Privacy Policy
Effective date: 20 July 2026
1. Who we are
The data controller is Skoot, Ireland. In this policy, “we”, “us”, and “Skoot” mean that controller.
For privacy requests, use our contact form. We aim to respond within one month.
2. Scope
This policy covers personal data we process when you visit our website, contact us, create an account, or use the Skoot service (signal-driven B2B lead generation).
When you use the service to research leads and contacts for your own business development, you are the controller of that workspace data. We process it on your instructions as a processor, except where we process it for our own purposes (for example security, abuse prevention, or product operation), in which case we are a controller.
3. Data we collect
- Account data: name, work email, password (stored hashed), company name, role, team membership, and email notification preference.
- Contact and support: details you submit via the marketing contact form or in-app help (message content, and related account/company context), plus technical metadata such as IP address used for security and delivery.
- Usage and technical data: login sessions, IP address (including for rate limiting and security), and product usage events needed to operate the service.
- Workspace content you provide or generate: strategies, personas, signals, research history, notes, and similar content you enter or create in the product.
- Lead and contact data: company and person details researched from publicly available sources or entered by you (including names, titles, profile URLs, inferred emails or phones where available, evidence snippets, and outreach drafts). This is processed primarily on your behalf.
- Voice input (optional): if you use microphone-based strategy notes, speech is transcribed in the browser and the resulting text may be stored as strategy content.
We do not require payment card data today. We do not use non-essential analytics or advertising cookies.
4. Purposes and legal bases
- Provide the service (account, workspace, research jobs, drafts) — contract (GDPR Art. 6(1)(b)).
- Respond to enquiries and support — legitimate interests in operating and improving a B2B service, or steps prior to contract (Art. 6(1)(b)/(f)).
- Security, abuse prevention, and rate limiting — legitimate interests in protecting the service and users (Art. 6(1)(f)).
- Optional product emails you enable — consent or legitimate interests as applicable; you can turn these off in settings (Art. 6(1)(a)/(f)).
- Legal compliance — legal obligation where applicable (Art. 6(1)(c)).
Where we rely on legitimate interests, those interests are operating a secure B2B SaaS product, preventing abuse, and communicating about enquiries you initiate. You may object as described in section 8.
5. Who we share data with
We use service providers (processors) to run the product, including:
- Hosting and infrastructure providers
- Database hosting
- Transactional email delivery (currently Resend)
- AI and web-search providers used to research public sources (currently including xAI and Exa)
They may only process personal data on our instructions and under appropriate contracts. We may also disclose data if required by law or to protect rights, safety, or security.
6. International transfers
Some providers may process data outside the European Economic Area (for example in the United States). Where that happens, we rely on an adequacy decision where available, or appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7. Retention
- Account and workspace data: kept while your account is active. After closure or deletion request, we delete or anonymise within a reasonable period unless we must retain it longer for legal or security reasons.
- Contact and support messages: kept as long as needed to handle your request and for a limited follow-up period.
- Security logs (including IP-related records): kept for a limited period needed for security and abuse prevention.
8. Your rights
Under GDPR you may have the right to access, rectify, erase, restrict, or object to processing of your personal data, and to data portability. Where processing is based on consent, you may withdraw consent at any time without affecting prior lawful processing.
To exercise these rights, use our contact form. You also have the right to lodge a complaint with the Data Protection Commission (Ireland), or with your local supervisory authority if you live elsewhere in the EEA/UK.
10. Automated processing
The service uses automated systems (including AI) to research public information and suggest leads, contacts, and outreach drafts for your workspace. These outputs are assistive; they do not produce legal or similarly significant decisions about individuals without human involvement by you. You remain responsible for how you use those outputs.
11. Children
The service is for business users. We do not knowingly offer it to children under 16.
12. Changes
We may update this policy from time to time. The effective date above will change when we do. Continued use of the service after an update means you accept the revised policy, except where applicable law requires a different approach.