Privacy notice for APV Skills
We sign you in via Slack so you can use APV Skills. That involves processing personal
data. What we process, why, and what rights you have — in short form.
Controller
AlphaPet Ventures GmbH. APV IT-Apps is responsible for this application. For questions or to
exercise your rights, contact the IT-Apps team or the data protection officer.
Purposes and legal basis
We process your sign-in data in order to
- restrict access — only people in the APV Slack workspace and explicitly
approved external collaborators may use the marketplace;
- attribute contributions — to keep it traceable who contributed a skill or
last changed it;
- offer standards-based, per-person access instead of one token shared by
everyone.
The legal basis is our legitimate interest under Art. 6(1)(f) GDPR (governance,
security and maintainability of a company-wide tool). We are not asking for your
consent — the confirmation below is solely an acknowledgement that you have read this notice.
What data
From your Slack profile: Slack user ID, work email address, name and the
workspace ID. The "email verified" flag is evaluated for the check only and not stored. A
profile picture is deliberately not included. No performance or
behavioural profile is created; marketplace usage statistics do not identify
individuals.
Who receives the data
- Slack — performs the sign-in.
- APV infrastructure (EU) — the marketplace is self-hosted in the APV Docker
Swarm.
- GitLab (APV) — when you share a skill, you are recorded as its author in
the skill file and shown in the catalog by name.
- The client you connect with — see below.
Where your data is processed
Signing in issues an access token that identifies you: it carries your name and
your email address. Where that token is then held and processed depends entirely on the client or
agent you use to reach the marketplace. A locally installed client keeps it on your own device; a
hosted or cloud-based one keeps it on its provider's infrastructure, which may be located
outside the EU/EEA. Which client you connect with is your own choice, and that
processing takes place under that provider's terms rather than ours. Please take this into
account when deciding how to connect.
Retention
Access tokens are short-lived; refresh tokens and the browser session expire after a defined
period. The authorship recorded on a skill is kept indefinitely — that is
the point of attribution. On objection it is deleted or anonymised.
Your rights
You have the right of access, rectification, erasure, restriction of processing and data
portability, as well as the right to lodge a complaint with a supervisory authority. To exercise
them, contact APV IT-Apps or the data protection officer.
Right to object (Art. 21 GDPR)
You may object at any time to processing based on our legitimate interest,
with effect for the future and without any disadvantage to you. Following an objection we will
stop processing the data concerned unless there are compelling legitimate grounds to the
contrary; authorship already published is deleted or anonymised.
Address your objection to APV IT-Apps or to the data protection officer.
Version: 2026-08-05-en