Privacy Policy

Last updated: May 15, 2026 · Effective: May 15, 2026

SkyNimbus Inc. ("SkyNimbus," "we," "us") is committed to protecting your personal information in accordance with Japan's Act on the Protection of Personal Information (APPI) and applicable international data protection laws. This policy describes how we collect, use, store, and protect your personal information when you use the SkyNimbus cloud governance platform.

1. Data Controller

SkyNimbus Inc.
Email: privacy@skynimbus.net
Support: support@skynimbus.net
Data Protection Contact: privacy@skynimbus.net

2. Personal Information We Collect

We collect the following categories of personal information, each for a specific and limited purpose:

Data CategoryExamplesPurpose of UseRetention
Account InformationName, email address, company nameAccount creation, authentication, communicationDuration of account + 30 days
Authentication DataPassword hash, MFA tokens, SSO tokensSecure access to your accountActive session duration; tokens purged on expiry
Cloud Connection CredentialsAWS/Azure/GCP API keys, role ARNsRead-only access to your cloud cost and resource dataDuration of connection; deleted on disconnect
Cloud Spend DataService costs, resource usage, billing periodsCost analysis, budgeting, anomaly detection, governanceDuration of account or per customer agreement
Usage DataLogin timestamps, pages visited, features usedProduct improvement, security monitoring12 months rolling
Support DataTicket content, repliesCustomer supportDuration of account + 90 days
Payment RecordsPayment amount, method, invoice referencesBilling, invoicing7 years (tax/legal requirement)

3. Purpose of Use

We use your personal information exclusively for the following purposes. We will not use your information beyond these stated purposes without your prior consent:

4. Third-Party Provision & Sub-Processors

We do not sell your personal information. We share data with the following service providers only as necessary to operate our platform:

ProviderPurposeData SharedLocation
ResendTransactional email deliveryEmail address, nameUnited States
Cloud hosting providerServer infrastructureAll platform data (encrypted at rest)See data residency section
AWS/Azure/GCP APIsCloud cost data retrieval (on your behalf)Your cloud API credentials (read-only)Per your cloud provider regions
Let's EncryptSSL/TLS certificate issuanceDomain name onlyUnited States

All sub-processors are contractually obligated to protect your data. We maintain agreements ensuring security measures equivalent to our own.

5. Cross-Border Data Transfers

Your data may be processed in jurisdictions outside Japan. When this occurs, we ensure protection through:

For customers requiring data residency in Japan, our self-hosted database feature provides full tenant data isolation — your cloud spend data, connections, budgets, and governance data remain in your PostgreSQL instance, under your control.

6. Data Security

Technical Measures

  • Passwords hashed with bcrypt (12 rounds)
  • AES-256-CBC encryption for stored credentials
  • HTTP-only secure cookies for session management
  • Multi-factor authentication (TOTP)
  • TLS/SSL for all data in transit
  • Role-based access control (5 permission tiers)
  • API key authentication with hashed storage

Organizational Measures

  • Comprehensive audit logging of all access and changes
  • Principle of least privilege for all system access
  • Time-bound administrative access with audit trail
  • Regular security reviews

7. Your Rights Under APPI

As an individual whose personal information we hold, you have the following rights. To exercise any of these rights, contact privacy@skynimbus.net.

RightDescriptionHow to Exercise
Access / DisclosureRequest disclosure of your retained personal dataSettings → My Data → Download, or email privacy@skynimbus.net
CorrectionRequest correction of inaccurate personal dataSettings → Profile, or email privacy@skynimbus.net
DeletionRequest deletion of your personal dataSettings → My Data → Delete Account, or email privacy@skynimbus.net
Cessation of UseRequest we stop using your data for specific purposesEmail privacy@skynimbus.net
Cessation of Third-Party ProvisionRequest we stop sharing your data with third partiesEmail privacy@skynimbus.net

We will respond to all data subject requests within 14 business days. Identity verification may be required.

8. Data Retention & Deletion

We retain personal information only as long as necessary for the purposes stated in this policy:

When data is deleted, it is permanently removed from our active systems. Backup retention does not exceed 90 days.

9. Cookies & Tracking

SkyNimbus uses only essential cookies required for platform functionality:

We do not use advertising cookies, analytics trackers, or third-party tracking pixels. No cookie consent banner is required as we only use strictly necessary cookies.

10. Breach Notification

In the event of a data breach that may affect your rights and interests:

11. Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email to all registered users at least 30 days before taking effect.

12. Contact

For privacy inquiries, data subject requests, or complaints:
Email: privacy@skynimbus.net
Support: app.skynimbus.net/support

If you are unsatisfied with our response, you may lodge a complaint with the Personal Information Protection Commission (PPC) of Japan at www.ppc.go.jp.