1. Who we are
This Privacy Policy explains how Automatinator, operating the Skoowad product (together, “Skoowad”, “we”, “us”, or the “Company”), collects, uses, discloses, and otherwise processes personal data in connection with https://skoowad.io, https://app.skoowad.io, and related services (the “Service”).
For personal data we control (for example, website visitors, account holders’ billing contacts, and our own marketing), Automatinator is the data controller. For Customer Content that organizations upload or connect into a Skoowad workspace, we generally act as a processor (or equivalent service provider) on the Customer’s documented instructions, and the Customer is the controller. See Roles.
Privacy requests: privacy@skoowad.io
Support: support@skoowad.io
Legal: legal@skoowad.io
This Policy should be read with our Terms of Service. If you do not agree, do not use the Service.
2. Scope
This Policy covers:
- the public marketing website and contact channels;
- accounts, workspaces, trials, and paid subscriptions;
- integrations you connect, including Google, Microsoft, Slack, Cal.com, and ClickUp;
- AI features;
- payments processed by Stripe;
- support, security, and service operations.
It does not cover Third-Party Services you use outside Skoowad (for example, your own Google Workspace admin console). Those providers have their own policies. Automatinator professional-services engagements may involve additional processing described in a proposal, statement of work, or data processing addendum.
3. Roles: controller and processor
When we are controller. We decide the purposes of processing for: website analytics we operate (if any), account authentication on our side, billing records, security logs, abuse prevention, product communications, and improving the Service at a company-wide level using de-identified or aggregated data.
When we are processor. Your organization decides why candidate files, employee hours, CRM records, emails, calendar events, interview recordings, and similar workspace data are processed. We process that Customer Content to provide the Service, on your instructions, and as described in the Terms. If you need a data processing addendum (DPA), email privacy@skoowad.io.
Authorized Users who are employees or contractors of a Customer should generally contact their employer or the workspace administrator to exercise rights in Customer Content. We may redirect individual requests to the Customer where we are the processor.
4. Personal data we process
Depending on how the Service is used, we may process:
Account and organization data
- name, email address, password hashes, role, organization name;
- invite records, seat usage, plan tier, trial and subscription status;
- authentication data, including session cookies and, if enabled, passkeys / WebAuthn credentials and multi-factor authentication configuration;
- profile and appearance preferences.
Billing data
- payment method metadata, tax information, invoices, and subscription identifiers processed by Stripe (we do not store full card numbers);
- business contact details associated with an Order.
Workspace and Customer Content
- organization structure, assignments, checklists, hours, schedules, reports, comments, files, and similar operational records;
- CRM, sales, recruitment, onboarding, and candidate information you enter or import (which may include CVs, notes, interview outcomes, and contact details);
- interview recordings, transcripts, and evaluation materials you choose to upload;
- content generated in the Service, including AI drafts you keep.
Connected-account data
- OAuth tokens, account email, and the provider data you authorize (mail metadata and content, calendar events, Slack workspace identifiers, Cal.com bookings, ClickUp tasks, and similar);
- configuration such as selected “from” addresses and calendars.
Technical and usage data
- IP address, device and browser type, timestamps, URLs, diagnostic logs, security events, and approximate location derived from IP;
- cookie identifiers and local storage preferences (see Cookies).
Support and communications
- emails you send us, support tickets, and related attachments.
We do not require special-category data (such as health, religion, or biometric templates for identification) to use Skoowad. If you submit such data, you must have a lawful basis and you do so at your own risk. Passkeys use public-key cryptography; we store credential IDs and public keys, not fingerprint or face images.
5. How we collect data
- Directly from you, when you browse the website, create an account, complete onboarding, pay, or contact us.
- From Authorized Users acting for a Customer.
- From Third-Party Services you connect, according to the scopes you approve.
- Automatically, through cookies, logs, and similar technologies.
- From payment and infrastructure providers (for example Stripe confirming a payment).
6. Purposes and legal bases (GDPR / UK GDPR)
Where the EU or UK GDPR applies, we process personal data on the following bases. More than one basis may apply.
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the Service | Accounts, workspaces, features you enable, hosting Customer Content | Contract (Art. 6(1)(b)); processor instructions for Customer Content |
| Billing and accounts | Trials, subscriptions, invoices, collections | Contract; legitimate interests; legal obligation (tax) |
| Security and abuse prevention | Authentication, logs, fraud, malware, service integrity | Legitimate interests; legal obligation |
| Communications | Service notices, security alerts, support | Contract; legitimate interests |
| Marketing | Product emails where permitted | Consent where required; otherwise legitimate interests with opt-out |
| Improve the product | Aggregated usage, debugging, feature design | Legitimate interests; consent for non-essential cookies where required |
| Legal | Establish, exercise, or defend claims; comply with lawful requests | Legal obligation; legitimate interests |
| AI features you invoke | Generating plans or drafts from prompts you submit | Contract; processor instructions for Customer Content |
Our legitimate interests include operating a secure SaaS business, improving reliability, and communicating with customers, balanced against individuals’ rights. You may object as described in Your rights.
7. Google user data and Limited Use
Google API Services User Data Policy. Skoowad’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Why we request Google access
Customers and users may connect Google accounts to use Skoowad features that depend on Gmail, Google Calendar, or basic identity. We request only the scopes needed for the feature you start:
- Identity:
userinfo.email(and similar) to know which Google account was connected; - Calendar:
calendar.eventsto create, update, and delete events associated with Skoowad scheduling (for example HR or workspace events for connected users); - Gmail (organization connect):
gmail.send,gmail.readonly,gmail.compose, andgmail.settings.basicso the workspace can send, read, and compose mail through a mailbox you authorize, and use basic send-as / settings needed to operate that mailbox in product.
What Google data we access
Subject to the scopes you grant, this may include:
- Google account email address;
- OAuth refresh and access tokens, stored encrypted at rest where implemented;
- Calendar event fields needed to sync Skoowad-generated or Skoowad-managed events (times, titles, attendees, descriptions you set in Skoowad);
- Gmail message content, headers, threads, drafts, and labels to the extent required to send outreach or operational mail, continue a thread, show delivery status, or otherwise perform the mailbox feature you enabled;
- basic mailbox settings required for send-from configuration.
How we use Google user data (Limited Use)
We use Google user data:
- solely to provide and improve user-facing features that are prominent in the Skoowad interface and that you choose to use;
- to maintain, secure, and troubleshoot those features;
- to comply with law and Google’s policies.
We do not:
- sell Google user data;
- use Google user data for serving advertisements;
- use Google user data to train, improve, or develop generalized AI or ML models;
- transfer Google user data to third parties except (i) as necessary to provide the user-facing features you requested (for example infrastructure subprocessors acting on our behalf), (ii) with your direction or consent, (iii) for security, fraud, or abuse prevention, or (iv) as required by law;
- allow humans to read Google user data unless: you have given affirmative consent for specific messages or data; it is necessary for security purposes (investigating abuse, spam, or technical issues); it is necessary to comply with applicable law; or the data is aggregated and used for internal operations and no longer associated with an identifiable Google user.
Sharing, retention, and deletion of Google user data
Tokens and synced artifacts are stored with our application database and related infrastructure. We retain them for as long as the connection is enabled and for a limited period afterward in backups. You can disconnect Google in Skoowad settings (where available) and also revoke access in your Google Account permissions. After disconnect or revocation, we will stop new API calls and delete or de-identify stored Google user data that is no longer needed to provide the Service, except where retention is required for security, billing, or legal obligations.
Independent security assessors, professional advisors, or authorities may receive access only under confidentiality and only as permitted by Limited Use and applicable law.
8. Microsoft, Slack, Cal.com, ClickUp, and other connectors
If you connect Microsoft Outlook or Outlook Calendar, we may process mailbox and calendar data under the Microsoft Graph scopes you approve (including mail send/read and calendar read/write) for the same operational purposes as the Google features: sending authorized mail and managing events you initiate in Skoowad.
If you connect Slack, we may read basic workspace and user identifiers and post messages to channels you authorize. If you connect Cal.com, we process booking data needed to confirm interviews or onboarding. If you connect or sync ClickUp, we may create or update tasks and custom fields that you map to Skoowad workflows (for example hours or hiring stages).
Each provider’s terms apply to your account there. Disconnect the integration and revoke the provider’s OAuth grant to stop new processing.
9. AI processing
Assignment planning, campaign drafts, classification, and similar features may send prompts and necessary context to model providers (including providers reached through the Vercel AI Gateway and OpenAI). That content can include personal data if you put it in a prompt or in records the feature reads.
We use AI providers as subprocessors to generate the requested output and operate the feature. We do not use Google user data to train generalized AI models. You should not paste secrets or unnecessary special-category data into prompts. You are responsible for reviewing AI Output before use, especially for hiring or legal documents.
10. Payments
Paid subscriptions and certain other charges are processed by Stripe. Stripe processes payment-method and transaction data as an independent controller or as our processor, depending on the context. See Stripe’s privacy policy. We receive limited payment metadata (for example last four digits, brand, tax location, subscription status) to provision the Service.
11. Recruitment, HR, and candidate data
When a Customer uses Skoowad for hiring or people operations, the Customer is responsible for privacy notices to candidates and employees, lawful bases, retention schedules, and responding to data-subject requests. We process that data as a processor.
If you apply to work at Automatinator or otherwise send us a CV for our own recruitment, we are the controller of that application data and use it to evaluate the application and related legal obligations.
12. Interview recordings and evaluations
Customers may upload or record interview media and store evaluations. That data can be sensitive in practice even when it is not a GDPR special category. Customers must obtain all required consents and provide notices before recording. Media may be stored in object-storage infrastructure we operate or contract (S3-compatible storage). Access is restricted to Authorized Users of that workspace and to personnel or subprocessors who need access to operate the feature, under the Limited Use-style human-access limits described for Google data where Google data is involved, and under confidentiality for other recordings.
15. Categories of subprocessors and infrastructure
We use service providers in these categories. The specific vendors may change.
- Application hosting and edge delivery: Vercel and related cloud infrastructure;
- Databases and object storage: PostgreSQL and S3-compatible object storage operated by us or our hosting providers;
- Payments: Stripe;
- Email delivery: providers such as Resend and/or connected customer mailboxes (Gmail or Microsoft);
- AI inference: Vercel AI Gateway and model providers such as OpenAI;
- Optional customer-connected tools: Google, Microsoft, Slack, Cal.com, ClickUp, as enabled by the Customer.
A current list of subprocessors is available on request at privacy@skoowad.io. We will not use a subprocessor in a way that violates the Google Limited Use rules for Google user data.
16. International transfers
We are associated with operations in Finland / the EU, but the Service and our providers may process data in the United States and other countries. Where we transfer personal data out of the EEA, UK, or Switzerland, we use appropriate safeguards, which may include the European Commission’s Standard Contractual Clauses, UK addenda, adequacy decisions, and supplementary measures as needed.
Connected Third-Party Services may transfer data under their own mechanisms (for example Google’s and Microsoft’s terms). You are responsible for assessing those transfers for your organization.
17. Retention
We retain personal data only as long as needed for the purposes described, including:
- Account and workspace data: for the life of the account and a reasonable period after closure so we can delete or export as described in the Terms;
- Billing and tax records: for the period required by bookkeeping and tax law (often several years);
- Security logs: for a limited period appropriate to incident investigation;
- Google and other OAuth tokens: until you disconnect, plus backup rotation;
- Backups: rolling windows after which data is overwritten.
Customers set retention for their own HR and candidate files as controllers. When we are instructed to delete Customer Content, we will do so from live systems within a reasonable period, subject to backups and legal holds.
18. Security
We implement technical and organizational measures designed to protect personal data, including transport encryption (HTTPS), access controls, session integrity, encryption of certain secrets (such as OAuth refresh tokens where implemented), and least-privilege administration. No method of transmission or storage is 100% secure. You are responsible for the security of your accounts, endpoints, and the Third-Party Services you connect.
Report suspected vulnerabilities or incidents to privacy@skoowad.io or support@skoowad.io. Please do not publicly disclose a live issue until we have had a reasonable chance to investigate.
19. Your rights (EEA, UK, Switzerland, and similar)
Subject to conditions and exceptions in applicable law, you may have the right to:
- access personal data we hold about you;
- rectify inaccurate data;
- erase data;
- restrict or object to processing;
- data portability;
- withdraw consent where processing is based on consent, without affecting prior processing;
- lodge a complaint with a supervisory authority.
To exercise rights, email privacy@skoowad.io. We may need to verify your identity. If we process the data only as a processor, we will refer you to the Customer or act on the Customer’s instructions.
If you are in the EEA, you may contact your local data protection authority, or the Office of the Data Protection Ombudsman in Finland (tietosuoja.fi). UK users may contact the ICO.
20. U.S. state privacy rights
If you are a resident of California or another U.S. state with a consumer privacy law (including, as applicable, the CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, OCPA, and similar), you may have rights to know, access, correct, delete, and opt out of certain processing, and not to be discriminated against for exercising those rights.
We do not sell personal information as “sale” is commonly defined, and we do not share personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for inferring characteristics beyond providing the Service. Authorized agents may submit requests as permitted by law, with proof of authority.
Submit requests to privacy@skoowad.io. We will verify and respond within the statutory period. You may appeal a denial by replying to our decision email.
21. Children
The Service is not directed to children under 16 (or under 13 where that is the applicable threshold), and we do not knowingly collect personal data from children. If you believe we have, contact privacy@skoowad.io and we will delete it. Customers must not use Skoowad to profile children except where they have an independent lawful basis and we have agreed in writing.
22. Automated decision-making
Skoowad does not make legally binding decisions about individuals solely by automated means. AI suggestions are assistive. Customers must not use the Service as the sole basis for hiring, firing, or similar decisions without human review. We do not perform profiling that produces legal effects on website visitors.
23. Do Not Track
Some browsers send Do Not Track signals. There is no consistent industry standard for responding to them. Our practices are described in this Policy. We do not track users across third-party websites for advertising.
24. Changes to this Policy
We may update this Policy from time to time. The effective date at the top will change. Material changes will be notified by posting on this page and, where appropriate, by email or in-product notice. Continued use after the effective date means you accept the updated Policy, except where consent is required by law for a new processing purpose.
25. Contact and complaints
Controller / operator: Automatinator, providing Skoowad at https://skoowad.io.
Privacy: privacy@skoowad.io
Support: support@skoowad.io
Legal: legal@skoowad.io
You also have the right to complain to a supervisory authority, in particular in the EEA member state of your residence, place of work, or of an alleged infringement.
