Privacy Policy
This Privacy Policy explains how Smart Sky for Advanced Systems and Computer Software (السماء الذكية للأنظمة المتطورة والبرمجيات الحاسوبية), a company registered in the Hashemite Kingdom of Jordan (company ID 200214341) (“ACP”, “we”, “us”) handles personal data when you visit our website, request early access, use Agent Control Panel (the “Service”), or contact us. It also explains the different role we play for data your agents send to the Service.
On this page
- 1. Our role
- 2. Personal data we collect as a controller
- 3. Customer data we process as a processor
- 4. How we use personal data and our lawful bases
- 5. How we share personal data
- 6. How long we keep personal data
- 7. Your rights and how to exercise them
- 8. International transfers
- 9. Security
- 10. Children
- 11. EU and UK representatives
- 12. Complaints
- 13. Cookies
- 14. Changes to this policy
- 15. Contact us
1. Our role
As a controller. We decide how and why personal data is processed for our website, early-access applications, invitations, customer accounts, billing, support, and the security of the Service. This policy describes that processing.
As a processor. When your agents report runs and telemetry to the Service, that data may contain personal data of your end users (for example, a name or email inside a prompt). We process it only on your instructions as your processor under our Data Processing Addendum. Your organization is the controller and its own privacy notice applies. If you are an end user of one of our customers, please contact that customer; we will help them respond.
2. Personal data we collect as a controller
Account data
Email address, authentication identifiers (such as your user ID and sign-in provider), organization membership and role, and sign-in timestamps. Passwords are handled by our authentication provider and are never stored by us. If you sign in with Google or GitHub, that provider shares your email address, account identifier, and basic profile details (such as your name and profile picture) with our authentication provider; we use only your email address and identifiers. Sign-in, confirmation, and password-reset emails are delivered through our email provider.
Early-access and invitation data
When you request early access: name, email address, company or project, a short description of what you are building, how you heard about us and the plan you are interested in if you choose to say, the version of the notice shown to you, and whether you asked for product updates. When an operator or an organization invites you: the invited email address, the intended role, and whether the invite was accepted, declined, expired, or revoked. Invite links are stored as hashes only; the raw token is shown once and is not kept.
Document requests
When you request contract or security documents on our Security & Trust page: your name, work email, company, optional job title, the documents you asked for, an optional message, your confidentiality confirmation, and when and how often you opened the private link we send.
Security and audit data
Records of security-relevant actions in the Service, such as API key, secret, scope, command, settings, and skill changes and denied access attempts, including the acting user and the IP address of the request. Our access logs record the method, path, status, and duration of API requests (never request or response bodies). Our hosting and network providers (Railway and Cloudflare) may also record IP addresses in their infrastructure and security logs.
Communications
Messages you send us by email or through a scheduled call, and our replies.
Billing data
If you buy a paid plan, billing contact details and transaction records. We do not store full card numbers; card payments are handled by a payment provider, which we will list on the Security & Trust page before we start using it.
Website and browser storage
The marketing site sets no cookies and uses no analytics or advertising trackers. The dashboard uses strictly necessary cookies and browser storage to keep you signed in and remember interface preferences, described in our Cookie Policy.
3. Customer data we process as a processor
Depending on how you configure your integration, the Service receives run records (inputs, outputs, errors, timings), token and cost usage, heartbeats, feedback, prompts and skills, and configuration. Any of these can contain personal data of your end users. We use this data only to provide the Service to you, including its optional AI Features, to secure it, and as described in the DPA.
When you use AI Features, such as quality reviews, error explanations, Test Lab judging, or integration analysis, the relevant run content is sent to our AI subprocessors (Anthropic, with OpenAI and Google as fallbacks). Organization owners can restrict AI processing to the primary provider (no fallback) or disable AI Features entirely in settings. We do not use customer data to train machine-learning models.
4. How we use personal data and our lawful bases
| Purpose | Data | Lawful basis (EU/UK GDPR) |
|---|---|---|
| Provide the Service, create and manage accounts | Account data, customer data | Performance of a contract |
| Secure the Service, prevent abuse, investigate incidents | Security and audit data, account data | Legitimate interests in protecting our customers and the Service |
| Respond to requests and provide support | Communications, account data | Performance of a contract; legitimate interests |
| Review early-access requests and contact you about access | Early-access data | Steps taken at your request before entering into a contract |
| Answer document requests and share documents under confidentiality | Document requests | Steps taken at your request before entering into a contract; legitimate interests in sharing confidential documents only with verified businesses |
| Understand which channels bring people to us (the optional “How did you hear about us?” answer) | Early-access data | Legitimate interests in knowing where our visitors come from; you can leave it blank |
| Send product updates, only if you ticked the optional box | Name and email address | Consent, which you can withdraw at any time |
| Invite people to create or join an organization | Invitation data | Legitimate interests in controlling access; contract once the invite is accepted |
| Billing, accounting, and tax | Billing data | Performance of a contract; legal obligation |
| Comply with law and enforce our terms | Any relevant data | Legal obligation; legitimate interests |
We do not sell personal data, and we do not share it for cross-context behavioral advertising. We do not make decisions that produce legal or similarly significant effects based solely on automated processing.
6. How long we keep personal data
Run records and the telemetry derived from them, ingest attempt logs, audit logs, early-access applications, and closed invitations are deleted automatically when their period below ends.
| Data | Retention |
|---|---|
| Run records | Deleted after your organization’s retention window: 30 days on Free and Hobby, 90 days on Team, or as agreed for Scale |
| Ingest attempt logs | 7 days |
| Audit logs | 365 days |
| Early-access applications | 24 months, or until you withdraw consent or ask us to delete them |
| Document requests | 24 months; the private link stops working after 30 days |
| Closed or expired invitations | 24 months after they are accepted, declined, revoked, or expire |
| Account data | While your account is active, then deleted after account closure except where we must keep it by law |
| Other customer data (usage, feedback, prompts, skills, configuration) | According to the retention controls in the Service, or until you delete it or close your organization |
| Billing records | As long as required by tax and accounting law |
7. Your rights and how to exercise them
If you are in Jordan, the Personal Data Protection Law (Law No. 24 of 2023) gives you rights over your personal data, and we honor them in the same way. Depending on where you live, you may also have the right to access, correct, delete, restrict, or object to our processing of your personal data, to data portability, and to withdraw consent at any time without affecting earlier processing. You also have the right not to be discriminated against for exercising these rights.
- In the product. Organization owners can export all organization data and delete the organization from the dashboard settings. Owners and admins can delete an individual run, which lets you honor an end user’s erasure request without deleting other data.
- By email. Write to Founders@skaigroup.tech. We may need to verify your identity. We respond within one month, or sooner where the law requires.
- Early access. Ask us to remove your application at any time, or use the unsubscribe link in any update email we send.
- End users of our customers. Contact the customer that controls the data. If you contact us, we will forward your request to them.
8. International transfers
We store and process customer data and account data in the United States. Requests to the Service pass through our network provider (Cloudflare), which processes them in transit at the data center nearest to the user and does not store customer data. When we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent safeguards, together with supplementary measures where appropriate. Contact us for a copy of the relevant safeguards.
9. Security
We use technical and organizational measures designed to protect personal data, including tenant isolation, encryption of secrets, hashed API keys, strict access controls, and security logging. No system is perfectly secure. Our current controls, including what we do not have yet, are listed on our Security & Trust page.
10. Children
The Service is for business use and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
11. EU and UK representatives
We are established in Jordan. We have not appointed a representative in the European Union or the United Kingdom under Article 27 of the EU GDPR and UK GDPR. If the law requires one for our processing, we will appoint one and name them here. Until then, you can reach us directly at Founders@skaigroup.tech; we handle requests from every country the same way.
12. Complaints
Please contact us first so we can try to help. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live, work, or where you believe an infringement occurred. In the UK, that is the Information Commissioner’s Office.
14. Changes to this policy
We will post any changes here with a new “Last updated” date. If a change is material, we will notify account owners by email or in the Service before it takes effect, and ask for consent where the law requires it.
15. Contact us
Smart Sky for Advanced Systems and Computer Software (السماء الذكية للأنظمة المتطورة والبرمجيات الحاسوبية), a company registered in the Hashemite Kingdom of Jordan (company ID 200214341)
Amman, Hashemite Kingdom of Jordan
Privacy: Founders@skaigroup.tech
General: Founders@skaigroup.tech