Privacy statement
Skylar Automation LLC, doing business as Simpson Consulting. Effective 2026-09-24.
This statement explains what personal information the Command Center Project portal handles, why, and for how long. The portal exists to show your organization its own project dashboards; we use the information below to run it and for nothing else. We never sell personal information, never use it for advertising, and never use any data from the portal to train any model.
What we receive when you sign in
With a Microsoft work account: your name, email address, your organization's tenant id, your account's object id and the role your organization assigned you. That is what the sign-in token carries. We do not read your Microsoft directory, do not call Microsoft Graph, and keep none of Microsoft's tokens after the sign-in is recorded.
With a password account we created for your organization: your name, email address, a hash of your password (never the password itself) and, where a one-time code is enrolled, the encrypted secret for it.
Cookies
The portal sets only the cookies it needs to keep you signed in and to protect the session. There are no analytics, advertising or tracking cookies. Sessions end after 30 minutes without activity or 12 hours in any case, and sign-out ends them at once.
Records we keep
Sign-ins and failed attempts, terms acceptance, schedule saves, schedule distributions (who sent what to whom), access changes and administrative actions on your organization, each with the time, the account, the IP address and the browser identifier. These records are kept for 12 months and then deleted. Your organization's administrator may request a copy of its own records.
If your organization uses the commissioning schedule, the documents you save, their version history and the recipient lists you keep are stored for your organization until its agreement with us ends.
Where the information is held and who processes it
Everything is hosted in the United States, encrypted in transit and at rest. Our processors are Vercel (application hosting and private file storage), Neon (database), Resend (delivery of password reset links and distributed schedule PDFs; it keeps message data for 30 days), Axiom (storage of the platform's request and error logs, which carry IP addresses, request paths and browser identifiers but never schedule or project content) and, for sign-in, Microsoft, acting for your own organization under its own Microsoft agreement. We give organizations 30 days' notice before adding or replacing a processor.
Deletion
When your organization's agreement ends, its data is deleted within 30 days, except the records above, which are kept until their normal 12 month purge, and the database's 7 day recovery history, after which nothing deleted can be restored. Your organization can ask us to delete sooner.
Your choices and rights
Your organization controls who may sign in and can remove your access at any time. To see, correct or delete personal information about you, ask your organization's administrator or write to us at the address below; we answer through your organization. Residents of states with consumer privacy laws may have additional rights, which we honor to the extent they apply to information we process on your organization's behalf.
Security incidents
We notify an affected organization within 72 hours of confirming a security incident that affects its data, with what we know and what we are doing.
Changes
When this statement changes, the effective date above changes with it and organizations are told in advance of anything that reduces the protections described here.
Contact
Questions about this page: hello@skylarautomation.ai.
