GDPR Compliance & Data Processing

Transparency and compliance at Skillsive. Learn how we handle your data.

Data Controller & Location

Skillsive is a Data Controller responsible for processing personal data. We process data in accordance with GDPR, ensuring data protection, transparency, and compliance with individual rights.

Data Controller

Skillsive sp. z o.o., operating from Poland and Netherlands

Data Location

Primary: Azure West Europe (Netherlands). Secondary: Azure Poland Central for backups and disaster recovery.

Data Processors

We work with trusted third-party processors to deliver our services. All processors have signed Data Processing Agreements and comply with GDPR requirements.

Microsoft Azure

Processes user accounts, training progress, certificates, and system logs. Location: West Europe (Netherlands) and Poland Central. SOC 2 Type II and ISO 27001 certified.

Cloudflare

Provides CDN, DDoS protection, and DNS services. Processes HTTP metadata (headers, IP addresses, timestamps). Does not see encrypted request payloads. SOC 2 Type II certified.

SendGrid

Handles transactional email delivery. Processes email addresses and notification content. Data retention: 30 days. Location: USA (Standard Contractual Clauses in place).

Personal Data We Collect

Account data (name, email, phone), training progress (course completion, scores, certificates), technical data (IP address, device type, session logs), and communication data (support tickets, emails).

Legal Basis for Processing

We process your data based on: (1) Contract - to deliver services, (2) Consent - for marketing emails and optional features, (3) Legitimate Interest - for security and platform improvement, (4) Legal Obligation - for tax and compliance records.

Your GDPR Rights

You have the right to access, rectify, erase, restrict, and port your data. You can also object to processing and lodge complaints with supervisory authorities.

Right to Access

Request a copy of your personal data. Response time: 30 days.

Right to Rectification

Correct inaccurate or incomplete information. Available through account settings.

Right to Erasure

Request deletion of your account. 30-day grace period, then permanent hard deletion after 2 years.

Right to Restrict Processing

Temporarily pause data processing while maintaining your account.

Right to Object

Opt-out from marketing emails and certain processing activities.

Right to Portability

Export your data in machine-readable format. Planned implementation: Q3 2026.

Data Retention

Active account data is retained while your account is active. Deleted accounts: 30-day soft deletion, then permanent deletion after 2 years. Backups retained for 35 days. Certificates retained for 7 years (legal requirement).

Security & Encryption

Data is encrypted at rest (AES-256 in SQL, Blob Storage) and in transit (TLS 1.2+). Access controlled via RBAC and MFA. All activity logged for audit purposes.

Contact & Complaints

For GDPR-related questions or to exercise your rights, contact [email protected]. Response time: 30 days. You may also lodge a complaint with your national Data Protection Authority.

Have Questions?

Contact our Data Protection Officer for GDPR-related inquiries.

[email protected]