Skip to content

Privacy Policy

The stored previous version of this policy is empty, so the diff shows the entire Scaleway Privacy Policy as newly added. Nothing can be compared: it is not possible to tell from this diff whether Scaleway changed anything, or whether the earlier capture simply failed. The cause is unknown. What can be reported is what the policy now says on record. It is a fairly standard GDPR policy: Scaleway says it does not resell personal data, and it lists in detail why it uses your data, who receives it, and how long it keeps it. A few items are worth knowing about: face-scan (biometric) checks may be used for identity verification on certain services, abuse reports can be handled by automated decision-making, some records are kept for 10 years, your data can move to a new owner if the company is sold, and some data can go outside the EU. None of these is shown to be new — they are simply the first version of this text on record.

Face-scan identity checks for some servicesScaleway may run facial recognition or similar technology on a photo, video or voice…

Scaleway may run facial recognition or similar technology on a photo, video or voice recording to verify your identity on certain services. Biometrics are sensitive because, unlike a password, you cannot change your face. Note: because the earlier snapshot is empty, there is no way to tell from this diff whether this is new or has been in the policy for a long time.

“Biometric data collected from an image, video or audio recording via facial recognition technology or similar technology for the provision of certain Services”

What you can do — If you are asked for a face or video identity check, ask Scaleway (privacy@scaleway.com) whether a manual document check is available instead, and how long the biometric record is held.

DATA COLLECTION
Abuse complaints can be decided automaticallyReports of spam, malware, copyright problems or offensive content may be processed by…

Reports of spam, malware, copyright problems or offensive content may be processed by automated systems rather than reviewed by a person. An automated flag against your account can affect your service, so it matters that you can ask for a human to look at it. This is not shown to be a new provision — there is no earlier text to compare with.

“These data processings are likely to be subject to automated decision-making (e.g. anti-spam control)”

What you can do — If an automated abuse decision affects your account, you can demand human review under GDPR Article 22 — email privacy@scaleway.com or raise it in the console.

OTHER
Some records kept for 10 yearsAbuse tickets are held for 10 years after they close, billing records for 10 years after…

Abuse tickets are held for 10 years after they close, billing records for 10 years after the contract ends, and litigation files are archived for 10 years. Even after you close your account, some of your information stays on file for a long time. Accounting retention is normally required by law; the 10-year abuse-ticket period is longer than many providers use. Again, this diff cannot show whether these periods changed.

“10 years from the closure of the ticket concerned”

What you can do — When closing your account, ask Scaleway in writing which of your records will be kept and for how long.

DATA RETENTION
Your data goes with the business if it is soldIf Scaleway is bought or merges with another company, your personal data can be handed to…

If Scaleway is bought or merges with another company, your personal data can be handed to the new owner. That new owner may run things differently. This is a common clause, but you have no say in it under the policy as written.

“In the event of a business transfer (included merger or acquisition of the company);”
DATA SHARING
Some data can be sent outside the EUScaleway says it keeps transfers outside the EU to a minimum and uses the EU's Standard…

Scaleway says it keeps transfers outside the EU to a minimum and uses the EU's Standard Contractual Clauses to protect them. Still, data that leaves the EU can be exposed to laws that give you less protection than the GDPR.

“The processed data may be transferred to a third country under the conditions of protection mechanisms compliant with the GDPR (including: Standard contractual clauses and appropriate security measures).”
DATA SHARING
Policy updates apply the day they are postedScaleway can change this privacy policy at any time, and the new version applies as soon…

Scaleway can change this privacy policy at any time, and the new version applies as soon as it goes on the website. You are not promised any advance warning, so you would have to check the page yourself to notice a change.

“Any changes will take effect from the date of publication.”

What you can do — Check the "Last update" date on the policy page from time to time if these terms matter to you.

UNILATERAL CHANGES
20260101_rev01 → 20260811_rev01COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
1## Overview
2
3SCALEWAY attaches great importance to compliance with regulations relating to the protection of personal data and in particular the General Data Protection Regulation (EU Regulation 2016/679 of the European Parliament known as "GDPR") and the data processing and freedom law (law no. 78-17 of January 6, 1978 relating to data processing, files and freedoms).
4
5In this context, this Privacy Policy will help you to understand what personal data concerning you is collected by Scaleway and what it is intended for.
6
7## Scope
8
9This privacy policy is intended to govern the processing carried out by Scaleway as data controller (Scaleway, 8 RUE DE LA VILLE L'EVÊQUE 75008 PARIS 8), in particular the data collected in the context of:
10
11- the management of your customer account
12- the management of marketing communications or prospection
13- the use of one of our websites (not already covered by a specific privacy policy)
14- the recruitment management
15- the compliance with our legal obligations
16- the guarantee of legitimate interests
17
18The data collected for the operation of our services, where Scaleway acts as a processor, is governed by our [General Conditions of Services](https://www.scaleway.com/en/contracts/) as well as our [Data Processing Agreement (DPA).](https://www.scaleway.com/en/contracts/)
19
20## What kind of personal data is processed ?
21
22Scaleway is required to process the following categories of data:
23
24- Data relating to identity: Name, surname, postal address, email, telephone number, customer number, signature, proof of identity.
25- Billing data: bank details, terms of payment, invoices, etc.
26- Consumption data: history of services and products used, event logs etc.
27- Communication data: mails, emails, telephone number, history of exchanges with Scaleway, complaints, support tickets, etc.
28- Connection data: IP address, user ID, location data, connection and event logs etc.
29
30The categories of data used are indicated in each of the treatments in the following section. Any reference to "user account data" includes all account data.
31
32## What data do we share?
33
34Scaleway does not resell any personal data of its customers or contacts. We only share data as part of operations related to your contract, to meet a legal obligation, or in the company's legitimate interest in the following cases:
+ ADDEDScaleway says it does not sell personal data

The policy states plainly that customer and contact data is not resold. Sharing is limited to running the service, meeting legal duties, or the company's stated legitimate interests.

35
36- Transfer of data to a sub-processor or partner for the performance of the service;
37- In the event of a business transfer (included merger or acquisition of the company);
+ ADDEDYour data can transfer if the company is sold

If Scaleway is merged into or bought by another company, your personal data can be passed to the new owner.

38- To comply with our legal obligations (e.g., sharing data at the request of an authorized public body to identify fraud or as part of a criminal investigation);
39- To ensure the security of our services and infrastructure (e.g. sharing data with security-related service providers).
40
41## How do we use your data ?
42
43Contracts management and customer relations
44
45Scaleway processes your data in order to manage contracts for the services you use. This includes the management of accounts, support and payment methods.
46
47| Purposes | Categories of data | Legal basis | Retention | Categories of recipients |
48| --- | --- | --- | --- | --- |
49| Management of contracts and customer relations (management of accounts, support and means of payment) | Identity data
50Billing data
51Consumption data
52Communication data
53Connection data | Execution of the contract
54Legal obligation (invoicing, accounting records, compliance)
55Legitimate interest (security, fraud prevention) | Duration of the contractual relationship plus an archiving period to meet our legal obligations and guarantee the defense of our legitimate interest | Scaleway Services
56Entitled Scaleway Partners for support and payment management
57Authorized third parties\* |
58| Management of contracts with our partners (service providers and suppliers) | Identity data
59Commercial relationship monitoring data (activity reports and, communications) | Execution of the contract
60Legal obligation (invoicing, accounting records, compliance) | Duration of the contractual relationship | Scaleway Services
61Entitled Scaleway Partner for the management of suppliers
62Authorized third parties |
63
64\*Means any public authority or administration authorized by a text to receive personal information
65
66Communication and Marketing
67
68Scaleway processes certain data in order to send its service offers to its customers or prospects, guests for events or even collect their opinions on products (processing may involve profiling techniques). These processing operations may be based either on legitimate interest, if the person is already a customer of the company, particularly if the proposals concern products or services similar to those already subscribed, or on consent. Scaleway mainly collects this data directly but can also obtain it indirectly via specialized data processors in conformity with all applicable legal requirements.
69
70| Purposes | Categories of data | Legal basis | Retention | Categories of recipients |
71| --- | --- | --- | --- | --- |
72| Commercial prospecting and communication campaigns relating to our products and services | Identity data
73Billing data
74Consumption data
75Communication data
76Connection data | Legitimate interest
77Consent | Duration of the contractual relationship
78Account deletion request
79Prospects : deletion after 3 years of inactivity from the last contact | Scaleway Sales and Marketing Teams
80Entitled Scaleway Partners for the management of marketing campaigns and customer relation
81Authorized third parties |
82| Organization of events to promote our services | Identity data
83Communication data
84Connection data
85Data relating to the professional background of the speakers | Legitimate interest
86Consent | Duration of the contractual relationship
87Account deletion request
88Prospects : deletion after 3 years of inactivity from the last contact | Scaleway teams involved in the event
89Entitled Scaleway Partners for the management of events
90Scaleway service concerned by the event
91Authorized third parties |
92| Management of third-party cookies from our websites ([learn more about our cookie policy](https://www.scaleway.com/en/cookie/)) | Connection data | Consent | Cookies are stored between 3 months and 1 year depending on the type of cookie used | Scaleway Sales and Marketing Teams
93Entitled Scaleway Partners for the cookies management
94Authorized third parties |
95| Tracking email opens and clicks for our marketing emails via a tracking pixel.
96These trackers can also be used to provide proof that a contact is active or has opened an email | Contact identifier or unique identifier associated with the pixel
97Communication data (email)
98Click data (link clicks)
99Connection data (IP address) | Legitimate interest
100Consent | Duration of the contractual relationship
101Contact activity period | Scaleway Sales and Marketing teams
102Scaleway partners for marketing analytics management
103Authorized third parties |
104| Carrying out satisfaction surveys or quality surveys on our services and the training of our teams | Identity data
105Billing data
106Consumption data
107Communication data
108Connection data
109Audio or video recording | Legitimate interest
110Consent | 1 year and anonymization | Scaleway Sales and Marketing Teams
111Entitled Scaleway Partners for marketing analysis
112Authorized third parties |
113| Produce usage statistics | Connection data | Legitimate interest | Cookies: between 3 months and 1 year
114Service usage data kept during the contractual period or anonymized | Scaleway Sales and Marketing Teams
115Entitled Scaleway Partners for quality analysis
116Authorized third parties |
117
118Recruitment and application management
119
120Scaleway also processes the personal data of candidates as part of its recruitment procedure.
121
122| Purposes | Categories of data | Legal basis | Retention | Categories of recipients |
123| --- | --- | --- | --- | --- |
124| Recruitment | Identity data
125Communication Data
126Professional Data (Curriculum vitae, salary position, and specifics of the contract)
127 | Execution of contract or pre-contractual measures
128 | If the application is not accepted, the data is kept for a maximum period of 2 years
129If the application is accepted, the data is kept for the entire duration of the contract, accompanied by an archiving period intended to comply with our legal obligations or guarantee the legitimate interests of the company. | Human resources services
130Manager and team concerned
131Scaleway partners for human resources
132Authorized third parties |
133
134Legal obligations
135
136Scaleway processes some of your data in order to meet its legal obligations. This is particularly the case in order to secure our services as a provider of electronic communications services, to meet our accounting and tax obligations or to process your requests for rights relating to data protection.
137
138| Purposes | Categories of data | Legal basis | Retention | Categories of recipients |
139| --- | --- | --- | --- | --- |
140| Guarantee the security of our customers as a provider of electronic communications services (Directive 2002/58/EC and art 32 of the GDPR) in particular to prevent fraud and identity theft. The processed data may be transferred to a third country under the conditions of protection mechanisms compliant with the GDPR (including: Standard contractual clauses and appropriate security measures).
+ ADDEDSome data can leave the EU

Scaleway says it tries to keep transfers outside the EU to a minimum, and that any such transfer is covered by the EU's Standard Contractual Clauses. Security and anti-fraud data is specifically named as something that may go to a country outside the EU.

141 | Customer account data
142Photographs and visual or audio recordings
143Biometric data collected from an image, video or audio recording via facial recognition technology or similar technology for the provision of certain Services | Legal obligation | Duration of the contractual relationship plus an archiving period for the data necessary to guarantee compliance with our legal obligations
+ ADDEDFace-scan checks possible for identity verification

For some services, Scaleway may use facial recognition or similar technology on a photo, video or audio recording to confirm who you are and prevent fraud. It says this data is kept only as long as needed for the check, then archived to meet legal rules and later deleted.

144The data used for KYC checks is retained only for the time strictly necessary to verify identity, after which it is archived to comply with applicable legal requirements or those of the relevant service provider, and subsequently deleted. | Entitled Scaleway Services
145Entitled Scaleway Partners for security management or KYC checks
146Authorized third parties (auditors etc.) |
147| Abuse of Scaleway services includes cyber-crime, copyright violation, illegal or offensive content, spamming and malware distribution. Abuse should be reported in the console. These data processings are likely to be subject to automated decision-making (e.g. anti-spam control) | Identity data
+ ADDEDAbuse reports may be decided by automated systems

Complaints about things like spam, malware or illegal content can be handled by automated decision-making rather than by a person reviewing each case.

148User account information | Legal obligation | 10 years from the closure of the ticket concerned
+ ADDEDLong record-keeping periods for some categories

Abuse tickets are kept for 10 years after the ticket closes, billing records for 10 years after the contract ends, and litigation records are archived for 10 years. Security and fraud records are kept for 5 years.

149 | Entitled Scaleway Services
150Entitled Scaleway Partners for the ticketing and support management
151Authorized third parties |
152| Responses to the data protection requests and any complaints related to the protection of personal data | Identity data (including proof of identity)
153User account information
154ll the data related to the complaint | Legal obligation | 5 years from ticket closing
155Verification of identity card: 1 month | Entitled Scaleway Services
156Entitled Scaleway Partner for the management of subject requests
157Authorized third parties
158Entitled Iliad service |
159| Data breaches management | Identity data
160User account information related to the data breach
161All data related to the data breach | Legal obligation | 5 years from the closure of the data breach | Entitled Scaleway Services
162Competent administrative authority |
163| Accounting obligations | Billing data | Legal obligation | 10 years from the end of the contract | Entitled Scaleway Services
164Entitled Scaleway Partner for the management of payments and invoices
165Competent administrative authority |
166| Legal or administrative procedure management | Identity data
167User account information related to the case | Legal obligation | The necessary data is kept until the expiration of the legal remedies | Scaleway Legal Department
168Iliad Legal Department
169Competent administrative authority
170Entitled third parties (legal advisor etc.) |
171| Compliance with legal and regulatory obligations applicable to registrars (including ICANN). | Identification data
172Customer account dataw
173Billing data
174Technical data related to domain management | Legal obligation | The duration of the contractual relationship includes a necessary archiving period to ensure compliance with our legal obligations. | Domain Teams
175Payment providers
176Support tools
177Resellers
178Authorized Third Parties |
179
180Legitimate interest
181
182Scaleway processes some of your data in order to meet a legitimate interest. This is particularly the case in order to secure our services, ensure the management of unpaid debts and the training of our teams (processing relating to security or fraud may involve profiling techniques).
183
184| Purposes | Categories of data | Legal basis | Retention | Categories of recipients |
185| --- | --- | --- | --- | --- |
186| Guarantee the security of services we offer | Identity data
187User account information | Legitimate interest | 5 years from the end of the contract
188 | Scaleway IT security service
189Competent administrative authority |
190| Debt collection | Identity data
191User account information | Legitimate interest | 5 years from the payment incident
192 | Scaleway Legal and Accounting Services
193Entitled Scaleway Partner for debt collection |
194| Fraud detection and prevention | Bank details
195Identity data
196User account information | Legitimate interest | 5 years maximum from the suspicion of an incident
197ID card verification: 1 month | Entitled Scaleway service
198Entitled Scaleway Partner for support and ticketing |
199| Anti-spam policy | Email addresses
200Spam content | Legitimate interest | The reporter's data is deleted immediately after reporting | Service provider concerned |
201| Litigation management | Identity data
202Data necessary for the purposes of establishing evidence | Legitimate interest | The data is kept until the expiration of the legal remedies and archived for 10 years | Scaleway legal department
203Entitled Scaleway partner |
204| Ensure the training of our teams | Identity data
205User account information | Legitimate interest | The data is kept during the contractual period | Entitled Scaleway service |
206
207## Sub-processing
208
209As a data controller, Scaleway uses data processors for the following purposes:
210
211- customer relationship management (support management, etc.)
212- carrying out emailing campaigns and surveys on the services
213- partnership management with other cloud providers
214- meeting our legal obligations (accounting, data protection etc.)
215- marketing data analysis
216- website data analysis
217- management of payment services
218- consulting or audit firms
219- the organization of events
220- security and identity control
221
222Scaleway selects its data processors through a strict security control procedure to ensure that they only process data for the purposes for which they have been chosen. Scaleway also ensures that its data processors have technical and organizational security measures in accordance with the regulations relating to the protection of personal data.
223
224## Transfer of data outside the European Union
225
226Scaleway strives to minimize data transfers outside the European Union and only carries out such transfers as data controller for the purposes listed above. Data transferred as part of our services is governed by our [Data Processing Agreement (DPA)](https://www.scaleway.com/en/contracts/)
227
228All transfers outside the European Union are subject to a strict control to ensure that the contracts entered into with our service providers comply with the Standard Contractual Clauses (SCC) updated by the implementing decision ( EU) 2021/914 of the Commission of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries under Regulation (EU) 2016/679 of the European Parliament and of the Council (Text presenting interest for the EEA) and where possible, to supplement these clauses
229
230## Requests from authorities
231
232Scaleway may receive direct (administrative or judicial authorities) or indirect (lawyers, bailiffs, notaries, etc.) requests from competent authorities to transmit certain data relating to its customers.
233
234In this case, and to the extent that Scaleway is legally entitled to do so, Scaleway may inform its customers in advance in order to enable them to assert their rights subject to compliance with applicable regulations. Scaleway cannot oppose such a request if it complies with French or European regulations, an international agreement (art. 48 of the GDPR) or with one of the exemptions provided for in art. 49 of the GDPR.
235
236## Children
237
238Scaleway does not provide services to children. Any children wishing to use our services must be accompanied and under the responsibility of an adult.
239
240## Link to our partners
241
242Our sites may contain links to our partners. We inform you that these links refer directly to the sites of these partners who have their own confidentiality policy for which Scaleway cannot be held responsible.
243
244## Data Security
245
246Scaleway implements technical and organizational security measures to guarantee the constant confidentiality, integrity, availability and resilience of its information systems and services. These measures meet the state of the art and are adapted to the type of data concerned. All of our staff are aware of IT security and data protection issues.
247
248Our security measures specifically meet data protection regulations and in particular the following points:
249
250- Information systems security policy (ISSP)
251- Physical protection measures for all of our data centers
252- Secure authentication of user accounts
253- Logging
254- Security Information and Event Management (SIEM)
255- Incident management procedure
256- Secure management procedure for data processors
257- Procedure for handling data breaches
258- Secure data backup
259- Anonymization of data when personal data is no longer necessary for processing in order to produce statistics or improve our services or marketing communication
260
261In accordance with our general conditions of service, we remind you that the customer is solely responsible for the management and security of its content as well as the environments and systems that it deploys on the infrastructures made available to it as part of the services offered by Scaleway. It is also up to the customer to make any backups of their content (or other means aimed at ensuring their longevity) that he considers necessary in order to protect against possible deletion, alteration or modification of said content.
262
263For more information regarding all of our security measures, you can consult our [Security and Resilience page.](https://www.scaleway.com/en/security-and-resilience/)
264
265For more information about all our security measures, please visit the following pages:
266
267- Scaleway: [Security and Resilience](https://www.scaleway.com/en/security-and-resilience/)
268- [Scaleway Trust Center](https://security.scaleway.com/)
269- Contract page: [Technical and Organizational Security Measures](https://www.scaleway.com/en/contracts/) (TOMs)
270
271If you have identified a vulnerability or would like to send us a security question, please send it to us at: [security@scaleway.com](mailto:security@scaleway.com)
272
273## Data subjects rights & contact
274
275Scaleway informs you that you have the following rights depending on the purpose of processing:
276
277- Be informed why we process your personal information
278- Access your data and obtain a copy of the personal data we process about you
279- Rectify incorrect, incomplete or outdated data
280- Limit the use of your data
281- Oppose the processing of your data if it is processed on the basis of legitimate interest
282- Withdraw your consent at any time if the processing is based on this legal basis
283- Delete data that is no longer necessary for processing or to meet a legal obligation
284- Exercise your right to portability
285
286You can exercise your rights directly in the privacy section of your Scaleway account or contact our DPO via the following address : via [privacy@scaleway.com](mailto:privacy@scaleway.com). If you believe that your rights have not been respected, you can also file a complaint [with the competent supervisory authority](https://www.edpb.europa.eu/about-edpb/about-edpb/members_fr).
+ ADDEDYour GDPR rights and how to use them

The policy lists your rights — access, correction, deletion, portability, objecting to legitimate-interest processing, and withdrawing consent — and says you can act on them in the privacy section of your account or by emailing the data protection officer.

287
288## Policy update
289
290This privacy policy may be updated to reflect changes in regulations or services offered by Scaleway, as well as to improve the transparency of our practices. Any changes will take effect from the date of publication.
+ ADDEDPolicy changes take effect when published

Scaleway can update this policy, and updates apply from the day they are posted. No advance notice to users is promised.

291
292Last update : June 2026
+ ADDEDDocument dated June 2026

The version now on record is stamped June 2026. There is no earlier text in this diff, so nothing here shows whether the previous version carried a different date.

ALSO IN THIS CHANGE, NOT TIED TO ONE LINE

  1. + ADDEDNo previous text to compare against

    The stored earlier version of this document contains no text at all, so the whole policy appears as new. This does not tell us that Scaleway rewrote anything. It only tells us the earlier snapshot was empty. Why it was empty — a failed capture, or a genuine first publication — cannot be determined from this diff. Everything below describes what the policy says now, not what changed.