LEGAL

Privacy statement

VERSION 1.0 · LAST CHANGED 21 AUG 2026 · APPLIES TO SKUPLY.IO AND THE SERVICE

THESE ARE DRAFTS IN OUR OWN WORDS. THEY NEED A LAWYER BEFORE THEY BIND ANYONE. ANYTHING IN VERMILION IS A NUMBER OR A PERIOD THAT STILL HAS TO BE FIXED.

01

Who we are

Skuply is a product of AImplement, established in [city], registered with the Dutch Chamber of Commerce under [number]. For this website we are the data controller: we decide ourselves what happens to visitors’ data. For the product data in your webshop it is the other way round. There you are the controller and we are the processor, and we record that in the data processing agreement.

02

What data we process

From visitors to this site: the address you enter in the scan and what the scan produces about it. From customers: name, business email address, phone number and billing details. From the catalogue: product titles, descriptions, attributes and images.

A product catalogue should contain no personal data. If it does anyway, for instance a designer’s name inside a description or an email address in a supplier field, we treat it as customer data and it falls under the data processing agreement.

03

The scan without a login

Anyone who enters an address lets us read the public product pages at that address, exactly as any visitor can. We ask for no name and no email address, and we do not log in to your shop. We do not keep the outcome: the whole report sits inside the link itself and in no database of ours. The address you entered appears in our hosting provider’s server log, which expires after thirty days. Whoever has the link can read the report.

04

What we use it for

To deliver the service. To be able to show why a field was filled the way it was, because without that nothing can be rolled back. To invoice. And to reply when you ask us something.

We sell nothing on, we rent out no files and we do not use your catalogue to train third-party models. That last one also sits in the data processing agreement, so it is enforceable and not just a promise on a page.

05

On what legal basis

For customers: performance of the contract. For the scan and our own administration: legitimate interest, namely showing what we do and being able to prove what we did. For keeping invoices: a legal obligation.

For none of this do we need consent, so we do not ask for it as a cover either. Where we do need consent, we ask for it separately and you can withdraw it just as easily.

06

Automated decisions

Our pipeline derives values with a model, and that is automated processing. It is not automated decision-making about people within the meaning of article 22 GDPR: nothing is decided about a human, only about a product field. On top of that, anything staying under the threshold of 0.85 does not go live but to a list a human decides on.

07

Who else sees it

We engage a small number of processors. They are listed below by name, with what they are used for and where they process the data. This list is part of the data processing agreement and we give thirty days notice when something about it changes, so you can object.

PROCESSOR

WHAT FOR

WHERE

[hosting party]

running the pipeline

EU

[model supplier]

deriving attributes

EU

[mail party]

sending reports

EU

[payment party]

invoicing

EU

NAMES ARE PLACEHOLDER

08

Where it sits and for how long

Processing and storage happen inside the EU. No catalogue goes to a party outside the EU, and we do not pick a supplier that cannot guarantee this.

WHAT

HOW LONG

WHY

Scan results

thirty days

after that the measurement is stale

The field log

as long as the contract runs

otherwise nothing can be rolled back

Customer data

until end of contract plus six months

questions afterwards

Invoices

seven years

tax retention obligation

PERIODS ARE PLACEHOLDER EXCEPT THE TAX ONE

09

Your rights

Access, correction, deletion, restriction, portability and objection. A request may simply come by email and costs nothing. We respond within a month, and if it takes longer we say so within that month with the reason attached.

If you think we are getting it wrong, a complaint can go to the Dutch Data Protection Authority. That right sits here because it must, but we would rather hear it ourselves first.

10

Security

Access to your shop runs through an API key with only the permissions needed for products. We do not ask for an admin login and no access to orders or customers. Tokens and keys are stored encrypted. Access on our side is limited to the people who run the service, and every write action sits in the log with a timestamp.

11

Changes and contact

If something material changes, we let you know before it takes effect, not afterwards. The previous version stays available on request, so you can see what changed.

Questions about this go to hallo@skuply.io and are answered by somebody who builds the service themselves.