GDPR Compliance & Data Processing
Transparency and compliance at Skillsive. Learn how we handle your data.
Data Controller & Location
Skillsive is a Data Controller responsible for processing personal data. We process data in accordance with GDPR, ensuring data protection, transparency, and compliance with individual rights.
Data Controller
Skillsive sp. z o.o., operating from Poland and Netherlands
Data Location
Primary: Azure West Europe (Netherlands). Secondary: Azure Poland Central for backups and disaster recovery.
Data Processors
We work with trusted third-party processors to deliver our services. All processors have signed Data Processing Agreements and comply with GDPR requirements.
Microsoft Azure
Processes user accounts, training progress, certificates, and system logs. Location: West Europe (Netherlands) and Poland Central. SOC 2 Type II and ISO 27001 certified.
Cloudflare
Provides CDN, DDoS protection, and DNS services. Processes HTTP metadata (headers, IP addresses, timestamps). Does not see encrypted request payloads. SOC 2 Type II certified.
SendGrid
Handles transactional email delivery. Processes email addresses and notification content. Data retention: 30 days. Location: USA (Standard Contractual Clauses in place).
Personal Data We Collect
Account data (name, email, phone), training progress (course completion, scores, certificates), technical data (IP address, device type, session logs), and communication data (support tickets, emails).
Legal Basis for Processing
We process your data based on: (1) Contract - to deliver services, (2) Consent - for marketing emails and optional features, (3) Legitimate Interest - for security and platform improvement, (4) Legal Obligation - for tax and compliance records.
Your GDPR Rights
You have the right to access, rectify, erase, restrict, and port your data. You can also object to processing and lodge complaints with supervisory authorities.
Right to Access
Request a copy of your personal data. Response time: 30 days.
Right to Rectification
Correct inaccurate or incomplete information. Available through account settings.
Right to Erasure
Request deletion of your account. 30-day grace period, then permanent hard deletion after 2 years.
Right to Restrict Processing
Temporarily pause data processing while maintaining your account.
Right to Object
Opt-out from marketing emails and certain processing activities.
Right to Portability
Export your data in machine-readable format. Planned implementation: Q3 2026.
Data Retention
Active account data is retained while your account is active. Deleted accounts: 30-day soft deletion, then permanent deletion after 2 years. Backups retained for 35 days. Certificates retained for 7 years (legal requirement).
Security & Encryption
Data is encrypted at rest (AES-256 in SQL, Blob Storage) and in transit (TLS 1.2+). Access controlled via RBAC and MFA. All activity logged for audit purposes.
Contact & Complaints
For GDPR-related questions or to exercise your rights, contact [email protected]. Response time: 30 days. You may also lodge a complaint with your national Data Protection Authority.
Related documents: