LEGAL
Privacy statement
VERSION 1.0 · LAST CHANGED 21 AUG 2026 · APPLIES TO SKUPLY.IO AND THE SERVICE
THESE ARE DRAFTS IN OUR OWN WORDS. THEY NEED A LAWYER BEFORE THEY BIND ANYONE. ANYTHING IN VERMILION IS A NUMBER OR A PERIOD THAT STILL HAS TO BE FIXED.
01
Who we are
Skuply is a product of AImplement, established in [city], registered with the Dutch Chamber of Commerce under [number]. For this website we are the data controller: we decide ourselves what happens to visitors’ data. For the product data in your webshop it is the other way round. There you are the controller and we are the processor, and we record that in the data processing agreement.
02
What data we process
From visitors to this site: the address you enter in the scan and what the scan produces about it. From customers: name, business email address, phone number and billing details. From the catalogue: product titles, descriptions, attributes and images.
A product catalogue should contain no personal data. If it does anyway, for instance a designer’s name inside a description or an email address in a supplier field, we treat it as customer data and it falls under the data processing agreement.
03
The scan without a login
Anyone who enters an address lets us read the public product pages at that address, exactly as any visitor can. We ask for no name and no email address, and we do not log in to your shop. We do not keep the outcome: the whole report sits inside the link itself and in no database of ours. The address you entered appears in our hosting provider’s server log, which expires after thirty days. Whoever has the link can read the report.
04
What we use it for
To deliver the service. To be able to show why a field was filled the way it was, because without that nothing can be rolled back. To invoice. And to reply when you ask us something.
We sell nothing on, we rent out no files and we do not use your catalogue to train third-party models. That last one also sits in the data processing agreement, so it is enforceable and not just a promise on a page.
05
On what legal basis
For customers: performance of the contract. For the scan and our own administration: legitimate interest, namely showing what we do and being able to prove what we did. For keeping invoices: a legal obligation.
For none of this do we need consent, so we do not ask for it as a cover either. Where we do need consent, we ask for it separately and you can withdraw it just as easily.
06
Automated decisions
Our pipeline derives values with a model, and that is automated processing. It is not automated decision-making about people within the meaning of article 22 GDPR: nothing is decided about a human, only about a product field. On top of that, anything staying under the threshold of 0.85 does not go live but to a list a human decides on.
07
Who else sees it
We engage a small number of processors. They are listed below by name, with what they are used for and where they process the data. This list is part of the data processing agreement and we give thirty days notice when something about it changes, so you can object.
PROCESSOR
WHAT FOR
WHERE
[hosting party]
running the pipeline
EU
[model supplier]
deriving attributes
EU
[mail party]
sending reports
EU
[payment party]
invoicing
EU
NAMES ARE PLACEHOLDER
08
Where it sits and for how long
Processing and storage happen inside the EU. No catalogue goes to a party outside the EU, and we do not pick a supplier that cannot guarantee this.
WHAT
HOW LONG
WHY
Scan results
thirty days
after that the measurement is stale
The field log
as long as the contract runs
otherwise nothing can be rolled back
Customer data
until end of contract plus six months
questions afterwards
Invoices
seven years
tax retention obligation
PERIODS ARE PLACEHOLDER EXCEPT THE TAX ONE
09
Your rights
Access, correction, deletion, restriction, portability and objection. A request may simply come by email and costs nothing. We respond within a month, and if it takes longer we say so within that month with the reason attached.
If you think we are getting it wrong, a complaint can go to the Dutch Data Protection Authority. That right sits here because it must, but we would rather hear it ourselves first.
10
Security
Access to your shop runs through an API key with only the permissions needed for products. We do not ask for an admin login and no access to orders or customers. Tokens and keys are stored encrypted. Access on our side is limited to the people who run the service, and every write action sits in the log with a timestamp.
11
Changes and contact
If something material changes, we let you know before it takes effect, not afterwards. The previous version stays available on request, so you can see what changed.
Questions about this go to hallo@skuply.io and are answered by somebody who builds the service themselves.