Corporate Privacy Policy
1. Candidate Confidentiality & AI Processing
TestByAI ("we", "our", or "the Platform") provides B2B automated candidate resume ranking and shortlisting software for corporate recruiters, talent acquisition teams, and hiring managers.
Strict No-Training Policy: Candidate resumes, personal identifiable information (PII), job descriptions, and recruiter notes processed through TestByAI are NEVER used to train, retrain, fine-tune, or improve public or proprietary foundation artificial intelligence models.
All AI evaluations are executed through enterprise-tier, zero-data-retention AI endpoints with ephemeral processing memory.
2. Data Collection & Processing Architecture
A. Client-Side Document Extraction
Resume PDF files are parsed locally within the recruiter's web browser using client-side WebAssembly text extraction. Unstructured binary PDF files are not permanently uploaded to our document stores, minimizing data exposure.
B. Candidate Resume Content
Only the extracted textual representation of candidate qualifications (experience, education, skills, certifications) is transmitted encrypted over TLS 1.3 to perform real-time compatibility scoring against your specified job description.
C. Recruiter Account & Payment Data
We collect basic business identity data required for service operation:
- Account Credentials: Corporate email address, authentication identifiers, and login timestamps.
- Credit & Billing Data: Transaction records and purchased credit balances. Payment card processing is managed directly by Stripe Inc. under PCI-DSS Level 1 compliance; we never store card numbers.
- Scan History: Up to 50 recent ranking evaluations are retained in your secure database partition to allow recruiter report export and review. Older scans are automatically purged via FIFO sliding window.
3. Roles Under GDPR & CCPA (Data Processor Agreement)
For the purposes of the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and applicable international data protection statutes:
- Customer as Data Controller: You (the employer, recruiter, or staffing organization) determine the legal basis and purposes for evaluating candidate resumes.
- TestByAI as Data Processor / Service Provider: We process candidate data exclusively upon your instruction to generate candidate scores, justifications, and exportable reports.
4. Data Security & Storage
All customer workspaces and evaluation history are hosted on SOC 2 and ISO 27001 certified Google Cloud Platform infrastructure. Protections include:
- Encryption in Transit: Strict HTTPS / TLS 1.3 encryption across all client and API interactions.
- Encryption at Rest: AES-256 encryption on all persistent Firestore database records.
- Access Control: Granular row-level security ensuring recruiters can only access scans associated with their authenticated UID.
5. Data Deletion & User Rights
Recruiters maintain complete control over their evaluation history:
- Instant Scan Deletion: Clicking "New Scan" or resetting history immediately disassociates active ranking data.
- Account Termination: Upon account closure, all associated scan history, credits, and profile records are permanently purged within 30 days.
6. Contact & Data Protection Office
For inquiries regarding enterprise compliance, Data Processing Agreements (DPA), or candidate data inquiries, contact our Privacy Officer at: contact.testbyai@gmail.com.