CodeOath

Candidate Consent Notice — DRAFT

Shown to a candidate before an assessment starts. Must be actively accepted (checkbox, not pre-ticked) — not buried inside a longer signup or ToS flow. Per DPDP Act requirements, consent must be specific, informed, and unambiguous per data type, not one blanket "I agree."


Before you begin

[Company Legal Name] ("we", "us", the "Platform") has been asked by [Hiring Company Name] to run a technical assessment as part of your job application. Before you start, here's exactly what happens to your data.

What we collect

DataWhy we collect it
Name and email addressProvided by the hiring company to invite you; used to identify your results to them
Code, answers, and responses you submit during the testThis is the assessment itself — it's what gets scored
Your score and a breakdown of correct/incorrect answersShared with the hiring company to inform their decision
IP address, browser/device information, and timestampsSecurity and integrity — detecting shared/proxied sessions, confirming when the test was taken
[If enabled] Tab-switch or copy-paste events during the testAnti-cheat — flagged for the hiring company's review, not used to auto-disqualify you

We do not collect anything beyond what's listed above unless a specific test explicitly asks for it (and if it does, that request will say so separately).

Who sees this data

How long we keep it

By default, your assessment data (code, answers, scores, security logs) is kept for [180] days after the assessment, then permanently deleted, unless:

See data-retention-policy.md for the full schedule.

Your rights

Under India's Digital Personal Data Protection Act (and GDPR, if you're in the EU), you can:

Consent

Please confirm each of the following individually:

By clicking "Start Assessment," you confirm all boxes above have been checked and you consent to the processing described here.


Implementation note: each checkbox must be independently required (not one master checkbox) and the consent event (timestamp, IP, which boxes were checked, notice version shown) should be logged server-side as proof of consent — this is what you'd need to produce if a candidate or the Data Protection Board ever asks how consent was obtained.