Legal
Privacy Policy
This policy explains how we collect, use, share, and protect personal data when you use Skedra, in accordance with the EU General Data Protection Regulation (GDPR), the Irish Data Protection Act 2018, and the ePrivacy Regulations (S.I. 336/2011).
Last updated: 14 June 2026
1. Who we are
Skedra is operated by Aiqon Limited(“Skedra”, “we”, “us”, “our”), a company registered in Ireland (company registration number [CRO number]), with its registered office at [registered office address], Cork, Ireland. VAT number: [VAT number].
For any privacy matter you can contact us at hello@skedra.ie. We have not appointed a statutory Data Protection Officer, as we are not required to; the above address is our point of contact for all data-protection queries.
2. Our two roles — controller and processor
Skedra plays two distinct roles depending on whose data is involved:
- Data controller — for the personal data of our business customers and their staff (the people who hold a Skedra account), and for visitors to our website. For this data, we decide why and how it is processed, and this policy applies directly.
- Data processor — for the personal data that a business customer enters or collects about their own clients (for example, the people who book appointments through a salon or garage). For that data, the business is the controller and we process it only on their instructions, under a data-processing agreement. If you are a client of a business that uses Skedra, please contact that business directly to exercise your rights; we will assist them.
3. Personal data we collect
From business users (where we are controller)
- Identity & contact details: name, email address, phone number, business name and address.
- Account credentials: passwords (stored only as a salted hash — never in plain text).
- Billing information: subscription plan, billing contact, and VAT details. Card details are handled by Stripe; we never see or store full card numbers.
- Communications: messages you send us and our correspondence with you.
From clients of our business customers (where we are processor)
- Name and contact details (email, phone), booking and appointment history, service notes, and any custom intake fields the business chooses to collect.
- Marketing preferences, loyalty balances, and reviews submitted after a visit.
Collected automatically
- Technical data: IP address, approximate location (city/country) derived from IP, browser and device type, and pages or actions within the service.
- Log and security data: sign-in events, timestamps, and audit records of changes made in an account.
- Cookies and similar technologies (see section 7).
4. Why we use it and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing and operating the Skedra service | Performance of a contract |
| Processing payments and managing subscriptions | Performance of a contract; legal obligation (tax/accounting) |
| Sending booking confirmations and appointment reminders | Performance of a contract / legitimate interests |
| Sending marketing emails or messages | Consent (you can withdraw it at any time) |
| Securing the service, preventing fraud and abuse | Legitimate interests |
| Product analytics and improving the service | Legitimate interests |
| Complying with legal and regulatory obligations | Legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to such processing at any time (see section 12).
5. AI-assisted features
Some features (such as the Skedra Assistant message drafts and the WhatsApp auto-reply) send limited content to a third-party AI provider to generate suggestions. We do not use your data to train third-party AI models, and AI output is presented to a human for review before it is sent. These features do not make decisions that produce legal or similarly significant effects about any individual.
6. Automated decision-making and profiling
Skedra includes a “no-show risk” indicator that estimates the likelihood a client will miss an appointment, based on their past booking behaviour. This is a decision-support tool only — it informs staff but does not, on its own, produce legal or similarly significant effects, and a human always remains in control. We do not carry out solely automated decision-making within the meaning of Article 22 of the GDPR.
7. Cookies and similar technologies
We use a small number of strictly necessary cookies that are required for the service to function — for example, secure sign-in tokens (skedra_access and skedra_refresh, both HTTP-only). These do not require consent under the ePrivacy Regulations because they are essential to deliver a service you have requested.
We do not use advertising cookies or non-essential third-party trackers. If we introduce any non-essential cookies in the future, we will ask for your consent first through a cookie banner. You can also control cookies through your browser settings, though disabling strictly necessary cookies will prevent you from signing in.
8. Who we share data with (sub-processors)
We do not sell personal data. We share it only with trusted service providers who process it on our behalf, under contracts that meet GDPR requirements (Article 28). Our current sub-processors include:
| Provider | Purpose | Location |
|---|---|---|
| Our hosting provider | Application and database hosting | EU (Ireland) |
| Stripe | Payment processing and subscription billing | EU / US |
| Resend | Transactional and reminder emails | US |
| Twilio | SMS and WhatsApp messaging | US |
| Anthropic | AI-assisted suggestions | US |
| Cloudflare | Image storage and content delivery | Global (EU edge) |
We may also disclose data where required by law, to enforce our terms, or to protect the rights, safety, or property of Skedra, our customers, or others.
9. International data transfers
Our primary application and database are hosted within the EU (Ireland). Some sub-processors listed above are based outside the European Economic Area, principally in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses or an applicable adequacy decision (including the EU–US Data Privacy Framework) — to ensure your data receives an equivalent level of protection.
10. How long we keep data
- Account and business data is retained for as long as your account is active.
- After an account is closed, we retain data for a limited period to allow reactivation and to meet legal obligations, then delete or anonymise it. Invoicing and tax records are kept for the period required by Irish law (generally six years).
- Client booking data processed on behalf of a business is retained according to that business’s instructions, and is deleted or returned when our agreement with them ends.
- Backups are kept for a short rolling period and then overwritten.
11. How we protect data
We use appropriate technical and organisational measures, including encryption of data in transit (TLS/HTTPS), hashing of passwords, role-based access controls, audit logging, and EU-based hosting. No system is perfectly secure, but we work to protect your data and to respond promptly to any incident. Where a personal-data breach is likely to result in a risk to individuals, we will notify the Data Protection Commission within 72 hours and affected individuals where required.
12. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Have inaccurate data corrected (rectification).
- Have your data erased (the “right to be forgotten”), where applicable.
- Restrict or object to certain processing, including direct marketing.
- Receive your data in a portable, machine-readable format (data portability).
- Withdraw consent at any time, where processing is based on consent.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise any of these rights, email hello@skedra.ie. We will respond within one month. If you are a client of a business that uses Skedra, please contact that business first, as they are the controller of your booking data.
13. Complaints
If you have concerns, please contact us first so we can help. You also have the right to lodge a complaint with the Irish supervisory authority:
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie
14. Children
Skedra is a tool for businesses and is not directed at children. We do not knowingly collect personal data directly from children. Where a business records appointments for a minor, it does so as controller and is responsible for the appropriate legal basis and any required parental consent.
15. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the “Last updated” date above. Where changes are significant, we will take reasonable steps to notify you.
16. Contact us
Aiqon Limited — Cork, Ireland. Email: hello@skedra.ie.
