Candidate data is borrowed data. We collect as little of it as we can.

An assessment runs on data collected at one of the more vulnerable moments in a working life. So we collect as little of it as we can, keep it for as short a time as we can, and never use it for anything else.

Candidate data is borrowed data.

KVKK and GDPR alignment

Our processes are designed to align with KVKK and GDPR: a clear privacy notice, explicit consent and a strictly limited processing purpose. We hold no independent certification yet, and we do not claim one we do not have.

Candidate rights

A candidate can access their own report, ask for corrections and request deletion. A deletion request covers the transcript, the scores and the evidence quotes together.

No training on customer data

Candidate transcripts and report content never train any model. This is not a policy preference but an architectural rule: assessment data is never carried into a training pipeline.

Access control and audit trail

A report is reachable only by the users assigned to that hiring process. Who opened which report and when is recorded, and exported as an audit log on the enterprise plan.

Data residency and retention

Hosting is offered in the European Union or in Türkiye. Retention is set in the contract, and records are deleted once the period ends.

Read our wording closely

Where this page says “designed to align with”, that is precisely what we mean. When we pass an independent audit, the certificate number will appear here alongside it.

Ready for your security review. The questions get answered before the call, not after it.

Send your information security team's questionnaire ahead of time and we come to the call with the answers.

Or leave us a short message: Contact form

Security and privacy — Sezra