Privacy policy
This policy describes how Skilluv collects, uses, shares and protects your personal data, pursuant to Regulation (EU) 2016/679 ("GDPR"), the French Data Protection Act, Beninese Act No. 2017-20 of 20 April 2018 (Digital Code), and other applicable laws.
1. Data controller
The data controller is [TODO: legal name], whose details are listed in the legal notice.
Data protection officer (DPO) or data-protection contact: [TODO: dpo@skilluv.… or DPO name].
2. Data we collect
2.1 Data you provide
- Account: username, first name, last name, email, hashed password, domain of interest (code, design, game, security).
- Profile: bio, avatar, external links (GitHub, LinkedIn, X, personal site), visibility preferences.
- Content: submitted solutions, created challenges, comments, votes, messages sent to other users or companies.
- Communications: emails you send us, abuse reports, support replies.
- Enterprise account (if applicable): company name, size, industry, country, talent lists and bookmarks.
2.2 Data collected automatically
- Technical data: IP address, session ID, browser and device type, OS, language.
- Usage data: pages viewed, challenges started, submissions, time spent, streaks, fragments earned, badges.
- Server logs: HTTP requests, status codes, timestamps, for security and diagnostics.
- Cookies and trackers: see section 9.
3. Purposes and legal bases
- Provision of the service (account creation, authentication, access to challenges, progress tracking) — basis: performance of the contract (Art. 6(1)(b) GDPR).
- Social and community features (leaderboards, public profiles, community content) — basis: contract and, where applicable, your consent (visibility settings).
- Connecting talents and companies — basis: your explicit consent via the "allow expressions of interest" setting.
- Security, fraud prevention and moderation — basis: legitimate interest (Art. 6(1)(f)) and legal obligation.
- Service improvement and aggregated statistics — basis: legitimate interest.
- Transactional communications (email verification, password reset, account notifications) — basis: contract.
- Marketing communications — basis: your consent, withdrawable at any time.
- Compliance with legal obligations (accounting records, responses to authorities) — basis: legal obligation.
4. Retention periods
- Active account: kept as long as your account exists.
- Deleted account: deletion or anonymisation within 30 days, subject to legal obligations (e.g. connection logs kept for up to 12 months).
- Public content (approved community challenges, ranking solutions): may be retained anonymously for leaderboard consistency.
- Server logs: 12 months max.
- Cookies: 13 months max (CNIL recommendation).
- Accounting records and invoices: 10 years (legal obligation).
5. Recipients and processors
Your data is only accessible to authorised personnel and to technical sub-processors, strictly within their mission. We notably use:
- Hosting: [TODO: provider, country]
- Transactional email: [TODO: provider]
- Analytics: [TODO if applicable]
- File storage: [TODO if applicable]
Each processor is bound by a contract compliant with Article 28 GDPR. We do not sell your personal data.
6. Transfers outside the EU
Some processors may be located outside the European Economic Area. In that case, the transfer is governed by:
- an adequacy decision of the European Commission, or
- Standard Contractual Clauses (SCCs) adopted by the Commission, or
- any other mechanism under Articles 44 et seq. GDPR.
For users residing in Benin, cross-border transfers comply with Articles 391 et seq. of Act No. 2017-20 (Beninese Digital Code).
7. Security
We implement appropriate technical and organisational measures: TLS-encrypted communications, password hashing (bcrypt or equivalent), access control, logging, regular backups, two-factor authentication available to users.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent authority within 72 hours and, where applicable, affected individuals without undue delay.
8. Your rights
Under the GDPR and applicable laws, you have rights over your data: access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and post-mortem directives. Details and the exercise procedure are on our GDPR rights page.
9. Cookies and trackers
Skilluv uses a minimal set of strictly necessary cookies:
- Session cookies (authentication, CSRF token) — exempt from consent.
- User preferences (theme, language, terminal mode) — stored in
localStorage, exempt from consent as strictly necessary to a service you requested. - Anonymised analytics — [TODO: specify or remove if unused].
You may configure your browser to refuse cookies. Refusing strictly necessary cookies may prevent the service from working.
10. Minors
Skilluv is not intended for persons under 15 (16 in some EU countries). If you are a minor, consent from your parental authority holder is required to open an account.
11. California residents (CCPA / CPRA)
California residents have additional rights: right to know, delete, correct, opt out of sale or sharing of personal information, and to non-discrimination. We do not sell your personal information within the meaning of California law.
12. Changes
This policy may be updated at any time. The last-updated date appears in the sidebar. For material changes, we will notify you via the app or by email.
13. Contact
For any question regarding your personal data, write to [TODO: dpo@skilluv.…] or by mail at the registered office address (see legal notice).