Privacy PolicyHow Skill Accolades handles personal data, assessments, credentials, reports, wallets, and AI-assisted services
Skill Accolades Platform Privacy Policy
Version: 2.3
Effective date: 28 July 2026
Primary privacy contact: privacy@skillaccolades.com
Escalations and formal legal notices: bc@coincentives.io
Version: 2.3
Effective date: 28 July 2026
1. Purpose and scope
This Privacy Policy explains how Coincentives Labs collects, uses, stores, shares, protects, and otherwise processes personal data in connection with the Skill Accolades Platform and related services.
The Platform includes skillaccolades.com, affiliated websites and applications, Skill Accolades credentials and verification services, the AI Fluency Accelerator (AFA) service family, including AI Fluency Accelerator - Assessment (AFAA) and AI Fluency Accelerator - Coach (AFAC), other approved Custom GPTs or AI interfaces, chat-client integrations, collaboration-platform integrations, application programming interfaces (APIs), payment and checkout functions, certificates, assessment reports, profiles, platform-generated or connected wallets, smart-contract interactions, and related support and communications. This includes services accessed through ChatGPT, Microsoft Teams, website-embedded assistants, approved third-party chat clients, enterprise integrations, and other environments that connect to the AFA or Skill Accolades backend.
This Policy applies when Coincentives Labs acts as a data controller. Where a Customer or Sponsor determines why and how personal data is processed, that Customer or Sponsor may be the controller and Coincentives Labs may act as its processor. Section 4 explains these roles.
This Policy should be read together with the Platform Terms and Conditions, the Digital Credential and Blockchain Terms, any assessment-specific notice, any Customer or Sponsor notice, and the privacy terms of third-party environments used to access the Platform, including OpenAI's ChatGPT and Microsoft Teams where applicable.
2. Who we are
The data controller for the Platform is Coincentives Labs, a Danish sole proprietorship registered in the Danish Central Business Register (CVR) under number 39388871, trading through the Skill Accolades Platform.
Registered address: Frederikskaj 2M, 1. tv, 2450 Copenhagen SV, Denmark.
Primary privacy contact: privacy@skillaccolades.com.
Escalations and formal legal notices: bc@coincentives.io.
If a data protection officer is appointed, the officer's contact details will be published here.
3. Key definitions
AFA means AI Fluency Accelerator, the broader family of Skill Accolades assessment, coaching, backend, and related AI fluency services, including AFAA and AFAC.
AFAC means AI Fluency Accelerator - Coach.
AFAA means AI Fluency Accelerator - Assessment.
AI means artificial intelligence.
API means application programming interface.
Custom GPT means a customised AI assistant or interface made available through ChatGPT or a similar AI environment.
EEA means the European Economic Area.
GPT means a generative AI assistant, including a Custom GPT, where the term is used in this Policy.
IP address means Internet Protocol address.
IPFS means the InterPlanetary File System or a similar content-addressed storage network, where used.
SBT means Soulbound Token, a blockchain-based credential designed to be non-transferable or restricted in transferability.
Assessment Data means information used, generated, or inferred during an assessment or coaching interaction, including the assessment brief, task context, user responses, structured session summaries, behavioural and outcome indicators, assessment scores, narratives, reports, and credential eligibility information.
Certificate Display Data means optional personal details, such as first name, last name, title, prefix, or display name, that a user chooses to provide for inclusion on a certificate, report, or other downloadable artifact. Certificate Display Data is normally stored off-chain and used to generate, display, verify, support, or reissue the requested artifact, unless the user chooses to publish or share it. It does not become Public Credential Data merely because it appears in a user-requested Portable Document Format (PDF) file, certificate, report, or downloadable artifact.
Credential means a Skill Accolades proof-of-skill or performance credential, whether allocated off-chain, represented by a certificate or report, or minted as a blockchain-based Soulbound Token (SBT).
Customer means any individual, organisation, or legal entity that purchases, requests, accesses, funds, administers, or receives a Platform service, including an assessment, coaching session, credential, certificate, report, wallet, or related service.
Sponsor means a person or organisation, other than the assessed user acting only for themselves, that requests, funds, administers, assigns, or receives an assessment or credential service for another person or group. This may include an employer, recruiter, headhunter, learning provider, assessment provider, manager, educational institution, enterprise customer, or other organisation.
Personal Data means information relating to an identified or identifiable natural person. Pseudonymous information, including a wallet address or a hashed identifier, may still be Personal Data where it can be linked to a person.
Platform means the websites, Custom GPTs, AI interfaces, chat-client integrations, collaboration-platform integrations, applications, APIs, backend systems, credentials, certificates, reports, wallets, blockchain functions, and related services operated, controlled, connected to, or made available by Coincentives Labs. This includes services accessed through skillaccolades.com, ChatGPT, Microsoft Teams, website-embedded assistants, approved third-party chat clients, enterprise integrations, and other environments that connect to the AFA or Skill Accolades backend.
Public Credential Data means the limited information made publicly verifiable when a user chooses to mint, publish, or share a credential, such as credential type, issuer, wallet address, token identifier, transaction hash, issue and expiry dates, status, and verification hash. Public Credential Data does not include the user's email address, assessment brief, detailed assessment evidence, private report content, or personal name by default. A name supplied for a user-requested PDF certificate or report is treated as Certificate Display Data unless the user or an authorised workflow chooses to publish or share it.
User-Published Credential Data means credential, certificate, report, profile, or verification information that the user chooses to download, publish, share, send to a third party, display on a public profile, or otherwise make available outside the Platform. Once shared by the user or by a third party acting on the user's instruction, it may be copied, stored, forwarded, indexed, or republished outside Coincentives Labs' control.
Verification or Verifiable means that a verifier may be able to check certain record information, such as issuer, credential type, wallet address, token identifier, transaction hash, issue date, expiry date, status, verification hash, or whether the record has been altered, expired, replaced, or revoked. Verification does not mean that Coincentives Labs guarantees the truth, completeness, future accuracy, employment relevance, or suitability of the underlying assessment or credential. Unless expressly stated in writing, Skill Accolades credentials are not represented as World Wide Web Consortium (W3C) Verifiable Credentials or as compliant with any particular third-party credential standard.
Personal AI Profile or Surrogate Profile means a user-specific memory, preference, capability, or behavioural profile that may be used by a future personal assistant, intelligent surrogate, or delegated AI service. Such a profile is different from a standard AFAA assessment record.
4. Our role: controller, processor, or separate provider
4.1 Direct-to-user services. When you independently create an account, verify your identity, take an assessment, request a certificate or report, mint a credential, contact support, or otherwise use the Platform directly, Coincentives Labs generally acts as the controller for the personal data needed to provide and protect those services.
4.2 Sponsored or organisational assessments. When a Customer or Sponsor selects participants, defines the assessment purpose, provides candidate or employee data, or decides how results will be used, that organisation may be the controller and Coincentives Labs may act as its processor under a data processing agreement. In that case, the Customer or Sponsor is primarily responsible for providing the lawful basis, required notices, access to human review, and instructions concerning retention, disclosure, and deletion.
4.3 Mixed roles. Coincentives Labs may remain an independent controller for limited processing necessary to secure the Platform, prevent fraud, maintain credential integrity, comply with law, manage payments, defend legal claims, and operate its own user accounts, even where it otherwise acts as a processor for a Customer or Sponsor.
4.4 Third-party platforms. OpenAI, payment processors, blockchain networks, wallet providers, and other third-party services may act as separate controllers or processors for information they receive. Their own privacy terms apply to their processing.
5. Personal data we collect
Depending on how you use the Platform, we may collect the following categories.
5.1 Identity and account data: email address, name, title or prefix, organisation, role, account identifiers, verification status, preferred language, connected account details, and other information you provide when creating or managing an account.
5.2 Verification and security data: verification codes, code expiry data, request timestamps, failed attempts, hashed identity keys, session identifiers, session status and expiry, authentication events, fraud and abuse indicators, access logs, and security investigation records.
5.3 Assessment brief and context data: assessment scenario, specific, measurable, achievable, relevant, and time-bound (SMART) or comparable assessment goal, problem statement, expected artifact, timebox, success criteria, audience, basis, current or target role, job description, role or job context, assessment constraints, user-declared constraints, externally specified assessment details, template and cohort identifiers, and goal version.
5.4 Interaction and assessment data: information you submit during an assessment or coaching session; structured summaries of the interaction; prompts or excerpts transmitted through Platform Actions; generated alternatives, corrections, decisions, artifacts, and outputs; protocol-completion and deviation records; assistance level; internal behavioural and outcome indicators; assessment scores; eligibility status; assessment narratives; strengths, outcomes, development points; and quality, anti-gaming, or integrity signals.
5.5 Credential, certificate, report, and profile data: badge or credential type, status, allocation and expiry dates, unique hashes, source session and log references, credential metadata, verification links, Certificate Display Data, assessment report content, public profile settings, and records of revocation, expiry, replacement, or correction.
5.6 Wallet and blockchain data: connected or platform-generated wallet address, encrypted wallet credentials or key material where platform-generated wallets are offered, smart-contract address, token identifiers, transaction hashes, blockchain status, minting attempts, gas and fee data, network errors, and public on-chain records.
5.7 Payment and transaction data: checkout session identifiers, product and price, currency, payment status, payment dates, tax or location indicators, refund or dispute information, and limited payment metadata. Full payment-card details are normally processed by the payment provider and are not stored by Coincentives Labs.
5.8 Technical and usage data: IP address, approximate location derived from IP, browser and device type, operating system, referring page, pages and features used, timestamps, error logs, cookies, analytics identifiers, and performance or diagnostic data.
5.9 Communications and support data: messages, support requests, feedback, complaints, appeals, identity-verification material used to handle rights requests, and records of communications with us.
5.10 Customer and business data: Customer contact details, billing and contract data, administrator details, seat or cohort information, organisation identifiers, and instructions or data supplied by a Customer or Sponsor.
5.11 Data from third parties: information supplied by a Customer or Sponsor, an issuer, a connected wallet provider, payment processor, identity or fraud-prevention provider, blockchain network, or other integration. We may also receive information when you ask a third party to share it with us.
5.12 Research, consent, and future-service preference data: records of privacy notice versions, consent choices, withdrawal records, purpose tags, research-use preferences, opt-in or opt-out settings, permitted data sources for future services, restrictions on sponsored or confidential data, and records needed to honour those choices.
6. Data you should not submit
The Platform is not designed to collect special-category personal data, biometric data, medical records, criminal-conviction data, government identifiers, financial account credentials, confidential third-party personal data, or trade secrets unless the relevant workflow expressly requests them and provides an appropriate notice and lawful basis.
Do not submit information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, health information, sex life, or sexual orientation unless strictly necessary and expressly authorised. AFAA does not use facial analysis, voice analysis, emotion recognition, or biometric identification for assessment scoring.
Assessment questions are not intended to solicit protected characteristics. If you voluntarily include sensitive data, we may restrict access, remove it, redact it, or process it only where necessary to provide the requested service, comply with law, protect legal claims, or act on valid Customer instructions. Where required, we will seek explicit consent or another lawful basis.
If you submit information about another person, you are responsible for having authority and a lawful basis to do so, providing any required notice, and limiting the information to what is necessary. Do not upload confidential employer, client, candidate, colleague, or customer data unless you are authorised to use it for the assessment.
7. How we collect personal data
We collect data directly from you when you use the Platform, enter information, interact with an AI interface, verify your email, submit an assessment, request a report or certificate, connect a wallet, mint a credential, make a payment, contact support, or exercise a privacy right.
We collect data automatically through Platform systems, logs, cookies, security controls, APIs, payment webhooks, blockchain events, and diagnostic tools.
We may receive data from a Customer or Sponsor that invites you to an assessment, from an issuer that allocates a credential, or from third-party services you choose to use. If we obtain personal data from another source, we or the relevant controller will provide the information required by applicable law, subject to lawful exceptions.
8. Why we process data and our legal bases
We process personal data only where we have a lawful basis. The applicable basis depends on the service, relationship, and jurisdiction.
8.1 Performance of a contract or steps requested before a contract: to create and manage accounts; verify identity; open and maintain assessment sessions; deliver AFAA, AFAC, and related services; generate results, certificates, reports, and credentials; process checkout and minting requests; provide support; and perform requested integrations.
8.2 Legitimate interests: to secure the Platform; detect fraud, impersonation, automation, tampering, repeated attempts, prompt injection, abuse, and credential gaming; maintain assessment and credential integrity; troubleshoot and improve reliability; conduct proportionate quality assurance and validation; understand service usage; protect users and third parties; enforce terms; manage business operations; and establish, exercise, or defend legal claims. We balance these interests against your rights and expectations.
8.3 Consent: for optional marketing; non-essential cookies where required; publication of optional personal details; certain optional sharing; processing of special-category data where explicit consent is required; and other activities for which we specifically request consent. You may withdraw consent prospectively, but withdrawal does not affect processing already lawfully carried out.
8.4 Legal obligation: to keep accounting and transaction records, respond to valid legal requests, comply with tax, sanctions, anti-fraud, consumer, data-protection, and other legal obligations, and notify authorities or individuals of qualifying security incidents.
8.5 Vital interests or public interests: only in exceptional circumstances where necessary and permitted by law, such as responding to an immediate threat to safety.
8.6 Processing for a Customer or Sponsor: where Coincentives Labs acts as a processor, we process personal data on documented instructions from the Customer or Sponsor. That organisation determines the lawful basis unless the processing is independently required by Coincentives Labs.
8.7 Future-service consent and research choices: we may rely on legitimate interests for proportionate aggregated, de-identified, pseudonymised, or transformed research and service-improvement uses, subject to safeguards and your rights. We will seek consent, explicit consent, contract terms, or another appropriate lawful basis before using identifiable historical assessment or coaching records, raw transcripts, uploaded documents, sponsored assessment content, or confidential third-party material to create, personalise, train, or operate a user-specific personal AI profile, surrogate, or similar future service.
9. AI-assisted assessment, profiling, methodology, and automated processing
9.1 Nature of the processing. AFAA and related services use AI-assisted and rules-based processing to structure interactions, summarise evidence, calculate internal indicators, generate assessment narratives, identify possible anomalies, determine whether Platform criteria for a credential appear to be met, and support credential allocation or reporting workflows.
9.2 General logic. At a high level, the assessment considers observable collaboration behaviour and evidence, including how the user frames goals and context, identifies constraints and success criteria, develops and compares alternatives, tests assumptions and trade-offs, verifies or corrects uncertain outputs, preserves decision ownership, and produces a usable or reusable artifact. Exact internal taxonomies, weights, thresholds, anti-gaming controls, and proprietary validation logic are not published because disclosure could undermine assessment integrity and enable manipulation.
9.3 Accuracy and limitations. AI-generated summaries, scores, classifications, and narratives may be incomplete, inconsistent, or wrong. They are evidence signals from a bounded session, not a clinical, psychological, educational, regulatory, or professional diagnosis, and not a guarantee of job performance, suitability, productivity, safety, or future behaviour.
9.4 Methodology changes and versioning. Our assessment methods, AI-assisted processing, scoring approaches, evidence standards, eligibility logic, report formats, credential categories, validity periods, and integrity controls may change over time. Where we keep assessment or credential records, we may store version information so that records can be interpreted in the context of the methodology, protocol, policy, credential, or report format in effect at the time. Unless otherwise stated, methodology changes apply prospectively and do not automatically re-score, upgrade, downgrade, revoke, or alter previously issued credentials, reports, certificates, or assessment results.
9.5 Corrections and credential integrity. We may correct, suspend, revoke, expire, replace, annotate, or reissue a credential, certificate, report, or assessment result where we reasonably believe there has been error, fraud, abuse, impersonation, system malfunction, security incident, policy violation, legal requirement, payment issue, or credential-integrity concern.
9.6 No solely automated significant decisions by Coincentives Labs. Automated processing may determine Platform outcomes such as session status, credential eligibility, allocation, expiry, or fraud review. Coincentives Labs does not use AFAA to make solely automated decisions that determine employment, dismissal, promotion, compensation, admission, credit, insurance, access to essential services, or another legal or similarly significant outcome.
9.7 Customer responsibilities in hiring or employment. A Customer or Sponsor must not use an AFAA result as the sole basis for a legally or similarly significant decision. It must independently assess relevance, provide meaningful human review, comply with employment, equality, data-protection, and AI laws, and offer any notice, accommodation, appeal, or alternative assessment required by law. Coincentives Labs may suspend access where it reasonably believes a Customer or Sponsor is using the Platform unlawfully or contrary to these restrictions.
9.8 Review and challenge. You may ask us to investigate a suspected factual, identity, security, or technical error in a Platform-generated result. We may correct objective errors, re-run affected processing, annotate a record, revoke or replace a credential, or refer the matter to a Customer or Sponsor. A disagreement with an assessment judgment does not automatically require us to change the result, but we will consider substantiated evidence of material error or unfair processing.
9.9 Fairness and integrity. We may test and monitor assessment protocols, outputs, system performance, and aggregate outcome patterns to improve consistency, security, reliability, and fairness. We do not intentionally infer or use protected characteristics for scoring. No AI system can be guaranteed to be error-free, unbiased, or equally suitable for every user or context.
10. Assessments initiated by employers, recruiters, or other sponsors
When an assessment is initiated or funded by a Customer or Sponsor, we may receive your name, email address, role or application context, assessment template, cohort identifier, and related instructions from that organisation.
Before or at the start of the assessment, you should be told who the Sponsor is, the purpose of the assessment, what information will be shared, and whether an alternative or accommodation is available. The Sponsor is responsible for the lawfulness of its invitation, selection, decision-making, and use of results.
Subject to the relevant contract and notice, we may share with the Sponsor your completion status, assessment result, report, credential status, and limited evidence necessary to interpret or verify the result. We do not provide a complete ChatGPT transcript to a Sponsor unless that disclosure is expressly described, necessary, lawful, and technically enabled.
Where the Sponsor is the controller, requests to delete, correct, restrict, or access sponsored assessment data may need to be directed to the Sponsor. We will assist the Sponsor as required by contract and law.
A Sponsor may set a longer or shorter retention period, subject to law and our independent need to preserve security, payment, credential-integrity, or legal-claims records.
11. Use through ChatGPT and other third-party AI environments
Some Platform services are delivered through Custom GPTs or other AI environments operated by OpenAI or another provider. Those providers process the conversation and account information under their own terms, privacy policies, workspace settings, and data controls.
A GPT builder does not receive access to the full individual conversation merely because a user interacts with its GPT. However, relevant portions of your input and generated output may be sent to Coincentives Labs when the GPT calls a Platform Action or API. For AFAA, this may include identity and verification data, the assessment brief, a structured session summary, scoring or evidence indicators, assessment narrative, and credential or minting instructions.
Files or information you upload to ChatGPT are not automatically received by Coincentives Labs unless relevant content is transmitted through a Platform Action, you separately submit it to us, or the applicable workflow expressly provides otherwise.
Whether OpenAI uses a conversation to improve its models depends on the user's OpenAI plan, account settings, workspace controls, and OpenAI's policies. Coincentives Labs does not control OpenAI's independent retention, training, or account-administration practices. If your ChatGPT account is managed by an employer or other organisation, that organisation's administrator settings and privacy notice may also apply.
Do not enter information into a third-party AI environment that you are not authorised to disclose. Review the provider's privacy controls before using the service.
12. Service improvement, research, and future optional services
12.1 Aggregated and de-identified improvement. We may use aggregated, statistical, or de-identified information to measure performance, evaluate assessment consistency, improve prompts and protocols, detect abuse, develop features, conduct research, and publish insights that do not identify individuals.
12.2 De-identification and pseudonymisation. We will maintain de-identified data in de-identified form and will not attempt to re-identify it except where necessary to test de-identification, investigate security or fraud, protect legal claims, or comply with law. Pseudonymised data may still be Personal Data if it can reasonably be linked to a person.
12.3 Restricted identifiable use. We do not sell identifiable assessment content for model training. We do not use identifiable assessment content to train a general-purpose foundation model unless we provide a separate notice and have an appropriate contractual or legal basis. We may use limited identifiable records for quality assurance, troubleshooting, support, security, fraud prevention, assessment validation, and legal defence where access is restricted and necessary.
12.4 Research and non-personal improvement. We may analyse Platform use, assessment outcomes, and interaction patterns to improve reliability, assessment quality, abuse prevention, benchmarks, educational content, product design, and future non-personal service features. Where possible, we use aggregated, de-identified, pseudonymised, or transformed information rather than directly identifiable records. We do not design non-personal research outputs to identify, imitate, represent, or act on behalf of any specific user.
12.5 Safeguards for identifiable records. Unless we provide a separate notice and have an appropriate lawful basis, we do not use identifiable raw conversations, uploaded documents, employer-sponsored assessment materials, recruiter-sponsored assessment materials, confidential third-party information, special-category data, minor-related data, or legally restricted data to train or personalise a non-personal AI system or benchmark. We may apply safeguards such as data minimisation, access controls, source restrictions, exclusion of sensitive or confidential records, redaction, aggregation, pseudonymisation, anonymisation where feasible, memorisation or re-identification testing, and compatibility review.
12.6 Future optional personalisation services. We may develop optional services that allow a user to create or operate a Personal AI Profile, memory layer, personalised assistant, digital representative, intelligent surrogate, or delegated AI service. These services are separate from basic AFAA assessment, credentialing, certificate, report, wallet, and verification functions.
12.7 Opt-in for user-specific personalisation. We will not use identifiable historical assessment data, coaching data, uploaded documents, reports, credentials, or interaction records to create, train, personalise, or operate a user-specific personal AI profile or surrogate unless we provide a clear notice and obtain the required permission or another valid lawful basis. Where such a feature is offered, we will explain what data sources may be used, whether past AFAA, AFAC, assessment, coaching, credential, profile, or uploaded-content data will be imported, what the feature may remember, infer, recommend, or do, whether it may interact with third parties, how it may be used across services or organisations, and how the user can review, correct, export, restrict, reset, or delete the profile where legally and technically possible.
12.8 Exclusions for sponsored and restricted data. Unless expressly agreed, employer-sponsored, recruiter-sponsored, customer-sponsored, confidential third-party, minor-related, special-category, or legally restricted data will not be used to build or personalise a user-specific personal AI profile or surrogate. Sponsored assessment data will be processed according to the Customer or Sponsor role, notice, lawful basis, and contract.
12.9 User choices. Where processing is based on consent, you may withdraw consent prospectively. Withdrawal will not affect processing already lawfully carried out, records we must keep for legal, security, fraud-prevention, payment, credential-integrity, or blockchain-verification purposes, or data that has been irreversibly anonymised. Where processing is based on legitimate interests, you may object as described in Section 21.
12.10 Feedback and user-owned content. Feedback about the Platform may be used to improve our services. User-owned assessment content, job cases, business context, and artifacts are not treated as unrestricted product suggestions merely because they are submitted during an assessment.
13. Credentials, public profiles, certificates, blockchain, and immutable storage
An allocated credential may initially exist only in Platform records. When you choose to mint a credential, blockchain data becomes publicly visible and may be copied, indexed, analysed, or republished by third parties beyond our control.
Public blockchain records may include a wallet address, smart-contract address, token identifier, transaction hash, issue time, status, credential type, expiry or revocation information, and cryptographic or content-addressed metadata. A wallet address is pseudonymous, not anonymous, and may become linked to you through other activity.
We aim to keep names, email addresses, detailed assessment evidence, and private reports off-chain unless you expressly choose a workflow that publishes them and we clearly explain the consequence. Public credential metadata should be limited to public-safe proof necessary for authenticity, status, and integrity verification.
Names and other Certificate Display Data used on certificates or reports are off-chain by default. They may appear in downloaded PDFs, reports, certificates, emails, profile pages, or user-shared links only when the user chooses that workflow, asks us to generate the artifact, or the relevant Customer or Sponsor workflow expressly requires it and provides notice. If you download, publish, upload, email, or share a named certificate or report, recipients may copy, store, forward, index, or republish it outside our control.
Credential metadata or files may be stored using decentralised or content-addressed services such as IPFS, where used. Information published to a blockchain or immutable storage may remain accessible indefinitely and may not be capable of erasure, correction, or restriction by Coincentives Labs. We may be able to revoke, supersede, hide, or mark a credential as expired in Platform interfaces, but the historical on-chain record may remain.
Deleting your Platform account does not delete blockchain transactions, data copied by third parties, credentials already shared, downloaded certificates or reports held by others, or information retained under legal obligations.
14. Platform-generated and connected wallets
Where the Platform offers a wallet generated or managed on your behalf, we may process the wallet address and encrypted wallet credentials or key material necessary to operate the wallet. Access may depend on control of the verified email account or other authentication method associated with the wallet.
Where you connect a self-managed wallet, we process the wallet address and transaction data required to provide the requested service. We do not request your seed phrase or private key for a self-managed wallet. Never provide them to us or to an AI assistant.
Loss of email access, wallet credentials, private keys, or third-party account access may result in loss of access to credentials or digital assets. Blockchain transactions are generally irreversible. Security incidents, network changes, smart-contract defects, wallet-provider failures, and user error may affect access or availability.
We may restrict wallet or minting functions to prevent fraud, protect users, comply with law, investigate suspicious activity, or maintain credential integrity.
15. How and why we share personal data
We disclose personal data only where reasonably necessary for the purposes described in this Policy, under appropriate contractual, technical, and organisational safeguards where required.
15.1 Service providers and subprocessors: cloud hosting, database, authentication, AI infrastructure, email delivery, customer support, analytics, security, payment processing, certificate and report generation, blockchain infrastructure, decentralised storage, and technical operations.
15.2 Customers, Sponsors, and issuers: where an assessment or credential is sponsored, administered, issued, or verified by an organisation, and the disclosure is described in the relevant workflow, notice, or agreement.
15.3 User-directed recipients: persons, employers, recruiters, professional networks, wallet services, or other third parties to whom you choose to send a report, certificate, credential, profile, or verification link.
15.4 Professional advisers and insurers: lawyers, accountants, auditors, security specialists, insurers, and other advisers subject to confidentiality obligations.
15.5 Authorities and legal process: where required by law or reasonably necessary to respond to valid legal process, protect rights or safety, investigate fraud or abuse, enforce agreements, or establish, exercise, or defend legal claims.
15.6 Corporate transactions: prospective or completed financing, merger, acquisition, reorganisation, sale of assets, insolvency, or transfer of the Platform, subject to confidentiality and applicable law.
We do not sell personal data. We do not share identifiable assessment data for cross-context behavioural advertising. We do not disclose identifiable assessment content to marketers or data brokers.
16. Principal third-party services
The exact service-provider list may change as the Platform develops. Coincentives Labs may maintain a current subprocessor or service-provider register at skillaccolades.com/legal/subprocessors or another published legal page.
Current or anticipated categories include AI infrastructure providers; cloud hosting, database, authentication, and server-function providers; email and communication providers for verification and service emails; payment processors; blockchain infrastructure providers; public blockchain networks such as Polygon; IPFS or other content-addressed storage providers where used; analytics providers; and hosting, content-delivery, monitoring, support, and security providers.
Examples may include OpenAI for ChatGPT and AI interaction environments, Google Cloud or Firebase for cloud and backend services, Google Workspace or another email provider, Stripe for payments, Polygon infrastructure providers, Lighthouse or another storage provider where used, and analytics or monitoring providers used by the Platform. We do not list a provider here as a commitment that it is used in every workflow.
Third-party wallet, browser-extension, marketplace, social-network, chat-client, enterprise, or verification services selected by the user or a Customer process data under their own terms.
17. International data transfers
Coincentives Labs is established in Denmark, but service providers may process personal data in the European Economic Area, the United States, and other countries.
Where personal data is transferred outside the EEA, the United Kingdom (UK), or Switzerland, we use an available lawful transfer mechanism, such as an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, or another legally recognised safeguard. Where required, we assess transfer risks and implement supplementary measures.
Public blockchain and decentralised-storage data may be replicated globally without a single destination or controller. By choosing to mint or publish, you acknowledge this technical characteristic and the resulting limitations.
18. Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, to meet Customer instructions, preserve credential integrity, comply with law, resolve disputes, and protect legal rights. The following schedule describes our default approach unless a different period is required by law, contract, Customer instruction, security need, product workflow, legal hold, or technical constraint.
Verification code: normally valid for 10 minutes. The active code should cease to be usable after expiry. Associated request, rate-limit, fraud, and security metadata may be retained for up to 12 months.
Pending unverified assessment brief: up to 30 days after the last verification request, unless a shorter or longer period is required for security, troubleshooting, legal, or product-integrity reasons.
Account and identity data: while the account is active and for up to 60 days after verified deletion, subject to backups, legal holds, payment records, credential records, Customer instructions, and records needed to preserve credential integrity.
Assessment brief, structured session records, scores, evidence indicators, narratives, reports, and protocol records: generally 6 years after the session ends or the related credential is issued, whichever is later, unless a Customer contract, legal requirement, appeal period, or shorter user-facing product commitment applies.
Credential verification and integrity records: for the credential's validity period and generally 6 years thereafter. A minimal audit record may be retained longer where necessary to verify issuance, expiry, revocation, fraud, or legal claims.
Payment, tax, and accounting records: for the period required by applicable accounting, tax, consumer, and anti-fraud laws.
Support, complaints, and appeals: generally 3 years after closure, or longer if needed for a dispute or legal claim.
Marketing records: until consent is withdrawn or an objection is received, plus a limited suppression record to respect the opt-out and demonstrate compliance.
Backups: deleted data may remain in encrypted backups for up to 90 days before routine overwriting, unless a longer period is required for security, disaster recovery, or legal hold.
Blockchain and immutable-storage records: public blockchain records and certain content-addressed records may remain available indefinitely and may not be within our technical ability to delete.
De-identified or aggregated data: may be retained for longer where it no longer identifies a person and is maintained in de-identified or aggregated form.
19. Security
We use reasonable and proportionate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
Measures may include encryption in transit and at rest where appropriate, hashing or pseudonymisation, access controls, least-privilege permissions, separation of public and private evidence, secure credential and secret management, rate limiting, audit and security logs, monitoring, backups, incident-response procedures, staff or contractor confidentiality, vendor due diligence, and contractual data-protection obligations.
No internet, AI, cloud, wallet, blockchain, or storage system is completely secure. We cannot guarantee that personal data will never be accessed, disclosed, altered, lost, or destroyed. You are responsible for protecting your email account, devices, ChatGPT account, connected wallets, passwords, multi-factor authentication, and recovery methods.
If a personal-data breach creates a legally reportable risk, we will notify the competent authority and affected individuals as required by law.
20. Cookies, analytics, and similar technologies
We may use essential cookies and local storage to provide authentication, security, preferences, sessions, checkout, and core functionality.
With consent where required, we may use analytics or performance technologies to understand use of the Platform and improve reliability. We do not activate non-essential analytics, advertising, or cross-site tracking unless the legally required consent or notice has been provided.
We do not use assessment content for targeted advertising. A separate Cookie Notice should identify the technologies used, provider, purpose, duration, and available controls. Browser settings may block cookies, but essential functions may then fail.
21. Your choices and data-protection rights
Subject to applicable law and exceptions, you may have the right to request access to personal data, correction of inaccurate data, completion of incomplete data, deletion, restriction of processing, data portability, objection to processing based on legitimate interests, objection to direct marketing, and withdrawal of consent. Where we offer research or future optional personalisation choices, you may also have product controls to allow, restrict, withdraw, or change permitted data sources. These controls do not replace statutory data-protection rights.
You may also have rights relating to solely automated decisions with legal or similarly significant effects, including the right to obtain human intervention, express your point of view, and contest a decision. As described above, Coincentives Labs does not intend AFAA to make such decisions, but we will provide applicable safeguards where the law requires them.
To exercise a right, contact privacy@skillaccolades.com. We may need to verify your identity and may refuse or limit a request where permitted by law, such as to protect another person, preserve evidence, comply with legal obligations, maintain credential integrity, or handle blockchain or immutable-storage limitations.
Where Coincentives Labs acts as processor for a Customer or Sponsor, we may refer your request to that Customer or Sponsor and assist it according to contract and law.
22. Complaints
Please contact us first so we can try to resolve your concern.
You also have the right to complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, DK-2500 Valby, Denmark, email dt@datatilsynet.dk, or to another competent supervisory authority in the country where you live or work or where the alleged infringement occurred.
23. United States and other jurisdiction-specific rights
Where applicable under California or other United States state privacy laws, residents may have rights to know, access, correct, delete, and obtain a portable copy of personal information; opt out of sale, sharing, or targeted advertising; limit certain uses of sensitive personal information; and appeal a refusal to act on a request.
Coincentives Labs does not sell personal information and does not share identifiable assessment data for cross-context behavioural advertising. We will not discriminate against a person for exercising an applicable privacy right.
Residents of other jurisdictions may have additional rights. We will honour applicable rights and may publish jurisdiction-specific supplements where required.
24. Children
The Platform is intended for persons aged 18 or older. We do not knowingly collect personal data from children under 18 through the direct-to-user Platform.
A school, learning provider, or Customer must not use the Platform with minors unless a separate written agreement, age-appropriate notice, lawful basis, parental or guardian authorisation where required, and appropriate safeguards are in place.
If we learn that a child has provided personal data without appropriate authorisation, we may suspend the account and delete or restrict the data, subject to legal and technical limitations.
25. Third-party links and user-directed sharing
The Platform may link to third-party websites, wallets, payment pages, professional networks, marketplaces, blockchain explorers, or other services. We do not control their privacy practices.
When you download, publish, or share a certificate, report, credential, profile, or verification link, the recipient may copy, store, analyse, or redistribute it. Review the content and recipient before sharing. We are not responsible for a recipient's independent use after a user-directed disclosure, subject to non-waivable law.
26. Business transfers and service changes
If Coincentives Labs or the Platform is reorganised, financed, sold, merged, transferred, or becomes subject to insolvency proceedings, personal data may be disclosed to advisers and transferred to a successor as permitted by law. We will require the recipient to protect the data and will provide notice where legally required.
We may add, replace, or discontinue features, service providers, blockchain networks, credential types, or delivery environments. Material changes affecting privacy will be reflected in this Policy or a supplemental notice.
27. Changes to this Policy
We may update this Policy to reflect changes in law, technology, products, contracts, or processing practices. The revised version will show an updated date.
Where required, we will provide advance or prominent notice of material changes and seek consent if the change requires it. Continuing to use the Platform does not override any consent requirement imposed by law.
28. Contact us
Privacy questions, data-protection rights requests, objections, complaints, or security concerns may be sent to:
Coincentives Labs / Skill Accolades Platform
Danish Central Business Register (CVR) 39388871
Frederikskaj 2M, 1. tv, 2450 Copenhagen SV, Denmark
Primary privacy email: privacy@skillaccolades.com
Escalations and formal legal notices: bc@coincentives.io
For a sponsored assessment, you may also contact the Customer or Sponsor identified in the invitation or assessment notice.
