CodeOath

Privacy Policy — DRAFT

Last updated: [date]. This is a first draft for CA/lawyer review — do not publish as final without that review.

[Company Legal Name] ("we", "us", "the Platform") operates a technical screening platform used by companies ("Customers") to assess job candidates ("Candidates"), along with a public learning site (blog and practice tools). This policy explains what personal data we collect from each group, why, and what rights you have over it.

1. Who this applies to

2. What we collect

Candidates

Name, email, submitted code/answers, scores, IP address, device/browser metadata, timestamps, and (where enabled) anti-cheat signals (tab-switch/copy-paste events). Full detail and purpose is in the Candidate Consent Notice, shown before every assessment.

Customer users

Name, work email, company name, billing contact and payment details (processed by our payment provider, not stored by us directly), and usage data (which assessments were created, invited, and reviewed).

Website visitors

Standard analytics data (page views, referrer, approximate location from IP, device type) via privacy-respecting analytics. No assessment-related personal data is collected from anonymous visitors.

3. Why we process this data (legal basis)

4. Who we share it with

We do not sell personal data to third parties, and we do not use candidate assessment data for advertising or profiling purposes.

5. Where data is stored

[State region(s) — e.g., "Primary hosting is in [region], with some infrastructure providers operating in the United States/EU."] See §5 of data-retention-policy.md for the cross-border transfer note.

6. How long we keep it

See data-retention-policy.md for the full retention schedule by data category.

7. Your rights

Depending on your location, you may have rights under India's Digital Personal Data Protection Act 2023 and/or the EU GDPR, including the right to access, correct, delete, or port your data, and to withdraw consent. To exercise any of these, contact our Grievance Officer at [grievance-officer@yourcompany.com]. We will acknowledge requests within [3] business days.

If you're not satisfied with our response, Indian data principals may approach the Data Protection Board of India; EU data subjects may approach their local supervisory authority.

8. Cookies

We do not use analytics or tracking cookies of our own. Once Google AdSense is active on this site, Google and its advertising partners may set cookies to serve and measure ads. On your first visit, a banner lets you choose:

Your choice is stored in your browser only (not on our servers) and you can change it any time by clearing your browser's local storage for this site. See Google's own policies for how it uses advertising cookies: policies.google.com/technologies/ads.

9. Children's data

This platform is intended for use in employment/hiring contexts and is not directed at, or knowingly used to collect data from, children under 18.

10. Security

We apply technical and organizational measures appropriate to the sensitivity of the data we hold, including [encryption in transit (TLS), access controls, and sandboxed code execution — see ../security/sandbox-hardening-checklist.md for the code-execution-specific measures]. No system is perfectly secure; see our breach-notification commitment in vendor-dpa-template.md for what happens if that ever changes.

11. Changes to this policy

We'll post any material changes here with an updated "Last updated" date, and notify active Customers by email for changes that affect how their candidates' data is handled.

12. Contact

[Company Legal Name] [Registered address — once business entity is registered] [grievance-officer@yourcompany.com]