GDPR & governance

GDPR information for organizations

In an employment context, AISkillProof may process employee personal data. Roles, purposes, access, and retention periods therefore need to be clear before using the platform with real employee data.

Last updated: 5 September 2026

AISkillProof · Validee BV

Planetariumlaan 4 bus 2.5
2610 Wilrijk · Belgium

Company number / VAT: BE 1031 559762

Contact and privacy: info@validee.be

Processing roles

In a typical B2B implementation, the customer organization determines why and how employee data is used for skill development, while AISkillProof processes the agreed data under customer instructions. Exact roles are confirmed in contractual and DPA documentation.

Legal basis and transparency

The customer organization is responsible for an appropriate legal basis and clear information to employees about the purpose, access, and consequences of the measurement. Consent should not be assumed as the default solution where the employment relationship may call free consent into question.

DPA and subprocessors

Processing real employee data should be accompanied by an appropriate data processing agreement and current information about relevant service providers and data flows. That contractual documentation takes precedence over this public summary.

Data minimization

Measure only what is needed for the agreed skill purpose. AISkillProof is not designed to collect private behavior, general productivity, or hidden employee surveillance.

Data subject rights

Users have a privacy center for export and requests involving access, correction, restriction, and deletion. In an employment context, the organization deploying the assessment remains the first point of contact for the concrete processing.

DPIA and high-risk use

Each organization must assess whether its specific use requires a data protection impact assessment or additional employee-representation consultation. Do not use results as a hidden ranking or as the sole basis for an important employment decision.

Security incidents

Technical and organizational security is part of the product architecture. Notification duties, contact points, and incident procedures are further specified in contractual privacy and security arrangements.

This public information describes the current product operation and does not replace a signed customer agreement, data processing agreement, or legal advice.