Privacy Policy

Last updated: August 2025 | Effective Date: August 24, 2025

Data Controller Information

Company: Skill Solutions Inc.
Address: 123 Business Park Drive, Suite 100, San Francisco, CA 94105, United States
Email: privacy@skillsolutions.io
Data Protection Officer: dpo@skillsolutions.io
EU Representative: [If applicable, add details]

1. Information We Collect

Personal Information

We collect information you provide directly to us, such as:

  • Name and contact information
  • Job title and department
  • Organization details
  • Account credentials
  • Profile information and preferences
  • Employee ID (when provided by your organization)
  • Manager and team information

Learning Platform Integration Data

When your organization integrates third-party learning platforms:

  • xAPI statements from Udemy, Coursera, LinkedIn Learning
  • Course enrollment and completion data
  • External certifications and badges
  • Learning activity timestamps and duration

Usage Information

We automatically collect certain information about your use of our platform:

  • Learning progress and completion data
  • Assessment results and performance metrics
  • Platform usage patterns and preferences
  • Device and browser information
  • IP address and location data

2. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases:

  • Contract Performance: To provide learning management services to your organization
  • Legitimate Interests: For platform security, fraud prevention, and service improvement
  • Legal Obligations: To comply with applicable laws and regulations
  • Consent: For optional features like marketing communications (you can withdraw consent anytime)
  • Vital Interests: In rare cases involving health and safety

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our learning platform
  • Personalize your learning experience and content recommendations
  • Track progress and generate performance reports
  • Communicate with you about your account and platform updates
  • Provide customer support and respond to inquiries
  • Analyze usage patterns to improve our services
  • Ensure platform security and prevent fraud
  • Comply with legal obligations

4. Information Sharing and Sub-Processors

We do not sell, trade, or otherwise transfer your personal information to third parties except in the following circumstances:

With Your Organization

Your organization's administrators may have access to your learning progress, assessment results, and other performance data for training and development purposes.

Service Providers

We use carefully selected sub-processors to help deliver our services:

  • Supabase (Database hosting) - United States
  • Vercel (Application hosting) - Global CDN
  • Resend (Email services) - United States
  • OpenAI/Anthropic (AI services, optional) - United States

All sub-processors are bound by data processing agreements and appropriate safeguards.

Legal Requirements

We may disclose information if required by law or to protect our rights, property, or safety, or that of our users or the public.

5. Multi-Tenant Data Isolation

As an enterprise B2B platform, we implement strict data isolation:

  • Complete tenant data separation using organization UUIDs
  • Row-level security policies in our database
  • Organization-specific encryption keys
  • Isolated subdomain access (e.g., yourcompany.api.skillsolutions.io)
  • No cross-tenant data access or sharing

6. Technical Security Controls

We implement enterprise-grade technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

Encryption and Data Protection

  • AES-256 encryption for data at rest using industry-standard algorithms
  • TLS 1.3 for data in transit with perfect forward secrecy
  • Hardware Security Module (HSM) for cryptographic key management
  • Annual key rotation procedures for all encryption keys
  • Database-level encryption with organization-specific keys

Access Controls and Authentication

  • Multi-factor authentication (MFA) required for all administrative access
  • Just-in-time (JIT) access for privileged operations
  • Role-based access control (RBAC) with principle of least privilege
  • Regular access reviews and quarterly certification processes
  • Zero-trust network architecture implementation
  • Session management with device fingerprinting and anomaly detection

Infrastructure and Network Security

  • Web Application Firewall (WAF) with real-time threat protection
  • DDoS mitigation and advanced rate limiting mechanisms
  • Container security scanning and runtime protection
  • Network segmentation and microsegmentation implementation
  • Regular penetration testing by certified third-party firms
  • 24/7 security monitoring and incident detection

Multi-Tenant Security Architecture

  • Complete tenant data separation using UUID-based isolation
  • Row-level security (RLS) policies preventing cross-tenant access
  • Organization-specific encryption keys and subdomain isolation
  • Isolated backup and disaster recovery per organization
  • Compliance boundaries enforced at the database and application levels

Security Monitoring and Incident Response

  • Security Information and Event Management (SIEM) system
  • Real-time threat detection and automated response capabilities
  • Digital forensics capabilities for incident investigation
  • Incident response plan with defined escalation procedures
  • Business continuity and disaster recovery testing
  • Compliance monitoring and automated audit trail generation

Security Certifications and Standards

  • SOC 2 Type II compliance in progress (annual audits)
  • ISO 27001 information security management system alignment
  • NIST Cybersecurity Framework implementation
  • Regular security assessments and vulnerability management
  • Employee security awareness training and certification programs

7. AI and Machine Learning Privacy Protections

Our platform uses artificial intelligence and machine learning technologies to enhance learning experiences while maintaining strict privacy protections for all user data.

AI Data Usage and Training

  • Customer data is never used for training general AI models or shared with AI providers
  • All AI processing occurs within tenant security boundaries with complete data isolation
  • Differential privacy techniques applied to all learning analytics to prevent individual identification
  • Federated learning approaches used for personalization without centralizing user data
  • AI model training limited to aggregated, anonymized, non-personal datasets only

AI Model Security and Privacy

  • End-to-end encryption for all AI inference requests and responses
  • AI model access controls with role-based permissions and audit logging
  • Regular bias auditing and algorithmic fairness assessments
  • AI decision-making transparency with explainable AI (XAI) capabilities
  • Secure model deployment with runtime protection and monitoring

AI Decision-Making and User Rights

  • Human oversight required for all high-impact AI-powered recommendations
  • Right to explanation for automated decisions affecting learning paths or assessments
  • Opt-out mechanisms available for AI-powered features and personalization
  • AI system transparency reports published quarterly
  • User control over AI personalization settings and data usage preferences

AI Provider Data Protection

  • Data Processing Agreements (DPAs) in place with all AI service providers
  • Minimal data sharing limited to non-personal, aggregated information only
  • AI provider compliance with GDPR, CCPA, and enterprise security standards
  • Regular audits of AI provider security practices and data handling
  • Contractual guarantees against unauthorized data use or model training

AI Ethics and Governance

  • AI Ethics Review Board oversight for all AI implementations
  • Responsible AI development practices following industry best practices
  • Regular AI impact assessments for privacy and fairness
  • Algorithmic transparency in learning recommendations and assessments
  • Continuous monitoring for AI bias and discriminatory outcomes

8. Data Retention

We retain data according to the following schedule:

  • Personal Identifiable Information: 30 days after account deletion, then anonymized
  • Employee Training Records: 3 years for compliance audits
  • Compliance Certificates: 7 years for regulatory requirements
  • Audit Logs: 2 years for security and compliance
  • Aggregated Analytics: Indefinitely in anonymized form

Important for Employees: Training data belongs to your organization. Individual employees cannot delete training records as these are required for compliance and organizational reporting.

9. Your Rights

GDPR Rights (European Economic Area)

  • Access: Request a copy of your personal information
  • Rectification: Request correction of inaccurate information
  • Erasure: Request deletion (subject to legal retention requirements)
  • Portability: Receive your data in a machine-readable format
  • Restriction: Request limitation of processing
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent where processing is consent-based
  • Automated Decision-Making: Right not to be subject to automated decisions
  • Lodge a Complaint: File a complaint with your supervisory authority

CCPA Rights (California Residents)

  • Right to Know: Request disclosure of personal information collected
  • Right to Delete: Request deletion of personal information
  • Right to Opt-Out: We do not sell personal information
  • Right to Non-Discrimination: Equal service regardless of privacy choices

Categories of Personal Information Collected: Identifiers, professional information, education information, commercial information, internet activity, and inferences.

To exercise these rights, email privacy@skillsolutions.io or call 1-800-SKILLOS (1-800-754-5567). We will respond within 30 days (GDPR) or 45 days (CCPA).

10. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms:

  • We will notify relevant supervisory authorities within 72 hours (GDPR requirement)
  • We will notify affected individuals without undue delay if the breach poses high risk
  • We will notify your organization's administrators immediately
  • We maintain incident response procedures and breach documentation

11. Cookies and Tracking

We use cookies and similar tracking technologies to enhance your experience on our platform. These technologies help us:

  • Remember your preferences and settings
  • Analyze platform usage and performance
  • Provide personalized content and recommendations
  • Ensure platform security and functionality

You can control cookie settings through your browser preferences, though disabling certain cookies may affect platform functionality.

12. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure that such transfers comply with applicable data protection laws and implement appropriate safeguards.

For users in the European Economic Area (EEA), UK, and Switzerland:

  • We use Standard Contractual Clauses (SCCs) approved by the European Commission
  • We implement supplementary technical measures for data protection
  • We conduct transfer impact assessments where required
  • Data Processing Agreements are available for enterprise clients

13. Children's Privacy

Our platform is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

14. Data Processing Agreements

For enterprise clients, we offer:

  • Standard Data Processing Agreements (DPA) compliant with GDPR Article 28
  • Custom DPAs for specific regulatory requirements
  • Business Associate Agreements (BAA) for HIPAA compliance where applicable
  • Security addendums and audit rights

Contact legal@skillsolutions.io to request a DPA.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

16. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Privacy Inquiries: privacy@skillsolutions.io
Data Protection Officer: dpo@skillsolutions.io
Legal/DPA Requests: legal@skillsolutions.io
Address: 123 Business Park Drive, Suite 100, San Francisco, CA 94105, United States
Phone: 1-800-SKILLOS (1-800-754-5567)
EU Representative: [Add if required]

For California Residents: To exercise your CCPA rights, you may also submit requests at our dedicated portal: privacy.skillsolutions.io/ccpa-request