Privacy Policy
Last updated: 2 August 2026
Who is responsible
The controller of personal data processed through skyfirstlabs.com, the Sky web platform, and the Sky by SkyFirst mobile app is SPECIAL OPTION, LDA (trading as Sky First Labs), a private limited company registered in Portugal under tax identification number 518824985, with registered office at Estrada Nacional 4, Quinta Fernão Pote, caixa 3, 7350-422 Elvas, Portugal.
For any privacy matter, write to info@skyfirstlabs.com. We have not appointed a Data Protection Officer because the company does not meet the criteria of Article 37 GDPR.
Scope of this policy
This policy covers three things:
- The website — skyfirstlabs.com: browsing it, filling in the contact form, requesting a 5-day audit, or otherwise interacting with us through the site.
- The Sky web platform — the product itself, used by people whose employer has a Sky workspace.
- Sky by SkyFirst — our mobile app for iOS and Android. Section 04 covers it in detail.
Where we process business data inside a customer workspace, we act as a processor on behalf of that customer, and the processing is governed by the Data Processing Agreement (DPA) signed with them. Where we process account, device, and diagnostic data in order to run and secure the service, we act as controller and this policy applies.
What we collect and why
| Category | Examples | Purpose | Lawful basis |
|---|---|---|---|
| Contact data | Name, business email, company, role, message text | Reply to enquiries, schedule audits, send proposals | Art. 6(1)(b) — pre-contractual steps |
| B2B prospecting | Name, business email, role, company, public LinkedIn data | Outbound to operating leaders at relevant European scaleups, with a clear opt-out in every email | Art. 6(1)(f) — legitimate interest |
| Analytics | Pseudonymous identifiers, page paths, country, device class | Measure traffic, fix what is broken, improve content | Art. 6(1)(a) — consent (cookie banner) |
| Server logs | IP address, user agent, timestamps | Security, abuse prevention, debugging | Art. 6(1)(f) — legitimate interest |
We do not collect special categories of data (Article 9 GDPR), and we do not run profiling or automated decision-making with legal effect on visitors.
The Sky by SkyFirst mobile app
Sky by SkyFirst is our native app for iOS and Android. It is a business tool, and it does not register users: we provision each customer's workspace and its first administrator, that administrator creates the remaining accounts, and the app only signs in accounts that already exist.
What the app collects
| Category | What it includes | Why |
|---|---|---|
| Account data | Name, work email address, company, role | Authenticate you and apply your workspace permissions |
| Conversation content | The questions you ask, the answers Sky returns, and files you upload | Deliver the core functionality of the app |
| Device and push data | Push notification token, device identifier | Deliver notifications and keep sessions secure |
| Diagnostics | Crash reports, performance traces, in-app interaction events | Find and fix faults, keep the app stable |
We use this data for three purposes only: functionality, security, and diagnostics. The lawful basis is Article 6(1)(b) — performance of the contract under which your employer provides you with Sky — and Article 6(1)(f), our legitimate interest in keeping the service secure and working.
We do not train models on your data
We do not use your business data or your conversations to train models. Not our own models, and not anyone else's.
Where the processing happens
Your data is stored on Amazon Web Services in eu-west-1 (Ireland). Model inference runs on Amazon Bedrock within the European Union: requests start in eu-west-1 and may be served from another EU region through Bedrock's EU inference profiles. They do not leave the EU. That is the provider in production today — if we change inference provider or move processing outside the EU, we will update this policy before the change takes effect.
What the app does not do
- No advertising SDKs and no advertising identifiers.
- No tracking of you across other companies' apps or websites.
- No sale of personal data, and no sharing of it for advertising.
Deleting accounts and data
Your Sky account belongs to your employer, not to you, so your workspace administrator is the person who can remove it. Where we are the controller — account, device, and diagnostic data — you can exercise your erasure right with us directly. Who can delete what, what is erased, what we must keep, and how long it takes are set out on our Account and Data Deletion page.
Who we share data with
We share personal data only with processors strictly necessary to run the site, the product, and our outbound process, under contracts that include Standard Contractual Clauses (SCCs) where applicable.
Sub-processors for the Sky platform and mobile app
- Amazon Web Services EMEA SARL (Luxembourg) — hosting and model inference (Amazon Bedrock), in eu-west-1, Ireland.
- Crash and performance diagnostics are processed inside our own AWS environment. If we engage a third-party error monitoring provider, we will name it here before it begins processing data.
The complete, authoritative list — including the website and outbound processors below — is maintained on our Sub-processors page, with a change history.
Processors for the website and outbound
- Vercel Inc. (USA) — hosting, edge delivery, product analytics.
- Google Ireland Ltd / Google LLC — Google Analytics 4 with IP anonymisation.
- Resend, Inc. (USA) — transactional email delivery for contact form replies.
- HubSpot, Inc. (USA / EU) — CRM for lead and account management.
- Instantly.ai — outbound email delivery for B2B prospecting.
- Calendly LLC (USA) — meeting scheduling. When you book a discovery call, Calendly receives your name, email address, time-zone, and any answers you give to booking questions.
We never sell personal data, and we do not share it for advertising purposes.
International transfers
Data in the Sky platform and the Sky by SkyFirst app is stored in the European Union (AWS eu-west-1, Ireland). Model inference also runs in the European Union, and may be served from another EU region — see section 04.
Some of the website and outbound processors above are established outside the European Economic Area, principally in the United States. Where personal data is transferred, we rely on the EU–U.S. Data Privacy Framework where the recipient is certified, and otherwise on the European Commission's Standard Contractual Clauses (Decision 2021/914) plus additional safeguards as appropriate.
A copy of the safeguards in place can be requested at info@skyfirstlabs.com.
How long we keep data
Sky platform and Sky by SkyFirst
- Account data: for the life of the account, then 90 days.
- Conversations and business data: for the life of the workspace. Your employer controls this data and may set a shorter period.
- Database backups: 30 days, then overwritten.
- Application and security logs: 90 days.
- Infrastructure audit trail: 365 days in production. This records administrative actions on the infrastructure, not the content of your workspace.
Website and outbound
- Contact form submissions: up to 24 months after the last meaningful interaction, then deleted or archived under contract retention rules if a customer relationship was formed.
- B2B prospecting records: up to 24 months after the last contact attempt, or immediately on opt-out.
- Analytics: 14 months in Google Analytics, the shortest retention GA4 allows.
- Website server logs: up to 30 days unless required for incident investigation.
Your rights
Under Articles 15 to 22 GDPR you have the right to access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interest. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing already carried out.
To exercise any of these rights, write to info@skyfirstlabs.com. We respond within one month, which may be extended by two further months for complex requests.
You also have the right to lodge a complaint with the Portuguese supervisory authority, Comissão Nacional de Proteção de Dados (CNPD), or with the supervisory authority of your habitual residence.
Security
Data is stored on infrastructure protected by encryption in transit (TLS 1.2+) and at rest. Access to personal data within Sky First Labs is limited to staff with a need to know and is logged. We carry out regular reviews of vendors and access controls.
We will notify the supervisory authority and, where required, affected individuals of personal data breaches in accordance with Articles 33 and 34 GDPR.
Children
The site, the platform, and the app are intended for business users. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact us and we will delete it.
Changes to this policy
We update this policy when our processing changes or when the law requires it. Material changes are announced on this page with a new "last updated" date. Continued use of the site, the platform, or the app after a change means you have read the updated policy.
