Draft. This policy has not yet been reviewed by a lawyer and must be before launch — read it as a statement of intent, not as final legal wording.
Legal
Privacy policy
Last updated 12 September 2026.
1. Who we are
Scout Lane is a client gallery, review and delivery platform for production companies. This policy explains what we do with personal data, in the sense the General Data Protection Regulation (EU) 2016/679 gives that term.
Placeholder — founder to complete before launch
The controller for the purposes of this policy is the entity named here.
- Legal entity name
- [ legal entity name ]
- Registered address
- [ street, postcode, city, country ]
- Company registration number
- [ registration number and register ]
- VAT number
- [ VAT number ]
- Data protection contact
- [ confirm: privacy@scoutlane.com ]
- Data protection officer
- [ appointed / not required — to be confirmed ]
For anything covered by this policy, write to privacy@scoutlane.com.
2. Controller or processor
Two different relationships run through this platform, and the answer to "who is responsible for this data" is different in each.
We are the controller for the data of the people who buy and administer Scout Lane: the producers and heads of production who hold an account, the people who contact us through the website, and the billing contacts on a subscription. We decide why and how that data is processed.
We are the processor for everything a customer puts into their workspace: the photographs, video, call sheets and casting material they upload, the names of their projects and clients, the gallery logins they create for their clients, and the record of what those clients looked at and liked. The customer is the controller for all of it. We process it on their documented instructions, which are the actions they take in the product plus the data processing agreement.
If you were given a login to look at a gallery and you want to know what is held about you, the production company that invited you is the controller and is the right first contact. Write to us anyway if you cannot reach them and we will pass the request on and tell you we have.
3. Data we hold as controller
| Category | What it contains | Where it comes from |
|---|---|---|
| Account | Name, work email address, role in the workspace, an Argon2id hash of the password, invitation and password-reset tokens | You, or a colleague who invited you |
| Sessions | A keyed hash of each session token, creation and last-seen time, device class, browser user agent | Generated when you sign in |
| Workspace | Company name, plan, subscription status, logo and accent colour, contact email | You |
| Billing | Billing name and address, VAT number, invoices, payment status. Card details are held by our payment processor and never by us | You, and our payment processor |
| Enquiries | Email address, company, country and message from the contact form, plus a salted hash of the sending IP address, the browser user agent and the referring page | You, when you use the contact form |
| Support correspondence | Emails you send us and our replies | You |
| Server logs | Web server access logs, which include the connecting IP address, the requested path and a timestamp | Generated automatically |
| Audit log | Administrative actions inside a workspace — who invited whom, who deleted what | Generated by the product |
We do not buy contact lists, we do not enrich your record from third-party data brokers, and we do not profile you. There is no automated decision-making that produces legal or similarly significant effects.
4. Data we hold as processor
On behalf of our customers, and only on their instructions, the platform holds:
- Uploaded material — stills, video, PDFs and the derivatives generated from them. Photographs of identifiable people are personal data, and on this platform they are frequently the whole point: casting portraits, crew stills, scouting images with passers-by in frame.
- Project metadata — project, client, category and folder names, notes and file names.
- Gallery logins — the username, display name, password hash, permissions and expiry of each client login the customer creates.
- Viewing records — when a gallery session started, how long it lasted, which images were opened, liked, annotated or downloaded, a coarse device class, the browser user agent, and a salted hash of the viewer's IP address rather than the address itself.
The salted hash is deliberate. Counting sessions requires knowing whether two visits came from the same place; it does not require knowing where that place is. The hash supports the first and cannot answer the second, so no raw viewer IP address is written to the database at any point.
We do not use this material for our own purposes. We do not train machine learning models on it, we do not scan it for content beyond generating thumbnails and poster frames, and we do not disclose it to anyone except the sub-processors listed below and where the law compels us.
5. Lawful bases
| Purpose | Basis |
|---|---|
| Giving you an account and running the service you subscribed to | Performance of a contract — Art. 6(1)(b) |
| Answering an enquiry sent through the contact form | Steps taken at your request before entering a contract — Art. 6(1)(b), and our legitimate interest in responding to business enquiries — Art. 6(1)(f) |
| Taking payment, issuing invoices, keeping accounting records | Contract — Art. 6(1)(b) — and legal obligation — Art. 6(1)(c) |
| Rate limiting, login throttling, abuse detection, fraud prevention, server logs | Legitimate interests — Art. 6(1)(f): keeping the service available and other people's material private |
| Service email you cannot opt out of — security notices, breach notifications, changes to these terms, billing failures | Contract — Art. 6(1)(b) — and legal obligation — Art. 6(1)(c) |
| Marketing email about the product | Consent — Art. 6(1)(a) — withdrawable at any time, or Art. 6(1)(f) for existing customers about a directly comparable service, with an unsubscribe link in every message |
| Processing a customer's project material and their clients' viewing records | We act as processor on the customer's instructions — Art. 28. The customer determines the lawful basis |
Where we rely on legitimate interests we have weighed those interests against your rights and freedoms, and you can object at any time — see section 9.
6. How long we keep it
| Data | Kept for |
|---|---|
| Account and workspace records | While the subscription is live, then 30 days after it closes |
| Uploaded material and project metadata | Until the customer deletes it. On closure of a workspace, 30 days for export, then the storage subtree is purged |
| Gallery logins | Until deleted or expired by the customer; removed with the project |
| Viewing records and analytics events | 24 months, then deleted |
| Sessions | Until they expire — one hour for a staff access token, 30 days for a refresh token, 14 days for a gallery session — or until revoked |
| Web server access logs | 14 days |
| Audit log | 12 months |
| Contact form enquiries | 24 months from the last exchange, unless the enquiry became a subscription |
| Invoices and accounting records | As long as tax and commercial law requires, typically up to ten years |
| Backups | Rolling 30 days, after which the backup containing the data expires |
Deleting something in the product removes it from every view immediately and queues the bytes for removal from disk. It remains in the encrypted backups until those backups age out, which is the honest description of what "deleted" means for any system that keeps backups at all. If you need a deletion confirmed earlier than that, tell us and we will handle it individually.
7. Sub-processors
These are the only third parties that can touch personal data held on this platform. Customers on a signed data processing agreement are notified before a sub-processor is added or replaced, and may object.
| Provider | Purpose | Location |
|---|---|---|
| IONOS SE | Servers, storage and backups — all data at rest | Germany |
| Stripe Payments Europe, Ltd. | Subscription billing, card processing, invoices | Ireland, with onward transfer to the United States |
| [ transactional email provider ] | Invitations, password resets, download notifications, service email | [ EU region — to be confirmed ] |
The email provider is a placeholder pending the founder's final choice of relay. No other analytics, advertising, support-chat or tracking provider is used.
8. International transfers
All customer data at rest — the database, the media volume, the backups — is held in Germany and does not leave the European Union in the ordinary course of running the service.
The one routine exception is payment processing. Stripe Payments Europe, Ltd. is established in Ireland and transfers some data onward to its parent in the United States. Those transfers are covered by the European Commission's Standard Contractual Clauses together with Stripe's own transfer safeguards. No project media is ever sent to Stripe — only the billing contact, the amount and the subscription state.
We will not move hosting outside the EU without notifying customers in advance and giving anyone who objects the opportunity to terminate.
9. Your rights
Under the GDPR you have the right to:
- Access — a copy of the personal data we hold about you, and an explanation of what we do with it.
- Rectification — correction of anything inaccurate. Most account fields you can edit yourself in the app.
- Erasure — deletion, where we have no overriding obligation to keep it. Invoices are the usual exception.
- Restriction — a pause on processing while a dispute about accuracy or legitimate interests is resolved.
- Portability — your data in a structured, machine-readable format. In practice: a full export of your workspace, which you can also trigger yourself at any time.
- Objection — to any processing we base on legitimate interests, and at any time and without reason to direct marketing.
- Withdrawal of consent — where consent was the basis, withdrawable at any time without affecting what was lawful beforehand.
Send requests to privacy@scoutlane.com. We answer within one month and will tell you if we need the extension the regulation allows for a complicated request. We may ask you to confirm your identity first — not to obstruct you, but because handing an account's data to whoever asks would be the very failure this section exists to prevent. Exercising these rights is free.
If your request concerns material inside a customer's workspace — a gallery you were given access to, a photograph of you in a casting folder — we will forward it to that customer, who is the controller, and confirm to you that we have. We do not delete a customer's material on a third party's instruction.
11. Security
Passwords are hashed with Argon2id. Session tokens are stored only as a keyed hash.
Every query is scoped to one workspace, storage is partitioned per workspace on disk,
and media is served through short-lived signed links with
Cache-Control: private so no shared cache can retain one client's material.
Everything is served over TLS. The measures are described in full, in engineering terms,
on the security page.
If a personal data breach occurs we notify the competent supervisory authority within 72 hours where the regulation requires it, and affected customers without undue delay. When we act as processor, we notify the customer without undue delay so that they can meet their own deadline.
12. Children
Scout Lane is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 16. Material uploaded by a customer may depict minors — child casting is ordinary production work — and where it does, the customer is the controller and is responsible for holding the necessary consents.
13. Changes
When this policy changes we update the date at the top of the page. If a change materially affects how we handle personal data, we email account holders at least 30 days before it takes effect. Previous versions are available on request.
14. Complaints
Tell us first — privacy@scoutlane.com — and we will try to put it right. You also have the right to complain to a data protection supervisory authority, either in the EU member state where you live or work, or where the alleged infringement took place.
Placeholder — founder to complete
The lead supervisory authority follows the registered seat of the entity named in section 1.
- Lead supervisory authority
- [ authority name, address and website ]
Last updated 12 September 2026. See also the terms of service and the data processing agreement.