Privacy notice
Last updated 4 October 2026.
1. Who this notice covers and who we are
AkolagTech (“AkolagTech”, “we”, “us”) operates Skillermatic, a multi-tenant learning and compliance-training platform used by companies, small businesses, and individuals. This notice explains what personal data Skillermatic collects, why, how long we keep it, and the rights available to you under the laws that apply to you - including the EU/UK General Data Protection Regulation (GDPR/UK GDPR), the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Commission’s General Application and Implementation Directive 2025 (NDPA/GAID), and US state privacy laws such as the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
If you use Skillermatic through your employer, please also read “Controller and processor” below - your employer controls some of these choices, not us.
2. Controller and processor - who decides what happens to your data
Two different relationships exist on Skillermatic, with different answers to “who is responsible for my data”:
- Company accounts. When a company signs up its staff (a “Customer”), the Customer is the data controller for its employees’ and learners’ personal data (name, work email, course activity, quiz results, and so on), and AkolagTech is the data processor, acting only on the Customer’s documented instructions under the Data Processing Agreement (see Data Processing Agreement). If you are a learner inside a company account, your employer - not AkolagTech - decides why your data is processed, and is usually the right first point of contact for a request about your data, though you are always welcome to contact us directly and we will help route your request.
- Individual accounts. When you sign up for yourself, with no company involved, AkolagTech is the data controller.
- Our own marketing, website, and billing relationship with whoever pays us: AkolagTech is the data controller.
3. What data we collect and why
Skillermatic’s sign-in is handled by Amazon Cognito, which holds only your email address and an internal account identifier - nothing else. Everything else lives in a single encrypted database, scoped to your company’s workspace (“tenant”). We collect:
- Account and identity data: name, work email address, department, job role, and your company (if any).
- Training data: which courses you are enrolled in, lesson progress, quiz attempts and scores, assignment due dates, and certificates issued to you. Certificates carry a public verification page - see “Certificate verification” below.
- Phishing simulation data (company accounts only, where the feature is enabled): whether a simulated phishing email was opened, a link in it was clicked, or it was reported as suspicious. We never ask for, and never collect, your real password or any other credential during a simulation - it only ever measures a click or a report action, never a login attempt.
- Audit and security logs: a record of key actions taken in your account (for example, who assigned what course to whom), kept for accountability and dispute resolution.
- Technical and server logs: standard web request logs generated by our infrastructure (Amazon CloudFront and AWS Lambda), such as IP address, browser type, and timestamps, used only for security, troubleshooting, and keeping the service running.
- Payment data (only if your company turns on paid billing): handled directly by our payment processors, Paystack and/or Stripe - we do not store your card number.
- Anti-bot verification: when you sign up, Cloudflare Turnstile checks that you are a real person, not an automated script, before your account is created. Turnstile never receives your password.
We do not use advertising trackers, third-party ad pixels, or cross-site behavioral tracking of any kind. See “Cookies” below.
4. Lawful bases (GDPR/UK GDPR)
Where GDPR or UK GDPR applies, we rely on the following lawful bases, as applicable:
- Contract (Art. 6(1)(b)): to create your account, run the courses you are enrolled in, score your quizzes, and issue your certificates.
- Legitimate interests (Art. 6(1)(f)): to keep Skillermatic secure (audit logs, server logs, anti-bot checks), to run phishing-awareness simulations your employer has set up against its own staff, and to improve the service - balanced against your rights, and you can object as described below.
- Legal obligation (Art. 6(1)(c)): where we must keep certain records (for example, billing and financial records) for a period required by law.
- Consent (Art. 6(1)(a)): where we ask for it specifically - for example, the optional monthly “tip of the month” email a company can opt into.
5. Nigeria Data Protection Act 2023 and GAID 2025
For users and companies based in Nigeria, the Nigeria Data Protection Act 2023 (“NDPA”) and the Nigeria Data Protection Commission’s General Application and Implementation Directive 2025 (“GAID”) apply:
- We process personal data on one of the lawful bases the NDPA recognizes - most commonly performance of a contract (running your training account) or legitimate interest (security, fraud prevention, and phishing-awareness testing a company runs against its own staff), and consent where we specifically ask for it.
- Where a company is the data controller for its own staff’s data, that company carries the NDPA obligations that attach to a data controller (for example, having a lawful basis for uploading staff data, and telling staff about the training program); AkolagTech acts as its data processor under the DPA.
- You have the rights listed in “Your rights” below, and you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your rights under the NDPA have been violated.
- Cross-border transfer. Skillermatic’s infrastructure runs in AWS’s US East (N. Virginia) region. Where a Nigerian data subject’s personal data is transferred outside Nigeria, we rely on the NDPA’s permitted transfer mechanisms - including that the recipient is subject to a law, contract, or certification mechanism that provides an adequate level of protection, and/or that the transfer is necessary to perform the contract between you (or your employer) and us. AWS maintains independently audited security and compliance certifications for the infrastructure underlying this processing.
6. UK/EU international transfers
Because our infrastructure runs in AWS’s US East region, personal data of EU/UK data subjects is transferred outside the EU/UK. We rely on the European Commission’s Standard Contractual Clauses (and, for the UK, the UK International Data Transfer Addendum), incorporated into our agreements with AWS and our other infrastructure providers, as the transfer mechanism - together with the technical and organizational measures described in our Data Processing Agreement (Annex 2).
AkolagTech has not appointed a representative in the EU or the UK under Art. 27 GDPR / Art. 27 UK GDPR at this time. If you are in the EU or UK and have a question about our processing of your data, please contact us at privacy@skillermatic.com.
7. US privacy rights (CCPA/CPRA and other state laws)
If you are a California resident, or a resident of another US state with a comparable privacy law, this section is our notice at collection:
- Categories of personal information we collect: identifiers (name, email), professional/employment information (job role, department, company), and other training-related records (course progress, quiz results, certificates) - as described in “What data we collect and why” above.
- We collect this information to provide Skillermatic to you or your employer, to keep it secure, and for the other purposes described in this notice.
- We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months.
- We do not use or disclose sensitive personal information for purposes beyond what is necessary to provide the service.
- You have the right to know what personal information we hold about you, to request its deletion, to correct inaccurate information, and not to be discriminated against for exercising these rights. See “How to exercise your rights” below. If you are an employee of a company customer, your employer may need to be involved in fulfilling certain requests, since it controls your account.
8. Your rights
Subject to the exceptions and conditions under the law that covers you, you may have the right to:
- Know what personal data we hold about you and why.
- Access a copy of your personal data.
- Correct inaccurate or incomplete data (for example, the name printed on your certificates).
- Request deletion of your personal data.
- Restrict or object to certain processing.
- Receive your data in a portable format, where applicable.
- Withdraw consent at any time, where processing is based on consent, without affecting processing already carried out.
- Lodge a complaint with your supervisory authority: in the EU, your national data protection authority; in the UK, the Information Commissioner’s Office (ICO); in Nigeria, the Nigeria Data Protection Commission (NDPC); in the US, your state Attorney General or applicable state privacy agency.
If you are a learner inside a company account, some requests are best directed to your employer first, since they control your workspace - but you are always welcome to contact us directly and we will help route your request.
9. How to exercise your rights
Email privacy@skillermatic.com with your name, the company workspace you belong to (if any), and what you are asking for. We will verify your identity before acting on a request and respond within the time required by the law that applies to you (for example, 30 days under GDPR, and the equivalent periods under the NDPA and applicable US state laws, each extendable in limited circumstances as those laws allow).
10. Certificate verification
When you complete a course, Skillermatic issues a certificate with a public verification link. Anyone with that link can see the learner’s name, the course title, the issuing company’s name, and the issue/expiry dates - and nothing else: no password, no quiz answers, no account identifier. This is by design, so an employer or auditor can confirm a certificate is genuine without needing access to your account.
11. How long we keep your data
We keep your personal data for as long as your account is active, plus the retention period your company (or you, for an individual account) has configured. When an account is closed, we delete the associated personal data within 30 days, except for records we are legally required to keep for longer (for example, billing and tax records). Our database uses point-in-time recovery, which can restore data from any point in the preceding 35 days - so a deletion can take up to 35 days to fully clear out of backups, even though it is removed from the live system immediately.
12. Security
We use encryption in transit (TLS) and encryption at rest (AWS-managed encryption on our database and file storage) everywhere personal data is stored. Every company’s data is logically isolated from every other company’s data at the application layer, enforced on every request - a request can never read or write another company’s records, even by guessing an identifier. Access to the underlying systems is limited on a least-privilege basis, and administrator accounts can use multi-factor authentication (MFA). No method of transmission or storage is 100% secure, but we design and operate Skillermatic to a security-by-default standard - see our Data Processing Agreement, Annex 2, for the full list of technical and organizational measures.
13. Sub-processors
We use the following sub-processors to provide Skillermatic:
- Amazon Web Services (AWS) - cloud hosting, database, file storage, authentication, and email delivery (United States).
- Cloudflare - bot/abuse protection on signup (Turnstile) (global network).
- Paystack and Stripe - payment processing, only if and when your company or account turns on paid billing (Nigeria / global).
We give at least 30 days’ notice before adding or replacing a sub-processor that will process company customers’ personal data - see the Data Processing Agreement for the mechanism.
14. Children
Skillermatic is a workplace and professional-skills training platform. It is not directed at children, and we do not knowingly collect personal data from anyone under the age of 16.
15. Changes to this notice
We may update this notice from time to time. If we make a material change, we will update the “Last updated” date on this page and, where appropriate, let company administrators know.
16. Contact us
Email: privacy@skillermatic.com. Skillermatic is operated by AkolagTech.
17. Cookies
Skillermatic uses only strictly necessary storage, never optional tracking cookies:
- Authentication session storage - used only to keep you signed in during your visit and to recognize your browser between page loads. Without it, you cannot stay signed in.
- No advertising cookies. No third-party ad trackers. No cross-site behavioral tracking of any kind.
- Because this storage is strictly necessary for the service to function, we do not show a cookie-consent banner asking you to opt in - this is consistent with the “strictly necessary” exemption under the EU ePrivacy rules and equivalent guidance under the NDPA/GAID.