Privacy Policy
Effective date: 18 June 2026 · Last updated: 18 June 2026 · Applies to: skippy.id and the Skippy platform
1. Introduction
This Privacy Policy explains how Skippy Software solutions Ltd (“Skippy,” “we,” “us,” or “our”) handles personal information in connection with our website at skippy.id and our credential issuance and verification platform (together, the “Service”).
We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia's Personal Information Protection Act (PIPA), and, where it applies to our activities, the EU and UK General Data Protection Regulation (GDPR). “Personal information” (or “personal data”) means information about an identifiable individual.
This Policy works alongside our Terms & Conditions and Cookie Policy.
2. Our Two Roles
Skippy handles personal information in two distinct capacities, and your rights differ depending on which applies:
- As a controller — when we decide why and how information is processed. This covers visitors to our website, prospects, account administrators, and our own business contacts. This Policy governs that processing.
- As a processor / service provider — when our business customers (each, a “Customer”) use the Service to issue or verify credentials, we process personal information about their credential holders (“Subjects”) on the Customer's behalf and under their instructions. For that processing, the Customer is the controller and the Customer's own privacy policy applies. See Section 13.
3. Information We Collect
| Category | Examples |
|---|---|
| Account & contact data | Name, work email, phone, organisation, role, login credentials, billing contact. |
| Usage & technical data | IP address, device and browser type, pages viewed, API calls, log and diagnostic data, timestamps. |
| Cookies & similar | Identifiers and preferences set via cookies and similar technologies (see Cookie Policy). |
| Communications | Messages you send us, support tickets, sales enquiries, and form submissions. |
| Payment data | Billing details processed through our payment provider (we do not store full card numbers). |
| Credential / Subject data | Information within credentials our Customers issue or verify, processed on their behalf as a processor (Section 13). |
We collect this information directly from you, automatically through your use of the Service, and from our Customers (for Subject data).
4. How & Why We Use It
As a controller, we use personal information to:
- provide, operate, secure, and improve the Service;
- create and manage accounts and authenticate users;
- process payments and manage billing;
- respond to enquiries, provide support, and communicate about the Service;
- send administrative and, where permitted, marketing communications (you can opt out at any time);
- monitor, detect, and prevent fraud, abuse, and security incidents;
- produce de-identified, aggregated analytics that do not identify any individual; and
- comply with legal obligations and enforce our agreements.
5. Legal Bases (GDPR)
Where the GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Service and manage your account); legitimate interests (to secure, operate, and improve the Service and for B2B marketing, balanced against your rights); consent (for certain cookies and marketing, which you may withdraw); and legal obligation (to meet legal and regulatory requirements). Under Canadian law, we collect, use, and disclose personal information with consent or as otherwise permitted or required by law.
8. Subprocessors
We engage trusted third parties to help deliver the Service (for example, cloud hosting, analytics, payment processing, and customer communications). We require them to protect personal information under written terms consistent with this Policy and applicable law. A current list of subprocessors is available on request by emailing us.
9. International Transfers
We are based in Canada. Personal information may be processed and stored in Canada, the United States, and other jurisdictions where we or our subprocessors operate. Privacy laws in those countries may differ from your own, and information may be accessible to courts, law enforcement, and authorities there. Where required, we use appropriate safeguards (such as the GDPR Standard Contractual Clauses) for international transfers.
10. Data Retention
We keep personal information only as long as necessary for the purposes described in this Policy, to provide the Service, to comply with legal, tax, and accounting obligations, to resolve disputes, and to enforce our agreements. When no longer needed, we delete or de-identify it. For Subject data processed on a Customer's behalf, retention follows the Customer's instructions and our agreement with them.
11. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information appropriate to its sensitivity, including encryption in transit, access controls, and monitoring. No system is perfectly secure, however, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by applicable law.
12. Your Privacy Rights
Subject to applicable law, you may have the right to:
- access the personal information we hold about you;
- correct inaccurate or incomplete information;
- withdraw consent or opt out of marketing;
- under the GDPR, additionally request erasure, restriction, portability, and object to certain processing.
To exercise these rights, contact us at privacy@skippy.id. We will respond within the time required by law. You may also complain to a regulator — in Canada, the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia; in the EU/UK, your local supervisory authority.
Are you a credential holder (Subject)? If a request relates to a credential issued or verified about you by one of our Customers, that Customer is the controller. Please contact them directly. We will assist them as their processor, and will forward your request to them where appropriate.
13. Credential & Subject Data
When a Customer uses the Service to issue or verify credentials, Skippy acts as a processor and handles Subject data strictly on the Customer's documented instructions and for the purposes of providing the Service. The Customer is responsible for having a lawful basis and any required consents, and for the accuracy of the credentials it issues. A verification result confirms a credential's cryptographic integrity and issuer — it is not Skippy's confirmation of the truth of the underlying facts. Where required, Skippy and the Customer enter into a Data Processing Agreement (DPA) that governs this processing.
14. Children
The Service is intended for organisations and business users and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it. (Note: if your Customers issue credentials to minors — e.g., student credentials — that is governed by the Customer as controller and their consents.)
15. Automated Decisions
Skippy does not use your personal information to make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement. Decisions about whether to rely on a credential are made by the relevant Customer or Relying Party, not by Skippy.
16. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will post the updated Policy here with a new effective date and, where appropriate, notify you. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
17. Contact & Privacy Officer
We have designated a Privacy Officer accountable for our compliance with this Policy and applicable privacy law. To ask a question, exercise a right, or make a complaint, contact:
Privacy Officer
Skippy Software solutions Ltd
Email: privacy@skippy.id
Address: 645 Como Lake Avenue, Suite 307, Coquitlam, BC V3J 0N9, Canada
See also our Terms & Conditions and Cookie Policy.
© 2026 Skippy.id. All rights reserved. Governed by the laws of British Columbia, Canada.