Privacy Policy

Effective date: August 25, 2026

This Privacy Policy explains how SkimOrg ("SkimOrg," "we," "us"), maintained by compilerflow.com, collects, uses, and protects information when you visit this website, submit our contact form, or use the SkimOrg portal application and its CRM, ticketing, and AI chat features.

1. Information We Collect

We collect the following categories of information:

  • Contact form data: name, email address, company name, and any message you submit through this website.
  • Account & workspace data: when you sign up through our portal, we (via the portal application) collect account details, organization information, and the content you create in tickets, CRM records, and chat conversations.
  • CRM tracking data: this website loads a lightweight tracking script from our portal to identify visits and support lead capture for the CRM add-on. This may record page visits and basic device/browser information.
  • Usage & log data: IP address, browser type, and pages visited, collected automatically for security and reliability purposes (e.g. rate-limiting form submissions).

2. How We Use Information

  • To respond to inquiries submitted through the contact form;
  • To provide, maintain, and improve the SkimOrg platform;
  • To power AI-assisted features (see Section 3);
  • To detect, prevent, and investigate fraud, abuse, or security incidents;
  • To comply with legal obligations.

3. AI Processing

SkimOrg's AI chat and automation features are powered by large language model providers. Depending on which provider your workspace administrator has configured, this may include DeepSeek, OpenAI, Anthropic, or Google (Gemini). When you use these features inside the portal, relevant workspace content (such as message text, ticket details, or CRM records referenced in your request) is transmitted to the configured provider to generate a response.

OpenAI, Anthropic, and Google's API/enterprise tiers state that data submitted through their API is not used to train their models by default. DeepSeek's data handling practices differ, and data sent to DeepSeek may be processed on servers outside the UK/EEA/US. If your workspace is configured to use DeepSeek, this applies to the content you send it. Workspace administrators can change which provider is used.

4. Google Workspace Data & Limited Use

If you connect your Google account to enable Gmail and Calendar features, SkimOrg's use of that data adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail and Calendar data is used only to provide the specific features you've enabled, such as drafting or sending email and scheduling events on your behalf. It is never sold, and it is never used to develop, improve, or train any AI/ML model, whether foundational, generalized, or belonging to any of the third-party providers described in Section 3.

5. Cookies & Similar Technologies

This website itself does not set non-essential cookies. It does load a CRM lead-capture script (see Section 1) that records page visits and contact-form submissions - but only after you accept via the cookie banner shown on your first visit; if you decline, the script never loads. A local storage entry recording your choice is itself essential to remembering it, and is set regardless of your answer. The portal application separately uses an essential session cookie to keep you signed in, which does not require consent under applicable law.

6. Sharing & Disclosure

We do not sell personal data. We share information with: (a) subprocessors that host our infrastructure or provide AI processing, under contractual confidentiality obligations; (b) law enforcement or regulators where required by law; and (c) a successor entity in the event of a merger, acquisition, or asset sale, subject to the same protections described here.

7. International Data Transfers

Our infrastructure is currently hosted in the United States. If you are located in the United Kingdom, the European Economic Area, or another jurisdiction with data transfer restrictions, your information will be transferred to and processed in the United States. We are working to put a recognized transfer safeguard in place with our infrastructure provider (such as Standard Contractual Clauses) and are evaluating hosting your data within the UK/EEA directly. This section will be updated to name the specific mechanism, or confirm regional hosting, once finalized. Separately, if your workspace is configured to use DeepSeek for AI features (see Section 3), content you send to it may be processed outside the UK/EEA/US under DeepSeek's own data handling terms.

8. Data Retention

We do not retain personal data beyond what's needed to provide the Service. Contact form submissions are retained only as long as necessary to respond to your inquiry. Account and workspace data is retained for as long as your organization maintains an active subscription. You can delete your account and its associated data at any time from within the portal (Settings), which takes effect immediately - you do not need to wait for us to act on a request.

9. Your Rights

Depending on your location, you may have rights under data protection law (including the EU/UK General Data Protection Regulation, or GDPR, where applicable) to access, correct, export (data portability), or delete (erasure) personal data we hold about you, and to object to or restrict certain processing. To exercise these rights, submit a request through our contact form. We will respond within one month of a verified request, extendable by a further two months for complex requests, as permitted under applicable law. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

Within the portal application itself, account holders can exercise the export and erasure rights directly and immediately from Settings, without needing to submit a request.

10. Security

We apply industry-standard technical and organizational measures to protect information from unauthorized access, alteration, or disclosure, including TLS encryption in transit and AES-256 encryption of sensitive fields at rest. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above, and where appropriate, communicated through the portal or by email.

12. Contact Us

For privacy questions or data requests, reach out via our contact form.