Data Processing Addendum
For business customers whose workspace holds personal data. It forms part of the Terms of Service and applies automatically; no signature is needed. To receive a countersigned copy, write to hello@skailstudio.com.
Last updated 25 September 2026.
1. Roles
For personal data in your workspace (for example names in your website’s content, people you invite, or figures from Google Analytics), you are the controller and Skail Consulting LLC (Skail Studio) is the processor. For the data we need to run our own business, such as billing contacts and sign-in records, we are a controller and the Privacy Policy applies. Under the CCPA we act as your service provider and do not sell, share, retain or use that data for any purpose other than providing PageSoar to you.
2. Instructions
We process workspace data only on your documented instructions, which are the Terms, your settings and what people in your workspace ask PageSoar to do, unless the law requires otherwise, in which case we tell you first where the law allows. The data concerns your website visitors, customers and staff, and is processed for as long as your workspace is open.
3. Confidentiality and security
People at PageSoar with access to workspace data are bound by confidentiality and see it only to operate and support the service. The measures we take are listed in Annex II below.
4. Subprocessors
You authorise the subprocessors on the subprocessors list. We will update that list and email workspace admins at least 14 days before adding or replacing one, and you may object; if we cannot meet the objection, you may end the affected service and receive a refund of prepaid fees for the time left. We hold each subprocessor to data protection terms at least as protective as these.
5. International transfers
Workspace data is stored in the United States. Where data moves out of the EU or EEA, the transfer relies on the European Commission’s standard contractual clauses (Decision 2021/914), incorporated here by reference: Module 2 (controller to processor) where you are the controller, and Module 3 (processor to processor) where you are yourself a processor for someone else. For both, clause 7 (docking) applies; in clause 9 option 2 (general authorisation, with the notice in section 4 above); clause 11’s optional wording does not apply; clauses 17 and 18 choose the law and courts of Ireland. For the UK, the UK International Data Transfer Addendum applies alongside them; for Switzerland, the clauses apply with the Swiss FDPIC as the supervisory authority. The annexes below complete them.
6. Helping you
We help you answer requests from people exercising their rights, and with security, impact assessments and consultations with authorities, as far as our part of the processing allows. We tell you without undue delay, and within 72 hours, after becoming aware of a personal data breach affecting your workspace, with what we know.
7. Deletion and audits
When the service ends, we delete workspace data on your request, or return it first if you ask, unless the law requires us to keep it. We make available the information needed to show we meet this addendum and answer reasonable written audit questions once a year.
Report a security issue
Found a vulnerability in PageSoar? The Security page says where to write and what happens next. Please give us time to fix it before you tell anyone else, and do not access data that is not yours.
Annex I: the parties and the processing
Data exporter
- Who
- The business customer that accepted the Terms of Service
- Contact
- The workspace admin named in the account
- Role
- Controller (Module 2), or processor (Module 3)
Data importer
- Name
- Skail Consulting LLC (Skail Studio)
- Contact
- support@skailstudio.com
- Role
- Processor (Module 2), or subprocessor (Module 3)
- Activities
- Providing hosted PageSoar under the Terms of Service
Data subjects
- Who
- The customer’s staff and invited users; people named in the customer’s website content; the customer’s website visitors, as counted by Google Analytics and Search Console
Personal data
- What
- Names, work email addresses, roles and sign-in records of users; any personal data in website pages PageSoar reads and edits; aggregated visit, search and conversion figures from Google, which name no visitor; sales lines from uploaded spreadsheets, with name and email columns removed
- Sensitive data
- None is intended. The Acceptable use rules forbid putting health records, card numbers or passwords into PageSoar
Processing
- Nature
- Storage, reading, analysis, AI drafting, and publishing changes a person approves
- Purpose
- To audit and improve the customer’s website and measure the result
- Frequency
- Continuous while the workspace is open
- Duration
- While the workspace is open, then until the customer asks for deletion (section 7)
Supervisory authority
- Which
- The authority of the EU member state where the data exporter is established, or its EU representative’s, as clause 13 says
Annex II: technical and organisational measures
- Encryption in transit: every public address answers HTTPS only, with HSTS (frontdoor/fly.toml force_https; the front door sends Strict-Transport-Security).
- Encryption at rest: every workspace disk is a Fly.io volume created with encryption on.
- Isolation: each workspace runs on its own machine with its own disk, and its own key for connected credentials. A workspace holds no AI or market-data vendor key.
- Connected credentials (WordPress, Google) are kept in the workspace’s encrypted credential store.
- Passwords are stored only as scrypt hashes. Five wrong passwords lock an account for 15 minutes.
- Two-step sign-in (an authenticator app code) is required by default for every workspace.
- Sessions are random, stored only as a hash, sent in HttpOnly cookies, and end after 12 hours, or 14 days when “Keep me signed in” is chosen.
- Roles within a workspace decide who may approve and publish; nothing is published without a person’s approval.
- Access logging: sign-ins, with their IP address, and administrative changes are recorded, and kept for 12 months.
- Records the service no longer needs are deleted on a schedule (Privacy Policy, “How long it is kept”).
Annex III: subprocessors
The list below is the one the subprocessors page shows.
Fly.io, Inc.
- What for
- Hosting: the website, sign-in, every workspace and PageSoar's model service run on its machines and disks.
- Data it receives
- Everything a workspace stores
- Where
- United States (Chicago)
Anthropic, PBC
- What for
- AI writing and analysis, through PageSoar's model service.
- Data it receives
- Website content, your instructions, and Search Console query and performance context sent with a request
- Where
- United States
DataForSEO OÜ
- What for
- Market data: search volumes, rankings and competitor pages.
- Data it receives
- Website addresses and search terms
- Where
- Estonia (European Union)
Google LLC
- What for
- PageSpeed checks; the mail relay for PageSoar's email; Search Console and Analytics when you connect them.
- Data it receives
- Page addresses; email you are sent; the Google data you choose to read
- Where
- United States
Paddle.com Market Limited
- What for
- Checkout and billing, as the reseller and merchant of record.
- Data it receives
- Name, email, billing address, payment details, tax details
- Where
- United Kingdom
Nowlark (run by Skail Consulting LLC)
- What for
- Alerts PageSoar's own staff to a new Contact us or demo tour message, connector request or trial sign-up.
- Data it receives
- The sender's name, email and message, or the new customer's name, email and plan
- Where
- United States (Chicago, on Fly.io)
Apple Inc.
- What for
- Delivers those staff alerts to a PageSoar staff member's iPhone (Apple Push Notification service).
- Data it receives
- The alert's title and text
- Where
- United States
Changes
- 25 September 2026: Selects the standard contractual clauses modules and adds Annexes I, II and III.
- 25 September 2026: First published.