GDPR compliance
Data processing and ownership
During the course of recruiting, our clients need to collect PII (Personally Identifiable Information) from candidates to build a profile and perform an automated evaluation using our assessment chatbot.
When a candidate begins an assessment session initiated by an Testlify client, we store the following information of the candidate on behalf of our client:
- Email address
- Name
- Optional at the client’s discretion: Phone number, the last school attended, academic degree, major, programming experience, resume, and a link to social profiles (GitHub, LinkedIn, etc).
- Metadata collected for proctoring: IP Address, Webcam snapshots, Browser usage data and Session recording data. Some of these data points are optional and collected at client’s discretion.
- If the recruiter uses an Testlify account for inviting candidates to assessments, we store the following information:
- Name
- Email address
- Phone number (Optional)
This data comes under the purview of GDPR. Given that the processing should be fair, Testlify ensures that we obtain consent from candidates when they sign up (using their invited emails to access our assessments). Our updated privacy policy clearly states how we process information in a fair and transparent manner. All the candidate information we receive or collect is handled securely with adequate data protection.
Data subject rights
Under GDPR, individuals have the right to ask the organizations they apply to for the right to portability, rectify and be forgotten. Testlify collects candidates’ data on behalf of our clients, any requests regarding accessing/ editing/ deleting of candidates’ data will be forwarded to our clients. We give our clients the mechanisms to access their candidates’ data and also comply with requests from their candidates. This way, our customers are always in control of their candidate data.
Our client can determine if the candidate’s request is valid and can be fulfilled. We will take action based on the direction provided by our client on how to proceed with any such request.
As a processor, Testlify gives flexibility to our clients to determine their data policies, which offer rights to their candidates. This includes the ability to access / edit/ delete information regarding a candidate. We also give the ability to set a routine data deletion process at a cadence determined by the client.
Data management
Data within Testlify is secured using industry-standard encryption. Data can be transferred outside EU borders if our client and Testlify have entered into a contract that includes contractual clauses specified by EU. Testlify has a standard EU-specific data transfer and processing agreement to ensure compliance with GDPR.
GDPR also stipulates that personally identifiable data should not be stored indefinitely. Testlify’s data retention policy provides flexibility to our client to define how long their candidates’ PII should be stored and when it should be deleted. Data is stored for the duration of the contracted period with our client, and a grace period thereafter.
Testlify maintains a detailed audit log of all the activities. As part of compliance, Testlify will add any additional activities that our clients need to be recorded. These logs are viewable in our dashboard or can be requested for export/ deletion by contacting us at [email protected].
Data breach and mitigation process
We have sufficient data monitoring mechanisms in place to become aware of any data breach. In case a personal data breach occurs, we will send breach notifications in accordance with our internal incident response policy (within 72 hours of us discovering the breach). This will give sufficient time for our clients to convey the breach to the respective authorities. Additionally, we will notify users through our blogs and social media for general incidents. We will notify the concerned party through email (using the primary email address) for incidents specific to an individual user or an organization.
Infrastructure
Protecting our customers’ information and their users’ and candidates’ privacy is extremely important to us. As a cloud-based company entrusted with some of our customers’ most valuable data, we’ve set high standards for security.
Testlify has invested heavily in building a robust security team, one that can handle a variety of issues – everything from threat detection to building new tools. In accordance with GDPR requirements relating to security incident notifications, Testlify will continue to meet its obligations and offer contractual assurances.
If you’d like to learn more about Testlify’s security policies and procedures, please see our security page. It provides detailed information on how we approach security, and includes a white paper on how Testlify ensures user data security in particular, including our technical and organisational measures(TOMs), as well as our encryption standards.