Sykik
SecurityPricing
Request early access
Back to sykik.ai

Privacy Policy

Version 1 August 2026Effective 1 August 202619 sectionssykik.ai/privacy

This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use the Service, and outlines your rights and choices under the GDPR and other applicable law.

One agreement, four documents — plus the Imprint
Terms of ServicePrivacy PolicyData Processing AgreementSecurity · TOMsImprint

The Terms of Service incorporate the Privacy Policy and the DPA by reference. The measures published on the Security page are Annex III of the DPA. The Imprint is the disclosure required by § 5 ECG and is not part of the agreement.

Sections
  1. 1Introduction
  2. 2Controller and DPO
  3. 3Information we collect
  4. 4How we use your information
  5. 5Legal basis for processing
  6. 6AI technology partners
  7. 7Google Workspace API services
  8. 8Microsoft Graph API compliance
  9. 9Data processors
  10. 10Automated decision-making
  11. 11International transfers
  12. 12Data retention
  13. 13Data subject rights
  14. 14Technical and organisational measures
  15. 15Children's privacy
  16. 16Business transfers
  17. 17Cookies and tracking
  18. 18Changes to this policy
  19. 19Contact us
SECTION 1

Introduction

This Privacy Policy is issued by Sykik [FlexCo i.G.] ("Sykik," "we," "us," or "our"), provider of the Sykik AI service and related software, integrations, and documentation (collectively, the "Service"). Sykik integrates with your Google Workspace or Microsoft Office environment (Gmail, Calendar, Drive, Chat, Outlook, OneDrive, Teams) to help you and your colleagues be more productive by blending AI-generated analysis, drafting, and proactive suggestions into your existing workflows.

This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use the Service, and outlines your rights and choices under the GDPR and other applicable law. By using the Service, you agree to the practices described in this Privacy Policy.

We review this Privacy Policy at least annually to ensure it remains accurate, complete, and compliant with applicable law and our internal data governance standards.

Key definitions

Customer Data
Data submitted to or processed by the Service on your behalf, including: connection credentials (OAuth tokens), workspace/user identifiers, email and chat content, calendar events, document content, voice/audio recordings (where enabled), AI conversation history, drafts and outputs generated by Sykik, and service logs.
Controller
The entity determining the purposes and means of processing personal data — for data Sykik processes to run the Service, Sykik is normally the Controller; for data processed on behalf of a customer organisation under a Sykik-for-Business contract, the customer organisation is the Controller and Sykik is the Processor.
SECTION 2

Controller and Data Protection Officer

Controller: Sykik [FlexCo i.G.], Wollzeile 6-8, 46, 1010 Vienna, Austria, [FN Number — to be added after incorporation].

Sykik has appointed a Data Protection Officer (DPO) in accordance with Article 37 GDPR.

DPO: Hermann Wagner. Email: sykik-privacy@sykik.ai. Postal: Wollzeile 6-8, 46, 1010 Vienna, Austria.

SECTION 3

Information We Collect

We collect only the information necessary to provide, maintain, and secure the Service.

A. Workspace and user information

When you install or use Sykik, we may store: workspace/organisation identifiers, administrator information for the person who installs Sykik (name and email as provided by Google/Microsoft), and user identifiers for users who interact with Sykik (user ID, display name, email address as provided by the SSO provider).

B. Connection credentials

We store credentials necessary to maintain integrations, including OAuth access/refresh tokens, token scopes, and expiration metadata for Google Workspace and Microsoft 365 integrations you enable. Integrations are scoped per-user; each user's OAuth grant governs exactly which of their own data Sykik may access.

C. Content processed inside Sykik

We process (and, depending on the feature, may briefly store) content needed to provide the Service, including:

  • Email content and metadata (from/to/cc/bcc, subject, body, attachments) accessed via Gmail/Outlook API scopes you grant
  • Chat messages (Google Chat / Microsoft Teams) accessed via granted scopes
  • Calendar events (title, participants, time, location, description)
  • Document content (Google Drive / OneDrive / SharePoint files) accessed via granted scopes
  • Conversation threads between you and Sykik, including AI-generated outputs and tool calls
  • Draft emails, chat replies, and other AI-generated content pending your review
  • Scheduled/proactive task configurations and their outputs

D. Voice and audio data

Where you use real-time multi-modal (voice/audio) conversation features, we process audio input and may generate synthetic voice output. This may include emotion-recognition or voice-synthesis processing depending on the feature. Use of these features requires your explicit consent and is disclosed in-product per Article 50(3)/(4) EU AI Act (see Section 10).

E. Service logs and usage data

Service logs and audit/security logs (timestamps, error logs, request/response metadata), and usage events needed to operate and improve reliability (features used, suggestions accepted/rejected, tasks executed).

F. Website and product analytics

When you visit sykik.ai or use in-product analytics-instrumented surfaces, we may collect cookie/pixel identifiers used for analytics, device and browser metadata, IP address, pages viewed, and interaction events, subject to your cookie consent choices (Section 17).

G. Communications with us

If you contact us (support requests, email), we collect the information you provide in those communications.

Special category / sensitive data

Sykik does not intentionally process special categories of personal data under Article 9 GDPR. However, because Sykik processes the content of emails, chat messages, and documents at your direction, such data may appear incidentally (e.g. health information mentioned in an email). Users must not deliberately route special category data through Sykik outside the intended use case.

SECTION 4

How We Use Your Information

A. Provide and operate the Service

Authenticate users and workspaces; maintain Google Workspace and Microsoft 365 integrations you enable; execute tasks, respond to requests, generate outputs, and provide context continuity across conversations.

B. AI processing to generate outputs

Relevant portions of Customer Data are processed by AI systems (routed via OpenRouter to underlying model providers) to produce email drafts, chat replies, summaries, suggestions, and other outputs at your direction.

  • We do not use Customer Data for advertising.
  • We do not train our own or third-party foundation models on Customer Data, and our processor agreements require model providers not to do so for models we route to.
  • See Section 6 for full AI-provider disclosure.

C. Maintain security, safety, and integrity

Detect and prevent fraud, abuse, and unauthorized access; investigate incidents; maintain audit trails.

D. Service improvement (aggregated or de-identified)

We may use aggregated or de-identified data that cannot reasonably identify you to understand usage patterns and improve reliability.

E. Communications

Send service-related communications (product updates, security notices, billing messages) and provide customer support.

F. Compliance and protection

Comply with legal obligations, enforce our Terms of Use, and protect the rights, safety, and property of our users and Sykik.

SECTION 5

Legal Basis for Processing (GDPR)

Data category
Purpose
Legal basis
Email/chat/calendar/document content
Purpose
AI drafting, analysis, summarisation, suggestions
Legal basis
Legitimate interest (Art. 6(1)(f)) — or contract performance under a Sykik-for-Business agreement
Voice & audio recordings
Purpose
Real-time multimodal conversations
Legal basis
Consent (Art. 6(1)(a))
Account data (name, email, profile)
Purpose
Account creation, authentication, billing
Legal basis
Contract performance (Art. 6(1)(b))
Usage/product analytics
Purpose
Product improvement, troubleshooting
Legal basis
Legitimate interest (Art. 6(1)(f)); consent where non-essential cookies are used
Payment data
Purpose
Billing
Legal basis
Contract performance (Art. 6(1)(b))
Service/security logs
Purpose
Fraud prevention, security, abuse detection
Legal basis
Legitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c))
SECTION 6

AI Technology Partners

When you invoke AI features, the relevant prompt/context needed to generate an output is sent — via our inference gateway, OpenRouter — to a third-party AI model provider. We require these providers, contractually and through OpenRouter's routing policies, to use your data only to generate the requested output and not for advertising or training their general models.

AI provider details

  • AI workloads are routed through OpenRouter, Inc., which selects the underlying model provider based on your workspace's configured preferences (cost-optimised, performance-optimised, or a specific model/provider you choose — reflecting Sykik's freedom-of-choice architecture).
  • Underlying providers may include Anthropic, OpenAI, Google, Mistral, and open-weights model hosts, depending on the model selected for your workspace.
  • Data tenancy: your data is processed in isolated API requests and is not shared with or visible to other customers.
  • No training: OpenRouter does not use your Inputs or Outputs for model training. We configure our OpenRouter account to exclude providers whose own terms permit training on submitted data (as of this policy, this excludes DeepSeek and NVIDIA-hosted endpoints).
  • Data retention by providers: providers may temporarily retain data (typically 0-30 days) for security and abuse monitoring, in accordance with their own API retention policies. We enable Zero Data Retention (ZDR) endpoints where offered.
  • Data residency: AI providers process data in the United States or other regions used by those providers, under Standard Contractual Clauses and/or EU-US Data Privacy Framework adequacy where applicable (see Section 11).
  • Current list: the authoritative, current list of AI providers and their data practices is maintained at [sykik.ai/subprocessors] and openrouter.ai/docs/features/provider-routing.

Fine-tuning (planned feature)

Sykik may in future offer customer-specific model fine-tuning as an opt-in feature. Where implemented, each customer's fine-tuned model will be architected as a separate AI system with that customer as deployer and Sykik as processor/tool provider, to avoid Sykik becoming the general-purpose AI (GPAI) provider for every customer model under the EU AI Act. This policy will be updated with specific consent and retention terms before the feature launches.

SECTION 7

Google Workspace API Services — Limited Use Disclosure

Sykik's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • Sykik accesses Gmail, Google Calendar, Google Drive, and Google Chat data only after you explicitly grant permission through Google's OAuth consent screen, scoped to exactly the data categories you authorize.
  • Sykik uses Google user data solely to provide or improve user-facing features that are prominent in the requesting application's interface (i.e. the AI drafting, analysis, scheduling, and suggestion features you see and use in Sykik) — consistent with the accompanying descriptions in the OAuth consent screen.
  • Sykik does not transfer Google user data to third parties except: (a) with your explicit consent, (b) for security purposes (e.g. investigating abuse), (c) to comply with applicable law, or (d) as part of a merger, acquisition, or sale of assets, in which case Sykik will continue to ensure the confidentiality of your data.
  • Sykik does not use Google user data for serving advertisements.
  • Sykik does not allow humans to read Google user data unless: (a) we have your affirmative agreement for specific messages/files, (b) it is necessary for security purposes, (c) it is necessary to comply with applicable law, or (d) it is aggregated and anonymized and used for internal operations in accordance with our applicable privacy policy and consistent with the applicable Google API Terms of Service.
  • Sykik does not use Gmail, Drive, or Calendar data to train or improve generalized AI/ML models that are not used to provide the requesting application's user-facing features.

You can revoke Sykik's access to your Google Workspace data at any time via your Google Account permissions page (myaccount.google.com/permissions). After revocation, we stop collecting new data from the relevant Google API immediately; previously stored data is deleted per Section 12 (Data Retention).

SECTION 8

Microsoft Graph API Compliance (where enabled)

Where a customer's workspace uses Microsoft 365 integrations (Outlook, OneDrive, Teams) instead of or alongside Google Workspace, the same Limited Use principles apply by commitment: access only via explicit OAuth consent, use limited to the features you request, no advertising use, no use to train generalized AI/ML models beyond providing the requested feature, and revocability at any time via your Microsoft 365 admin/account permissions.

SECTION 9

Data Processors (Sub-Processors)

Sykik engages the following processors to provide its Service. All processors are, or will be prior to public launch, bound by Data Processing Agreements (DPAs) under Article 28 GDPR.

Subprocessor
Service / purpose
Data potentially processed
Google Cloud Platform (GCP)
Service / purpose
Cloud infrastructure — hosting, storage, compute (EU region)
Data potentially processed
All Customer Data, encrypted at rest and in transit
OpenRouter, Inc.
Service / purpose
AI model inference gateway — routes requests to model providers
Data potentially processed
Prompt/context text sent for AI processing; see Section 6
Anthropic / OpenAI / Google / Mistral / other model providers
Service / purpose
Underlying LLM inference (via OpenRouter routing)
Data potentially processed
Prompt/context text, only for the duration of the inference request (ZDR enabled where available)
Google Workspace APIs
Service / purpose
Source integration — Gmail, Calendar, Drive, Chat (customer-authorized)
Data potentially processed
Email, calendar, document, chat content per granted OAuth scopes
Microsoft Graph API
Service / purpose
Source integration — Outlook, OneDrive, Teams (customer-authorized, where enabled)
Data potentially processed
Email, calendar, document, chat content per granted OAuth scopes
Stripe
Service / purpose
Payment processing and billing
Data potentially processed
Billing contact info, transaction metadata (card details handled by Stripe directly, PCI-DSS compliant)
PostHog
Service / purpose
Product analytics
Data potentially processed
Usage events, identifiers, session metadata (subject to cookie consent)
Brevo
Service / purpose
Transactional email delivery and marketing communications
Data potentially processed
Recipient addresses and email content sent by the Service
Slack
Service / purpose
Source integration — Slack messaging (customer-authorized)
Data potentially processed
Channel messages, DMs, thread replies, user profile info per granted OAuth scopes
Cloudflare
Service / purpose
CDN, DDoS protection, edge security, DNS
Data potentially processed
Network metadata, request logs, IP addresses
HubSpot
Service / purpose
CRM integration (if enabled by customer)
Data potentially processed
CRM records and metadata authorized by customer
Meta Ads
Service / purpose
Ads integration (if enabled by customer)
Data potentially processed
Ads account and reporting data authorized by customer
Google Ads
Service / purpose
Ads integration (if enabled by customer)
Data potentially processed
Ads account and reporting data authorized by customer
QuickBooks
Service / purpose
Finance/accounting integration (if enabled by customer)
Data potentially processed
Accounting records authorized by customer
Shopify
Service / purpose
E-commerce integration (if enabled by customer)
Data potentially processed
Store, product, order, and customer data accessed via granted OAuth scopes
Notion
Service / purpose
Workspace/document integration (if enabled by customer)
Data potentially processed
Notion content authorized by customer
Moz
Service / purpose
SEO tooling/integration (if enabled)
Data potentially processed
SEO-related data authorized by customer
Clerk
Service / purpose
Authentication and single sign-on
Data potentially processed
Account identifiers, authentication events, email addresses
Pipedream
Service / purpose
Integration connectivity platform (for certain connected tools)
Data potentially processed
OAuth credentials and data transiting customer-enabled integrations
Composio
Service / purpose
Integration connectivity platform (for certain connected tools)
Data potentially processed
OAuth credentials and data transiting customer-enabled integrations
Zapier
Service / purpose
Integration connectivity platform (for certain connected tools)
Data potentially processed
Data transiting customer-enabled integrations; OAuth credentials held by Zapier

A current, authoritative list of sub-processors will be maintained and updated at sykik.ai/subprocessors. Customers will be notified of material changes to this list in accordance with the change-notification terms of their Data Processing Agreement.

SECTION 10

Automated Decision-Making & AI Transparency

Sykik uses AI to analyse, draft, summarise, and suggest content. Per Article 22 GDPR, you have the right not to be subject to decisions based solely on automated processing that produce legal effects concerning you, and to request human intervention.

Sykik's AI suggestions are assistive — the user always reviews, edits, and confirms before any action (such as sending an email or scheduling a meeting) is taken. Sykik does not make autonomous decisions that produce legal effects concerning data subjects.

In accordance with the EU AI Act, Sykik is classified as a Limited Risk AI system (Article 50). Users are informed that they interact with an AI system via:

  • In-product indicators (badge/icon on AI-generated responses, e.g. "Drafted by Sykik AI")
  • This privacy policy section
  • Onboarding flow disclosure at first use

Where voice features involve synthetic voice generation, this is disclosed as artificially generated per Article 50(3). Where voice features involve emotion recognition, this is disclosed to users per Article 50(4).

SECTION 11

International Transfers

Sykik primarily processes data within the EU (GCP EU regions). Where data is transferred to third countries — notably for AI model inference via OpenRouter to US-based model providers — such transfers are governed by:

  • EU-US Data Privacy Framework adequacy decisions (Art. 45 GDPR), for certified recipients
  • Standard Contractual Clauses (SCCs) under Art. 46 GDPR, for non-certified recipients
  • A Transfer Impact Assessment (TIA), documented and available on request

We configure integrations to prefer EU-region processing where available (e.g. OpenRouter Enterprise EU in-region routing, once upgraded; GCP europe-west regions).

SECTION 12

Data Retention

Email/chat/document content processed by AI (prompt/context)
Not persisted beyond the AI request-response cycle where ZDR is enabled; otherwise session-only
Conversation history / AI outputs shown to user
Retained until deleted by user, or account closure + 30 days
Account data
Duration of account + 90 days after closure
Usage/product analytics
26 months maximum
Voice/audio recordings
Deleted immediately after processing, unless retained briefly (max 24h) for quality/abuse review
Payment records
7 years (Austrian tax/commercial law retention obligation)
Service & security logs
90 days, then aggregated or deleted
Encrypted backups
Aged out on rotation, currently ~35 days, then automatically overwritten

When an account is closed or we receive a validated deletion request, we delete Customer Data from active production systems typically within 30 days. Remaining copies are removed as encrypted backups age out on their normal rotation. Where legally permitted, customers may request an export of their data prior to deletion.

SECTION 13

Data Subject Rights

Under the GDPR, you have the following rights:

  • Access (Art. 15) — confirm what data is processed, receive a copy
  • Rectification (Art. 16) — correct inaccurate data
  • Erasure (Art. 17) — deletion, subject to legal retention obligations
  • Restriction (Art. 18) — limit processing in certain circumstances
  • Portability (Art. 20) — receive data in a structured, machine-readable format
  • Object (Art. 21) — object to processing based on legitimate interest
  • Withdraw consent — where processing is based on consent (e.g. voice features, non-essential cookies), you may withdraw at any time without affecting the lawfulness of prior processing

For workspace-level Customer Data, we may require the request to come from an authorized workspace administrator, or we may direct individual members to their workspace administrator, where the administrator's organisation is the Controller.

To exercise your rights, contact: sykik-privacy@sykik.ai. We will respond within 30 days (Art. 12(3)), extendable by a further 60 days for complex requests with notice to you.

You have the right to lodge a complaint with the Austrian Data Protection Authority: Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Wien, dsb.gv.at.

SECTION 14

Technical and Organisational Measures (Security)

  • Encryption in transit: TLS 1.3
  • Encryption at rest: AES-256, via GCP-managed keys (CMEK under evaluation)
  • Access control: RBAC, least-privilege, scoped OAuth per integration (each of Gmail, Calendar, Drive, Chat requested and granted separately)
  • Secrets management: API keys for AI providers stored in GCP Secret Manager
  • Audit logging: data access events logged and monitored
  • Breach notification: internal runbook targeting 72-hour notification to the Austrian DSB per Article 33 GDPR, and notification to affected users without undue delay where required under Article 34
  • Pseudonymisation: applied to analytics data where technically feasible

The full set of measures is published as Technical and Organisational Measures.

You are responsible for maintaining appropriate security in your own Google Workspace or Microsoft 365 environment (e.g. limiting who can install third-party apps, managing admin permissions).

SECTION 15

Children's Privacy

The Service is a business productivity tool intended for use by working professionals and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16 (the GDPR's default digital consent age, absent a lower age set by Austrian law). If we learn we have collected such data, we will delete it promptly. Contact sykik-privacy@sykik.ai if you believe a child has provided personal data to us.

SECTION 16

Business Transfers

If Sykik is involved in a merger, acquisition, restructuring, financing due diligence, insolvency, or sale of assets, personal data may be disclosed to advisors and successor entities, subject to confidentiality obligations and, where required, prior notice to affected users.

SECTION 17

Cookies and Tracking Technologies

sykik.ai uses the following categories of cookies:

  • Strictly necessary cookies (session, authentication) — exempt from consent under Austria's TTDSG §4, cannot be disabled
  • Analytics cookies — require your opt-in consent before being set, per TTDSG §4. We use a consent management platform to obtain and record this consent before any analytics cookie is placed.

You can manage or withdraw cookie consent at any time via the cookie settings link in the site footer, or through your browser settings.

SECTION 18

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by appropriate means (e.g. notifying workspace administrators and/or emailing the address associated with the account). The "Version" date reflects the most recent revision. Your continued use of the Service after changes become effective indicates acceptance of the revised policy.

SECTION 19

Contact Us

Controller: Sykik [FlexCo i.G.] · Wollzeile 6-8, 46, 1010 Vienna, Austria · [FN]

DPO: Hermann Wagner · sykik-privacy@sykik.ai

Supervisory Authority: Österreichische Datenschutzbehörde · dsb.gv.at

The rest of the legal section
Terms of ServiceThe agreement that governs access to and use of Sykik.Data Processing AgreementThe Article 28 processor terms, the sub-processor register and the annexes.Technical and Organisational MeasuresThe Article 32 controls behind the Service — where a security review starts.Impressum — Legal DisclosureWho operates sykik.ai, and who is answerable for it.
Sykik

AI agents that do the work — on the model you choose.

Product
  • What Sykik delivers
  • Chatbot vs. Sykik
  • How it works
  • Control & security
  • FAQ
Resources
  • Blog
  • Pricing
  • Security
Company
  • Contact
  • Imprint
Legal
  • Privacy
  • Terms
  • DPA
© 2026 Sykik. All rights reserved.Logos provided by Logo.dev