Legal

Privacy Policy

Status: Not yet in effect — draft

What we collect, why, how long we keep it, and how to get it back or have it deleted.

Draft — not yet binding

Complete in structure, but not reviewed by a lawyer and missing the entity details below. The factual parts — what is collected and who it is shared with — are accurate as of 5 October 2026.

1. The short version

  • We collect what we need to run a learning platform: who you are, what you enrolled in, what you completed, and the work you submit for review.
  • We do not sell your data, and we do not use your submitted work to train third-party AI models.
  • We do not run advertising trackers. There is currently no analytics product on this site at all.
  • We store no password for you — sign-in is passwordless.
  • You can ask for a copy of your data, or its deletion, at [email protected].

2. Who is responsible

The controller is [[ LEGAL ENTITY NAME ]], [[ REGISTERED ADDRESS ]], [[ JURISDICTION ]]. Data protection contact: [email protected]. EU/UK Article 27 representative: [[ EU/UK REPRESENTATIVE ]].

Where your employer enrolled you through an organisation account, they are a controller for their own use of your progress data, and we process it on their instructions.

3. What we collect

CategoryExamplesWhere it comes from
IdentityName, email address, profile photo, the organisation you belong toYou, or your SSO provider
Learning activityEnrolments, lessons completed, quiz and exam results, streaks, XP, cohort and squad membershipGenerated as you use the platform
Submitted workProof files you upload for instructor review, and notes you writeYou
Time recordsTime spent per lesson and per courseGenerated as you use the platform
ContributionsCourse and lesson ratings, review text, cheers and lessons you share with your squadYou
CredentialsCertificates issued, the program and level, the dateGenerated on completion
TechnicalIP address, browser type, and server logs including request timesAutomatic, as with any website

We do not ask for special-category data (health, beliefs, biometrics) and you should not put it in a proof submission. We do not take payment card details — if a course is ever priced, the payment provider handles the card and we never see it.

4. Why we use it, and our lawful basis

PurposeBasis
Giving you an account and delivering the courses you enrol inPerformance of a contract
Having an instructor review the work you submitPerformance of a contract
Issuing and verifying certificatesPerformance of a contract
Showing your activity to your squad and cohortPerformance of a contract — it is the core of the product
Reporting progress to the organisation that enrolled youLegitimate interests of that organisation
Reminder and re-engagement emailLegitimate interests — you can opt out at any time
Keeping the platform secure and preventing abuseLegitimate interests
Meeting legal and accounting obligationsLegal obligation

5. Who we share it with

  • Instructors and providers — the instructor of a course you enrol in sees your progress and the work you submit. They need to, in order to teach and grade you.
  • Your squad and cohort — other learners in your cohort see your name, profile photo, activity and streaks. This is the product working as designed. If you do not want it, do not join a cohort.
  • Your organisation — if an employer enrolled you, their admins see your progress, completions and learning hours.
  • Anyone you give a certificate link to — a certificate verification page shows the name it was issued to, the program, the level and the date.
  • Service providers that process data on our behalf — listed at /subprocessors.
  • Authorities, where we are legally required to.

We do not sell personal data, and we do not share it with advertisers.

6. How long we keep it

DataKept for
Account and profileWhile your account is open, then [[ RETENTION ]]
Learning records and certificatesRetained after closure so issued certificates stay verifiable
Submitted proof files[[ RETENTION ]] after the course ends
Server logs[[ RETENTION ]]

7. Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to processing, take it elsewhere, and complain to a regulator. To exercise any of these, email [email protected]. We will respond within one month.

Being straight with you: self-service export and deletion are not built yet. Today these requests are handled by a person when you email us. We would rather tell you that than imply a button exists.

If you are in the EU or UK you may complain to your local supervisory authority. Ours is [[ LEAD SUPERVISORY AUTHORITY ]].

8. Email you receive

We send transactional email (sign-in links, enrolment confirmations, certificate notices) and re-engagement reminders when you have gone quiet in a course. Every non-transactional message carries an unsubscribe link, and you can also email us to switch them off. Transactional email cannot be switched off while your account is open, because it is how sign-in works.

9. Cookies

We use cookies to keep you signed in and to remember basic preferences. We do not run advertising or profiling cookies. Full detail at /cookies.

10. Security

Everything is served over TLS, sign-in is passwordless, roles are separated, and administrative actions are logged. Our full posture — including what we do not claim — is at /security.

11. International transfers

Skill.re is operated from [[ JURISDICTION ]] and some of our service providers are outside your country. Where data leaves the EEA or UK we rely on [[ TRANSFER MECHANISM ]].

12. Children

Skill.re is for adults in a working context and is not directed at children. We do not knowingly collect data from anyone under [[ MINIMUM AGE ]]. If you believe we have, tell us and we will delete it.

13. Changes

We will post updates here and, for material changes, tell you by email or in the product before they take effect.

14. Contact

[email protected], or write to [[ REGISTERED ADDRESS ]].