Introduction
SCIM.ninja is operated by Objective Labs LTD ("we", "us", "our"), a company registered in England and Wales under company number 17303955, with our registered address at 124 City Road, London EC1V 2NX.
We act as the data controller for the personal data described in this policy — meaning we determine the purposes for which and the means by which that data is processed.
This policy covers only the personal data for which we are the controller. Where we process personal data on behalf of our customers — in particular the records of the end users our customers provision through the service, and the logs of provisioning activity relating to those end users — we act as a processor on our customer's documented instructions. That processing is governed by our Data Processing Agreement, not by this policy. If you are an end user of one of our customers, your organisation is the controller of your data, and you should direct privacy enquiries to it in the first instance.
This policy explains what personal data we collect when you use SCIM.ninja, why we collect it, how long we keep it, who we share it with, and what rights you have. It applies to all visitors, registered users, and administrators of the SCIM.ninja platform.
If you have any questions about this policy or about how we handle your personal data, please contact us at privacy@scim.ninja or by post at the registered address above.
What we collect
We collect personal data across five categories. For each category we explain the data involved, the purpose for which it is processed, and the legal basis under the UK GDPR that permits us to do so.
Account and organisational information
Data collected: Your name, your company name, and your email address.
Why we collect it: To create and manage your SCIM.ninja account, to communicate with you about your service (including onboarding, service updates, and support), and to associate your usage with your organisation.
Legal basis: Performance of a contract (UK GDPR Article 6(1)(b)) — this data is necessary to provide you with access to SCIM.ninja and to fulfil our obligations to you as a customer.
Shared with: Our call scheduling provider (to provide context to any scheduled calls), our live chat support provider (to identify you during support interactions), our billing provider (to associate billing records with your account), and our analytics partner (if opted into analytical cookies, for linking your page usage information to your identity).
Billing information
Depending on your location, your subscription will be processed through one of two billing arrangements. We determine which arrangement applies at our discretion, based on factors including your billing country and applicable tax obligations. The arrangement in place for your account will be clear at the point of purchase.
Direct billing
Where we bill you directly, we collect payment card details, billing contact information, and company billing information (such as company name and address for invoice purposes) in order to process subscription payments, issue invoices, and manage your billing relationship with us.
Legal basis: Performance of a contract (UK GDPR Article 6(1)(b)) — payment processing is necessary to maintain your paid subscription. We share this data with Stripe, our payment provider, who processes card transactions on our behalf. We do not store full card details on our own systems.
Billing via Paddle (Merchant of Record)
For some customers, subscription billing is handled by Paddle.com Market Ltd ("Paddle"), a company registered in England and Wales, acting as our merchant of record. In this arrangement, Paddle is the legal seller of the subscription to you and is an independent data controller for the billing and transaction data you provide at checkout. We do not collect or control your payment card details or billing information in this scenario — that data is collected directly by Paddle and governed by Paddle's privacy policy.
We receive from Paddle only the information necessary to manage your subscription on our platform, such as your subscription status, plan details, and a customer identifier. We use this data solely to provision and maintain your access to SCIM.ninja.
Legal basis (for data received from Paddle): Performance of a contract (UK GDPR Article 6(1)(b)).
Integration information
Data collected: Technical configuration information and authentication credentials you provide during the integration setup process. Where credentials are tied to a named individual (for example, a personal API token), they constitute personal data and are treated as such. Where they relate to a system or service account with no link to an individual, they are treated as confidential business data. In either case, credentials are encrypted at rest, access is strictly limited, and they are used solely to build and operate your integration.
Why we collect it: To configure and operate your SCIM integration — this information is used by our team to build, test, and maintain the connection between your Identity Provider and your target application.
Legal basis: Performance of a contract (UK GDPR Article 6(1)(b)) — this information is essential to deliver the core service you have engaged us to provide.
Shared with: Our infrastructure provider (who hosts the platform and processes data on our behalf) and our API testing software provider (used by our integration team to validate that connections function correctly).
User behaviour, device, and browser information
Data collected: Information about how you use the SCIM.ninja dashboard, including pages visited, actions taken, your device type, browser type and version, operating system, IP address, and the URL from which you arrived at our site.
Why we collect it: To understand how the platform is used, to improve user experience, to identify and resolve technical issues, and to protect the platform against fraudulent or abusive behaviour.
Legal basis: Legitimate interests (UK GDPR Article 6(1)(f)) — analytics help us to improve the product and serve our users better, and fraud and bot prevention (via reCAPTCHA) is necessary to protect the security of our service. Where analytics cookies are enabled, we additionally rely on your consent (Article 6(1)(a)) for the collection and processing of that data. We do not use behavioural data for advertising purposes.
Shared with: Our analytics partner and Google (for reCAPTCHA v3 bot and fraud detection on our authentication forms). Google's use of reCAPTCHA data is governed by Google's own privacy policy.
Login credentials
Data collected: Your email address and password. Passwords are stored in hashed form and are never stored or transmitted in plain text. We also offer magic link authentication, in which case a time-limited token is sent to your email address in place of a password.
Why we collect it: To authenticate you when you sign in to SCIM.ninja.
Legal basis: Performance of a contract (UK GDPR Article 6(1)(b)) — authentication is necessary to provide secure access to your account.
Shared with: Our infrastructure provider, who hosts the authentication system on our behalf.
How we use your data
The purposes and legal bases for our processing are described for each data category in section 02. In summary, we rely on two legal bases under UK GDPR Article 6:
- Performance of a contract (Article 6(1)(b)): The majority of our processing — including account management, integration delivery, billing, and authentication — is necessary to fulfil our service obligations to you.
- Legitimate interests (Article 6(1)(f)): We process usage data on the basis of our legitimate interest in operating a reliable, secure, and improving service. In each case we have assessed that this processing does not unduly override the privacy interests of the individuals concerned.
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not use your data for advertising or marketing to third parties.
Is providing your personal data a requirement?
Providing your account information (name, email address, company name) and login credentials is a contractual requirement. Without this information, we cannot create or maintain your account or provide you with access to SCIM.ninja.
Providing integration information (credentials, application details) is also a contractual requirement for the core service. Without it, we cannot build or operate your SCIM integration.
Providing billing information is required to maintain a paid subscription following the end of any free trial period.
Providing device and usage data is not a condition of using the service; however, some elements (such as reCAPTCHA data) are technically necessary to protect the security of our authentication system.
Data sharing
We share personal data only where necessary to provide the service, and only with reputable third parties bound by appropriate data processing agreements. We do not sell your data.
Our third-party providers
- Infrastructure provider — hosts the SCIM.ninja platform and processes data on our behalf, including integration configuration and authentication.
- Stripe (payment provider) — processes card transactions on our behalf where we bill you directly. We do not store full card details on our own systems.
- Paddle.com Market Ltd — acts as merchant of record for some customers and is an independent data controller for checkout data in those arrangements.
- Call scheduling provider — receives account and contact information to pre-fill booking forms during guided onboarding.
- Live chat support provider (Zoho) — receives account information to identify you during support interactions.
- API testing software provider — used by our integration team to validate that connections function correctly; may process integration configuration data.
- Analytics partner — receives usage and behavioural data to help us understand how the platform is used and improve user experience.
- Google (reCAPTCHA v3) — receives device and browser data from our authentication forms for fraud and bot detection. Governed by Google's privacy policy.
International transfers of personal data
Some of the third parties we share data with are based outside the United Kingdom. For each international transfer we ensure an appropriate mechanism is in place under UK GDPR Chapter V before any personal data is shared.
United States — UK-US Data Bridge
Where we transfer personal data to US-based providers, we verify that the recipient holds active certification under the UK Extension to the EU-US Data Privacy Framework (the "UK-US Data Bridge") before doing so. We rely on the UK-US Data Bridge as our transfer mechanism for all such providers, which means no additional safeguard such as an International Data Transfer Agreement (IDTA) is required. Certification can be verified at dataprivacyframework.gov.
We periodically re-verify that our US providers maintain active DPF certification. In the event that a provider's certification lapses or the UK-US Data Bridge is suspended or invalidated, we will put alternative transfer safeguards in place before continuing to transfer personal data.
India — Data Processing Agreement (Zoho)
Zoho (our live chat support provider) is headquartered in India, which does not currently hold a UK adequacy decision. Zoho operates a UK legal entity (Zoho Corporation Limited, registered in England) and has appointed a Data Protection Officer registered with the ICO. Zoho hosts customer data on servers within the European Economic Area; however, as Zoho group entities and their staff may access data internationally as part of service delivery and support, we treat this as an international transfer requiring an appropriate safeguard.
We have addressed this by entering into Zoho's UK Data Processing Addendum, which incorporates transfer clauses that meet the requirements of UK GDPR Article 46. This DPA governs how Zoho processes personal data on our behalf, restricts use of that data to service delivery purposes, and requires Zoho to implement appropriate technical and organisational security measures.
If you would like more information about the transfer mechanisms in place for any of our providers, please contact us.
Data retention
We retain your personal data only for as long as is necessary for the purposes described in this policy.
| Category | Retention period |
|---|---|
| Account and organisational information | For the duration of your account, plus 2 years after closure |
| Billing information | For the duration of your subscription, plus 6 years to meet legal accounting and tax obligations |
| Integration information | For the duration of your integration, plus 90 days after termination to support handover |
| User behaviour and device data | 7 years from collection |
| Login credentials | For the duration of your account; passwords deleted promptly upon account closure |
We will review these periods periodically. Where we are required to retain data for legal or regulatory reasons, we will retain it for the period required by law.
Your rights
Under the UK GDPR, you have the following rights in relation to your personal data. You can exercise any of these rights by contacting us at privacy@scim.ninja.
- Right of access. You have the right to request a copy of the personal data we hold about you, together with information about how we process it.
- Right to rectification. You have the right to ask us to correct any inaccurate personal data we hold about you, and to complete any incomplete data.
- Right to erasure. You have the right to ask us to delete your personal data in certain circumstances — for example, where the data is no longer necessary for the purpose for which it was collected, or where you withdraw consent and there is no other legal basis for processing.
- Right to restriction. You have the right to ask us to restrict processing of your personal data in certain circumstances — for example, while we are investigating a challenge to the accuracy of your data.
- Right to data portability. Where we process your personal data on the basis of your consent or in performance of a contract, and the processing is carried out by automated means, you have the right to receive a copy of your data in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller where technically feasible.
- Right to object. Where we rely on legitimate interests as our legal basis, you have the right to object to that processing on grounds relating to your particular situation. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, or unless processing is necessary for the establishment, exercise, or defence of legal claims.
- Right to withdraw consent. Where we rely on your consent as the legal basis for processing, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing that took place before withdrawal.
- Right not to be subject to automated decision-making. We do not make decisions about you solely on the basis of automated processing that produce legal or similarly significant effects.
We will respond to any request within one month of receipt. If a request is complex or we receive a high volume of requests, we may extend this by a further two months, in which case we will notify you. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive.
Right to lodge a complaint
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK's data protection supervisory authority. We would, however, appreciate the opportunity to address your concerns before you do so — please contact us at privacy@scim.ninja in the first instance.
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
ico.org.uk · 0303 123 1113
Cookies & tracking
We use cookies and similar technologies to operate the SCIM.ninja platform. These fall broadly into two categories:
- Strictly necessary: Cookies required to authenticate you and maintain your session. These cannot be disabled without affecting the core functionality of the service.
- Analytics and security: We use an analytics partner to understand how the platform is used, and Google reCAPTCHA v3 to protect our authentication forms from bots and fraud. These involve the collection of device, browser, and behavioural data as described in section 02.
For full details of the cookies we use, how long they are retained, and how to manage your preferences, see our Cookie Policy.
Changes to this policy
We will update this policy from time to time to reflect changes in how we process personal data or to comply with changes in the law. We will notify you of any material changes — for example, by emailing registered users or by displaying a notice within the SCIM.ninja dashboard.
The date at the top of this policy indicates when it was last revised. We encourage you to review this page periodically to stay informed about how we protect your data.
Contact us
If you have any questions about this privacy policy or about how we handle your personal data, please get in touch:
Email: privacy@scim.ninja
Post: Objective Labs Ltd., 124 City Road, London EC1V 2NX
For complaints, you also have the right to contact the Information Commissioner's Office directly — see section 06 for their details. We would always appreciate the opportunity to resolve your concerns in the first instance.