CompetenceCore

Privacy Policy

This privacy policy describes which personal data CompetenceCore processes, for what purpose, and on what legal basis. It is addressed to employees and administrators of the organization using the platform.

Notice: Template for review

This page is a template and does not constitute legal advice. It must be reviewed, completed, and approved by your organization's Data Protection Officer (DPO) before going live, in particular the details on the responsible entity, processors, and contact information.

Responsible entity

The entity responsible for data processing within the meaning of the GDPR is: [Your Company], [Address], represented by [Name/Role]. These details must be completed by your organization.

What data we process

When you use CompetenceCore, we process the following categories of personal data:

  • Account data: email address and name, used for sign-in and identification within your organization.
  • Competency data: skills and self-assessed ratings that you maintain yourself (and, where applicable, ratings from others).
  • Optional profile data: additional information you voluntarily add to your profile (e.g. projects, evidence).

Processors & service providers

To operate CompetenceCore, we use the following service providers, each covered by a data processing agreement (existing or to be concluded):

  • Supabase, database hosting and authentication, data center in the EU (Frankfurt).
  • Vercel, application hosting and delivery via a content delivery network (CDN).
  • Google Analytics, usage analytics, activated only after you consent via the cookie banner.

Cookies & consent

On your first visit, we show a cookie banner where you can accept or decline the use of analytics cookies (Google Analytics). Strictly necessary cookies (e.g. for sign-in) are set regardless of this consent. Analytics cookies are only activated after you consent and can be withdrawn at any time by clearing your browser data for this site.

Your rights

Under the GDPR, you have in particular the following rights:

  • Access to the data stored about you (Art. 15 GDPR).
  • Rectification of inaccurate data (Art. 16 GDPR).
  • Erasure of your data, unless statutory retention obligations apply (Art. 17 GDPR).
  • Portability of your data in a structured, commonly used format (Art. 20 GDPR).

To exercise these rights, please contact the address below or your organization's administration.

Contact

For questions about data protection, please contact: [insert your organization's contact email].

Last updated on September 11, 2026