Agent Control Panel
HomePricingDocsTrust
Request early access
Legal
  • All documents
  • Terms of Service
  • Privacy Policy
  • Data Processing Addendum
  • Acceptable Use Policy
  • Cookie Policy
  • Responsible Disclosure
  • Enterprise Agreement (on request)
Legal/Privacy Policy
Legal

Privacy Policy

Last updated: September 30, 2026

This Privacy Policy explains how Smart Sky for Advanced Systems and Computer Software (السماء الذكية للأنظمة المتطورة والبرمجيات الحاسوبية), a company registered in the Hashemite Kingdom of Jordan (company ID 200214341) (“ACP”, “we”, “us”) handles personal data when you visit our website, request early access, use Agent Control Panel (the “Service”), or contact us. It also explains the different role we play for data your agents send to the Service.

On this page
  1. 1. Our role
  2. 2. Personal data we collect as a controller
  3. 3. Customer data we process as a processor
  4. 4. How we use personal data and our lawful bases
  5. 5. How we share personal data
  6. 6. How long we keep personal data
  7. 7. Your rights and how to exercise them
  8. 8. International transfers
  9. 9. Security
  10. 10. Children
  11. 11. EU and UK representatives
  12. 12. Complaints
  13. 13. Cookies
  14. 14. Changes to this policy
  15. 15. Contact us

1. Our role

As a controller. We decide how and why personal data is processed for our website, early-access applications, invitations, customer accounts, billing, support, and the security of the Service. This policy describes that processing.

As a processor. When your agents report runs and telemetry to the Service, that data may contain personal data of your end users (for example, a name or email inside a prompt). We process it only on your instructions as your processor under our Data Processing Addendum. Your organization is the controller and its own privacy notice applies. If you are an end user of one of our customers, please contact that customer; we will help them respond.

2. Personal data we collect as a controller

Account data

Email address, authentication identifiers (such as your user ID and sign-in provider), organization membership and role, and sign-in timestamps. Passwords are handled by our authentication provider and are never stored by us. If you sign in with Google or GitHub, that provider shares your email address, account identifier, and basic profile details (such as your name and profile picture) with our authentication provider; we use only your email address and identifiers. Sign-in, confirmation, and password-reset emails are delivered through our email provider.

Early-access and invitation data

When you request early access: name, email address, company or project, a short description of what you are building, how you heard about us and the plan you are interested in if you choose to say, the version of the notice shown to you, and whether you asked for product updates. When an operator or an organization invites you: the invited email address, the intended role, and whether the invite was accepted, declined, expired, or revoked. Invite links are stored as hashes only; the raw token is shown once and is not kept.

Document requests

When you request contract or security documents on our Security & Trust page: your name, work email, company, optional job title, the documents you asked for, an optional message, your confidentiality confirmation, and when and how often you opened the private link we send.

Security and audit data

Records of security-relevant actions in the Service, such as API key, secret, scope, command, settings, and skill changes and denied access attempts, including the acting user and the IP address of the request. Our access logs record the method, path, status, and duration of API requests (never request or response bodies). Our hosting and network providers (Railway and Cloudflare) may also record IP addresses in their infrastructure and security logs.

Communications

Messages you send us by email or through a scheduled call, and our replies.

Billing data

If you buy a paid plan, billing contact details and transaction records. We do not store full card numbers; card payments are handled by a payment provider, which we will list on the Security & Trust page before we start using it.

Website and browser storage

The marketing site sets no cookies and uses no analytics or advertising trackers. The dashboard uses strictly necessary cookies and browser storage to keep you signed in and remember interface preferences, described in our Cookie Policy.

3. Customer data we process as a processor

Depending on how you configure your integration, the Service receives run records (inputs, outputs, errors, timings), token and cost usage, heartbeats, feedback, prompts and skills, and configuration. Any of these can contain personal data of your end users. We use this data only to provide the Service to you, including its optional AI Features, to secure it, and as described in the DPA.

When you use AI Features, such as quality reviews, error explanations, Test Lab judging, or integration analysis, the relevant run content is sent to our AI subprocessors (Anthropic, with OpenAI and Google as fallbacks). Organization owners can restrict AI processing to the primary provider (no fallback) or disable AI Features entirely in settings. We do not use customer data to train machine-learning models.

4. How we use personal data and our lawful bases

PurposeDataLawful basis (EU/UK GDPR)
Provide the Service, create and manage accountsAccount data, customer dataPerformance of a contract
Secure the Service, prevent abuse, investigate incidentsSecurity and audit data, account dataLegitimate interests in protecting our customers and the Service
Respond to requests and provide supportCommunications, account dataPerformance of a contract; legitimate interests
Review early-access requests and contact you about accessEarly-access dataSteps taken at your request before entering into a contract
Answer document requests and share documents under confidentialityDocument requestsSteps taken at your request before entering into a contract; legitimate interests in sharing confidential documents only with verified businesses
Understand which channels bring people to us (the optional “How did you hear about us?” answer)Early-access dataLegitimate interests in knowing where our visitors come from; you can leave it blank
Send product updates, only if you ticked the optional boxName and email addressConsent, which you can withdraw at any time
Invite people to create or join an organizationInvitation dataLegitimate interests in controlling access; contract once the invite is accepted
Billing, accounting, and taxBilling dataPerformance of a contract; legal obligation
Comply with law and enforce our termsAny relevant dataLegal obligation; legitimate interests

We do not sell personal data, and we do not share it for cross-context behavioral advertising. We do not make decisions that produce legal or similarly significant effects based solely on automated processing.

5. How we share personal data

  • Subprocessors and service providers that host, secure, and operate the Service, listed on our Security & Trust page. They may use the data only to provide their services to us.
  • Destinations you configure, such as an alert webhook to Discord or another service. These are sent on your instructions.
  • Professional advisers, such as lawyers and accountants, under confidentiality obligations.
  • Authorities, when required by law or to protect rights, safety, and security, after reviewing the request.
  • A successor in a merger, acquisition, or sale of assets, subject to this policy.

6. How long we keep personal data

Run records and the telemetry derived from them, ingest attempt logs, audit logs, early-access applications, and closed invitations are deleted automatically when their period below ends.

DataRetention
Run recordsDeleted after your organization’s retention window: 30 days on Free and Hobby, 90 days on Team, or as agreed for Scale
Ingest attempt logs7 days
Audit logs365 days
Early-access applications24 months, or until you withdraw consent or ask us to delete them
Document requests24 months; the private link stops working after 30 days
Closed or expired invitations24 months after they are accepted, declined, revoked, or expire
Account dataWhile your account is active, then deleted after account closure except where we must keep it by law
Other customer data (usage, feedback, prompts, skills, configuration)According to the retention controls in the Service, or until you delete it or close your organization
Billing recordsAs long as required by tax and accounting law

7. Your rights and how to exercise them

If you are in Jordan, the Personal Data Protection Law (Law No. 24 of 2023) gives you rights over your personal data, and we honor them in the same way. Depending on where you live, you may also have the right to access, correct, delete, restrict, or object to our processing of your personal data, to data portability, and to withdraw consent at any time without affecting earlier processing. You also have the right not to be discriminated against for exercising these rights.

  • In the product. Organization owners can export all organization data and delete the organization from the dashboard settings. Owners and admins can delete an individual run, which lets you honor an end user’s erasure request without deleting other data.
  • By email. Write to Founders@skaigroup.tech. We may need to verify your identity. We respond within one month, or sooner where the law requires.
  • Early access. Ask us to remove your application at any time, or use the unsubscribe link in any update email we send.
  • End users of our customers. Contact the customer that controls the data. If you contact us, we will forward your request to them.

8. International transfers

We store and process customer data and account data in the United States. Requests to the Service pass through our network provider (Cloudflare), which processes them in transit at the data center nearest to the user and does not store customer data. When we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent safeguards, together with supplementary measures where appropriate. Contact us for a copy of the relevant safeguards.

9. Security

We use technical and organizational measures designed to protect personal data, including tenant isolation, encryption of secrets, hashed API keys, strict access controls, and security logging. No system is perfectly secure. Our current controls, including what we do not have yet, are listed on our Security & Trust page.

10. Children

The Service is for business use and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

11. EU and UK representatives

We are established in Jordan. We have not appointed a representative in the European Union or the United Kingdom under Article 27 of the EU GDPR and UK GDPR. If the law requires one for our processing, we will appoint one and name them here. Until then, you can reach us directly at Founders@skaigroup.tech; we handle requests from every country the same way.

12. Complaints

Please contact us first so we can try to help. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live, work, or where you believe an infringement occurred. In the UK, that is the Information Commissioner’s Office.

13. Cookies

We use only strictly necessary cookies and browser storage. See the Cookie Policy for the full list.

14. Changes to this policy

We will post any changes here with a new “Last updated” date. If a change is material, we will notify account owners by email or in the Service before it takes effect, and ask for consent where the law requires it.

15. Contact us

Smart Sky for Advanced Systems and Computer Software (السماء الذكية للأنظمة المتطورة والبرمجيات الحاسوبية), a company registered in the Hashemite Kingdom of Jordan (company ID 200214341)
Amman, Hashemite Kingdom of Jordan
Privacy: Founders@skaigroup.tech
General: Founders@skaigroup.tech

Questions about this document? Email Founders@skaigroup.tech. Other policies: Legal hub · Security & Trust.

© 2026 Agent Control Panel
OverviewDocumentationPricingSecurity & TrustTermsPrivacyGuidesLegalContactSign in