LegalLast updated 21 August 2026

Privacy Policy

Who we are

SKAIYON is a consulting firm based in Dubai, United Arab Emirates, founded in 2025. For any question about this policy, or about information we hold, contact info@skaiyon.com.

This policy describes what this website does. Systems we build and operate for clients are separate and are governed by the written agreement with that client.

What we collect, and why

Only what you give us, and one thing you can agree to. There are six ways to give us something, and nothing else on this site collects anything.

Booking a call. Your name, email address, company and role if you enter them, what you say you are trying to solve, and the time you choose. Used to hold the meeting and to prepare for it.

Asking for a quote. This form asks for more than the others, so it is worth listing in full. Required: your name, work email address, company, the country and city you operate in, and a description of the problem. Optional, and blank is a perfectly good answer to any of them: company website, sector, roughly how many people work there, how the work is done today, which systems it touches, where the data sits, who operates it, what timeline you have in mind, whether you have already tried an off-the-shelf tool, any budget you want to mention, and how you came across us. We also record which page you submitted from. Used to work out whether we can help and to reply to you about it.

Requesting a case study. Your name, email address, company and role if you enter them, and what you tell us you want to see.

Sending an enquiry. Your name, email address, and your message.

Subscribing to the newsletter. Your email address, and nothing else. It is a double opt-in: the address is stored as pending and receives one confirmation email, and it joins the list only when you click the link in it. Anyone can type someone else's address into a form, so nothing is sent to an unconfirmed address beyond that single confirmation. Once you are on the list we also keep a record of each newsletter sent to you: the date, and the message identifier our email provider returns. That record is what lets us answer whether a particular email actually reached you rather than only that it was sent.

The chat assistant. Whatever you type into it, and the answer it gives. There is no account and no name attached unless you type one.

Page views, but only if you agree. There is a banner on your first visit with two buttons of equal weight. If you say yes, this browser stores one random number and each page you open is recorded against it: which page, when, and the site you arrived from if it was an external one. If you say no, or ignore the banner entirely, nothing is stored and nothing is sent.

There is no advertising, no advertising network, and nothing here is shared with one. We do not profile you. We do not know who you are unless you tell us.

The one cookie, in detail

It is not strictly a cookie. It is a random identifier stored in this browser's local storage, which behaves the same way for you and is never sent to another site.

What it is: a random value, generated in your browser at the moment you agree. It is not derived from your address, your device or anything about you, and it is not linked to a name. Nothing on this site ever greets you by name from it, because the record it belongs to has no name in it and is never joined to one.

How long it lasts: until you clear it, or until you use the control below. Visit history is deleted after twelve months by a job that runs daily inside the database.

What it is for: counting how many people read a piece of writing, so there is some basis for deciding what to write next. That is the whole of it.

It is only created after you agree. Declining is recorded too, in the same place, so you are not asked again on every page; that record contains your answer and nothing else.

Two different things count page views here, and they work differently, so it is worth being exact about which is which. The identifier described above is stored on your device, which is why it is behind the banner and why declining stops it completely. Cloudflare Web Analytics stores nothing on your device at all: it has no cookie to refuse, so the banner does not govern it and switching the banner off does not switch it off. It is named below with everything else that processes anything, because not asking for permission is not a reason to be quiet about it.

If you would rather not be counted by it either, a content blocker or Do Not Track will stop the script loading. We have not built a switch for something that stores nothing, and would rather say that plainly than imply a control that does not exist.

Verification on the forms

Cloudflare Turnstile runs on every form on this site: the quote form, the case-study request, the booking form and the newsletter signup. It is there to tell a person from a script, because a form that anyone can automate becomes a way to spend our email allowance, fill the database with noise, or send mail in our name to an address someone else typed.

What Cloudflare receives in order to do it: your IP address, your browser's user agent, and signals about the browser itself. It sets its own cookie on challenges.cloudflare.com for this purpose. Cloudflare states that Turnstile data is not used for advertising or cross-site tracking. We receive only a pass or fail, and a token that proves it; we never see the signals behind the decision.

The check runs when you press the send button, not when the page loads, so nothing is sent to Cloudflare unless you are actually submitting something.

Rate limiting, and what happens to your address

Your IP address is never stored. To tell one visitor from another for rate limiting, the address is combined with a secret value and hashed, and only that hash is kept. It cannot be reversed to an address.

Two records use it. A counter, which holds the hash and a number and is deleted after seven days. And a log of refused requests, which holds the hash, which endpoint was involved and why it was refused, and is deleted after ninety days. Neither contains a message, a name or an address.

Why we hold it

To answer your enquiry, to hold the meeting you booked, to send you the writing you asked for, to work out whether we can help with what you described and reply to you about it, and if we begin working together, to deliver and administer that work. Nothing else.

Chat transcripts are kept for one reason: to see which questions the site fails to answer, so the site can answer them. They are read in bulk, not individually.

Who else sees it, and where they are

Five companies process some of this on our behalf. Each is named here with what it handles and the country the processing happens in. We do not sell your information and we do not share it for advertising.

Supabase — the database and the code that runs behind this site. It holds everything submitted here: enquiries, bookings, quote requests, case-study requests, newsletter signups, chat transcripts and, if you agreed to it, page views. Region: Tokyo, Japan (ap-northeast-1). Your information therefore leaves the United Arab Emirates.

Resend — sends the confirmation and notification emails, and holds newsletter subscribers. Processing region: Tokyo, Japan.

Cloudflare — serves this website, provides Turnstile on the forms, and provides Cloudflare Web Analytics. Cloudflare is a United States company operating a global network; a request is served from wherever is nearest to you, which for most readers of this site is inside the Gulf.

cal.com — creates the booking and the calendar invitations, and receives your name, email and answers so it can put them on the invitation. United States.

Moonshot AI — powers the chat assistant. Your question and the relevant extracts from this site are sent to it to produce an answer. The service is provided by MOONSHOT AI PTE. LTD., a Singapore entity, and its privacy policy states that data is stored on servers in Singapore. Moonshot AI is part of a Chinese-headquartered group.

Google is not a processor for this site. Google Apps Script and Google Sheets were used until August 2026 and were retired; nothing from this site is sent to Google.

A caution about the chat

Moonshot AI's privacy policy lists user content under training and refining its models, and there is no opt-out on the plan this site uses. The chat box says so directly, above the field, rather than only here.

So do not type anything into the chat that you would not want leaving our control: no personal details beyond a first name, nothing confidential about your business, no client data, no credentials. The assistant does not need any of it, and it is told not to ask for it.

If you want to tell us something specific about your situation, use the quote form, the booking form, the case-study form or email. Those go to us, to Supabase and to Resend, and not to a model provider.

Client data

Where we build or operate systems for a client, any data those systems process remains that client's data. We process it only to deliver the service, under the agreement with that client, and never to train models for anyone else. Nothing a client's system holds is sent to the chat assistant.

How long we keep it

Enquiries, quote requests, bookings and case-study requests: kept while there is an active conversation and for twenty-four months after the last contact, then deleted. If none of those is left and you are not a newsletter subscriber, your name and address go with them.

Newsletter subscribers: kept until you unsubscribe. Every newsletter carries an unsubscribe link that works on the first click, with no login and no confirmation step, and your mail client may also show its own unsubscribe control drawn from the same instruction. Using either marks the address as unsubscribed and it receives nothing further.

Newsletter send records: no period is stated, because nothing currently deletes them. The daily deletion job does not cover them and this policy does not claim a period it cannot keep. If one is set, it will be added to the job and to this page in the same change.

Chat transcripts: kept for twelve months, then deleted.

Page views, if you agreed to them: kept for twelve months, then deleted.

Rate limit counters: seven days. Refused-request logs: ninety days.

Cloudflare Web Analytics: retained by Cloudflare under their own policy, not ours. We see totals in a dashboard and can delete nothing individually, because nothing in it identifies anyone.

None of those periods is a promise about intentions. A job inside the database runs every day at 03:40 UTC and deletes everything past its date, so each period is a property of the system rather than a sentence on this page. That is stated after checking it: a script reads the job out of the running database, confirms it is scheduled, active, that its last run succeeded, and that the run happened after the current version of the deletion function was installed — a function that will delete something tomorrow is not the same as one that has. A period this page states that the job does not enforce is treated as a fault in the page, not in the job.

Client records: kept as long as the engagement and our legal obligations require.

Your rights

Under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, you may ask what we hold about you, ask us to correct it, or ask us to delete it. Email info@skaiyon.com and we will respond within thirty days.

For a deletion request we remove your rows from our records — enquiries, quote requests, case-study requests and bookings alike — remove you from the newsletter list at Resend, and cancel and delete any booking held at cal.com.

Chat transcripts carry no name, so if you want one removed, tell us roughly when you used the chat and what you asked and we will find it.

Page-view records are the one thing we cannot look up for you, because they are deliberately not linked to anything about you. The identifier exists only in your browser. Using the control on this page deletes it, which ends the connection between anything already recorded and any later visit.

One limit worth stating plainly: where text you typed into the chat has already been sent to Moonshot AI, we cannot recall it. Their policy governs it at that point, and their privacy policy sets out how to make a request to them directly.

Changes

If this policy changes, the date above changes with it.

Counting page views needs JavaScript, so with it turned off nothing is recorded and there is nothing here to switch off.

Stopping deletes the random identifier from this browser as well as the answer, so nothing links a later visit to an earlier one. It applies to this browser only, because that is the only place the identifier ever existed.

Questions. Asked before every engagement.

Your data is yours. You can export it at any time, and it is exported to you in a documented format before any engagement closes. The software itself is licensed: we build it around your business, host it, and run it, and you pay monthly for that. If you'd rather own it outright, that's possible. It's a different kind of engagement and it's priced accordingly. Licensing keeps maintenance our problem rather than yours, which is why it is the default.

Two weeks' notice, either side. Your data is yours. You can export it at any time, and it is exported to you in a documented format before any engagement closes. The system stops running. If you'd rather keep it running, the ownership option is available at that point as well. Ending the retainer doesn't force you to lose what was built.

Typically four to eight weeks from signing to a working system, depending on how many tools it connects to and what state the data is in. A scoping conversation and a written plan come first, so the timeline is agreed before anything is committed to.

Access to the tools and data the system will work with, one person who can make decisions, and a few hours in the first two weeks while we map how work actually moves through your business. After that, very little. The point of the engagement is that it runs without your attention.

Usually. Most business software exposes an interface we can build against, and where one doesn't there's normally a way around it. Which connections are viable is settled in the scoping conversation, so you find out before committing rather than after.

Hosting region for a system we build for you is decided at the start of the engagement, not inherited from a default. If data residency is a hard requirement, raise it in the first conversation and we will tell you plainly whether we can meet it. This website is separate and its processing is already fixed: enquiries, quote requests, bookings and chat are handled by Supabase in Tokyo, Resend in Tokyo, Cloudflare, cal.com and Moonshot AI, which the privacy policy names individually along with where each one processes. Nothing from a client system is ever sent to the chat assistant.

That's the normal starting point, and mapping them is part of the work. Automating a process nobody has examined just makes the confusion faster, so we don't start there. The first phase establishes how things actually happen, as opposed to how they're supposed to.