Privacy Policy

How the European Skills Lab handles personal data, under the EU General Data Protection Regulation (GDPR). Last updated: 28 July 2026

1. Who is responsible

The European Skills Lab (https://www.skills-lab.eu) is operated by ACEEU GmbH (Accreditation Council for Entrepreneurial and Engaged Universities), Münster, Germany, which is the controller for the processing described here. Full postal address and legal details are in our Legal Notice.

For any data protection matter — including all the rights listed in section 10 — please write to mail@skills-lab.eu. ACEEU has not appointed a Data Protection Officer and is not required to do so under Art. 37 GDPR.

2. Browsing without an account

You can browse published projects, folders, files and search results without registering. You do not have to tell us who you are to do so, but the following is still processed:

Server log files

Our web server records the usual technical data for each request — IP address, date and time, the URL requested, the HTTP status, the amount of data transferred, the referring page and your browser's User-Agent string. This is needed to deliver the site and to detect and investigate attacks and faults.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in operating the service securely and reliably.

Cookies

We set exactly one cookie of our own: the PHP session cookie (PHPSESSID). It holds a random identifier, expires when you close your browser, and is what keeps you logged in and remembers a course pack you are collecting. It carries no analytics and no advertising identifiers.
Legal basis: § 25 (2) No. 2 TDDDG — strictly necessary for a service you have requested; no consent is required.

Google reCAPTCHA (section 7) may set cookies or store data in your browser under Google's own responsibility. It is the only third party this site contacts: fonts, stylesheets, scripts and images are all served from our own server, so simply reading a page discloses nothing to anyone else. We do not use any analytics, advertising, profiling or social-media tracking — no Google Analytics, no tag manager, no pixels.

3. What we record about how the platform is used

We keep our own usage statistics, so we know which material is useful and what people look for and do not find. This runs on our own server; nothing is shared with an analytics provider. Four kinds of event are recorded, and each row includes your IP address and your browser's User-Agent — so this data is personal data, not anonymous statistics:

  • Pages you visit — a timestamp, which kind of page it was (landing page, project, folder, file, search, assistant, get-engaged, suggest-a-feature) and, where applicable, which project, folder or file.
  • Files you download — a timestamp, which file, and whether it came from a single download or a ZIP archive.
  • Searches you run — a timestamp, the search terms you typed, how many results each category returned, and whether the AI matcher added anything. Please avoid entering personal or confidential information into the search box.
  • Questions you ask the AI assistant — a timestamp, the text of your question, how many sources were found, how relevant the best one was, and the tokens and cost of the request. The request is also counted against a per-IP hourly quota to stop the feature being abused.

Requests that look like they come from a bot are flagged as such but still recorded. If you are signed in, your user account is stored alongside the search and assistant records.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in understanding and improving a research repository, in identifying gaps in its content, and in preventing abuse of a costly public feature. You may object at any time (section 10).

Approximate location (GeoIP)

For each recorded page view and download we also derive an approximate location — country, region and city — from the IP address and store it with the usage row. The lookup runs entirely on our own server, against a local copy of the GeoLite2 database; your IP address is not sent to MaxMind or anyone else. Where usage figures appear publicly on this site (for example “a visitor from Berlin, Germany viewed this project”), they only ever show this coarse location — never the IP address itself. The derived location is deleted together with its usage row under the retention period below.
Legal basis: Art. 6 (1) (f) GDPR — the same legitimate interest as the usage statistics above. This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Feature suggestions

If you use the suggest-a-feature form, the name, email address and message you enter are sent to us by email and handled like any other correspondence — they are not stored in the platform's database. We use your email address only to reply to your suggestion.
Legal basis: Art. 6 (1) (f) GDPR — answering a request you sent us.

4. If you register an account

Researchers can register to submit projects. We ask for your first name, last name and email address, and store a cryptographic hash of your password — never the password itself. If you use the “forgot password” function we generate a new password and email it to you; your existing password keeps working until the new one is first used.
Legal basis: Art. 6 (1) (b) GDPR — performance of the user agreement you enter into by registering.

Administrators of the platform can sign in as a user account in order to help with a submission or investigate a problem. While they do so, they can see and change what that account can see and change.

5. Content you submit

Projects, organisation profiles, funding programme entries, logos and material files you upload are stored on our server. A project is a draft until an administrator publishes it; only you and the administrators can see a draft. Once a project is published, everything in it is publicly accessible on the internet — including the material files, their descriptions and the organisations listed — and can be indexed by search engines. Your name is shown to administrators as the owner of the project.

Please do not upload personal data about other people unless you are entitled to publish it.
Legal basis: Art. 6 (1) (b) GDPR for storing and publishing what you chose to submit.

6. AI features and OpenAI

Two features on this platform use an external AI provider, OpenAI (OpenAI Ireland Ltd. / OpenAI, L.L.C.):

  • Automatic descriptions and search indexing. When a material file is uploaded, its contents — the text of a document, or the image itself — may be sent to OpenAI so that a description and a search text can be written for it. The same applies to project and folder titles and descriptions, which are sent to produce the numeric vectors that power semantic search.
  • Search and the AI assistant. Your search terms and the questions you ask the assistant are sent to OpenAI to be turned into a vector, and an assistant question is additionally sent to a language model together with excerpts from the matching materials, so that an answer can be composed.

We do not send OpenAI your account details, such as your email address, or your IP address. We do send the text you type, and — for the automatic descriptions above — the contents of uploaded files, which may themselves contain names or other personal data. So please do not enter personal or confidential information into the search box or the assistant, and do not upload material containing personal data you are not entitled to publish.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in making a research repository findable and usable.

A Data Processing Addendum with OpenAI is in place, and the data we send is not used to train OpenAI's models. OpenAI processes data on servers that may be located outside the European Economic Area, in particular in the United States; those transfers are safeguarded by the European Commission's Standard Contractual Clauses.

7. Third-party services on our pages

Google reCAPTCHA

The login form, the registration form, the AI assistant and the feature-suggestion form are protected by Google reCAPTCHA (Google Ireland Limited), which distinguishes human visitors from automated scripts. To do this, reCAPTCHA loads a script from Google and evaluates data including your IP address, how long you spend on the page and your mouse and keyboard behaviour. On the assistant, a failed check does not block you — it only reduces how many questions you may ask per hour.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in protecting accounts and a costly public feature from automated abuse.

Google's privacy information: policies.google.com/privacy.

8. Hosting, email and recipients

Hosting. This platform runs on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in a data centre in Germany. Hetzner acts as our processor under a data processing agreement pursuant to Art. 28 GDPR, which is signed and on file.

Email. Registration confirmations, password resets and notifications are sent over our own mail server. Your email address and the content of the message are processed for that purpose.
Legal basis: Art. 6 (1) (b) GDPR.

Apart from the recipients named in this policy — OpenAI, Google and Hetzner — we do not pass your data to anyone. We do not sell personal data and we do not use it for advertising. Data is disclosed to public authorities only where we are legally required to do so.

9. How long we keep data

  • Account data — for as long as your account exists. Ask us and we will delete it.
  • Content you submitted — for as long as it is published, or until you or an administrator removes it.
  • Usage records (the four kinds in section 3) — 5 years (60 months), after which they are deleted automatically. Projects on this platform typically run for three to five years, and their usage statistics are meant to cover the whole project lifetime.
  • Server log files10 days, after which they are rotated away automatically by the hosting platform.

10. Your rights

You have the right to:

  • access the personal data we hold about you (Art. 15 GDPR);
  • rectification of inaccurate data (Art. 16 GDPR);
  • erasure (Art. 17 GDPR);
  • restriction of processing (Art. 18 GDPR);
  • data portability (Art. 20 GDPR);
  • object to processing based on legitimate interests (Art. 21 GDPR) — this covers all of our usage statistics in section 3;
  • withdraw consent at any time, where processing rests on consent, without affecting what was done before you withdrew it.

To exercise any of these, write to mail@skills-lab.eu.

You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority for the controller is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Kavalleriestr. 2–4, 40213 Düsseldorf, Germany — www.ldi.nrw.de.

11. Is any of this required?

Browsing published content requires no personal data beyond the technical minimum described in section 2. Registering an account requires your name and email address — without them we cannot create or secure the account. There is no automated decision-making and no profiling within the meaning of Art. 22 GDPR.

12. Changes to this policy

We will update this page when the platform changes. The date at the top shows the current version.


See also our Legal Notice.