1. Who we are

SkyeConnex Inc. is a Canadian corporation headquartered in Ottawa, Ontario. For privacy-related inquiries, contact [email protected].

2. The data we collect

2.1 Account data

When you create a SkyeConnex account, we collect your email address, organisation name (where provided), and authentication metadata necessary to operate the account (hashed password, 2FA configuration, passkey identifiers).

2.2 File metadata

To operate the platform, we hold metadata about your files: filenames, sizes, frame counts, shard manifests, provider connexion identifiers, upload and access timestamps, audit-log events. We do not hold the content of your files in plaintext. File contents are encrypted client-side before any byte leaves your device.

2.3 Usage data

We log technical data necessary to operate the platform: IP addresses, user agents, request paths, response codes, error traces. This data is retained for incident-investigation purposes per the retention windows described below.

2.4 Marketing data

If you submit our contact form or subscribe to updates, we store the information you provide. We do not sell this data and do not pass it to third parties beyond infrastructure providers necessary to operate the service.

3. How we use it

To operate the platform, satisfy contractual obligations, comply with applicable law, communicate with you about the service, and improve the service. We do not use customer file metadata for model training, advertising, or analytics beyond aggregate usage measurement.

4. Where it lives

Operational platform data lives in PostgreSQL databases hosted in Canada by default. Production deployments serving non-Canadian customer cohorts may be hosted in EU or US regions, as configured per customer. Encrypted file shards live with the storage providers you select — SkyeConnex does not control or read those shards.

5. Your rights

Under PIPEDA, GDPR, UK-GDPR, CCPA, and other applicable regimes, you have rights to access, correct, delete, and port your data. Where you control your encryption keys (which is the default), deletion is a cryptographic operation as well as a metadata operation. To exercise any right, email [email protected].

6. Retention

  • Account data: retained while your account is active and for 30 days thereafter.
  • Audit log: retained per the compliance pack you have configured; minimum 12 months for SOC 2, GDPR, and PIPEDA pre-set packs.
  • Technical logs (IP, request traces): 90 days.
  • Marketing data: retained until you unsubscribe or request deletion.

7. Sub-processors

SkyeConnex uses a small number of operational sub-processors (database hosting, transactional email, telemetry). A current list is available on request to [email protected].

8. Changes

We may update this policy from time to time. Material changes will be notified via email to account holders. The "last updated" date at the top of this page always reflects the current version.

9. Contact

Privacy enquiries: [email protected]
General contact: [email protected]
SkyeConnex Inc., Ottawa, Canada.