Skip to content
[[LEGAL_REVIEW]] Draft, not yet reviewed
This page was drafted to be reviewed by a lawyer before the site takes traffic. Do not rely on it until that review has happened and this notice is gone.

Legal

Privacy policy

updated [[DATE]]

This policy covers sylo.technology and the scoping form on it. It applies to Sylo Technology LLC, a Florida limited liability company, which we refer to as Sylo, we and us.

Reading the site collects nothing

There are no analytics, no advertising tags, no cookies and no third-party scripts. The fonts and the icons are served from sylo.technology itself, not from a content delivery network, so opening a page sends no request to anyone but our own host.

The site stores 1 value in your browser, sylo-theme, which records whether you chose light or dark mode. It stays on your device and is never sent to us.

What the scoping form collects

The form asks 9 things, and every one of them is on the screen in front of you.

  • What kind of project it is.
  • When you want to start.
  • A summary of the problem, in your words.
  • A budget, if you give one. The field is optional.
  • Your name.
  • Your email address.
  • Your organization, if you give one. Optional, like the budget.
  • Whether you are an individual, a private business or a government body.
  • Your consent for us to keep what you wrote and reply to it.

Three more things travel with the submission that you do not type.

  • The page you submitted from, the address of the page that linked you to it if your browser sends one, and any utm_ campaign tags in the URL. That is how we tell whether an ad or an article brought you here.
  • Your browser's user agent string, which names the browser and the operating system.
  • The time we received it.

We do not store your IP address. When a submission arrives the address is combined with a secret salt and put through a one-way hash, and the hash is what gets written down. We use it to count submissions from one source, which we cap at 5 an hour, and for nothing else. A hash cannot be turned back into an address, although anyone holding the salt could test a guess against it.

The form also carries a hidden field that a person never sees and an automated form-filler does. If it comes back filled in we discard the submission and store nothing.

The summary box is free text and nobody reads it before it is stored. Do not put passwords, health or financial details, or anyone else's personal information into it.

What we do with it

We use it to reply to you, to prepare for the intro call, and, if it becomes a project, to run that project. That is the whole list. We do not sell it, we do not rent it, we do not hand it to anyone for advertising, and nothing automated makes a decision about you from it.

Where it is stored

In a DynamoDB table in Amazon Web Services' us-east-1 region, in northern Virginia, where one submission is one record. A copy of the same submission is emailed through Amazon SES to 1 address at Sylo.

The table is encrypted at rest and point-in-time recovery is switched on, which means AWS holds a continuous backup of it. A record we delete can still be restorable from that backup for up to 35 days afterwards. Our server logs errors rather than submissions, and AWS keeps those logs for 30 days.

How long we keep it

Nothing expires on its own. A submission stays in the table until a person at Sylo deletes it, so the period that follows is one we keep by hand rather than one the system enforces: we delete an inquiry [[DURATION]] after our last contact with you, unless it became a project, in which case the project agreement sets the period.

The rate-limiting records are the exception. Each one holds a hashed address and a count, no submission content, and deletes itself 2 hours after the hour it counts.

Who else sees it

Amazon Web Services serves the site, stores the table and sends the notification. [[EMAIL_PROVIDER]] carries the mailbox we read that notification in. Each of them handles what it receives under its own terms, and neither is allowed to use it for anything but running the service for us.

Cal.com will run the booking calendar on /scope. It is not connected yet, and today the site loads nothing from cal.com. Once it is connected, opening the booking step will load Cal.com's script into your browser and pass it your name and email so you do not type them twice, under Cal.com's own privacy policy.

Beyond those, nobody, except where the law requires it of us. We will tell you if that happens, where the law allows us to.

Asking us for it, or asking us to delete it

You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Email support@sylo.technology. We answer within [[DURATION]], we do not charge for it, and asking changes nothing about how we treat your inquiry.

Two limits are worth saying in advance. We cannot find you by IP address, because we never kept one. And a deletion removes the record from the table and the notification from our mailbox, while the AWS backup described above ages out on its own.

Keeping it safe

The site and the form are served over HTTPS only, the table is encrypted at rest, and access to both the table and the notification mailbox is limited to [[N]] people at Sylo. If information you gave us is exposed in a way that puts you at risk, we will tell you within [[DURATION]] of finding out.

Children

The site is for people scoping software projects and is not directed at children. Do not use the form if you are under 18.

Where this happens

Sylo operates from Florida and everything described here is stored in the United States. If you send us a form from outside the United States, the United States is where it will be processed.

Changes to this policy

We change this policy when the site changes what it collects. The date at the top is the date of the last change, and the previous version is available on request.

Contact

Sylo Technology LLC, 7901 4th St N STE 300, St. Petersburg, FL 33702. Email support@sylo.technology.