Skemy privacy notice
Faithful translation of
privacy-it.md(the Italian text is the drafting baseline). Text adopted by the owner as a self-managed position (blockers C, D, A, E, F, T, G, H, N, 2026-09-27); it is not an external legal validation.
Version: effective from 2026-09-28
1. Who processes the data
Skemy is offered by Marco Caporali, a natural person, named as controller of the processing relating to the management of their users and of support requests.
Postal address: Via Enrico Malatesta 26, 56121 Pisa, Italy. Privacy contact for exercising your rights, usable without an account: privacy@skemy.eu.
No data protection officer (DPO) has been designated: the current processing does not fall within the cases where designation is mandatory (GDPR Art. 37). For any data question use privacy@skemy.eu.
For personal data you enter in projects, organisations, the client registry and libraries while processing it for your own activity (as an organisation or as a professional, including in a personal project), you or your organisation are the controller and Skemy acts as processor under the Data Processing Agreement (DPA) annexed to the Terms of use. Data-subject requests about these data are forwarded to the controlling customer. Skemy remains controller of its own processing described in this notice: accounts and sign-in, evidence of acceptance of the Terms, support, security, registers and legal obligations. When Skemy acts on the customer's instructions as processor or sub-processor, the customer keeps its own responsibilities and notices; this notice does not replace them.
2. Scope and source of the data
This notice covers the website www.skemy.eu, the web application app.skemy.eu and the desktop applications for macOS and Windows. Data may be provided directly by you, entered by an authorised administrator or collaborator of your organisation, or generated technically by the use of the features. Project contents may relate to other people, for example customer contacts, designers or people shown in files.
You must be at least 18 years old to create a Skemy account (Terms of use, §1). At sign-up we ask only for a declaration to that effect: we do not collect your date of birth and the declaration itself is not stored; the version of the Terms you accepted is recorded. Skemy can be accessed from any country, in Italian and English, and is also intended for consumers; it is not assumed that every user is a professional.
3. What data we process
- Account: email, password managed by the authentication service (not stored by Skemy in clear text), user and session identifiers, confirmation and access-recovery events. The profile may contain first name, last name, phone and job title.
- Acceptance of the Terms of use: accepted version, date and time recorded by the server, method (sign-up or in the app).
- Organisations and clients: members and roles; registry and business data and contacts of the organisation and of its clients (for example company name, VAT number/tax code, certified email (PEC), registered office, contact persons, email, phone, notes, logos).
- Projects and libraries: technical content created or imported: devices, cables, drawings, title blocks (including designers' names), notes, operational status, network data entered in the project, device libraries and templates. IP addresses, MAC addresses and host names in projects are design content: Skemy does not automatically detect your computer's network.
- Collaboration and history: authors, identifiers, dates, revisions, change proposals and actions; presence in the project (device and session identifier, role, active view). The author name may be your email address when no name is available.
- Files: uploaded drawings and logos, original name, type, size and technical references; DWG files are converted by a dedicated service. Commissioning photos and attachments stay on the device; their metadata may travel with the cloud project.
- Support: category, title and text of the request, reference, status, date and account; technical diagnostics only if you choose to attach them (section 6).
- Traffic and operation: technical metadata of requests to the website, authentication, synchronisation, files and updates (for example IP address and HTTP headers needed for transport); technical logs of the services within the limits of section 4.
We found no advertising, marketing pixels, newsletters, payments, sale of data, profiling or automated decisions with legal effects in the code, nor external product-analytics or crash-reporting tools. In the operational configuration too, we use no web analytics or client-side performance measurement tools (such as Cloudflare Web Analytics): Cloudflare processes only the technical data needed to provide and protect its infrastructure. We take no decisions based solely on automated processing and do no profiling.
4. Purposes, legal basis and retention
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Creating and managing accounts, access, profile, security emails | Account, profile | Performance of the contract (GDPR Art. 6(1)(b)) | Until the account is closed; no deletion for inactivity. We carry out a closure request within 30 days. Copies in the providers' backups disappear with their normal rotation (§8). |
| Keeping evidence of acceptance of the Terms | Version, date, account | Performance of the contract (Art. 6(1)(b)) while the account exists; after closure, legitimate interest (point (f)) in documenting the relationship and establishing, exercising or defending legal claims | After closure we keep only minimal evidence (Terms version, time of acceptance, technical identifier of the former account, time of closure; no email, name or profile data) for as long as needed to document the relationship and to establish, exercise or defend legal claims within the applicable limitation periods; reviewed periodically. |
| Cloud saving, libraries, projects, files and conversion, collaboration | Content and metadata | Customer content: Skemy processor on behalf of the controlling customer (DPA). No processing of this content by Skemy for its own purposes beyond the other rows (account, security, support) | While the project or account exists. Deleting a project removes it from the database at once; its files are removed from storage by a check run at least every 14 days, so normally within 30 days. Shared project history: §8. Backups: until they rotate (§8). |
| Handling support requests | Text and request data, correspondence | Performance of the contract (point (b)) for support to users; legitimate interest (point (f)) in replying to non-users; legal obligation (point (c)) for data-subject requests and their record (GDPR Arts. 12–22) | Normally 12 months from the last relevant communication, reviewed periodically; longer only where needed for a dispute, a legal claim, a security matter or a regulatory matter, and only for that purpose. |
| Analysing optional diagnostics | Fields shown in the preview | Consent (point (a)), given by ticking the optional box, which is not pre-ticked; can be withdrawn (§6) | As the request they are attached to; deleted earlier if you withdraw consent (§6). |
| Security, reliability and abuse prevention | Logs, events, metadata | Legitimate interest (point (f)) in network and information security, abuse prevention and service integrity; incident register: legal obligation (point (c), GDPR Art. 33(5)) | Conversion service logs: 7 days; file service logs: not kept; logs of account emails sent: 30 days (provider); database, authentication and network logs: per the providers' rotation. Security incident register: only what is needed to document incidents and handle any follow-up, reviewed periodically. |
| Delivery of the app and its updates | Request metadata | Performance of the contract (point (b)) to provide the app and updates; legitimate interest (point (f)) in secure delivery | Request metadata per Cloudflare's log rotation. |
Email, password and the declaration that you are at least 18 are needed to create the account: without them you cannot register. First name, last name, phone and job title are optional; if missing, collaborators may see your email address as your name. To get support we need the text of the request and the data to record it; diagnostics are optional and you can ask for help without them. We do not use a single blanket consent for all processing.
Where we rely on legitimate interest, we do so to protect Skemy and its users (security, abuse prevention, service integrity) and to be able to document the relationship and defend our rights.
5. Data on the device and synchronisation
Skemy saves on the device (browser or app storage) projects, caches, recovery copies, revisions, libraries, templates, commissioning attachments, support drafts and preferences. A local-only project is distinct from a project linked to the cloud: when you save it to or link it with the cloud, the relevant content and metadata are transmitted and synchronised. Cloud drawings and DWG conversion involve sending the files to the dedicated services.
Signing out closes the session but does not delete the projects, caches, recovery copies, libraries, drafts and preferences saved on the device, nor the files you exported. Revoking cloud access prevents new access but does not withdraw copies already downloaded or exported. On a shared device, export what you want to keep and then use "Remove Skemy data from this device" ("Rimuovi i dati di Skemy da questo dispositivo") on the Account page (section 10).
6. Support and diagnostics
When you send a request, we transmit to support the text you write, the category, your account and the data needed to record it. The form does not attach copies of your projects, library or files. Do not enter passwords, keys, other people's data or unnecessary details.
If you choose to attach diagnostics, we send exactly the values shown in the preview: app version and type, operating system (category), language and window size, connection, synchronisation and update status, format versions, technical counters and the app's latest errors. A filter removes addresses, emails, paths, file names and codes from error messages, but a name or a project detail may remain: check the preview and, if it contains unnecessary information, do not attach it. The server accepts only the expected fields, with checked type and length.
The app's latest errors (at most 10, already filtered) are kept only in memory during the session, even before you choose to send them; they are not transmitted unless you attach them. Until a request is shown as sent, its text stays saved on the device, separately for each account, so you can resume it.
Diagnostics are optional: the box to attach them is never pre-ticked and you can send the request without them. You can withdraw consent for attached diagnostics at any time by writing to privacy@skemy.eu with the request reference: we delete them from the request, which otherwise stays unchanged, within the time limits in section 8. Withdrawal of consent does not affect processing already carried out.
7. Recipients and transfers
To operate Skemy we use the following providers, which process data on our behalf as processors:
- Supabase — authentication, database and realtime features. The service's database is hosted in the EU (Frankfurt, Germany).
- Cloudflare — hosting of the website and web app, content delivery, storage of files uploaded to projects (R2) and update distribution. Project files are stored in Eastern North America (Cloudflare's "ENAM" region), so not in the EU; requests may pass through Cloudflare's global network.
- Resend — sending account emails (address confirmation, password reset). Emails are sent from the EU (Ireland), but the service processes data mainly in the United States.
- Fly.io — DWG file conversion. Conversion runs in the EU (Paris, France); data the provider handles for its own service and support may be processed in the United States.
- Register.it — the privacy@skemy.eu and support@skemy.eu mailboxes, through which data requests and support correspondence pass. Its data centres are located in Italy and in other countries.
Each provider may in turn use sub-processors, including outside the European Economic Area (EEA). Within Skemy, only the controller (Marco Caporali) has access to support and data requests.
Members and collaborators of your organisation see content according to the organisation's and project's permissions.
Some of these services transfer data, or make it accessible, outside the EEA, in particular in the United States; not all data stays in the EU. In those cases the transfer relies on:
- Cloudflare and Resend: the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework (Implementing Decision (EU) 2023/1795) and the Commission's Standard Contractual Clauses;
- Supabase: the Standard Contractual Clauses included in its data processing agreement;
- Fly.io: the Standard Contractual Clauses included in its data processing agreement; the provider also participates in the EU-U.S. Data Privacy Framework;
- Register.it: an adequacy decision where applicable, otherwise the Standard Contractual Clauses (Module Three, processor to processor) entered into with the non-EEA sub-processor.
You can ask for information about these safeguards, and for a copy of them, by writing to privacy@skemy.eu. We do not sell data or use it for advertising.
8. Your rights and account closure
You can request access to and a copy of your personal data, rectification, erasure where applicable, restriction, objection and portability where the conditions are met, by writing to the privacy contact in section 1, even if you can no longer sign in. We normally reply within one month; where the law allows, this period may be extended, with reasons given to you. We may ask for proportionate identity verification. First name, last name, phone and job title can be corrected directly on the Account page.
Closing the account, ending the contract, archiving a client and deleting a project are different operations. When the account is closed we delete the account, the projects you own (except organisation projects transferred to another member), your personal libraries, your support requests and your organisation memberships; shared organisation data stays with the organisation, no longer linked to your account.
Closing the account does not rewrite the history of shared projects. The historical records of those projects (activity, revisions, versions and commissioning or verification data) keep, as recorded, the name or email under which you appeared as author and a technical identifier of the account, which after closure no longer matches any active account. We keep them for the continuity and integrity of the technical records shared with the other project participants and to be able to reconstruct who did what. This does not exclude your right to erasure: if you specifically ask for these data to be erased, we assess the request case by case and, where keeping them is not justified for those data, we anonymise or remove them; if we keep them, we explain the reasons to you in writing.
Right to object. Where processing is based on our legitimate interest (section 4), you can object at any time, on grounds relating to your particular situation, by writing to privacy@skemy.eu. We stop processing those data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the data are needed to establish, exercise or defend legal claims (GDPR Art. 21).
We carry out a closure request within 30 days. Files of deleted projects are removed from storage normally within 30 days. Copies in the providers' backups and logs disappear with their normal rotation (database backups are daily and currently kept for 7 days); if a backup is ever restored, we re-apply the deletions. After closure, the minimal evidence of acceptance of the Terms described in section 4 remains, together with the record of your request: for each data request we keep only what is needed to show how we handled it, follow up any complaint and re-apply a deletion after a restore (date, type, actions taken and, for closures, the account identifier and email), without copies of the data provided, reviewed periodically. We cannot remotely delete copies saved on devices or exported files.
You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or the competent supervisory authority and to seek a judicial remedy.
9. Security and changes
We use access controls on cloud data (per account, organisation and project) and temporary signed links for files. We do not promise absolute security or end-to-end encryption. Organisationally: only the controller accesses data for support, requests and security; accounts with providers are protected with multi-factor authentication; keys are not kept in the code; there is an incident procedure and register, daily database backups and a procedure to re-apply deletions after a restore. The measures are described in Annex 1 of the DPA.
We will publish changes to this notice with a new date and point them out in a way appropriate to their significance: significant changes are also notified to you by email and, where the product supports it, in the app. The notice does not require acceptance; if a change required new consent, we would ask for it separately.
10. Device storage and technical technologies
Skemy uses browser or app storage (localStorage, sessionStorage and IndexedDB) for the features you request. The website www.skemy.eu and the app do not set their own cookies and do not use advertising or analytics technologies.
| Group | Function and duration |
|---|---|
| Sign-in | Sign-in session (managed by the authentication service) and the "stay signed in" choice. With "Resta connesso" (stay signed in) it lasts until you sign out; without it, until the tab or app is closed. Signing out removes it; the "stay signed in" choice stays remembered |
| Projects, libraries and files | Local copies, file cache, templates, revisions and recovery copies; they remain until you remove them or delete the project |
| Collaboration | Random device identifier and tab identifier used for collaboration, synchronisation and history |
| Preferences | Theme, date format, quality, table views and rules, panels, recent and favourite projects, update preferences |
| Support | Drafts not yet sent |
To delete this data use "Remove Skemy data from this device" ("Rimuovi i dati di Skemy da questo dispositivo") on the Account page: it deletes Skemy's databases, settings and sign-in session from the browser or app and signs you out; it does not touch other sites' data, cloud data or files you exported. In a browser you can also clear the site data for app.skemy.eu in its settings. Uninstalling the desktop app may, depending on the system, not delete the app's local data: if you want it removed, use Skemy's function before uninstalling, or the system's cleanup tools. Deleting it also removes work and attachments kept only on the device: export first what you want to keep. Closing the account and deleting data from the device are separate operations.
The authentication, security and functionality technologies described above are used to provide the features you request and therefore do not require prior consent; we do not display a cookie banner for those technologies.
Cloudflare Network Error Logging (NEL).
On www.skemy.eu, app.skemy.eu and releases.skemy.eu, Cloudflare currently
continues to send the NEL and Report-To headers. Where supported by the
browser, these headers may cause technical connectivity and network-error
reports to be sent to Cloudflare. Those reports may include technical
request and connection metadata such as URLs and referrers, HTTP method and
protocol, status and error type/phase, timing information and network
information; Cloudflare may also derive information such as ASN, country and
approximate geographic area from the client IP address.
Skemy does not use these reports for advertising, profiling or behavioural analytics. Network Error Logging is an infrastructure-level Cloudflare feature that we have disabled in our settings; however, at the time this notice is published, the related headers remain observable on some Skemy domains and we have opened a support request with Cloudflare.
Accepting the Terms of use does not amount to consent to optional technologies.