Privacy
What we collect, why, and how long we keep it.
Last updated 12 August 2026
Controller
Skylence, privacy@skylence.be
Scope
This policy covers the Skylence web properties: this marketing site (skylence.be) and the account and billing application (account.skylence.be), where you create an account, manage licenses, and pay for subscriptions.
What we process
On the marketing site we process no account data: there are no analytics trackers and we set no cookies. Standard technical server logs (IP address, requested page, user agent) are kept briefly by our hosting infrastructure for security and capacity purposes.
On the account application we process account identity (name, email), authentication and security data (passwords stored hashed, optional 2FA/passkeys, OAuth token metadata), team membership and invitations, and billing metadata needed to provide subscriptions. Payment card data is processed by Paddle as merchant of record and is not stored as full card numbers in our application.
Purposes and legal bases
- Provide the service and contract (account, teams, licensing): art. 6(1)(b) GDPR.
- Security and integrity of the service: art. 6(1)(f) GDPR, legitimate interests.
- Legal obligations (for example tax/invoice records where applicable, handling data subject requests): art. 6(1)(c) GDPR.
Processors and transfers
- Paddle.com Market Limited (payment / merchant of record): customer identity needed for checkout and invoicing. Location: EEA / as disclosed by Paddle.
- Laravel Cloud (infrastructure processor): application data, logs, backups under contract. Location: EEA.
- Twilio SendGrid (transactional email delivery): recipient email address, name where included in the email body, delivery metadata. Location: United States (Twilio Inc.); transfers under Twilio's DPA with Standard Contractual Clauses.
The current list also lives on thesubprocessors page.
Retention
Account data is kept while your account is active. After erasure we remove or anonymize personal data in our application, except where a legal obligation requires limited retention (for example an audit record of the erasure request with a hashed email). This includes the local billing mirror (subscriptions and transaction records) held in our application. Paddle acts as merchant of record for your subscription and separately retains its own billing and invoice records under its own legal obligations.
Your rights
You may access, rectify, erase, restrict, or port your personal data, and object to processing based on legitimate interests. Signed-in users can export their data and delete their account under Settings in the account application. You may also contact us at the email above. You can lodge a complaint with your supervisory authority (for Belgium: the Gegevensbeschermingsautoriteit / Autorité de protection des données).
Cookies
The marketing site sets no cookies. The account application uses only essential cookies required for authentication, security, and session continuity. The full inventory is on thecookie policy page. Because every cookie is strictly essential, no cookie consent banner is required.
Security
We apply technical and organisational measures appropriate to the risk, including encrypted transport (HTTPS), hashed passwords, optional multi-factor authentication, and access controls on application data.
This page is a product privacy notice, not legal advice. Controller details will be completed with the company registration data once the legal entity is incorporated.