Privacy Policy
Stalwart Blue (“we”, “us”, or “our”)
Last updated: 21 August 2026
1. Introduction
At Stalwart Blue, we respect your privacy and are committed to protecting your personal data. This Privacy Policy details how we collect, process, and safeguard your information when you visit our website, engage our services, or use our proprietary platforms ScaleBridge, OptiCap and StraOps.
This document outlines your privacy rights and how the law protects you. We encourage you to read this policy carefully to understand our practices regarding your personal data.
2. The Data We Collect About You
Personal data means any information about an individual from which that person can be identified. We may collect, use, store, and transfer different kinds of personal data, which we have grouped together as follows:
- Identity Data: First name, last name, username, title, and professional affiliation.
- Contact Data: Billing address, business email address, and telephone numbers.
- Financial Data: Asset details, capital structures, bank account details, and payment card information.
- Transaction Data: Details about payments to and from you, alongside other details of products and services you have purchased from us.
- Technical Data: Internet protocol (IP) address, your login data, browser type and version, time zone setting and location, and operating system used to access our platforms.
- Usage Data: Information about how you use our website, products, and services.
- Marketing and Communications Data: Your preferences in receiving marketing from us and your communication preferences.
- Connected Mailbox Data: The email address of a mail account you choose to connect to one of our platforms, the display name associated with it, and the encrypted authorisation token that permits us to send messages from that account on your behalf. It also includes the messages you compose and send through our platforms, and a record of when each was sent. It does not include the contents of your inbox, which we have no permission to access.
3. How We Collect Your Data
We use different methods to collect data from and about you, including:
- Direct Interactions: You may give us your Identity, Contact, and Financial Data by filling in forms or by corresponding with us by post, phone, email, or otherwise. This includes data you provide when you subscribe to our services, use ScaleBridge, OptiCap or StraOps, or request marketing material.
- Automated Technologies: As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions, and patterns. We collect this personal data by using cookies, server logs, and other similar technologies.
- Third Parties or Publicly Available Sources: We may receive personal data about you from various third parties and public sources, such as analytics providers, search information providers, and publicly available corporate registries.
4. How We Use Your Data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Performance of a Contract: Where we need to perform the contract we are about to enter into or have entered into with you.
- Legitimate Interests: Where it is necessary for our legitimate business interests, and your interests and fundamental rights do not override those interests.
- Legal Obligation: Where we need to comply with a legal or regulatory obligation.
- Consent: Where you have provided clear, explicit consent for us to process your data for a specific purpose.
5. Artificial Intelligence and Automated Processing
To provide sophisticated financial insights, streamline due diligence, and optimise operational efficiency, we utilise advanced artificial intelligence models.
This section describes processing carried out by OptiCap. It does not apply to ScaleBridge, which has no artificial intelligence or machine learning component of any kind. See sub-section D below and Section 6.
A. Data Minimisation and Privacy by Design
We do not feed your entire database into our AI models. We implement strict data minimisation protocols. Personal identifiers are stripped, masked, or subjected to anonymisation before any data is processed by the AI. Only data fields strictly necessary to generate the requested insight are analysed.
B. Purpose of AI Processing
Our AI systems categorise and analyse data to identify operational inefficiencies, structure deal frameworks, and review financial performance. These systems act as analytical tools to support our experts.
C. Human Oversight
We do not rely solely on automated decision-making for actions that produce legal or significant effects. We maintain a strict “Human-in-the-Loop” policy. All AI-generated insights, particularly those regarding high-stakes financial recommendations or acquisitions, are reviewed by our professional team before execution.
D. Exclusion of Connected Mailbox Data
This section does not apply to any data obtained through a connected email account. Data received from Google or Microsoft APIs is excluded from all automated analysis, model training, profiling and AI processing described above, and is never transferred to any AI infrastructure provider. See Section 6 below.
To state it positively: ScaleBridge, the only platform that connects Google or Microsoft mailboxes, integrates no artificial intelligence or machine learning service, and makes no call to any AI provider. The AI processing described in this section belongs to OptiCap, a separate platform which has no Google or Microsoft integration and never receives Workspace user data.
6. Connected Email Accounts (Google and Microsoft)
Our platforms — currently ScaleBridge — allow you to connect your own email account so that outreach you write is sent from your own address rather than ours, and replies return directly to you. Connecting an account is entirely optional and is never required to use our services.
What we ask for
When you connect a Google account, we request a single permission, https://www.googleapis.com/auth/gmail.send, which allows an application to send mail on your behalf. We also request your basic profile identifiers (openid and your email address) solely so we can display which account is connected.
When you connect a Microsoft account, we request the equivalent single permission, Mail.Send.
We do not request permission to read, search, download, modify or delete any message in your mailbox, and we do not request access to your contacts, calendar, files or any other data held in your account.
What we do with it
We use this access for one purpose only: to send email messages that you have composed, reviewed or expressly approved within our platform, together with a single test message at your request to confirm the connection is working.
What we never do
We do not, and will not:
- read, store or analyse the contents of your mailbox or inbox;
- use data obtained through this connection for advertising, marketing or profiling;
- use it to train, develop or improve artificial intelligence or machine learning models;
- sell, rent or transfer it to any third party, except as required to provide the service to you or where compelled by law;
- allow our staff to read it, except with your explicit prior consent, where necessary for security purposes such as investigating abuse, or where required by law.
Limited Use
Stalwart Blue’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use, transfer or sell Workspace or Photos user data — raw, aggregated, anonymised or derived — to create, train or improve any foundational or generalised artificial intelligence or machine learning model, and we do not transfer such data to any third-party AI or machine learning service.
How this data is protected
The authorisation token that permits sending is encrypted before it is stored, using a key held separately from the database. It is never returned to your browser and is not accessible to our administrators through the platform interface. We do not store your email account password; where you connect by Google or Microsoft, no password is ever supplied to us.
Withdrawing access
You may disconnect a mailbox at any time from Settings → Email sending within the platform. You may also revoke our access directly and with immediate effect from your provider:
- Google — myaccount.google.com/permissions
- Microsoft — account.microsoft.com/privacy
When you disconnect a Google mailbox from within our platform, we both delete the stored authorisation token and instruct Google to revoke the grant, so the authorisation is withdrawn at Google as well as removed from our systems. Microsoft provides no equivalent instruction, so for a Microsoft mailbox we delete the stored token and ask you to withdraw the grant from your Microsoft account. Records of messages already sent are retained in line with Section 10 below.
Lawful basis
We process this data to perform our contract with you, and on the basis of the consent you give at the point you connect the account. You may withdraw that consent at any time by disconnecting, without affecting the lawfulness of processing before withdrawal.
7. Disclosures of Your Personal Data
We may share your personal data with external third parties to fulfil the purposes set out in Section 4. These include:
- Service Providers: Companies acting as processors who provide IT, system administration, and secure cloud hosting services.
- Professional Advisers: Lawyers, bankers, auditors, and insurers providing consultancy, banking, legal, insurance, and accounting services.
- Regulators and Authorities: Bodies based in the UK and other relevant jurisdictions who require reporting of processing activities in certain circumstances.
- Email and Identity Providers: Including Google LLC and Microsoft Corporation, where you have chosen to connect an email account, to the extent necessary to authenticate that connection and deliver the messages you send.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law.
8. International Transfers
Some of our external third parties, including Qwen.ai, the AI infrastructure provider used by OptiCap, are based outside the UK and the European Economic Area (EEA). Their processing of your personal data may involve a transfer of data outside these regions, such as to servers located in Singapore.
Whenever we transfer your personal data out of the UK or EEA, we ensure a similar degree of protection is afforded to it by ensuring appropriate safeguards are implemented. This includes the use of Standard Contractual Clauses (SCCs) approved for use in the UK, ensuring our providers maintain compliance with stringent, international data protection standards.
For the avoidance of doubt, data obtained from Google or Microsoft APIs through a connected email account is never transferred to Qwen.ai or to any other AI infrastructure provider, and is not processed outside the scope described in Section 6. ScaleBridge does not use Qwen.ai.
9. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. This includes end-to-end encryption for data in transit and robust access controls for our deal-management modules. In addition, we limit access to your personal data to those employees, agents, and contractors who have a strict business need to know.
10. Data Retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
11. Your Legal Rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data. You have the right to:
- Request access to your personal data.
- Request correction of the personal data that we hold about you.
- Request erasure of your personal data.
- Object to processing of your personal data where we are relying on a legitimate interest.
- Request restriction of processing of your personal data.
- Request the transfer of your personal data to you or to a third party.
- Withdraw consent at any time where we are relying on consent to process your personal data.
12. Contact Details
If you have any questions about this Privacy Policy or our privacy practices, please contact our Data Protection Team:
Email address: [email protected]
Postal address: 48 West George Street, 2/3, 2nd Floor,
Glasgow, Scotland, G2 1BP, UK
Stalwart Blue is registered in England, company number 15289659.
If you are based in the UK, you have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues. We would, however, appreciate the chance to deal with your concerns before you approach the ICO.