Privacy Policy

Effective date: 18 June 2026 · Last updated: 18 June 2026 · Applies to: skippy.id and the Skippy platform

1. Introduction

This Privacy Policy explains how Skippy Software solutions Ltd (“Skippy,” “we,” “us,” or “our”) handles personal information in connection with our website at skippy.id and our credential issuance and verification platform (together, the “Service”).

We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia's Personal Information Protection Act (PIPA), and, where it applies to our activities, the EU and UK General Data Protection Regulation (GDPR). “Personal information” (or “personal data”) means information about an identifiable individual.

This Policy works alongside our Terms & Conditions and Cookie Policy.

2. Our Two Roles

Skippy handles personal information in two distinct capacities, and your rights differ depending on which applies:

  • As a controller — when we decide why and how information is processed. This covers visitors to our website, prospects, account administrators, and our own business contacts. This Policy governs that processing.
  • As a processor / service provider — when our business customers (each, a “Customer”) use the Service to issue or verify credentials, we process personal information about their credential holders (“Subjects”) on the Customer's behalf and under their instructions. For that processing, the Customer is the controller and the Customer's own privacy policy applies. See Section 13.

3. Information We Collect

CategoryExamples
Account & contact dataName, work email, phone, organisation, role, login credentials, billing contact.
Usage & technical dataIP address, device and browser type, pages viewed, API calls, log and diagnostic data, timestamps.
Cookies & similarIdentifiers and preferences set via cookies and similar technologies (see Cookie Policy).
CommunicationsMessages you send us, support tickets, sales enquiries, and form submissions.
Payment dataBilling details processed through our payment provider (we do not store full card numbers).
Credential / Subject dataInformation within credentials our Customers issue or verify, processed on their behalf as a processor (Section 13).

We collect this information directly from you, automatically through your use of the Service, and from our Customers (for Subject data).

4. How & Why We Use It

As a controller, we use personal information to:

  • provide, operate, secure, and improve the Service;
  • create and manage accounts and authenticate users;
  • process payments and manage billing;
  • respond to enquiries, provide support, and communicate about the Service;
  • send administrative and, where permitted, marketing communications (you can opt out at any time);
  • monitor, detect, and prevent fraud, abuse, and security incidents;
  • produce de-identified, aggregated analytics that do not identify any individual; and
  • comply with legal obligations and enforce our agreements.

6. Cookies & Analytics

We use cookies and similar technologies to run the site, remember preferences, and understand usage. You can control cookies through your browser and, where shown, our cookie banner. For details, see our Cookie Policy.

7. How We Share Information

We do not sell personal information. We share it only as follows:

  • Service providers / subprocessors who process data on our behalf under contract (e.g., hosting, analytics, payments, support) — see Section 8.
  • With our Customers, where you are a Subject or user associated with their account.
  • Legal & safety — to comply with law, lawful requests, or to protect the rights, safety, and property of Skippy, our users, or the public.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
  • With your direction or consent — for any other disclosure you authorise.

8. Subprocessors

We engage trusted third parties to help deliver the Service (for example, cloud hosting, analytics, payment processing, and customer communications). We require them to protect personal information under written terms consistent with this Policy and applicable law. A current list of subprocessors is available on request by emailing us.

9. International Transfers

We are based in Canada. Personal information may be processed and stored in Canada, the United States, and other jurisdictions where we or our subprocessors operate. Privacy laws in those countries may differ from your own, and information may be accessible to courts, law enforcement, and authorities there. Where required, we use appropriate safeguards (such as the GDPR Standard Contractual Clauses) for international transfers.

10. Data Retention

We keep personal information only as long as necessary for the purposes described in this Policy, to provide the Service, to comply with legal, tax, and accounting obligations, to resolve disputes, and to enforce our agreements. When no longer needed, we delete or de-identify it. For Subject data processed on a Customer's behalf, retention follows the Customer's instructions and our agreement with them.

11. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information appropriate to its sensitivity, including encryption in transit, access controls, and monitoring. No system is perfectly secure, however, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by applicable law.

12. Your Privacy Rights

Subject to applicable law, you may have the right to:

  • access the personal information we hold about you;
  • correct inaccurate or incomplete information;
  • withdraw consent or opt out of marketing;
  • under the GDPR, additionally request erasure, restriction, portability, and object to certain processing.

To exercise these rights, contact us at privacy@skippy.id. We will respond within the time required by law. You may also complain to a regulator — in Canada, the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia; in the EU/UK, your local supervisory authority.

Are you a credential holder (Subject)? If a request relates to a credential issued or verified about you by one of our Customers, that Customer is the controller. Please contact them directly. We will assist them as their processor, and will forward your request to them where appropriate.

13. Credential & Subject Data

When a Customer uses the Service to issue or verify credentials, Skippy acts as a processor and handles Subject data strictly on the Customer's documented instructions and for the purposes of providing the Service. The Customer is responsible for having a lawful basis and any required consents, and for the accuracy of the credentials it issues. A verification result confirms a credential's cryptographic integrity and issuer — it is not Skippy's confirmation of the truth of the underlying facts. Where required, Skippy and the Customer enter into a Data Processing Agreement (DPA) that governs this processing.

14. Children

The Service is intended for organisations and business users and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it. (Note: if your Customers issue credentials to minors — e.g., student credentials — that is governed by the Customer as controller and their consents.)

15. Automated Decisions

Skippy does not use your personal information to make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement. Decisions about whether to rely on a credential are made by the relevant Customer or Relying Party, not by Skippy.

16. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will post the updated Policy here with a new effective date and, where appropriate, notify you. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

17. Contact & Privacy Officer

We have designated a Privacy Officer accountable for our compliance with this Policy and applicable privacy law. To ask a question, exercise a right, or make a complaint, contact:

Privacy Officer

Skippy Software solutions Ltd

Email: privacy@skippy.id

Address: 645 Como Lake Avenue, Suite 307, Coquitlam, BC V3J 0N9, Canada

See also our Terms & Conditions and Cookie Policy.

© 2026 Skippy.id. All rights reserved. Governed by the laws of British Columbia, Canada.