Skip to content
SKY DUST LogoSKY DUST
PlatformSmart Fitting MirrorAboutContact
Log inStart LiftOFF, from €39/month
SKY DUST LogoSKY DUST

AI platform for operations, growth and knowledge. Assistants prepare; you approve.

Microsoft for StartupsAlumni 2021-2023

Platform

  • Platform overview
  • AI for email
  • AI automation
  • Client portal
  • Pricing

Products

  • SKY DUST LiftOFF
  • Smart Fitting Mirror
  • Custom AI development

Information

  • About SKY DUST
  • Partners
  • Blog
  • Contact
Privacy policyTerms of ServiceCookie policyAll legal documents
© 2026 SKY DUST · Sky Dust Platform B.V. · Hanzeplein 11 - 27, 8017 JD Zwolle · KvK 86188216 · BTW NL863889608B01
CBS AI Monitor 2025
All legal documents

Security Policy

This policy describes the key technical and organisational measures we use to protect SKY DUST LiftOFF and our customers' data. It accompanies our Data Processing Agreement.

Last updated: 14 July 2026

1. Infrastructure and hosting
  • The platform runs on professional European and US cloud infrastructure from established providers (see the subprocessor list for details).
  • Customer data is stored in data centres within the European Economic Area wherever possible.
  • Systems receive security updates on a regular basis.
2. Encryption
  • All connections are encrypted with TLS (HTTPS).
  • Data is encrypted at rest.
  • Passwords are never stored in readable form, only as secure hashes.
3. Access and organisation
  • Access to production systems and customer data is limited to people who need it for their work (least privilege).
  • Administrative access is protected with multi-factor authentication (MFA).
  • Each customer workspace is logically isolated from other customers; your data is never visible to other customers.
  • Staff and engaged persons are bound by confidentiality.
4. Backups and continuity
  • Customer data is backed up automatically on a regular schedule.
  • Backups are stored encrypted and periodically tested for recoverability.
  • In case of a serious outage, we restore the service from the most recent usable backup.
5. Incident response
  • Security incidents are logged, investigated and resolved following a fixed process: detect, contain, recover, evaluate.
  • If an incident affects personal data of your customers, we notify you without undue delay and at the latest within 48 hours of discovery (see the Data Processing Agreement).
  • After every relevant incident we run an evaluation and improve our measures where needed.
6. Retention and deletion
  • Data in your workspace is retained for as long as your account is active.
  • After termination, you can export your data for 30 days; we then delete it from active systems and backups within 90 days.
  • Security log files are kept for a maximum of 30 days.
  • Statutory retention obligations (such as tax retention periods for invoices) may require longer retention.
7. Reporting vulnerabilities

Found a vulnerability in our systems? Please report it via our Responsible Disclosure Policy at skydust.io/legal/responsible-disclosure.

8. Questions

Questions about security, or does your organisation have a security questionnaire for us to complete? Email karlo.timmerman@skydust.io.