Legal

Data processing terms

Last updated 23 August 2026

These terms form part of the terms and conditions and apply whenever iScholarX LLC processes personal data on your behalf through ScodyX. They are written to satisfy Article 28 of the GDPR and the equivalent UK GDPR provisions. If your organisation requires a countersigned copy, request one at support@ischolarx.com.

1. Roles

For content you put into your workspace — prompts, project files, data you load into an app you build, and details of the people you invite — you are the controller and we are the processor. For our own account, billing and security records about your use of ScodyX, we are the controller and our privacy notice governs that processing.

2. Scope and instructions

Subject matter: provision of the ScodyX platform. Duration: the term of your subscription, plus the retention periods described below. Nature and purpose: storing, transmitting and generating application code and related records so you can build, preview, deploy and export software. Categories of data subject: your workspace members and any individuals whose data you choose to place in your projects. Categories of personal data: account identifiers and email addresses, plus whatever you include in prompts or project data.

We process personal data only to provide and secure the service, to comply with law, and on your documented instructions — your configuration and use of the product being those instructions. We do not sell personal data and we do not use your workspace content to make decisions about individuals.

3. Confidentiality and personnel

Access is limited to personnel who need it to operate or support the service. Operator access is held in a separate staff register with named roles, is logged, and critical actions require a second authorised approver. Personnel are bound by confidentiality obligations that survive the end of their engagement.

4. Security measures

We apply the technical and organisational measures described in the security overview and mapped in the compliance register, which together form the security annex to these terms. In summary: TLS in transit, provider-managed encryption at rest, row-level tenant isolation enforced in the database, secrets stored write-only and decrypted only server-side, request-identified audit logging, automated isolation and regression testing, and documented incident response. Measures may change as technology changes, but not in a way that materially reduces protection.

5. Subprocessors

You authorise the providers listed in the subprocessor register. Each is engaged under written terms imposing data protection obligations no less protective than these. We remain responsible for their performance. We update the register when a provider changes, and will notify organisations that ask to be on the notification list.

6. International transfers

Where personal data is transferred outside the UK or EEA, the transfer relies on the receiving provider's standard contractual clauses, together with the UK international data transfer addendum where applicable, and on encryption in transit and at rest. If a mechanism we rely on is invalidated, we will work with you on a lawful alternative or, if none is available, on ceasing the affected processing.

7. Assistance with data subject requests

Workspace members can export their data and raise export or deletion requests in the product's data controls page, which tracks the request until it is closed. Where a request reaches us and relates to data you control, we will refer the individual to you and assist you in responding, taking into account the nature of the processing.

8. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your workspace data, with the information available at the time, and will keep you updated as the investigation proceeds. We do not publish a fixed clock shorter than the law requires, because the honest answer depends on the incident.

9. Audit and information

On reasonable written request, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will provide the information needed to demonstrate compliance with these terms: the control register, the results of our automated isolation and regression suites, and answers to a security questionnaire. We do not hold an accredited ISO certification or a SOC 2 report and therefore cannot supply either.

10. Return and deletion

You can export your projects and workspace data at any time while your subscription is active. On termination we delete or de-identify workspace content within a reasonable period after the account closes, other than records we must keep for tax, accounting, fraud prevention or dispute purposes, and encrypted backups which age out on their normal cycle. Unused credits are non-refundable and expire as set out in the refund policy.

11. Not in scope

ScodyX is not designed for special category data at scale, protected health information under HIPAA, cardholder data, or classified government data. We do not offer a Business Associate Agreement. Do not place such data in the platform.