Privacy Policy
1. Scope
This policy explains how Self-degree processes data for its learning, knowledge-verification, mentoring, exam, roadmap, and organization features. An organization may also have its own privacy notices and agreements with its employees.
2. Data we process
We may process account and organization details; roadmap, skill, quest, exam, and activity data; answers, transcripts, simulator events, uploaded files, recordings, mentor observations, and evaluation rationales; integration identifiers and approved source-system data; and technical, security, and analytics data.
When a person submits a pilot request, we process the contact details and request information they provide so we can respond and scope the requested service. We retain approved first-landing attribution parameters (such as UTM parameters or an advertising click identifier) only with that request. We may use optional Google Ads conversion measurement and product analytics to understand whether an advertisement led to a stored pilot request; those events do not include form answers or contact details.
On localized marketing homepages, we use PostHog to assign a bounded anonymous experiment variant and record a corresponding exposure so we can compare marketing copy. The experiment stores only a random anonymous identifier and its exact assignment in session storage; it does not use the product analytics identifier, local storage, or cookies. This experiment does not use session replay or autocapture; its exposure event excludes page URLs, referrers, campaign parameters, browser data, and device data. An accepted network response confirms HTTP acceptance only and does not establish durable ingestion.
Private organization resources remain visible only to that organization unless an authorized owner publishes them. Public resources may display global ratings, while organization views may also display an organization-specific rating.
3. Why we process it
We use this data to provide and secure the service, personalize learning, generate and run quests, evaluate submitted evidence, identify knowledge gaps, support mentoring, maintain audit history, operate integrations, communicate with users, and understand product performance.
When someone submits a B2B pilot request, we process the contact details, request content, consent record, and limited campaign attribution needed to respond, prevent abuse, and measure the request. Campaign attribution can include UTM parameters and Google click identifiers; it is retained with the request under our operational retention rules. Where enabled, Google Ads receives only a success conversion signal, never form content, contact details, or click identifiers. We use OneSignal to send transactional request acknowledgements and owner alerts; provider acceptance is not a representation that an email reached an inbox.
AI providers may process the minimum context needed to generate, personalize, or evaluate an activity. Provider, model-improvement, residency, and additional processing terms for an enterprise deployment are defined in the applicable organization agreement and connector scope.
4. Employee access and organization visibility
Employees always access their own results and evidence. This self-access cannot be disabled by an organization administrator.
Within an organization, company sharing is the default for a new roadmap. The employee can change a roadmap to private, company-only, or public sharing. Managers are observers. Mentors may review evidence and attest only when they have access. Organization administrators configure other role permissions, subject to mandatory employee self-access.
When an employee makes a roadmap private or the organization relationship ends, the organization immediately loses access to that roadmap and its historical results. The access relationship is removed; the underlying evidence is not rewritten or transferred to the organization.
5. Retention and deletion
Verification evidence and first-attempt decision records are retained indefinitely to preserve a traceable learning history. Later practice attempts may also remain attached to the roadmap. Removing an organization relationship deletes the access relation, not the evidence itself.
Other personal, operational, and analytics data is kept only as needed for the service, security, legal obligations, dispute resolution, and applicable agreements. A user may request access, correction, restriction, export, or deletion where applicable law provides that right. Some deletion requests may be limited by legal obligations or by the evidence-retention behavior described above; we will explain any applicable limitation.
6. Integrations and service providers
Each connector is implemented and scoped for the customer system. Role references, assignments, catalogs, policies, and employment decisions may remain in the source system. Self-degree stores only the agreed learning and verification data and returns only the agreed status, gap, or evidence references.
We may use infrastructure, analytics, communications (including OneSignal for B2B transactional email), authentication, payment, and AI service providers. They process data within the provider boundary under their own terms and our applicable agreements. Data may be processed in countries other than the user's country, subject to applicable transfer requirements.
7. Security
We use reasonable technical and organizational safeguards, access controls, and monitoring. No internet or storage system can guarantee absolute security. Please report suspected unauthorized access promptly.
8. Contact and changes
Privacy rights depend on location. Contact yev@quested.io to ask about access, correction, deletion, an enterprise data-processing agreement, or the providers used for a proposed pilot. Material policy changes will be dated and communicated as required by law or contract.
