Privacy Policy - BScale AI
Last updated: 2026-06-19
1. Who we are
This Privacy Policy describes how BScale AI processes personal data when you visit bscale.co.il or use our SaaS platform.
Data controller: Asher Bukshpan, operating under the trade name BScale AI.
Contact for privacy matters: main@bscale.co.il. Phone: +972-52-564-0054.
We do not currently have a designated EU Representative under GDPR Art. 27; EU/EEA residents should contact main@bscale.co.il.
2. Scope
This policy applies globally. Region-specific provisions for Australia, United Kingdom, Canada, Netherlands, Germany, France, California, Brazil and China are in dedicated sections below.
When you connect a third-party platform (Meta, Google Ads, GA4, Search Console, Gmail, Drive, TikTok, LinkedIn, WooCommerce, PayPal), their terms apply to data they hold.
3. Data we collect
Account data: name, email, password (salted hash only), profile photo, role, workspace.
Business and billing data: company name, website, billing address, VAT/tax ID, PayPal order IDs, invoice numbers and amounts.
Connection data: OAuth tokens (encrypted AES-256-GCM at rest), account identifiers, granted scopes.
Operational data from connected platforms: campaigns, audiences, creatives, performance metrics, search queries, page analytics, Meta Lead Form leads, WooCommerce orders (including end-customer names, addresses, phones).
AI usage data: prompts you submit, generated assets, wallet balance, USD amount spent.
Technical data: IP, user-agent, device, language, theme, pages visited, actions, timestamps.
Support data: messages, attachments, metadata.
4. How we use your data and our legal basis
GDPR Art. 6 legal bases:
(a) Provide and operate the platform - performance of contract.
(b) Bill, process payments, issue invoices - contract and legal accounting obligation.
(c) Service notifications - contract and legitimate interest.
(d) Analyze usage, detect abuse, prevent fraud - legitimate interest.
(e) Generate AI-based insights - performance of contract.
(f) Marketing communications - your consent or, where permitted, legitimate interest.
(g) Comply with legal obligations - legal obligation.
5. Sharing with sub-processors
Cloud hosting and storage: Google Cloud Platform (Cloud Run europe-west1, Cloud Storage, Cloud Logging).
Application monitoring: Sentry (with PII redaction).
Email to end-customers on your behalf: your connected Gmail account (only when you authorize).
Payment processing: PayPal (Orders API + IPN). We do not store card numbers; PayPal does.
AI providers: Anthropic (Claude), OpenAI (GPT, image gen), Google (Gemini), Runway, Kling, Seedance (video), a text-to-speech provider.
Connected ad/analytics platforms (only when you connect them): Meta, Google Ads, GA4, Search Console, Google Drive, TikTok Ads, LinkedIn Ads, WooCommerce.
Web analytics and ads measurement: Google Analytics and Google Ads may run by default when you visit the site, before you make a choice in the cookie panel, unless you reject or change preferences.
We do not sell personal information in the ordinary commercial sense.
An up-to-date sub-processor list is available on request.
6. International data transfers
Primary infrastructure in the EU (Google Cloud europe-west1, Belgium).
Some sub-processors (Sentry, Anthropic, OpenAI, Google AI APIs, Meta, TikTok, LinkedIn, PayPal) process data in the US or other countries outside the EEA.
For such transfers we rely on EU Standard Contractual Clauses (2021/914), the UK IDTA and Swiss FDPIC clauses.
You may request a copy of the transfer safeguards by writing to main@bscale.co.il.
7. Data retention
Account data: kept for the lifetime of your account; deleted within 30 days of closure.
Billing data and invoices: 7 years (Israeli tax and accounting law).
Audit logs: 12 months active storage, up to 24 months cold storage.
Backups: rolling 35-day backups.
Support messages: 24 months from last interaction.
AI prompts and generated assets: kept while your wallet history needs them, then deleted within 60 days of account closure.
8. Security
Reasonable and appropriate technical and organizational measures including:
TLS 1.2+ encryption in transit.
AES-256-GCM encryption at rest for sensitive credentials including OAuth tokens.
Salted password hashing.
Per-request CSP with nonces, double-submit CSRF cookies, HMAC-signed cron endpoints.
Role-based access control with least privilege.
Immutable audit log of administrative actions.
Tiered rate limiting on sensitive endpoints.
9. Your rights
EU/EEA, UK, Switzerland, Israel and Australia residents (and equivalents elsewhere) have the following rights. Exercise via main@bscale.co.il or Settings > Security & privacy.
Access (GDPR Art. 15): JSON export from Settings.
Rectification (Art. 16): edit profile in Settings.
Erasure (Art. 17): delete account in Settings; cascades to related records.
Restriction (Art. 18): contact us.
Data portability (Art. 20): the JSON export is machine-readable.
Object (Art. 21) to processing based on legitimate interests, including profiling.
Withdraw consent (Art. 7(3)) at any time.
Not subject to fully automated decisions with legal effects (Art. 22). Our AI recommendations are decision support; you act on them yourself.
10. California residents (CCPA / CPRA)
California residents have, in addition to Section 9, the following rights:
Right to know what categories were collected, sources, purposes, and third parties - see Sections 3 and 5.
Right to delete, subject to legal exceptions.
Right to correct.
Right to opt out of 'sale' or 'sharing' for cross-context behavioral advertising. We do not sell personal information. To exercise: email main@bscale.co.il with subject 'Do Not Sell or Share'.
Right to limit use of sensitive personal information.
Right to non-discrimination.
An authorized agent may submit requests on your behalf.
10a. United States customers (billing & tax)
If your billing country is the United States, subscription and balance top-up checkout may be priced in USD through PayPal.
Applicable state and local sales tax is calculated from your billing state and ZIP/postal code using our tax engine (TaxJar when enabled).
You can submit privacy requests (access, delete, opt-out of sale/sharing) at /privacy-request or by emailing main@bscale.co.il.
We honor Global Privacy Control (GPC) and the in-product 'Do Not Sell or Share' control as opt-out signals where required by state law.
10b. Australia residents (Privacy Act 1988 & APPs)
Australian Privacy Principles (APPs) 1–13 apply when we process personal information of individuals in Australia.
We collect only information reasonably necessary for our functions; you may access and correct your information and complain to us first.
Eligible data breaches are assessed under the Notifiable Data Breaches (NDB) scheme; affected individuals and the OAIC are notified when required (typically within 72 hours of becoming aware).
Direct marketing requires express or inferred consent under the Spam Act 2003 and APP 7; you can opt out at any time.
Complaints: Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au.
10c. United Kingdom residents (UK GDPR & DPA 2018)
UK GDPR and the Data Protection Act 2018 apply to UK residents.
You have the same core rights as EU GDPR (access, rectification, erasure, restriction, portability, objection).
Electronic marketing is subject to PECR; see our Cookies Policy for cookie and similar technologies.
Complaints: Information Commissioner's Office (ICO) at https://ico.org.uk.
10d. Netherlands residents (UAVG & Telecommunicatiewet)
The UAVG (Dutch GDPR implementation) applies together with the Telecommunicatiewet for electronic communications.
Tracking and marketing cookies require prior consent under the Telecommunicatiewet; manage preferences via the cookie panel.
Complaints: Autoriteit Persoonsgegevens (AP) at https://autoriteitpersoonsgegevens.nl.
10e. Germany residents (BDSG & TTDSG)
The BDSG supplements GDPR for Germany; the TTDSG governs access to end-user terminal equipment.
Non-essential cookies and similar tracking require opt-in consent under TTDSG §25 before activation.
Complaints: Federal Commissioner for Data Protection (BfDI) at https://www.bfdi.bund.de.
10f. France residents (CNIL & Code de la consommation)
CNIL guidance applies to French residents alongside GDPR.
You may lodge a complaint with CNIL at https://www.cnil.fr.
Commercial prospecting is subject to French consumer and e-privacy rules; opt-out links are honored promptly.
11. Brazil residents (LGPD)
Brazilian residents have LGPD rights: confirmation, access, correction, anonymization, portability, deletion, information about third parties.
Legal bases under LGPD Art. 7.
Complaints to ANPD: https://www.gov.br/anpd.
12. Canada residents (PIPEDA and Quebec Law 25)
PIPEDA rights: access, correction, withdraw consent.
Quebec Law 25: portability and information about automated decisions.
Privacy Officer: main@bscale.co.il.
Complaints to OPC of Canada or CAI of Quebec.
12a. Canada - CASL and expanded PIPEDA
Commercial electronic messages (CEMs) require express or implied consent under CASL; every CEM includes identification and unsubscribe.
PIPEDA accountability: we maintain safeguards proportionate to sensitivity; Quebec Law 25 adds portability and automated-decision transparency.
Complaints: Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca) or Commission d'accès à l'information du Québec.
13. China residents (PIPL)
PIPL requires a specific legal basis. We rely on your explicit consent and the CAC standard contract for cross-border transfers where applicable.
Rights to be informed, decide, restrict, access, copy, correct, delete and de-register, and to request explanations of automated decisions.
15. AI transparency
Features use third-party generative AI from Anthropic, OpenAI, Google (Gemini), Runway, Kling and Seedance.
Content you submit is sent to the chosen provider, processed and stored in your workspace.
We instruct providers, where they offer it, not to use your inputs to train public models. We do not sell prompt data.
AI outputs may be inaccurate or misleading. See /ai-disclosure (EU AI Act Art. 50).
When you publish an AI Visibility business profile, selected business information (and contact details or address when opted in) becomes publicly accessible and machine-readable via llms.txt, profile.json and Schema.org for AI engines and crawlers. You control what is published through opt-in settings.
16. Children
Platform intended for business users 16 or older (13+ where COPPA applies).
To report a minor's data: main@bscale.co.il.
17. Our role as Data Processor
When you use the platform to manage leads, customer orders, deliveries and similar business records, you are the data controller for your end customers and we are your data processor.
We process such data only on your documented instructions, will assist you in responding to customer requests, and will return or delete data when your account closes.
A DPA is available at /dpa for B2B users.
18. Personal data breach notification
If a personal data breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and notify affected users without undue delay where the risk is high (GDPR Arts. 33-34).
19. Changes to this policy
We may update this policy from time to time. Registered users will be emailed at least 30 days before material changes take effect.
The 'Last updated' date always reflects the current version.
20. Right to lodge a complaint
EU: data protection authority of your EU member state. Directory at https://edpb.europa.eu.
UK: ICO at https://ico.org.uk.
Switzerland: FDPIC.
Israel: Privacy Protection Authority at the Ministry of Justice.
Brazil: ANPD at https://www.gov.br/anpd.
United States: FTC (https://reportfraud.ftc.gov) or California Privacy Protection Agency (https://cppa.ca.gov).
Canada: OPC of Canada (https://www.priv.gc.ca).
Australia: OAIC (https://www.oaic.gov.au).
21. Responsibility for actions on connected platforms
The platform may perform real actions on third-party platforms (creating, editing, pausing or budgeting campaigns on Google Ads, Meta, TikTok, LinkedIn and others) on your behalf after you connect the relevant account.
You are responsible for the consequences. BScale AI does not warrant any specific result and is not liable for direct, indirect, incidental or consequential damages, except where law prohibits exclusion.