How Scalegrowth handles data privacy, consent management, and regulatory compliance.
Scalegrowth is designed from day 1 for multi-framework compliance:
India's Digital Personal Data Protection Act. Scalegrowth implements consent management, data localization (Mumbai data region), and data principal rights (access, correction, erasure).
Lawful basis tracking, data processing records, DPIA support, right to erasure, data portability, and breach notification procedures.
Do Not Sell toggle, data access requests, opt-out mechanisms, and annual privacy audit support.
In progress. Controls for security, availability, processing integrity, confidentiality, and privacy. Audit trail on all data access.
Information security management system. Risk assessment, access controls, incident management, and continuous improvement.
Every data processing activity in Scalegrowth is linked to a consent record:
Data subjects (leads, users) can exercise their rights:
DSRs can be submitted via Settings > Data & Privacy or via API. Deadlines are automatically calculated based on the applicable regulation.
Default retention periods (configurable in Settings > Privacy):
Data is automatically deleted after the retention period. You can shorten (but not extend beyond regulatory maximums) the retention period for each category.