See what's new

Testlify

Legal.

GDPR compliance

1. Data processing and ownership

During the course of recruiting, our clients need to collect PII (Personally Identifiable Information) from candidates to build a profile and perform an automated evaluation using our assessment chatbot.

When a candidate begins an assessment session initiated by a Testlify client, we store the following information of the candidate on behalf of our client: email address; name; optionally, at the client's discretion, phone number, the last school attended, academic degree, major, programming experience, resume, and a link to social profiles (GitHub, LinkedIn, etc.); and metadata collected for proctoring, including IP address, webcam snapshots, browser usage data, and session recording data (some of these data points are optional and collected at the client's discretion). If the recruiter uses a Testlify account for inviting candidates to assessments, we store the recruiter's name, email address, and phone number (optional).

As Testlify operates under the scope of GDPR, we are committed to fair and transparent data processing. Candidates are informed of our Terms of Use and Privacy Policy at the time of sign-up, and their continued use of the platform constitutes consent. Our updated privacy policy outlines how candidate data is collected, processed, and protected in compliance with applicable laws. All information is handled securely, with robust safeguards to ensure data protection throughout the assessment process.

2. Data subject rights

Under GDPR, individuals have the right to ask the organizations they apply to for the right to portability, rectification, and erasure. Testlify collects candidates' data on behalf of our clients; any requests regarding accessing, editing, or deleting candidates' data will be forwarded to our clients. We give our clients the mechanisms to access their candidates' data and also comply with requests from their candidates. This way, our customers are always in control of their candidate data.

Our client can determine if the candidate's request is valid and can be fulfilled. We will take action based on the direction provided by our client on how to proceed with any such request.

As a processor, Testlify gives flexibility to our clients to determine their data policies, which offer rights to their candidates. This includes the ability to access, edit, or delete information regarding a candidate. We also give the ability to set a routine data deletion process at a cadence determined by the client.

3. Data management

Data within Testlify is secured using industry-standard encryption. Data can be transferred outside EU borders if our client and Testlify have entered into a contract that includes contractual clauses specified by the EU. Testlify has a standard EU-specific data transfer and processing agreement to ensure compliance with GDPR.

GDPR also stipulates that personally identifiable data should not be stored indefinitely. Testlify's data retention policy provides flexibility to our client to define how long their candidates' PII should be stored and when it should be deleted. Data is stored for the duration of the contracted period with our client, and a grace period thereafter.

Testlify maintains a detailed audit log of all activities. As part of compliance, Testlify will add any additional activities that our clients need to be recorded. These logs are viewable in our dashboard or can be requested for export or deletion by contacting us at support@testlify.com.

4. Data breach and mitigation process

We have sufficient data monitoring mechanisms in place to become aware of any data breach. In case a personal data breach occurs, we will send breach notifications in accordance with our internal incident response policy (within 72 hours of us discovering the breach). This will give sufficient time for our clients to convey the breach to the respective authorities. Additionally, we will notify users through our blogs and social media for general incidents. We will notify the concerned party through email (using the primary email address) for incidents specific to an individual user or an organization.

5. Infrastructure

Protecting our customers' information and their users' and candidates' privacy is extremely important to us. As a cloud-based company entrusted with some of our customers' most valuable data, we've set high standards for security.

Testlify has invested heavily in building a robust security team, one that can handle a variety of issues, everything from threat detection to building new tools. In accordance with GDPR requirements relating to security incident notifications, Testlify will continue to meet its obligations and offer contractual assurances.

If you'd like to learn more about Testlify's security policies and procedures, please see our Security page. It provides detailed information on how we approach security, and includes a white paper on how Testlify ensures user data security, including our technical and organisational measures (TOMs) and our encryption standards.

6. Data removal request

To request removal of your candidate data, email us at support@testlify.com with your name, email address, and details of your request, and we will route it to the relevant client for action.

Frequently asked questions

Make a data protection request

Tell us what you need and our privacy team will respond within the statutory period.

Questions about this policy?.

Talk to our team

See how Testlify's platform, security, and compliance posture fit your hiring process.

We use cookies to enhance your browsing experience, serve personalised ads or content, and analyse our traffic. By clicking "Accept All", you consent to our use of cookies.