Privacy Policy
Straightforward about how we handle your data.
Candidate data carries real weight — it influences hiring decisions and careers. This policy explains what information AssessIQ collects, why we collect it, how it is used, and what rights data principals have under India's Digital Personal Data Protection Act 2023.
Who we are
AssessIQ and the organisation operating it.
AssessIQ is a candidate and team assessment platform. It allows organisations to create, administer, and grade assessments for hiring, internal evaluation, and skill-gap analysis.
The platform is operated by AssessIQ, based in India at Bommanahalli, Bangalore 560068, India. References to "AssessIQ", "we", "us", or "our" in this policy refer to that entity.
Information we collect
What data we process, and where it comes from.
Candidate data
Name, email address, and assessment responses are collected when a candidate accepts an invitation to take an assessment. Where proctoring is enabled by the hiring organisation, this also includes webcam footage or screenshots, device and browser metadata (operating system, browser version, screen resolution), and IP address. Proctoring is always disclosed to the candidate before the assessment begins.
Admin and account data
When a company administrator or reviewer logs in to AssessIQ, we process their name, work email address, and role within the platform. Administrators are invited by their organisation; they do not self-register through a public sign-up flow.
Usage and platform logs
We maintain server logs of platform activity — page loads, API requests, errors — for security monitoring and debugging. Logs include IP addresses and timestamps. These are retained for a limited operational period and are not used for analytics or marketing profiling.
What we do not collect
We do not collect payment card details (billing is handled by a third-party payment processor). We do not collect sensitive personal data — such as caste, religion, health status, or financial account numbers — and our assessment packs are reviewed to avoid questions that solicit such information.
How we use data
Purpose-limited processing.
Delivering and grading assessments.
Candidate data is used to administer the assessment the candidate was invited to take and to produce a scored result. Grading is performed on behalf of the hiring organisation. The result and any rationale are made available to that organisation's administrators and assigned reviewers.
Generating reports for the hiring organisation.
Assessment outcomes, band scores, and supporting rationale are compiled into reports that the hiring organisation uses to make hiring or evaluation decisions. We do not add our own interpretation beyond what the rubric produces.
Platform security and support.
Usage logs and metadata are used to detect abuse, investigate reported incidents, and respond to support requests. Data is not used for behavioural advertising, sold to data brokers, or shared with third parties for their independent marketing purposes.
Legal basis
India DPDP Act 2023 and our role in processing.
India's Digital Personal Data Protection (DPDP) Act 2023 governs the processing of digital personal data of individuals in India. AssessIQ operates in this framework in two capacities depending on context.
For candidate data, the hiring organisation (the company or institution that invited the candidate) is the Data Fiduciary — it determines the purpose of the assessment and bears primary obligations to the data principal under the Act. AssessIQ acts as a Data Processor, processing candidate data only on that organisation's instructions and for the purpose of delivering the assessment.
For administrator account data, AssessIQ acts as a Data Fiduciary with respect to the personal data of the administrators it onboards on behalf of their employer organisations.
In both cases, processing is purpose-limited: candidate data is processed to conduct and grade the assessment; it is not repurposed for unrelated activities. We continue to monitor DPDP rulemaking as subsidiary rules and guidance are issued under the Act.
Data residency
Assessment data stored in India.
All assessment data, candidate records, proctoring footage, and attempt logs are stored on India-region infrastructure. We do not route personal data through overseas servers for routine processing. Where a sub-processor is involved (for example, a transactional email provider), that sub-processor is contracted to handle data in a manner consistent with our obligations and does not retain personal data beyond the transaction. See the security page for the full infrastructure posture.
Data sharing
Who can see candidate data.
The hiring organisation.
The organisation that invited a candidate to take an assessment can view that candidate's result, band score, and supporting rationale. Access within the organisation is further limited by role: reviewers see only the assessments assigned to them; administrators see all assessments within their tenant. No organisation can see data belonging to another.
Sub-processors under contract.
We use a small number of infrastructure and operational sub-processors — hosting, transactional email — each under a data processing agreement that limits their use of data to providing the contracted service. We do not authorise sub-processors to use personal data for their own purposes.
We do not sell data.
Candidate data, assessment responses, and account data are never sold to third parties, shared with data brokers, or used for advertising profiling. Disclosure to law enforcement or regulatory authorities occurs only where required by applicable law and, where permitted, after notifying the relevant Data Fiduciary.
Cookies & sessions
Essential cookies, plus marketing analytics.
AssessIQ uses session cookies solely to maintain a logged-in state during a platform session. These cookies are essential for the platform to function — without them, neither candidates nor administrators can authenticate.
On the assessment and administration application we run no third-party analytics, advertising, or session-recording scripts — no Google Analytics, no Meta Pixel, or anything equivalent. The only cookies there are the essential session cookies described above.
This public marketing website uses Microsoft Clarity, a product-analytics tool that provides aggregate traffic insights, heatmaps, and masked session replays to help us improve the site. Clarity sets first-party analytics cookies (_clck and _clsk) and is configured to mask text input, so it does not record what you type. Clarity is not loaded on the assessment or administration application, and no candidate assessment data is ever processed by it. See the Microsoft Privacy Statement for Microsoft's practices.
Data retention
Kept as long as needed, no longer.
Candidate data is retained for the lifecycle of the assessment engagement and for as long as the hiring organisation's account remains active on the platform. When a customer terminates their contract, candidate data associated with their account is deleted or anonymised within a reasonable period, subject to any legal hold obligations.
Organisations can request deletion of specific candidate records at any time via the admin interface or by contacting us. We will fulfil deletion requests subject to any mandatory retention period required by applicable Indian law.
Server and audit logs are retained for a defined operational period for security and compliance purposes and are then purged.
Your rights
Rights of data principals under the DPDP Act.
Access
You have the right to know what personal data is held about you, the basis on which it is processed, and who it has been shared with. Requests should be directed to the hiring organisation that administered your assessment, as it is the Data Fiduciary for that data. We will support the organisation in responding.
Correction
You have the right to request correction of inaccurate or incomplete personal data. If your name or contact details recorded in the platform are incorrect, contact the hiring organisation or reach us at the grievance address below.
Erasure
You have the right to request erasure of your personal data where the purpose of processing is fulfilled and no legal obligation requires retention. Erasure requests are processed in accordance with the DPDP Act and subject to any applicable legal hold.
Grievance redressal
You have the right to raise a grievance about how your personal data has been handled. See the grievance-redressal section below for contact details. We aim to acknowledge grievances within 48 hours and resolve them within the period prescribed under the DPDP Act.
Grievance redressal
How to raise a complaint.
If you have a grievance about how your personal data has been handled — consistent with the grievance-redressal expectations of the Digital Personal Data Protection Act 2023 — you can reach us using the details below:
Email:
[email protected]
Organisation: AssessIQ
Address: Bommanahalli, Bangalore 560068, India
Grievances should be submitted in writing with a clear description of the concern, the data involved, and the relief sought. We will acknowledge receipt and respond within the period prescribed by applicable law.
Eligibility
Not directed at children under 18.
AssessIQ is a professional and institutional assessment platform. It is not directed at children under the age of 18. We do not knowingly process the personal data of children in a consumer context.
Where an educational institution administers assessments to students who may be under 18, it is the institution's responsibility — as Data Fiduciary — to ensure that appropriate parental or guardian consent is obtained in accordance with the DPDP Act and any applicable institutional policy before inviting those students to take an assessment on the platform.
Policy updates
Changes to this policy.
We may update this policy as the platform evolves, as regulatory guidance under the DPDP Act develops, or as our data practices change. Material changes will be communicated to active account holders via the email address on record. The updated policy will be published at this URL with a revised effective date.
Continued use of the platform after a material change constitutes acceptance of the revised policy. If you do not accept the revised terms, you should cease using the platform and contact us to request deletion of your data.
Effective date: May 2026
Questions about how we handle your data?
If you have a specific privacy or data-protection question — about your candidate data, our DPDP Act posture, or a deletion request — reach out. We'll give you a plain answer.
Related policies