Note: This English version is provided for convenience only. In case of any discrepancy, the Czech version (Zasady ochrany osobnich udaju) shall prevail.
1. Introduction
This Privacy Policy (hereinafter the “Policy”) describes how Jurij Starynec, sole trader (OSVC), ID No.: 04080866, Tax ID: CZ9305054319, with registered office at Korunni 2569/108h, Vinohrady, 101 00 Prague 10, Czech Republic (hereinafter “SkillSetup”, “we”, “us”, or “the Controller”), collects, uses, stores, and otherwise processes personal data.
This Policy is issued in accordance with:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, hereinafter “GDPR”); and
- Act No. 110/2019 Coll., on the Processing of Personal Data (Czech GDPR adaptation act).
2. Controller Contact Information
| Detail | Information |
|---|---|
| Controller | Jurij Starynec, sole trader (OSVC) |
| ID No. | 04080866 |
| Tax ID | CZ9305054319 |
| Registered office | Korunni 2569/108h, Vinohrady, 101 00 Prague 10, Czech Republic |
| contact@skillsetup.tech | |
| Website | https://skillsetup.tech |
The Controller has not appointed a Data Protection Officer (DPO) as it is not required under Article 37 GDPR. For any data protection inquiries, please contact us using the details above.
3. Scope and Roles
3.1. Scope of This Policy
This Privacy Policy covers two contexts in which SkillSetup acts as the Controller of personal data:
- Website visitors — individuals who visit the website skillsetup.tech; and
- Customer contact persons — company administrators and authorised representatives who create an account and use the SkillSetup platform on behalf of their organisation.
3.2. SkillSetup as Controller
When you visit our website or register as a customer contact person (company administrator), SkillSetup determines the purposes and means of processing your personal data. In these contexts, SkillSetup is the Controller within the meaning of Article 4(7) GDPR.
3.3. SkillSetup as Processor — Employee Data
When our customers (employer companies) use the SkillSetup platform to manage their employees’ personal data, SkillSetup acts as a Processor within the meaning of Article 4(8) GDPR. In this capacity:
- The customer (employer) is the Controller of the employee data.
- SkillSetup processes employee data solely on behalf of and in accordance with the documented instructions of the customer.
- The relationship between SkillSetup and the customer is governed by a separate Data Processing Agreement (DPA), concluded in accordance with Article 28 GDPR.
- This Privacy Policy does not describe in detail the processing of employee data carried out on behalf of customers. Employees should refer to the privacy policy of their employer (our customer) for information about how their personal data is processed.
- A summary of the categories of employee data processed is provided in Section 5.2 for transparency purposes only.
4. Legal Bases for Processing
We process personal data on the following legal bases under Article 6(1) GDPR:
4.1. Performance of a Contract — Article 6(1)(b)
Processing that is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract. This includes:
- Creating and maintaining your user account;
- Providing the SkillSetup platform and its functionality;
- Communicating with you regarding service delivery;
- Managing authentication and session security.
4.2. Legal Obligation — Article 6(1)(c)
Processing that is necessary for compliance with a legal obligation to which the Controller is subject. This includes:
- Retention of accounting and billing records under Czech Act No. 563/1991 Coll. (Act on Accounting);
- Retention of tax-related records under Czech tax legislation;
- Compliance with other applicable Czech and EU legal requirements.
4.3. Legitimate Interest — Article 6(1)(f)
Processing that is necessary for the purposes of the legitimate interests pursued by the Controller, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. This includes:
- Ensuring the security and integrity of our systems and services;
- Preventing fraud, abuse, and unauthorised access;
- Analysing aggregated, non-identifying usage patterns to improve the service;
- Maintaining audit trails for compliance and accountability purposes;
- Debugging and quality assurance through application session replay (see below).
Session replay (Sentry). For debugging and quality-assurance purposes, SkillSetup may use Sentry’s session replay functionality, which records on-screen application activity during a user’s session (e.g., screens viewed, interface interactions). The legal basis for this processing is legitimate interest (Article 6(1)(f) GDPR). Retention periods for session replay recordings are set out in the Data Retention Schedule (see Section 8).
You have the right to object to processing based on legitimate interest, including session replay, at any time (see Section 10.6).
4.4. Consent — Article 6(1)(a)
Processing based on the data subject’s freely given, specific, informed, and unambiguous consent. This includes:
- Marketing communications (if any);
- Non-essential cookies (if and when introduced; see our Cookie Policy).
Where consent is the legal basis, you have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
5. Categories of Personal Data
5.1. Data Processed by SkillSetup as Controller
5.1.1. Contact Data
Data collected when you register an account or contact us:
- Full name (first name, last name);
- Email address;
- Phone number.
5.1.2. Account Data
Data related to your user account on the platform:
- Email address (used as login identifier);
- Password hash (stored using Argon2id; we never store plaintext passwords).
5.1.3. Technical Data
Data collected automatically when you access the Website or platform:
- IP address;
- User agent string;
- Browser type and version;
- Operating system;
- Device information (type, screen resolution).
5.1.4. Session Data
Data related to your authenticated sessions:
- Access token (stored as
access_tokenHttpOnly cookie); - Refresh token (stored as
refresh_tokenHttpOnly cookie); - Session metadata (creation time, expiration, device fingerprint).
5.1.5. Communication Data
Data related to communications between you and SkillSetup:
- Emails sent and received (content, timestamps, recipients);
- Support inquiries and correspondence.
5.2. Data Processed by SkillSetup as Processor (Reference Only)
The following categories of employee data may be processed by SkillSetup on behalf of customers. This processing is governed exclusively by the DPA between SkillSetup and the respective customer and is listed here for transparency only.
5.2.1. Identity Data
First name, last name, email address, personal email address, phone number, date of birth, nationality, personal identification number (rodne cislo).
5.2.2. Employment Data
Position, salary, employment type, FTE (full-time equivalent), working pattern, employment start and end dates.
5.2.3. Financial Data
Bank account number, IBAN, SWIFT/BIC code, BIN (tax identification number — DIČ), VAT number.
5.2.4. Contact and Address Data
Permanent address, temporary address, contact address, emergency contacts (name, phone, relationship).
5.2.5. Health Data (Article 9 GDPR — Special Category)
Sick leave records, disability status. This constitutes special category data within the meaning of Article 9 GDPR and is processed under Article 9(2)(b) (employment and social security obligations) on the basis of the customer’s instructions and applicable labour law.
5.2.6. Insurance Data
Insurance number, insurance company code, insurance company name.
5.2.7. Document Data
Employment contracts, electronic signatures (e-signatures), consent records.
5.2.8. Absence Data
Leave requests, approval records, leave balances.
5.2.9. Inventory Data
Asset assignments (company property assigned to employees).
5.2.10. Audit Data
Records of all user actions, including actor identity, IP address, user agent, timestamps, and data changes (before/after snapshots).
5.2.11. Geolocation Data (Consent-Based)
GPS coordinates captured at check-in and check-out for customers using the geofenced attendance-tracking feature. This data is processed only with the specific consent of the individual employee, which may be withdrawn at any time via the platform’s consent grant/revoke mechanism. Legal basis: Article 7(1) GDPR (conditions for consent), in conjunction with Section 316 of Act No. 262/2006 Coll. (Labour Code). As with all data in this Section 5.2, this processing is carried out by SkillSetup solely as Processor on behalf of the customer (Controller) under the DPA, and is listed here for transparency only.
6. Purposes of Processing
| Purpose | Data Categories | Legal Basis |
|---|---|---|
| Account creation and management | Contact data, account data | Art. 6(1)(b) — contract |
| Service delivery and platform operation | Contact data, account data, session data | Art. 6(1)(b) — contract |
| Authentication and session management | Account data, session data, technical data | Art. 6(1)(b) — contract |
| Communication regarding services | Contact data, communication data | Art. 6(1)(b) — contract |
| Accounting and tax compliance | Contact data, billing data | Art. 6(1)(c) — legal obligation |
| Security and fraud prevention | Technical data, session data, audit data | Art. 6(1)(f) — legitimate interest |
| Service improvement | Technical data (aggregated) | Art. 6(1)(f) — legitimate interest |
| Audit trail and accountability | Technical data, audit data | Art. 6(1)(f) — legitimate interest |
| Debugging and quality assurance (application session replay) | Technical data, on-screen session content | Art. 6(1)(f) — legitimate interest |
| Marketing communications (if applicable) | Contact data | Art. 6(1)(a) — consent |
| Non-essential cookies (if applicable) | Technical data | Art. 6(1)(a) — consent |
7. Cookies and Similar Technologies
We use strictly necessary cookies for authentication and session management. For full details on the cookies we use, their purposes, durations, and your choices, please refer to our Cookie Policy available at skillsetup.tech.
8. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law.
The Data Retention Schedule below is the single canonical source for retention figures across the SkillSetup legal document pack (this Policy, the DPA, the ROPA, and the Terms). Retention figures are not restated in any other document, so they cannot drift out of sync between documents.
8.1. Data processed by SkillSetup as Controller
| Data category | Retention period | Legal basis |
|---|---|---|
| Customer registration and accounting data, and tenant contact-person data | Contract duration + 10 years | § 35a of Act No. 235/2004 Coll., on Value Added Tax |
| Invoicing and accounting records | 10 years | Act No. 563/1991 Coll., on Accounting; Act No. 235/2004 Coll., on VAT |
| Security and audit logs | 7 years | Legitimate interest — platform security, fraud prevention, audit trail |
| Marketing-website visitor logs | 90 days | Legitimate interest — security |
| Session data | Session end + 30 days | Legitimate interest — security |
| Communications (support, contract correspondence) | 3 years | Legitimate interest / statute of limitations |
| Marketing consents | 3 years after withdrawal | Consent record-keeping under Article 7(1) GDPR |
| Error logs (Sentry) | 90 days | Legitimate interest — platform stability |
| Session replay recordings (Sentry) | 30 days | Legitimate interest — debugging and quality assurance |
8.2. Data processed on the Customer’s behalf (SkillSetup as Processor)
This processing falls outside the scope of this Policy (see Section 3.3) and is governed by the DPA and the Customer’s instructions as Controller. The periods are stated here for completeness.
| Data category | Retention period | Legal basis |
|---|---|---|
| Work-presence and attendance records | Per the Customer’s instruction; § 96 of the Labour Code recommends that employers retain time records for at least 3 years | § 96 of Act No. 262/2006 Coll., the Labour Code |
| Geolocation data (geofenced check-in and check-out) | Same category as attendance records; the consent record itself is retained for the lifetime of the account + 1 year after withdrawal | § 316 of the Labour Code, Article 7(1) GDPR |
| E-signature evidentiary records | Per document type — mirrors the retention of the underlying signed document | Evidentiary requirements of the eIDAS Regulation |
After the applicable retention period expires, personal data is securely deleted or irreversibly anonymised.
9. Recipients and Sub-processors
9.1. Categories of Recipients
We may share your personal data with the following categories of recipients:
- Sub-processors listed in Section 9.2, who process data on our behalf under appropriate contractual safeguards;
- Public authorities, where required by law (e.g., tax authorities, supervisory authorities);
- Professional advisors (legal counsel, accountants), subject to professional confidentiality obligations.
We do not sell personal data to any third party.
9.2. Sub-processors
We use the following sub-processors to deliver our services. This is the complete list; the same list appears consistently across this Policy, the DPA, and the ROPA.
| Name | Service | Data Processed | Location | DPA in Place |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, S3 object storage, SES email delivery | All data stored and processed on the platform | EU (Frankfurt, eu-central-1) | Yes |
| Sentry | Error monitoring, application performance, and session replay | Error logs, technical metadata, session replay recordings (on-screen application activity) | EU | Yes |
| Slack Technologies, LLC | Absence-approval workflow notifications (Slack integration) | Employee names, absence information | USA (EU-US Data Privacy Framework) | Yes |
9.3. International Transfers
All personal data is primarily processed and stored within the European Union (Frankfurt, eu-central-1 data center). When the Slack integration is activated by a customer, employee names and absence information are transferred to Slack Technologies, LLC (USA) on the basis of the European Commission’s adequacy decision under the EU-US Data Privacy Framework (Art. 45 GDPR). No other transfers to third countries outside the EU/EEA are made.
10. Data Subject Rights
Under the GDPR, you have the following rights regarding your personal data. To exercise any of these rights, please contact us at contact@skillsetup.tech.
We will respond to your request without undue delay and in any event within one month of receipt. This period may be extended by two further months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receipt of the request, together with the reasons for the delay.
10.1. Right of Access (Article 15 GDPR)
You have the right to obtain confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, access to the personal data and the following information: the purposes of the processing, the categories of personal data concerned, the recipients or categories of recipients, the envisaged retention period, the existence of your rights, and the right to lodge a complaint with a supervisory authority.
10.2. Right to Rectification (Article 16 GDPR)
You have the right to obtain without undue delay the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
10.3. Right to Erasure (Article 17 GDPR)
You have the right to obtain the erasure of personal data concerning you without undue delay where one of the grounds set out in Article 17(1) GDPR applies (e.g., the data is no longer necessary, you withdraw consent, you object to processing). This right does not apply where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.
10.4. Right to Restriction of Processing (Article 18 GDPR)
You have the right to obtain restriction of processing where one of the conditions set out in Article 18(1) GDPR applies (e.g., you contest the accuracy of the data, the processing is unlawful but you oppose erasure, we no longer need the data but you require it for legal claims).
10.5. Right to Data Portability (Article 20 GDPR)
You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format (e.g., JSON, CSV), and have the right to transmit that data to another controller without hindrance, where the processing is based on consent or a contract and is carried out by automated means.
10.6. Right to Object (Article 21 GDPR)
You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Article 6(1)(f) (legitimate interest) — including processing carried out via application session replay (see Section 4.3). We shall no longer process the personal data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims.
10.7. Right to Lodge a Complaint (Article 77 GDPR)
If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.
The competent supervisory authority in the Czech Republic is:
Urad pro ochranu osobnich udaju (UOOU) (Office for Personal Data Protection)
| Detail | Information |
|---|---|
| Address | Pplk. Sochora 27, 170 00 Prague 7, Czech Republic |
| Website | https://www.uoou.cz |
| podatelna@uoou.cz | |
| Phone | +420 234 665 111 |
11. Security of Processing
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. These measures include, but are not limited to:
- Encryption at rest: AES-256-GCM encryption for sensitive data stored in the database;
- Encryption in transit: TLS 1.2 or higher for all data transmitted between clients and servers;
- Password security: Argon2id password hashing algorithm (no plaintext passwords are stored);
- Access control: Role-Based Access Control (RBAC) with five distinct roles, enforcing the principle of least privilege;
- Multi-factor authentication (MFA): Available for user accounts to provide an additional layer of security;
- Audit trail: Comprehensive logging of all user actions, including actor identity, IP address, user agent, timestamps, and data changes;
- Tenant isolation: Multi-tenant architecture with PostgreSQL schema-level isolation, ensuring that each customer’s data is logically separated from other customers’ data;
- Session security: HttpOnly and Secure cookie flags on authentication tokens, preventing client-side access and ensuring transmission only over encrypted connections;
- Regular security reviews: Ongoing assessment and improvement of security measures.
12. Personal Data Breaches
In the event of a personal data breach, SkillSetup shall:
- notify the supervisory authority (the Czech Data Protection Authority) without undue delay and, where feasible, not later than 72 hours after having become aware of it, where the breach is likely to result in a risk to the rights and freedoms of natural persons (Article 33 GDPR);
- inform the affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Article 34 GDPR).
13. Source of Personal Data
We obtain personal data:
- directly from data subjects — on registration, when a contact form is submitted, through email correspondence, or through use of the Service;
- automatically — technical data collected when you visit our website (IP address, user agent, device information).
14. Obligation to Provide Personal Data
Providing the contact and account data described in Section 5.1 is a contractual requirement necessary to create a user account and to receive the SkillSetup service. Without this data the Service cannot be provided.
Providing consent to marketing communications and to non-essential cookies is voluntary, and withholding it has no effect on your ability to use the Service.
15. Automated Decision-Making and Profiling
We do not engage in any automated decision-making, including profiling, within the meaning of Article 22 GDPR. No decisions that produce legal effects concerning you or similarly significantly affect you are made solely by automated means.
We do not currently use any artificial intelligence (AI) features or systems in the processing of personal data. Should this change in the future, we will update this Policy and ensure compliance with applicable EU legislation, including Regulation (EU) 2024/1689 (EU AI Act) where relevant.
16. Data Protection by Design and by Default
In accordance with Article 25 GDPR, we implement data protection principles both at the time of determining the means for processing and at the time of the processing itself. This includes:
- Data minimisation: We collect only the personal data that is necessary for the specified purposes.
- Purpose limitation: Personal data is processed only for the purposes for which it was collected.
- Storage limitation: Personal data is retained only for as long as necessary, as set out in Section 8.
- Default privacy settings: By default, the strictest privacy settings apply. Only data necessary for the specific service is processed.
17. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time. Any changes will be published on this page with an updated effective date. Where changes are material, we will use reasonable efforts to notify you in advance (e.g., by email or through a notice on the platform).
We encourage you to review this Policy periodically to stay informed about how we protect your personal data.
18. Applicable Law and Jurisdiction
This Privacy Policy and any disputes arising from or in connection with it shall be governed by the laws of the Czech Republic. The courts of the Czech Republic shall have jurisdiction over any disputes, without prejudice to your right to lodge a complaint with a supervisory authority or to seek a judicial remedy in the Member State of your habitual residence, as provided under Articles 77-79 GDPR.
19. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact us at:
- Email: contact@skillsetup.tech
- Post: Jurij Starynec, Korunni 2569/108h, Vinohrady, 101 00 Prague 10, Czech Republic
20. Version History
| Version | Status | Date | Note |
|---|---|---|---|
| 2.0 | Published | 4 August 2026 | Consolidated revision |
This is an English translation of the authoritative Czech version of this document. In case of any discrepancy between this translation and the Czech original, the Czech version shall prevail.