Privacy policy
Information about personal-data processing under Regulation (EU) 2016/679 (GDPR).
1. Data controller
Lab42 SrlVAT number: IT03677180121
2. Scope and data collected
This notice applies to visits to openskills.info and to any account you create. What we process depends on how you use the site.
Browsing. When you request a page, ordinary web-server and security data may be processed: IP address, request date and time, requested URL, HTTP method and status, referrer, user-agent and device/browser information, and diagnostic or security events. This information is necessary to deliver the site, maintain availability, diagnose faults, and prevent abuse.
Accounts. If you log in, we process your email address. You can sign in via a one-time "magic link" sent to that address, or with a Google or GitHub account — either way, we never store a password. If you sign in with one of those providers, it shares your email address with our authentication provider, Supabase, and may also share basic profile information such as your name or profile picture depending on what the provider returns; the site itself only uses your email address and an internal account identifier, whichever method you use to sign in. Your account also has an internal identifier and, only if a site administrator has granted you one, a role (for example, administrator).
Access and subscriptions. For your account we record which discipline(s) you have access to, the status of that access (active, trialing, past due, canceled, paused, or revoked), whether it comes from a paid subscription or a manual grant, and — for paid subscriptions — a reference ID linking to your subscription at Paddle, our payment provider. We do not receive or store your payment card details; those are collected and processed directly by Paddle (see section 4).
If a site administrator grants you access before you have created an account yourself, your email address is processed at that point to create the account and send you an invitation, even though you did not submit it to us directly.
Some course pages request a small product icon from Google’s favicon service. The request is configured without a referrer, but Google still receives the IP address, any cookies its domain has set in your browser, and basic request metadata needed to return the image.
Newsletter consent. If you opt in from your account page, we record the fact and time of that consent and where it was given. This does not currently result in any email being sent — no newsletter exists yet, and no third-party sending service processes your address for this purpose. The record exists so a newsletter can be introduced later without asking again for consent already given. Turning the toggle off clears this consent record.
3. Purposes and legal bases
- Delivering requested pages and network communications: performance of the service you request and our legitimate interest in operating the site (GDPR Articles 6(1)(b) and 6(1)(f)).
- Creating and managing your account, sending the login link you request, and giving you access to the content you are entitled to: performance of a contract (Article 6(1)(b)).
- Processing and administering paid subscriptions, including the billing status Paddle reports back to us: performance of a contract (Article 6(1)(b)).
- Security, abuse prevention, troubleshooting, and service reliability: our legitimate interest in protecting the site and its users (Article 6(1)(f)).
- Compliance with binding legal obligations or lawful authority requests, where applicable (Article 6(1)(c)).
- Recording newsletter consent: your consent (Article 6(1)(a)), which you may withdraw at any time from your account page.
We do not use personal data from this site for advertising, profiling, or solely automated decisions producing legal or similarly significant effects. Access is granted or revoked by fixed rules tied to subscription status, not by profiling.
4. Service providers and recipients
The site is hosted on Vercel. Vercel Inc. and its infrastructure providers may process request, network, and diagnostic data to deliver and secure the service. Google LLC also receives the limited request data described above when a course icon is loaded.
Account sign-in and the underlying database are provided by Supabase, Inc., which processes your email address, authentication tokens, and the access/subscription data described in section 2. If you choose to sign in with Google or GitHub instead of an email link, that provider acts as an independent data controller for the sign-in step: it authenticates you and shares your email address (and, depending on the provider, basic profile information) with Supabase so your account can be created or matched. Consult the provider's own privacy notice for how it processes your data up to that point.
Login and account emails are delivered through Resend, which processes the recipient email address and the message content necessary to send that email.
Paid subscriptions are sold and billed by Paddle (Paddle.com Market Ltd for customers in the UK/EEA, Paddle.com Inc. elsewhere), acting as Merchant of Record: Paddle, not Lab42 Srl, is the seller of record for your subscription. Paddle collects and processes your payment and billing details directly, issues your receipt or invoice, and handles applicable VAT or sales tax. We only receive your subscription's status and an internal reference ID from Paddle — never your full payment details.
Data may also be disclosed when required by law or necessary to establish, exercise, or defend legal claims.
Read the service providers’ current notices at Vercel, Supabase, Resend, Paddle, Google, GitHub.
5. International transfers
Vercel, Supabase, Resend, Paddle, Google, GitHub, or their subprocessors may process data outside the European Economic Area. Where GDPR transfer restrictions apply, such transfers must be covered by an adequacy decision, approved standard contractual clauses, or another lawful safeguard. You may contact us for information about safeguards relevant to your data.
6. Retention
Technical logs and security events are retained only for the periods configured in the hosting service and reasonably necessary for delivery, security, incident investigation, and legal compliance. The period may be extended where an event must be preserved to investigate abuse, resolve a dispute, or comply with law.
Account, access, and subscription records are retained for as long as your account exists. Where a record is linked to a paid subscription's billing history, we retain it for as long as reasonably necessary for accounting, tax, and dispute-resolution purposes, even after the subscription ends or the account is closed. Your payment card and billing details themselves are retained by Paddle under its own retention policy, not by us.
7. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction, portability, or objection to processing based on legitimate interests. There is currently no self-service option to delete an account — contact us using the details in section 1 and we will action the request, subject to any records we must keep for accounting or legal-defense purposes. You may also lodge a complaint with the competent supervisory authority. In Italy, this is the Garante per la protezione dei dati personali. We may need to verify your identity before acting on a request.
8. Changes to this notice
We will update this notice before introducing materially different data processing beyond what is described above, such as new third-party services or non-essential tracking. The date below identifies the current version.
Last updated: 20 July 2026.
