Data Privacy & GDPR
How LucentSkill handles consent, data portability, erasure, and retention for personal data, and where the records of processing live.
What it is
LucentSkill treats organizations as the controller of their members' personal data and processes that data on their behalf, while acting as the controller for data it collects directly from people without an organization (the public signup path). This split shapes every privacy feature below, and every one is designed to stay neutral across both roles.
Use
- Consent is explicit and recorded. Creating an account requires an affirmative consent checkbox for the Privacy Policy and Terms, and each grant is written to an immutable consent ledger with the document version in force at the time.
- Withdraw consent any time. A withdrawal is appended to the same ledger - it is as easy to revoke as it was to give, and never deletes the historical grant record.
- Export your data. The self-service export returns a portable JSON snapshot of your profile, consent history, survey responses, learning progress, submissions, and assignments. See Data Export.
- Delete your account. Account deletion removes every trace of your personal data, including encrypted columns, consent records, survey responses, progress, roster linkage, and auth events. See Data Retention.
Transparency
The Privacy Policy and Terms of Service describe what is collected, why it is used, how long it is kept, and your rights in plain language. Both are linked from the account signup flow and from the site footer.
A full record of processing (data categories, purposes, retention, sub-processors, and the DPA pointer) is published in the Data Retention doc, so anyone can see the controller-to-processor relationship at a glance.
Security
- Consent records are append-only and never edited, so the consent chain is provable under audit.
- Data export returns plaintext to the subject only; the admin path requires an owner/admin session in the same organization plus a fresh MFA step-up, and is strictly tenant-scoped.
- Erasure runs in a single transaction and closes gaps foreign-key cascades miss (auth events, roster entries, course shares, blog subscriptions, and denormalized decision-log names).
- Encrypted columns are decrypted only at export time, and only for the subject the export is authorized to receive.