Scoutiv
FeaturesHow it worksCompliancePricingAbout
FeaturesHow it worksCompliancePricingAbout
Compliance

GDPR Policy

Last updated: 6 March 2026 ยท Mahl Technologies Ltd

Summary: If you are located in the EU or EEA, or if you send emails to EU or EEA residents using Scoutiv, this policy applies to you. Contact [email protected] for any GDPR-related data requests. We respond within 30 days.

1. Overview

The General Data Protection Regulation (GDPR) is a European Union law that governs the collection, processing, and storage of personal data about individuals in the EU and European Economic Area (EEA). This policy explains how Scoutiv and Mahl Technologies Ltd relate to GDPR, both as a data processor and as a data controller.

2. Scoutiv as Data Controller

When you create a Scoutiv account, Mahl Technologies Ltd acts as the data controller for your personal data โ€” your name, email address, sender account connection data, and platform usage data. We determine how and why your data is processed. Our Privacy Policy provides full details of this processing.

3. Scoutiv as Data Processor

When you use Scoutiv to send emails to your own contact list, Mahl Technologies Ltd acts as your data processor. You are the data controller for your recipients' personal data. You determine who receives emails, what those emails contain, and for what purpose. We process that data only on your instructions to deliver your campaigns.

As your data processor, we:

  • Process recipient data only to deliver the campaigns you create and initiate
  • Do not use your recipients' data for our own marketing or profiling purposes
  • Maintain suppression lists as required by applicable law
  • Delete recipient data upon your account deletion (within 30 days), except suppression list data required for compliance

If you are based in the EU or regularly sending to EU/EEA residents at scale, you may wish to enter into a Data Processing Agreement (DPA) with Mahl Technologies. Contact [email protected] to request one.

4. Legal Bases for Processing Your Data

We process your personal data under the following legal bases as defined in GDPR Article 6:

  • Contract performance (Article 6(1)(b)): Processing your account information, sender account connection data, and campaign data is necessary to deliver the Scoutiv service you have subscribed to.
  • Legitimate interests (Article 6(1)(f)): We process server logs and usage data to maintain platform security, detect abuse, and improve the platform. These interests are balanced against your rights โ€” we process only what is necessary and do not use this data for profiling or advertising.
  • Legal obligation (Article 6(1)(c)): We retain suppression lists indefinitely as required to comply with email law obligations. We may retain certain data as required by applicable law.
  • Consent (Article 6(1)(a)): If we send you optional product update emails or marketing communications, this is based on your explicit opt-in. You can withdraw consent at any time.

5. Your Rights Under GDPR

If you are located in the EU or EEA, you have the following rights with respect to your personal data:

  • Right of access (Article 15): You may request a full copy of all personal data we hold about you.
  • Right to rectification (Article 16): You may correct any inaccurate personal data we hold about you. Most account information can be updated directly in your account settings.
  • Right to erasure (Article 17): You may request deletion of your account and personal data. We will complete deletion within 30 days, except where we have a legal obligation to retain certain data (such as suppression list entries).
  • Right to restriction of processing (Article 18): In certain circumstances, you may request that we restrict how we process your data while a dispute is being resolved.
  • Right to data portability (Article 20): You may request your personal data in a structured, commonly used, machine-readable format (such as CSV or JSON) to transfer to another service.
  • Right to object (Article 21): You may object to processing based on our legitimate interests. We will honor this unless we have compelling legitimate grounds that override your interests.
  • Right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, email [email protected] with the subject line "GDPR Data Request" and specify the right you are exercising. We respond within 30 days. We may need to verify your identity before fulfilling your request.

6. Your Obligations When Emailing EU/EEA Residents

If you use Scoutiv to send emails to individuals located in the EU or EEA, you are the data controller for those individuals' personal data. Under GDPR, you must:

  • Have a valid legal basis for processing each recipient's email address. For most email marketing, this requires explicit prior consent (opt-in). Legitimate interest is a narrow legal basis that requires a balancing test and is difficult to rely on for cold email marketing.
  • Be able to demonstrate consent if requested โ€” maintain records of when and how consent was obtained
  • Provide recipients with information about how their data is used
  • Honor data subject rights requests from recipients, including access and deletion
  • Not transfer recipients' personal data to countries outside the EU/EEA without appropriate safeguards โ€” when you upload a contact list to Scoutiv, that data is processed on our servers

Scoutiv enforces unsubscribe compliance automatically. However, GDPR's consent requirements before sending are your responsibility. Scoutiv is not able to verify that you had valid consent to email the addresses on your list.

7. International Data Transfers

Mahl Technologies Ltd is based in Nigeria. If you are in the EU/EEA, your personal data is transferred to Nigeria for processing. Nigeria does not currently have a European Commission adequacy decision.

We implement the following safeguards for international transfers:

  • AES-256 encryption for all data in transit (HTTPS/TLS) and at rest (sensitive connection data and passwords)
  • Access controls limiting who can access production data
  • Data minimization โ€” we collect and store only what is necessary to provide the service

If you have concerns about international data transfers and would like to discuss appropriate safeguards, contact [email protected].

8. Data Retention

We retain your personal data for as long as your account is active. On account deletion, personal data is deleted within 30 days. Suppression list entries are retained indefinitely for compliance purposes. Server logs are retained for up to 90 days.

9. Contact and Complaints

For all GDPR-related requests and questions:

  • Email: [email protected]
  • Subject: GDPR Data Request
  • Company: Mahl Technologies Ltd

If you are not satisfied with our response to a GDPR request, you have the right to lodge a complaint with your local data protection supervisory authority.

Scoutiv

Outreach software for sending personalized campaigns through Google, Outlook, or custom SMTP accounts, with reply tracking and unsubscribe compliance built in.

Product
  • Features
  • Pricing
  • How it works
  • Compliance
Company
  • About Us
  • Contact
Legal
  • Privacy Policy
  • Terms of Service
  • CAN-SPAM Policy
  • GDPR
  • Unsubscribe
Scoutiv uses connected email account data only to provide user-requested sending, reply tracking, compliance, and account security features. We do not sell customer data, use message content for advertising, or train models on customer campaign content.

ยฉ 2026 Scoutiv ยท Mahl Technologies Ltd, Lagos, Nigeria. All rights reserved.

PrivacyTermsUnsubscribeContact