Skima AI

PRIVACY POLICY

Last Updated: July, 2026

1. Introduction

Skima Innovation Private Limited (trading as skima.ai) ("we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy sets out how we collect, use, store, share, and protect information that identifies you or is associated with you ("personal data") when you use the skima.ai platform and related services (the "Service").

This Policy applies globally. Jurisdiction-specific rights are set out in the relevant sections below. Our full compliance posture, sub-processor list, and certifications are available at our Trust Centre: https://skima.scrut.io/

For any questions, contact our Data Protection Officer at yash@skima.ai.

2. Who We Are

  • Legal Name: Skima Innovation Private Limited
  • Trading Name: skima.ai
  • Registered Address: 3rd Floor, Chintamani Plaza, Andheri-Kurla Road, Mota Nagar, Andheri East, Mumbai, Maharashtra 400053, India
  • Website: www.skima.ai
  • Trust Centre: https://skima.scrut.io/
  • Certifications: SOC 2 Type II (April to September 2025, No Exceptions Noted) | GDPR Compliant (September 2025, Scrut Automation)

3. Our Roles: Data Processor and Data Controller

Skima acts in different capacities depending on the type of data involved. This distinction determines who is responsible for what.

3.1 Where We Act as a Data Processor

For candidate and end-user data submitted by our enterprise clients, we act as a Data Processor on behalf of the enterprise client (the Data Controller / Data Fiduciary). This includes:

  • Candidate resumes, profiles, and application content
  • AI-generated candidate scores and rankings
  • Recruitment pipeline and workflow data submitted by the client

3.2 Where We Act as a Data Controller

For our own business operations, we act as the Data Controller. This includes:

  • Platform user and account information (recruiters, hiring managers, administrators)
  • Billing and subscription data
  • Website usage analytics
  • Support communications
  • Marketing and business development activity

Where this Policy refers to your rights, the correct point of contact depends on which role applies to your data. See Section 14 for details.

4. Privacy by Design and Data Minimisation

Skima designs and operates its systems in accordance with the principles of Privacy by Design and Privacy by Default, as required by GDPR Article 25 and independently verified under Skima's GDPR Compliance Audit (Controls 22-23, Compliant, September 2025).

  • Privacy by Design: Data protection considerations are integrated into the architecture, development, and operation of the Service from inception.
  • Privacy by Default: Only personal data strictly necessary for each specified processing purpose is collected and processed. No excess data is collected by default.
  • Data Minimisation: Skima collects only the minimum personal data required to deliver the Service. Fields capturing candidate PII are configurable by the enterprise client through the Admin Portal, allowing clients to further restrict data collection.
  • No Temporary Files: Customer personal data is not stored in temporary files during processing. All processing occurs in controlled, persistent storage environments.
  • Pseudonymisation and Anonymisation: Skima anonymises and de-identifies personal data attributes wherever possible. IP addresses are anonymised by default using an md5 hash before storage.

5. No Selling or Sharing Your Personal Data for Advertising

Skima does not sell, rent, lease, or otherwise commercially exploit personal data to any third party. Skima does not use third-party advertising or cross-site tracking cookies, and does not share personal data for cross-context behavioural advertising.

In its capacity as a Service Provider and Contractor under the CCPA/CPRA, Skima is expressly prohibited from:

(i) selling or sharing consumer personal information;
(ii) using or disclosing personal information for any purpose other than the Business Purposes set out in the applicable Data Protection Addendum; or
(iii) combining personal information from one client with personal information from another source.

This commitment is set out in Skima's Data Protection Addendum, which is incorporated by reference into all client engagements.

6. Special Categories of Personal Data: Strict Prohibition

Skima's AI scoring engine evaluates candidates exclusively on job-relevant qualification signals. The following protections apply by design and by contract:

  • GDPR Article 9 special category data, including health and medical data, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic data, biometric data, and data concerning sex life or sexual orientation, is never processed as a scoring input under any circumstance.
  • Employment law protected attributes (sex, race, age, religion, disability, national origin) are never used as inputs to or outputs from the candidate scoring model.
  • Clients are contractually prohibited from submitting special category personal data to Skima without prior written agreement (DPA Schedule 1, Part C).
  • No proxy variables that correlate with protected characteristics (university prestige, name-based inference, address, postcode) are used in candidate scoring.

Enterprise clients may request full architecture documentation confirming these exclusions under NDA. Contact: support@skima.ai.

7. Information We Collect

(a) Information You Provide Directly

We collect information you submit when you use the Service, including: name, email address, telephone number, work history, educational qualifications, professional interests, job titles, CV and resume content, communications you send us, and survey responses.

(b) Information Provided by Your Organisation

If an employer or recruiting organisation creates an account for you on the Service, they may provide your name, job title, work telephone number, and email address to create your profile.

(c) Service Usage Data

We collect data about how you use the Service, including access times, referring sites, selections and preferences you make, and data you input while using the platform.

(d) Device and Connection Information

We collect technical data about the device you use to access the Service: device type, unique device identifiers, operating system, browser type, Internet service provider, mobile network, and IP address. IP addresses are anonymised by default using an md5 hash before storage.

(e) Location Information

We do not automatically collect precise location information. We may determine an approximate city-level location from your IP address only.

(f) Resumes and Profiles via Browser Extension

When an end user uses the Skima browser extension on LinkedIn, Naukri, Indeed, or other platforms configured in the Skima dashboard, candidate resume data is uploaded to the Skima platform automatically or manually depending on the configuration set by the user or their team administrator.

What the extension does:

  • Reads and extracts candidate profile and resume content from the current page you are viewing, only on the platforms configured in your dashboard.
  • Sends the extracted content to the Skima platform for processing under your organisation's configuration.

What the extension does not do:

  • The extension does not inject content into or modify the pages you visit.
  • The extension does not request or store your LinkedIn, Naukri, or other third-party platform password.
  • The extension does not operate in Incognito or private browsing mode.
  • The extension does not collect data from personal or entertainment-focused platforms.

Lawful basis: Legitimate interests of the recruiting organisation (facilitating the recruitment process). Candidates whose data is collected via the extension may contact yash@skima.ai to exercise their rights under Section 15.

GDPR Article 14 notice: Where candidate data is sourced from third-party platforms rather than provided directly to Skima, candidates may obtain information about how their data is processed by contacting yash@skima.ai.

(g) Browser Extension Activity Monitoring

The Skima browser extension may monitor user activities including network requests, clicks, mouse movements, scrolling, and keystrokes, strictly within the context of the Skima platform and configured recruitment platforms. This data is used exclusively to enhance the functionality, security, and user experience of the Skima platform. This telemetry is not retained beyond the active session and is not used for any profiling purpose.

Lawful basis: Legitimate interests (platform improvement and security monitoring).

(h) Google Workspace API Data

The Skima application uses the following Google OAuth 2.0 scopes for optional features:

  • .../auth/gmail.send: To send emails you compose or schedule through Skima Campaigns and email outreach features.
  • .../auth/gmail.readonly: To retrieve and display your Gmail emails for response monitoring and email tracking.

All Gmail data is encrypted in transit and at rest. We do not store email content beyond what is required to deliver the feature. We do not share your Gmail data with third parties except as required by law or explicitly authorised by you. These APIs are NOT used to develop, improve, or train generalised AI or machine learning models. You may revoke Skima's access to your Gmail data at any time via your Google Account Permissions page.

8. How We Use Your Information

Legal Bases for Processing

Depending on the circumstances, Skima processes personal data on one or more of the following legal bases: performance of a contract, compliance with a legal obligation, our legitimate interests (balanced against your rights), consent where required by law, and the establishment, exercise, or defence of legal claims.

We process your personal data for the following purposes on the following lawful bases:

Purpose Description Lawful Basis
Account management and service delivery Manage your account, validate data, and provide features of the Service. Contract performance
Service improvement Improve the Service using aggregated, anonymised, non-personally identifiable data only. Legitimate interests
Marketing and product information Provide information about products or services you have requested or that may interest you, in accordance with your marketing preferences. Consent / Legitimate interests
Personalisation Determine and predict content that may be of interest to you. Legitimate interests
Contractual obligations Carry out obligations from agreements between you and us, including allowing employer clients to evaluate assessments. Contract performance
Service notifications Notify you about changes to the Service and address complaints and issues. Contract performance / Legal obligation
Security and fraud prevention Prevent, detect, and investigate illegal activities, breaches, and security threats. Legitimate interests / Legal obligation
Aggregate analytics Produce aggregate statistical information from which individuals cannot be identified. Legitimate interests
Extension functionality Support core features of the Skima browser extension as described in Section 7(g). Legitimate interests

9. AI Processing and Automated Decision-Making

How AI Processes Your Data

  • Candidate personal data (resumes, profiles, employment history) is processed exclusively by Skima's internal proprietary AI models hosted on AWS Dublin, Ireland (EU). No candidate PII is ever transmitted to external AI or large language model providers.
  • External AI APIs (OpenAI, OpenRouter) are used solely for non-personally identifiable tasks, specifically job description generation, under strict Zero Data Retention (ZDR) enterprise agreements. Data is processed ephemerally in memory and immediately discarded.
  • Each enterprise client operates in a logically isolated tenant environment. No candidate data is aggregated across clients.
  • Candidate data is never used to train, retrain, or improve Skima's generalised AI models. This restriction is set out in DPA Section 4(c).
  • IP addresses are anonymised by default (md5 hash) before storage.

Human Oversight: No Autonomous Hiring Decisions

Skima AI ranks, scores, and surfaces candidates for human review. Skima AI does not make, execute, or record final hiring decisions. Every candidate progression, rejection, or offer requires authorisation by a human recruiter or hiring manager, and this step is built into the platform's workflow, consistent with EU AI Act Annex III requirements for human oversight of high-risk AI systems.

Your Right Not to Be Subject to Automated Decision-Making

Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces significant legal or similarly significant effects. Skima AI does not make final hiring decisions; human review is built into this stage of the process. For concerns, contact yash@skima.ai.

10. Where We Store Your Data and Security Measures

Primary Data Location

All customer personal data is stored on Amazon Web Services (AWS) in Dublin, Ireland (eu-west-1). By default, all customer personal data remains within the European Union.

Security Architecture

Security Control Detail Verification
Encryption at rest AES-256 applied to all production databases and backup copies SOC 2 / GDPR Audit Art. 32
Encryption in transit TLS 1.2 or higher for all data transmitted over public networks SOC 2 / GDPR Audit Art. 32
Access control Role-Based Access Control (RBAC) on least-privilege basis; quarterly access reviews SOC 2 / GDPR Audit Art. 32
Authentication Multi-Factor Authentication (MFA) required for all administrative access SOC 2 Type II
Network security AWS VPC with private subnets; Cloudflare Web Application Firewall in Block mode SOC 2 Type II
Penetration testing Annual third-party VAPT; automated scanning before every production release SOC 2 / GDPR Audit Art. 32
Vulnerability management Critical vulnerabilities patched without undue delay SOC 2 / GDPR Audit Art. 32
Audit logging Audit logging enabled on all systems; extractable for all products GDPR Audit Control 38
Environment segregation Development, test, and production environments fully segregated GDPR Audit Control 48
Backup Databases backed up on a defined schedule; backup copies overwritten on their normal rotation cycle per Retention Policy GDPR Audit Control 37

SOC 2 Type II and GDPR audit reports are available to enterprise clients under NDA. Contact support@skima.ai to request access.

Password Security

Where you have been given or have chosen a password to access the Service, you are responsible for keeping it confidential. If you believe your password has been compromised, notify us immediately at support@skima.ai.

11. Data Retention

We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by applicable law. The following retention schedule applies:

Data Category Retention Period Source
Active client account / candidate data Duration of active service DPA Schedule 1
Client account data (post-termination) Maximum 3 months from termination date DPA Schedule 1 / Retention Policy
Candidate and end-user data (post-termination) Maximum 12 months from termination, then securely deleted DPA Schedule 1 / Retention Policy
Files and media in cloud storage Maximum 12 months from termination Retention Policy Annexure A
Database backups 1 month Retention Policy Annexure A
Trial customer data Deleted within 1 month of trial end Retention Policy Annexure A
Data subject rights request records As required by applicable law GDPR Art. 5(2)

Upon termination of a Service Agreement, all customer personal data will be returned or permanently and securely deleted within 30 calendar days. Written certification of deletion is provided upon request.

12. Disclosure of Personal Data

We may disclose your personal data in the following circumstances:

  • Group companies: To subsidiaries and holding companies bound by the same data protection obligations.
  • Sub-processors: To third-party service providers acting strictly on Skima's instructions and under binding data protection obligations. See Section 13 for the full named list.
  • Business transfers: In connection with a sale, merger, or transfer of business or assets, to the prospective buyer or transferee.
  • Legal obligations: To comply with subpoenas, court orders, or legally binding regulatory requests, including law enforcement.
  • Security and fraud prevention: To investigate, prevent, or act on suspected illegal activities, fraud, or threats to physical safety.
  • Contractual enforcement: To enforce or apply agreements between you and us.
  • Joint business partners: To employer clients whose recruitment processes you are participating in through the Service.

We do not disclose personal data to any party for advertising or cross-context behavioural advertising purposes.

13. Sub-Processors and International Data Transfers

Skima engages carefully selected third party service providers ("Subprocessors") to support the hosting, security, operation, and delivery of the Service. Where a Subprocessor processes personal data on our behalf, it does so under written contractual obligations requiring appropriate technical and organisational security measures, confidentiality, and compliance with applicable data protection laws.

A current list of our authorised Subprocessors, including the services they provide and the locations where they process data, is available at https://skima.ai/subprocessors.

International Transfer Safeguards

For transfers of personal data to sub-processors outside the EU/EEA, the following safeguards are in place:

  • EU Standard Contractual Clauses (SCCs): Module 2 (Controller to Processor), approved by the European Commission pursuant to Decision of 4 June 2021, incorporated into all applicable agreements.
  • Zero Data Retention (ZDR): External AI APIs (OpenAI, OpenRouter) operate under ZDR enterprise agreements. Data is processed ephemerally in memory and immediately discarded, never stored, never used to train models.
  • EU-US Data Privacy Framework (DPF): Applied where applicable for US-based sub-processors.
  • UK International Data Transfer Addendum (IDTA): Applied for transfers of data subject to UK GDPR.
  • Swiss nFADP safeguards: Applied for data subject to the Swiss Federal Act on Data Protection.
  • DPDPA 2023 (India): Cross-border transfer provisions of the Digital Personal Data Protection Act 2023 are complied with for Indian data principals.

14. Your Rights as a Data Subject

To exercise any of the rights below, contact our Privacy Officer at yash@skima.ai. We will respond within one month of receiving your verified request. Where requests are complex or numerous, we may extend this by a further two months and will inform you within the first month. Identity verification is required before we process any request.

If your data is processed by Skima as part of an enterprise client's recruitment process (see Section 3.1), your primary point of contact for a rights request is that enterprise client, as the Data Controller. Skima will assist the enterprise client in fulfilling your request. If the enterprise client is unresponsive, you may contact Skima directly using the details above.

GDPR and UK GDPR Rights

  • Right to be Informed: To be told how your personal data is collected and used.
  • Right of Access: To obtain a copy of the personal data we hold about you.
  • Right to Rectification: To have inaccurate or incomplete personal data corrected.
  • Right to Erasure (Right to be Forgotten): To request deletion of your personal data.
  • Right to Restrict Processing: To request we temporarily or permanently stop processing your data.
  • Right to Object: To object to processing based on legitimate interests or for direct marketing purposes. You have an absolute right to object to direct marketing processing.
  • Right to Data Portability: To receive a copy of your data in a commonly used machine-readable electronic format.
  • Right Not to Be Subject to Automated Decision-Making: Supported by design, see Section 9. Human authorisation is required for all final hiring decisions.

Rights of Indian Data Principals (DPDPA 2023)

If your personal data is processed by Skima and you are subject to the Digital Personal Data Protection Act, 2023 (India), you have the following rights:

  • Right to Information: To obtain information about the personal data being processed and the manner of its use.
  • Right to Correction and Erasure: To correct inaccurate personal data and have data erased where it is no longer necessary.
  • Right to Grievance Redressal: To have grievances addressed by our Grievance Officer within 30 days.
  • Right to Nominate: To nominate another individual to exercise your rights in the event of your death or incapacity.

Rights of California Consumers (CCPA / CPRA)

The following rights apply to California residents under the California Consumer Privacy Act (Cal. Civ. Code Section 1798.100 et seq.) as amended by the California Privacy Rights Act. Where you are a candidate or employee of one of Skima's enterprise clients, direct your CCPA rights request in the first instance to that enterprise client. Skima will assist the enterprise client in fulfilling your request.

  • Right to Know: To request disclosure of the categories and specific pieces of personal information collected, the purposes, and categories of third parties with whom it is shared.
  • Right to Delete: To request deletion of personal information collected, subject to certain legal exceptions.
  • Right to Correct: To request correction of inaccurate personal information we hold about you.
  • Right to Opt Out of Sale or Sharing: Skima does not sell or share personal information. This right is confirmed as available and no opt-out is required.
  • Right to Limit Use of Sensitive Personal Information: Skima does not use sensitive personal information beyond what is necessary to provide the Service. No limitation request is required, but this right is available.
  • Right to Non-Discrimination: You will not receive discriminatory treatment for exercising any CCPA/CPRA rights.

Right to Complain to a Supervisory Authority

If you are dissatisfied with how we have handled your personal data or rights request, you have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction.

15. Cookies

We use cookies and similar tracking technologies on our website and platform. Full detail, including how to manage your cookie preferences, is set out in our Cookie Policy at skima.ai/cookie-policy.

16. Data Breach Notification

Skima operates a formal Data Breach Management Procedure. In the event of a personal data breach:

  • Supervisory Authority: We will notify the relevant supervisory authority without undue delay and within 72 hours of becoming aware of any qualifying breach (GDPR Article 33 / DPDPA 2023).
  • Data Subjects: Where a breach is likely to result in a high risk to the rights and freedoms of individuals, we will communicate the breach to affected data subjects without undue delay (GDPR Article 34).
  • Enterprise Clients: Notified within 48 hours of a confirmed data incident under the terms of the applicable Data Protection Addendum.
  • Breach notifications will include: the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed to address and mitigate the breach.

17. Third-Party Links and Services

Our website and Service may contain links to third-party websites, or integrate with external services such as applicant tracking systems and job boards. This Privacy Policy does not apply to those third-party services. Please review their privacy policies separately.

18. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate consent, we will delete that data promptly.

19. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of India, subject to the following:

  • EU / EEA data subjects: To the extent this Policy relates to personal data subject to the EU GDPR, EU data protection law and the relevant supervisory authority shall apply.
  • UK data subjects: To the extent this Policy relates to data subject to the UK GDPR and Data Protection Act 2018, UK data protection law shall apply.
  • California consumers: To the extent this Policy relates to personal information subject to CCPA/CPRA, California law shall apply to those provisions.
  • Enterprise clients: The governing law for data processing obligations is set out in the applicable Data Protection Addendum, which prevails over this Policy on data protection matters.

Any dispute arising from this Privacy Policy (where not governed by the applicable DPA) shall be subject to the exclusive jurisdiction of the courts of Mumbai, Maharashtra, India.

20. Data Protection Officer and Grievance Officer

For all queries, requests, and complaints relating to this Privacy Policy or the processing of your personal data:

  • Data Protection Officer / Privacy Officer: Yash Dave
  • Email: yash@skima.ai
  • Address: 3rd Floor, Chintamani Plaza, Andheri-Kurla Road, Mota Nagar, Andheri East, Mumbai, Maharashtra 400053, India

Grievance Officer (India, IT Act 2011 / DPDPA 2023): Yash Dave | yash@skima.ai

Grievances will be acknowledged and addressed within 30 days of receipt, in accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDPA 2023.

21. Service Availability and SLA

Uptime commitments, service availability guarantees, and support response SLAs are set out in the applicable Service Agreement between Skima and each enterprise client. These terms are separate from this Privacy Policy. For current availability and compliance information, visit: https://skima.scrut.io/

22. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will use reasonable endeavours to notify you of material changes by email or by notice on the Service, with at least 30 days' notice for changes that materially reduce your rights. Any changes will be reflected on this page with an updated "Last Updated" date. A complete history of changes to this Privacy Policy is available below.

Version History

Version Date Description of Changes Created By Published By
1.0 May 2026 Initial release Yash Dave Sumit Rai
2.0 July 2026 Full rewrite adding entity details, Processor/Controller role mapping, retention schedule, security architecture, sub-processor detail, GDPR/DPDPA/CCPA rights sections, AI processing disclosures, and Third-Party Links and Children's Privacy sections. Standardised naming, removed unlawful consent language and retention.com sharing, rewrote extension disclosure, corrected overcommitment language, and moved sub-processors to a standalone page Yash Dave Sumit Rai

23. Do Not Track

This Application does not respond to "Do Not Track" browser signals. To determine whether third-party services we use honour Do Not Track requests, please refer to their respective privacy policies.