Privacy Policy

How the European Skills Lab handles personal data, under the EU General Data Protection Regulation (GDPR). Last updated: 18 September 2026

1. Who is responsible

The European Skills Lab (https://www.skills-lab.eu) is operated by ACEEU GmbH (Accreditation Council for Entrepreneurial and Engaged Universities), Münster, Germany, which is the controller for the processing described here. Full postal address and legal details are in our Legal Notice.

For any data protection matter — including all the rights listed in section 10 — please write to mail@skills-lab.eu. ACEEU has not appointed a Data Protection Officer and is not required to do so under Art. 37 GDPR.

2. Browsing without an account

You can browse published projects, folders, files and search results without registering. You do not have to tell us who you are to do so, but the following is still processed:

Server log files

Our web server records the usual technical data for each request — IP address, date and time, the URL requested, the HTTP status, the amount of data transferred, the referring page and your browser's User-Agent string. This is needed to deliver the site and to detect and investigate attacks and faults.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in operating the service securely and reliably.

One consequence is worth spelling out. Researchers can place a download-counter badge — an image served from this site — on their own project websites. When someone visits such a page, their browser fetches that image from us, so we learn that visitor's IP address, their User-Agent and, as the referring page, the address of the website the badge was placed on. That happens even though they never came to this site themselves. We record these retrievals in our usage statistics (section 3, “Embedded badges and share links”): a timestamp, which badge and format, the referring page, the IP address and User-Agent, and the approximate location — country, region and city — derived from that IP locally on our own server (section 3, “Approximate location”). The rows are not linked to any user account, and after the period in section 9 the referring page's full address is deleted — only the site the badge sits on is kept. Badge fetches whose referring page identifies one of our own pages (the preview image in the share box) are not recorded; if your browser sends no referring page at all, a fetch is recorded like any other, as a retrieval from an unknown page. The server log entries expire after 10 days (section 9), as before.

Cookies and browser storage

We set exactly one cookie of our own: the PHP session cookie (PHPSESSID). It holds a random identifier, expires when you close your browser, and is what keeps you logged in and remembers a course pack you are collecting. It carries no analytics and no advertising identifiers.
Legal basis: § 25 (2) No. 2 TDDDG — strictly necessary for a service you have requested; no consent is required.

In addition, if you use the display controls in the header (dark mode, text size), we store these display settings in your browser's localStorage. They never leave your device and are never transmitted to us; you can remove them at any time by clearing your browser's site data.
Legal basis: § 25 (2) No. 2 TDDDG — storing a setting you explicitly chose; no consent is required.

Google reCAPTCHA (section 7) may set cookies or store data in your browser under Google's own responsibility. It is the only third party this site contacts: fonts, stylesheets, scripts and images are all served from our own server, so simply reading a page discloses nothing to anyone else. We do not use any analytics, advertising, profiling or social-media tracking — no Google Analytics, no tag manager, no pixels.

3. What we record about how the platform is used

We keep our own usage statistics, so we know which material is useful and what people look for and do not find. This runs on our own server; nothing is shared with an analytics provider. Five kinds of event are recorded, and each row includes your IP address and your browser's User-Agent — so this data is personal data, not anonymous statistics:

  • Pages you visit — a timestamp, which kind of page it was (landing page, all-projects page, project, folder, file, search, assistant, statistics page, get-engaged, suggest-a-feature, organisations, individual organisation page, EQF levels, competence frameworks, funding programmes, beta, about, about — why ESL, about — benefits, about — members, about — organisation hubs, about — FAQ, and the pages of an organisation hub: its home, projects, partners, individual partner, statistics and about pages) and, where applicable, which project, folder or file. For a page viewed inside an organisation hub (/hub/…) we also record which hub, and — if you arrived there directly from another website — the name of that website (for example example.org): never the full address of the page you came from, and nothing at all when you move between our own pages.
  • Files you download, and website links you follow — a timestamp, which file, whether it came from a single download or a ZIP archive, and — if you arrived through a marked share link — which kind of link that was (see the last bullet). Some material is a link to another website rather than a file; following one is recorded here in exactly the same way, and the record notes that it was a link. The record names the link material, so it does say which site you went to; nothing follows you once you are there, and that site's own records are its own. Where your browser runs JavaScript, a short notice names the address and asks you to confirm before you go. A download or link started inside an organisation hub also records which hub.
  • Searches you run — a timestamp, the search terms you typed, how many results each category returned, and whether the AI matcher added anything. Please avoid entering personal or confidential information into the search box.
  • Questions you ask the AI assistant — a timestamp, the text of your question, how many sources were found, how relevant the best one was, and the tokens and cost of the request. The request is also counted against a per-IP hourly quota to stop the feature being abused.
  • Embedded badges and share links — when a download-counter badge or raw counter is retrieved from another website (section 2): a timestamp, which project or file it belongs to, the image or counter format, and the address of the page it is embedded on (the referring page your browser sends, where it sends one). And when you arrive here through a marked share link — a copied link, a badge, a Markdown snippet or a QR code, recognisable by ?src= in the address: a timestamp, which project or file, which kind of link, and the referring page. These rows are never linked to a user account.

Requests that look like they come from a bot are flagged as such but still recorded. If you are signed in, your user account is stored alongside the search and assistant records.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in understanding and improving a research repository, in identifying gaps in its content, and in preventing abuse of a costly public feature. You may object at any time (section 10).

Approximate location (GeoIP)

For each recorded page view, download, and embedded-badge or share-link event (the fifth kind above) we also derive an approximate location — country, region and city — from the IP address and store it with the usage row. The lookup runs entirely on our own server, against a local copy of the GeoLite2 database; your IP address is not sent to MaxMind or anyone else. Where usage figures appear publicly on this site (for example “a visitor from Berlin, Germany viewed this project”), they only ever show this coarse location — never the IP address itself. Because the derived location is never more precise than a city, it remains part of the anonymised long-term statistics described in section 9.
Legal basis: Art. 6 (1) (f) GDPR — the same legitimate interest as the usage statistics above. This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Feature suggestions

If you use the suggest-a-feature form, the name, email address and message you enter are sent to us by email and handled like any other correspondence — they are not stored in the platform's database. We use your email address only to reply to your suggestion.
Legal basis: Art. 6 (1) (f) GDPR — answering a request you sent us.

4. If you register an account

Anyone can register — to save and organise materials for their own learning or teaching, or to submit projects. We ask for your first name, last name and email address, and store a cryptographic hash of your password — never the password itself. If you use the “forgot password” function we generate a new password and email it to you; your existing password keeps working until the new one is first used.
Legal basis: Art. 6 (1) (b) GDPR — performance of the user agreement you enter into by registering.

We also record, with the account itself, how it came into being and when it was last used: the date and time you registered, the IP address the registration came from and the approximate location derived from it (as in section 3, looked up on our own server — your IP address is not sent to anyone), your browser's User-Agent and preferred languages together with our own note of whether that User-Agent looked automated, the page that referred you to the registration form, and the date, IP address and country of your most recent sign-in together with a count of sign-ins. Administrators can also attach an internal note to an account. This exists so we can tell a genuine researcher from the automated and throwaway registrations the form attracts, and so we can answer questions about an account later; it is visible to administrators only. The details that could identify you — the IP addresses, the region and city, the User-Agent, the languages and the referring page — are erased when the account is closed; the dates, the countries, whether the registration looked automated, and the number of sign-ins remain, because none of them identifies a person. See below and section 9. The internal note is the one exception: it is kept, as the record of how the account was handled. Our administrators are instructed to write about the account rather than the person; if you would like the note on your account removed as well, ask us and we will delete it.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in keeping the platform free of abuse and in being able to support and secure accounts.

An account can use the platform in three ways — a Learning Area, a Teaching Area and a Project Management Area — and we store which of them you have activated and which one you want to start in after signing in. You choose both when you register. Afterwards you can switch a further area on under “Manage Roles”, switch one off again there, and — once you hold more than one — change which one you start in under “Change profile”. You always keep at least one area. Switching an area off hides it but deletes nothing: what you saved in it stays stored and is there again if you switch it back on. If you would rather have it erased, empty the area first, or ask us.
Legal basis: Art. 6 (1) (b) GDPR — providing the account you asked for.

In the Learning and Teaching Areas you can build a personal library: Saved Materials — a bookmark pointing at a project, folder or file, with the date you saved it — and Collections, which are lists you name, describe and put those bookmarks into in your own order. We store the pointers and your titles, notes and ordering; we do not copy the material itself. Your library is private: it is not shown to other users, it never appears on a public page, and no other user can reach it. Administrators handling an account see how many items it holds — the confirmation screen before an account is closed says so — rather than a listing of them; an administrator who signs in as your account, as described just below, sees your library as you do. Saving something is not the same as downloading it: the usage records in section 3 are written when you download or view, not when you bookmark. The whole library is deleted when the account is closed (see below and section 9).
Legal basis: Art. 6 (1) (b) GDPR — providing the account you asked for.

Administrators of the platform can sign in as a user account in order to help with a submission or investigate a problem. While they do so, they can see and change what that account can see and change.

You can close your account at any time under “Change profile” → “Close your account”, or by asking us. When an account is closed, the name, email address, organisation and password stored for it are erased immediately, together with the registration and sign-in details described above — the IP addresses, the region and city, the User-Agent and the languages and the referring page. What is left of them is the registration and last-sign-in dates, the country each came from, whether the registration looked automated, the number of sign-ins, and the internal administrator note, which is kept as the record of how the account was handled (ask us and we will delete that too). Your Saved Materials, your Collections and the record of which areas you had activated are deleted outright — they are yours alone, so unlike published content there is nothing to hand on. The account can no longer sign in. Projects that were already published stay online — they are openly licensed contributions and your name is never shown on them publicly — but they are transferred to a member of our team, who maintains them from then on; the same applies to organisation and funding programme entries. You choose whether unpublished drafts are transferred with them or deleted. If you manage an organisation hub, your management of it ends, but the hub stays online — it belongs to the organisation; hub requests you made that are still open are withdrawn, and the role, organisational e-mail address and explanation you gave in any hub request are erased. Anything we still keep afterwards is described in section 9.

To protect accounts and the integrity of the platform we keep an internal audit log: registrations, sign-ins (including failed attempts), password resets, profile changes, changes to projects and materials, and administrative actions — including when an administrator signs in as a user. Each record stores the account involved, the action, the affected item, the time, the IP address and the browser signature; it is visible to administrators only. After 60 months the IP address, browser signature and personal detail fields are removed automatically; what was done by which account is kept.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in securing accounts and keeping administrative actions accountable.

5. Content you submit

Projects, organisation profiles, funding programme entries, logos and material files you upload are stored on our server. A project is a draft until you publish it; only you, anyone you have given access to the project, and the administrators can see a draft. Once a project is published, everything in it is publicly accessible on the internet — including the material files, their descriptions and the organisations listed — and can be indexed by search engines. Your name is shown to administrators as the owner of the project.

Please do not upload personal data about other people unless you are entitled to publish it.
Legal basis: Art. 6 (1) (b) GDPR for storing and publishing what you chose to submit.

Inviting somebody to a project

A project owner can invite an e-mail address that has no account here yet. We then store that address, which project it was invited to, which access it was offered, who invited it and the dates, and we send an e-mail to it — at most three in total, if the owner withdraws the invitation and issues it again. The invitation link is valid for 30 days. If the invitation is never accepted, we delete the record — address included — 90 days after it was sent. If it is accepted, the person has an account by then and the record stays as part of the project's access history — and is deleted if that account is ever closed. Our administrative records (section 9) note that an invitation was sent and by whom, but never to which address. Nobody is added to any mailing list, and the address is used for nothing else.
Legal basis: Art. 6 (1) (f) GDPR — the legitimate interest of a project team in inviting its own partners to collaborate. You can object at any time using the contact details in section 1, and the project owner can withdraw a pending invitation themselves.

Organisation hubs

A user with the Project Management Area can request an organisation hub — a branded public page for an organisation's projects — or ask for access to manage an existing one. We store the request: which organisation and account it is for, the applicant's role, their organisational e-mail address, the proposed hub name and address, the explanation they gave, their confirmation that they may act for the organisation, and the decision with its dates and message. A new hub request is e-mailed to our team for review; an access request is shown to the hub's managers, who decide on it together with our administrators. We keep which accounts manage a hub, and who added them. Managers' names are never shown publicly. What a hub publishes — its name, texts, logos, colours, website and optional contact address, and the projects it shows — is public once the hub is published, like a published project. Hub managers also see the hub's usage statistics described in section 3 as totals and top lists: page views, visitors counted by IP address, countries and the names of referring websites — never an IP address or an individual visit.
Legal basis: Art. 6 (1) (b) GDPR.

ESL Membership

A user with the EU Project Manager role can register an ESL Membership on behalf of an organisation. We store which organisation, which account registered and manages it, an optional Department/Unit text, the date and version of the accepted Member Commitment, the registration and — if it ends — cancellation dates, and a Founding Member designation that only administrators assign. While a membership is active, the organisation's name and logo, the Department/Unit and the Founding Member designation are shown publicly on the Members page. Membership records are kept permanently, including after cancellation, as the organisation's membership history; they are not deleted when the managing account is closed, because the membership belongs to the organisation. A membership that is still active when the account is closed is named on the account-closure page; an administrator can cancel it, and on request its management can be moved to another account of the organisation.
Legal basis: Art. 6 (1) (b) GDPR.

6. AI features and OpenAI

Three features on this platform use an external AI provider, OpenAI (OpenAI Ireland Ltd. / OpenAI, L.L.C.):

  • Automatic descriptions and search indexing. When a material file is uploaded, its contents — the text of a document, or the image itself — may be sent to OpenAI so that a description and a search text can be written for it. The same applies to project and folder titles and descriptions, which are sent to produce the numeric vectors that power semantic search.
  • Educational classification. The contents of a material file — together with its file name, folder path and description, and basic information about its project (acronym, title, description, tags) — may also be sent to OpenAI to classify the resource into fixed educational categories: its target group, resource type, language, education sector, estimated learning duration, and an internal flag distinguishing learning resources from project paperwork — so that materials can later be found by what they teach. We store the chosen categories together with an internal confidence score used for quality control; the model's raw response is not retained.
  • Search and the AI assistant. Your search terms and the questions you ask the assistant are sent to OpenAI to be turned into a vector, and an assistant question is additionally sent to a language model together with excerpts from the matching materials, so that an answer can be composed.

We do not send OpenAI your account details, such as your email address, or your IP address. We do send the text you type, and — for the automatic descriptions and the educational classification above — the contents of uploaded files, which may themselves contain names or other personal data. So please do not enter personal or confidential information into the search box or the assistant, and do not upload material containing personal data you are not entitled to publish.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in making a research repository findable and usable.

A Data Processing Addendum with OpenAI is in place, and the data we send is not used to train OpenAI's models. OpenAI processes data on servers that may be located outside the European Economic Area, in particular in the United States; those transfers are safeguarded by the European Commission's Standard Contractual Clauses.

7. Third-party services on our pages

Google reCAPTCHA

The login form, the registration form, the AI assistant and the feature-suggestion form are protected by Google reCAPTCHA (Google Ireland Limited), which distinguishes human visitors from automated scripts. To do this, reCAPTCHA loads a script from Google and evaluates data including your IP address, how long you spend on the page and your mouse and keyboard behaviour. On the assistant, a failed check does not block you — it only reduces how many questions you may ask per hour.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in protecting accounts and a costly public feature from automated abuse.

Google's privacy information: policies.google.com/privacy.

8. Hosting, email and recipients

Hosting. This platform runs on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in a data centre in Germany. Hetzner acts as our processor under a data processing agreement pursuant to Art. 28 GDPR, which is signed and on file.

Email. Registration confirmations, password resets and notifications are sent over our own mail server. Your email address and the content of the message are processed for that purpose.
Legal basis: Art. 6 (1) (b) GDPR.

Apart from the recipients named in this policy — OpenAI, Google and Hetzner — we do not pass your data to anyone. We do not sell personal data and we do not use it for advertising. Data is disclosed to public authorities only where we are legally required to do so.

9. How long we keep data

  • Account data — for as long as your account exists. This includes the registration and sign-in details in section 4, which are not on the 60-month clock below: they belong to the account, not to a usage record, and they go when it does. You can close your account yourself at any time (section 4), or ask us to; either way the name, email address, organisation, password, both IP addresses, the region and city, the User-Agent, the languages and the referring page are erased immediately. What remains is an account number, the registration and last-sign-in dates, the country each of them came from, whether the registration looked automated, the number of sign-ins, and the internal administrator note (section 4) — because other records, the audit entries below and the ownership of published content, refer to it. Ask us and we will remove the note as well. Your Saved Materials, Collections and activated areas (section 4) are deleted at the same moment — no list, title or bookmark of yours survives. The only trace left is in the audit records below, which note that the account chose those areas when it registered or switched one on.
  • Content you submitted — for as long as it is published, or until you or an administrator removes it.
  • ESL Membership records — permanently, including cancelled periods: they are the organisation's membership history (section 5). Closing the managing account does not remove them.
  • Organisation hub requests (section 5) — kept as the hub's history for as long as the organisation's record exists. When the account that made a request is closed, its role, organisational e-mail address and explanation are erased immediately and any open request is withdrawn. A hub itself stays until our team removes it, even when its managers' accounts are closed: it belongs to the organisation.
  • Project invitations (section 5) — the invitation link works for 30 days, and an invitation that is never accepted is deleted automatically 90 days after it was sent, e-mail address included. An accepted one is kept as part of the project's access history — but if that account is later closed, the invitation is deleted with it. Our administrative records (below) note that an invitation was sent and by whom, never to which address.
  • Usage records (the five kinds in section 3) — kept in identifiable form for 5 years (60 months). Projects on this platform typically run for three to five years, and their usage statistics are meant to cover the whole project lifetime. After 60 months each record is anonymised automatically: the IP address is truncated (the last part is removed, so it no longer identifies a connection), the browser's User-Agent string is deleted, any link to a user account is removed, and on badge/share-link records the referring page's full address is deleted (only the referring site is kept). The hub a page was viewed in and the name of the website a hub visitor came from are kept, since they identify nobody. What remains — the timestamp, what was viewed, downloaded, searched for or embedded where, and the coarse location of section 3 — no longer relates to an identifiable person and is kept indefinitely as long-term usage statistics (Art. 5 (1) (e) GDPR does not restrict anonymous data). Search terms and assistant questions are retained as part of these statistics — which is one more reason not to enter personal data into those boxes (sections 3 and 6).
  • Audit records (section 4) — IP address, browser signature and personal detail fields are removed automatically after 60 months; the record of which account performed which action is kept for the security and integrity of the platform. If you close your account, your name and email address are removed from these records straight away — what stays is the account number and what was done.
  • Server log files10 days, after which they are rotated away automatically by the hosting platform.

10. Your rights

You have the right to:

  • access the personal data we hold about you (Art. 15 GDPR);
  • rectification of inaccurate data (Art. 16 GDPR);
  • erasure (Art. 17 GDPR) — for your account you can exercise this yourself at any time, see section 4;
  • restriction of processing (Art. 18 GDPR);
  • data portability (Art. 20 GDPR);
  • object to processing based on legitimate interests (Art. 21 GDPR) — this covers all of our usage statistics in section 3;
  • withdraw consent at any time, where processing rests on consent, without affecting what was done before you withdrew it.

To exercise any of these, write to mail@skills-lab.eu.

You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority for the controller is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Kavalleriestr. 2–4, 40213 Düsseldorf, Germany — www.ldi.nrw.de.

11. Is any of this required?

Browsing published content requires no personal data beyond the technical minimum described in section 2. Registering an account requires your name and email address — without them we cannot create or secure the account. There is no automated decision-making and no profiling within the meaning of Art. 22 GDPR.

12. Changes to this policy

We will update this page when the platform changes. The date at the top shows the current version.


See also our Legal Notice.