Data Processing Agreement
Last updated: July 15, 2026. For a new Customer, this version becomes effective when an authorized Customer representative expressly accepts an Agreement that identifies and incorporates this version. For an existing Customer, it becomes effective only through that express acceptance or a separately signed agreement. A generic change notice or continued use does not accept this version. It does not retroactively replace a DPA version that governed earlier processing.
This Data Processing Agreement (the "DPA") forms part of and supplements the Skillsail Terms and Conditions. If Skillsail processes Customer Personal Data on behalf of a Customer, acceptance of the Terms by the Customer acting through a legally capable and authorized representative also constitutes acceptance of this DPA on behalf of that Customer.
Where Customer Personal Data relates to a child or another User for whom applicable law requires additional permission or authorization, the Customer remains responsible for the obligations that apply to it in its actual role. If the Customer is a Controller, this includes determining and documenting its lawful basis, providing required notices, obtaining and maintaining any authorization from a parent, legal guardian, holder of parental responsibility, or other legally authorized person that applicable law requires, and issuing lawful documented instructions. If the Customer is a Processor, it must act under its Controller's lawful instructions and agreement and ensure that its instructions to Skillsail are lawful and within the authority granted by that Controller. Customer authorization for a User to access Skillsail does not by itself constitute consent by the User or a holder of parental responsibility, establish the Customer as that holder, or satisfy an obligation that applicable law places directly on Skillsail. Each party remains responsible for obligations that apply to it in its actual role.
This DPA has 2 parts: (1) the Key Terms on this Cover Page and (2) the Common Paper DPA Standard Terms Version 1.1 posted at commonpaper.com/standards/data-processing-agreement/1.1 ("DPA Standard Terms"), which is incorporated by reference. If there is any inconsistency between the parts of the DPA, the Cover Page will control over the DPA Standard Terms. Capitalized and highlighted words have the meanings given on the Cover Page. However, if the Cover Page omits or does not define a highlighted word, the default meaning will be "none" or "not applicable" and the correlating clause, sentence, or section does not apply to this DPA. All other capitalized words have the meanings given in the DPA Standard Terms or the Agreement.
Key Terms
The key legal terms of the DPA are as follows:
| Agreement | This DPA supplements the following agreement: https://skillsail.com/legal/terms |
|---|---|
| Approved Subprocessors | https://skillsail.com/legal/subprocessors |
| Provider Security Contact | nico@skillsail.com Skillsail GmbH Elektrastraße 11 81925 München, Germany |
| Security Policy | None. No separate security policy or independent third-party security audit report is incorporated into this DPA. The applicable technical and organizational measures are listed in Annex II below and summarized in the Data Protection and Security section of the Privacy Policy. |
| Changes to the Agreement | A change to the Agreement, a generic change notice, or continued use of the Service does not accept a new DPA Cover Page or modify the DPA Standard Terms. Processing details may be updated only through a mechanism permitted by the DPA Standard Terms. Any other change to this DPA requires express acceptance of an updated Cover Page by an authorized Customer representative or a separately signed data processing agreement. |
| Governing Law and Chosen Courts | Notwithstanding the governing law or similar clauses of the Agreement, all interpretations and disputes about this DPA will be governed by the laws of the Governing State without regard to its conflict of laws provisions. In addition, and notwithstanding the forum selection, jurisdiction, or similar clauses of the Agreement, the parties agree to bring any legal suit, action, or proceeding about this DPA in, and each party irrevocably submits to the exclusive jurisdiction of, the courts of the Governing State. Governing State means: Germany |
| Service Provider Relationship | To the extent California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq ("CCPA") applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed below (see Nature and Purpose of Processing), which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA. |
| Restricted Transfers | Restricted Transfers may occur in providing the Service. Sections 3.2 and 3.3 of the DPA Standard Terms apply only when their stated conditions are met for a qualifying transfer from Customer to Provider. Module Two of the EEA SCCs applies where Customer is a Controller and Provider is a Processor; Module Three applies where Customer is a Processor and Provider is a Subprocessor. The Customer-Provider SCCs or UK Addendum do not, by themselves, govern or validate a later transfer from Provider to a downstream recipient. Provider must separately ensure that each transfer for which it is responsible is covered by the authorization, contractual terms, transfer mechanism, and supplementary measures required by applicable law. Current provider locations and transfer information are listed on the Subprocessors page. |
| Governing Member State | EEA SCCs: Germany |
Annex I(A) List of Parties
| Data Exporter | Name: the Customer entering into this DPA Address: the Customer address recorded in the applicable order form, Organization Account, or other Agreement record Contact person, position, and contact details: the authorized representative and contact details recorded in the applicable order form, Organization Account, or electronic acceptance record Activities relevant to transfer: See Annex 1(B) Signature and date: the Customer's electronic acceptance of the Agreement version that expressly incorporates this DPA, as recorded by Skillsail, or the signature and date in a separately signed agreement Role: Controller where Customer determines the purposes and means of the relevant Processing; Processor where Customer Processes the relevant Personal Data on behalf of another Controller. The applicable role is determined for the transfer concerned. |
|---|---|
| Data Importer | Name: Skillsail GmbH Contact person, position, and contact details: Nico Schriever, CEO, hello@skillsail.com Address: Elektrastraße 11, 81925 München, Germany Activities relevant to transfer: See Annex 1(B) Signature and date: incorporated from Provider's electronic issuance record for this DPA version and the Customer's acceptance record; if the parties use a separately signed DPA, the signatures and dates in that agreement apply. This DPA takes effect for a Customer only on the Customer effective date described above Role: Processor where Customer is the Controller; Subprocessor where Customer is a Processor. The applicable role is determined for the transfer concerned. |
Annex I(B) Description of Transfer and Processing Activities
| Service | The Service is: Skillsail Platform, an AI-powered eLearning content creation, hosting, sharing, and export service, including related support services. |
|---|---|
| Categories of Data Subjects | Customer's Authorized Users, learners, employees, customers, and other individuals whose Personal Data the Customer submits or directs Skillsail to process, including Children and other younger Users where the Customer directs Skillsail to process their data and that processing is permitted under the Agreement and applicable law, and individuals whose data is received or processed despite absent or disputed authorization Parents, legal guardians, representatives, or other requesters whose information the Customer submits or directs Skillsail to process in support, permission-withdrawal, or privacy-rights correspondence |
| Categories of Personal Data | The following categories are included only to the extent they are Customer Personal Data processed on the Customer's lawful documented instructions. They do not include data Skillsail processes independently as Controller for its direct Customer relationship, billing, fraud prevention, legal compliance, security, or direct support and rights requests. Names and account or organization membership identifiers Contact information such as email address, phone number, or postal address Prompts, instructions, messages, uploaded files, and generated eLearning or training content, to the extent they contain Personal Data Employment, role, training, or organizational information that Customer chooses to include in Customer Data File, media, module, and content metadata User activity, usage, diagnostics, device, browser, IP address, and provider-derived country or region information where infrastructure produces it from the IP address Contact, relationship, correspondence, and authority-verification information supplied in connection with support, permission withdrawal, or privacy-rights requests, only where processed on the Customer's instructions The ordinary Service does not request a date of birth, an identity-document copy, guardian contact details, age band, or proof of parental or guardian permission as account fields. Customer must not submit such documents for verification unless the parties first agree in writing on the purpose, instructions, safeguards, and retention. |
| Special Category Data | Is special category data (as defined in Article 9 of the GDPR) Processed? Not authorized by default. Customer must not submit or instruct Skillsail to process Special Category Data unless the parties first agree in writing on the permitted categories, purposes, instructions, legal basis, and safeguards. |
| Frequency of Transfer | Continuous |
| Nature and Purpose of Processing | Receiving data, including collection, accessing, retrieval, recording, and data entry Holding data, including storage, organization, and structuring Using data to provide requested content generation, analysis, support, security, and service functionality. The Service is not intended to make decisions based solely on automated processing that produce legal or similarly significant effects about data subjects unless the parties separately document and authorize that processing and the required safeguards Protecting data, including restricting, encrypting, and security testing Sharing data, including disclosure, dissemination, allowing access, or otherwise making available Returning data to the data exporter or data subject |
| Duration of Processing | Provider Processes Customer Personal Data for the term of the DPA and only for as long as necessary to perform the Customer's documented instructions, subject to the return, deletion, and legally permitted retention provisions of the DPA Standard Terms. The Privacy Policy describes the applicable retention purposes and current operational criteria for Skillsail-controlled copies; it does not replace a verified system and provider retention schedule. Provider-specific retention for subprocessors is governed by the applicable written subprocessor terms and disclosed configuration. Nothing in this row expands Provider's right to retain Customer Personal Data. |
Annex I(C)
| Competent Supervisory Authority | The supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum. |
|---|
Annex II
| Technical and Organizational Security Measures | User identification and authorization process and protection: Passwordless and single sign-on authentication are used where available. Private application and MCP access is authenticated, organization-scoped, and owner-scoped for authoring records. Protecting Customer Personal Data during transmission (in transit): Customer-facing services use HTTPS. Private stored resources use access-controlled object storage and time-limited signed links where downloads are required. Events logging: Error and issue logging designed to support timely detection, investigation, and remediation of problems. Ensuring data minimization: Access checks and response schemas are designed to return only the data needed for the requested operation. File imports are subject to type, size, and organization ownership validation. Ensuring data quality: We provide mechanisms for customers to update applicable user data and respond without undue delay to verified requests or lawful documented controller instructions concerning inaccurate Customer Personal Data. Allowing data portability and erasure: An Organization Account administrator can initiate deletion of that Organization Account through the settings button or by contacting support. An individual User can request deletion of the User's account and associated personal data by contacting support. A data extract can also be requested from customer support. |
|---|---|
| Other Changes to the DPA Standard Terms Additional modifications or customizations | Additional Cover Page terms: (i) the role-specific paragraph concerning Customer Personal Data relating to younger Users; (ii) the role clarification in Annex I(A); (iii) the scope clarification for Controller data in Annex I(B); and (iv) the Approved Subprocessors clarification below. These additions form part of the Cover Page. Except for the selections, processing details, and additional Cover Page terms expressly identified on this page, the DPA Standard Terms are unchanged. |
Acceptance and Provider Details
This DPA consists of this Cover Page and the incorporated DPA Standard Terms. The Cover Page includes the selections, processing details, and additional terms expressly identified above. Except as stated in the Cover Page, the DPA Standard Terms are not modified. For an online self-service Customer, this DPA takes effect only when the Customer, acting through a legally capable and authorized representative, accepts an Agreement that incorporates this version. If Provider and Customer execute a separately signed data processing agreement, that agreement controls for that Customer to the extent it states.
| Provider | Skillsail GmbH |
|---|---|
| Print Name | Nico Schriever |
| Title | CEO |
| Legal Notice Address | Elektrastraße 11 81925 München, Germany |
Subprocessors
The Approved Subprocessors list identifies providers authorized for routes in which Skillsail processes Customer Personal Data on the Customer's behalf. A role label does not alter a recipient's status under applicable law. Skillsail will not use a provider to process Customer Personal Data on the Customer's behalf unless the applicable authorization and written flow-down obligations are in place. A provider used only through an independently selected service is not an Approved Subprocessor solely for that reason; if the same provider also participates in a Skillsail-operated route, its role in that separate route must be identified on our Subprocessors page.
Source and License
This DPA is based on the Common Paper Data Processing Agreement, including the Common Paper DPA Standard Terms Version 1.1, and is used and modified under the Creative Commons Attribution 4.0 International License. It has been customized for Skillsail GmbH. Common Paper is not a party to this DPA.