Privacy Policy
Last updated: · Effective Date:
This Privacy Policy explains how Skyone Technologies Pte Ltd (“Skyone”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal data in connection with our website at skyone.com.sg, our IT services (web hosting, business email, virtual machine servers, IT maintenance), and our Skyone AI Workspace platform (collectively, the “Services”).
We are committed to compliance with Singapore’s Personal Data Protection Act 2012 (PDPA). By using our Services, you acknowledge that you have read and understood this Policy.
- 1. Who We Are
- 2. Information We Collect
- 3. How We Use Your Information
- 4. Disclosure of Information & Sub-Processors
- 5. AI Workspace Data Flow Disclosure
- 6. Data Retention
- 7. Cross-Border Data Transfers
- 8. Security
- 9. Your Rights Under PDPA
- 10. Cookies & Tracking
- 11. Children’s Privacy
- 12. Changes to This Policy
- 13. Contact & DPO
1. Who We Are
Skyone Technologies Pte Ltd
Company Registration No. (UEN): 201228874G
Registered Address: Singapore (full registered office address available on request)
General enquiries: sales@skyone.com.sg
Technical support: support@skyone.com.sg
Phone: +65 8282 8043
Data Protection Officer (DPO): dpo@skyone.com.sg. The DPO oversees compliance with this Policy and PDPA, and is the point of contact for all data-related enquiries.
2. Information We Collect
2.1 Information you provide directly
- Account information: name, business email, phone number, company name, job title.
- Billing information: company billing address and tax details. Payment card details are processed and stored by Stripe; we do not retain card numbers.
- Communications: enquiries submitted via website forms, emails, support tickets, and call/chat records.
2.2 Information collected automatically
- Technical data: IP address, browser type, device type, operating system.
- Usage data: pages visited, timestamps, referring URLs, navigation patterns.
- Cookies and local storage: essential session cookies; we do not use third-party advertising or marketing cookies.
2.3 AI Workspace specific data
When you subscribe to the AI Workspace platform, we additionally process, on your behalf and on your documented instructions:
- Authorised user list (employee names, business emails) provided by you, the Customer.
- Conversation content entered by your authorised users, including prompts, AI responses, file uploads, and any custom knowledge base content.
- Usage metadata: model selected, token counts, conversation timestamps, login records.
For AI Workspace, you (the Customer) are the data controller and Skyone acts as your data intermediary (data processor) under PDPA. We process this data only as required to deliver the service and only on your documented instructions.
3. How We Use Your Information
We use information collected to:
- Provide, operate, secure, and maintain the Services;
- Process payments and prevent fraud (via Stripe);
- Send transactional communications (invoices, service updates, security notices);
- Respond to enquiries and provide technical support;
- Generate aggregated, de-identified analytics for service improvement;
- Comply with legal obligations (taxation, audit, lawful requests from authorities).
We do not sell your personal data; use AI Workspace conversation content to train AI models; or use your data for online advertising.
4. Disclosure of Information & Sub-Processors
We share personal data only with the following categories of recipients:
4.1 Sub-processors acting on our behalf
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe Inc. | Payment processing | Singapore / United States |
| Cloudflare Inc. | CDN, DNS, Cloudflare Tunnel for AI Workspace | Global (Singapore POP) |
| M1 Limited | Singapore data centre | Singapore |
| OpenRouter Inc. | LLM API routing for AI Workspace (default) | United States |
| Underlying LLM providers (OpenAI, Anthropic, Google, etc.) | Inference processing for AI Workspace prompts | Varies by provider |
| Transactional email services | Service notification emails only | Varies |
We execute Data Processing Agreements (DPAs) and, where necessary, Standard Contractual Clauses (SCCs) with sub-processors. A current sub-processor list is available on request.
4.2 Legal disclosures
We may disclose information when required by law, court order, or valid legal process, or to protect our rights, property, safety, or that of our users or others.
4.3 Business transfers
In the event of a merger, acquisition, or sale of substantially all assets, personal data may be transferred to the successor entity, subject to PDPA notification and the same protections under this Policy.
5. AI Workspace Data Flow Disclosure
When your authorised user submits a prompt within AI Workspace:
- The prompt and any attached files are transmitted via TLS to Skyone’s VM infrastructure in M1 Singapore data centre.
- The prompt is forwarded via TLS to OpenRouter (default), or directly to your chosen LLM provider if you have selected the Bring-Your-Own-Key (BYOK) option.
- OpenRouter routes the prompt to the underlying LLM provider (e.g., OpenAI, Anthropic, Google) for inference.
- The response returns via the same path.
- The full conversation (prompt + response + metadata) is stored in your dedicated MongoDB instance on Skyone’s VM in Singapore.
Important notes:
- LLM providers may temporarily process prompt content for inference. Under their published API/enterprise terms, providers do not use your data for model training.
- Some providers retain prompts for a limited period (typically up to 30 days) for abuse monitoring before deletion. Provider-specific commitments are available on request.
- For maximum data control, the BYOK option allows your AI Workspace to connect directly to your own API account with the LLM provider, bypassing OpenRouter.
- Conversation history is stored in your dedicated environment; you control retention via the admin panel and may export or delete data at any time.
6. Data Retention
- Account information: retained while your account is active, plus 90 days after termination.
- Billing records: retained for 7 years for tax and audit compliance, in line with the Companies Act and Income Tax Act.
- Service logs: retained for 12 months.
- AI Workspace conversation history: customer-controlled (configurable from 7 days to indefinite via the admin panel; default: 12 months).
- Backups: encrypted, retained for up to 30 days on a rolling basis.
After applicable retention periods, data is securely deleted or fully anonymised.
7. Cross-Border Data Transfers
Some sub-processors (e.g., Stripe, Cloudflare, OpenRouter, LLM providers) may process personal data outside Singapore.
We ensure such transfers are lawful by:
- Selecting providers operating in jurisdictions with privacy protection at a level comparable to PDPA (e.g., EU GDPR);
- Executing Data Processing Agreements and, where required, Standard Contractual Clauses;
- Contractually requiring providers to maintain a comparable standard of data protection.
For customers requiring strict in-Singapore inference, BYOK with Singapore-region LLM endpoints (e.g., AWS Bedrock Singapore, Azure OpenAI Singapore) can be configured on request.
8. Security
We employ industry-standard security measures:
- TLS 1.3 encryption for data in transit;
- AES-256 encryption for data at rest (MongoDB, backups);
- Role-based access control to administrative systems with multi-factor authentication;
- Network isolation per AI Workspace customer (separate Docker stacks, separate database instances, separate Cloudflare Tunnel endpoints);
- Regular vulnerability scanning, patching, and incident response procedures;
- Daily encrypted off-site backups for AI Workspace Business and Enterprise tiers.
In the event of a personal data breach affecting you, we will notify you and the Personal Data Protection Commission of Singapore (PDPC) within 72 hours, in accordance with PDPA breach notification requirements.
9. Your Rights Under PDPA
Subject to PDPA and applicable contractual obligations, you have the right to:
- Access — request a copy of personal data we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Withdraw consent — subject to contractual and legal obligations.
- Data portability — request export of your data in a machine-readable format. AI Workspace conversation export is available via the admin panel.
- Complain — lodge a complaint with the PDPC if you believe we have not complied with PDPA.
To exercise any right, contact our DPO at dpo@skyone.com.sg. We will respond within 30 days. We may charge a reasonable fee for access requests, in line with PDPA.
10. Cookies & Tracking
We use only essential cookies necessary for site functionality (session management, language preference). We do not use third-party advertising or tracking cookies. Browser localStorage may cache non-personal data, such as the OpenRouter model catalogue, for performance.
11. Children’s Privacy
Our Services are intended for businesses and are not directed to individuals under 16. We do not knowingly collect personal data from children. If we become aware of such collection, we will delete the data promptly.
12. Changes to This Policy
We may update this Policy to reflect changes in law, our Services, or our practices. Material changes will be notified via email to active customers at least 30 days before taking effect. The “Last updated” date at the top reflects the most recent revision.
13. Contact & DPO
For all privacy-related questions or to exercise your rights:
Data Protection Officer: dpo@skyone.com.sg
General support: support@skyone.com.sg
Phone: +65 8282 8043
Skyone Technologies Pte Ltd
Singapore (registered office address available on request)
See also: Terms of Service.