Privacy Policy
Last updated: [Effective date]
Skeme (“Skeme”, “we”, “us”) is an AI orchestration platform that handles your organization's communication, automation and data. This policy explains what we collect when you use the Skeme website and platform, why we collect it, and the choices you have.
1. Information We Collect
We collect information in three ways: what you give us, what your use of the platform generates, and what your organization sends through it.
- Account information — name, work email address, organization name, and authentication identifiers created when you sign up or are invited to a workspace.
- Customer content — the questionnaires, workflows, prompts, documents, messages, and records you and your organization create, upload, or connect to Skeme.
- Usage and device data — pages viewed, features used, timestamps, IP address, browser and operating system, and diagnostic logs.
- Integration data — information we retrieve from third-party services you choose to connect, limited to the scopes you authorize.
2. How We Use Your Information
We use it to:
- provide, operate, and maintain the platform;
- authenticate users, enforce workspace permissions, and prevent abuse;
- run the AI features you invoke, including routing content to the model providers described in section 4;
- diagnose faults, monitor reliability and performance, and improve the product;
- communicate with you about service changes, security notices, and support requests;
- meet legal, tax, and accounting obligations.
We do not sell personal information, and we do not use customer content to train foundation models.
3. Cookies and Similar Technologies
We use strictly necessary cookies to keep you signed in and to secure sessions, and analytics cookies to understand aggregate usage. You can block non-essential cookies through your browser settings; the platform will continue to function, though some preferences may not persist.
4. How We Share Information
We share information only in these circumstances:
- Sub-processors — hosting, storage, error monitoring, email delivery, and AI model providers that process data on our behalf under written contract.
- Within your workspace — other members of your organization can see content according to the permissions your administrators configure.
- Legal requirements — where we are compelled by valid legal process, or where disclosure is necessary to protect rights, safety, or the integrity of the service.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy continuing to apply.
5. Data Retention
We keep customer content for as long as your workspace is active. After an account is closed we delete or anonymize it within 90 days, except where a longer period is required by law or needed to resolve disputes. Backups are purged on a rolling schedule.
6. Security
We encrypt data in transit and at rest, restrict internal access on a least-privilege basis, and log administrative actions. No system is perfectly secure, so we also maintain an incident response process and will notify affected customers and regulators where the law requires it.
7. Your Rights and Choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. Where Skeme processes data on behalf of your organization, we will refer your request to that organization and support them in answering it. To exercise a right, contact us at the address in section 11.
8. International Data Transfers
Skeme operates globally, so your information may be processed in countries other than your own. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on Standard Contractual Clauses or another approved safeguard.
9. Children's Privacy
Skeme is a business product and is not directed to children under 16. We do not knowingly collect their personal information; if we learn we have, we will delete it.
10. Changes to This Policy
We may update this policy as the platform evolves. We will revise the date above and, for material changes, notify account administrators before the change takes effect.
11. Contact Us
Questions about this policy or your data can be sent to privacy@skeme.com, or by post to [Company legal name], [Registered address].