GDPR & governance
GDPR information for organizations
In an employment context, AISkillProof may process employee personal data. Roles, purposes, access, and retention periods therefore need to be clear before using the platform with real employee data.
Last updated: 5 September 2026
AISkillProof · Validee BV
Planetariumlaan 4 bus 2.5
2610 Wilrijk · Belgium
Company number / VAT: BE 1031 559762
Contact and privacy: info@validee.be
Processing roles
In a typical B2B implementation, the customer organization determines why and how employee data is used for skill development, while AISkillProof processes the agreed data under customer instructions. Exact roles are confirmed in contractual and DPA documentation.
Legal basis and transparency
The customer organization is responsible for an appropriate legal basis and clear information to employees about the purpose, access, and consequences of the measurement. Consent should not be assumed as the default solution where the employment relationship may call free consent into question.
DPA and subprocessors
Processing real employee data should be accompanied by an appropriate data processing agreement and current information about relevant service providers and data flows. That contractual documentation takes precedence over this public summary.
Data minimization
Measure only what is needed for the agreed skill purpose. AISkillProof is not designed to collect private behavior, general productivity, or hidden employee surveillance.
Data subject rights
Users have a privacy center for export and requests involving access, correction, restriction, and deletion. In an employment context, the organization deploying the assessment remains the first point of contact for the concrete processing.
DPIA and high-risk use
Each organization must assess whether its specific use requires a data protection impact assessment or additional employee-representation consultation. Do not use results as a hidden ranking or as the sole basis for an important employment decision.
Security incidents
Technical and organizational security is part of the product architecture. Notification duties, contact points, and incident procedures are further specified in contractual privacy and security arrangements.