Privacy Policy

Effective Date: 16th March 2026

Systems & Scale Ltd ("we", "our", "us", or "Systems & Scale") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our services, including our website (https://www.systemsandscale.co.uk), platform, community, and related tools (the "Platform").

Please read this Privacy Policy carefully to understand our policies and practices regarding your personal data and how we will handle it. If you do not agree with our policies and practices, please do not use the Platform. By accessing or using the Platform, you agree and consent to this Privacy Policy.

1. Introduction

Systems & Scale Ltd is a UK-based CRM and business systems platform built on Go High Level technology. We provide members with:

• Pre-built CRM systems and automation templates

• Business systems training and resources

• Community support and group programmes

• Integration with Go High Level and related business tools

Important: Data Controller vs Data Processor

We act in two different roles depending on whose data we're processing:

• Data Controller: For your Systems & Scale account data (name, email, billing, login information), we decide how and why your data is used.

• Data Processor: When you store your client/business data within your Systems & Scale account (via our Go High Level integration), you control how this data is used, and we process it on your behalf according to your instructions.

2. Data We Collect

We may collect the following types of personal data:

Account & Registration Information

• Name, email address, phone number

• Business name and details

• Billing and payment information

• Account credentials and login information

• Communication preferences

Technical Data

• IP address and device information

• Browser type and operating system

• Device ID and identifiers

• Cookies and similar tracking technologies

• Platform usage patterns and analytics

Business & Client Data (you control)

• Client contact information, business details, and communications (you provide this)

• Pipeline, project, and transaction data

• Custom data fields you create

• This data remains under your control; you are the data owner

Communications

• Support requests and customer service inquiries

• Feedback, surveys, and testimonials

• Marketing preferences and email communications

• Community forum posts and member interactions

Third-Party Integration Data

• Information from connected integrations (email providers, payment processors, etc.)

• Data shared through Go High Level's API connections

• Social media data (if you choose to connect social accounts)

3. How We Collect Data

We collect personal data:

• Directly from you — When you create an account, subscribe, make a purchase, or contact us

• Automatically — Through cookies, analytics tools, and tracking technologies as you use the Platform

• From third parties — Through Go High Level integrations, payment processors, email services, and other connected tools

• From marketing partners — Through affiliate programmes and referral tracking

4. How We Use Your Data

Account Management & Service Delivery

• Provide, manage, improve, and personalise the Platform

• Process payments, invoices, and billing

• Deliver member access to courses, templates, and community resources

• Manage your account, subscriptions, and user permissions

Customer Support

• Respond to support requests and inquiries

• Troubleshoot technical issues

• Provide training and onboarding assistance

Communication

• Send service updates, security alerts, and policy changes

• Send account notifications and subscription reminders

• Send marketing and promotional content (with consent)

• Conduct surveys and collect feedback

Platform Improvement

• Analyse usage data to improve features and user experience

• Identify trends and develop new services

• Test and optimise Platform functionality

• Generate statistical reports on Platform usage

Business Operations

• Perform accounting, invoicing, and reconciliation

• Comply with legal and contractual obligations

• Fraud prevention and security monitoring

• Legal compliance and regulatory requirements

Advertising & Marketing

• Personalise marketing content and offers

• Analyse advertising effectiveness

• Share anonymised insights with partners

5. Legal Basis for Processing (UK GDPR)

We process your personal data on the following legal bases:

• Performance of a contract — To deliver Platform services you've subscribed to

• Consent — For marketing communications and optional data processing (you can withdraw this anytime)

• Legitimate interests — For business operations, fraud prevention, security, platform improvement, and direct marketing

• Legal obligation — To comply with UK law, tax requirements, and regulatory obligations

For marketing communications, we rely on your consent. You can withdraw consent anytime by updating your preferences or contacting us.

6. Sharing Your Information

We may share your data with:

Service Providers

• Go High Level — Our core CRM platform provider (acts as a sub-processor for your data)

• Email service providers — For sending communications and campaigns

• Payment processors — Stripe, PayPal, or similar (for billing)

• Hosting providers — For website and platform infrastructure

• Analytics providers — For usage analysis and improvement

• Customer support tools — For managing inquiries and support tickets

Business Partners & Integrations

• Third-party apps — If you connect integrations (Zapier, Make, etc.), data may be shared per their terms

• Affiliate partners — If you accessed Systems & Scale through an affiliate link

• Marketing partners — For advertising and promotional campaigns

Legal & Regulatory

• Law enforcement or government agencies (if required by law or valid legal process)

• Professional advisors (solicitors, accountants, auditors) where necessary

Business Transfers

• In the event of a merger, acquisition, or sale of Systems & Scale Ltd, your data may be transferred as part of that transaction

We are not responsible for how third-party services use your data. Each third party has their own privacy policy, and you should review these before connecting integrations.

7. Data Retention

We retain your data only for as long as necessary to fulfil the purposes for which it was collected:

• Account data — Retained while your account is active, plus 7 years for legal/tax compliance

• Billing data — Retained for 6 years (UK legal requirement)

• Client/business data — Retained while your account is active; you control deletion

• Support communications — Retained for 3 years or as long as necessary to resolve issues

• Marketing data — Retained until you unsubscribe or request deletion

• Cookies — Retained per our Cookie Policy settings

If you cancel your account, we may retain certain information for:

• Legal and regulatory compliance

• Fraud prevention and dispute resolution

• Backup and archival purposes

You can request data deletion anytime, subject to legal retention requirements.

8. Your Rights

Under UK GDPR, you have the following rights:

Right of Access

You can request a copy of the personal data we hold about you.

Right to Rectification

You can correct inaccurate or incomplete data.

Right to Erasure ("Right to be Forgotten")

You can request deletion of your data, subject to legal obligations to retain it.

Right to Restrict Processing

You can ask us to limit how we use your data.

Right to Data Portability

You can request your data in a portable format to transfer to another service.

Right to Object

You can object to certain types of processing, including:

• Marketing and promotional emails

• Automated decision-making

• Processing for legitimate interests

Right to Withdraw Consent

If we process your data based on consent, you can withdraw that consent anytime.

Right to Lodge a Complaint

You can file a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk if you believe we're not handling your data fairly.

How to exercise your rights:

Contact us at [email protected] with your request, and we'll respond within 30 days.

9. Cookies & Tracking Technologies

We use cookies and similar technologies to:

• Maintain your login session

• Remember preferences

• Analyse website and platform usage

• Deliver personalised content

• Track advertising effectiveness

• Improve user experience

Types of cookies:

• Essential cookies (required for Platform function)

• Analytical cookies (usage data)

• Marketing cookies (personalised ads)

• Third-party cookies (from partners)

You can manage cookie preferences through your browser settings. Please refer to our separate Cookie Policy for detailed information.

Note: If you disable essential cookies, the Platform may not function properly.

10. Data Security

We implement appropriate technical and organisational security measures to protect your personal data against loss, misuse, unauthorised access, alteration, and disclosure:

• Encrypted data transmission (SSL/TLS)

• Secure data storage and access controls

• Regular security assessments and updates

• Staff training on data protection

• Incident response procedures

• Vendor security requirements

However, no technology is 100% secure. If you believe your account has been compromised (e.g., password breached), please notify us immediately at [email protected].

11. International Data Transfers

Go High Level (our platform provider) is a US-based company. When your data is transferred to the US and processed there, we ensure:

• Go High Level participates in the EU-U.S. Data Privacy Framework (DPF) and UK-U.S. DPF

• Appropriate safeguards are in place (Standard Contractual Clauses)

• Compliance with UK GDPR and international data protection laws

12. Children

We do not knowingly collect, use, or disclose personal data from children under 16. If we learn that we've collected data from a child under 16, we'll delete it immediately. If you're under 16, please do not provide any personal information to Systems & Scale.

13. Data Processing Agreement (DPA)

If you use Systems & Scale to process personal data of your customers or clients, you are the data controller, and we act as your data processor. A Data Processing Agreement (DPA) governs how we handle this data. Contact us at [email protected] to request or sign a DPA.

14. Links to Third-Party Websites

The Platform may contain links to third-party websites and services. We are not responsible for their privacy practices. This Privacy Policy applies only to Systems & Scale. Please review their privacy policies before using those services.

15. Privacy Policy Updates

We may update this Privacy Policy at any time. Changes will be posted on this page with an updated "Effective Date." For significant changes, we'll notify you via email or by prominent notice on the Platform.

Your continued use of the Platform after changes constitutes acceptance of the updated Privacy Policy.

16. Contact Us

For privacy inquiries, data requests, or complaints:

Systems & Scale Ltd

Data Protection Officer / Privacy Team

4 Curteys

Old Harlow

Essex, CM17 0JG

United Kingdom

Email: [email protected]

Response time: Within 30 days

For GDPR complaints:

Information Commissioner's Office (ICO)

Wycliffe House

Water Lane

Wilmslow

Cheshire, SK9 5AF

United Kingdom

Website: www.ico.org.uk

Phone: 0303 123 1113

17. Data Protection Representation (EU/EEA)

If you're in the EU or EEA and have concerns about data protection, you can contact us through the contact details above.

Last Updated: 16th March 2026

© 2026 Systems & Scale - All rights reserved.