Privacy Policy

Last updated: 6 August 2026

This Privacy Policy explains how Skemia, operated by AIT Consulting ("Skemia", "we", "us"), collects, uses, shares, and protects your personal information when you use our website and application at skemia.co.za and app.skemia.co.za (the "Service").

Skemia serves business analysts worldwide. We are based in South Africa, so we process personal information in line with the Protection of Personal Information Act, 2013 (POPIA). Where we offer the Service to people in the United Kingdom or the European Economic Area, we also process their personal information in line with the UK GDPR and the EU General Data Protection Regulation. Where those laws give you a stronger right than POPIA does, you get the stronger right.

By using the Service you agree to this policy. If you do not agree, please do not use the Service.

Who we are

Skemia is a workspace for business analysts that turns a project's context into documents such as a business case, functional specification, and user stories, along with related registers and diagrams. AIT Consulting is the responsible party (data controller) for the personal information described here.

Information Officer: Naseem Terblanche. Contact: info@skemia.co.za. Business address: [your registered business address].

Information we collect

  • Account information. Your email address and the password you set (stored securely by our authentication provider, never in plain text), and your workspace and team details.
  • Project content you provide. The project context, notes, uploaded documents, and any other content you or your team add. This may include your own or your clients' confidential business information. You decide what to put into Skemia.
  • Content Skemia generates. The documents, requirements, diagrams, and other outputs produced from your content.
  • Payment information. When you subscribe, Creem processes your card details as merchant of record, along with the billing country and any tax identifier it needs to charge the right tax. We never receive or store your card number. We keep only your subscription status and a customer reference.
  • Technical and usage data. Standard information such as your IP address, browser type, and how you use the Service, used to run, secure, and improve it.

How we use your information

  • To provide the Service: create your account, generate and store your documents, and run the features you use.
  • To process payments and manage your subscription and free trial.
  • To secure the Service, prevent abuse, and troubleshoot problems.
  • To contact you about your account, important service notices, and support.
  • To comply with our legal obligations.

We do not sell your personal information, and we do not use the content of your projects to advertise to you.

Why we are allowed to use it

The UK GDPR and the EU GDPR require us to name a lawful basis for each use, and POPIA requires an equivalent justification. Ours are:

  • To perform our contract with you. Creating your account, generating and storing your documents, running the features you use, and managing your subscription and trial.
  • Our legitimate interests. Keeping the Service secure, preventing abuse, troubleshooting, and improving how it works. We weigh these against your rights and use the least information that does the job.
  • Our legal obligations. Keeping tax and billing records, and answering lawful requests.

Artificial intelligence processing

Skemia uses OpenAI to generate documents and to power the assistant. To do this, the relevant parts of your project content are sent to OpenAI to produce a response. Under OpenAI's API terms, content sent through the API is not used to train their models. We send only what is needed to produce the output you asked for.

AI output can contain mistakes and is a starting draft, not professional, legal, or financial advice. You are responsible for reviewing and verifying it before you rely on it.

Who we share information with

We share personal information only with the service providers (operators) that help us run Skemia, each bound to use it only for that purpose:

  • Google Firebase / Google Cloud - authentication, database, and file storage. Privacy
  • OpenAI - AI document generation and the assistant. Privacy
  • Creem - payment processing, as merchant of record. Privacy
  • Resend - sending transactional email (invites, notices). Privacy
  • Vercel - website and application hosting. Privacy

We may also share information if required by law, to protect our rights or users, or as part of a business transfer (such as a merger or sale), in which case we will tell you.

International transfers

Skemia is a worldwide service, so your information will cross borders. Our providers process data on servers in several countries, including the United States and the European Union, and we are based in South Africa.

Where we transfer personal information out of the United Kingdom or the European Economic Area, we rely on the safeguards permitted under the UK GDPR and the EU GDPR, principally the European Commission's Standard Contractual Clauses (with the UK Addendum where the UK GDPR applies) as offered by the providers listed above. Where we transfer personal information out of South Africa, we rely on the transfer grounds permitted under section 72 of POPIA. You can ask us for details of the safeguards that apply to a particular transfer.

How we protect your information

Your data is encrypted in transit (TLS) and at rest, and access is restricted to your workspace: one workspace cannot read another's data. File storage and generated documents are written only by our server, not directly by the browser. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your information.

How long we keep it

We keep your information for as long as your account is active and as needed to provide the Service. If you delete a project it is removed from your workspace. If you close your account, we delete or anonymise your personal information within a reasonable period, except where we must keep certain records (for example billing records) to meet legal obligations.

Your rights

Wherever you are, you have the right to:

  • ask what personal information we hold about you and request a copy;
  • ask us to correct or update information that is wrong or incomplete;
  • ask us to delete your information, subject to our legal obligations;
  • object to certain processing; and
  • complain to your data protection regulator.

If the UK GDPR or the EU GDPR applies to you, you also have the right to ask us to restrict how we process your information, the right to receive the information you gave us in a portable machine-readable format, and the right to withdraw consent at any time where we relied on consent. We do not make decisions about you by automated means that produce legal or similarly significant effects.

To exercise any of these, email info@skemia.co.za. We answer within 30 days and we do not charge for a first request.

If you are unhappy with our answer you can complain to your own regulator. In South Africa that is the Information Regulator; in the United Kingdom the Information Commissioner's Office; in the European Economic Area your national supervisory authority.

Cookies

We use only the cookies and similar storage needed to sign you in, keep you signed in, and run the Service. We do not use third-party advertising cookies.

Children

Skemia is a business tool and is not intended for anyone under 18. We do not knowingly collect information from children.

Changes to this policy

We may update this policy from time to time. If we make a material change we will update the date above and, where appropriate, notify you. Continuing to use the Service after a change means you accept the updated policy.

Contact us

Questions about this policy or your information? Email info@skemia.co.za.