Draft. This policy has not yet been reviewed by a lawyer and must be before launch — read it as a statement of intent, not as final legal wording.

Legal

Privacy policy

Last updated 12 September 2026.

1. Who we are

Scout Lane is a client gallery, review and delivery platform for production companies. This policy explains what we do with personal data, in the sense the General Data Protection Regulation (EU) 2016/679 gives that term.

Placeholder — founder to complete before launch

The controller for the purposes of this policy is the entity named here.

Legal entity name
[ legal entity name ]
Registered address
[ street, postcode, city, country ]
Company registration number
[ registration number and register ]
VAT number
[ VAT number ]
Data protection contact
[ confirm: privacy@scoutlane.com ]
Data protection officer
[ appointed / not required — to be confirmed ]

For anything covered by this policy, write to privacy@scoutlane.com.

2. Controller or processor

Two different relationships run through this platform, and the answer to "who is responsible for this data" is different in each.

We are the controller for the data of the people who buy and administer Scout Lane: the producers and heads of production who hold an account, the people who contact us through the website, and the billing contacts on a subscription. We decide why and how that data is processed.

We are the processor for everything a customer puts into their workspace: the photographs, video, call sheets and casting material they upload, the names of their projects and clients, the gallery logins they create for their clients, and the record of what those clients looked at and liked. The customer is the controller for all of it. We process it on their documented instructions, which are the actions they take in the product plus the data processing agreement.

If you were given a login to look at a gallery and you want to know what is held about you, the production company that invited you is the controller and is the right first contact. Write to us anyway if you cannot reach them and we will pass the request on and tell you we have.

3. Data we hold as controller

Personal data held by Scout Lane as controller
CategoryWhat it containsWhere it comes from
Account Name, work email address, role in the workspace, an Argon2id hash of the password, invitation and password-reset tokens You, or a colleague who invited you
Sessions A keyed hash of each session token, creation and last-seen time, device class, browser user agent Generated when you sign in
Workspace Company name, plan, subscription status, logo and accent colour, contact email You
Billing Billing name and address, VAT number, invoices, payment status. Card details are held by our payment processor and never by us You, and our payment processor
Enquiries Email address, company, country and message from the contact form, plus a salted hash of the sending IP address, the browser user agent and the referring page You, when you use the contact form
Support correspondence Emails you send us and our replies You
Server logs Web server access logs, which include the connecting IP address, the requested path and a timestamp Generated automatically
Audit log Administrative actions inside a workspace — who invited whom, who deleted what Generated by the product

We do not buy contact lists, we do not enrich your record from third-party data brokers, and we do not profile you. There is no automated decision-making that produces legal or similarly significant effects.

4. Data we hold as processor

On behalf of our customers, and only on their instructions, the platform holds:

  • Uploaded material — stills, video, PDFs and the derivatives generated from them. Photographs of identifiable people are personal data, and on this platform they are frequently the whole point: casting portraits, crew stills, scouting images with passers-by in frame.
  • Project metadata — project, client, category and folder names, notes and file names.
  • Gallery logins — the username, display name, password hash, permissions and expiry of each client login the customer creates.
  • Viewing records — when a gallery session started, how long it lasted, which images were opened, liked, annotated or downloaded, a coarse device class, the browser user agent, and a salted hash of the viewer's IP address rather than the address itself.

The salted hash is deliberate. Counting sessions requires knowing whether two visits came from the same place; it does not require knowing where that place is. The hash supports the first and cannot answer the second, so no raw viewer IP address is written to the database at any point.

We do not use this material for our own purposes. We do not train machine learning models on it, we do not scan it for content beyond generating thumbnails and poster frames, and we do not disclose it to anyone except the sub-processors listed below and where the law compels us.

5. Lawful bases

Lawful bases for processing
PurposeBasis
Giving you an account and running the service you subscribed toPerformance of a contract — Art. 6(1)(b)
Answering an enquiry sent through the contact formSteps taken at your request before entering a contract — Art. 6(1)(b), and our legitimate interest in responding to business enquiries — Art. 6(1)(f)
Taking payment, issuing invoices, keeping accounting recordsContract — Art. 6(1)(b) — and legal obligation — Art. 6(1)(c)
Rate limiting, login throttling, abuse detection, fraud prevention, server logsLegitimate interests — Art. 6(1)(f): keeping the service available and other people's material private
Service email you cannot opt out of — security notices, breach notifications, changes to these terms, billing failuresContract — Art. 6(1)(b) — and legal obligation — Art. 6(1)(c)
Marketing email about the productConsent — Art. 6(1)(a) — withdrawable at any time, or Art. 6(1)(f) for existing customers about a directly comparable service, with an unsubscribe link in every message
Processing a customer's project material and their clients' viewing recordsWe act as processor on the customer's instructions — Art. 28. The customer determines the lawful basis

Where we rely on legitimate interests we have weighed those interests against your rights and freedoms, and you can object at any time — see section 9.

6. How long we keep it

Retention periods
DataKept for
Account and workspace recordsWhile the subscription is live, then 30 days after it closes
Uploaded material and project metadataUntil the customer deletes it. On closure of a workspace, 30 days for export, then the storage subtree is purged
Gallery loginsUntil deleted or expired by the customer; removed with the project
Viewing records and analytics events24 months, then deleted
SessionsUntil they expire — one hour for a staff access token, 30 days for a refresh token, 14 days for a gallery session — or until revoked
Web server access logs14 days
Audit log12 months
Contact form enquiries24 months from the last exchange, unless the enquiry became a subscription
Invoices and accounting recordsAs long as tax and commercial law requires, typically up to ten years
BackupsRolling 30 days, after which the backup containing the data expires

Deleting something in the product removes it from every view immediately and queues the bytes for removal from disk. It remains in the encrypted backups until those backups age out, which is the honest description of what "deleted" means for any system that keeps backups at all. If you need a deletion confirmed earlier than that, tell us and we will handle it individually.

7. Sub-processors

These are the only third parties that can touch personal data held on this platform. Customers on a signed data processing agreement are notified before a sub-processor is added or replaced, and may object.

Sub-processors
ProviderPurposeLocation
IONOS SE Servers, storage and backups — all data at rest Germany
Stripe Payments Europe, Ltd. Subscription billing, card processing, invoices Ireland, with onward transfer to the United States
[ transactional email provider ] Invitations, password resets, download notifications, service email [ EU region — to be confirmed ]

The email provider is a placeholder pending the founder's final choice of relay. No other analytics, advertising, support-chat or tracking provider is used.

8. International transfers

All customer data at rest — the database, the media volume, the backups — is held in Germany and does not leave the European Union in the ordinary course of running the service.

The one routine exception is payment processing. Stripe Payments Europe, Ltd. is established in Ireland and transfers some data onward to its parent in the United States. Those transfers are covered by the European Commission's Standard Contractual Clauses together with Stripe's own transfer safeguards. No project media is ever sent to Stripe — only the billing contact, the amount and the subscription state.

We will not move hosting outside the EU without notifying customers in advance and giving anyone who objects the opportunity to terminate.

9. Your rights

Under the GDPR you have the right to:

  • Access — a copy of the personal data we hold about you, and an explanation of what we do with it.
  • Rectification — correction of anything inaccurate. Most account fields you can edit yourself in the app.
  • Erasure — deletion, where we have no overriding obligation to keep it. Invoices are the usual exception.
  • Restriction — a pause on processing while a dispute about accuracy or legitimate interests is resolved.
  • Portability — your data in a structured, machine-readable format. In practice: a full export of your workspace, which you can also trigger yourself at any time.
  • Objection — to any processing we base on legitimate interests, and at any time and without reason to direct marketing.
  • Withdrawal of consent — where consent was the basis, withdrawable at any time without affecting what was lawful beforehand.

Send requests to privacy@scoutlane.com. We answer within one month and will tell you if we need the extension the regulation allows for a complicated request. We may ask you to confirm your identity first — not to obstruct you, but because handing an account's data to whoever asks would be the very failure this section exists to prevent. Exercising these rights is free.

If your request concerns material inside a customer's workspace — a gallery you were given access to, a photograph of you in a casting folder — we will forward it to that customer, who is the controller, and confirm to you that we have. We do not delete a customer's material on a third party's instruction.

10. Cookies

The only cookies this platform sets are the session cookies that keep you signed in — one for the admin app, one for a client gallery. They are strictly necessary for a service you asked for, which is why there is no consent banner: there is nothing to consent to.

Where the gallery runs embedded inside a customer's own website, third-party cookies do not work and are not used; the embedded session is held by the parent page as a bearer token instead.

There is no analytics cookie, no advertising cookie, no tag manager, no pixel, no session recording and no third-party JavaScript on any page of this site or the product.

11. Security

Passwords are hashed with Argon2id. Session tokens are stored only as a keyed hash. Every query is scoped to one workspace, storage is partitioned per workspace on disk, and media is served through short-lived signed links with Cache-Control: private so no shared cache can retain one client's material. Everything is served over TLS. The measures are described in full, in engineering terms, on the security page.

If a personal data breach occurs we notify the competent supervisory authority within 72 hours where the regulation requires it, and affected customers without undue delay. When we act as processor, we notify the customer without undue delay so that they can meet their own deadline.

12. Children

Scout Lane is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 16. Material uploaded by a customer may depict minors — child casting is ordinary production work — and where it does, the customer is the controller and is responsible for holding the necessary consents.

13. Changes

When this policy changes we update the date at the top of the page. If a change materially affects how we handle personal data, we email account holders at least 30 days before it takes effect. Previous versions are available on request.

14. Complaints

Tell us first — privacy@scoutlane.com — and we will try to put it right. You also have the right to complain to a data protection supervisory authority, either in the EU member state where you live or work, or where the alleged infringement took place.

Placeholder — founder to complete

The lead supervisory authority follows the registered seat of the entity named in section 1.

Lead supervisory authority
[ authority name, address and website ]

Last updated 12 September 2026. See also the terms of service and the data processing agreement.