Skemy Terms of use
Faithful translation of
terms-it.md(the Italian text is the drafting baseline). Text adopted by the owner as a self-managed position (blockers C, D, T, G, 2026-09-27; N for Annex B); it is not an external legal validation. Structure: Terms + Desktop annex + DPA, no separate EULA.
Version: 1.0 (2026-09-28) · Effective from 2026-09-28
1. Provider and users
Skemy is offered by Marco Caporali, a natural person, hereinafter the "Provider". The Provider operates as a natural person, with no sole-proprietorship registration, VAT number, registered office, certified e-mail (PEC) or company-register entry.
Contacts: support at support@skemy.eu; privacy and exercising your rights at privacy@skemy.eu. Address for communications and complaints: Via Enrico Malatesta 26, 56121 Pisa, Italy.
These terms apply to consumers and to professional customers. A consumer is anyone acting for purposes outside their professional activity under the applicable law; merely choosing a label in the account does not remove that status.
You must be at least 18 years old to create and hold a Skemy account. This requirement concerns the capacity to enter into these terms and to manage the account; it does not mean that Skemy contains adult-only content. At sign-up the user declares that they are at least 18; no date of birth is requested. Anyone under 18 cannot create an account on their own.
Skemy can be accessed from any country, in Italian and English. The Provider does not guarantee that its use is permitted in every jurisdiction: you must comply with the laws that apply to you, including restrictive measures (sanctions) and export-control rules. You may not use Skemy where the applicable law prohibits it; the Provider may restrict access where the law requires.
2. Service, requirements and formation of the contract
Skemy lets you design and document audio/video, network and integrated systems: schematics, cable schedules, racks, floor plans, device libraries, organisations, collaboration and commissioning. It is available on the web and as a desktop application for macOS and Windows. Some features require a connection, an account or the organisation's authorisation; DWG conversion requires cloud saving.
At launch Skemy is free: there are no prices, subscriptions, automatic renewals or other payments. Features are provided as currently available and may evolve. Current technical limits: 200 MB per uploaded file and 50 MB per project saved to the cloud; they may change for reasonable technical needs. System requirements and supported environments are set out in the technical documentation. No service level agreement (SLA) is provided.
The contract is formed when you create the account accepting these terms in the version shown; the Provider records the accepted version with date and time. These terms, including the DPA, can be read, downloaded and printed before acceptance and at any time from the page that publishes them. The privacy notice explains how data is processed: reading it is not consent to every processing operation.
3. Accounts and organisations
Provide correct information, protect your credentials and report suspicious access to the contact given. Use an account you are entitled to act for. Anyone who uses Skemy or accepts these terms on behalf of an organisation or a customer represents and warrants that they have authority to bind it to these terms and the DPA and to share data on its behalf.
Organisation owners and administrators manage members, roles, projects and permissions with the available features; an organisation always has at least one owner. Check the recipients before sharing. If you are the only owner of an organisation and want to close your account, you must first transfer ownership to another member or delete the organisation with the available features. Owners can delete an organisation after moving or deleting its projects; export first what you want to keep.
The Provider does not decide internal disputes of an organisation about ownership, members or access: it follows the ownership recorded in the service and the owners' instructions, and departs from them only when required by a binding order of a court or competent authority, by the law or by another mandatory obligation.
4. User content and intellectual property
The rights in your content remain with you or the respective rights holders. By uploading it you grant the Provider only the permissions needed to store, process, convert, synchronise, display and transmit it for the features you request, within these terms and the Data Processing Agreement (DPA), annexed to these terms and forming part of them, which applies when you process personal data as controller. No licence is granted for advertising, sale or training systems on your projects.
You must be entitled to use and share the data, drawings, photos, trademarks and documents you enter and respect the rights of the people concerned. Do not enter credentials or information not needed for the work.
Do not intentionally enter or use in Skemy: unlawful content; content that infringes third-party rights, such as intellectual-property or confidentiality rights; malware or other malicious code; special categories of personal data (GDPR Art. 9); data relating to criminal convictions and offences (GDPR Art. 10). Skemy is a technical and engineering tool, not designed to process those personal data: it does not technically prevent them from being entered and provides no measures for them beyond those described in the DPA.
The Skemy software, its interface and Skemy's own device catalogue belong to the Provider. Manufacturers' names and trademarks belong to their respective holders and are used only to identify the products. Catalogue information is for information only: check the relevant data against the manufacturer's documentation. Your drawings, projects and content remain yours or your customer's, subject only to the permissions needed to operate the service described above. Third-party components remain subject to their own licences, listed under "About Skemy › Third-party licences".
5. Permitted use and professional responsibilities
You may use Skemy for the documented features. You may not use it for unlawful activities, to infringe others' rights, to access content without authorisation, to spread malware, to compromise the service or to bypass access controls. Uses and exceptions that cannot be waived under the law remain unaffected.
Check imported data, scales, units, connections, calculations and results before operational use. Skemy is a design-support tool: on its own it is not acceptance testing, certification of an installation's compliance or a substitute for the professional's checks. This allocation does not exclude liability that cannot be waived or the software's conformity guarantees.
You can report content you consider unlawful or contrary to these terms by writing to support@skemy.eu, in Italian or English, stating where it is, why you consider it so and a contact address. The same address is the point of contact for authorities. The Provider examines reports diligently; if it restricts content or accounts, it gives reasons under section 9.
6. Cloud, collaboration, copies and exports
Local projects are kept on the device. When you save a project to the cloud, the relevant data is transmitted and synchronised; changes made offline wait and are sent when you are back online. Check the synchronisation status and any conflicts before considering a change available to collaborators.
The history identifies the author of changes and keeps revisions. Revoking access prevents future access to the service but does not withdraw local or exported copies already lawfully obtained. In the current flow, commissioning attachment files stay on the device that added them, while their metadata may synchronise: a collaborator might not receive all photos.
You can export your projects and libraries with the available features and keep copies. Synchronisation, a local copy and a restorable backup are different things. The Provider's backups serve to restore the service after failures or incidents: they are not a service for restoring individual projects and do not guarantee that a project can be recovered on request. Regularly export a copy of important projects. Backup retention is described in the privacy notice. No unlimited retention or SLA is agreed; legal obligations remain.
7. Support and availability
Support requests send the text you fill in and the data needed to record them; diagnostics are optional, shown in a preview and described in the privacy notice. You do not need to accept diagnostics to get support.
Support is provided by email at support@skemy.eu, on a best-effort basis, with no guaranteed response times. Planned maintenance is announced where reasonably possible and the service may be temporarily unavailable. We do not promise continuous availability or numeric response times. Limitations of the service do not derogate from consumer rights.
8. Updates
The Provider updates the web service. The desktop app may check for updates at start-up, according to the device preference; downloading and installing happen only on your action. Updates may be needed for compatibility with the cloud service: before important operations check saving and copies.
The latest version of the desktop app is supported; earlier versions may stop working with the cloud service and updating may be necessary. No minimum support period or permanent compatibility with earlier versions is guaranteed. Minimum system requirements are set out in the technical documentation. Updates required by law, including security updates, remain unaffected. Declining an update does not waive your rights.
9. Closure, suspension and termination
You can ask at any time for your account to be closed by writing to privacy@skemy.eu; the request is carried out within 30 days, as stated in the privacy notice. Before closure we tell you what happens to shared projects and to organisations of which you are the only owner (to be transferred or deleted), to libraries and to copies to export. Closure deletes the data described in the privacy notice; it does not delete the organisation's shared data or copies on devices or exported files.
The Provider may restrict, suspend or, in the most serious cases, end access to content or accounts for unlawful conduct, serious breaches of these terms, abuse, concrete security risks or where the law requires. The measure is proportionate. Unless it is urgent, necessary for security, prohibited by law or notice would defeat its purpose, the Provider informs you by email beforehand, giving reasons; you can clarify or object by writing to support@skemy.eu. If the measure is immediate, the reasons are given as soon as possible. During a suspension exporting your data remains possible, unless it creates a security risk, is prohibited by law or defeats the purpose of the measure. The service is free: no refunds are provided. No unlimited discretionary power of deletion is provided.
The contract has an indefinite duration and ends when the account is closed or in the cases provided in these terms. If the Provider discontinues the service, it gives notice by email and in the app, where available, at least 60 days in advance, unless urgent, security or legal reasons prevent it; during the notice period export remains available where technically and legally possible. You can export your data at any time with the service features, free of charge; no dedicated migration service is provided.
10. Consumers
If you are a consumer, the mandatory rights the applicable law gives you remain intact, including, where they apply, those on conformity of digital content and services, updates and remedies for defects or failure to supply. No label such as "preview", "beta", "release candidate" or similar reduces those rights.
At launch the service is free and personal data are processed only to provide it and for legal obligations, as described in the privacy notice. You can stop using Skemy and close the account at any time, free of charge. Registering, downloading or accepting these terms does not waive any right the law gives you.
11. Warranties and liability
The Provider is liable within the limits set by law and by the obligations undertaken. Nothing excludes liability that the law does not allow to be limited, including wilful misconduct and gross negligence, nor consumers' mandatory rights.
Skemy is a technical tool: it does not certify that projects are correct; they must be checked as set out in section 5. Except as the law requires, the Provider does not guarantee that the service is uninterrupted or error-free. For professionals no caps or exclusions of liability beyond those provided by law apply. No total exclusion for loss of data is introduced.
12. Changes to the terms and the service
The Provider may change these terms and the service for legal, security or technical reasons or as the service evolves. Material changes are notified to you by email and, where the product supports it, in the app, normally at least 30 days in advance, stating their nature and reason. When a change requires your acceptance, you are asked for it before continuing to use the service and the accepted version is recorded; if you do not accept it you can close the account at no cost. Non-material changes are published as a new version. New versions have a new version number. Changes do not retroactively remove rights already acquired; for consumers the legal conditions and remedies on changes to digital services apply. Continued use alone does not count as acceptance of a change that requires it.
13. Applicable law, disputes and documents
These terms are governed by Italian law. The choice of law does not deprive consumers of the mandatory protection of the law that would apply absent a choice. Mandatory rules on jurisdiction, including the consumer's forum, remain unaffected.
For disputes with professionals the Court of Pisa has exclusive jurisdiction, subject to mandatory rules. Complaints: support@skemy.eu or the address in section 1. The Provider has not committed to using alternative dispute resolution (ADR) bodies; if a consumer's complaint is not resolved, the Provider gives the consumer, where the law requires, on a durable medium the information on the competent ADR bodies, stating whether it intends to use them. The European ODR platform has been discontinued and is not referenced.
The Desktop annex supplements these terms for the installed software. The DPA, published together with these terms and accepted with them, governs the processing the Provider carries out as processor on the customer's behalf; the privacy notice describes processing and is not a licence on content. Mandatory rights prevail over any incompatible provision.
Desktop annex
Provider and contacts: section 1 of the Terms. Same version as the Terms.
A. Subject and permission to use
This annex concerns the Skemy application for macOS and Windows. The Provider grants a non-exclusive permission to install and use the software for the documented features, under the Terms. The licence is free of charge, non-exclusive and non-transferable, lasts for the duration of the Terms and of your account and allows personal and professional use. You may not redistribute, resell, sublicense, or modify and distribute the software without authorisation. No maximum number of installations is set.
The software remains the Provider's; you keep the rights in your content. Open-source components and third-party materials remain subject to their licences, viewable in the app under "About Skemy › Third-party licences", also without a connection. Exceptions that cannot be waived, permitted copies and interoperability provided by law are not limited.
B. Local data and connected services
The app keeps data in the local storage of its own web view and, for imports and exports, in the files and folders you choose. Cloud, collaboration and DWG conversion use the services described in the Terms and the privacy notice. Installation does not automatically upload projects to the cloud and not all features are available offline.
Signing out does not remove projects, caches and recovery copies from the device. Uninstalling the app is neither a request to close the account nor to delete data on the server and, depending on the system, may not delete the app's local data. To remove it, first use "Remove Skemy data from this device" ("Rimuovi i dati di Skemy da questo dispositivo") on the Account page, or the system's cleanup tools. Files you exported are not deleted.
C. Updates and compatibility
The update check at start-up is on by default and can be turned off on the Updates page; the request reaches the update distribution service described in the privacy notice. Downloading and installing happen only on your action; the app installs only updates whose signature is verified with the Provider's key.
The latest version of the app is supported; earlier versions may stop working with the cloud service. Minimum requirements and compatible versions are set out in the technical documentation; no minimum support period is guaranteed. Updates required by law remain unaffected.
D. Operational use, support and termination
Check the results before professional use, as provided in the Terms. The licence does not authorise any data collection beyond what the privacy notice describes.
When the contract ends or the account is closed, the licence linked to the account also ends: since the app requires sign-in, it can no longer be used with that account. Termination alone does not automatically delete the projects on the device; files exported earlier remain usable within the limits of their format. Export what you need before closing the account.
E. Common clauses
Warranties, liability, consumer rights, law and disputes are governed by the Terms, without duplication or less favourable derogation. Mandatory rights and the licences of third-party components remain unaffected.
Data Processing Agreement (DPA) — Skemy
Text adopted by the service owner as a self-managed position (blocker T, 2026-09-27); it is not an external legal validation. English translation of
dpa-it.md(the Italian text is the drafting baseline). It is published together with the Terms of use, of which it forms part, and shares their version. Basis: GDPR Art. 28; EDPB Guidelines 07/2020.
This agreement is annexed to the Skemy Terms of use and forms an integral part of them. By accepting the Terms, including in electronic form, the Customer accepts this agreement (GDPR Art. 28(9)).
1. Parties and scope
1.1. The controller is the Customer: the organisation or person that uses Skemy for its own activity and, in doing so, processes personal data as controller. Anyone accepting the Terms on behalf of an organisation declares that they have authority to bind it to this agreement.
1.2. The processor is the Provider named in the Terms of use (section 1).
1.3. This agreement applies whenever the Customer processes personal data as controller through Skemy, whether in an organisation workspace or in a personal project. It does not apply to processing by a natural person in the course of a purely personal or household activity, which is outside the GDPR (Art. 2(2)(c)).
1.4. "Customer Content" means projects and their data (devices, connections, cables, racks, floor plans, title block, issues, commissioning and verification data, attachments, history), uploaded files, organisation data, the client registry and device libraries, to the extent they contain personal data.
2. Processing the Provider carries out as an independent controller
The following processing, which the Provider carries out for its own purposes, is not covered by this agreement and is described in the privacy notice:
- account management, sign-in and security emails;
- evidence of acceptance of the Terms and contractual records;
- the support relationship with users (requests, optional diagnostics) and handling of data-subject requests addressed to the Provider;
- security, abuse prevention and technical logs;
- the Provider's own legal obligations, including the request and incident registers.
The Provider does not process Customer Content for its own purposes: it does not use it for advertising, profiling, sale or training systems. If it did, it would be the controller of that processing (GDPR Art. 28(10)).
3. Subject matter, nature, purpose and duration
3.1. Subject matter and purpose: providing the Skemy service to the Customer.
3.2. Nature: storage, synchronisation between devices and authorised users, sharing according to the roles set by the Customer, display, DWG file conversion, export, backup and deletion of Customer Content.
3.3. Duration: for as long as the Customer uses the service and afterwards until deletion under section 11.
4. Categories of data and data subjects
4.1. Data: identification and contact data (name, email, phone, role, company) of contacts, clients, installers, designers and members; names and references in drawings, title blocks, notes, issues and uploaded files; the attribution of activities (who created, changed, tested or verified); business data of the organisation and of the client registry.
4.2. Data subjects: the Customer's staff and members; the Customer's clients and their contacts; installers, suppliers and other people named in Customer Content.
4.3. Skemy is a technical and engineering service and is not designed for the intentional processing of special categories of personal data (GDPR Art. 9) or of data relating to criminal convictions and offences (GDPR Art. 10). The Customer does not intentionally include special categories of personal data (GDPR Art. 9) or data relating to criminal convictions and offences (GDPR Art. 10) in Customer Content. The service does not technically prevent such data from being entered and, for such data, provides no measures beyond those described in Annex 1. Any use of the service to intentionally process such data requires a prior review of the contractual scope, the risks and the safeguards.
5. Customer obligations and rights
The Customer: - is responsible for the lawfulness of its processing, its legal basis and the information given to data subjects; - enters only data it is entitled to process and that is necessary; - sets roles, sharing and access in the service; - gives instructions that comply with the law.
The Customer has the rights GDPR Art. 28 gives it, including those in sections 7, 12, 13 and 16.
6. Documented instructions
6.1. The Provider processes Customer Content only on the Customer's documented instructions. Documented instructions are: - the Terms of use and this agreement; - the Customer's use of the service features: creating, editing, sharing, roles, deletion and export; - the documented behaviour of the service accepted by the Customer, including the retention of the history of shared projects described in the privacy notice (section 8) and the deletion times in section 11.
6.2. Further instructions are given in writing to privacy@skemy.eu. If an instruction goes beyond the scope of the service, the parties agree how to carry it out.
6.3. The Provider informs the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other data-protection provisions.
6.4. If Union or Member State law requires different processing, the Provider informs the Customer beforehand, unless that law prohibits it.
7. Confidentiality
The Provider is a natural person and personally accesses Customer Content only when needed to provide the service, for support that was requested, or for legal obligations. Anyone authorised to access it in the future will be bound by confidentiality.
8. Security
The Provider takes the technical and organisational measures in Annex 1, appropriate to the risk (GDPR Art. 32), and updates them over time without reducing their overall level.
9. Sub-processors
9.1. The Customer gives general written authorisation for the sub-processors in Annex 2.
9.2. Before adding or replacing a sub-processor, the Provider informs the affected account holders by email at least 30 days in advance. The Customer may object in writing to privacy@skemy.eu within that period, giving reasonable grounds. The parties seek a solution; failing that, the Customer may stop using the feature concerned or close the account at no cost.
9.3. Notice may be shorter only where required by law, by urgent security needs or by circumstances outside the Provider's reasonable control; in those cases notice is given as soon as reasonably practicable, and the right to object remains.
9.4. The Provider imposes on each sub-processor data-protection obligations substantially equivalent to this agreement and remains liable to the Customer for the sub-processor's performance (GDPR Art. 28(4)).
10. Transfers outside the European Economic Area
Transfers to third countries take place only with the safeguards set out in Annex 2 (adequacy decisions or the European Commission's Standard Contractual Clauses). The Customer may request a copy at privacy@skemy.eu.
11. Deletion and return
11.1. The Customer may export its projects at any time (.skemy/JSON backup)
before deleting them or closing the account.
11.2. On termination, or when the Customer deletes a project, an organisation or the account: - database data is deleted immediately when the project is deleted; - account closure is carried out within 30 days of the request; - files of deleted projects are removed from storage normally within 30 days; - copies in the providers' backups and logs disappear with their normal rotation (database backups are daily and currently kept for 7 days); after any restore the deletions are re-applied.
11.3. Retention obligations under Union or Member State law remain unaffected. The Provider cannot delete copies saved on users' devices or files already exported.
12. Assistance with data-subject rights
12.1. The service gives the Customer features to view, correct, export and delete Customer Content.
12.2. If the Provider receives a request from a data subject concerning Customer Content, it forwards it to the Customer without undue delay and does not answer it on the merits, other than telling the data subject to contact the Customer.
12.3. The Provider carries out the Customer's decisions, including, if the Customer requests it, targeted removal or anonymisation of attribution in the history of the Customer's projects, through a documented manual procedure.
13. Assistance with security, breaches, impact assessments and consultations
Taking into account the nature of the processing and the information available to it, the Provider assists the Customer in meeting the obligations under GDPR Arts. 32–36: security, breach notification and communication, data protection impact assessment and prior consultation.
14. Personal data breaches
The Provider notifies the Customer without undue delay after becoming aware of any personal data breach affecting Customer Content, by writing to the email of the affected account holders or organisation owners. The notice contains, as far as available, the information in GDPR Art. 33(3), which may be provided in phases.
15. Compliance information
The Provider makes available to the Customer the information necessary to demonstrate compliance with GDPR Art. 28: this agreement, its annexes, a description of the security measures and, where available and shareable, the sub-processors' reports and certifications.
16. Audits and inspections
16.1. The Provider allows for and contributes to audits, including inspections, conducted by the Customer or by an auditor mandated by it and bound by confidentiality.
16.2. Audits are agreed with reasonable prior notice and carried out so as not to compromise the security of the service or other customers' data. Where appropriate, they start from the documentation and independent evidence in section 15; this does not exclude an inspection where these are not sufficient, where a supervisory authority requires it, or in the case of a suspected or confirmed breach or non-compliance.
16.3. Each party bears its own costs. The Provider may ask for reimbursement only of reasonable costs of extraordinary, repetitive or Customer-specific activities going beyond what the audit needs, and never for audits required by a supervisory authority or prompted by a suspected or confirmed breach or non-compliance by the Provider. Any reimbursement may not make the audit right theoretical or dissuasive.
16.4. For sub-processors' infrastructure, audits are normally carried out through the reports and certifications they make available.
17. Duration and precedence
This agreement remains in force as long as the Provider processes Customer Content. In case of conflict on data protection, it prevails over any other clause of the Terms of use. Mandatory rules remain unaffected.
Annex 1 — Technical and organisational measures
- Access control: every database read and write is filtered by row-level access rules per account, organisation and project; critical operations go through server-side functions that check permissions.
- Files: stored in a private container with no public access; downloaded and uploaded only via short-lived signed URLs (5 minutes for download, 10 for upload), issued after checking permissions on the project.
- Transmission: encrypted connections (TLS) to all services.
- Application: content security policy (CSP) for the web app; minimal permissions for the desktop app; desktop updates signed and verified before installation.
- Provider's accounts with its providers: multi-factor authentication on the database account; keys and secrets never included in source code.
- Staff access: only the Provider, a natural person.
- Backups: daily database backups with restore points; a procedure to re-apply deletions after a restore.
- Minimisation: no analysis, advertising or profiling of Content; temporary DWG conversion files are deleted after each job; technical logs contain identifiers and codes, not content.
- Incidents: internal incident-handling procedure and incident register.
Annex 2 — Sub-processors for Customer Content
| Sub-processor | Service | Customer data processed | Location | Transfer safeguards |
|---|---|---|---|---|
| Supabase | database, authentication, realtime synchronisation | projects, organisations, client registry, libraries, history, file metadata | database in the EU (Frankfurt, Germany); its sub-processors may process data outside the EEA | Standard Contractual Clauses in its data processing agreement |
| Cloudflare | file storage (R2), file service, app hosting | uploaded and converted files, request metadata | files in Eastern North America (Cloudflare's "ENAM" region), not in the EU; global network | EU-U.S. Data Privacy Framework adequacy decision (Implementing Decision (EU) 2023/1795) and Standard Contractual Clauses |
| Fly.io | DWG file conversion | DWG files and DXF result during conversion | conversion in Paris (France); provider's own data in the United States | Standard Contractual Clauses in its data processing agreement; participation in the EU-U.S. Data Privacy Framework |
| Register.it | privacy@ and support@skemy.eu mailboxes | support and data-subject-request correspondence concerning Customer Content | data centres in Italy and other countries | adequacy decision where applicable, otherwise Standard Contractual Clauses (Module Three) with the non-EEA sub-processor |