Privacy Policy

Last updated: 13 August 2026

This policy applies to the SkyX smart home platform, operated by SKYX AUTOMAÇÃO LTDA.

Data Controller: SKYX AUTOMAÇÃO LTDA, CNPJ (Brazilian corporate taxpayer registry) 62.757.825/0001-02, headquartered at Q SMPW Trecho 3, Bloco A, SN, Sala 110 - Setor de Indústrias Bernardo Sayão, CEP 71.736-301, Brasília/DF, Brazil.

Data Protection Officer (DPO): Gabriel De Melo Filipe, contact [email protected].

Contact for exercising rights: [email protected].

1. Introduction

1.1. This Privacy Policy describes how SkyX collects, uses, stores, shares, and protects the personal data of users of its residential and building automation platform.

1.2. SkyX undertakes to process personal data in compliance with the Brazilian General Data Protection Law (LGPD, Law No. 13,709/2018), the Brazilian Internet Civil Framework (Marco Civil da Internet, Law No. 12,965/2014), and other applicable regulations.

1.3. This Policy applies to all users: B2B Clients (condominiums and property managers), B2C Clients (household residents), Residents at B2B installations, and website visitors.

1.4. By using the Service, the user declares that they have read and agreed to this Policy. Specific processing of sensitive data (biometrics) requires additional consent, as set out in Section 6.

2. Roles in Data Protection

2.1. SkyX as Controller: for data collected directly by SkyX, such as:

  • Client registration data (name, e-mail, CPF/CNPJ where applicable, address).
  • Service usage data (access logs, operational telemetry, quality metrics).
  • Financial and billing data.
  • Support data (ticket history).

2.2. SkyX as Processor: for data that B2B Clients enter into the Service about their Residents:

  • The B2B Client is the Controller of such data.
  • SkyX acts as Processor, handling it in accordance with the B2B Client's instructions and within the limits of this Policy.
  • Examples: resident records, facial images of residents enrolled for recognition (B2B only), visitor access logs.

2.3. In the B2C case (Home-Installed), the Client themselves is simultaneously the Controller of personal data they enter into the Service about members of their family or invited residents. SkyX acts as Processor in these cases.

3. Personal Data Collected

3.1. Registration Data

CategoryExamplesSource
IdentificationName, e-mail, phone, CPF (optional), CNPJ (B2B)Provided at registration
AddressStreet, neighborhood, city, state, ZIP codeProvided at registration / SOW
ProfessionalRole/function (building manager, resident, admin)Provided at registration
AuthenticationPassword (stored as a hash), session tokensGenerated by the system

3.2. Usage and Telemetry Data

CategoryExamplesSource
Access logsDate/time, source IP, resource accessedCollected automatically
User actionsCommands, configuration changesCollected automatically
Device telemetrySensor states, energy consumption, eventsCollected from connected devices
Operational metricsLatency, errors, software versionCollected automatically

3.3. Media Data

CategoryExamplesSource
Camera imagesContinuous or on-demand video, detected events (person, vehicle)Installed cameras
Facial imagesEnrollment photos for facial recognition (B2B only, when enabled)Captured by the user
Biometric embeddingsMathematical vectors derived from facial images (B2B only, when enabled)Internal processing
AudioOnly when the user starts SkyX in-app voice transcription. Voice assistants such as Google Home, Alexa, and Siri send structured commands, not raw microphone audio (Section 8).Captured by the device, when the user starts the feature

3.4. Payment Data

Processed by Stripe. SkyX does not store the full card number; it stores only reference tokens and the last 4 digits for identification.

3.5. Sensitive Data (LGPD Art. 11)

Biometric data (facial images and embeddings) are considered sensitive personal data. Home-Installed (B2C) cannot enable facial recognition. In B2B, processing requires specific and prominent consent. The B2B Client may enable the feature and, in doing so, must present the Consent Form to each person whose face will be enrolled.

4. Legal Bases for Processing (LGPD Art. 7 and 11)

4.1. SkyX uses the following legal bases according to the nature of the data:

Legal basis (LGPD)Applies toExample
Performance of a contract (Art. 7, V)Data necessary to deliver the ServiceRegistration, authentication, operational telemetry, billing
Consent (Art. 7, I; Art. 11, I)Optional features and sensitive dataB2B facial recognition, promotional notifications, optional cloud AI
Legitimate interest (Art. 7, IX)Security, fraud prevention, Service improvementSecurity logs, abuse detection, aggregated metrics
Compliance with a legal obligation (Art. 7, II)Tax data, retention for regulatory bodiesElectronic invoices (NF-e), audit logs, labor obligations
Protection of life or physical safety (Art. 7, VII)Emergency situationsElderly fall detection, leak alarm

4.2. For biometric data, the legal basis is specific consent (Art. 11, I), revocable at any time, without prejudice to rights exercised previously. This applies only when a B2B Client has enabled facial recognition.

5. Purposes of Processing

5.1. Personal data are processed exclusively for the following purposes:

  • Provision of the contracted Service: enabling the operation of automation, monitoring, control, and notification features.
  • Communication with the user: technical support, operational notifications, billing, legal communications.
  • Security: detection of unauthorized access, fraud prevention, preservation of integrity.
  • Service improvement: aggregated and anonymized usage analysis to identify bugs, optimize performance, and develop new features.
  • Legal compliance: issuance of tax invoices, response to legal requests, minimum retention required by law.
  • Facial recognition (B2B only, optional, subject to consent): identification of registered persons for access control, notification to the building manager/resident about unknown visitors.

5.2. Explicit prohibitions: SkyX does not use personal data for:

  • Sale or sharing with third parties for advertising purposes.
  • Training SkyX or third-party AI models on identifiable client data, including data received from the Google Home Developer Platform.
  • Behavioral monitoring for profit beyond what is strictly necessary to provide the contracted Service.

6. Processing of Biometric Data (LGPD Art. 11)

Home-Installed (residential) notice

In the current Home-Installed (B2C) plan, facial recognition is disabled and cannot be enabled by the Client. Sections 6.1 and following apply only when a B2B Client (building management) enables the feature. This keeps consent simpler and reduces risk for household residents in the early product phase.

6.1. Facial recognition is available only in B2B. It is optional and disabled by default. Enabling it requires explicit action by the B2B Client. Home-Installed (B2C) Clients cannot enable it.

6.2. Each person whose face will be enrolled must sign the Biometric Consent Form before processing.

6.3. Minors: biometric enrollment of minors follows the protections of Art. 14 of the LGPD. It requires the express consent of at least one legal guardian, registered on the platform as "Guardian", with a record of the kinship relationship.

6.4. Storage: facial images and embeddings are stored on SkyX's own servers in Brazil (São Paulo) with an operational replica in South Korea. They are not sent to third-party cloud services for processing or storage.

6.5. Right to revoke: biometric consent may be revoked at any time via e-mail at [email protected]or through the app. Upon revocation, the user's facial images and embeddings are deleted within a maximum of 7 calendar days; biometric audit logs (which do not contain images) are retained in accordance with legal retention requirements.

6.6. Accuracy: the technology has a margin of error. Both mistaken recognition and failure to recognize are possible. SkyX does not recommend using the results as sole evidence for legal or punitive decisions.

7. Sharing and Sub-processors

7.1. To provide the Service, SkyX shares data with selected sub-processors:

Sub-processorPurposeData sharedLocation
StripePayment processingPayment tokens, tax identificationUSA with LGPD SCCs
eNotas (or equivalent)Issuance of electronic invoices (NF-e)Client tax dataBrazil
TailscaleSecure mesh VPN between the local server and cloudNode identifiers, network metadataUSA with LGPD SCCs
CloudflareWeb proxy and DDoS protectionWeb requests, source IPUSA with LGPD SCCs
xAI (optional cloud AI)AI response generationChat prompts (when the user uses cloud AI)USA with LGPD SCCs
Groq (optional voice transcription)Speech-to-text conversionAudio sent when the user uses cloud transcriptionUSA with LGPD SCCs
SentryError monitoringStack traces, technical metadata (no PII by design)USA with LGPD SCCs
Alexa / Google / Siri (optional)Voice controlSkyX account identity, device catalog, and device state needed to run commands (see Section 8)As per those services' policies

7.2. SkyX applies contractual safeguards appropriate to each transfer, including Standard Contractual Clauses where required.

7.3. International transfers: when data are transferred outside Brazil (for example, Stripe), Standard Contractual Clauses approved by the ANPD are used as a supplementary safeguard, under the terms of Art. 33 of the LGPD.

7.4. No sale of data: SkyX does not sell personal data to third parties, including for advertising. Transfers are exclusively for the provision of the Service.

7.5. Legal disclosure: SkyX may disclose data pursuant to a court order, a valid request from a competent authority, or to protect the rights of SkyX, users, or third parties, always respecting the principle of purpose limitation and notifying the data subject when legally permitted.

8. Voice assistants (Google Home, Alexa, Siri)

8.1. SkyX can link to Google Home, Amazon Alexa, and Apple Siri so you can control devices by voice. Account linking shares the SkyX account identity and the device catalog and state needed to execute commands.

8.2. SkyX does not receive raw microphone audio from Google, Alexa, or Siri. Those platforms process speech on their side and send SkyX structured commands (for example, turn on a light or set a scene).

8.3. You can unlink SkyX in Google Home, Alexa, or SkyX settings. When you unlink, access tokens are revoked.

8.4. Data received from the Google Home Developer Platform is not used to train SkyX AI models or third-party AI models.

8.5. If you use SkyX's own in-app voice features (optional cloud transcription), audio is sent only when you start that feature. That path is separate from Google Home, Alexa, and Siri.

9. Data Retention

9.1. Data are retained for the time strictly necessary for the stated purposes or for the period required by law:

CategoryRetention periodJustification
Registration dataDuring the term of the contract + 5 years after terminationLimitation period for contractual obligations
Tax data (NF-e, payments)5 yearsLegal obligation (art. 173 of the Brazilian Tax Code, CTN)
Biometric audit logs365 daysLGPD Art. 37, demonstration of compliance
Facial images and embeddingsAs long as consent is active; deleted within 7 days after revocationLGPD Art. 18
Camera images30 days by default; configurable by the B2B Client up to 90 daysMinimum necessary limit
Person detections (events)90 daysSupport for incident review
Conversations with the AI assistant30 operational days; anonymized thereafterDialogue context and quality improvement
Operational telemetry (heartbeats, metrics)30 daysTroubleshooting

9.2. Anonymization: when the retention period expires, data are deleted or anonymized (removal of identifiers, keeping aggregated statistics).

9.3. Adjustment upon request: the B2B Client may request extended retention (up to the legal maximum) or reduced retention (minimum compatible with security) for configurable categories.

10. Data Subject Rights (LGPD Art. 18)

10.1. The data subject may exercise the following rights, at any time, via [email protected] or through the settings panel:

  • Confirmation of the existence of processing
  • Access to the data: report in PDF and in a structured format (JSON/CSV)
  • Correction of incomplete, inaccurate, or outdated data
  • Anonymization, blocking, or deletion of unnecessary, excessive, or non-compliantly processed data
  • Portability of the data to another provider
  • Deletion of data processed on the basis of consent (respecting mandatory legal retention periods)
  • Information about sharing with public and private entities
  • Information about the possibility of withholding consent and the consequences
  • Revocation of consent under the terms of Art. 8, §5
  • Objection to processing carried out on the basis of a consent-exemption hypothesis, in the event of non-compliance with the LGPD
  • Review of automated decisions that affect their interests

10.2. Response time: up to 15 calendar days from the request, under the terms of Art. 19, §1 of the LGPD.

10.3. Identity validation: to protect against fraudulent requests, SkyX may request identity confirmation before fulfilling the request.

10.4. Free of charge: the exercise of these rights is free. In exceptional cases of manifestly unfounded or excessive requests, SkyX may charge an administrative fee or refuse the request, providing a formal justification.

11. Information Security

11.1. SkyX adopts technical and administrative measures compatible with industry standards to protect personal data:

  • Encryption in transit: all communications between the client and the server use TLS 1.2+ (HTTPS).
  • Encryption at rest: production databases with disk-level encryption.
  • Authentication: passwords stored with bcrypt hashing at an adequate cost; JWT tokens with rotation; 2FA available.
  • Access control: principle of least privilege; roles (admin, building manager, resident); auditing of access to sensitive data.
  • Infrastructure: SkyX's own servers in Brazil (São Paulo) with an operational replica in South Korea; regional redundancy; regular backups with tested restoration.
  • Segregation: data of different Clients are logically segregated; permission validation on every operation.
  • Monitoring: anomaly detection, intrusion alerts, immutable audit logs.
  • Training: personnel with access to personal data receive training in the LGPD and best practices.

11.2. Continuous assessment: SkyX conducts periodic reviews of its controls and updates them as threats evolve.

11.3. Limitations: despite all efforts, no system is 100% secure. SkyX does not guarantee absolute invulnerability; it undertakes to comply with the LGPD in the event of an incident (Section 12).

12. Security Incidents (LGPD Art. 48)

12.1. In the event of a security incident that may cause relevant risk or harm to data subjects:

  • Containment: immediate actions to limit the impact.
  • Notification to the ANPD: within a period compatible with the authority's guidelines (currently interpreted as up to 2 business days from becoming aware).
  • Notification to affected data subjects: by e-mail and/or WhatsApp, containing the nature of the affected data, measures taken, recommendations to the data subject, and the DPO's contact.
  • Recording and root-cause analysis.
  • Corrective measures to prevent recurrence.

13. Cookies and Similar Technologies

13.1. SkyX uses essential cookies and browser storage so the service can function: authentication and session, language preference, and security. These are required to sign in, keep you signed in, and remember the language you chose.

13.2. SkyX does not use advertising cookies and does not sell personal data for ads.

13.3. SkyX operates a first-party Umami instance for operational traffic measurement. It is not an advertising product. The public site does not set advertising cookies or other non-essential third-party tracking cookies, so SkyX does not display a consent prompt for cookies.

13.4. You can delete cookies in your browser. If you delete essential cookies, you will need to sign in again and set your language again.

14. Minors

14.1. The Service is not intended for the direct registration of persons under 18 years of age.

14.2. Minors may be included in B2B installations (as condominium residents) or B2C installations (as dependents in home automation). In these cases:

  • Registration is done by an adult legal guardian.
  • Personal data of minors are processed under reinforced protection (LGPD Art. 14).
  • Facial recognition of minors (B2B only, when enabled) requires the express consent of the legal guardian, with a record of the kinship relationship.

14.3. If SkyX identifies inadvertent processing of a minor's data without proper consent, it will take immediate corrective measures, including deletion of the data.

15. Changes to this Policy

15.1. This Policy may be updated to reflect:

  • Evolution of the Service and its processing activities.
  • Legal updates (LGPD, Marco Civil, new ANPD regulations).
  • Changes in sub-processors.

15.2. Material changes will be notified at least 30 days in advance, by e-mail and notice in the user's panel.

15.3. The user may always consult the current version at https://skyxsmart.com/en/privacy.

16. Contact and Authority

16.1. Data Protection Officer (DPO): Gabriel De Melo Filipe

  • E-mail: [email protected]
  • WhatsApp: +55 (61) 99904-2267
  • Address: Q SMPW Trecho 3, Bloco A, SN, Sala 110 - Setor de Indústrias Bernardo Sayão, CEP 71.736-301, Brasília/DF, Brazil

16.2. Channel for exercising rights (DSAR): [email protected]

16.3. Data Protection Authority (ANPD): if the response from SkyX is not satisfactory, the data subject may file a complaint with the ANPD, the Brazilian National Data Protection Authority, at https://www.gov.br/anpd/pt-br.