Back to Skillora

Skillora Privacy Policy

Last updated: 21 September 2026

1. Purpose of This Policy

This Privacy Policy explains how Skillora handles personal information when providing a business-to-business learning management platform to South African Skills Development Providers (SDPs), training institutions, employers, administrators, instructors, moderators, learners, and related users.

Skillora is designed for learner administration, course records, assessments, portfolios of evidence (POE), moderation workflows, certificate generation and verification, compliance reporting, communications, and audit support.

2. POPIA Roles

South Africa's Protection of Personal Information Act, 2013 (POPIA) distinguishes between a Responsible Party and an Operator.

In most cases:

  • The Customer, such as the SDP or training institution, is the Responsible Party because it decides why learner, staff, assessment, POE, certificate, and institutional information is processed.
  • Skillora is the Operator because it processes personal information on behalf of the Customer to provide the platform.

There may be limited cases where Skillora acts as a Responsible Party for its own business operations, such as billing, account administration, security monitoring, product analytics, legal compliance, and direct communications with institutional representatives.

3. Personal Information We Process

Skillora may process the following categories of personal information, depending on how the Customer uses the service:

  • Account information: names, email addresses, phone numbers, roles, login identifiers, status, and institution associations.
  • Learner information: learner names, contact details, student numbers, identity or registration numbers where supplied, course enrolments, progress records, assessment submissions, POE records, workplace records, attendance records, moderation outcomes, and certificate records.
  • Staff information: administrator, instructor, assessor, moderator, and support-user profile details, role assignments, activity records, and SETA registration information where supplied.
  • Assessment and POE information: files, evidence, rubrics, feedback, scores, competency decisions, moderation notes, audit trails, and related metadata.
  • Certificate information: learner name, course or qualification details, NQF level, credits, unit standard, SETA or accreditation details, issue date, certificate number, verification code, and verification URL.
  • Communications: platform messages, email or WhatsApp notification logs where enabled, support requests, and account-help messages.
  • Billing information: institution name, billing plan, subscription status, payment references, invoice metadata, and PayFast-related transaction references.
  • Technical information: IP addresses, browser or device information, timestamps, authentication events, logs, error reports, security events, and usage analytics.
  • AI usage information: prompts or inputs submitted to AI-assisted features, model responses, token counts, cost estimates, and usage-limit records, where AI features are enabled.

Customers should avoid uploading unnecessary special personal information unless required for lawful training, assessment, compliance, accreditation, or recordkeeping purposes.

4. Why We Process Personal Information

Skillora processes personal information to:

  • Provide and maintain the Skillora platform.
  • Authenticate users and manage role-based access.
  • Support learner enrolment, course administration, assessments, POE workflows, moderation, certification, audit exports, and compliance records.
  • Generate and verify certificates.
  • Send operational notices, account messages, assessment reminders, payment notices, and support communications.
  • Process subscriptions and billing.
  • Provide AI-assisted study, assessment, compliance, grading, moderation, and risk-analysis features where enabled.
  • Monitor security, prevent abuse, investigate incidents, and protect platform integrity.
  • Improve reliability, usability, performance, and support.
  • Comply with law, legal process, contractual obligations, SETA/QCTO-related requirements, and regulator requests where applicable.

5. Legal Bases and POPIA Conditions

The applicable legal basis will depend on the Customer's use case and the relevant data subject relationship. Processing may be based on:

  • The Customer's contractual obligations to learners, employees, clients, funders, SETAs, QCTO, or other stakeholders.
  • The Customer's legal or regulatory obligations.
  • Consent, where required and valid under POPIA.
  • Legitimate interests of the Customer or Skillora, where lawful and balanced against data subject rights.
  • The need to protect rights, safety, security, or evidence.

Customers are responsible for ensuring they have a lawful basis to collect and process the personal information they upload to Skillora.

6. Data Subject Rights

Under POPIA, data subjects may have rights to:

  • Request access to their personal information.
  • Request correction or deletion of inaccurate, excessive, irrelevant, outdated, incomplete, misleading, or unlawfully obtained personal information.
  • Object to processing in certain circumstances.
  • Withdraw consent where processing is based on consent.
  • Complain to the Information Regulator.
  • Request information about processing and safeguards.

Because the Customer is usually the Responsible Party, learners and staff should normally direct requests to their institution first. Skillora will provide reasonable assistance to the Customer in responding to valid data subject requests.

7. Retention

Skillora retains personal information for as long as reasonably required to provide the service, comply with legal obligations, support audits, resolve disputes, maintain security, and preserve training, assessment, POE, moderation, and certification records.

Training and compliance records may need to be kept for extended periods due to accreditation, SETA, QCTO, contractual, audit, or legal requirements. Unless a shorter period is required by law or agreed in writing, Skillora may support a default retention period of up to five years for learner, assessment, POE, moderation, attendance, and certificate records, subject to Customer instructions and legal review.

Backup copies may persist for a limited period after deletion as part of ordinary backup and disaster-recovery processes.

8. Deletion and Correction Requests

Customers may request correction or deletion of data through platform tools or support channels, subject to role permissions and legal retention duties.

Skillora may decline or delay deletion where retention is necessary for lawful recordkeeping, audit obligations, dispute resolution, fraud prevention, security, regulatory compliance, or certification verification.

Where deletion is legally appropriate, Skillora will take reasonable steps to delete or anonymise the relevant information from active systems and allow backup copies to expire according to backup cycles.

9. Sharing and Disclosure

Skillora may share personal information with:

  • The Customer and its authorised users.
  • Hosting, database, email, payment, storage, analytics, support, security, and infrastructure providers.
  • Payment processors such as PayFast for subscription payment processing.
  • AI service providers where AI features are enabled and a user submits information for AI processing.
  • Regulators, SETAs, QCTO, courts, law enforcement, or other authorities where legally required or reasonably necessary.
  • Professional advisers, auditors, insurers, and legal representatives.
  • Successors or assignees in connection with a merger, restructuring, sale, or transfer of the business, subject to appropriate safeguards.

Skillora does not sell learner records or Customer Data.

10. Cross-Border Processing

Some service providers may process or store information outside South Africa. Where cross-border processing occurs, Skillora will use reasonable contractual, technical, and organisational safeguards appropriate to the nature of the information and POPIA requirements.

Customers should consider whether their own learner agreements, client contracts, accreditation obligations, or funder requirements impose additional restrictions on cross-border processing.

11. Security

Skillora uses reasonable technical and organisational safeguards to protect personal information, including role-based access, authentication, tenant separation, audit trails, encryption in transit where supported, access controls, backups, monitoring, and operational security measures.

No system is perfectly secure. Customers and users must protect login credentials, assign roles carefully, review access regularly, and notify Skillora promptly of suspected unauthorised access or data incidents.

12. AI-Assisted Features

Skillora may provide AI-assisted features for study support, assessment generation, grading support, moderation review, compliance assistance, and learner risk analysis.

Users should not submit unnecessary personal information into AI prompts. AI outputs may be inaccurate or incomplete and must be reviewed by a qualified human user before being used for official assessment, moderation, certification, compliance, or learner-support decisions.

Skillora may log AI usage for budgeting, abuse prevention, security, auditability, and service operation. This may include user ID, institution ID, route, provider, model, token counts, cost estimates, timestamps, and submitted content where technically necessary.

13. Cookies and Local Storage

Skillora may use cookies, local storage, and similar technologies for authentication, session management, security, preferences, theme settings, and platform functionality.

For example, Skillora may store a theme preference in local storage using a Skillora-branded key. Older users who previously used the old branded local storage key may lose that saved theme preference after the rename; this is low-risk preference data and does not require migration unless the business wants to preserve existing theme settings.

14. Children's and Learner Data

Skillora is a B2B platform used by institutions. Customers are responsible for ensuring that they have the required authority, notices, consents, contracts, or legal basis to process learner information, including information relating to minors where applicable.

15. Information Officer

Information Officer: Monde Hewana

Email: helpdeskskillora@gmail.com

Customers should also publish or provide their own Information Officer or privacy contact details where required by POPIA and PAIA.

16. Complaints

Data subjects may contact their institution or Skillora about privacy concerns. They may also lodge a complaint with the Information Regulator South Africa.

Information Regulator South Africa: https://inforegulator.org.za/

17. Changes to This Policy

Skillora may update this Privacy Policy from time to time. Material changes will be communicated through reasonable means, such as in-app notice, email, or publication on the Skillora website.

18. Contact

For privacy questions, requests, or concerns, contact:

Email: helpdeskskillora@gmail.com

Information Officer: Monde Hewana, 0665158825

References for Legal Review

  • Protection of Personal Information Act 4 of 2013, South African Government: https://www.gov.za/documents/protection-personal-information-act
  • Information Regulator South Africa: https://inforegulator.org.za/
  • POPIA definitions and concepts, National Consumer Tribunal: https://www.ncpt.gov.za/POPIA.aspx