This Privacy Policy explains how Droidtech 42 AI Labs AB ("Droidtech", "we", "us", "our") processes personal data when you visit our website or use our SkillSea service.
1. Data Controller
The data controller is:
Droidtech 42 AI Labs AB
Organisation number: 559534-0745
VAT number: SE559534074501
Address: Co. Sandberg, Dannemoragatan 4, 4 tr, 113 44 Stockholm, Sweden
Website: https://www.skillsea.ai
Email: info@skillsea.ai
Phone: +46 (0)76 229 81255
Data protection contact person: Lee Sandberg
Email: support@skillsea.ai
2. What Personal Data We Collect
2.1 When you create an account
When you register for SkillSea, we collect:
- Name
- Email address
- Authentication credentials (OAuth tokens if using SSO)
- Profile information you choose to provide
2.2 When you purchase a subscription
When you upgrade to a paid plan (payments handled by Stripe), we collect:
- Billing address
- Company name and VAT number (if provided)
- Purchase details (product, price, date, currency)
Payment card details are processed directly by Stripe; we do not see or store full card details.
2.3 When you use the service
During your use of SkillSea, we process:
- Skills you create, fork, or modify
- Search queries for skill discovery
- Usage analytics (feature usage, skill activations)
- API requests and MCP server interactions
2.4 When you contact our support
When you contact us at support@skillsea.ai, we process:
- Your email address and name (if provided)
- Content of your message and attachments
- Technical information you choose to share
2.5 Website visits and cookies
Our web hosting and security providers may collect standard server logs (IP address, browser type, date and time, etc.). If we use analytics or other non-essential cookies, we will ask for your consent via a cookie banner. For details, see our Cookie Policy.
3. Skill Data and Neo4j Storage
Skills you create are stored in our Neo4j database infrastructure. This includes:
- Skill content and metadata
- Relationships between skills (dependencies, tags, subjects)
- Embedding vectors for semantic search
- Access permissions and ownership information
Team and organization skills are shared according to your configured permissions. Skills submitted to the community library become publicly accessible.
4. Purposes and Legal Bases of Processing
We process personal data only when we have a legal basis under the GDPR.
- Account management and service provision
To create and manage your account, provide access to skills, and deliver the service.
Legal basis: performance of a contract (GDPR Art. 6(1)(b)). - Subscription and billing
To process payments and manage subscriptions.
Legal basis: performance of a contract (GDPR Art. 6(1)(b)). - Customer support
To respond to your questions and assist with technical issues.
Legal basis: legitimate interest (Art. 6(1)(f)). - Service improvement
To analyze usage patterns and improve the service.
Legal basis: legitimate interest (Art. 6(1)(f)). - Accounting and tax
To comply with Swedish accounting and tax laws.
Legal basis: legal obligation (Art. 6(1)(c)).
5. Data Storage, Location and Security
5.1 Locations and providers
- Neo4j Aura – Skill database (managed Neo4j cloud)
- Hetzner (Germany) – Web application hosting
- Stripe – Payment processing
- Resend – Email delivery
- Google Workspace – Email and internal documentation
We use technical and organisational measures to protect your data, including encryption in transit, access controls, and security monitoring.
6. Data Retention
We retain personal data only for as long as necessary for the purposes described above or as required by law.
- Account data: Kept for the duration of your account plus 30 days after deletion.
- Skill data: Kept until you delete them or close your account. Community skills remain available.
- Billing and accounting data: Kept for 7 years in accordance with Swedish accounting rules.
- Support communications: Kept for up to 24 months after the last contact.
7. Sharing of Personal Data
We do not sell your personal data. We share data only when necessary and only with:
- Payment provider (Stripe) to process your purchase
- Infrastructure providers (Neo4j, Hetzner) to host services
- Email providers (Resend, Google Workspace) to send communications
- Professional advisors (e.g. accountants) where legally required
- Authorities or courts when required by law
8. International Data Transfers
We aim to keep data within the EU/EEA. Where data is transferred outside the EU/EEA by our processors, such transfers are protected by appropriate safeguards (such as Standard Contractual Clauses) and additional measures where required.
9. Your Rights Under GDPR
You have the following rights, subject to legal limitations:
- Right of access – to know what data we process about you.
- Right to rectification – to correct inaccurate data.
- Right to erasure – to request deletion of your data, where applicable.
- Right to restriction of processing.
- Right to data portability, where technically feasible.
- Right to object to processing based on legitimate interest.
- Right to withdraw consent at any time, where processing is based on consent.
To exercise your rights, contact us at support@skillsea.ai. We may need to verify your identity before acting on your request.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority in the EU/EEA.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be available on our website. Material changes will be communicated where appropriate.
11. Contact
For questions about this Privacy Policy or our data protection practices, please contact:
Droidtech 42 AI Labs AB
Co. Sandberg, Dannemoragatan 4, 4 tr
113 44 Stockholm, Sweden
Email: info@skillsea.ai
Support: support@skillsea.ai
Phone: +46 (0)76 229 81255