Skip to content

SkilledDragon, LLC

Privacy Policy

What personal information is collected when you browse this site or book an advisory package, why, who processes it, and how to ask about it.

Version 2026-09-09.2 · Effective 2026-09-09

1. Who is responsible

SkilledDragon, LLC is responsible for the personal information described here. Sessions are delivered by David Discua. Contact details are on the Contact page.

2. Browsing this site

This site sets no cookies, uses no analytics, advertising, or tracking scripts, and does not read or write browser storage. Pages are served by our hosting provider, which keeps standard server logs (IP address, requested URL, browser type, timestamp) for security and reliability. We do not combine those logs with booking data.

Booking happens on calendly.com. When you open a booking link you leave this site; Calendly's own cookie banner and privacy policy apply there.

3. Information we collect when you book

When you book a package, Calendly collects your details and sends them to our private booking record over a signed connection. The follow-up call included in the package is arranged directly with you and its date is recorded in the same private record; no further information is collected for it. Where the package includes an email follow-up window, the questions you send during it stay in ordinary email correspondence between us; only the window's opening and closing dates are recorded, not the emails. The categories below describe what is actually stored and why. We do not collect card details, we do not record sessions or follow-up calls, and we do not send your materials to AI services by default.

3.1 Identity and contact details

Purposes: Schedule and deliver the session and the follow-up call; Send the booking confirmation and the written deliverable; Respond to your requests.

Where GDPR or UK GDPR applies, the legal basis relied on is: Performance of a contract or Legitimate interests (client records).

Providers involved: Calendly, Turso, Resend.

Retention: Kept while the client relationship is active and for as long as required afterwards for accounting and dispute purposes.

  • Name
  • Email address
  • Company and website when you provide them
  • Preferred language when you state it

3.2 Booking and intake information

Purposes: Prepare for and deliver the session, the written deliverable, and the follow-up call; Keep an accurate private record of bookings; Handle rescheduling and cancellations.

Where GDPR or UK GDPR applies, the legal basis relied on is: Performance of a contract.

Providers involved: Calendly, Turso.

Retention: Booking records are kept with the client record. Preparation materials are kept only as long as needed to deliver the session, the written deliverable, and the follow-up call.

  • Package booked, scheduled start and end time of the main session, your timezone
  • Booking status (active, canceled, rescheduled) and Calendly booking references
  • Your answers to the intake questions, stored with length limits
  • Materials you choose to share for preparation (diagram, system description, product brief)
  • Follow-up status: when the written deliverable was sent, the date agreed for the follow-up call and whether it took place, and the dates of the email follow-up window where the package includes one

3.3 Payment references and status

Purposes: Match payments to bookings; Issue refunds under the cancellation policy; Meet accounting obligations.

Where GDPR or UK GDPR applies, the legal basis relied on is: Performance of a contract or Legal obligation (accounting).

Providers involved: Stripe, Calendly, Turso.

Retention: Payment references are kept for as long as accounting and tax rules require.

  • Stripe payment identifier, amount, currency, and whether Calendly reported the payment as successful
  • No card numbers or other card details; payment happens on Stripe's systems through Calendly

3.5 Security and operational metadata

Purposes: Keep the booking record accurate; Protect the service from abuse; Diagnose delivery failures.

Where GDPR or UK GDPR applies, the legal basis relied on is: Legitimate interests (security and reliability).

Providers involved: Vercel, Turso, Resend.

Retention: Rate-limit counters expire automatically within hours. Delivery and webhook records are kept with the booking record. Hosting logs follow the hosting provider's retention.

  • Webhook delivery records (hashed identifiers and processing status; no payload copies)
  • Hashed client IP addresses used only to rate-limit failed webhook authentication
  • Email delivery status and provider message identifiers for transactional emails
  • Server logs kept by the hosting provider, containing request metadata and error codes but not the content of your intake answers

4. Providers who process information for us

We use the following providers. Each processes information only to provide its service to us. Their locations mean your information may be processed outside your country; where a transfer mechanism is legally required, we rely on the provider's standard data processing terms.

  • Calendly (United States): Scheduling: shows availability, collects your name, email, timezone, intake answers, and policy acceptance, and hosts the booking page you use. Data involved: Identity, booking, intake, policy acceptance, payment status as reported by Stripe.
  • Stripe (United States): Payment processing through Calendly's Stripe integration. Card details are entered on Stripe's systems and are never received by this site. Data involved: Payment details (held by Stripe), payment identifier and status (shared with us).
  • Turso (Turso managed cloud regions): Managed database that stores the private booking record. Data involved: Identity, booking, payment references, policy-acceptance records, operational metadata.
  • Vercel (United States (edge locations worldwide)): Hosting for this website and its server functions, including request logs. Data involved: Request metadata and error logs.
  • Resend (United States): Sends the transactional booking emails (confirmation, reschedule, cancellation). Data involved: Name, email address, booking details contained in the email.

5. What we do not do

To be explicit:

  • We do not sell or rent personal information.
  • We do not send marketing email unless you separately and expressly opt in; booking a session is not an opt-in.
  • We do not put personal information in analytics events, URLs, browser console output, or public page data.
  • We do not record sessions or upload your materials to AI services unless you ask for it in writing for a specific session.
  • We do not expose the booking record through any public endpoint; it is reached only by the provider through private tooling.

6. How long information is kept

Retention is described per category in section 3. In general, booking and payment records are kept for as long as accounting, tax, and dispute-limitation rules require, which means some information is retained after a deletion request. Security counters expire automatically.

7. Your requests and rights

You can ask what information we hold about you, ask us to correct it, or ask us to delete it. Depending on where you live you may also have rights to restrict or object to processing, to receive your information in a portable format, or to complain to a supervisory authority.

To make a request, contact us using the details on the Contact page from the email address you booked with, or quote your booking date and time. We verify requests before acting on them and respond in the same channel; we do not confirm or deny whether an email address is in our records to anyone who cannot verify it. Where information must be kept for legal reasons, we will tell you what is retained and why.

8. Security

The booking record is stored in a managed database reachable only by our server code with credentials that never reach the browser. Incoming booking notifications are accepted only when their signature verifies. Access is limited to the provider. No system is perfectly secure; if a breach affecting you occurs, we will notify you as the law requires.

9. Changes to this policy

Each version of this policy carries a version identifier and an effective date. Changes are made by publishing a new version; earlier versions are archived. The version in effect when you book is the one that applies to that booking.