult business users and is not designed for children. Do not submit children’s personal data in the pilot. Material changes to data handling must be reflected in an updated, dated notice and communicated before the new activity begins.