Privacy Policy
This is a courtesy translation. The German version is legally binding.
1. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Scalia Studio GbR
represented by its partners Max Hengl and Matteo Mio
Köpenicker Str. 43
10179 Berlin, Germany
Email: max@scaliastudio.org
Phone: +43 664 2793259
We have not appointed a data protection officer, as the legal requirements for doing so (Art. 37 GDPR, § 38 BDSG) are not met. For any question about data protection, please contact us using the details above.
2. Overview
We process personal data only where this is necessary to operate this website, answer your enquiries and provide our services, or where you have given your consent. We do not sell data, we do not use advertising tracking, and we do not set cookies for analytics or marketing purposes.
Our services are aimed exclusively at businesses. The following sections describe each processing activity individually: which data, for what purpose, on which legal basis, to whom, and for how long.
3. Hosting, delivery and security (Cloudflare)
This website is delivered via the infrastructure of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. When you visit the website, Cloudflare processes technically necessary data, in particular your IP address, the date and time of access, the requested address, the amount of data transferred, the referrer, and browser and operating system information (server log files). Cloudflare also protects the website against attacks and abuse.
The legal basis is our legitimate interest in providing the website securely, quickly and reliably (Art. 6(1)(f) GDPR). We have a data processing agreement with Cloudflare (Art. 28 GDPR). Cloudflare is certified under the EU-US Data Privacy Framework, so transfers to the USA are covered by an adequacy decision of the European Commission (Art. 45 GDPR). Cloudflare deletes or anonymises log data after a short period.
4. Audience measurement (Cloudflare Web Analytics)
We use Cloudflare Web Analytics to understand which pages are visited and how often. The service works without cookies, without storage in your browser and without fingerprinting; it does not build user profiles and does not track you across other websites. It processes technical information about the page view (e.g. the page visited, referrer, load times, approximate origin at country level).
The legal basis is our legitimate interest in statistical analysis and in improving our website (Art. 6(1)(f) GDPR). Provider and third-country transfer: see section 3.
5. Spam protection (Cloudflare Turnstile)
Our forms are protected against automated submissions by Cloudflare Turnstile. Your IP address and technical characteristics of your browser and device are transmitted to Cloudflare and evaluated to check whether a submission comes from a human. Turnstile is loaded only on pages that contain a form.
The legal basis is our legitimate interest in protecting our forms against abuse and spam (Art. 6(1)(f) GDPR). Provider and third-country transfer: see section 3.
6. Enquiries by form, email and phone
When you send us an enquiry using a form on this website (e.g. the enquiry or audit form, or the contact pop-up), we process the data you provide: name, email address, company, website, your request, and the page from which the enquiry was sent. When you contact us by email or phone, we process the data you share with us.
Form data is passed through our interface (api.scaliastudio.dev, operated on Cloudflare) and stored in a database we operate ourselves (NocoDB) on a server of Hetzner Online GmbH in Germany. Name, email address and company are also sent as an internal notification to our workspace at Slack (Slack Technologies, LLC, a Salesforce company, USA), so that we can respond promptly.
If you give us a website to analyse, we access it automatically and have it measured via the Google PageSpeed Insights interface (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Only the address of the website is transmitted, no information about you.
The legal basis is taking steps prior to entering into a contract at your request (Art. 6(1)(b) GDPR) and our legitimate interest in handling enquiries efficiently (Art. 6(1)(f) GDPR). We have data processing agreements with Hetzner and Slack. Slack/Salesforce is certified under the EU-US Data Privacy Framework (Art. 45 GDPR).
We delete enquiries once they have been fully dealt with and no contract has been concluded, at the latest after 12 months. If a contract is concluded, the periods in section 9 apply.
7. Waitlist and updates
On some product pages (e.g. Open Claude) you can join a waitlist. We store your email address, the product, the time, and, where available, campaign information from the link you arrived through (UTM parameters). The data is held in the same database as described in section 6. We use it to inform you when the product launches.
You can optionally tick a box to receive occasional updates from Scalia Studio. In that case we also store your consent, its exact wording and the time. We do not send such updates yet. Before the first one, you will confirm your address via a confirmation email (double opt-in); only then will you receive updates.
The legal basis for the waitlist is your request (Art. 6(1)(b) GDPR), and for updates your consent (Art. 6(1)(a) GDPR). You can withdraw your consent at any time with effect for the future, e.g. by email to max@scaliastudio.org or via the unsubscribe link in every message. We delete waitlist entries immediately on request, and otherwise at the latest 12 months after the product launches; we keep your address for updates until you withdraw your consent.
8. Storage in your browser (local storage)
We do not set cookies. For two convenience functions we store small pieces of information in your browser's local storage: whether and when you closed or submitted our contact pop-up, so that it does not appear again, and, on some demo pages, your language choice. This information does not leave your device and is not sent to us. You can delete it at any time in your browser settings.
The legal basis is § 25(2) no. 2 TDDDG (strictly necessary for a service you requested) in conjunction with Art. 6(1)(f) GDPR.
9. Clients and business partners
If you commission us, we process the data needed to perform the contract, in particular the names and contact details of your contact persons, project and invoicing data, and our correspondence.
The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR). We keep documents relevant under commercial and tax law for the statutory periods, usually six or ten years (§ 257 HGB, § 147 AO), and delete them afterwards.
10. Embedded content (YouTube, Google Maps)
YouTube. On some pages we embed videos from YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) in privacy-enhanced mode (youtube-nocookie.com). At first, only a preview image served from our own server is shown. Only when you click play is the player loaded and a connection to YouTube established; your IP address and technical information, among other things, are transmitted. The legal basis is your consent given by clicking (Art. 6(1)(a) GDPR, § 25(1) TDDDG).
Google Maps. Some demo pages embed a map from Google Maps (Google Ireland Limited). When the map loads, your IP address and technical information, among other things, are transmitted to Google; this may include a transfer to Google LLC in the USA, which is certified under the EU-US Data Privacy Framework. The legal basis is our legitimate interest in a clear presentation (Art. 6(1)(f) GDPR) or, where we load the map only after a click, your consent (Art. 6(1)(a) GDPR).
More information: Google's privacy policy.
11. Links to LinkedIn and other websites
We link to our profiles on LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland) and to other external websites. These are plain links without embedded plugins: only when you click a link do you leave our website, and the privacy terms of the respective provider then apply.
12. Fonts
All fonts are served from our own server. There is no connection to Google Fonts or any other font provider.
13. Encryption
This website uses TLS encryption throughout (recognisable by "https://" in the address bar). Data you send to us therefore cannot be read by third parties.
14. Recipients and transfers to third countries
We share personal data only with the service providers named in this policy, who process it on our behalf and according to our instructions, or where we are legally obliged to do so. Transfers to the USA are made to Cloudflare, Inc. and Slack Technologies, LLC (Salesforce) and, where applicable, to Google LLC. These companies are certified under the EU-US Data Privacy Framework and covered by an adequacy decision of the European Commission (Art. 45 GDPR).
15. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to withdraw any consent given with effect for the future (Art. 7(3)). An informal message to max@scaliastudio.org is sufficient.
Right to object (Art. 21 GDPR). Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59–61, 10555 Berlin, www.datenschutz-berlin.de.
Providing your data is not required by law or contract. Without the mandatory fields in a form, however, we cannot process your enquiry there. No automated decision-making, including profiling (Art. 22 GDPR), takes place.
16. Information for data subjects in Austria
You may also lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde): Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, www.dsb.gv.at. As we are established in Germany, the lead authority is the Berlin Commissioner for Data Protection and Freedom of Information; the Austrian authority may forward your complaint there.
17. Information for persons in Switzerland
For persons in Switzerland, the Swiss Federal Act on Data Protection (FADP/DSG) applies in addition. You have the rights granted under Swiss law, in particular access (Art. 25 FADP), data disclosure and portability (Art. 28 FADP), and rectification and erasure.
Disclosure abroad (Art. 19(4) FADP). Your data is processed in Germany and transferred to the following recipients in the USA: Cloudflare, Inc. (hosting, security, statistics), Slack Technologies, LLC / Salesforce (internal notification of enquiries) and, where applicable, Google LLC (embedded content). Under Annex 1 of the Swiss Data Protection Ordinance (DPO/DSV), Germany and the USA are considered to provide adequate data protection; for the USA, this applies to companies certified under the Swiss-U.S. Data Privacy Framework.
You can file a report with the Federal Data Protection and Information Commissioner (FDPIC/EDÖB): www.edoeb.admin.ch.
18. Changes
We update this privacy policy when our website, our service providers or the legal situation change. The version published here applies.
As of: 1 October 2026