1. Information We Collect
At KafaVerify (kafaverify.com), we collect information necessary to deliver automated candidate assessment and verification services:
- Account Information: Name, business email, company name, phone number, and billing credentials when you create a recruiter account.
- Candidate Assessment Data: Candidate name, email, submitted code solutions, answer choices, and test scores submitted during screening sessions.
- Proctoring Telemetry: Browser focus events (tab-switches), fullscreen mode flags, and optional webcam verification snapshots strictly for candidate authentication when authorized by the testing employer.
- Payment Information: All payment transactions are securely processed by Dodo Payments. We do not store raw credit or debit card numbers on our servers; card details are tokenized directly with PCI-DSS compliant payment gateways.
- Log & Device Data: IP addresses, browser types, session timestamps, and diagnostic error logs to maintain system performance and prevent abuse.
2. How We Use Your Information
We use collected data solely for legitimate business purposes:
- To authenticate recruiter accounts and manage technical assessment pipelines.
- To compile and score candidate test submissions using our automated execution engines.
- To process subscription payments and issue billing receipts through Dodo Payments.
- To provide customer support and respond to inquiries within our guaranteed turnaround times.
- To detect, prevent, and mitigate security threats, cheating attempts, or malicious code injections.
We NEVER sell, rent, or trade your personal data or candidate resumes to third parties or advertising networks.
3. Data Security & Encryption
We enforce enterprise-grade security standards across all layers of our application architecture:
- All data in transit is encrypted using TLS 1.3 / 256-bit SSL encryption.
- Candidate code execution runs inside isolated, sandboxed Docker containers with strict resource and network isolation.
- Database records are stored with multi-tenant company scoping, ensuring organization records are never leaked across companies.
- Access to production databases is restricted to authorized engineers under strict multi-factor authentication.
4. Cookies and Session Management
We use strictly necessary cookies and localized browser storage (such as authentication tokens and language preferences) to keep you securely signed in and preserve your workspace settings. We do not employ third-party tracking cookies or behavioral advertising trackers.
5. Candidate Rights & GDPR Compliance
Under applicable data protection regulations (including the EU GDPR and UK Data Protection Act), candidates and users possess specific legal rights:
- Right to Access: You can request a copy of the personal assessment data held in our systems.
- Right to Rectification: You can correct inaccurate personal details.
- Right to Erasure (Right to be Forgotten): You can request the permanent deletion of your assessment records and personal data.
- Right to Restrict Processing: You can request limits on how your personal data is utilized.
To exercise any of these rights, please email our Data Protection officer at privacy@kafaverify.com.
6. Third-Party Service Providers
We partner with trusted, industry-leading vendors to operate our cloud infrastructure:
- Payment & Merchant Processing: Dodo Payments (PCI-DSS Level 1 Compliant).
- Cloud Hosting & Compute: Secure data centers located in compliance with international cloud standards.
- Transactional Email: Enterprise email delivery providers with SPF and DKIM authentication for invitation dispatch.
7. Contact Data Protection Officer
If you have questions or concerns regarding our privacy practices, please contact us:
KafaVerify Privacy & Compliance
Website: kafaverify.com
Privacy Email: privacy@kafaverify.com
General Support: support@kafaverify.com