[ Legal ]
Data processing agreement
How we process the personal data in your Skein workspace for you, as GDPR article 28 requires. It is part of the terms of service: you accept it when you reserve or subscribe, with nothing else to sign.
Effective 3 October 202601Parties and roles
- The customer (“you”) is the controller of the personal data in its workspace.
- Carlos Martínez, a self-employed professional in Spain (NIF 49424598J) (“we”) is the processor, and processes it only to provide Skein.
This agreement is part of the terms of service. Where the two differ on personal data, this agreement prevails.
02Details of the processing
| Subject and purpose | Hosting your mail, calendars and contacts, and running the Skein agent on them |
|---|---|
| Duration | While the service runs, and until deletion after it ends |
| Nature | Storage, indexing, search, sending and receiving mail, and analysis by the agent to draft replies and propose actions |
| Personal data | Email messages and attachments, headers and addresses, contacts, calendar events, account and usage data |
| Data subjects | Your users, and the people they correspond with |
| Special categories | Not intended, but may appear in mail content; protected by the same measures |
03Your instructions
We process personal data only on your documented instructions: these terms, your settings, and the rules you give the agent. If we think an instruction breaks data protection law, we tell you. If the law makes us process data otherwise, we tell you first unless the law forbids it.
04The agent and AI providers
Your mail is never used to train AI models: not by us, and not by our AI providers.
- The agent acts only on your instructions and the autonomy rules you set; you can pause it at any time.
- It never writes to new recipients or adds attachments without a person’s approval.
- Email content is treated as data, never as instructions; the agent does nothing automatic on mail that fails authentication or looks like phishing.
- AI providers process content only to answer each request, with no retention for training, under contracts at least as strict as this one.
05Confidentiality and access
- Everyone who can access personal data is bound by confidentiality.
- Our team sees the content of your workspace only with a grant from your admins, for 7 days at most, and every access is logged.
06Security measures
- Encryption in transit (TLS) and at rest.
- Each organization’s data is isolated in the database by row-level security.
- Least-privilege access for staff and systems, with strong authentication.
- Logs and error reports never contain email bodies, tokens or secrets.
- Backups encrypted and kept in the EU.
- Mail authentication (SPF, DKIM, DMARC) and abuse controls on outgoing mail.
07Subprocessors
You authorize the subprocessors in the subprocessor list. We email you 30 days before adding or replacing one. You can object on reasonable data protection grounds; if we cannot resolve it, you can end the service and we refund any prepaid period not used.
Each subprocessor is bound by data protection terms at least as strict as these, and we remain responsible for it.
08International transfers
Your workspace is hosted in the EU. Where a subprocessor or its parent company is outside the EU, the transfer relies on the EU–US Data Privacy Framework or the Standard Contractual Clauses, with the supplementary measures the subprocessor list states.
09Helping you comply
- We help you answer requests from data subjects (access, deletion, export…), mostly through the app’s export and deletion tools, and reply to requests you send us within 30 days.
- We help with data protection impact assessments and consultations with authorities, with the information we have.
10Personal data breaches
We notify you without undue delay, and within 48 hours of becoming aware of a breach that affects your data, with what we know, the likely consequences and the measures taken. We keep you updated as we learn more.
11At the end of the service
You can export your data at any time. After the service ends we keep it for 30 days so you can export it or come back, then delete it, including copies, except where the law requires us to keep something.
12Information and audits
We give you the information needed to show compliance with this agreement. You can audit it, or have an independent auditor do it, with reasonable notice, once a year or after a breach, without access to other customers’ data. Write to info@skein.email.