Privacy Policy
This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use the Service, and outlines your rights and choices under the GDPR and other applicable law.
The Terms of Service incorporate the Privacy Policy and the DPA by reference. The measures published on the Security page are Annex III of the DPA. The Imprint is the disclosure required by § 5 ECG and is not part of the agreement.
Introduction
This Privacy Policy is issued by Sykik [FlexCo i.G.] ("Sykik," "we," "us," or "our"), provider of the Sykik AI service and related software, integrations, and documentation (collectively, the "Service"). Sykik integrates with your Google Workspace or Microsoft Office environment (Gmail, Calendar, Drive, Chat, Outlook, OneDrive, Teams) to help you and your colleagues be more productive by blending AI-generated analysis, drafting, and proactive suggestions into your existing workflows.
This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use the Service, and outlines your rights and choices under the GDPR and other applicable law. By using the Service, you agree to the practices described in this Privacy Policy.
We review this Privacy Policy at least annually to ensure it remains accurate, complete, and compliant with applicable law and our internal data governance standards.
Key definitions
- Customer Data
- Data submitted to or processed by the Service on your behalf, including: connection credentials (OAuth tokens), workspace/user identifiers, email and chat content, calendar events, document content, voice/audio recordings (where enabled), AI conversation history, drafts and outputs generated by Sykik, and service logs.
- Controller
- The entity determining the purposes and means of processing personal data — for data Sykik processes to run the Service, Sykik is normally the Controller; for data processed on behalf of a customer organisation under a Sykik-for-Business contract, the customer organisation is the Controller and Sykik is the Processor.
Controller and Data Protection Officer
Controller: Sykik [FlexCo i.G.], Wollzeile 6-8, 46, 1010 Vienna, Austria, [FN Number — to be added after incorporation].
Sykik has appointed a Data Protection Officer (DPO) in accordance with Article 37 GDPR.
DPO: Hermann Wagner. Email: sykik-privacy@sykik.ai. Postal: Wollzeile 6-8, 46, 1010 Vienna, Austria.
Information We Collect
We collect only the information necessary to provide, maintain, and secure the Service.
A. Workspace and user information
When you install or use Sykik, we may store: workspace/organisation identifiers, administrator information for the person who installs Sykik (name and email as provided by Google/Microsoft), and user identifiers for users who interact with Sykik (user ID, display name, email address as provided by the SSO provider).
B. Connection credentials
We store credentials necessary to maintain integrations, including OAuth access/refresh tokens, token scopes, and expiration metadata for Google Workspace and Microsoft 365 integrations you enable. Integrations are scoped per-user; each user's OAuth grant governs exactly which of their own data Sykik may access.
C. Content processed inside Sykik
We process (and, depending on the feature, may briefly store) content needed to provide the Service, including:
- Email content and metadata (from/to/cc/bcc, subject, body, attachments) accessed via Gmail/Outlook API scopes you grant
- Chat messages (Google Chat / Microsoft Teams) accessed via granted scopes
- Calendar events (title, participants, time, location, description)
- Document content (Google Drive / OneDrive / SharePoint files) accessed via granted scopes
- Conversation threads between you and Sykik, including AI-generated outputs and tool calls
- Draft emails, chat replies, and other AI-generated content pending your review
- Scheduled/proactive task configurations and their outputs
D. Voice and audio data
Where you use real-time multi-modal (voice/audio) conversation features, we process audio input and may generate synthetic voice output. This may include emotion-recognition or voice-synthesis processing depending on the feature. Use of these features requires your explicit consent and is disclosed in-product per Article 50(3)/(4) EU AI Act (see Section 10).
E. Service logs and usage data
Service logs and audit/security logs (timestamps, error logs, request/response metadata), and usage events needed to operate and improve reliability (features used, suggestions accepted/rejected, tasks executed).
F. Website and product analytics
When you visit sykik.ai or use in-product analytics-instrumented surfaces, we may collect cookie/pixel identifiers used for analytics, device and browser metadata, IP address, pages viewed, and interaction events, subject to your cookie consent choices (Section 17).
G. Communications with us
If you contact us (support requests, email), we collect the information you provide in those communications.
Special category / sensitive data
Sykik does not intentionally process special categories of personal data under Article 9 GDPR. However, because Sykik processes the content of emails, chat messages, and documents at your direction, such data may appear incidentally (e.g. health information mentioned in an email). Users must not deliberately route special category data through Sykik outside the intended use case.
How We Use Your Information
A. Provide and operate the Service
Authenticate users and workspaces; maintain Google Workspace and Microsoft 365 integrations you enable; execute tasks, respond to requests, generate outputs, and provide context continuity across conversations.
B. AI processing to generate outputs
Relevant portions of Customer Data are processed by AI systems (routed via OpenRouter to underlying model providers) to produce email drafts, chat replies, summaries, suggestions, and other outputs at your direction.
- We do not use Customer Data for advertising.
- We do not train our own or third-party foundation models on Customer Data, and our processor agreements require model providers not to do so for models we route to.
- See Section 6 for full AI-provider disclosure.
C. Maintain security, safety, and integrity
Detect and prevent fraud, abuse, and unauthorized access; investigate incidents; maintain audit trails.
D. Service improvement (aggregated or de-identified)
We may use aggregated or de-identified data that cannot reasonably identify you to understand usage patterns and improve reliability.
E. Communications
Send service-related communications (product updates, security notices, billing messages) and provide customer support.
F. Compliance and protection
Comply with legal obligations, enforce our Terms of Use, and protect the rights, safety, and property of our users and Sykik.
Legal Basis for Processing (GDPR)
AI Technology Partners
When you invoke AI features, the relevant prompt/context needed to generate an output is sent — via our inference gateway, OpenRouter — to a third-party AI model provider. We require these providers, contractually and through OpenRouter's routing policies, to use your data only to generate the requested output and not for advertising or training their general models.
AI provider details
- AI workloads are routed through OpenRouter, Inc., which selects the underlying model provider based on your workspace's configured preferences (cost-optimised, performance-optimised, or a specific model/provider you choose — reflecting Sykik's freedom-of-choice architecture).
- Underlying providers may include Anthropic, OpenAI, Google, Mistral, and open-weights model hosts, depending on the model selected for your workspace.
- Data tenancy: your data is processed in isolated API requests and is not shared with or visible to other customers.
- No training: OpenRouter does not use your Inputs or Outputs for model training. We configure our OpenRouter account to exclude providers whose own terms permit training on submitted data (as of this policy, this excludes DeepSeek and NVIDIA-hosted endpoints).
- Data retention by providers: providers may temporarily retain data (typically 0-30 days) for security and abuse monitoring, in accordance with their own API retention policies. We enable Zero Data Retention (ZDR) endpoints where offered.
- Data residency: AI providers process data in the United States or other regions used by those providers, under Standard Contractual Clauses and/or EU-US Data Privacy Framework adequacy where applicable (see Section 11).
- Current list: the authoritative, current list of AI providers and their data practices is maintained at [sykik.ai/subprocessors] and openrouter.ai/docs/features/provider-routing.
Fine-tuning (planned feature)
Sykik may in future offer customer-specific model fine-tuning as an opt-in feature. Where implemented, each customer's fine-tuned model will be architected as a separate AI system with that customer as deployer and Sykik as processor/tool provider, to avoid Sykik becoming the general-purpose AI (GPAI) provider for every customer model under the EU AI Act. This policy will be updated with specific consent and retention terms before the feature launches.
Google Workspace API Services — Limited Use Disclosure
Sykik's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- Sykik accesses Gmail, Google Calendar, Google Drive, and Google Chat data only after you explicitly grant permission through Google's OAuth consent screen, scoped to exactly the data categories you authorize.
- Sykik uses Google user data solely to provide or improve user-facing features that are prominent in the requesting application's interface (i.e. the AI drafting, analysis, scheduling, and suggestion features you see and use in Sykik) — consistent with the accompanying descriptions in the OAuth consent screen.
- Sykik does not transfer Google user data to third parties except: (a) with your explicit consent, (b) for security purposes (e.g. investigating abuse), (c) to comply with applicable law, or (d) as part of a merger, acquisition, or sale of assets, in which case Sykik will continue to ensure the confidentiality of your data.
- Sykik does not use Google user data for serving advertisements.
- Sykik does not allow humans to read Google user data unless: (a) we have your affirmative agreement for specific messages/files, (b) it is necessary for security purposes, (c) it is necessary to comply with applicable law, or (d) it is aggregated and anonymized and used for internal operations in accordance with our applicable privacy policy and consistent with the applicable Google API Terms of Service.
- Sykik does not use Gmail, Drive, or Calendar data to train or improve generalized AI/ML models that are not used to provide the requesting application's user-facing features.
You can revoke Sykik's access to your Google Workspace data at any time via your Google Account permissions page (myaccount.google.com/permissions). After revocation, we stop collecting new data from the relevant Google API immediately; previously stored data is deleted per Section 12 (Data Retention).
Microsoft Graph API Compliance (where enabled)
Where a customer's workspace uses Microsoft 365 integrations (Outlook, OneDrive, Teams) instead of or alongside Google Workspace, the same Limited Use principles apply by commitment: access only via explicit OAuth consent, use limited to the features you request, no advertising use, no use to train generalized AI/ML models beyond providing the requested feature, and revocability at any time via your Microsoft 365 admin/account permissions.
Data Processors (Sub-Processors)
Sykik engages the following processors to provide its Service. All processors are, or will be prior to public launch, bound by Data Processing Agreements (DPAs) under Article 28 GDPR.
A current, authoritative list of sub-processors will be maintained and updated at sykik.ai/subprocessors. Customers will be notified of material changes to this list in accordance with the change-notification terms of their Data Processing Agreement.
Automated Decision-Making & AI Transparency
Sykik uses AI to analyse, draft, summarise, and suggest content. Per Article 22 GDPR, you have the right not to be subject to decisions based solely on automated processing that produce legal effects concerning you, and to request human intervention.
Sykik's AI suggestions are assistive — the user always reviews, edits, and confirms before any action (such as sending an email or scheduling a meeting) is taken. Sykik does not make autonomous decisions that produce legal effects concerning data subjects.
In accordance with the EU AI Act, Sykik is classified as a Limited Risk AI system (Article 50). Users are informed that they interact with an AI system via:
- In-product indicators (badge/icon on AI-generated responses, e.g. "Drafted by Sykik AI")
- This privacy policy section
- Onboarding flow disclosure at first use
Where voice features involve synthetic voice generation, this is disclosed as artificially generated per Article 50(3). Where voice features involve emotion recognition, this is disclosed to users per Article 50(4).
International Transfers
Sykik primarily processes data within the EU (GCP EU regions). Where data is transferred to third countries — notably for AI model inference via OpenRouter to US-based model providers — such transfers are governed by:
- EU-US Data Privacy Framework adequacy decisions (Art. 45 GDPR), for certified recipients
- Standard Contractual Clauses (SCCs) under Art. 46 GDPR, for non-certified recipients
- A Transfer Impact Assessment (TIA), documented and available on request
We configure integrations to prefer EU-region processing where available (e.g. OpenRouter Enterprise EU in-region routing, once upgraded; GCP europe-west regions).
Data Retention
When an account is closed or we receive a validated deletion request, we delete Customer Data from active production systems typically within 30 days. Remaining copies are removed as encrypted backups age out on their normal rotation. Where legally permitted, customers may request an export of their data prior to deletion.
Data Subject Rights
Under the GDPR, you have the following rights:
- Access (Art. 15) — confirm what data is processed, receive a copy
- Rectification (Art. 16) — correct inaccurate data
- Erasure (Art. 17) — deletion, subject to legal retention obligations
- Restriction (Art. 18) — limit processing in certain circumstances
- Portability (Art. 20) — receive data in a structured, machine-readable format
- Object (Art. 21) — object to processing based on legitimate interest
- Withdraw consent — where processing is based on consent (e.g. voice features, non-essential cookies), you may withdraw at any time without affecting the lawfulness of prior processing
For workspace-level Customer Data, we may require the request to come from an authorized workspace administrator, or we may direct individual members to their workspace administrator, where the administrator's organisation is the Controller.
To exercise your rights, contact: sykik-privacy@sykik.ai. We will respond within 30 days (Art. 12(3)), extendable by a further 60 days for complex requests with notice to you.
You have the right to lodge a complaint with the Austrian Data Protection Authority: Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Wien, dsb.gv.at.
Technical and Organisational Measures (Security)
- Encryption in transit: TLS 1.3
- Encryption at rest: AES-256, via GCP-managed keys (CMEK under evaluation)
- Access control: RBAC, least-privilege, scoped OAuth per integration (each of Gmail, Calendar, Drive, Chat requested and granted separately)
- Secrets management: API keys for AI providers stored in GCP Secret Manager
- Audit logging: data access events logged and monitored
- Breach notification: internal runbook targeting 72-hour notification to the Austrian DSB per Article 33 GDPR, and notification to affected users without undue delay where required under Article 34
- Pseudonymisation: applied to analytics data where technically feasible
The full set of measures is published as Technical and Organisational Measures.
You are responsible for maintaining appropriate security in your own Google Workspace or Microsoft 365 environment (e.g. limiting who can install third-party apps, managing admin permissions).
Children's Privacy
The Service is a business productivity tool intended for use by working professionals and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16 (the GDPR's default digital consent age, absent a lower age set by Austrian law). If we learn we have collected such data, we will delete it promptly. Contact sykik-privacy@sykik.ai if you believe a child has provided personal data to us.
Business Transfers
If Sykik is involved in a merger, acquisition, restructuring, financing due diligence, insolvency, or sale of assets, personal data may be disclosed to advisors and successor entities, subject to confidentiality obligations and, where required, prior notice to affected users.
Cookies and Tracking Technologies
sykik.ai uses the following categories of cookies:
- Strictly necessary cookies (session, authentication) — exempt from consent under Austria's TTDSG §4, cannot be disabled
- Analytics cookies — require your opt-in consent before being set, per TTDSG §4. We use a consent management platform to obtain and record this consent before any analytics cookie is placed.
You can manage or withdraw cookie consent at any time via the cookie settings link in the site footer, or through your browser settings.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by appropriate means (e.g. notifying workspace administrators and/or emailing the address associated with the account). The "Version" date reflects the most recent revision. Your continued use of the Service after changes become effective indicates acceptance of the revised policy.
Contact Us
Controller: Sykik [FlexCo i.G.] · Wollzeile 6-8, 46, 1010 Vienna, Austria · [FN]
DPO: Hermann Wagner · sykik-privacy@sykik.ai
Supervisory Authority: Österreichische Datenschutzbehörde · dsb.gv.at