Founder price · 100 spots leftReserve

[ Legal ]

Data processing agreement

How we process the personal data in your Skein workspace for you, as GDPR article 28 requires. It is part of the terms of service: you accept it when you reserve or subscribe, with nothing else to sign.

Effective 3 October 2026

01Parties and roles

  • The customer (“you”) is the controller of the personal data in its workspace.
  • Carlos Martínez, a self-employed professional in Spain (NIF 49424598J) (“we”) is the processor, and processes it only to provide Skein.

This agreement is part of the terms of service. Where the two differ on personal data, this agreement prevails.

02Details of the processing

Subject and purposeHosting your mail, calendars and contacts, and running the Skein agent on them
DurationWhile the service runs, and until deletion after it ends
NatureStorage, indexing, search, sending and receiving mail, and analysis by the agent to draft replies and propose actions
Personal dataEmail messages and attachments, headers and addresses, contacts, calendar events, account and usage data
Data subjectsYour users, and the people they correspond with
Special categoriesNot intended, but may appear in mail content; protected by the same measures

03Your instructions

We process personal data only on your documented instructions: these terms, your settings, and the rules you give the agent. If we think an instruction breaks data protection law, we tell you. If the law makes us process data otherwise, we tell you first unless the law forbids it.

04The agent and AI providers

Your mail is never used to train AI models: not by us, and not by our AI providers.

  • The agent acts only on your instructions and the autonomy rules you set; you can pause it at any time.
  • It never writes to new recipients or adds attachments without a person’s approval.
  • Email content is treated as data, never as instructions; the agent does nothing automatic on mail that fails authentication or looks like phishing.
  • AI providers process content only to answer each request, with no retention for training, under contracts at least as strict as this one.

05Confidentiality and access

  • Everyone who can access personal data is bound by confidentiality.
  • Our team sees the content of your workspace only with a grant from your admins, for 7 days at most, and every access is logged.

06Security measures

  • Encryption in transit (TLS) and at rest.
  • Each organization’s data is isolated in the database by row-level security.
  • Least-privilege access for staff and systems, with strong authentication.
  • Logs and error reports never contain email bodies, tokens or secrets.
  • Backups encrypted and kept in the EU.
  • Mail authentication (SPF, DKIM, DMARC) and abuse controls on outgoing mail.

07Subprocessors

You authorize the subprocessors in the subprocessor list. We email you 30 days before adding or replacing one. You can object on reasonable data protection grounds; if we cannot resolve it, you can end the service and we refund any prepaid period not used.

Each subprocessor is bound by data protection terms at least as strict as these, and we remain responsible for it.

08International transfers

Your workspace is hosted in the EU. Where a subprocessor or its parent company is outside the EU, the transfer relies on the EU–US Data Privacy Framework or the Standard Contractual Clauses, with the supplementary measures the subprocessor list states.

09Helping you comply

  • We help you answer requests from data subjects (access, deletion, export…), mostly through the app’s export and deletion tools, and reply to requests you send us within 30 days.
  • We help with data protection impact assessments and consultations with authorities, with the information we have.

10Personal data breaches

We notify you without undue delay, and within 48 hours of becoming aware of a breach that affects your data, with what we know, the likely consequences and the measures taken. We keep you updated as we learn more.

11At the end of the service

You can export your data at any time. After the service ends we keep it for 30 days so you can export it or come back, then delete it, including copies, except where the law requires us to keep something.

12Information and audits

We give you the information needed to show compliance with this agreement. You can audit it, or have an independent auditor do it, with reasonable notice, once a year or after a breach, without access to other customers’ data. Write to info@skein.email.

© 2026 Carlos Martínez · Skein

Questions: info@skein.email