Legal
Privacy policy
How Cloudskill collects, uses, and protects your information.
Summary
- We collect the minimum needed to run the service: account info, member emails, the skills you upload, and timestamps showing when each personal URL is fetched.
- We do not have access to your team members' Claude conversations.
- We do not sell your data, ever.
- Customer data is held in the EU. US data residency is coming soon.
- You can export and delete your data at any time. Under UK and EU GDPR, you have the right to access, correct, delete, and port your data, and to lodge a complaint with the ICO.
- For privacy queries, email privacy@cloudskill.com.
Who we are
Cloudskill is operated by LIONS, TYGAS AND BAIRS LTD, a company registered in England and Wales (company number 15459732). Our registered office is at Mulberry Cottage, Mulberry Close, Horsham, West Sussex, United Kingdom, RH12 2NH. References in this policy to "we", "us", and "our" refer to this entity. References to "you" refer to the individual or organisation using Cloudskill.
For privacy-related queries, contact privacy@cloudskill.com.
Data controller and data processor
Where Cloudskill processes data about an organisation's members at that organisation's instruction (such as the skills, member emails, and assignments your admins upload), the customer organisation is the data controller and Cloudskill acts as a data processor on its behalf. Where Cloudskill processes data for its own purposes (account creation, billing, security monitoring, support correspondence), Cloudskill is the data controller.
What data we collect
We collect the following categories of personal data:
- Account data: organisation name, billing email, member emails, names if provided
- Authentication data: per-user secret tokens (embedded in personal URLs) used to authenticate Cloudskill requests
- Skill content: markdown files uploaded to your organisation's catalogue (these may contain text written by your employees)
- Usage data: timestamps of when each personal URL is fetched, daily invocation counts, audit log entries (which admin made which change to skills, assignments, or members at what time)
- Billing data: when billing is active, payment processing is handled by a PCI DSS-compliant third-party. We receive billing events (subscription created, cancelled, renewed) but do not store payment card details
What data we do not collect
We do not collect or have access to the conversations your team members have with Claude. Cloudskill returns the list of skills assigned to a user at chat-start; what happens inside the chat is between the user and Anthropic.
We do not use behavioural tracking, advertising cookies, or analytics that profile individual users.
How we use it
We use your data to:
- Provide the Cloudskill service (authenticating requests, returning assignment lists, hosting your skill catalogue)
- Process billing through our payment provider
- Send transactional emails (welcome emails, billing notifications, security alerts)
- Respond to support enquiries
- Diagnose and fix technical problems
- Comply with legal obligations
We do not sell your data to anyone, ever.
Legal basis (UK / EU GDPR)
Our legal bases for processing personal data are:
- Contract: most processing is necessary to provide the service you've contracted with us
- Legitimate interests: technical operations, security monitoring, fraud prevention
- Legal obligation: tax, financial records, lawful requests from authorities
- Consent: where required (e.g. marketing emails, which we currently don't send)
Sub-processors
We share data with third-party services as necessary to operate the platform. The complete list is on our security page.
Where data is stored
Our primary database is hosted in the EU region. US data residency is coming soon. Data may be transferred outside the EU/UK only via mechanisms that comply with applicable data protection law (Standard Contractual Clauses, adequacy decisions, etc.).
How long we keep it
Account and skill data: retained for the lifetime of your subscription. Deleted within 30 days of account deletion (with backups removed within an additional 30 days).
Audit logs: retained for the lifetime of your subscription, deleted alongside other account data on termination.
Billing records: retained for at least seven years for tax compliance, regardless of subscription status.
Your rights
Under UK and EU GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (subject to legitimate retention obligations like billing records)
- Request a copy of your data in a portable format
- Object to processing based on legitimate interests
- Withdraw consent where processing is based on consent
- Lodge a complaint with the UK Information Commissioner's Office or your national supervisory authority
To exercise any of these rights, email privacy@cloudskill.com. We respond within 30 days. Before responding, we may need to verify your identity by asking you to confirm details we already hold (typically the email address associated with your account).
To withdraw consent where processing is based on consent, email privacy@cloudskill.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Children
Cloudskill is not intended for use by individuals under 18. We do not knowingly collect data from children. If you believe we have collected such data inadvertently, please contact us so we can delete it.
Changes to this policy
We update this policy when our practices change. Material changes are notified by email at least 30 days before they take effect. The "last updated" date below indicates the most recent revision.
Contact
LIONS, TYGAS AND BAIRS LTD
Company number 15459732, registered in England and Wales
Registered office: Mulberry Cottage, Mulberry Close, Horsham, West Sussex, United Kingdom, RH12 2NH
Privacy queries: privacy@cloudskill.com
General: hello@cloudskill.com