Privacy Policy

For the MuchSkills platform

Last updated:
22 August 2026

1.  Who we are, and which role we play

This policy explains how MuchSkills handles personal data in the MuchSkills platform: what we collect, why, on what legal basis, how long we keep it, who receives it, and the rights you have. Our website is covered by a separate Website Privacy Policy, and cookies by a separate Cookie Policy.

MuchSkills AB, org. nr. 559282-2521, Andra Långgatan 7A, SE-413 03 Gothenburg, Sweden. Contact us about privacy at privacy@muchskills.com.

We play one of two roles, depending on how you came to use MuchSkills. This matters, because it decides who is responsible for your data.

If… then…
You signed up yourself as a private individual (an End User) MuchSkills is the controller of your data, and this policy applies to you in full.
Your employer or an organisation added you (a Company User), or set up a corporate account Your employer is the controller. MuchSkills processes your data on your employer’s instructions, under a data processing agreement. Your employer’s own privacy notice governs, and you should read it. This policy tells you how the platform works, but your employer, not MuchSkills, decides what data is used and why.

2.  The words we use

Term Definition
End User A private individual who signs up to MuchSkills themselves. End Users can use a free version at no cost.
Owner The person who sets up a corporate account on behalf of an organisation.
Admin A person the organisation authorises to configure and manage its corporate account.
Company User An employee or member invited by an organisation to create a profile in MuchSkills.
Organisation / Client The company or other body that holds a corporate account. Clients can use a free version or a paid version.

3.  What we do with your data, purpose by purpose

We set out each purpose separately, with the data used, where it comes from, the legal basis, how long we keep it, who receives it and whether any transfer outside the EEA arises. Where MuchSkills is a processor for a Client, the legal basis is the Client's to determine; we show the basis that typically applies.

A note on sensitive data. MuchSkills is not intended to hold special categories of personal data, such as data about health, political opinions, religion, trade-union membership, or sexual orientation. Organisations using MuchSkills are asked not to enter such data, and you should not add it to your profile. If you believe sensitive data has been entered, contact privacy@muchskills.com.

3.1  Creating and running your account

What data Your name and email address, your login credentials, and, if you choose to link them, a Google or LinkedIn identifier.
Where it comes from You. Where an Organisation adds you, some of this is provided by your Organisation.
Why we process it (legal basis) For End Users, performance of our agreement with you (Article 6(1)(b)). For Company Users, MuchSkills acts on the Organisation’s instructions as processor; the Organisation relies on its own basis, usually its legitimate interests or its employment relationship with you.
How long we keep it For the life of the account. After the account or the Organisation’s subscription ends, we keep the data for a limited period so it can be reinstated or exported, and then delete it, as described in section 8.
Do you have to provide it Name and email are the minimum needed to create an account. Without them an account cannot be set up.

3.2  Recording your skills, certifications and profile

What data Skills and expertise levels, certifications and their expiry dates, career goals, profile photo, biography, education history, work and project experience, and years of experience.
Where it comes from You. Also your Organisation’s admins or managers; and, where used, an import from an HR system or via our API, or an import you make from a connected service such as LinkedIn (for example work history and education). As we add features, further sources of this kind may be added.
Why we process it (legal basis) For End Users, performance of our agreement with you. For Company Users, the Organisation’s instructions as controller (typically its legitimate interests).
How long we keep it For the life of the account, then per section 8.

3.3  Planning and staffing your workforce

What data Skills, skill levels, certifications and availability, used to support workforce planning and staffing.
Where it comes from The profile data above.
Why we process it (legal basis) For a Client, its legitimate interests in planning and staffing its workforce, on the Client’s instructions. This is decision-support: MuchSkills does not itself make decisions about individuals. Results are presented to a person, who decides; your employer is responsible for keeping a person in the loop.
How long we keep it Generated on demand from current profile data; the underlying profile data is kept per section 3.2.

3.4  Importing and syncing data from other systems

What data Whatever the Organisation chooses to import. It depends on the systems the Organisation connects and how it configures them, so the categories vary from one Organisation to another. It can include profile, skills and certification data, HR data, learning and course records, resourcing data, and credentialing records. We publish the available connectors, and Organisations can also export data through our API to other systems.
Where it comes from The systems the Organisation chooses to connect, on the Organisation’s instruction, together with any files the Organisation provides and any service an individual chooses to connect to their own profile. The types of system vary, and include HR and HRIS platforms, learning management systems, resource and work-management tools, and credentialing systems, among others.
Why we process it (legal basis) The Organisation’s instructions as controller. The Organisation decides what to connect and import; it is responsible for having the authority to connect the source system, for having a lawful basis for the data it brings in, and for giving any notice its own people are due. MuchSkills processes only what the Organisation chooses to import, for the purposes above, and the connected source system remains the Organisation’s own system, not a MuchSkills sub-processor.
How long we keep it As for the profile data it becomes, per section 3.2.

3.5  Communicating with you

What data Your name, email address and the content of the message.
Where it comes from You, and your account.
Why we process it (legal basis) Three kinds of message, with different bases. (a) System messages you cannot unsubscribe from, reminders to keep a profile up to date, notice that a certification is expiring, and similar, are sent because they are necessary for you to do your work within an Organisation (the Organisation’s legitimate interests, or performance of the arrangement). (b) Operational messages you can unsubscribe from, onboarding guidance for users and managers, and product-release notes, are sent on the basis of legitimate interests, and you may opt out at any time. (c) Optional messages, news and articles, event and webinar invitations, and gifts, are sent only with your consent, which you can withdraw at any time.
How long we keep it Contact and preference data for as long as the account exists or until you unsubscribe; message records for a reasonable period for support and record-keeping.

3.6  Providing support

What data Your name, email, the account concerned, and the information you give us about the issue.
Where it comes from You.
Why we process it (legal basis) Performance of the agreement, and our legitimate interest in operating a support service.
How long we keep it For as long as needed to resolve the issue and for a reasonable period afterwards for quality and record-keeping.
Who receives it Our support tooling provider, as a processor (see section 5).

3.7  Linking a Google or LinkedIn account

What data The identifier and the specific profile data you choose to import.
Where it comes from You, and the service you link, at your instruction.
Why we process it (legal basis) Your consent, which you can withdraw at any time by unlinking. This is separate from account creation because it is voluntary.
How long we keep it Until you unlink or delete the account.
Who receives it Where you link a third-party service, that provider is the controller for its own processing; we refer you to that provider for how it handles your data.

3.8  Security, logging and fraud prevention

What data Sign-in timestamps, in-app actions, and error and security logs.
Where it comes from Collected automatically from your use of the service.
Why we process it (legal basis) Our legitimate interest in keeping the platform secure and preventing abuse, and, where applicable, a legal obligation.
How long we keep it Security logs are kept for up to 12 months for security and compliance.

3.9  Improving and developing the service

What data Aggregated and anonymised usage patterns, crash reports, and statistics on which features are used. We also aggregate skills and certification data to produce statistics, for example on which skills are most common, which we may publish in a form from which no individual and no Organisation can be identified.
Where it comes from Collected automatically, then aggregated.
Why we process it (legal basis) Our legitimate interest in understanding and improving the service. Where data is published or used for improvement it is anonymised, so that no individual or Organisation can be identified.
How long we keep it Aggregated and anonymised data is not personal data and is kept without a fixed limit.

3.10  Artificial-intelligence features

What data For most features, skill lists, skill descriptions, development plans, short summaries and similar, and AI-generated indicators about a person, content is minimised before it leaves the platform: direct identifiers are removed and remaining attributes generalised, so that the content sent does not, on its own, identify an individual. Where any doubt remains, we treat the processing as a transfer of personal data and apply the safeguards below. For a feature that generates a document about a named person, such as a curriculum vitae or résumé, the content necessarily includes employment history and other personal data; direct identifiers are removed where possible, but what is processed remains personal data. Where a feature generates a document about a named person, an Organisation may choose to import further information about that person, so the exact data depends on what the Organisation imports.
Where it comes from Your profile and the content you choose to work on. For a feature that generates a document about a named person, also information the Organisation imports to build a profile or résumé, for example to present an employee’s experience when bidding for a project with its own client. The Organisation decides what to import and is responsible for it.
Why we process it (legal basis) Performance of the service and, for a Client, its instructions. Customer content is not used to train third-party AI models. Outputs are suggestions for a person to review, not automated decisions.
How long we keep it AI providers process the content to return a result. MuchSkills contracts for the shortest retention the provider offers and, where available, for zero retention; any retention is limited to abuse-monitoring and reliability, after which the content is deleted. It is not used to train their models. The retention position for each provider is published on the sub-processor list.
Transfers outside the EEA Where a feature sends personal data, principally a feature generating a document about a named person, and the provider processes it outside the EEA, the transfer is made under the European Commission’s Standard Contractual Clauses with supplementary technical measures. Our contractual AI commitments are set out in the AI Addendum, and a plain-English summary is published as Our Approach to AI. The providers used and the processing location of each are published at trust.muchskills.com.

3.11  Meeting legal and accounting obligations

What data Transaction and billing records containing the relevant contact and payment details.
Where it comes from The account and the billing process.
Why we process it (legal basis) Compliance with a legal obligation, including Swedish bookkeeping law.
How long we keep it For the period required by law, for accounting records, seven years.

3.12  A sale or reorganisation of MuchSkills

What data Business records that may include limited data about Organisation representatives.
Where it comes from Our own records.
Why we process it (legal basis) Our legitimate interest, and that of a prospective buyer, in assessing and completing a transaction. If a transaction completes, we will inform affected Organisations.
How long we keep it For the duration of the process; thereafter per the transaction terms.

4.  Who can see your profile inside the platform

Your profile is private from the public unless you choose otherwise. Two things change that, and it is important you understand them:

  • Joining a team or organisation. When you are part of a team or Organisation in MuchSkills, your profile data, including your email, work history, education, skills, certifications and badges, is visible to others in that team and Organisation. This is how the platform does its job.
  • Making your profile public. If your Organisation has enabled it, or if you are an End User with your own account, you may choose to make your profile public, in which case it can be seen by anyone on the internet. This is your choice, and you can change it. Where you are a Company User, your Organisation controls whether this option is available at all, because the profile data in its account is data your Organisation is responsible for.

5.  Who we share data with

We share personal data only as needed to run the service and meet our obligations:

  • Sub-processors, providers that process data on our behalf under a data processing agreement, such as our hosting, database, email-delivery, support and AI providers. The current list, with the role and processing location of each, is published at trust.muchskills.com and updated there. We give advance notice of changes as described in our data processing agreement.
  • Your Organisation, where you are a Company User, within the visibility described in section 4.
  • Services you connect, where you link a third-party service, that provider acts as its own controller.
  • Authorities, where we are legally required to disclose.
  • A buyer, in a sale or reorganisation, as in section 3.12.

We never sell personal data.

6.  Transfers outside the EEA

Customer data is hosted in the European Union. Some processing may take place outside the EEA, principally the AI processing in section 3.10, and certain support and email-delivery providers. Where that happens, we rely on an adequacy decision of the European Commission, or on the Commission's Standard Contractual Clauses together with supplementary technical and organisational measures such as encryption, access controls and data minimisation. We do not rely on any transfer mechanism that has been invalidated. The transfer mechanism for each provider is shown on the sub-processor list, and a copy of the Standard Contractual Clauses is available on request from privacy@muchskills.com.

7.  Your rights

Under the GDPR you have the right to access your data; to have inaccurate data corrected; to have data erased; to restrict processing; to object to processing based on legitimate interests; to data portability; and to withdraw consent at any time where processing is based on consent. Where MuchSkills is the controller, contact privacy@muchskills.com and we will respond within one month; we may ask you to confirm your identity. Where your employer is the controller, we will refer your request to them, or support them in answering it. You also have the right to complain to a supervisory authority, in Sweden, IMY (see section 12).

8.  Retention and deletion

  • Self-service deletion. You can delete your profile in the platform; an Organisation's admins can delete its account. Deletion is normally performed by the Organisation's own authorised administrators. Where an Organisation instructs us in writing to delete data on its behalf, we carry out that instruction under a controlled, authenticated and logged process and confirm completion in writing.
  • After termination. When an account or subscription ends, we keep the data for a limited period so that the account can be reinstated or the data exported, and we then delete it. Deletion is normally completed within around 90 days and is carried out through periodic review rather than as an automatic process on a fixed day. An account that is still being actively used, for example where a user continues to log in, is treated as live and is not deleted. You or your Organisation can ask us to delete sooner, and we will act on that request.
  • Backups. Data removed from production is removed from backups as the backup cycle expires, within the backup retention period.
  • Specific periods apply where stated above, for example 12 months for security logs and seven years for accounting records.

9.  Cookies and tracking in the platform

Inside the logged-in platform we use only cookies that are necessary to sign you in and keep the service working, together with any cookie set by the in-product support tool listed on our sub-processor list. We do not use advertising cookies or cross-site tracking in the product, and we do not use product data for advertising. We keep security and activity logs, including sign-in records, as described in section 3.8. Cookies on our public website are covered by the separate Cookie Policy.

10.  Children

The platform is intended for users aged 18 and over, so we do not knowingly allow under-18s to use it. Separately, organisations must not upload personal data about children through the platform; our acceptable use terms define a child as under 16, in line with the GDPR age of consent. Where MuchSkills is the controller and we learn that an End User is under 18, we close the account and delete the data without undue delay. Where an Organisation is the controller, we tell the Organisation, which decides what happens to the data in its account. If you believe an underage individual has used the platform, please contact us.

11.  Changes to this policy

We may update this policy from time to time. Where a change is material, we announce it by in-product notice or email at least 30 days in advance. The "last updated" date at the top shows the current version.

12.  Contact and supervisory authority

For any privacy question or request, email privacy@muchskills.com, or write to MuchSkills AB, org. nr. 559282-2521, Andra Långgatan 7A, SE-413 03 Gothenburg, Sweden.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY): www.imy.se, +46 8 657 61 00, imy@imy.se.

Contents