Skeldy · EN
Data Processing Addendum
GDPR-compliant Data Processing Addendum forming part of the Terms of Service when Skeldy processes personal data on behalf of a customer.
Last updated · 14 August 2026
1. Subject matter and roles
This Addendum governs Skeldy's processing of Customer Personal Data on the customer's behalf. The customer is the controller; Skeldy SAS is the processor.
2. Categories of data and data subjects
- Data subjects — the customer's staff, managers, and authorised users. To these are added two populations the customer must take into account: people named on an imported schedule, even where they do not use Skeldy, and invited people who never accepted their invitation.
- Categories — identification (name, email, language), employment metadata (role, section, qualifications), schedule and availability data, time-off and swap requests, shift notes, AI assistant conversations, imported schedule documents, audit logs (privileged mutations, 13-month retention) and security logs.
- Signatory data — name, email, billing address, and VAT number, received from Stripe and retained by Skeldy inside the original billing event.
- Special categories (Art. 9 GDPR) — neither intended, nor requested, nor deliberately processed. One caveat all the same: the reason given for a time-off request is free text entered by the data subject and may receive health information. That field is readable by every manager in the organisation. The customer must instruct its teams to write no medical reason in it.
3. Duration and instructions
Processing lasts for the duration of the subscription, then until the effective deletion described in clause 10. Skeldy processes data only on the customer's documented instructions, including instructions given through the product UI and API. Use of an AI feature constitutes an instruction to transfer the data described in section 5 of the Privacy Policy.
A necessary clarification: apart from audit logs, purged at 13 months, no data is deleted automatically by the system when the subscription expires. Ending the processing requires a deletion request.
4. Sub-processors
Skeldy uses the sub-processors listed in section 4 of the Privacy Policy. That list names each AI inference provider, the task entrusted to it, and its country of establishment.
We notify customers of any new sub-processor at least 30 days in advance. Customers may object on reasonable grounds; if the objection cannot be resolved, the customer may terminate the affected service.
The list published on 13 August 2026 corrects an earlier list that was inaccurate. It names sub-processors already in production that had not been announced under the notice period set out above, in particular Moonshot AI, OpenAI, and Cloudflare. The right to object applies to this corrected list, from its effective date. The 30-day notice period applies to subsequent additions.
5. International transfers
Production data resides in the European Union, with Supabase (eu-central-1, Frankfurt) and Vercel (EU regions).
Three flows leave the European Economic Area. The first is network transit: Cloudflare, Inc., established in the United States, provides DNS, delivery in front of skeldy.com, and the routing of inbound email. Every HTTP request crosses its network before reaching our servers, which gives it access in transit to IP addresses, user agents, and the URLs requested; application content is encrypted in transit. The second is payment, with Stripe, in the United States. The third is language-model inference: with Moonshot AI, in the People's Republic of China, for schedule generation, rule interpretation, chat, and reading of photographed schedules; with OpenAI, in the United States, for text recognition on PDF documents.
The inference provider called is a deployment parameter, not a constant of the code. The split above describes the configuration in force as at the effective date of this Addendum; absent that parameter, the requests concerned would fall back to Google LLC's Gemini API. Any lasting change to this split constitutes a subsequent change of sub-processor and follows the notice period in clause 4.
The People's Republic of China is covered by no adequacy decision of the European Commission. The transfer to Moonshot AI relies on the Standard Contractual Clauses (Decision 2021/914), under the module applicable to a transfer from a processor to a sub-processor, supplemented by technical measures: encryption in transit, limitation of the fields transmitted to what the task requires, exclusion of sign-in credentials, of time-off request reasons, and of payment data. The relevant module of the SCCs is incorporated by reference into this Addendum.
These measures do not place the data beyond the reach of a requisition made under Chinese law. The customer is informed of this and takes it into account in its impact assessment. The exact detail of the fields transmitted is set out in section 5 of the Privacy Policy.
6. Security measures
- Encryption — TLS 1.2+ in transit, AES-256 at rest.
- Access — least-privilege role-based access, enforced in the database by RLS policies. Skeldy currently offers no two-factor authentication, neither for user accounts nor for administrative accounts in the customer dashboard: it is enrolled nowhere in the product. Earlier versions of this Addendum announced it as available; that was a capability of our authentication provider, not a measure in place here, and we are withdrawing it.
- Database — row-level security policies enforce hierarchy across every table.
- Logging — privileged mutations logged via in-database triggers, retained 13 months. The log records a copy of the row before and after modification, including on deletion.
- Storage of imported documents — schedule photos and PDFs are kept encoded inside the Frankfurt database, and not in a separate object store. No object storage bucket is used by the product.
- Application logs — our server function logs currently contain the calling user's email address on every AI request, together with staff names on the import path. They follow our hosting provider's retention rather than a period we set ourselves.
- Backups — provided by our database host under the plan subscribed, with a written recovery plan and documented restore commands. No restore drill has been carried out to date: the plan exists, putting it to the test remains to be done. We therefore do not present the restore as tested.
- Pen-test — no test by an independent third party has been carried out to date. The scope is drafted, an internal security review has been run and its findings addressed; the engagement with an external provider has still to be placed. Earlier versions announced an annual test: that was an intention, not a fact.
- Personnel — the team currently consists of its founder alone, the only person holding access to production data. No signed confidentiality undertaking therefore exists to date. Earlier versions of this Addendum announced such undertakings; that was the control planned for the first hire, not an existing document, and we are withdrawing it. Signing a confidentiality undertaking before any access remains the rule for every hire. The periodic security training programme is defined but has not yet been run; we will announce it when it has been, not before.
7. Assistance with data subject rights
Skeldy assists the customer in handling data subject requests, within 30 days. Contact [email protected].
Export and account deletion have been exposed as self-service in the settings since 13 August 2026. Earlier versions of this addendum announced them while no control was wired to them; that is no longer the case.
AI assistant conversations have been attached to their author since 14 August 2026: the export returns a data subject's own conversations to them, and deleting their account erases those conversations. Those written before that date record no author; they are neither exportable nor individually erasable, and no account can read them. Time-off requests they arbitrated are reduced to their identifier, status and date. A right of access must not serve to obtain a third party's data.
8. Personal data breach notification
We notify the customer without undue delay and at the latest within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data, with sufficient information to enable the customer's own GDPR Art. 33 / 34 obligations.
9. Audits
Customers may request audit information once per 12-month period. We currently respond with a completed security questionnaire, the documented inventory of our controls, and the findings of our internal security review. On-site audits are available where mandatory under applicable law and at the requesting party's expense.
We hold neither a SOC 2 report nor a third-party penetration test summary: SOC 2 Type 1 readiness is in progress and the penetration test has not been commissioned. Earlier versions of this Addendum offered those two documents as a means of satisfying an audit request; they do not exist and are withdrawn. They will be added to this list on the day they are issued, and we will inform the customers who have written to us to that end.
10. Return and deletion
On termination, the customer may export data for 30 days. After that period, Skeldy deletes Customer Personal Data on the customer's written request, within 30 days.
That deletion is currently a manual operation. No automatic mechanism erases a workspace when the subscription expires, and absent a request the data stays in the database. We write this down rather than announce a purge that does not exist.
What remains after deletion: audit logs for 13 months, including the record of the deletion itself and the copy of the erased rows; the invoices and receipts issued by Stripe, under the 10-year accounting obligation; names extracted from an imported schedule that were never matched to an account, held in shift notes, which we remove on targeted request. The detail is set out in section 7 of the Privacy Policy.
The technical log of Stripe webhooks is dealt with separately, because the earlier version of this Addendum wrongly placed it under the accounting obligation. That log serves to refuse the same event twice; as things stand it retains the complete payload received from Stripe, which may contain the signatory's name, email, billing address, and VAT number, and it carries no link to the organisation. The 10-year obligation covers accounting records, not that payload. We undertake to reduce this log to the identifier, type, and date of the event alone, and we delete the raw payload from it on the customer's written request.