Privacy Policy
Last updated: 22 July 2026
Effective date: 22 July 2026
This Privacy Policy explains how ODREN LTD (formerly SKILLFORGE.VIP LTD until 11 May 2026), a private limited company incorporated in England and Wales, company number 15944303, with its registered office at 7 Manchester Square, London, England, W1U 3PQ ("SkillForge", "we", "us", "our"), collects, uses, and shares personal data when you visit skillforge.vip, register a Provider account, use the SkillForge platform, or interact with our marketing and support channels.
We are the data controller for the personal data described in Section 1. Where we process personal data on behalf of a Provider in respect of that Provider's Learners, we act as a processor and the Provider is the controller, as described in Section 3.
At a glance
- We only collect the personal data we need to run the SkillForge platform, deliver Provider accounts, process payments through our Payment Processor, and comply with the law.
- We do not sell personal data. We do not run behavioural advertising on skillforge.vip.
- We rely primarily on contract, legitimate interests, consent (for marketing and non-essential cookies), and legal obligation as our lawful bases.
- We transfer personal data outside the UK, EEA, or Switzerland only under the UK IDTA, the EU Standard Contractual Clauses, and equivalent Swiss safeguards.
- You have full rights under the UK GDPR, EU GDPR, and revised Swiss FADP, including access, rectification, erasure, restriction, portability, objection, and complaint to a supervisory authority.
1. Who we are and our role
1.1 The data controller for personal data collected through our own services (Provider accounts, marketing, support, security logs) is ODREN LTD, trading as SkillForge, contactable at privacy@skillforge.vip.
1.2 For personal data of Learners that we process on behalf of a Provider (course access, exam results, credentials, invoicing data supplied by the Provider), the Provider is the controller and we act as a processor under our Data Processing Agreement.
1.3 We have not appointed a statutory Data Protection Officer at this time, on the basis that our core activities do not require one under Article 37 GDPR. Data protection matters are handled by our Privacy Team, reachable at privacy@skillforge.vip.
1.4 For the purposes of the EU GDPR, our EU representative under Article 27 is being appointed. Once designated, contact details will be published at this URL. In the meantime, EU data subjects may contact us at privacy@skillforge.vip.
1.5 For the purposes of the revised Swiss FADP, our Swiss representative is being appointed where required. Contact details will be published at this URL when confirmed.
2. Personal data we collect
We collect the following categories of personal data:
2.1 Account and identity data
- Full name of the Provider representative and any authorised users
- Email address
- Password (stored as a bcrypt or argon2 hash, never in clear)
- Provider display name, subdomain slug, country, plan
- Optional profile information such as description and logo
2.2 Contract and billing data
- Billing address, VAT number where applicable
- Subscription plan, order history, revenue share calculations
- Invoices issued to and by SkillForge
- Payment status information received from our Payment Processor
2.3 Course and product data on your account
- Courses, lessons, materials, and exams that you or your Teachers publish
- Learner enrolment lists, progress, exam results, and credentials, where processed on your behalf as processor
2.4 Communications data
- Emails, support tickets, chat messages exchanged with SkillForge
- Marketing preferences and consent records
- Meeting notes and demo recordings, where you have consented
2.5 Usage and device data
- IP address, browser, device type, operating system, referrer
- Pages visited, features used, timestamps, error logs
- Session identifiers stored in first-party cookies
2.6 Verification and compliance data
- Where required, sanctions screening results, know-your-customer data, and beneficial ownership information collected for anti-money laundering checks
- Identity documents that Providers upload for the credential signature workflow (where the diploma pathway is used)
We do not intentionally collect special category data (health, biometrics, political opinions, religious beliefs). Please do not upload such data unless it is strictly necessary for a lawful purpose and covered by a specific legal basis, in which case contact us at privacy@skillforge.vip in advance.
3. Where we act as controller versus processor
3.1 Controller. For the personal data listed in Sections 2.1, 2.2, 2.4, 2.5, and 2.6, we determine the purposes and means of processing, and act as controller.
3.2 Processor. For personal data listed in Section 2.3 that relates to a Provider's Learners (enrolments, progress, exam results, credentials, invoicing data supplied by the Provider), we act as processor on behalf of the Provider. Providers enter into a Data Processing Agreement with SkillForge, incorporated into the Terms and Conditions, that sets out the scope of processing, the sub-processors we engage, the security measures we apply, and the assistance we provide to the Provider in fulfilling its obligations.
4. Purposes and legal bases
We process personal data for the following purposes and on the following legal bases:
- Provider account creation, authentication, and account administration. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
- Delivering the Platform, hosting Provider Content, transcoding and streaming video. Legal basis: performance of a contract.
- Processing subscription payments and revenue share, issuing invoices. Legal basis: performance of a contract and compliance with a legal obligation (tax and accounting under UK, Italian, and Swiss law).
- Providing customer support. Legal basis: performance of a contract and legitimate interests in operating the service.
- Fraud prevention, security monitoring, and abuse detection. Legal basis: legitimate interests in operating a secure service and, where applicable, legal obligation.
- Compliance with anti-money laundering, sanctions, and tax obligations. Legal basis: legal obligation.
- Sending service and transactional emails. Legal basis: performance of a contract and legitimate interests.
- Sending marketing emails to Providers and prospects. Legal basis: consent for EU and UK marketing to individuals, and soft opt-in under PECR where we have collected the email in the course of a sale or negotiation and provided a clear opt-out. Marketing consent can be withdrawn at any time.
- Product analytics and improvement. Legal basis: legitimate interests, using aggregated or pseudonymised data wherever possible.
- Legal claims and litigation. Legal basis: legitimate interests and, where applicable, legal obligation.
- Corporate transactions such as merger, acquisition, financing, or asset sale. Legal basis: legitimate interests, subject to appropriate confidentiality safeguards.
Where we rely on legitimate interests, we have carried out a balancing test. You have the right to object at any time by contacting privacy@skillforge.vip.
5. Cookies and similar technologies
5.1 SkillForge uses a small set of first-party cookies described in the Cookie Policy at /cookies.
5.2 Strictly necessary cookies (session cookie sf_session, CSRF token) do not require consent under the ePrivacy Directive.
5.3 Preference cookies (for example, language selection) rely on consent or on legitimate interests where they are strictly required to provide a feature the user has actively requested.
5.4 We do not currently deploy third-party advertising cookies or cross-site tracking cookies. If we introduce analytics, we will collect prior explicit consent through a consent banner and update this Privacy Policy and the Cookie Policy.
6. Who we share personal data with
We share personal data only with:
- Our sub-processors listed in Section 10, under written contracts including Article 28 GDPR clauses and equivalent Swiss and UK obligations
- Our Payment Processor for the purpose of processing subscription fees and Course sales
- Our professional advisers such as lawyers, accountants, auditors, under duties of confidentiality
- Public authorities, courts, or regulators where we are required to do so by law, or where we consider disclosure is necessary to protect our rights or the safety of others
- A successor entity in the event of a merger, acquisition, financing, or asset sale, under appropriate confidentiality obligations
- Providers, in respect of Learner data where we act as processor and only on the Provider's instruction
We do not sell personal data. We do not share personal data with data brokers.
7. International transfers
7.1 Some of our sub-processors are established outside the UK, the European Economic Area, or Switzerland, notably certain infrastructure and video delivery vendors headquartered in the United States.
7.2 For transfers from the UK, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy regulation where one is in place. For transfers from the EEA, we rely on the EU Standard Contractual Clauses (Commission Decision 2021/914, Modules 2 and 3 as applicable) or an adequacy decision. For transfers from Switzerland, we rely on the Swiss annex to the EU SCCs and the safeguards recognised by the Swiss Federal Data Protection and Information Commissioner.
7.3 Where required, we carry out a transfer impact assessment considering the laws and practices of the recipient country, and implement supplementary technical, organisational, and contractual measures.
7.4 A copy of the transfer safeguards is available on request from privacy@skillforge.vip.
8. Retention
We retain personal data only for as long as necessary to fulfil the purposes for which we collected it, including for legal, tax, accounting, or reporting requirements. Indicative retention periods:
| Category | Retention |
|---|---|
| Provider account data | Duration of the account, then 7 years after termination for accounting purposes (UK Companies Act 2006, s.388) |
| Billing, invoicing, and payment records | 10 years after issuance where required by Italian tax law (DPR 600/1973), otherwise 7 years |
| Support tickets and communications | 2 years after resolution |
| Marketing consent records and opt-outs | Until consent withdrawal, then archived for evidentiary purposes for 3 years |
| Security logs, audit trails | 12 months, longer where a security investigation is ongoing |
| Backups | Rolling 30 days, then overwritten |
| Learner data processed as processor | For as long as the Provider instructs, then deleted or returned at the end of the Provider's subscription |
| KYC and AML documents | 5 years from the end of the relationship, in line with UK MLR 2017 |
After the retention period expires, we securely delete or anonymise the data.
9. Security
9.1 We apply technical and organisational measures appropriate to the risk, including:
- Encryption in transit (TLS 1.2 or higher) and at rest for databases and object storage
- Password hashing with bcrypt or argon2, never storing passwords in clear
- Session cookies marked HttpOnly and Secure, with reasonable expiration
- Role-based access control and least-privilege access for our staff
- Multi-factor authentication for administrator access to production systems
- Regular vulnerability scanning and patching
- Centralised logging and monitoring, with alerting on anomalies
- Documented incident response process
- Employee confidentiality obligations and privacy training
9.2 In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority within 72 hours and, where required, inform affected data subjects without undue delay. Providers acting as controllers will be notified without undue delay to enable them to comply with their own notification obligations.
10. Sub-processors
We engage the following categories of sub-processors. A live list including entity names and countries of processing is maintained and updated at least 30 days before adding or replacing a sub-processor.
| Purpose | Category | Examples | Country |
|---|---|---|---|
| Cloud hosting and database | Infrastructure provider | AWS, Vercel | EU and UK regions with US failover |
| Video transcoding, storage, delivery | Video platform | Mux, Cloudflare Stream | EU and US |
| Payments and payouts | Payment Processor | Stripe Payments Europe Limited | Ireland with US processing |
| Email and transactional messaging | Email service | Postmark, Resend, or SendGrid | EU and US |
| Customer support | Helpdesk | Front, HelpScout, or Intercom | EU and US |
| Analytics (only if enabled with consent) | Product analytics | Plausible or PostHog EU | EU |
| E-invoicing | Italian SDI integration | Fatture in Cloud, Aruba | Italy |
| Digital signature for diplomas | E-signature | DocuSign or Yousign | France, Ireland, US |
| Identity verification for diploma pathway | KYC provider | Stripe Identity, Onfido | EU and UK |
Providers acting as controllers give general authorisation for the use of sub-processors, subject to the notice and objection mechanism set out in the Data Processing Agreement.
11. Your rights
Under the UK GDPR, the EU GDPR, and the revised Swiss FADP, you have the following rights:
- Right of access to your personal data and to obtain a copy
- Right of rectification of inaccurate or incomplete data
- Right of erasure (right to be forgotten) in defined circumstances
- Right to restriction of processing in defined circumstances
- Right to data portability, where processing is based on consent or contract and carried out by automated means
- Right to object to processing based on legitimate interests, including profiling, and to object to direct marketing at any time
- Right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to exceptions
- Right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing
- Right to lodge a complaint with a supervisory authority (see Section 15)
To exercise any of these rights, contact privacy@skillforge.vip. We will respond within one month of receipt, extendable by two further months for complex requests. We may need to verify your identity before acting on a request. There is no fee for a request unless it is manifestly unfounded or excessive.
12. Automated decision-making
We do not use automated decision-making that produces legal or similarly significant effects on individuals. Fraud, sanctions, and abuse checks may involve automated processing that flags cases for human review; final decisions are taken by our staff.
13. Children
Our services are intended for professional Providers and their Learners aged 18 and over. We do not knowingly collect personal data from children under 16. If a Learner under 16 uses a Provider Page, the Provider is responsible for obtaining parental consent where required by local law. If you believe a child has provided personal data to us, contact privacy@skillforge.vip and we will delete it.
14. Marketing
14.1 We may send marketing communications to Providers about new features, products, and events, on the basis of consent or the PECR soft opt-in where applicable.
14.2 Every marketing email contains an unsubscribe link. You can also opt out at any time by writing to privacy@skillforge.vip.
14.3 Transactional messages relating to your account, billing, and support are not marketing and cannot be opted out of while the account is active.
15. Complaints and supervisory authorities
If you believe we have not handled your personal data correctly, we encourage you to contact us first at privacy@skillforge.vip. You also have the right to complain to a supervisory authority:
- United Kingdom: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, ico.org.uk
- Italy: Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Roma, gpdp.it
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern, edoeb.admin.ch
- Any other EEA data protection authority in your country of residence, place of work, or place of the alleged infringement
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be published at skillforge.vip/privacy with the "Last updated" date modified accordingly. Material changes will be notified to Providers by email at least 30 days before they take effect.
17. Contact
- Privacy team: privacy@skillforge.vip
- Legal: legal@skillforge.vip
- Postal: ODREN LTD, 7 Manchester Square, London, England, W1U 3PQ, United Kingdom