Privacy Policy
Last updated: 28 August 2026
1. Introduction
Skillvora ("Skillvora", "we", "us", "our") is committed to protecting the privacy and security of personal data relating to our Customers, their team members, and, where relevant, individuals whose data our Customers choose to store within the platform (for example, their own customers, leads and employees).
This Privacy Policy explains what personal data we collect, how and why we use it, who we share it with, how long we keep it, and the rights available to individuals under applicable data protection law. It applies to the Skillvora website, dashboard, and related services (together, the "Platform").
This Policy should be read alongside our Terms and Conditions. Where there is a Customer account involved, this Policy also explains the different roles Skillvora and the Customer play in relation to personal data held within the account, as set out in Section 4 below.
2. Who We Are and How to Contact Us
Skillvora is the data controller in respect of the personal data described in Section 3 (account and billing information) and, in respect of Customer Data, acts as a data processor on behalf of the Customer as described in Section 4. If you have any questions about this Policy or how we handle personal data, you can contact us at susmitagiri1321@gmail.com, or by post at 27 Vaughan Road, Newham, E15 4AA, United Kingdom. Skillvora has not appointed a formal Data Protection Officer. Data protection queries should be directed to the contact details above.
3. Personal Data We Collect
We collect and process the following categories of personal data in connection with operating the Platform and providing our services:
3.1 Account and Registration Data
- Name, business name, email address, telephone number and job title of the individual registering for or administering a Skillvora account.
- Login credentials, including a hashed password and, where enabled, multi-factor authentication details.
- Details of team members invited to an account, including name, email address and assigned role/permissions.
3.2 Billing and Payment Data
- Billing name and address, and subscription package and history.
- Limited payment metadata received from Stripe (such as payment status, card type and last four digits, or Bacs mandate status) necessary to manage your subscription. Full card numbers and full bank account details are captured and held directly by Stripe, not by Skillvora.
3.3 Usage and Technical Data
- Log data such as IP address, browser type and version, device type, operating system, and pages or features accessed within the Platform.
- Diagnostic and performance data used to identify and fix technical issues, and to understand how the Platform is used at an aggregate level.
- Cookies and similar technologies, as described in Section 9 (Cookies).
3.4 Communications Data
- Records of correspondence between you and Skillvora, including support requests, emails, and any feedback or survey responses you choose to provide.
3.5 Customer Data (entered by Customers into the Platform)
Customers use the Platform to record personal data relating to their own customers, leads and employees, including in the CRM, project management, HR and financial record-keeping modules. This may include, for example, contact details and communication history for leads and customers, and names, contact details, employment information, leave records and uploaded documents relating to employees. Skillvora processes this data solely as a processor, on the Customer's instructions, as set out in Section 4.
4. Our Role: Controller and Processor
In relation to a Customer's own account, billing and usage data (Section 3.1-3.4 above), Skillvora acts as the data controller, and this Policy describes how and why we use that data as controller.
In relation to Customer Data (Section 3.5) — the CRM, project, HR and financial records a Customer enters about their own customers, leads and employees — the Customer is the data controller, and Skillvora acts only as a data processor, processing that data solely to provide the Platform in accordance with the Customer's instructions, our Terms and Conditions, and, where applicable, a separate Data Processing Agreement. Skillvora does not decide why or how Customer Data is collected, and does not use Customer Data for its own independent purposes, such as marketing to a Customer's own leads or employees.
Individuals whose personal data has been entered into Skillvora by one of our Customers (for example, an employee whose leave record is stored in the HR module, or a lead in the CRM pipeline) should direct any data protection queries or rights requests in the first instance to that Customer, as the controller of their data. Skillvora will support Customers in responding to such requests in accordance with our processor obligations, as described in Section 8.
5. How We Use Personal Data and Our Legal Basis
We use personal data for the following purposes, relying on the legal bases indicated:
- Providing and operating the Platform (account registration, authentication, dashboard functionality) — necessary for the performance of our contract with you.
- Processing subscription payments via Stripe, including managing billing, renewals and the 14-day money-back guarantee — necessary for the performance of our contract with you, and to comply with our legal and accounting obligations.
- Customer support, responding to enquiries and resolving technical issues — necessary for the performance of our contract with you, and our legitimate interest in providing a responsive service.
- Improving the Platform, including analysing usage patterns, diagnosing faults, and developing new features — our legitimate interest in maintaining and improving a secure, functional product, balanced against your interests and rights.
- Security and fraud prevention, including monitoring for unauthorised access or misuse of accounts — our legitimate interest in protecting the Platform, our Customers and ourselves, and, where relevant, compliance with legal obligations.
- Marketing communications about Skillvora's own products and updates — based on your consent, where required, or our legitimate interest in informing existing Customers of relevant product updates, subject to your right to opt out at any time.
- Complying with legal obligations, such as tax, accounting and record-keeping requirements, or responding to lawful requests from regulators or law enforcement — necessary to comply with a legal obligation.
6. Sharing Personal Data
We do not sell personal data, and we do not share it with third parties for their own independent marketing purposes. We share personal data only in the following circumstances, and only to the extent reasonably necessary for the purpose described:
- Stripe — to process subscription payments, including card payments and Bacs Direct Debit. Stripe processes payment data under its own privacy policy and regulatory obligations as a payment institution; Skillvora does not control how Stripe uses data once it is processed under Stripe's own role as a controller of certain payment information.
- Hosting and infrastructure providers — who store and process data on our behalf in order to run the Platform, under contracts requiring them to protect that data appropriately and to process it only on our documented instructions.
- Other service providers — such as customer support tooling, analytics, and email delivery providers, engaged strictly to help us operate the Platform, and bound by data protection and confidentiality obligations no less protective than those set out in this Policy.
- Professional advisers — such as our accountants, auditors and legal advisers, where necessary for their professional services to us, and subject to their own professional confidentiality obligations.
- Regulators and law enforcement — where we are required to do so by law, court order, or a valid request from a competent authority, or to protect the rights, property or safety of Skillvora, our Customers, or others.
- A buyer or successor — in the event of a merger, acquisition, reorganisation, financing or sale of assets, subject to appropriate protections for the personal data involved and, where required, prior notice to affected individuals.
Where any service provider is located outside the UK or European Economic Area, we take steps to ensure an adequate level of protection is in place before any transfer occurs, such as reliance on UK adequacy regulations, or appropriate contractual safeguards including the UK International Data Transfer Agreement or the EU Standard Contractual Clauses as adapted for UK use. We carry out due diligence on international transfers and will provide further information about specific safeguards on request.
7. Cookies and Similar Technologies
We use cookies and similar technologies on our website and within the dashboard to make the Platform work, remember your preferences, and understand how the Platform is used.
- Strictly necessary cookies — required for core functionality such as authentication and session management; these cannot be switched off without affecting the Platform's operation.
- Functional cookies — used to remember settings and preferences, such as display options within the dashboard.
- Analytics cookies — used to understand how the Platform is used in aggregate, helping us identify and fix issues and prioritise improvements.
Where required by applicable law, we will ask for your consent before setting non-essential cookies, and you can manage or withdraw your cookie preferences at any time through your browser settings or, where available, a cookie preference tool on our website.
8. Data Security
We take the security of personal data seriously and apply appropriate technical and organisational measures designed to protect it against unauthorised or unlawful access, alteration, disclosure, loss or destruction, proportionate to the sensitivity of the data involved and the risks associated with processing it.
- Encryption of data in transit between your device and our servers, using industry-standard protocols.
- Access controls limiting internal access to personal data to individuals who need it to perform their role, supported by authentication and, where appropriate, logging of access to sensitive systems.
- Regular review of our security practices, vulnerability management, and prompt action to address identified issues.
- Contractual security requirements imposed on hosting and other service providers who process personal data on our behalf, including obligations to notify us of any security incident affecting that data.
- Regular backups of Platform data, designed to support business continuity and reduce the risk of data loss.
No method of transmission over the internet, or method of electronic storage, is completely secure, and while we work hard to protect personal data, we cannot guarantee its absolute security. Customers are responsible for keeping their own account credentials secure, enabling available security features such as strong passwords and multi-factor authentication, and managing user access permissions appropriately within their account, particularly given the commercially sensitive nature of the CRM, HR and financial data that may be stored within it.
In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will assess the incident promptly, take steps to contain and remediate it, and notify the relevant supervisory authority and, where required, affected individuals or Customers, in accordance with our obligations under applicable data protection law.
9. Data Retention
We retain personal data for as long as necessary to fulfil the purposes described in this Policy, including any legal, accounting or reporting requirements.
- Account and billing data is generally retained for the duration of your subscription and for a reasonable period afterwards to comply with tax, accounting and audit obligations, and to resolve any disputes.
- Customer Data entered into the Platform is retained in accordance with the Customer's own instructions and package limits, for as long as the Customer's account remains active, and for a limited period following termination to allow for data export, as described in our Terms and Conditions, after which it will generally be deleted or anonymised.
- Technical and usage logs are generally retained for a shorter period sufficient for security monitoring and diagnostic purposes, before being deleted or aggregated in a way that no longer identifies an individual.
Where personal data is no longer needed for these purposes, we will securely delete or anonymise it, save where we are required by law to retain it for longer.
10. Your Rights
Subject to applicable law, individuals have a number of rights in relation to their personal data. Where Skillvora is the controller (see Section 4), these rights can be exercised by contacting us directly using the details in Section 2. Where Skillvora is a processor acting on a Customer's instructions, requests should generally be directed to the relevant Customer as controller, though we will support Customers in responding to such requests in a timely manner, consistent with our processor obligations.
- The right to be informed about how your personal data is collected and used, as set out in this Policy.
- The right of access to a copy of the personal data we hold about you, together with supplementary information about how it is used.
- The right to rectification of inaccurate or incomplete personal data we hold about you.
- The right to erasure of personal data in certain circumstances, sometimes known as the "right to be forgotten", subject to any legal or contractual reasons we may have to retain it.
- The right to restrict processing of your personal data in certain circumstances, for example while the accuracy of the data is being verified.
- The right to data portability, allowing you to obtain and reuse your personal data, where we process it by automated means on the basis of consent or contract, for your own purposes across different services.
- The right to object to processing based on our legitimate interests, or to direct marketing at any time, free of charge.
- Rights related to automated decision-making, including profiling, where applicable — Skillvora does not currently use automated decision-making that produces legal or similarly significant effects on individuals.
If you wish to exercise any of these rights in relation to data for which Skillvora is the controller, please contact us using the details in Section 2. We may need to verify your identity before responding, and will respond within the timeframes required by applicable law, generally within one month of a valid request. If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or with the relevant supervisory authority in your own jurisdiction if you are located outside the UK.
11. Children's Privacy
The Platform is intended for use by businesses and their authorised representatives, and is not directed at, or intended for use by, children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so that we can take appropriate action.
12. Marketing Communications
Where you have opted in, or where permitted by our legitimate interests as an existing Customer, we may send you marketing communications about Skillvora's products, features and updates. You can opt out of marketing communications at any time by using the unsubscribe link included in each communication, or by contacting us directly. Opting out of marketing communications will not affect service-related communications necessary for the operation of your account and subscription.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, the Platform, or applicable law. Where changes are material, we will provide reasonable notice, such as by email or an in-app notification, before they take effect. The "Last updated" date at the top of this Policy indicates when it was last revised, and we encourage you to review it periodically.
14. A Note on Scope: What This Policy Does Not Cover
This Policy explains how Skillvora, as a software provider, handles personal data in connection with operating the Platform. It does not extend Skillvora's role beyond that of a software provider and, where applicable, data processor. Skillvora does not hold or transmit funds on behalf of third parties, does not process payroll or act as an employer, and does not provide accounting, tax, financial, investment or legal advice; accordingly, this Policy does not describe data handling associated with those regulated activities, because Skillvora does not carry them out. Where a Customer uses information recorded in Skillvora to fulfil its own regulatory or contractual obligations (for example, its obligations as an employer or as a business handling its own customers' data), the Customer's own privacy notices and compliance processes govern that activity, separately from this Policy.
Similarly, where a Customer's own website, app or offline processes collect personal data outside of the Skillvora Platform — for instance, a lead-capture form on a Customer's own website, before that lead is later added into Skillvora's CRM module — that initial collection is governed by the Customer's own privacy notice, not by this Policy. This Policy covers only personal data processed by Skillvora itself, in its capacity as controller of account and billing data, and as processor of Customer Data once it has been entered into the Platform.
15. Contact Us
If you have questions, concerns, or would like to exercise any of your rights in relation to this Privacy Policy, please contact us at susmitagiri1321@gmail.com, or by post at 27 Vaughan Road, Newham, E15 4AA, United Kingdom. We aim to respond to all privacy-related enquiries promptly and within the timeframes required by applicable law.