Schematify Beta
  • Pricing
  • Docs
Sign in Get started for free

Legal

Privacy Policy

Last updated: 18 June 2026

This Privacy Policy explains how Schematify Limited ("Schematify", "we", "us", or "our") collects, uses, shares, and protects personal data when you use our websites, hosted services, software, APIs, command-line tools, documentation, and related services (together, the "Services").

This is a general policy template and may need further customisation for specific products, jurisdictions, customer agreements, data processing arrangements, and regulatory requirements.

1. Who We Are

Schematify Limited is responsible for personal data processed through the Services unless a customer agreement states that we act as a processor on behalf of a customer.

For privacy questions, contact:

Schematify Limited
Email: info@schematify.com

2. Personal Data We Collect

We may collect the following categories of personal data.

2.1 Account and Identity Data

  • name;
  • email address;
  • username or user identifier;
  • organisation name and organisation identifier;
  • role, permissions, and group membership;
  • authentication provider identifiers;
  • profile information supplied through identity providers.

2.2 Usage and Technical Data

  • IP address;
  • device, browser, and operating system information;
  • log data;
  • pages, features, and APIs accessed;
  • timestamps, request metadata, error logs, and diagnostic information;
  • CLI, API, and integration usage metadata;
  • approximate location inferred from IP address.

2.3 Customer Content

Depending on how you use the Services, we may process schemas, diagrams, graph definitions, documents, configuration, source material, prompts, files, and other content you submit to the Services. This content may include personal data if you choose to include it.

2.4 Payment and Commercial Data

Where applicable, we may process billing contact details, subscription details, invoices, payment status, and transaction metadata. Payment card details may be processed by a third-party payment provider rather than stored by Schematify.

2.5 Communications

We may collect information you provide when you contact us, request support, participate in user research, respond to surveys, or communicate with us by email, chat, or other channels.

3. How We Collect Personal Data

We collect personal data:

  • directly from you;
  • from your organisation or account administrator;
  • from identity providers such as OAuth/OIDC providers;
  • automatically through the Services;
  • from integrations and APIs you configure;
  • from payment, hosting, analytics, security, support, and infrastructure providers.

4. How We Use Personal Data

We use personal data to:

  • provide, operate, and maintain the Services;
  • authenticate users and manage accounts;
  • enforce permissions, access control, and security policies;
  • process schemas, diagrams, documents, and related content as requested;
  • provide support and respond to enquiries;
  • monitor, debug, secure, and improve the Services;
  • detect, prevent, and investigate misuse, fraud, security incidents, and policy violations;
  • communicate service updates, administrative messages, and product information;
  • manage billing, subscriptions, and commercial relationships;
  • comply with legal obligations and enforce agreements.

5. Legal Bases for Processing

Where UK or EEA data protection law applies, we rely on one or more of the following legal bases:

  • performance of a contract;
  • legitimate interests, such as operating, securing, improving, and supporting the Services;
  • compliance with legal obligations;
  • consent, where required and obtained;
  • protection of vital interests, where applicable.

6. Customer Data and Processor Role

For many business customers, Schematify may process personal data contained in Customer Data as a processor or service provider on behalf of the customer. In those cases, the customer determines the purposes and means of processing, and Schematify processes the data according to the customer agreement and applicable data processing terms.

Customers are responsible for ensuring that they have the rights and notices necessary to submit personal data to the Services.

7. Sharing Personal Data

We may share personal data only in limited circumstances:

  • with hosting and infrastructure providers necessary to operate the Services;
  • with our payment providers, where payment processing is required; currently our only payment provider is Stripe;
  • with authorities, regulators, courts, or law enforcement where required by law;
  • with customers or account administrators where data relates to an organisational account and disclosure is necessary to administer that account;
  • with professional advisers, auditors, insurers, legal representatives, potential acquirers, investors, or successors only with the express permission of the relevant account holder, unless disclosure is required by law.

We do not currently share personal data with identity providers, support providers, analytics providers, monitoring providers, or security providers. We do not sell personal data.

8. International Transfers

Personal data may be processed in countries other than where you are located. Where required, we use appropriate safeguards for international transfers, such as adequacy decisions, standard contractual clauses, or other lawful mechanisms.

9. Security

We use reasonable technical and organisational measures designed to protect personal data, including access controls, encryption in transit, monitoring, and operational security practices.

No system is completely secure. You are responsible for protecting account credentials, managing authorised users, and configuring integrations securely.

10. Retention

We retain personal data for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business purposes.

Retention periods vary depending on the type of data, account status, customer configuration, legal requirements, and operational needs.

11. Cookies and Similar Technologies

We may use cookies, local storage, and similar technologies for authentication, session management, security, preferences, analytics, and service functionality.

You can control cookies through browser settings, but disabling cookies may prevent parts of the Services from working correctly.

12. Your Rights

Depending on your location and applicable law, you may have rights to:

  • access personal data;
  • correct inaccurate personal data;
  • delete personal data;
  • restrict or object to processing;
  • receive a copy of personal data in portable form;
  • withdraw consent where processing is based on consent;
  • complain to a data protection authority.

To exercise rights, contact privacy@schematify.com. If your data is controlled by a Schematify customer, we may direct your request to that customer.

13. Marketing Communications

We may send marketing communications where permitted by law. You can opt out of marketing emails using the unsubscribe link or by contacting us. We may still send non-marketing service, security, billing, or administrative messages.

14. Children's Privacy

The Services are not intended for children. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact us so we can take appropriate action.

15. Third-Party Services and Links

The Services may link to or integrate with third-party services. Their privacy practices are governed by their own policies. We are not responsible for third-party privacy practices outside our control.

16. Changes to this Policy

We may update this Privacy Policy from time to time. We will indicate the latest update date above. Material changes may be notified through the Services or by other reasonable means.

17. Contact

For privacy questions or requests, contact:

Schematify Limited
Email: info@schematify.com

Schematify Beta
Pricing Docs Terms Privacy

© 2026 Schematify

A quick note on cookies

Schematify needs a few cookies to run: sign-in, your settings, the essentials. Anything optional stays off until you turn it on.