1. Who is responsible?
The controller for personal accounts, platform administration, subscriptions and our own communications is:
[registered address required before production]
Enterprise: [enterprise number required before production]
VAT: Not applicable or not yet provided
privacy@lpcyberlaunchpad.com
For employee, candidate or compliance data entered by a business customer in its protected workspace, that customer will generally be the controller and LP Cyber Launchpad acts as processor to the extent it handles the data solely on the customer’s instructions. A data processing agreement is concluded before live use.
2. What data do we process?
We process only the data needed for the functions described below:
- Account and security: name, email address, authentication identifiers, optional phone number, MFA status and security events.
- Career profile: experience, goals, budget, employer funding, learning preferences, skills, selected domains and deadlines.
- Learning and certification: pathways, milestones, verification status, credential details and evidence you provide.
- Communications: support tickets, attachments, community and direct messages, and notification preferences.
- Subscriptions: Stripe customer and subscription identifiers, plan, payment status and billing events. We do not receive full card details.
- Career Bridge: job preferences, evidence-based match score and interest status. Identity remains withheld until both candidate and employer opt in.
- Business, OCR and NIS2: organisation membership, assessments, measures, incidents, evidence, audit events and reports within the workspace.
- Technical data: IP address, browser/device details, timestamps and logs needed by hosting, authentication and security providers.
Special-category data and anonymous reports
We do not actively request health information, political views, trade-union membership, origin or other special-category data. Free text and uploads may nevertheless contain it. Submit such data only when necessary and lawful. Anonymous OCR reports are designed without a user-profile link, although their content may identify people. Business customers must not attempt to re-identify reporters.
3. Purposes and legal bases
- Performance of a contract: accounts, personalised pathways, progress, verification, support, business workspaces and subscriptions.
- Legitimate interests: security, abuse prevention, reliable audit trails and service improvement, subject to a balancing assessment and a right to object where applicable.
- Consent: optional browser preferences, optional communications and features you activate, such as private job matching. Consent can be withdrawn at any time.
- Legal obligation: accounting, tax and required security or incident records.
4. Recipients, processors and transfers
We do not sell personal data. Depending on the feature used, data may be processed by:
- Supabase: authentication, database, storage and realtime infrastructure.
- Stripe: payments, subscriptions, invoices and the customer portal.
- The configured hosting and email infrastructure for delivery, security and transactional messages.
- Discord, Google, GitHub or LinkedIn only when you use the related integration or sign-in method.
- Authorised employees or curators, only for assigned tasks and under role-based access.
Where a provider processes data outside the EEA, we rely on an applicable adequacy decision, EU Standard Contractual Clauses or another valid safeguard. The current subprocessor list and safeguards can be requested through the privacy contact.
5. Retention
| Account and profile | For the life of the account; deletion within 30 days of a verified erasure request, subject to legal exceptions. |
|---|---|
| Profile drafts | No more than 90 days after the last change. |
| Credential evidence and progress | Until removed by the user or the account is closed. |
| Support and community | Generally no more than 24 months after closure or last activity; earlier following a valid erasure request unless retention is necessary. |
| Career Bridge | No more than 12 months after matching is disabled or the latest match activity. |
| Security logs | Generally no more than 12 months, longer where required for an investigation or legal claim. |
| Billing and statutory records | For the applicable Belgian statutory retention period. |
| Organisation, OCR and NIS2 records | Under the business agreement, legal duties and agreed retention schedule. |
| Backups | Rotating and generally overwritten within 30 days. |
6. Recommendations and automated processing
The platform calculates recommendations, progress, compliance indicators and Career Bridge matches from submitted data and verified evidence. Results are decision support. The platform does not make solely automated decisions with legal or similarly significant effects. Employers, candidates, curators or organisation administrators remain the decision-makers. You may ask about the main factors and request a review.
7. Your rights
- Access and a copy of your data.
- Correction of inaccurate or incomplete data.
- Erasure where the GDPR permits it.
- Restriction and objection to legitimate-interest processing.
- Portability of data you supplied that is processed automatically under consent or contract.
- Withdrawal of consent without affecting earlier lawful processing.
- Human intervention and contesting any solely automated decision, should one ever be introduced.
Use the available export and deletion controls in account settings or send a request to privacy@lpcyberlaunchpad.com. We normally respond within one month. We may verify your identity and will explain any legal exception.
You may also lodge a complaint with the Belgian Data Protection Authority. Belgian Data Protection Authority.
8. Security and incidents
We use protected storage, row-level security, role-based access, MFA, audit logging and encrypted connections. No system is entirely risk-free. Personal-data incidents are assessed and, where required, reported to the authority and affected people within the statutory deadlines.
9. Changes and contact
We update this statement when features, suppliers or laws change. Material changes will be clearly communicated. Questions and requests can be sent to privacy@lpcyberlaunchpad.com.
Cookie Policy