This document is a translation of the French original. In the event of any discrepancy, the French version prevails.
Preamble
Skillee attaches fundamental importance to the protection of personal data. This Privacy Policy describes how Skillee collects, uses, shares and protects the personal data of visitors to its websites and of professional users of the Studio platform. It applies to the services accessible from skillee.ai and studio.skillee.ai. A separate privacy policy applies to candidates who use Gabee (gabee.skillee.ai).
Article 1 — Controller
The controller of the personal data collected via skillee.ai and studio.skillee.ai is:
Skillee, a simplified joint-stock company (société par actions simplifiée) with share capital of €1,000, registered with the Trade and Companies Register (RCS) of Versailles under number 999 363 237, whose registered office is located at 13 avenue de Villeneuve l'Étang, 78000 Versailles.
For any question relating to the processing of your personal data, you may contact Skillee's external Data Protection Officer (DPO), DIPEEO SAS, at rgpd@skillee.ai (designation number with the CNIL, the French data protection authority: DPO-169761).
Article 2 — Categories of data subjects and data processed
2.1 Visitors to the skillee.ai website
The following data are collected when you browse the showcase website:
- Technical connection data (IP address, browser type, operating system, pages viewed, connection dates and times)
- Data provided via the contact form or appointment booking (surname, first name, business email address, appointment slot, any message)
2.2 Professional users of the Studio (recruiters, HR professionals)
The following data are collected when a Studio account is created and used:
- Identification data: business email address, surname, first name
- Authentication data: password (stored in hashed form, never in plain text)
- Data relating to the organisation: company name, description of the company entered by the user in their account settings
- Browsing and usage data: connection logs, actions performed on the platform, technical metadata
2.3 Candidates processed via Skillee agents — important clarification
The data of candidates processed by the Charlee (voice interview) and Julee (WhatsApp) agents and by the Studio's CV screening are collected by Skillee's customers (employers and their partner ATSs) as part of their own recruitment processes. For this processing, Skillee acts as a processor within the meaning of Article 28 of the GDPR, and not as a controller. Candidates should refer to the privacy policy of the employer processing their data in order to exercise their rights in respect of such data. Skillee will assist the employer in responding to candidates' requests in accordance with the contractual obligations set out in the DPA.
Article 3 — Purposes and legal bases of processing
Personal data are processed by Skillee for the following purposes and on the following legal bases:
- Provision of the Studio platform (account creation, authentication, features) — legal basis: performance of the service contract entered into (GDPR art. 6.1.b)
- Commercial communication and demonstrations (contact form, appointment booking via Calendly) — legal basis: Skillee's legitimate interest in responding to prospects' requests (GDPR art. 6.1.f)
- Security and fraud prevention (technical logs, monitoring) — legal basis: Skillee's legitimate interest in ensuring the security of its systems (GDPR art. 6.1.f)
- Compliance with legal obligations (invoicing, accounting) — legal basis: legal obligation (GDPR art. 6.1.c)
- Improvement of services (anonymised analysis of usage) — legal basis: Skillee's legitimate interest (GDPR art. 6.1.f). No personal data are used to train Skillee's artificial intelligence models. Skillee guarantees this commitment contractually and requires its AI processors to comply with this commitment.
Article 4 — Recipients and processors
Personal data are intended for:
- Skillee's authorised teams, strictly within the scope of their duties
- The technical processors listed below, who are subject to strict contractual obligations (Data Processing Agreement, security measures, confidentiality)
- The competent authorities where required by a legal or judicial obligation
No data are sold, rented or transferred to third parties for commercial or advertising purposes or for the purpose of building databases.
The processors used by Skillee are as follows:
- Microsoft Azure — hosting of the infrastructure and storage of the platform's data. Processing in France (France Central region)
- OVH — hosting and associated infrastructure services. Processing in France
- Cloudflare — content delivery and protection against attacks; processes technical connection data. Processing in the European Union and the United States
- Google (Vertex AI / Gemini) — natural language analysis and generation by Skillee's agents; processes the content submitted to them. Processing in the European Union and the United States
- Telnyx — routing of the telephone communications of the voice agents; processes telephone numbers and call streams. Has no access to any data originating from connected Google or Microsoft accounts
- Calendly — booking of sales appointments; processes the name, business email address and chosen slot. Processing in the United States
This list is also published in the Trust Center (skillee.trust.dipeeo.fr) and kept up to date. Any substantial change is brought to users' attention in accordance with Article 12.
Skillee contractually prohibits all of its AI processors from using the data processed to train, develop or improve generalised or non-personalised artificial intelligence models.
Article 5 — Data transfers outside the European Union
Data hosting and the main processing take place within the European Union (metropolitan France for the main Microsoft Azure and OVH infrastructure).
Certain processors listed in Article 4 may process data from the United States (in particular the AI model provider Google, as well as Cloudflare and Calendly). These transfers are governed by the mechanisms provided for by the GDPR:
- Adherence to the EU-US Data Privacy Framework (DPF) for the processors concerned
- Standard contractual clauses (SCCs) of the European Commission
- Additional technical measures (encryption in transit and at rest)
Article 6 — Access to your Google account data
If you choose to connect your Google account to Skillee, we access a limited set of data from that account, strictly within the scope of the permissions you grant on Google's consent screen. We never request more than what our features require.
- gmail.readonly — Data accessed: content, headers and metadata of messages in your mailbox. Why we need it: to identify candidate replies and automatically attach them to the matching application file, so recruiters can follow the exchange without re-entering anything.
- gmail.send — Data accessed: none (no reading — sending only). Why we need it: to send interview confirmations, prequalification summaries and candidate follow-ups from your own address, so candidates hear from the agency they applied to.
- calendar.freebusy — Data accessed: free/busy time blocks only — no titles, no attendees, no event content. Why we need it: to check your availability before proposing interview slots, without reading the content of your events.
- calendar.events.owned — Data accessed: events on the calendars you own. Why we need it: to create interview appointments in your own calendar, invite the candidate and generate the video-call link.
You can revoke Skillee's access to your Google account at any time from myaccount.google.com/permissions by selecting Skillee and clicking "Remove access", or by disconnecting the account from your Skillee settings. Revocation takes effect immediately and prevents any further access. Data obtained through these permissions is retained for the duration of the assignment it was collected for, and deleted afterwards. Your OAuth tokens are deleted immediately upon revocation or account termination.
With whom we share Google user data
Google user data obtained through the permissions listed above is disclosed only to the service providers strictly necessary to operate the features you enabled. It is never sold, rented, or disclosed to any other party. The recipients are:
- Microsoft Azure — hosting and storage of the Skillee platform. Receives message content and metadata, calendar events, and OAuth tokens (encrypted at rest). Processing takes place in France (France Central region).
- Google (Vertex AI / Gemini) — natural-language analysis performed by Skillee's agents. Receives only the extracts of messages that relate to an active recruitment assignment. Processing takes place in the European Union and the United States.
The following additional commitments apply to Google user data:
- Data minimisation. Skillee processes only what is required to identify and handle candidate replies relating to an active recruitment assignment. Messages unrelated to that purpose are not analysed, not acted upon, and not submitted to any of the providers listed above. Only the relevant extract of a qualifying message is submitted for analysis — never the mailbox as a whole.
- Automated processing only. The analysis described above is carried out by automated agents. Skillee staff do not read the content of your messages, save for the limited exceptions set out in the Limited Use section below.
- No model training. All providers listed above are contractually bound not to use Google user data to train, develop, or improve generalized or non-personalized artificial intelligence or machine learning models. Skillee does not use this data to train its own models either.
- No other recipients. Beyond the providers listed above, Google user data is disclosed only where required by applicable law or valid legal process, or as part of a merger or acquisition duly notified to you in advance. Skillee's telephony provider and its appointment-scheduling provider have no access to Google user data.
Limited Use of Google user data
Skillee's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we commit to the following:
- We do not transfer data obtained through Google permissions to third parties, except as necessary to provide or improve the service you requested (see "With whom we share Google user data" above), to comply with applicable law, or as part of a merger or acquisition duly notified to you.
- We do not use or transfer this data for advertising, marketing profiling, resale, or the building of commercial databases.
- We do not use this data to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models.
- We do not allow humans to read this data, except with your explicit prior consent for specific messages, where necessary for security purposes such as investigating abuse or a security incident, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations in accordance with applicable law.
Article 7 — Retention periods
Data are retained for the following periods:
- Studio account (professional user): for the entire term of the service contract, then deletion within a maximum of 30 days following termination, subject to legal retention obligations (invoicing: 10 years in accordance with the French Commercial Code (Code de commerce))
- Data from the contact form / appointment booking: 3 years from the last contact in the absence of an active business relationship
- Data from connected Google and Microsoft accounts: for the duration of the assignment for which they were collected, then deletion. OAuth tokens are deleted immediately in the event of revocation of access or termination of the account
- Technical connection logs: 30 days
- Logs of high-risk AI systems: 12 months (in accordance with Article 26.6 of the AI Act)
- Billing data: 10 years (French Commercial Code art. L.123-22)
Article 8 — Rights of data subjects
In accordance with the GDPR and the amended French Data Protection Act (Loi Informatique et Libertés), you have the following rights over your personal data:
- Right of access (GDPR art. 15) — to obtain confirmation that your data are being processed and to obtain a copy of them
- Right to rectification (GDPR art. 16) — to have inaccurate or incomplete data corrected
- Right to erasure (GDPR art. 17) — to request the deletion of your data in the cases provided for by law
- Right to restriction of processing (GDPR art. 18)
- Right to data portability (GDPR art. 20) — to receive your data in a structured format
- Right to object (GDPR art. 21) — to object to the processing of your data on legitimate grounds
- Right to set directives regarding what happens to your data after your death (French Data Protection Act art. 85)
- Right to withdraw your consent at any time where the processing is based on consent, without affecting the lawfulness of processing carried out prior to withdrawal
To exercise your rights, you may contact Skillee's DPO at rgpd@skillee.ai, or by post at the address of the registered office. Skillee will respond to your request within one month (which may be extended to three months depending on the complexity of the request, in accordance with the GDPR).
Article 9 — Automated decision-making and profiling
For professional users of the Studio (HR managers, recruiters), no decision producing legal effects concerning them or similarly significantly affecting them is taken solely on the basis of automated processing.
For candidates processed via Skillee's agents (Charlee, Julee, the Studio's CV screening), automated processing takes place as part of the employer's recruitment process. This processing is described in the privacy policy of each employer. In accordance with Article 22 of the GDPR, the candidate may request human intervention from the employer in the final decision-making. Skillee has implemented, by design, a mandatory human oversight mechanism (the employer validates the questions and criteria before each interview and may modify the scores produced by the AI agents), in accordance with Article 14 of the AI Act.
Article 10 — Security
Skillee implements appropriate technical and organisational measures to ensure the security of personal data: encryption of data in transit (TLS 1.2 minimum) and at rest (AES-256), strong authentication for administrator access, continuous backups with automatic restoration, access monitoring, strict management of rights by user profile. The detailed list of security measures is available on request in the Trust Center.
Article 11 — Complaints to the CNIL
If, after contacting Skillee, you consider that your rights over your personal data are not being respected, you may lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL):
- Website: www.cnil.fr/fr/plaintes
- Postal address: 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
Article 12 — Changes to the policy
Skillee reserves the right to amend this Privacy Policy at any time to reflect changes in its services, in the processors used or in the applicable regulations. Any substantial change will be brought to users' attention by notification in the Studio or by email with reasonable prior notice. The date of the last update is indicated below.
Last updated: 9 September 2026