Privacy Policy
Status: Not yet in effect — draft
What we collect, why, how long we keep it, and how to get it back or have it deleted.
Complete in structure, but not reviewed by a lawyer and missing the entity details below. The factual parts — what is collected and who it is shared with — are accurate as of 5 October 2026.
On this page
1. The short version
- We collect what we need to run a learning platform: who you are, what you enrolled in, what you completed, and the work you submit for review.
- We do not sell your data, and we do not use your submitted work to train third-party AI models.
- We do not run advertising trackers. There is currently no analytics product on this site at all.
- We store no password for you — sign-in is passwordless.
- You can ask for a copy of your data, or its deletion, at [email protected].
2. Who is responsible
The controller is [[ LEGAL ENTITY NAME ]], [[ REGISTERED ADDRESS ]], [[ JURISDICTION ]]. Data protection contact: [email protected]. EU/UK Article 27 representative: [[ EU/UK REPRESENTATIVE ]].
Where your employer enrolled you through an organisation account, they are a controller for their own use of your progress data, and we process it on their instructions.
3. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Identity | Name, email address, profile photo, the organisation you belong to | You, or your SSO provider |
| Learning activity | Enrolments, lessons completed, quiz and exam results, streaks, XP, cohort and squad membership | Generated as you use the platform |
| Submitted work | Proof files you upload for instructor review, and notes you write | You |
| Time records | Time spent per lesson and per course | Generated as you use the platform |
| Contributions | Course and lesson ratings, review text, cheers and lessons you share with your squad | You |
| Credentials | Certificates issued, the program and level, the date | Generated on completion |
| Technical | IP address, browser type, and server logs including request times | Automatic, as with any website |
We do not ask for special-category data (health, beliefs, biometrics) and you should not put it in a proof submission. We do not take payment card details — if a course is ever priced, the payment provider handles the card and we never see it.
4. Why we use it, and our lawful basis
| Purpose | Basis |
|---|---|
| Giving you an account and delivering the courses you enrol in | Performance of a contract |
| Having an instructor review the work you submit | Performance of a contract |
| Issuing and verifying certificates | Performance of a contract |
| Showing your activity to your squad and cohort | Performance of a contract — it is the core of the product |
| Reporting progress to the organisation that enrolled you | Legitimate interests of that organisation |
| Reminder and re-engagement email | Legitimate interests — you can opt out at any time |
| Keeping the platform secure and preventing abuse | Legitimate interests |
| Meeting legal and accounting obligations | Legal obligation |
5. Who we share it with
- Instructors and providers — the instructor of a course you enrol in sees your progress and the work you submit. They need to, in order to teach and grade you.
- Your squad and cohort — other learners in your cohort see your name, profile photo, activity and streaks. This is the product working as designed. If you do not want it, do not join a cohort.
- Your organisation — if an employer enrolled you, their admins see your progress, completions and learning hours.
- Anyone you give a certificate link to — a certificate verification page shows the name it was issued to, the program, the level and the date.
- Service providers that process data on our behalf — listed at /subprocessors.
- Authorities, where we are legally required to.
We do not sell personal data, and we do not share it with advertisers.
6. How long we keep it
| Data | Kept for |
|---|---|
| Account and profile | While your account is open, then [[ RETENTION ]] |
| Learning records and certificates | Retained after closure so issued certificates stay verifiable |
| Submitted proof files | [[ RETENTION ]] after the course ends |
| Server logs | [[ RETENTION ]] |
7. Your rights
Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to processing, take it elsewhere, and complain to a regulator. To exercise any of these, email [email protected]. We will respond within one month.
Being straight with you: self-service export and deletion are not built yet. Today these requests are handled by a person when you email us. We would rather tell you that than imply a button exists.
If you are in the EU or UK you may complain to your local supervisory authority. Ours is [[ LEAD SUPERVISORY AUTHORITY ]].
8. Email you receive
We send transactional email (sign-in links, enrolment confirmations, certificate notices) and re-engagement reminders when you have gone quiet in a course. Every non-transactional message carries an unsubscribe link, and you can also email us to switch them off. Transactional email cannot be switched off while your account is open, because it is how sign-in works.
9. Cookies
We use cookies to keep you signed in and to remember basic preferences. We do not run advertising or profiling cookies. Full detail at /cookies.
10. Security
Everything is served over TLS, sign-in is passwordless, roles are separated, and administrative actions are logged. Our full posture — including what we do not claim — is at /security.
11. International transfers
Skill.re is operated from [[ JURISDICTION ]] and some of our service providers are outside your country. Where data leaves the EEA or UK we rely on [[ TRANSFER MECHANISM ]].
12. Children
Skill.re is for adults in a working context and is not directed at children. We do not knowingly collect data from anyone under [[ MINIMUM AGE ]]. If you believe we have, tell us and we will delete it.
13. Changes
We will post updates here and, for material changes, tell you by email or in the product before they take effect.
14. Contact
[email protected], or write to [[ REGISTERED ADDRESS ]].