Trust Center
Effective date: September 1, 2025 · Last updated: September 6, 2026
Use this page for procurement and security reviews: how we process candidate and customer data, which sub-processors we use, high-level technical and organizational measures, and a downloadable Data Processing Agreement.
This policy applies to the TestnHire talent assessment and hiring platform (including the web application, candidate assessment experience, employer dashboards, job board workflows, and related support channels), and to personal data we process for employer customers, hiring managers, candidates invited to assessments, and authorized account users. It covers data processed in connection with those services in the regions where TestnHire is deployed (including configurable primary hosting regions such as the United States and European Union for enterprise customers) and the sub-processors listed on this page.
Data Processing Agreement (DPA)
You can read the full agreement for procurement and legal review.
Security at a glance
- Inventory and due diligence on sub-processors that process personal data
- Contractual DPAs and standard contractual clauses where applicable
- Enterprise security questionnaires and SOC 2 materials available under NDA on request
Your account team can provide SOC 2 reports, completed questionnaires, and organization-specific terms under NDA where required.
Privacy & data-handling summary
The sections below summarize data collected, why we process it, legal bases, sharing, retention, and user rights for the TestnHire services described in the scope statement. For the full legal text, see our Privacy Policy and Data Processing Agreement.
Data collected
Depending on how you use TestnHire, we may collect and process the following categories of personal data:
- Account and profile data: name, work email, company name, role, password credentials, and account preferences for employers and authorized users.
- Candidate assessment data: name, email, assessment responses, scores, proctoring signals where enabled, and related hiring workflow metadata provided by the inviting employer.
- Job and hiring content: job descriptions, assessment configurations, invites, and communications needed to run hiring workflows.
- Billing and commercial data: billing contact details, plan selection, invoices, and payment-related records processed through our payment provider (card data is handled by the processor under PCI-DSS).
- Usage and device data: IP address, browser type, approximate location derived from IP, log files, and product analytics needed to operate, secure, and improve the service.
- Support data: contact details and case content you share when you contact TestnHire support.
Purpose of processing
We process personal data to operate the TestnHire platform and related services, including to:
- Create and manage employer and candidate accounts and authenticate users.
- Deliver skill assessments, scoring, reports, and hiring workflows requested by customers.
- Send transactional messages such as invites, reminders, password resets, and service notices.
- Process subscriptions, billing, and customer support requests.
- Maintain security, prevent abuse, troubleshoot incidents, and improve product reliability.
- Meet legal, accounting, and compliance obligations, and respond to lawful requests.
Legal basis
Where GDPR, UK GDPR, or similar laws apply, we rely on one or more of the following legal bases:
- Contract: processing needed to provide the service under our customer agreement or to take steps at a user’s request before entering a contract.
- Legitimate interests: operating, securing, and improving the platform, preventing fraud or misuse, and communicating about the service in ways that do not override individuals’ rights.
- Legal obligation: processing required to comply with applicable law, regulation, or lawful requests.
- Consent: where we ask for consent (for example certain cookies or optional marketing), you may withdraw consent at any time without affecting prior lawful processing.
When we process candidate assessment data on behalf of an employer customer, the customer typically acts as controller and TestnHire acts as processor under our Data Processing Agreement.
Sharing and disclosures
We do not sell personal data. We share personal data only as needed to provide the service or as required by law:
- With sub-processors that host, email, bill, support, monitor, or power optional AI features, under contracts that require appropriate confidentiality and data-protection safeguards (see the sub-processor list below).
- With the employer customer that invited a candidate, so they can review assessment results and continue their hiring process.
- With professional advisors (such as legal or auditors) under confidentiality obligations where reasonably necessary.
- With authorities or other parties when required by law, legal process, or to protect rights, safety, and security.
- In connection with a corporate transaction (merger, acquisition, or asset sale), subject to appropriate protections.
Retention
We retain personal data only as long as needed for the purposes described on this page, including to provide the service, meet legal and accounting requirements, resolve disputes, and enforce agreements.
- Account and billing records are generally kept for the life of the customer relationship and for a limited period afterward as required for audits, tax, and legal claims.
- Assessment and candidate records are retained according to the customer’s configuration and our DPA, then deleted or anonymized when no longer needed or when a valid deletion request is completed.
- Support tickets and security logs are retained for operational, security, and compliance needs, then deleted or aggregated on a rolling schedule.
- When retention ends, we delete or irreversibly anonymize personal data, except where longer retention is required by law.
User rights
Depending on your location and role (candidate, employer user, or website visitor), you may have rights to:
- Access the personal data we hold about you and receive a copy in a portable format where applicable.
- Correct inaccurate or incomplete personal data.
- Request deletion of personal data, subject to legal or contractual retention requirements.
- Object to or restrict certain processing, and withdraw consent where processing is based on consent.
- Opt out of non-essential marketing communications.
- Lodge a complaint with a supervisory authority if you believe processing violates applicable law.
To exercise these rights, contact us at info@testnhire.com or through your employer if your data was submitted for an assessment they administered. We may need to verify your identity before fulfilling a request. For full privacy terms, see our Privacy Policy.
Technical & organizational measures (TOMs)
Summary of controls we apply to protect confidentiality, integrity, and availability of data.
Encryption
Data in transit protected with TLS. Sensitive data at rest encrypted using industry-standard algorithms and key management practices appropriate to the environment.
Access control
Role-based access to production systems; principle of least privilege; administrative actions logged and reviewed.
Authentication
Strong password policies for customer accounts; multi-factor authentication (MFA) supported for administrator and sensitive operations where the product provides it.
Organization & governance
Security-conscious development practices, dependency and change management, and vendor review for sub-processors that handle personal data.
SOC 2 readiness
Controls and documentation aligned toward SOC 2 Type II; formal attestation may be shared under NDA as your security review progresses.
Sub-processor list
Third parties that may process personal data in connection with the service.
| Sub-processor | Purpose | Categories of data | Region / notes |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, storage, compute, databases, and CDN for the TestnHire platform and candidate data. | All platform data including account, assessment, and candidate content as processed by the service. | Configurable (e.g. primary region aligned with deployment; EU/US options for enterprise). |
| OpenAI (or equivalent LLM provider) | Optional AI-assisted features such as grading explanations, summarization, or content generation where enabled. | Content submitted to those features (e.g. responses, job text) per product configuration; minimized where possible. | Per vendor sub-processors and enterprise terms (e.g. US/EU data processing options). |
| SendGrid / Twilio SendGrid | Transactional email (invites, notifications, password resets, product communications). | Email addresses, message metadata, and content required to deliver email. | Typically United States; DPA available from vendor. |
| Payment processor (e.g. Stripe) | Billing, subscriptions, and payment processing where applicable. | Billing contact and payment-related records; card data handled per PCI-DSS by the processor. | Per processor and merchant configuration. |
| Analytics & monitoring (e.g. privacy-conscious analytics) | Product usage and reliability metrics to improve service quality. | Aggregated or pseudonymous usage data as configured to limit personal data. | Typically global edge; configurable for enterprise deployments. |
| Support & ticketing (e.g. Zendesk, Intercom, or similar) | Customer support, helpdesk, and issue resolution. | Contact details and case content you share with support. | Per vendor region selection. |










