Privacy Policy · SkyX

Last updated: July 19, 2026

Data Controller: SKYX AUTOMAÇÃO LTDA, CNPJ (Brazilian corporate taxpayer registry) 62.757.825/0001-02, headquartered at Q SMPW Trecho 3, Bloco A, SN, Sala 110 - Setor de Indústrias Bernardo Sayão, CEP 71.736-301, Brasília/DF, Brazil.

Data Protection Officer (DPO): Gabriel De Melo Filipe, contact [email protected].

Contact for exercising rights: [email protected].

1. Introduction

1.1. This Privacy Policy describes how SkyX collects, uses, stores, shares, and protects the personal data of users of its residential and building automation platform.

1.2. SkyX undertakes to process personal data in compliance with the Brazilian General Data Protection Law (LGPD, Law No. 13,709/2018), the Brazilian Internet Civil Framework (Marco Civil da Internet, Law No. 12,965/2014), and other applicable regulations.

1.3. This Policy applies to all users · B2B Clients (condominiums and property managers), B2C Clients (household residents), Residents at B2B installations, and website visitors.

1.4. By using the Service, the user declares that they have read and agreed to this Policy. Specific processing of sensitive data (biometrics) requires additional consent, as set out in Section 6.

2. Roles in Data Protection

2.1. SkyX as Controller: for data collected directly by SkyX, such as:

  • Client registration data (name, e-mail, CPF/CNPJ where applicable, address).
  • Service usage data (access logs, operational telemetry, quality metrics).
  • Financial and billing data.
  • Support data (ticket history).

2.2. SkyX as Processor: for data that B2B Clients enter into the Service about their Residents:

  • The B2B Client is the Controller of such data.
  • SkyX acts as Processor, handling it in accordance with the B2B Client's instructions and within the limits of this Policy.
  • Examples: resident records, facial images of residents enrolled for recognition, visitor access logs.

2.3. In the B2C case (Home-Installed), the Client themselves is simultaneously the Controller of personal data they enter into the Service about members of their family or invited residents. SkyX acts as Processor in these cases.

3. Personal Data Collected

3.1. Registration Data

CategoryExamplesSource
IdentificationName, e-mail, phone, CPF (optional), CNPJ (B2B)Provided at registration
AddressStreet, neighborhood, city, state, ZIP codeProvided at registration / SOW
ProfessionalRole/function (building manager, resident, admin)Provided at registration
AuthenticationPassword (stored as a hash), session tokensGenerated by the system

3.2. Usage and Telemetry Data

CategoryExamplesSource
Access logsDate/time, source IP, resource accessedCollected automatically
User actionsCommands, configuration changesCollected automatically
Device telemetrySensor states, energy consumption, eventsCollected from connected devices
Operational metricsLatency, errors, software versionCollected automatically

3.3. Media Data

CategoryExamplesSource
Camera imagesContinuous or on-demand video, detected events (person, vehicle)Installed cameras
Facial imagesEnrollment photos for facial recognitionCaptured by the user
Biometric embeddingsMathematical vectors derived from facial images (pgvector)Internal processing
AudioOnly when the voice assistant is explicitly used by the userCaptured by the device

3.4. Payment Data

Processed by Stripe (processor), under the terms of the executed DPA. SkyX does not store the full card number; it stores only reference tokens and the last 4 digits for identification.

3.5. Sensitive Data (LGPD Art. 11)

Biometric data (facial images and embeddings) are considered sensitive personal data. Their processing requires specific and prominent consent. By default, facial recognition is not enabled; the Client chooses to enable it and, in doing so, presents the Consent Form to each person whose face will be enrolled.

4. Legal Bases for Processing (LGPD Art. 7 and 11)

4.1. SkyX uses the following legal bases according to the nature of the data:

Legal basis (LGPD)Applies toExample
Performance of a contract (Art. 7, V)Data necessary to deliver the ServiceRegistration, authentication, operational telemetry, billing
Consent (Art. 7, I; Art. 11, I)Optional features and sensitive dataFacial recognition, promotional notifications, non-essential cookies
Legitimate interest (Art. 7, IX)Security, fraud prevention, Service improvementSecurity logs, abuse detection, aggregated metrics
Compliance with a legal obligation (Art. 7, II)Tax data, retention for regulatory bodiesElectronic invoices (NF-e), audit logs, labor obligations
Protection of life or physical safety (Art. 7, VII)Emergency situationsElderly fall detection, leak alarm

4.2. For biometric data, the legal basis is specific consent (Art. 11, I), revocable at any time, without prejudice to rights exercised previously.

5. Purposes of Processing

5.1. Personal data are processed exclusively for the following purposes:

  • Provision of the contracted Service: enabling the operation of automation, monitoring, control, and notification features.
  • Communication with the user: technical support, operational notifications, billing, legal communications.
  • Security: detection of unauthorized access, fraud prevention, preservation of integrity.
  • Service improvement: aggregated and anonymized usage analysis to identify bugs, optimize performance, and develop new features.
  • Legal compliance: issuance of tax invoices, response to legal requests, minimum retention required by law.
  • Facial recognition (optional, subject to consent): identification of registered persons for access control, notification to the building manager/resident about unknown visitors.

5.2. Explicit prohibitions: SkyX does not use personal data for:

  • Sale or sharing with third parties for advertising purposes.
  • Training third-party AI models (the AI models used by SkyX are trained on generic public datasets or on aggregated-anonymized data from its own base, never on identifiable client data).
  • Behavioral monitoring for profit beyond what is strictly necessary to provide the contracted Service.

6. Processing of Biometric Data (LGPD Art. 11)

Important notice · Home-Installed (residential) version

In the current version of the Home-Installed (B2C) plan, facial recognition is disabled by defaultand cannot be enabled by the Client. This decision reduces consent complexity and risk to residents during the product's early phase. The biometric data described in this section currently applies only to the B2B version (building management).

6.1. Facial recognition is an optional feature and disabled by default. Enabling it requires explicit action by the Client.

6.2. Each person whose face will be enrolled must sign the Biometric Consent Form before processing.

6.3. Minors: biometric enrollment of minors follows the protections of Art. 14 of the LGPD. It requires the express consent of at least one legal guardian, registered on the platform as "Guardian", with a record of the kinship relationship.

6.4. Storage: facial images and embeddings are stored on SkyX's own servers in Brazil (São Paulo) with operational replication in South Korea via pgEdge Spock. Embeddings are generated using InsightFace buffalo_l (an open-source model) and stored in the PostgreSQL pgvector extension. They are not sent to third-party cloud services for processing or storage.

6.5. Right to revoke: biometric consent may be revoked at any time via e-mail at [email protected]or through the app. Upon revocation, the user's facial images and embeddings are deleted within a maximum of 7 calendar days; biometric audit logs (which do not contain images) are retained in accordance with legal retention requirements.

6.6. Accuracy: the technology has a margin of error. Both mistaken recognition and failure to recognize are possible. SkyX does not recommend using the results as sole evidence for legal or punitive decisions.

7. Sharing and Sub-processors

7.1. To provide the Service, SkyX shares data with selected sub-processors:

Sub-processorPurposeData sharedLocation
StripePayment processingPayment tokens, tax identificationUSA with LGPD SCCs
eNotas (or equivalent)Issuance of electronic invoices (NF-e)Client tax dataBrazil
TailscaleSecure mesh VPN between the local server and cloudNode identifiers, network metadataUSA with LGPD SCCs
CloudflareWeb proxy and DDoS protectionWeb requests, source IPUSA with LGPD SCCs
xAI (optional cloud AI)AI response generationChat prompts (when the user uses cloud AI)USA with LGPD SCCs
Groq (optional voice transcription)Speech-to-text conversionAudio sent when the user uses cloud transcriptionUSA with LGPD SCCs
SentryError monitoringStack traces, technical metadata (no PII by design)USA with LGPD SCCs
Alexa / Google / Siri (optional)Voice controlVoice commands routed through the respective assistantsAs per those services' policies

7.2. SkyX maintains a data processing agreement (DPA) with each listed sub-processor, ensuring an adequate level of protection.

7.3. International transfers: when data are transferred outside Brazil (e.g., Stripe), Standard Contractual Clauses approved by the ANPD are used as a supplementary safeguard, under the terms of Art. 33 of the LGPD.

7.4. No sale of data: SkyX does not sell personal data to third parties. Transfers are exclusively for the provision of the Service.

7.5. Legal disclosure: SkyX may disclose data pursuant to a court order, a valid request from a competent authority, or to protect the rights of SkyX, users, or third parties, always respecting the principle of purpose limitation and notifying the data subject when legally permitted.

8. Data Retention

8.1. Data are retained for the time strictly necessary for the stated purposes or for the period required by law:

CategoryRetention periodJustification
Registration dataDuring the term of the contract + 5 years after terminationLimitation period for contractual obligations
Tax data (NF-e, payments)5 yearsLegal obligation (art. 173 of the Brazilian Tax Code, CTN)
Biometric audit logs365 daysLGPD Art. 37 · demonstration of compliance
Facial images and embeddingsAs long as consent is active; deleted within 7 days after revocationLGPD Art. 18
Camera images30 days by default; configurable by the B2B Client up to 90 daysMinimum necessary limit
Person detections (events)90 daysSupport for incident review
Conversations with the AI assistant30 operational days; anonymized thereafterDialogue context and quality improvement
Operational telemetry (heartbeats, metrics)30 daysTroubleshooting

8.2. Anonymization: when the retention period expires, data are deleted or anonymized (removal of identifiers, keeping aggregated statistics).

8.3. Adjustment upon request: the B2B Client may request extended retention (up to the legal maximum) or reduced retention (minimum compatible with security) for configurable categories.

9. Data Subject Rights (LGPD Art. 18)

9.1. The data subject may exercise the following rights, at any time, via [email protected] or through the settings panel:

  • Confirmation of the existence of processing
  • Access to the data · report in PDF and in a structured format (JSON/CSV)
  • Correction of incomplete, inaccurate, or outdated data
  • Anonymization, blocking, or deletion of unnecessary, excessive, or non-compliantly processed data
  • Portability of the data to another provider
  • Deletion of data processed on the basis of consent (respecting mandatory legal retention periods)
  • Information about sharing with public and private entities
  • Information about the possibility of withholding consent and the consequences
  • Revocation of consent under the terms of Art. 8, §5
  • Objection to processing carried out on the basis of a consent-exemption hypothesis, in the event of non-compliance with the LGPD
  • Review of automated decisions that affect their interests

9.2. Response time: up to 15 calendar days from the request, under the terms of Art. 19, §1 of the LGPD.

9.3. Identity validation: to protect against fraudulent requests, SkyX may request identity confirmation before fulfilling the request.

9.4. Free of charge: the exercise of these rights is free. In exceptional cases of manifestly unfounded or excessive requests, SkyX may charge an administrative fee or refuse the request, providing a formal justification.

10. Information Security

10.1. SkyX adopts technical and administrative measures compatible with industry standards to protect personal data:

  • Encryption in transit: all communications between the client and the server use TLS 1.2+ (HTTPS).
  • Encryption at rest: production databases with disk-level encryption.
  • Authentication: passwords stored with bcrypt hashing at an adequate cost; JWT tokens with rotation; 2FA available.
  • Access control: principle of least privilege; roles (admin, building manager, resident); auditing of access to sensitive data.
  • Infrastructure: SkyX's own servers in Brazil (São Paulo) with operational replication in South Korea via pgEdge Spock; regional redundancy; regular backups with tested restoration.
  • Segregation: data of different Clients are logically segregated; permission validation on every operation.
  • Monitoring: anomaly detection, intrusion alerts, immutable audit logs.
  • Training: personnel with access to personal data receive training in the LGPD and best practices.

10.2. Continuous assessment: SkyX conducts periodic reviews of its controls and updates them as threats evolve.

10.3. Limitations: despite all efforts, no system is 100% secure. SkyX does not guarantee absolute invulnerability; it undertakes to comply with the LGPD in the event of an incident (Section 11).

11. Security Incidents (LGPD Art. 48)

11.1. In the event of a security incident that may cause relevant risk or harm to data subjects:

  • Containment: immediate actions to limit the impact.
  • Notification to the ANPD: within a period compatible with the authority's guidelines (currently interpreted as up to 2 business days from becoming aware).
  • Notification to affected data subjects: by e-mail and/or WhatsApp, containing the nature of the affected data, measures taken, recommendations to the data subject, and the DPO's contact.
  • Recording and root-cause analysis.
  • Corrective measures to prevent recurrence.

12. Cookies and Similar Technologies

12.1. SkyX's website and application use cookies for essential operation, authentication, and experience improvement.

12.2. Non-essential cookies (e.g., analytics) are used only with explicit consent via the cookie banner.

13. Minors

13.1. The Service is not intended for the direct registration of persons under 18 years of age.

13.2. Minors may be included in B2B installations (as condominium residents) or B2C installations (as dependents in home automation). In these cases:

  • Registration is done by an adult legal guardian.
  • Personal data of minors are processed under reinforced protection (LGPD Art. 14).
  • Facial recognition of minors requires the express consent of the legal guardian, with a record of the kinship relationship.

13.3. If SkyX identifies inadvertent processing of a minor's data without proper consent, it will take immediate corrective measures, including deletion of the data.

14. Changes to this Policy

14.1. This Policy may be updated to reflect:

  • Evolution of the Service and its processing activities.
  • Legal updates (LGPD, Marco Civil, new ANPD regulations).
  • Changes in sub-processors.

14.2. Material changes will be notified at least 30 days in advance, by e-mail and notice in the user's panel.

14.3. The user may always consult the current version at https://skyxsmart.com/en/privacy.

15. Contact and Authority

15.1. Data Protection Officer (DPO): Gabriel De Melo Filipe

  • E-mail: [email protected]
  • WhatsApp: +55 (61) 99904-2267
  • Address: Q SMPW Trecho 3, Bloco A, SN, Sala 110 - Setor de Indústrias Bernardo Sayão, CEP 71.736-301, Brasília/DF, Brazil

15.2. Channel for exercising rights (DSAR): [email protected]

15.3. Data Protection Authority (ANPD): if the response from SkyX is not satisfactory, the data subject may file a complaint with the ANPD · Brazilian National Data Protection Authority, at https://www.gov.br/anpd/pt-br.


Internal working draft. Legal review pending.