GDPR Compliance at TestTrick
Protecting Your Data, Empowering Your Rights
Last updated: 23-7-2025
TestTrick is fully committed to complying with the General Data Protection Regulation (GDPR) (EU Regulation 2016/679), which governs how personal data of individuals in the EU and EEA must be handled. Whether you're a recruiter using our platform or a candidate taking an assessment, your privacy and data rights are our priority.
Our Role Under GDPR
- • Customers (employers/recruiters) are the Data Controllers
- • TestTrick acts as the Data Processor
We process candidate data strictly under the instructions of our customers and never for our own purposes.
How We Help You Stay Compliant
We've built features and policies aligned with GDPR:
- • ✅ Data Processing Agreement (DPA) available for all customers
- • ✅ Consent controls before candidate assessments begin
- • ✅ Custom data retention settings
- • ✅ Tools to export, delete, or anonymize candidate data
- • ✅ Secure data hosting with encryption at rest and in transit
- • ✅ Audit logs and traceability of data actions
- • ✅ Support for all data subject rights (access, erasure, portability, etc.)
Candidate Rights We Support
As required by GDPR, TestTrick enables candidates to:
- • Access their data
- • Correct or update personal details
- • Request deletion ("Right to be Forgotten")
- • Export their information in a machine-readable format
- • Object or restrict certain processing
Candidates may contact the company that invited them or email us at privacy@testtrick.com. We act based on customer direction.
Data Security
We keep data safe through:
- • ISO-grade cloud infrastructure
- • TLS encryption
- • Role-based access controls
- • 2FA for internal access
- • Regular audits and monitoring
Data Breach Protocol
In case of a breach, TestTrick:
- • Notifies affected customers within 24 hours
- • Assists with regulatory reporting (within 72 hours)
- • Documents full incident response and resolution
Cross-Border Data Transfers
Data may be hosted outside the EU. All transfers follow Standard Contractual Clauses (SCCs) or equivalent safeguards.
TestTrick's Commitment to GDPR
Our commitment to GDPR is not a checkbox—it's a foundation of trust and data ethics.
- • We treat candidate data as sacred
- • We empower our customers with control
- • We provide product features that support full compliance
- • We ensure subprocessors meet our privacy standards