Versioned document. This is the complete 2026-10-02-1 version. Its body will not change in place. Any later revision will have a new version and permanent URL. The permanent URL for this version is https://skyflo.ai/legal/dpa/2026-10-02-1.
- This addendum applies automatically when Skyflo processes personal data on behalf of a business customer. Accepting the Terms incorporates it; you do not need to sign anything.
- We process that data only to provide the Services as you configure and instruct them, and never to sell it, advertise with it or train AI models on it.
- Annex III lists every subprocessor with its purpose, location and the terms it works under. We give 30 days’ notice of a new one, and you can object and, if we cannot resolve it, end the affected Services.
- We tell you of a personal data breach affecting your data without undue delay, and within 48 hours of becoming aware of it.
- Two providers are not authorised under this version: Z.ai, whose terms do not offer equivalent processor commitments, and Apple, for customer mission notifications. Section 7.7 and Annex III, Part B say how each is kept away from your personal data.
1. Parties, scope and incorporation
1.1 Parties. This Data Processing Addendum (the “DPA”) is between Operantix Systems Private Limited (CIN U62010PN2026PTC252795), a private limited company incorporated in India with its registered office at Office No. 01, 1st Floor, Future One, S. No. 245/5/1, D.P. Road, Aundh, Pune, Maharashtra 411007, India, trading as Skyflo (“Skyflo”, “we” or “us”), and the organisation or individual that has accepted the Terms and Desktop Licence (the “Terms”) and uses the Services for business or professional purposes (“Customer” or “you”). Capitalised terms not defined in this DPA have the meaning the Terms give them.
1.2 Incorporation. This DPA applies automatically whenever Customer’s use of the Services involves Skyflo processing Customer Personal Data on Customer’s behalf. It is incorporated into, and forms part of, the Terms. Customer’s acceptance of the Terms, including electronically in the account console, is its acceptance of this DPA and, where section 13 applies, of the Standard Contractual Clauses and the other transfer terms that section incorporates. Acceptance of an earlier Terms version that did not incorporate this DPA is not acceptance of this DPA. Existing customers can accept the current Terms in the account console’s Privacy page. Accepting the managed content disclosure alone does not accept a new Terms version. No separate signature is needed. If Customer wants a copy signed by Skyflo for its records, it may ask at contact (at) skyflo.ai; a signed copy carries the same terms as this version and does not change them.
1.3 What this DPA does not cover. It does not apply to an individual who uses the Services only for personal purposes, or to personal data Skyflo processes as a controller (section 3.3).
1.4 What Skyflo does not process. Skyflo Desktop runs on Customer’s Mac. Mission records, repositories and files that stay on Customer’s own devices are not processed by Skyflo. Requests Customer sends to a model provider with its own key, and the repositories GitHub holds for Customer, are processed by those providers under Customer’s own agreements with them. Those providers are not Skyflo’s Subprocessors.
2. Definitions
- “Applicable Data Protection Law” means every law on the protection of personal data that applies to the processing under this DPA, including, where it applies: Regulation (EU) 2016/679 (the “EU GDPR”); the EU GDPR as it forms part of the law of the United Kingdom and the UK Data Protection Act 2018 (the “UK GDPR”); the Swiss Federal Act on Data Protection of 25 September 2020 (the “FADP”); India’s Digital Personal Data Protection Act, 2023 and the rules made under it (the “DPDP Act”), and the Information Technology Act, 2000 and the rules made under it; and United States state privacy laws, including the California Consumer Privacy Act as amended (the “CCPA”).
- “Authorised User” means a person Customer allows to use the Services under its account or organisation.
- “Customer Content” means the content Customer and its Authorised Users submit to, or generate through, the Services that Skyflo processes on Customer’s behalf, as Annex I describes.
- “Customer Personal Data” means personal data in Customer Content.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data while Skyflo or a Subprocessor processes it. It does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as blocked sign-in attempts, pings and port scans.
- “Subprocessor” means a third party Skyflo engages to process Customer Personal Data.
- “SCCs” means the standard contractual clauses for the transfer of personal data to third countries set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 and in force from 21 March 2022.
- “Controller”, “processor”, “data subject”, “personal data”, “processing” and “supervisory authority” have the meanings Applicable Data Protection Law gives them. They include “Data Fiduciary”, “Data Processor” and “Data Principal” under the DPDP Act, and “business”, “service provider”, “consumer” and “personal information” under the CCPA, as the context requires.
3. Roles
3.1 Customer is the controller of Customer Personal Data, or a processor acting for its own customer, who is then the controller. Skyflo is Customer’s processor or, where Customer is a processor, Customer’s subprocessor.
3.2 Where Customer is a processor, Customer confirms that its instructions, including its appointment of Skyflo and of the Subprocessors in Annex III, Part A, are authorised by its controller. Customer is Skyflo’s single point of contact, and Skyflo need not deal with that controller directly unless the law requires it.
3.3 Skyflo as a controller. Skyflo is a controller, not a processor, of the personal data it uses to run accounts, authentication, billing, security and fraud prevention, support administration and legal compliance, and of its own service records. Those records include the operational records of managed requests and Skyflo Cloud runs described in the Privacy Notice: identifiers, timestamps, models, usage, charges and outcomes, without the content of the work. The Privacy Notice governs that processing; this DPA does not.
3.4 Each party will comply with the Applicable Data Protection Law that applies to it in its role.
4. Processing on documented instructions
4.1 Skyflo processes Customer Personal Data only on Customer’s documented instructions, including with regard to transfers, unless a law to which Skyflo is subject requires otherwise. In that case Skyflo will tell Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
4.2 Customer’s documented instructions are:
- the Terms and this DPA;
- the configuration and choices Customer and its Authorised Users make in the Services, including the managed-content choice, the models they select or leave to Skyflo’s routing, each mission’s access mode, starting or moving a mission to Skyflo Cloud, connecting the Skyflo GitHub App, pairing a phone and choosing its notification settings; and
- any other reasonable written instruction Customer gives that is consistent with the Terms. An instruction that would change what the Services do, their cost or their security needs the parties’ agreement. If Skyflo cannot follow a written instruction, it will say so, and Customer may stop using the affected part of the Services.
4.3 Skyflo will tell Customer promptly if, in its opinion, an instruction infringes Applicable Data Protection Law. This does not oblige Skyflo to review Customer’s instructions for legal compliance.
4.4 Skyflo does not sell Customer Personal Data, use it for advertising, or use it to train or fine-tune generalised artificial-intelligence models, and it has not agreed to let any model provider use it to develop or improve that provider’s models. Skyflo may compile aggregated statistics about use of the Services that contain no Customer Content, as section 9 of the Terms describes.
4.5 Customer is responsible for the lawfulness of Customer Personal Data and of its instructions, for giving any notice and obtaining any consent the law requires, for the configuration section 7.7 asks for where Customer relies on this DPA, and for not submitting data the Terms exclude. The Services are not designed for special categories of personal data, criminal records data, protected health information, payment-card data or comparable regulated data, and Customer must not submit them.
5. Confidentiality
Skyflo ensures that every person it authorises to process Customer Personal Data is bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, and gives access only to people who need it to operate, secure and support the Services. Section 6 of the Terms also applies to Customer Personal Data.
6. Security
6.1 Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing and the risks to people, Skyflo implements the technical and organisational measures in Annex II.
6.2 Skyflo may change those measures as the Services and threats change, but not in a way that materially reduces the overall protection of Customer Personal Data.
6.3 Customer is responsible for the security of its own devices, accounts, credentials and connected systems, for the access modes it chooses, and for its own backups. What a mission holds can itself contain secrets: files a repository tracks, its unpushed history, and a mission’s conversation and tool output travel with a mission moved to Skyflo Cloud, as the Privacy Notice explains. Skyflo’s secret masking does not catch every secret.
7. Subprocessors
7.1 General authorisation. Customer gives Skyflo general written authorisation to engage Subprocessors. The Subprocessors authorised on the date of this version are listed in Annex III, Part A, with their purpose, location and the terms they process under.
7.2 Skyflo’s obligations. Skyflo engages a Subprocessor only under a written contract, which may be the Subprocessor’s standard terms, that imposes data protection obligations no less protective in substance than those in this DPA, as far as they apply to the service that Subprocessor provides. Skyflo remains responsible to Customer for each Subprocessor’s performance of those obligations as for its own.
7.3 Notice of a new Subprocessor. Skyflo will give Customer at least 30 days’ notice before a new Subprocessor processes Customer Personal Data, by email to the address on Customer’s account and by publishing a new version of this DPA at skyflo.ai/legal/dpa whose Annex III names the Subprocessor, its purpose, its location and the terms it processes under.
7.4 Right to object. Customer may object to a new Subprocessor on reasonable grounds relating to data protection by writing to contact (at) skyflo.ai within that 30-day period. Skyflo will discuss the objection with Customer in good faith and, where it can, offer a way to use the Services without the new Subprocessor processing Customer Personal Data, for example by leaving out the feature or model that uses it. If the parties do not resolve the objection before the new Subprocessor begins processing Customer Personal Data, Customer may end the affected Services, or the Terms, by written notice without penalty, and Skyflo will refund the fees Customer prepaid for the part of the current billing period after the end date, through the refund process in the Refund Policy.
7.5 Urgent replacement. Where Skyflo must replace a Subprocessor sooner, to protect Customer Personal Data, to keep the Services available, or because the Subprocessor stops providing its service, Skyflo may give shorter notice only where Applicable Data Protection Law and the SCCs permit it. Where the SCCs require the notice in section 7.3, Skyflo obtains Customer’s specific written authorisation before the replacement processes Customer Personal Data, or suspends the affected processing until that notice period ends. Customer’s rights under section 7.4 then run from the notice.
7.6 Removal. Skyflo may stop using a Subprocessor at any time without notice.
7.7 Providers not authorised in this version. Annex III, Part B lists providers that can receive content through the Services but that this version does not authorise as Subprocessors, because their terms with Skyflo do not currently meet section 7.2:
- Z.ai is not authorised for managed processing in this version. Its published terms do not establish the required breach notification, subprocessor, audit and transfer commitments. Skyflo excludes Z.ai from Auto and refuses pinned GLM requests and token counts before content is sent. Auto uses the remaining admitted OpenAI and Google models. Existing provider records remain available for rights and billing requests.
- Apple delivers notifications to a paired iPhone or iPad through the Apple Push Notification service. Its terms do not provide the processor commitments in section 7.2. “Title only” removes mission text but still sends the phone’s push token and mission, approval or question identifiers used to open the relevant work. It does not establish that no Customer Personal Data is sent. Customer must not send Customer Personal Data to Apple through these notifications. Choose “Title only” to remove mission text; if the remaining identifiers would themselves disclose Customer Personal Data, turn off every notification category in Skyflo’s Notifications settings on each paired phone. The settings must reach Skyflo’s service; hiding notifications in iOS alone does not prevent their transmission to Apple. If the settings cannot be confirmed, unpair the phone before using the affected missions. Phone access remains available with the notification categories turned off. Apple’s terms also prohibit notification content containing sensitive personal or confidential information belonging to an individual.
A feature choice or managed-content acceptance does not waive Skyflo’s obligations under this DPA or authorise a provider in Part B to process Customer Personal Data. Skyflo does not send Customer Personal Data to such a provider without the required commitments and transfer safeguards. A feature may be used for content outside this DPA only within its stated restrictions and the provider’s terms. Skyflo’s records name the provider of every managed request, and on request Skyflo will tell Customer which of its requests reached a provider in Part B. If Skyflo learns of a breach of security at a provider in Part B that affects Customer Content, it will tell Customer as section 9 provides for a Personal Data Breach. Skyflo will move a provider to Part A, by publishing a new version of this DPA, once that provider’s terms meet section 7.2.
7.8 A Subprocessor’s own subprocessors. Each Subprocessor in Annex III, Part A uses its own subprocessors under its terms with Skyflo and publishes their list, and some give notice of a change only by updating that list. Fly.io updates its list at least 30 days before a new subprocessor of its own processes Skyflo’s data, and gives Skyflo 10 days from that update to object. Skyflo follows those lists and tells Customer of each change by email to the address on Customer’s account, as soon as it can. To have Skyflo object to a change at Fly.io, Customer’s objection must reach Skyflo within 5 days of Skyflo’s email, so that Skyflo can raise it within Fly.io’s period; Skyflo then objects on Customer’s behalf. If the objection is not resolved, Customer may stop using Skyflo Cloud, or end the affected Services, with the refund section 7.4 provides.
8. Assistance with data subject rights
8.1 If Skyflo receives a request from a data subject about Customer Personal Data, it will not answer it, except to direct the data subject to Customer where Skyflo can identify Customer, and will pass the request to Customer without undue delay, unless the law requires otherwise.
8.2 Taking into account the nature of the processing, Skyflo assists Customer by appropriate technical and organisational measures, insofar as this is possible, to respond to requests to exercise data subject rights. Most mission content is on Customer’s own devices and under its control. Within the Services, Customer can bring a mission back from Skyflo Cloud, end a run, unpair a phone and delete its account. Where Customer cannot do something itself, Skyflo will, on Customer’s written request, locate, provide, correct or delete specific Customer Personal Data held in Skyflo’s own systems where that is technically feasible, and will tell Customer which provider processed a given managed request. Skyflo cannot directly retrieve or delete copies held in a provider’s systems. It will relay applicable return, deletion or restriction instructions, seek the provider’s assistance under its processor agreement, and tell Customer of any documented limitation or legally required retention (section 11.3).
8.3 Skyflo gives this assistance without charge, unless requests are manifestly unfounded, excessive or repetitive, in which case Skyflo may charge a reasonable fee agreed in advance.
9. Personal data breaches
9.1 Notice. Skyflo notifies Customer of a Personal Data Breach without undue delay, and in any event within 48 hours after becoming aware of it, by email to the address on Customer’s account. Skyflo becomes aware of a Personal Data Breach when it has a reasonable degree of certainty that a security incident has compromised Customer Personal Data, including when a Subprocessor tells Skyflo of one.
9.2 What the notice contains. To the extent Skyflo knows it: the nature of the breach, including the categories and approximate number of data subjects and records concerned; its likely consequences; the measures Skyflo has taken or proposes to take to address it and to mitigate its possible adverse effects; and a contact point for more information. Where Skyflo cannot provide all of this at once, it provides it in phases without undue further delay.
9.3 Assistance. Skyflo takes reasonable steps to contain, investigate and mitigate a Personal Data Breach, and gives Customer reasonable assistance and the information Skyflo has, so Customer can meet its own obligations to notify supervisory authorities, the Data Protection Board of India and data subjects. Customer decides whether to notify authorities and data subjects about Customer Personal Data, except where the law requires Skyflo to notify. Skyflo reports cyber security incidents to CERT-In as Indian law requires; that report does not replace notice to Customer.
9.4 Subprocessors. Skyflo cannot see inside a Subprocessor’s systems, so it learns of a breach there when the Subprocessor tells it. The terms of each Subprocessor in Annex III, Part A commit it to notify Skyflo without undue delay. The 48 hours in section 9.1 run from when Skyflo learns of the breach.
9.5 Skyflo’s notice of, or response to, a Personal Data Breach is not an acknowledgement of fault or liability.
10. Impact assessments and prior consultation
Taking into account the nature of the processing and the information available to it, Skyflo gives Customer reasonable assistance with data protection impact assessments and with any prior consultation of a supervisory authority that Applicable Data Protection Law requires for Customer’s use of the Services. Skyflo does so first through this DPA, the Privacy Notice, the Managed content disclosure and written answers to Customer’s reasonable questions.
11. Deletion and return
11.1 While the Services are in use. Skyflo keeps Customer Content only for the periods set out in section 10 of the Privacy Notice and summarised in Annex I. In particular, Skyflo does not store the content of managed requests; copies held for a paired phone, and the copy relayed from a mission in Skyflo Cloud, are deleted 30 days after they last changed and 7 days after the mission is archived; and a Skyflo Cloud checkpoint is deleted no more than 30 days after its mission comes back, is stopped or its run ends.
11.2 At the end. When Customer deletes its account, or the organisation’s account where the organisation is the Customer, or the Terms otherwise end, Skyflo deletes Customer Personal Data from its live systems within 30 days. Skyflo first destroys any machine still running a mission for Customer in Skyflo Cloud, and then deletes the records.
11.3 Copies that expire on their own schedule. Deletion from live systems does not immediately remove every copy. The following remain until they expire, and Skyflo does not use them in ordinary operation of the Services:
- Database backups. Skyflo’s independent encrypted backups of its account database expire within 35 days. Its database host keeps continuous backups for point-in-time recovery over the window it documents for Skyflo’s plan, which is 3 days and never more than 7 days on any of its plans. A backup cannot safely be edited to remove one customer’s records; backups are used only to recover the service.
- Copies providers keep under their own terms. OpenAI keeps abuse-monitoring logs of API requests, which can include content, for up to 30 days by default, and longer where the law requires or to protect its services or others from harm; its prompt cache is kept for at most 24 hours. Google logs prompts and responses to the paid Gemini API for 55 days to detect and prevent policy violations, keep its services secure and make disclosures the law requires. Fly.io must delete Skyflo’s data once Skyflo stops using its services, within the period its data processing agreement sets, which is no more than 90 days, and does not state how long it keeps data from a machine after Skyflo destroys it while Skyflo still uses its services. These are the providers’ default retention periods, not a waiver of a return, deletion or restriction right under Applicable Data Protection Law or the SCCs. Skyflo will seek the provider’s assistance with applicable instructions, verify its response and identify any documented retention exception; it will not certify provider deletion that remains unverified. The retention of providers in Annex III, Part B is described there.
- Retention the law requires. Where a law requires Skyflo to keep Customer Personal Data, Skyflo keeps only what is required, protects it under this DPA, and processes it only for that purpose.
11.4 Return or deletion. At the end of the Services, Customer may choose return of the Customer Personal Data Skyflo holds followed by deletion, or deletion without return. Customer can retrieve its Customer Content by bringing each mission in Skyflo Cloud back to its Mac, which returns the mission’s complete record, and by asking for its account export. Skyflo assists with that return before deletion under section 11.2. A request to delete an account is Customer’s instruction to delete its remaining data; Customer should request any return it needs first. Skyflo cannot return managed request content, which it does not store. Retention required by law is handled as section 11.3 provides.
11.5 Confirmation. Where the SCCs apply, Skyflo certifies deletion to Customer as Clauses 8.5 and 16(d) require, without requiring a separate request. For other processing, Skyflo will confirm in writing on Customer’s request that deletion under section 11.2 is complete. A confirmation identifies any copies still retained under section 11.3 and when they expire.
12. Audits and evidence
12.1 Documentation first. Skyflo makes available to Customer the information necessary to demonstrate compliance with this DPA and with Article 28 of the EU GDPR and the UK GDPR where they apply: this DPA and its annexes, the Privacy Notice, the Managed content disclosure, and written answers to Customer’s reasonable security and privacy questionnaires. Skyflo answers a questionnaire once in any 12 months, and additionally after a Personal Data Breach affecting Customer or where a supervisory authority requires it.
12.2 Certifications. Skyflo does not currently hold a third-party security certification or attestation report, such as ISO/IEC 27001 or SOC 2. If it obtains one, it may meet a request under section 12.1 or 12.3 by providing the report, subject to confidentiality.
12.3 Audits. Where the information under section 12.1 does not reasonably demonstrate Skyflo’s compliance with this DPA, or where Applicable Data Protection Law or a supervisory authority requires it, Customer, or an independent auditor it appoints that is bound by confidentiality and is not a competitor of Skyflo, may audit Skyflo’s compliance with this DPA. Customer gives at least 30 days’ written notice with a proposed scope. The audit takes place at a mutually agreed time during business hours in India, remotely where practical, no more than once in any 12 months, and without access to other customers’ data, to Subprocessors’ systems, or to anything that would compromise the security of the Services. Customer bears its own costs. If an audit needs more than two working days of Skyflo’s time, Skyflo may charge reasonable costs for the excess, agreed in advance.
12.4 Exceptions to the annual limit. The once-a-year limits in sections 12.1 and 12.3 do not apply after a Personal Data Breach affecting Customer, or where a supervisory authority, the Data Protection Board of India or a court orders an audit.
12.5 Subprocessors. Skyflo relies on each Subprocessor’s own audit reports, certifications and terms for evidence about that Subprocessor, and will share what it may.
12.6 Results. Audit information and results are Skyflo’s confidential information. Customer will give Skyflo a copy of any report. Skyflo will remedy any material non-compliance it confirms.
13. International transfers
13.1 Where processing happens. Skyflo is established in India. Its account service, database and model gateway are hosted in the United States, and each Subprocessor processes in the locations Annex III gives. Skyflo does not offer an India-only or customer-selected regional guarantee.
13.2 EU transfers. Where Customer’s transfer of Customer Personal Data to Skyflo is subject to the EU GDPR and is not covered by an adequacy decision, the SCCs apply, incorporated into this DPA by reference and completed as follows:
| SCCs item | Election |
|---|---|
| Modules | Module Two (controller to processor) where Customer is a controller. Module Three (processor to processor) where Customer is a processor. |
| Parties | Customer is the data exporter. Skyflo is the data importer. |
| Clause 7 (docking clause) | Included. |
| Clause 9(a) (use of sub-processors) | Option 2, general written authorisation. The data importer informs the data exporter of intended changes at least 30 days in advance, as sections 7.3 to 7.5 of this DPA provide. |
| Clause 11(a) (redress) | The optional language allowing data subjects to use an independent dispute resolution body is not used. |
| Clause 13(a) and Annex I.C (supervisory authority) | The competent supervisory authority identified by Clause 13(a): the authority responsible for Customer where it is established in the EU; otherwise the authority of the member state where its Article 27 representative is established, where required; or, where Customer is exempt from appointing a representative, an authority of a member state in which the affected data subjects are located. Customer’s account or written instructions identify that authority before the affected transfer where it cannot be determined from its details. |
| Clause 17 (governing law) | Option 1: the law of Ireland. |
| Clause 18(b) (forum) | The courts of Ireland. |
| Clauses 8.5 and 16(d) (return and deletion) | Customer has the choice of return followed by deletion, or deletion. Skyflo certifies deletion as those clauses require. Section 11 applies only to the extent consistent with those clauses, which prevail. |
| Clause 8.9 (audits) | Section 12 of this DPA applies to the extent it is consistent with Clause 8.9. |
| Annexes | Annex I.A and I.B: Annex I of this DPA. Annex I.C: as for Clause 13 above. Annex II: Annex II of this DPA. Annex III: Annex III, Part A of this DPA. |
| Signature and date | Customer’s acceptance of the Terms is each party’s signature of the SCCs, and its date is the date of the SCCs. |
13.3 UK transfers. Where the transfer is subject to the UK GDPR, the UK Addendum applies, incorporated by reference and completed as follows. Table 1: the parties and their details are as in Annex I, Part A. Table 2: the Approved EU SCCs, including the modules and elections in section 13.2. Table 3: Annex I, Annex II and Annex III, Part A of this DPA. Table 4: neither party may end the UK Addendum under its section 19. Where the UK Addendum applies, it prevails over section 13.2 for UK transfers.
13.4 Swiss transfers. Where the transfer is subject to the FADP, the SCCs apply as completed in section 13.2 with these changes: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers governed by the FADP; references to the EU GDPR are read as references to the FADP for those transfers; and references to “member state” are read to include Switzerland, so that data subjects habitually resident in Switzerland can bring proceedings in Switzerland under Clause 18(c).
13.5 Onward transfers. Skyflo makes onward transfers of Customer Personal Data to Subprocessors under their data processing terms, as Clauses 8.7 and 9 of the SCCs require where the SCCs apply.
13.6 Requests from public authorities. Where the SCCs apply, Clause 15 governs a request from a public authority for Customer Personal Data. For other transfers, Skyflo handles such a request the same way to the extent the law allows.
13.7 Other mechanisms. If a transfer mechanism in this section is invalidated, or a new adequacy decision or approved mechanism becomes available, the parties will rely on the mechanism that is then valid and cooperate in good faith to put it in place.
14. India
14.1 Where the DPDP Act applies, Customer is the Data Fiduciary and Skyflo is a Data Processor, and this DPA is the contract under which Customer engages Skyflo to process Customer Personal Data.
14.2 Skyflo processes Customer Personal Data only for Customer’s purposes and as this DPA provides; keeps the reasonable security safeguards in Annex II to prevent a Personal Data Breach; informs Customer of a Personal Data Breach under section 9 so that Customer can inform the Data Protection Board of India and each affected Data Principal; erases Customer Personal Data when Customer instructs it to, or when the Services end, under section 11; assists Customer with requests from Data Principals under section 8; and keeps records and logs of its processing for the periods Indian law requires.
14.3 Skyflo also maintains reasonable security practices and procedures as the Information Technology Act, 2000 requires, and keeps the ICT logs that CERT-In’s directions under that Act require for 180 days, in India. Those logs hold request and event records, not Customer Content. References to duties under the DPDP Act are commitments under this DPA; they do not state that any provision of that Act has commenced.
15. United States
15.1 Where the CCPA or another United States state privacy law with service provider or processor provisions applies, Skyflo is Customer’s service provider or processor, and Customer discloses personal information to Skyflo only for the limited and specified business purposes of providing the Services described in Annex I.
15.2 Skyflo will not sell or share personal information, as those terms are defined in the CCPA, including for cross-context behavioural advertising; will not retain, use or disclose it for any purpose other than the business purposes in this DPA, or outside the direct business relationship between Customer and Skyflo, except as the law permits a service provider; and will not combine it with personal information it receives from, or on behalf of, anyone else, or collects from its own interactions with a consumer, except as the law permits a service provider.
15.3 Skyflo complies with the obligations those laws place on it, and provides the level of privacy protection they require. Skyflo will tell Customer if it determines that it can no longer meet its obligations under them. Customer may then take reasonable and appropriate steps to stop and remedy unauthorised use of personal information, including by giving instructions under section 4 or by ending the Services. Customer may take reasonable steps to confirm that Skyflo uses personal information consistently with Customer’s obligations, through section 12.
15.4 Sections 5, 7, 11 and 12 give Customer the duty of confidentiality, the flow-down to Subprocessors, the deletion or return and the information and assessments those laws require of a processor. Skyflo will not attempt to re-identify de-identified data it receives from Customer. Skyflo certifies that it understands and will comply with the restrictions in this section.
16. Liability
To the extent permitted by the SCCs and by Applicable Data Protection Law, each party’s liability arising out of or relating to this DPA, including the transfer terms in section 13, is subject to the exclusions and limitations in section 17 of the Terms, and Skyflo’s liability under it counts towards the aggregate limit stated there. Nothing in this DPA limits either party’s liability to data subjects under the third-party beneficiary rights of the SCCs or the UK Addendum, or any liability that cannot be limited by law.
17. Term, changes and precedence
17.1 Term. This DPA applies for as long as Skyflo processes Customer Personal Data on Customer’s behalf, including after the Terms end, until deletion under section 11 is complete.
17.2 Precedence. The SCCs, the UK Addendum and the Swiss changes in section 13, where they apply, prevail over this DPA and over the Terms. On the protection of Customer Personal Data, this DPA prevails over the Terms, the Privacy Notice and the Managed content disclosure. A written agreement signed by both parties prevails over this DPA only where it expressly amends it, and never over the SCCs. Mandatory law prevails over all of these.
17.3 Changes. Skyflo will not edit this published version in place. A change is published as a new version at a new dated URL. A new version applies from its effective date where it only updates Annex III under section 7, or does not reduce the protection this DPA gives Customer Personal Data. Any other change applies to Customer only once Customer accepts it, for example by accepting a new version of the Terms that incorporates it; until then, the version Customer last accepted continues to apply.
17.4 Governing law. This DPA is governed by the law, and subject to the jurisdiction, that section 20 of the Terms provides, except that the SCCs are governed as section 13.2 elects and the UK Addendum by the laws of England and Wales.
17.5 Severability. If a provision of this DPA is unenforceable, it is limited to the minimum extent necessary, and the rest of this DPA continues.
18. Contact
Questions about this DPA, notices under it, objections to a Subprocessor and requests for a signed copy go to contact (at) skyflo.ai, or by post to the registered office below.
Operantix Systems Private Limited
Office No. 01, 1st Floor, Future One,
S. No. 245/5/1, D.P. Road, Aundh,
Pune, Maharashtra 411007, India
CIN: U62010PN2026PTC252795
Grievance Officer and data protection contact. Karan Jagtiani, Director, reachable at contact (at) skyflo.ai or by post at the address above.
Customer care and grievance telephone: +91 7020882073
Annex I. Description of the processing
A. List of parties
| Party | Details |
|---|---|
| Data exporter | The Customer: its name, address and contact person are those on its Skyflo account. Activities relevant to the transfer: its use of the Services. Role: controller (Module Two) or processor (Module Three). Signature and date: Customer’s acceptance of the Terms. |
| Data importer | Operantix Systems Private Limited, trading as Skyflo, Office No. 01, 1st Floor, Future One, S. No. 245/5/1, D.P. Road, Aundh, Pune, Maharashtra 411007, India. Contact: Karan Jagtiani, Director, contact (at) skyflo.ai, +91 7020882073. Activities relevant to the transfer: providing the Services. Role: processor (Module Two) or subprocessor (Module Three). Signature and date: Customer’s acceptance of the Terms. |
B. Description of the processing and transfer
| Item | Description |
|---|---|
| Categories of data subjects | Customer’s Authorised Users, staff and contractors, as they appear in Customer Content; and any other people whose personal data appears in the repositories, code, files, commit history, logs, data, instructions and conversations that Customer’s missions work with, such as Customer’s own customers, users and business contacts. In Voice Mode, the people audible in the session. |
| Categories of personal data | Whatever personal data Customer Content contains, which Skyflo does not select. Typically: names, usernames, email addresses and other contact details; commit author identities; identifiers and technical data in logs and test data, such as IP addresses; the content of messages, issues, comments and documents; and images and screenshots. In Voice Mode, audio and the live transcript go directly from the Mac to OpenAI. When a session opens, including a reconnect or voice change, bounded current-mission context may pass through Skyflo’s gateway to OpenAI. Reconnects and voice changes may also send up to 12 recent transcript lines, each at most 1,000 characters. One short line may describe what is open on screen. This context is masked for recognised secrets on the Mac; the gateway does not store it. |
| Sensitive data | None is intended. Customer must not submit special categories of personal data or the other data section 4.5 excludes. The measures in Annex II apply to everything Skyflo processes. |
| Frequency | Continuous, whenever Customer uses managed inference or Voice Mode, pairs a phone, runs a mission in Skyflo Cloud, or writes to support. |
| Nature of the processing | Receiving, relaying and transmitting managed requests to model providers and their responses back; holding the copies a paired phone needs and the requests it sends; storing Skyflo Cloud checkpoints and running a mission on a machine created for its run; fetching and pushing the mission’s repositories through the Skyflo GitHub App; sending notifications; backing up the account database; and deleting all of these. |
| Purpose | To provide the Services Customer asks for, as configured and instructed under section 4, and to secure and support them. |
| Duration and retention | For as long as Customer uses the Services, with each kind of Customer Content kept only for the period below, and then as section 11 provides. |
| Transfers to Subprocessors | To the Subprocessors in Annex III, Part A, for the purposes and in the locations stated there, for the retention periods below and their own stated retention. |
Retention of Customer Content in Skyflo’s systems, as section 10 of the Privacy Notice states it:
| Customer Content | How long Skyflo keeps it |
|---|---|
| Content of a managed request, and Voice Mode context relayed to OpenAI | Not stored. The gateway handles it only while relaying it. |
| Copies held for a paired phone, and the copy relayed from a mission in Skyflo Cloud | Deleted 30 days after they last changed, and 7 days after the mission is archived. Unpairing a phone deletes what was waiting for it, and removing a Mac deletes what that Mac shared. |
| Instructions, answers, approvals and messages sent to a mission from a phone, or from a Mac to a mission in Skyflo Cloud | Deleted 7 days after the mission applies or refuses them, or after they expire unanswered. |
| A mission’s machine and disk in Skyflo Cloud | Until its run ends and its work is saved. A mission with no activity for 7 days is stopped and its work saved. |
| Skyflo Cloud checkpoint contents | While the mission runs in Skyflo Cloud; then no more than 30 days after the mission comes back, is stopped or its run ends, and no more than a day for a checkpoint that was never completed. |
| Records of each checkpoint without its contents (including the names of files not carried), and Skyflo Cloud run records (the mission title and first instruction, repositories and branch, and a record of each push and pull-request action) | While Customer’s account is open. |
| Content Customer sends to support | Handled for that support purpose. |
| Everything above, after the account is deleted | As section 11 provides, including database backups for up to 35 days. |
C. Competent supervisory authority
As section 13.2 provides for Clause 13, and for Swiss transfers as section 13.4 provides.
Annex II. Technical and organisational measures
These are the measures the Services implement today. They describe how the product and its operation actually work; where a measure has a limit, the limit is stated beside it.
1. Keeping content where it belongs
- Agents run on Customer’s Mac unless Customer runs a mission in Skyflo Cloud. Mission content leaves the Mac only on a path Customer turns on: managed inference, a paired phone, or Skyflo Cloud.
- The managed path relays request content without writing it to Skyflo’s account database, operational logs or diagnostics. Skyflo keeps operational records about each request, not its content.
- A Skyflo Cloud checkpoint is built only from the mission record and its repositories. It does not read the Mac’s Keychain, model keys or sign-ins, GitHub or SSH credentials, or environment variables. It leaves out files the repository ignores, untracked files over 25 MB, submodule contents, and untracked files whose names look like credentials. That name screen does not read file contents and does not apply to tracked files or history.
- Recognised secret patterns are masked in mission history as it is recorded, and in managed requests before they are sent. Masking does not catch every secret or personal detail, and does not read text inside images.
2. Encryption
- Skyflo Desktop connects to the account service only over HTTPS. Skyflo’s control plane reaches Skyflo Cloud machines over HTTPS and secure WebSockets. The website and account console are served over HTTPS with HSTS.
- At rest, Skyflo relies on the encryption its providers apply: its database host states that its databases are encrypted with AES, and its backup storage encrypts stored objects. Skyflo does not add a separate layer of encryption of its own to checkpoints.
3. Access control
- Records in the account database are isolated by organisation with enforced row-level security. The application connects with a restricted role, separate from the role that changes the database schema.
- A checkpoint can be read only by the device that wrote it, the device or machine that currently holds its mission, or the one it is reserved for, and only on behalf of the person the mission belongs to. Other members of the same organisation cannot read it.
- Skyflo offers no password sign-in. Device signing keys are generated in the Secure Enclave where the Mac, iPhone or iPad supports it, every linked device can be revoked, and sensitive account actions require reverification.
- The credentials that pay Skyflo’s model providers exist only in the model gateway, and an automated check in Skyflo’s build keeps them out of every other service. Every managed request is individually authorised and bound to the device that asked for it.
- Access to production systems and the account database is limited to the people who operate the service, for operating, securing and supporting it.
4. Skyflo Cloud
- Each run gets its own virtual machine, created for that run. The virtual machine is the boundary between one customer’s missions and every other customer’s. Automatic stopping and bringing a mission back save its work before its machine is destroyed. If saving fails, Skyflo keeps the machine and the work, retries the save, and reports the delay. Once the work is saved, Skyflo destroys the machine and keeps retrying until destruction succeeds. A machine that has done no work may be destroyed without a checkpoint. Customer may instead instruct Skyflo to end a run or delete its account without saving a new checkpoint; the Privacy Notice explains the resulting loss of unsaved work.
- Network access from the machine is denied except to Skyflo’s account service, its model gateway and public package registries. GitHub is not reachable directly.
- The machine holds no model provider key, no GitHub App private key or GitHub token, no credential that can manage machines, and no database credential. It holds only credentials for its own run: a device key that identifies it as that mission’s runner, a device token that lasts 10 minutes, and model-gateway grants that last at most 15 minutes, all usable only while that run holds the mission.
- Git goes through a Skyflo service outside the machine that uses a GitHub token limited to one repository and one kind of operation, valid for at most an hour, and allows pushes only to the mission’s own branch. Pushes to the default branch or any other branch, tags, deletions and merges are refused, and so is any push that changes files under .github/workflows or .github/actions, or an action.yml or action.yaml at the repository’s root. The GitHub token used for a cloud run has no permission to change workflow files.
- Inside its machine a mission runs with Full access, and nothing inside the machine separates the agent from the programs it runs: code it runs, including a dependency’s install script, can read what the machine holds and use that run’s access to managed models and to Git. That access is limited to the one run as described above.
5. Logging and monitoring
- The account service and model gateway do not write request content to their logs, and error reports are written to exclude prompts, code, tool output, credentials and provider payloads.
- Skyflo keeps a record of every managed request, including the provider and model that processed it and its outcome, which supports security review, billing and rights requests.
6. Backup and recovery
- The account database is backed up daily to separate storage, where each backup is locked against deletion and change for 34 days and then expires. Each backup run checks that the copy is intact and that no backup older than 35 days remains. The database host also keeps point-in-time recovery backups over the window in section 11.3.
7. Software integrity
- Production services are deployed from container images pinned by digest. Skyflo Desktop is signed and notarised through Apple before release. Changes pass automated tests and code scanning before release.
8. People and incidents
- People authorised to process Customer Personal Data are bound by confidentiality (section 5).
- Personal Data Breaches are handled and notified under section 9. Cyber security incidents are reported to CERT-In as Indian law requires.
9. Certifications
- Skyflo does not currently hold a third-party security certification or attestation report (section 12.2).
10. Subprocessors
- Each Subprocessor works under data processing terms that meet section 7.2, recorded in Annex III, Part A. Providers whose terms do not are listed in Part B, with what Customer must do to keep Customer Personal Data away from them.
Annex III. Subprocessors
Part A. Authorised Subprocessors
| Subprocessor | Purpose | Data it processes | Location | Terms |
|---|---|---|---|---|
| Render | Hosts Skyflo’s account service, model gateway and account database, and the database’s point-in-time recovery backups | Managed request content and Voice Mode context passing through the gateway; copies and requests held for a paired phone; Skyflo Cloud checkpoints, run records and relayed copies | Oregon, United States | Render Data Processing Addendum, part of Render’s Terms of Service |
| Fly.io | Runs the machine for each mission in Skyflo Cloud | Everything that mission holds while it runs there: its restored checkpoint, its repositories, and what its agents read, write and produce | Any country where Fly.io operates; Skyflo does not choose a region | Fly.io Data Processing Addendum, signed by Skyflo on 30 September 2026, incorporating the 2021 EU Standard Contractual Clauses. Fly.io’s own subprocessors: fly.io/legal/sub-processors |
| Cloudflare (R2 storage) | Stores Skyflo’s independent daily database backups, for up to 35 days | What the account database held when each backup was made | Western North America | Cloudflare Data Processing Addendum, part of Cloudflare’s self-serve subscription agreement |
| GitHub (Actions) | Runs the daily job that copies the database backup to storage and checks that it can be restored | A transient copy of that backup, while the job runs | Where GitHub runs its hosted runners | GitHub Data Protection Agreement |
| OpenAI | Model provider for managed inference with OpenAI models, for Voice Mode, and for missions in Skyflo Cloud that use Codex | Managed request content, Voice Mode audio, transcript and context, and pseudonymous identifiers | The United States and the other countries where OpenAI and its sub-processors operate | OpenAI Data Processing Addendum, part of the OpenAI Services Agreement |
| Google (Gemini API, paid tier) | Model provider for managed inference with Gemini models | Managed request content | Any country in which Google or its agents maintain facilities | Google’s Data Processing Addendum for Products Where Google is a Data Processor, which applies to Gemini API paid services |
| Google (Workspace) | Skyflo’s email, including support correspondence | Whatever Customer chooses to send Skyflo by email | Google’s facilities | Google Cloud Data Processing Addendum, part of the Google Workspace terms |
Part B. Providers not authorised under this version
| Provider | Role | Status of its terms | What Customer does |
|---|---|---|---|
| Z.ai, operated by JINGSHENG HENGXING TECHNOLOGY PTE. LTD. (Singapore) | Model provider for the GLM models in Skyflo managed inference. Skyflo refuses every managed request and token count for them, and, unless it records a clearance first, removes them from managed inference at 00:00 UTC on 9 November 2026. Z.ai generally processes in Singapore, states that it does not store API content, and can cache part of a recent request to serve a repeated one. | Its published terms and Data Processing Addendum for API Services do not commit it to notify a personal data breach, list its subprocessors or give notice of new ones, allow audits, or use a named transfer mechanism. | No action is required to exclude Z.ai: Skyflo blocks both pinned requests and token counting, and Auto uses other admitted providers. |
| Apple | Delivers notifications to a paired iPhone or iPad through the Apple Push Notification service. | The Apple Developer Program License Agreement governs the service and does not provide the processor commitments in section 7.2. | Choose “Title only” to remove mission text. It still sends push and mission identifiers and does not make notifications anonymous. If those notifications would disclose Customer Personal Data, turn off every category in Skyflo’s Notifications settings on each paired phone, as section 7.7 provides; phone access remains available. |
Not Subprocessors
Providers that Skyflo uses only for data it controls, such as Clerk for sign-in, Vercel for the website and account console, Amazon Web Services for Skyflo’s security-log archive in Mumbai, India, Sentry for error reports, Better Stack for availability monitoring, and Dodo Payments as merchant of record, are described in section 9 of the Privacy Notice and are not given Customer Content. The security-log archive keeps request and event records for 180 days, never prompts, code, model content, transcripts or credentials. A mission in Skyflo Cloud can download packages from public package registries, which receive the machine’s requests under their own terms. Model providers Customer uses with its own key, and GitHub as the host of Customer’s repositories, act under Customer’s own agreements with them (section 1.4).