Skip to content
Skyie GlobalInfoTech
Legal

Privacy Notice

This notice explains what Skyie Global InfoTech Ltd does with your personal information: what we hold, why, who else sees it, where it is kept, how long we keep it, and what you can ask us to do about it. It covers our websites at skyieglobal.com and skyieglobal.co.uk, and the correspondence we hold with candidates, clients and the people we write to. Version 2.1, revised 25 August 2026.

Last updated 25 August 2026

1. Who we are, and how to contact us

Skyie Global InfoTech Ltd is the data controller for everything described in this notice. That means we decide why your information is used, and how.

We are a company registered in England and Wales, company number 17294509. Our registered office is Unit 37B, Alpha House, 100 Borough High Street, London, SE1 1LB, United Kingdom. Our VAT registration number is GB 522 8591 81. We are registered with the Information Commissioner's Office (ICO) under data protection reference ZC180480.

If you have a question about this notice, or you want to exercise any of your rights, email [email protected] or write to us at the registered office above. We will tell you who is dealing with your request.

Data Protection Officer

We have designated a Data Protection Officer, and the appointment has been notified to the Information Commissioner's Office as Article 37(7) of the UK GDPR requires. You can contact them at [email protected], or by post at our registered office marked for the attention of the Data Protection Officer. You may contact them directly about anything to do with how we use your information, and you do not have to go through anyone else to do so.

2. Who this notice is for, and what it covers

You may be reading this because you have received an offer letter, an engagement letter or an invoice from us, and you may never have visited our website. This notice is written for you as much as for a visitor.

It covers five groups of people:

  • people who visit skyieglobal.com or skyieglobal.co.uk;
  • people who send us a message through the contact form, or who use our Skyie Guide assistant;
  • people who apply to work or train with us, and people we make an offer to;
  • the named individuals we deal with at organisations we quote for, invoice or engage;
  • the people who work here, whose sign-in and activity records our back office keeps.

It does not cover our products. Where you use a Skyie product under a separate agreement, that agreement and its data processing terms apply, and the organisation that gave you access is normally the controller rather than us.

3. What we hold about you, and where it came from

If you visit the website. Your IP address, the pages you requested, your browser's user-agent string, and security signals used to tell people from bots. Our websites are served through Cloudflare, which sits in front of them and handles all of this. If a page shows a background video, your browser fetches the video and its still poster image directly from Pexels, so Pexels receives your IP address for those requests.

If you send us a message. Your name, your email address, your organisation if you give one, and what you wrote. A contact-form message is not stored in any database of ours. It exists as an email in our mailbox, and as the acknowledgement we send back to you. Section 14 explains who holds that mailbox.

If you use the Skyie Guide assistant. Whatever you type into it, so that a reply can be produced. We do not keep the conversation. Your IP address is held in the server's memory for about a minute so that we can limit how fast messages can be sent; it is not written to disk.

If we make you an offer of employment or an internship. Your name, your email address and your postal address. The terms of the offer itself: the role or programme, the start date, hours and work pattern, place of work, pay (a salary or an hourly rate), holiday, notice on both sides, any probation period, pension, sick pay, training, and any conditions such as evidence of your right to work in the UK, references, or a satisfactory DBS check. We also hold the short brief a member of our staff wrote to prepare the letter, which normally names you and states the pay; the letter itself; its reference number and dates; the email address it was sent to; who approved it and when; and whether it was accepted, declined or withdrawn, with any short reason recorded at the time.

If you are our client, or the named contact at one. Your name, email address, telephone number and postal address; your organisation, and its company and VAT registration numbers; any notes a member of staff has added to your record; the engagement letter, quotations, invoices, receipts and credit notes we issue, including what is charged and what has been paid; a short note on the engagement letter recording that customer due diligence has been carried out or that the engagement is conditional on it; and our correspondence about all of that.

What our system records about sending and opening. Against each document or letter link we hold the email address it was sent to, who sent it, when it was created, when it expires, how many times it has been opened, and when it was first and last opened. Each time a link is opened we record the date and time, the IP address it was opened from, and the browser's user-agent string. Against each message we send we record what our mail system reports back about it, together with your email address.

The audit log. Our back office keeps a log of who did what and when, to which document, your name as it appears on the letter, the email address the letter was sent to, any short reason recorded when an offer was declined or withdrawn, and the internal account and IP address of the member of staff who acted. It can only be added to. Nothing in it can be changed or removed.

If you work here, or try to sign in to our back office. Your name and email address, your password hash, any authenticator secret and any passkey credentials, your sign-in sessions with the IP address and user-agent they were created from, and a log entry for every action you take. A failed sign-in is also logged, with the email address that was typed and the IP address it came from — so this can capture someone who does not work here and mistyped an address.

Where your information did not come from you. Most of what we hold comes from you directly, in your application, an interview, a meeting or an email exchange. Sometimes it does not. A colleague at your organisation may name you as the contact for a piece of work. A recruiter, a university or college, or a mutual contact may put us in touch. Company and VAT registration numbers may be taken from public registers such as Companies House. We do not buy personal data, we do not use data brokers, and we do not build profiles from social media.

4. If you apply to work or train with us

Our back office only creates a record once we are preparing an offer for you. Before that point, your application, your CV and any notes we make reach us as email and stay as email, in the mailbox described in section 14. None of the controls described in this notice for issued letters — the locking, the audit log, the expiring links — apply to it.

What we hold. Whatever you send us: your name, your contact details, your CV or application, and our correspondence with you. If a recruiter, a university or college, or a mutual contact put us in touch, that is where we got your details from, and you can ask us which.

Our lawful basis. Our legitimate interests in considering people who want to work with us and in keeping a short record of why a decision was made (Article 6(1)(f)). Where we are actively preparing an offer to you, we also rely on taking steps at your request before entering a contract (Article 6(1)(b)). We do not screen, score or rank applicants automatically.

How long we keep it. We do not have an automatic deletion rule for that mailbox today, and we would rather say so than quote a period nothing enforces. If you want your application removed, email [email protected] and we will delete it and tell you what we have done.

5. The contact form

The form asks for your name, your email address, an optional organisation and your message. Giving them is voluntary. There is no law and no contract that requires you to, and you can read the whole site without giving us anything. If you do not fill the form in, we simply cannot reply to you.

The form contains one field you cannot see. It is an anti-spam trap: automated submissions almost always fill it in, and any submission that fills it in is discarded without being read. It collects nothing about you and it is not used for tracking. A browser or password manager can occasionally fill it in for a real person, and today the page still shows a confirmation message when that happens. We are changing that. Until we have, if you send us a message and hear nothing, please email [email protected] directly.

The form is also protected by Cloudflare Turnstile, which looks at signals such as your IP address and how you interacted with the page to tell people from bots.

When you submit the form, your message is emailed to us and an automatic acknowledgement is emailed back to you. Both are sent by our own mail relay, described in section 14. Your message then sits as an email in our mailbox, which is hosted by Microsoft. The acknowledgement is a reply to your own message; we do not send marketing email.

6. The Skyie Guide assistant

Skyie Guide is an optional assistant that answers general questions about Skyie Global. What you type is sent to Google to produce a reply. We do not keep the conversation.

Which Google service handles it depends on our configuration at the time. Where our Google Cloud setup is available, the request goes to Vertex AI under Google Cloud's data processing terms. If it is not available, the assistant falls back to Google's Gemini API, which is a different service on different terms. We have kept that fallback deliberately, so that a credential problem takes the assistant's legal footing down a level rather than taking the assistant down altogether. It is the one place in this system where that trade-off is made, and letter drafting works the opposite way: it refuses to run rather than fall back.

Because we cannot promise which service answered a particular message, please do not type personal, confidential or sensitive information into the assistant. If you want to tell us something about yourself, use the contact form or email us instead.

7. Offers, engagement letters, and how we prepare them

Here is what actually happens when we send you an offer or an engagement letter.

A member of our staff writes a short brief: the role or the piece of work, the money, the dates. They can either write the letter themselves, or tick a box to have a first draft written for them. If that box is ticked, the brief is sent to Google's Vertex AI service in Google's London region (europe-west2) and comes back as a draft. Our software refuses to draft at all unless that governed London configuration is present — it will not quietly use another region, and it will not fall back to Google's consumer service. That is enforced in the code, not just set in a configuration file.

Every figure and every paragraph the model produced is marked in our system, so the person reviewing it can see exactly what came from where.

The draft can then be edited by a person. It is checked automatically against the legal requirements for that kind of letter, and it must be approved by a named administrator before it can be issued. Changing the wording, the figures, the title, or your name or address cancels that approval, and it has to be approved again.

We want to be exact about what that gate is. A letter may consist entirely of text the model drafted, approved as written. What we guarantee is that a named person read it and took responsibility for every figure in it before it left the building — not that a person wrote every word. Nothing goes out to you on a machine's say-so.

Once approved, the letter is issued: it takes a reference number, is locked so it cannot be quietly altered afterwards, and is emailed to you as a link.

An offer letter can be made conditional on things such as evidence of your right to work in the UK, references, or a satisfactory DBS check. The letter records that the condition applies. Our system has no field for the result of any check, for a copy of any document you produce, or for criminal record information.

If you are being offered a role or an engagement, we need the information described above to write the letter and, in the case of employment, to meet legal duties that fall on us as an employer. If you would rather not give it, we will not be able to make the offer or enter the contract.

8. Sensitive information, and information about criminal records

We do not ask you for special category information — health, race or ethnicity, religion, politics, trade union membership, sex life, sexual orientation, genetics or biometrics — and none of our letters or documents has a field designed to hold it.

Some fields are free text written by our staff: the prose of a letter, an "other conditions" note on an offer, notes about pay or sick pay, the note recording customer due diligence on an engagement letter, notes on a client record, the short brief behind a letter, and the reason recorded when an offer is declined or withdrawn. Nothing in the software stops a member of staff typing anything into those. We instruct our staff not to record health, criminal-record or other sensitive information in them, and we are constraining the fields where an outcome is recorded so that the instruction does not have to carry the whole weight.

We do not hold criminal offence information in this system. What we hold is the statement, in an offer letter, that the offer is conditional on a satisfactory DBS check. That is a condition, not a result. If we ever needed to hold the outcome of a check, we would first identify a condition in Schedule 1 to the Data Protection Act 2018, as section 10(5) of that Act requires for criminal offence data, and put in place the appropriate policy document that Schedule 1 calls for. We would update this notice before doing any of it.

Where an offer is declined or withdrawn we may record a short reason. That reason is copied into our audit log, which cannot be changed or removed. If you believe something inappropriate has been recorded about you, tell us at [email protected] and we will look at it and tell you what we find.

9. Why we use your information, and our lawful basis for each purpose

To read and answer your enquiry, and to keep a record of the exchange. Our legitimate interests in running a business and replying to people who contact us (Article 6(1)(f)). Where your enquiry is about possibly working together, also taking steps at your request before entering a contract (Article 6(1)(b)).

To send you the automatic acknowledgement. Our legitimate interests in confirming that your message arrived (Article 6(1)(f)).

To consider your application to work or train with us. Our legitimate interests in considering people who want to work with us (Article 6(1)(f)).

To keep the site available and to stop abuse — Cloudflare's protection, the Turnstile check, the anti-spam field, rate limits. Our legitimate interests in the security and availability of our systems (Article 6(1)(f)).

To answer questions through the Skyie Guide assistant. Our legitimate interests in offering an easy way to learn about what we do (Article 6(1)(f)).

To negotiate and make you an offer of employment or an internship. Taking steps at your request before entering a contract with you (Article 6(1)(b)).

To produce and keep the written statement of employment particulars, the pension auto-enrolment information, and the record of your right to work. A legal obligation (Article 6(1)(c)), under section 1 of the Employment Rights Act 1996, the Pensions Act 2008, and section 15 of the Immigration, Asylum and Nationality Act 2006. These are duties that fall on us as an employer, not steps taken at your request, so we do not claim Article 6(1)(b) for them.

To keep the record of an offer that was declined or withdrawn. Our legitimate interests in being able to answer a complaint or a tribunal claim about how we recruited (Article 6(1)(f)).

To prepare and issue engagement letters, quotations, invoices, receipts and credit notes. Where you are the individual we contract with, performance of that contract or steps before it (Article 6(1)(b)). Where you are a named contact and the contract is with your organisation rather than with you, our legitimate interests in dealing with that organisation through the person it has named (Article 6(1)(f)).

To have artificial intelligence produce a first draft of a letter. Our legitimate interests (Article 6(1)(f)) — not Article 6(1)(b). Drafting is optional: it is a box a member of staff ticks, and they can write the letter themselves instead. Because it is not necessary in order to contract with you, we do not claim that it is. Our interest is in producing accurate, complete and consistent letters more quickly. Weighing that against your interests: the brief goes to a business cloud service under a data processing contract; our software refuses to send it anywhere but Google's London region; every value the model produced is flagged for the person approving the letter; and a named person must approve it before it can be issued. Google publishes, for Vertex AI under its Cloud Data Processing Addendum, that submissions are not used to train its models. We are confirming that our own account is on those terms and will say so here once we have. You can object to AI drafting at any time — see section 20.

To send you the document and know whether it arrived. Our legitimate interests in confirming delivery of something we sent you (Article 6(1)(f)). Detecting whether an email was opened or a link was clicked is different, and is dealt with in section 12.

To keep VAT records. A legal obligation (Article 6(1)(c)). Paragraph 6(3) of Schedule 11 to the Value Added Tax Act 1994 empowers HMRC to require records to be preserved for a period of up to six years, and six years is the period HMRC requires. Regulation 31 of the VAT Regulations 1995 sets out which records must be kept. Where a VAT record is still on our systems after those six years — and, as section 16 explains, our software cannot delete it — we rely on our legitimate interests in being able to establish or defend a legal claim within the limitation periods in the Limitation Act 1980 (Article 6(1)(f)), not on the legal obligation, because the obligation does not run that long.

To keep client engagement records for anti-money-laundering purposes. A legal obligation (Article 6(1)(c)), under regulation 40 of the Money Laundering Regulations 2017. Regulation 40 requires those records to be kept for five years from the end of the business relationship, and then requires us to delete the personal data, unless a narrow exception applies — another enactment requires us to keep it, it is needed for legal proceedings, or you have consented. We state both limbs because both bind us, and section 16 is honest about the fact that our software cannot yet carry out that deletion.

To keep an audit log of what was issued, changed, approved and sent. A legal obligation to be able to show a VAT record has not been altered (Article 6(1)(c)), and our legitimate interests in accountability and security (Article 6(1)(f)).

To run the back office, and to keep sign-in and activity records for the people who use it. Our legitimate interests in the security of a system holding salaries and bank details (Article 6(1)(f)), and our accountability obligations (Article 6(1)(c)).

To establish, exercise or defend legal claims. Our legitimate interests (Article 6(1)(f)), or a legal obligation where one applies.

Consent (Article 6(1)(a)). We do not rely on consent today, other than for any optional cookies we might introduce in future. Where we ever ask for consent, you can withdraw it at any time, and withdrawing it does not affect anything we did beforehand. Section 12 explains one place where we are currently doing something that needs consent under different rules, and what we are doing about it.

10. What our emails actually say

We never attach a document to an email. Everything goes out as a link. But the email itself is not blank, and you should know what is in it before it lands in your inbox.

An invoice email states the amount due, the date payment is due, the VAT included, and our bank account name, sort code and account number so you can pay. The preview line your mail app shows before you open the message states the amount due and the due date. Because bank details in an email body are what invoice-redirection fraudsters alter, please treat any message that appears to change our bank details as suspect, and confirm it with us by telephone before paying.

A quotation email states the total and the date the quotation stands until. A receipt email states the amount received, the date it was received and any VAT included. A credit note email states the amount credited, the invoice it relates to, and the reason if one was recorded.

A letter — an employment offer, an internship offer or an engagement letter — is different. The standard letter email carries the reference number, the date, and a link. Your salary, your hourly rate or the fee is in the document behind the link, not in the email.

There is one thing we have to be plain about. Before sending any of these, a member of our staff can add a covering note, which replaces the standard opening line and appears in the email exactly as they typed it. Nothing in the software stops them putting money or terms in it. We ask them not to, and we are changing the software so that the letter email cannot carry free text of that kind.

The subject line and preview of a letter email do name the type of letter — for example "Employment offer letter from Skyie Global InfoTech Ltd" — so anyone who can glance at your inbox can tell that you have received one, even though they cannot see what it says.

Anyone with access to the mailbox we send to can read whatever the message states. If you would rather we used a different address, tell us and we will.

11. Document links, and what we record when one is opened

Every document and letter is sent as a link that is unique to one recipient. It expires 45 days after it is sent, and we can revoke it at any time. We store only a scrambled fingerprint of the link, not the link itself, so nobody reading our database can rebuild a working one. If you lose a link we issue a fresh one rather than looking the old one up.

Against each link we hold the email address it was sent to, who sent it, when it was created, when it expires, how many times it has been opened, and when it was first and last opened. Each time it is opened we record the date and time, the IP address it was opened from, and the browser's user-agent string.

The link is served from skyieglobal.co.uk, which sits behind Cloudflare. Section 14 explains what that means for the document itself.

Please do not forward a link. Ask us and we will send a copy directly to the person who needs it.

12. Delivery records

Our mail system reports back what happened to a message. We record those reports against the document they relate to, together with your email address, so that a bounce is visible next to the invoice nobody replied to. The events we record are: sent, delivered, bounced, and a record that a message was received where our mail system reports one.

We do not record whether you opened an email, or whether you clicked a link in one. Detecting an open normally works by loading a small invisible image from a server, which means reading or writing information on your own device. That needs your consent under regulation 6 of the Privacy and Electronic Communications Regulations, and legitimate interests cannot carry it. We do not ask you for that consent, so we do not do it. Our system discards any open or click report it receives, and it has never recorded one.

We have never used delivery data for marketing, for scoring, or for profiling of any kind.

Where a report arrives from our mail relay without a signature we can verify, we record it and mark it unverified rather than discarding it, so that a genuine bounce is not hidden by a configuration problem.

13. Cookies and similar technologies

We set only strictly necessary cookies. They keep the site secure (Cloudflare and Cloudflare Turnstile, for example __cf_bm and cf_clearance) and remember the choice you make in our cookie banner, which we store in a first-party cookie named skyie-consent and as an entry in your browser's local storage named skyie-cookie-consent. If a member of our staff signs in to the back office, a session cookie named skyie_admin_session keeps them signed in.

We set no analytics, advertising or cross-site tracking cookies, and we do not track you between websites. If we ever introduce an optional cookie, a banner will ask first and refusing will be as easy as accepting. Our Cookie Policy has the full detail.

14. Who else handles your information

We keep the list of outside organisations as short as we can. These are the ones we know of, and we have named every one we have been able to establish.

Contabo GmbH — our hosting provider. Our servers, our database and our own mail relay all run on Contabo infrastructure, in a data centre in Portsmouth, United Kingdom, operated by Contabo UK Ltd. Contabo holds everything our application holds. It processes it only on our written instructions, under a data processing agreement made under Article 28 of the GDPR on 16 August 2026.

Cloudflare, Inc. — our content delivery network, DNS, security protection, and the Turnstile anti-spam check on the contact form. This is a larger disclosure than we have made before, and it is the accurate one. Both of our websites are served through Cloudflare's proxy, which means Cloudflare terminates the encrypted connection at its own network. Cloudflare therefore handles the content of requests and responses, not only IP addresses and security signals. That includes every page you read, every contact-form message you submit, and every document and letter served through our expiring links at skyieglobal.co.uk — so an offer letter stating your name, your address, the role, the salary, the notice period and any DBS condition passes through Cloudflare's network in readable form. Our application also reaches our own mail relay over an address that Cloudflare serves, so the body of every message we send passes through Cloudflare's network too, including the bank account name, sort code and account number in an invoice email. We have decided to keep this arrangement, because of what Cloudflare's protection does for the availability and security of the site, and to tell you about it rather than describe it as something smaller.

Microsoft — the mailbox for skyieglobal.co.uk. Mail addressed to [email protected] is delivered into a Microsoft 365 mailbox. Microsoft therefore holds every contact-form enquiry, every application or CV emailed to us, every reply we send from that address, and every request you make to exercise your rights under this notice. We contract with Microsoft Ireland Operations Limited, under the Microsoft Products and Services Data Protection Addendum. Our tenant region is the United Kingdom.

Google — artificial intelligence services. Google's Vertex AI service produces the first draft of a letter when a member of our staff asks for one, in Google's London region (europe-west2). Google also provides the model behind the Skyie Guide assistant, as described in section 6.

Google — the mailbox for skyieglobal.com. Mail addressed to our .com domain is delivered into Google Workspace, with our own mail server only as a fallback. Google therefore holds correspondence sent to that domain. We have not yet independently confirmed which Google entity we contract with for Workspace, or the data-region setting on that account, and we will name both here as soon as we have.

Pexels — the source of the photography and video used in the site's design. Most photographs are fetched by our server and re-served from our own domain, so Pexels does not see you for those. Where a page shows a background video, your browser requests both the video file and its still poster image directly from Pexels, so Pexels receives your IP address for those requests. Nothing you send us ever goes to Pexels.

Our outbound mail relay is not on this list, because it is not somebody else's. Your acknowledgement, our copy of your enquiry, and every document and letter notification are sent by mail infrastructure we run ourselves, on our own server in Contabo's Portsmouth data centre. It hands messages straight to the recipient's mail provider; there is no upstream relay operated by another company. The one qualification, stated because it is true, is the Cloudflare point above: our application reaches that relay over a Cloudflare-served address, so Cloudflare handles the message on the way.

We may also disclose information where the law requires it, to HMRC and other authorities where we must, and to our professional advisers where we need advice or to defend a claim. We do not sell your personal data and we do not share it for anyone else's marketing.

15. Where your information is held, and transfers outside the UK

Our application data — the store holding letters, client records, invoices, the share and delivery records, and the audit log — is in Portsmouth, England. That is a fact, not an intention. Our mailboxes are a separate question and are dealt with below.

Contabo. The company we contract with, Contabo GmbH, is established in Munich, Germany, and its staff can reach the platform in order to run it. That is a transfer to the European Economic Area. The UK has adequacy regulations covering the EEA, so no additional safeguard such as an International Data Transfer Agreement is needed for it.

Cloudflare. Cloudflare, Inc. is a United States company operating a global network. Because our sites are proxied, what may be processed outside the UK is not only traffic and security data but the content described in section 14 — pages, contact-form submissions, the documents behind our links, and the bodies of the emails we send. Cloudflare's data processing terms incorporate the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. This is the transfer in this notice with the widest reach, and we would rather you saw it stated plainly than found it in a DNS lookup.

Microsoft. Mailbox data for skyieglobal.co.uk is held in the United Kingdom or elsewhere in the European Economic Area. The UK's adequacy regulations cover the EEA. Microsoft Ireland Operations Limited is established in Ireland, and Microsoft's group includes companies outside the UK and the EEA whose staff can be involved in support and administration. The safeguards for that are those in the Microsoft Products and Services Data Protection Addendum, which incorporates the EU Standard Contractual Clauses and the UK Addendum to them.

Google, for letter drafting. Drafting is sent to Vertex AI in Google's europe-west2 region, which is in London, so the request is served in the UK, and our software will not send it anywhere else. That does not settle the transfer question by itself, and we will not claim that it does: the Google entity we contract with is not established in the UK, and Google's support and administration can involve access from elsewhere. The safeguards are those in Google's Cloud Data Processing Addendum, which incorporates the UK Addendum to the EU Standard Contractual Clauses where a transfer needs one. We are confirming which Google entity and which terms apply to our account, and will update this notice once we have.

Google, for the skyieglobal.com mailbox. Mailbox data for that domain is held in the United Kingdom or elsewhere in the European Economic Area. We have not yet independently confirmed the contracting entity or the data-region setting, so we are not naming either here; the safeguard for any transfer outside the UK and EEA would be the one in Google's Workspace data processing terms.

Pexels. Where your browser loads a background video or its poster image, the request goes to Pexels' servers, which may be outside the UK, and Pexels receives your IP address for it.

You can ask us for a copy of, or more detail about, any of these safeguards at [email protected].

16. How long we keep it, and what our system cannot delete

We would rather tell you what our systems actually do than quote a tidy schedule they do not enforce.

What the system enforces. Once a quotation, invoice, receipt, credit note or letter has been issued, it is locked. It cannot be edited and it cannot be deleted from within the system at all. A mistake is corrected by a credit note, or by withdrawing a letter and issuing a replacement, and the original stays. Only a draft that has never been issued can be deleted. The audit log can only be added to.

What the system prompts but cannot carry out. When a letter is issued we set a review date: six months after issue for employment and internship offers, six years after issue for engagement letters. When that date passes, the letter appears on a list in our back office for a person to review. Our software has no way to delete an issued letter, so that review cannot end in the letter being removed by the software. Removing it would mean a deliberate change made directly to the database, outside the application. We are building a way to redact a record properly, so that the review has a real outcome and leaves a trace.

Two of those clocks are also wrong, and we would rather say so than let you read them as considered policy. An engagement letter's six years runs from the day it was issued, but the anti-money-laundering period runs for five years from the end of the business relationship, which is later. And an employment offer is flagged for review six months after issue whatever happened to it — a period chosen for a candidate who was not appointed, which is the wrong period for an accepted offer that is also your written statement of particulars and supports our right-to-work record. We are correcting both so that the clock depends on the outcome and starts from the right event.

What has no expiry today. The record of each document link, each time it was opened and the IP address it was opened from; and the record of delivery, bounce, open and click events with the email address they relate to. The links themselves expire after 45 days. The records of them do not, and there is no automatic clear-out. We are putting one in place.

The brief behind a letter. The short brief a member of our staff wrote — which normally names you and states your pay — stays on the letter's record for the life of that record, and once the letter is issued it cannot be deleted. It is never shown to you, but it is your personal data and it is disclosable if you ask for a copy of what we hold. We are changing our system to clear it once a letter has been approved, because after that it serves no purpose.

What we must keep. VAT documents and the records behind them are kept for six years, the period HMRC requires under paragraph 6(3) of Schedule 11 to the Value Added Tax Act 1994. Client engagement records sit alongside the anti-money-laundering period in regulation 40 of the Money Laundering Regulations 2017: five years from the end of the business relationship, after which regulation 40 requires us to delete the personal data unless a narrow exception applies. Our software cannot yet carry out that deletion, which is the gap we are closing.

Enquiries and applications. A contact-form message or an emailed application is not held in any database. It is an email in our mailbox, which we clear periodically. We do not have an automatic deletion rule for that mailbox today.

Assistant conversations. We do not keep them. Whatever Google retains for its own service is governed by its terms.

Back-office records. Sign-in sessions expire and are removed. The audit log does not expire.

If you ask us to erase something we are required to keep, or something our system cannot remove, we will tell you plainly which reason applies, what we are able to do, and what we are not.

17. How we protect your information

Everything is encrypted in transit (HTTPS), and the sites sit behind Cloudflare's security protection. As section 14 explains, that same arrangement means Cloudflare terminates the encryption at its network; we would rather describe our security accurately than claim end-to-end protection we do not have.

The back office where documents and letters are prepared is not indexed by search engines, is sent with headers that stop anything in between caching it, and is restricted to a small number of named accounts. Sign-in is by passkey or by password; an account can be set to require a passkey only, or to require an authenticator code as well as a password, and repeated failed attempts lock an account for a period that lengthens each time.

Documents leave as expiring, revocable, single-recipient links rather than as attachments, precisely because an attachment in a mailbox is permanent and silent. Only a scrambled fingerprint of each link is stored. Issued records are locked, and the audit log can only be added to.

Our hosting agreement with Contabo requires it to process data only on our documented instructions and never for its own purposes; to delete all of our data completely and irrevocably, including archive and backup copies, when we ask or when the agreement ends; to tell us about a data breach without undue delay; to help us answer your rights requests and carry out impact assessments; and it makes Contabo liable for the faults of its own sub-processors.

We are documenting where backups of our application data are held, who holds them and how long they are kept, and we will state that here once it is settled.

18. Automated decisions and artificial intelligence

We do not make decisions about you by automated means that produce a legal effect or similarly significantly affect you. There is no automated decision-making or profiling of the kind Article 22 of the UK GDPR is concerned with, and we do not score, rank or filter candidates or clients automatically.

Artificial intelligence appears in two places, and only two. It writes replies in the Skyie Guide assistant. And, when a member of our staff asks it to, it produces a first draft of a letter.

A draft is not a decision. The letter is tested automatically against the legal requirements for its type, and a named administrator must read it and approve it before it can be issued. Any change to the content cancels that approval. A letter may consist entirely of text the model drafted and a person approved unchanged — we would rather tell you that than imply a rewrite that our system does not require. The decision to make you an offer, on what terms, and whether to issue it, is made by people.

The automatic checks can stop us issuing a letter that would not meet the law. That stops us; it does not decide anything about you.

If you would rather no artificial intelligence were involved in preparing your letter, say so and we will write it by hand. Section 20 explains what that means before and after a letter has been issued.

19. Your rights

Before the list, the limits — because you should hear them from us rather than discover them.

If you are a client, some records we cannot erase because VAT and anti-money-laundering law require us to keep them, and we will tell you which obligation applies.

If you have received an offer letter or an engagement letter, that letter cannot be erased from our system either. Once issued it is locked and there is no way to delete it. What we can do is withdraw it and record that, and tell you exactly what remains.

Our audit log is built so that nothing can be removed from it. Where a request would require us to remove something from that log, the grounds we rely on are Article 17(3)(b) — compliance with a legal obligation, because the log is what shows a VAT record has not been altered — and Article 17(3)(e), the establishment, exercise or defence of legal claims. We rely on those grounds for the audit log specifically, not as a general answer, and we are building a way to redact an identifier from a record while keeping the record's integrity. Everything outside those grounds we will erase.

You have the right to:

  • ask for a copy of the personal data we hold about you;
  • ask us to correct anything inaccurate, or complete anything incomplete;
  • ask us to erase it;
  • ask us to restrict what we do with it;
  • object to our using it (see section 20);
  • where it applies, ask for it in a portable form or ask us to send it to someone else.

Where we rely on consent, you can withdraw it at any time. That does not make anything we did beforehand unlawful.

To exercise any right, email [email protected] or write to our registered office. We will respond within one month, and there is normally no fee.

20. Your right to object

This has its own section because it matters more here than the others, and because the law requires it to be brought to your attention clearly and separately.

Much of what we do rests on our legitimate interests. Wherever that is our lawful basis, you have the right to object at any time. If you object, we must stop unless we can show compelling grounds that override your interests, and we will explain our reasoning either way. Email [email protected].

Objecting to artificial intelligence being used to draft your letter. Tell us before a letter is drafted and we will write it by hand. If you tell us after a letter has been issued, we have to be honest about what we can do: an issued letter is locked, and neither the letter nor the brief behind it can be deleted or edited in our system. We will record your objection, we will not use drafting for any further letter to you, and once we have built the redaction path described in section 16 we will apply it to the brief. We will not tell you we have deleted something we cannot delete.

21. Complaining to the ICO

If you are unhappy with how we have handled your information, please tell us first — we would like the chance to put it right. You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, and you do not have to come to us first. The ICO is at ico.org.uk, on 0303 123 1113, or at the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

22. Children

This website and our services are aimed at businesses and professionals, and are not directed at children. We do not knowingly collect information about children. If you believe a child has given us their information, contact [email protected] and we will delete it.

23. Changes to this notice

We update this notice when our practices, our providers or the law change, and the date at the top shows when it was last revised.

This version corrects several things earlier versions got wrong, and we would rather collect the corrections here than argue with our own drafting history throughout the document.

Earlier versions said our email involved no third party. That was wrong. Mail sent to skyieglobal.co.uk is held by Microsoft, and mail sent to skyieglobal.com is held by Google. Only the sending side is ours.

Earlier versions described Cloudflare as handling our content delivery, DNS, security and anti-spam check. That understated it. Cloudflare terminates the encrypted connection to both of our sites, so it handles the content of pages, form submissions, the documents behind our links and the bodies of our emails.

Earlier versions said hosting was intended to be UK-based and did not name the provider. Our hosting provider is Contabo, and our application data is in Portsmouth.

Earlier versions said money is never in our emails. That was true of letters and wrong about invoices: an invoice email states the amount due and our bank details.

Earlier versions said a letter email carries only the reference number and the date. That is true of the standard email, but a member of our staff can add a covering note that appears in the message, and we should have said so.

Version 2.1 (25 August 2026) records our change of registered office to Unit 37B, Alpha House, 100 Borough High Street, London, SE1 1LB. This is the first version of this notice to describe our back office, our letters and our use of artificial intelligence. Before publishing it we switched off email open and click tracking, moved all of our AI processing onto Google Cloud's London region, and added a link to this notice to the foot of every document we send.

Where something here is still being confirmed — the terms that apply to our Google Cloud account, and the contracting entity and data region for the skyieglobal.com mailbox — we have said so rather than guessed, and we will update this notice as soon as each is settled.

Our Cookie Policy and our sub-processor list are being updated in the same change, so that the whole of our published estate says the same thing on the same date.

This notice is provided for transparency about how Skyie Global InfoTech Ltd handles your information and forms part of how we meet our obligations under UK data protection and consumer law. It is kept up to date and reviewed periodically. If anything here is unclear or you would like more detail, please contact us at [email protected].