Data Processing
This note describes how we process personal data in your Sklyvo workspace when you are the controller and we act as your processor. Throughout this page we means Jan Sedlář, who builds and runs Sklyvo as a natural person under the Venegard name, and who is your processor for the data described here. It is written for Article 28 of the GDPR, without the fog that usually comes with it.
Who does what
For the contacts, companies, drafts and messages you put into Sklyvo, you are the controller. You decide why those people are contacted and on what legal basis. We act as your processor: we host the data and run the tools you ask for, on your instructions.
Account data about you as a customer of Sklyvo is covered by the Privacy Policy. This page is about the people in your pipeline.
What we process for you
Only what your workspace needs to run:
- Business contact details returned by search or imported by you: names, roles, emails, phones, company details, notes.
- Drafts, sent messages, replies, and campaign settings tied to those contacts.
- Mailbox tokens you connect so outreach can be sent and replies read on your behalf.
- Technical logs needed to keep that processing reliable and secure.
We do not use workspace contacts to market Sklyvo to those people, and we do not sell them.
Why and how long
We process this data to provide the service you contracted for: finding, verifying, drafting, sending and tracking outreach inside your workspace. Processing lasts for the life of your account and stops when you delete the data or close the workspace, subject to short-lived backups that roll off within 30 days.
Your instructions
Your instructions are whatever the product lets you do: import, search, edit, send, suppress, export, delete. We will not process workspace data for another purpose. If a legal request forces us to act without you, we will tell you unless the law forbids it.
Sub-processors
We use carefully chosen providers so the product can run: hosting and databases in the EU, the model provider that drafts text from your prompts, and the mailbox or payment providers you connect yourself. Each is bound by contract to process data only on instructions and only for as long as the job requires.
Where a transfer leaves the EU, it runs on the European Commission’s standard contractual clauses or an equivalent safeguard.
Security
Access is limited to people who need it to run or support the service, and it is logged. Data in transit and at rest is encrypted. Mailbox tokens are encrypted separately from the main database. Workspaces are isolated from each other.
If a breach affecting your workspace data becomes known to us, we will notify you without undue delay so you can meet your own duties as controller.
Helping you with data-subject requests
If someone asks you for access, correction, deletion or another GDPR right about data sitting in Sklyvo, tell us at support@sklyvo.com. We will help you find, correct or remove what we hold, within the limits of the product and the law.
If someone writes to us directly about a contact in a customer workspace, we pass the request to the workspace that holds the record and keep a suppression mark so the person is not written to again from that workspace.
Your duties as controller
- Have a lawful basis for contacting the people in your workspace.
- Do not upload special-category data or data about children.
- Honour opt-outs and keep your suppression list clean.
- Tell us promptly when you need help with a rights request or a suspected incident.
End of the contract
When you close your account or delete a workspace, we delete the related personal data within 24 hours from live systems. Backups fall away within 30 days. We do not keep a copy for our own marketing.
Contact
Questions about processing in your workspace: support@sklyvo.com.