Privacy Policy

Datenschutzerklärung — Last updated: May 2026

1. Overview

SkillExchange ("we", "us", "our", "Betreiber") operates the website skillexchange.market — an AI skill marketplace and influencer discovery platform. This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service, in compliance with the EU General Data Protection Regulation (GDPR / DSGVO).

2. Data Controller (Verantwortlicher)

The data controller responsible for your personal data is:
Ultrion Publishing — Michael Büth
E-Mail: contact@ultrion.de
Deutschland

3. Categories of Data We Process

We collect and process the following categories of data:

a) User Account Data

  • Account Data: Name, email address, profile picture, and profile information when you sign up via GitHub or Google OAuth.
  • Transaction Data: Payment and payout records processed through Stripe Connect, including transaction amounts, dates, and status.
  • Usage Data: Skill usage metrics, API call logs, review data, trust scores, and platform interaction data.
  • Technical Data: IP address, browser type, device information, operating system, referring URL, collected automatically when you visit our platform.

b) Influencer Data

Our platform includes an influencer discovery and booking feature. We process the following influencer-related data:

  • Public Social Media Data: Publicly available profile information, follower counts, engagement rates, and content metrics from platforms like Instagram, TikTok, YouTube, and others, collected via Apify scraping services.
  • Influencer Registration Data: Name, email, social media handles, niche/category, location, pricing information, and portfolio data provided by influencers who register on our platform.
  • Booking Data: Collaboration requests, booking details, communication between brands and influencers, and booking status information.

c) Apify Scraping Data

We use Apify as a data processing service (Art. 28 DSGVO) to discover and aggregate publicly available social media data. Apify acts as our data processor. We only collect publicly available data from social media profiles. We do not scrape private or non-public information. Scraped data is used solely for influencer discovery, search, and matching on our platform.

4. How We Use Your Data

We use collected data for the following purposes:

  • Provide and maintain our skill marketplace and influencer platform
  • Process transactions and manage payouts via Stripe
  • Enable influencer discovery, booking, and collaboration
  • Build trust and reputation scores
  • Communicate with you about your account, transactions, and bookings
  • Improve our platform, user experience, and services
  • Ensure platform security and prevent fraud
  • Comply with legal obligations

5. Legal Basis for Processing (DSGVO / GDPR)

We process your personal data on the following legal bases:

  • Contract Performance (Art. 6(1)(b) GDPR): To fulfill our contractual obligations when you use our marketplace, process transactions, or facilitate influencer bookings.
  • Legal Obligation (Art. 6(1)(c) GDPR): To comply with tax, accounting, and other legal requirements (e.g., retention of transaction records for 10 years under German tax law).
  • Legitimate Interest (Art. 6(1)(f) GDPR): For security, fraud prevention, analytics, service improvement, and influencer discovery from publicly available data.
  • Consent (Art. 6(1)(a) GDPR): When you have given explicit consent for specific processing activities, such as newsletter subscriptions or optional analytics.

6. Data Sharing and Recipients

We share data with the following third parties:

  • Stripe (Payment Service Provider): For payment processing, payout management, and fraud detection. Stripe processes data under its own DPA. Stripe Privacy Policy
  • Apify (Data Processor): For web scraping and influencer data aggregation. Apify acts as our data processor under Art. 28 DSGVO. Apify Privacy Policy
  • GitHub / Google (OAuth Providers): For authentication only. Respective privacy policies apply.
  • Vercel (Hosting Provider): For hosting, deployment, and CDN delivery. Vercel Privacy Policy

We do not sell, rent, or trade your personal data to any third parties beyond the service providers listed above.

7. Data Retention

We retain your personal data only for as long as necessary:

  • Account Data: Retained until account deletion, plus 30 days for cleanup.
  • Transaction Data: Retained for 10 years as required by German tax law (§ 147 AO).
  • Influencer Scraped Data: Publicly available data is periodically refreshed and outdated entries are removed after 90 days of inactivity.
  • Server Logs: Deleted after 30 days.
  • Analytics Data: Anonymized after 26 months.

8. Your Rights (DSGVO / GDPR)

Under the General Data Protection Regulation, you have the following rights:

  • Right of Access (Art. 15 GDPR) — You can request information about the personal data we hold about you.
  • Right to Rectification (Art. 16 GDPR) — You can request correction of inaccurate data.
  • Right to Erasure (Art. 17 GDPR) — You can request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
  • Right to Restriction of Processing (Art. 18 GDPR) — You can request that we limit how we use your data.
  • Right to Data Portability (Art. 20 GDPR) — You can request to receive your data in a structured, machine-readable format.
  • Right to Object (Art. 21 GDPR) — You can object to processing based on legitimate interest.
  • Right to Withdraw Consent (Art. 7(3) GDPR) — You can withdraw any consent you have given at any time.
  • Right to Lodge a Complaint (Art. 77 GDPR) — You have the right to lodge a complaint with a supervisory authority (e.g., BfDI).

To exercise any of these rights, contact us at contact@ultrion.de. We will respond within one month.

9. Cookies and Tracking

We use the following types of cookies:

  • Essential Cookies: Session tokens, CSRF protection, authentication state. These are technically necessary and do not require consent.
  • Analytics: Server-side analytics only. We do not use client-side tracking cookies from third parties (no Google Analytics, no Facebook Pixel). Usage patterns are analyzed from server logs in anonymized form.

We do not use advertising cookies or share cookie data with advertising networks. No cookie consent banner is required as we do not deploy non-essential cookies.

10. International Data Transfers

Some of our service providers (Vercel, Stripe, Apify) may process data outside the European Economic Area (EEA). We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adherence to applicable data protection frameworks.

11. Security Measures

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption in transit (TLS/HTTPS) for all connections
  • Encrypted data storage for sensitive information
  • Access controls and authentication requirements
  • Regular security reviews and updates
  • Minimized data collection principles

12. Data of Minors

Our Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you become aware that a minor has provided us with personal data, please contact us and we will take steps to delete such information.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "last updated" date. We encourage you to review this Privacy Policy periodically.

14. Contact

For any questions about this Privacy Policy or to exercise your data protection rights:
Ultrion Publishing — Michael Büth
E-Mail: contact@ultrion.de