Version 2026-07-17 · Effective July 17, 2026
This Privacy Notice explains how Skygn ("Skygn," "we," "us") collects, uses, discloses, and protects personal data in connection with our software-as-a-service enterprise resource planning platform (the "Service"). Skygn is a business tool: we process data to operate the Service for the organizations that use it. We do not build consumer marketing profiles, and we do not sell or share personal data for cross-context behavioral advertising.
Our role depends on the data:
We use personal data to provide, secure, support, and improve the Service; to authenticate users and prevent abuse; to process billing; to communicate about your account and service-related matters; and to meet legal, accounting, tax, and security obligations. We do not use Customer Content for advertising, and we do not use it to train general-purpose AI models. AI features operate only on the data needed to answer a request within your organization.
Where the EU/UK GDPR applies and we act as controller, we rely on:
For Customer Content we act as processor; the organization determines the legal basis.
We share data only with subprocessors that help us run the Service, each under contractual data-protection obligations — for example cloud database & auth (Supabase), application hosting (Vercel), payments (Stripe), transactional email (Resend), rate-limiting (Upstash), error monitoring (Sentry), and the AI assistant (Anthropic); plus, only if an organization connects them, accounting sync (Intuit/QuickBooks), bank linking (Plaid), and address autocomplete (Google). We may disclose data where required by law or to protect rights and safety. We do not sell personal data.
The Service is primarily hosted in the United States. Our subprocessors may process data in the United States or other regions. Where personal data is transferred across borders (for example from the EEA/UK), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
We protect data with encryption in transit (TLS) and at rest, application-side encryption of the most sensitive secrets, strict per-tenant isolation, role-based access controls, append-only tamper-evident audit logging, continuous security monitoring, and a documented incident-response process (including breach notification where required). No system is perfectly secure, but we work to protect your data and respond promptly to incidents.
We retain personal data for as long as needed to provide the Service and to meet legal and accounting obligations, then delete or anonymize it according to our data-retention schedule. Operational logs are retained for defined short windows; financial ledger and tamper-evident audit records are retained for their statutory lifetime.
Depending on where you live, you may have the right to access, correct, delete, export (portability), or restrict/object to certain processing of your personal data, and to withdraw consent or lodge a complaint with a supervisory authority. Where we act as processor, we route such requests to the relevant organization and assist them; where we act as controller, we honor them directly. We may verify your identity before acting.
If you are a California resident (or in a U.S. state with a comparable law), you have the right to know/access, correct, and delete the personal information we hold as a controller; the right to opt out of the sale or sharing of personal information; and the right not to be discriminated against for exercising these rights. We do not sell or share personal information (as those terms are defined under the CCPA/CPRA), so there is nothing to opt out of, but you may still exercise your other rights below.
Individual users may contact us at privacy@skygn.ai. If your data was entered by an organization using the Service, contact that organization; its administrators can fulfil access and deletion requests directly through the Service's data-request tools, and we support them.
We use strictly necessary cookies to keep you signed in and to operate the Service securely. We do not use advertising or cross-site tracking cookies, so no consent banner is required.
The Service is a business tool not directed to children and is not intended for anyone under 16. We do not knowingly collect personal data from children.
We may update this notice; material changes will be posted here with a new version and effective date, and communicated where appropriate.
Questions or privacy requests? Contact us at privacy@skygn.ai or info@skygn.ai.