Skip to main content
QAVetted
  • How it works
  • Candidate respect
  • Contact

Effective 28 August 2026

Last updated 28 August 2026

Data and privacy

Privacy Notice

This notice explains the information QAVetted collects, why it is used, who receives it, how it is disclosed and protected, and the choices available to prospects, clients, and candidates.

1. Who operates QAVetted

QAVetted is a product operated by Om Testing Academy, an Indian sole proprietorship. General questions can be sent to support@qavetted.com. Access, correction, deletion, objection, or other privacy requests can be sent to data-protection@qavetted.com.

2. The roles we play

  • Candidate assessment data: the hiring organisation that invites a candidate ordinarily decides why and how that candidate's assessment data is used. It acts as controller and QAVetted processes the data to deliver the requested assessment service.
  • Prospect, client-account, support, website, and billing data: the operator decides why and how this information is used and acts as controller.

A candidate should normally contact the hiring organisation first because it controls the assessment and hiring process. If QAVetted receives the request, it forwards it securely to the relevant organisation and assists with the response.

3. Information we process

Public website visitors

This static website has no contact form, account login, advertising tracker, analytics tool, or non-essential cookie. Cloudflare necessarily receives network-request information such as IP address, requested URL, user-agent, time, and security signals to deliver and protect the site.

Prospects and support correspondents

When someone emails QAVetted, we receive the sender's name and email address, organisation and role information they provide, message content, attachments, and correspondence history. People should not send passwords, candidate content, card numbers, identity documents, or other unnecessary sensitive information.

Client accounts

For an approved client, QAVetted may process account identity, work email, organisation, role, assessment configurations, candidate invitations, billing state, subscription and usage records, support history, security events, and account-administration actions. Stripe handles complete payment-card details; QAVetted does not store full card numbers.

Candidates

On behalf of the hiring organisation, QAVetted may process:

  • name, email address, invitation status, and invitation timing;
  • answers to knowledge and behavioural MCQs;
  • practical challenge submissions, workspace artefacts, and test output;
  • criterion scores, cited evidence, strengths, improvements, skill summaries, and AI-assisted evaluation narratives;
  • Candidate AI Assistant interactions when that capability is enabled; and
  • the bounded assessment-activity observations described below.

4. Assessment activity observations

To support assessment integrity and fair review, the assessment page can record when its browser tab becomes hidden or visible, when the browser window loses or regains focus, copy, cut, and paste events on the assessment page, and long periods of inactivity. Clipboard content is not stored; the record states only that an event occurred.

QAVetted does not access a candidate's camera, microphone, screen recording, keystroke content, browsing history, or activity inside another tab or application, and does not collect biometric data. The welcome screen discloses the observations before an assessment starts. Signals provide context to authorised human reviewers and do not automatically reject a candidate.

5. Why information is used

  • to respond to private-preview, product, support, privacy, and contractual enquiries;
  • to review access requests and administer approved organisation accounts;
  • to configure, deliver, secure, evaluate, and support candidate assessments;
  • to provide clients with reviewable results and contextual evidence;
  • to operate trials, subscriptions, usage metering, invoices, refunds, and financial records;
  • to prevent abuse, investigate incidents, maintain reliability, and comply with legal obligations; and
  • to establish, exercise, or defend legal claims when necessary.

Where UK GDPR or EU GDPR applies, the applicable basis may be performance of a contract, steps requested before a contract, legal obligation, or legitimate interests in operating and securing a gated B2B assessment service. QAVetted does not rely on an AI score or integrity signal to make a solely automated hiring decision.

6. AI processing

QAVetted uses Anthropic's API to support assessment-content generation and draft evaluation narratives such as summaries of candidate work, skill evidence, and integrity context. The hiring organisation's reviewer remains responsible for interpretation and every hiring decision. QAVetted does not use candidate or client personal data to train general-purpose AI models.

7. Parties that receive information and how disclosure occurs

QAVetted discloses only the information required for the recipient's service or authorised purpose. Information is transferred through encrypted network connections, authenticated provider integrations, or controlled account access. Providers act under contractual and confidentiality obligations appropriate to their role.

  • Hiring organisation: authorised reviewers receive their invited candidates' assessment submissions, evaluation, and contextual signals through the protected product.
  • Amazon Web Services: application compute, object storage, transactional email, and operational logs in the London region.
  • Supabase: database and authentication services in the London region.
  • Cloudflare: delivery and security of the public website and application edge.
  • Stripe: payment processing, subscription billing, invoices, eligible refunds, and payment-risk controls.
  • Anthropic: API processing for assessment generation and evaluation assistance.
  • Sentry: scrubbed application error and performance information in its European region; QAVetted's scrubber excludes emails, tokens, and authentication headers.
  • Google Workspace: delivery and storage of business email when someone contacts QAVetted.
  • Cal.com: scheduling information only when a person chooses to use a future booking link.
  • Professional and public authorities: limited disclosure to advisers, auditors, banks, tax or regulatory authorities, courts, or law enforcement when reasonably necessary and lawfully authorised.

QAVetted does not sell personal data or disclose it for third-party advertising.

8. International transfers

The operator is based in India and the primary application infrastructure is located in the United Kingdom. Some providers operate globally, including in the United States and European Union. Where a data-protection law requires a transfer safeguard, QAVetted and the relevant client or provider use the applicable contractual or statutory mechanism. Client-specific data-processing and transfer terms are completed before a paid client submits candidate data.

9. Retention

  • Public-site security records: retained by Cloudflare under its service settings and legal obligations.
  • Prospect and ordinary support correspondence: normally up to twelve months after the last substantive contact unless an account, contract, dispute, or legal duty requires longer retention.
  • Raw assessment-activity events: deleted no later than ninety days after the assessment ends, in bounded automatic batches.
  • Assessment results, derived evaluation, submissions, and workspace artefacts: retained for the client-account lifecycle and deleted through the verified account-closure process, subject to the client's instructions and mandatory records.
  • Client-account data: retained until verified account closure and completion of required operational deletion.
  • Billing, tax, and financial records: retained for the period required by applicable law.
  • Operational logs: normally thirty days unless a security incident requires a limited, documented hold.

Deletion from an active system does not imply immediate removal from every encrypted backup. Backup copies expire through the applicable provider's protected retention cycle and are not restored for ordinary product use.

10. Security practices

QAVetted applies encryption in transit and at rest, tenant isolation, role-based and least-privilege access, protected secrets, short-lived capability credentials where appropriate, provider and application logging, bounded retention, and reviewed access to production systems. The static public site sends a restrictive content-security policy and requests no camera, microphone, geolocation, or payment browser capability.

No internet service can guarantee absolute security. A suspected security or privacy incident should be reported to data-protection@qavetted.com without including passwords, tokens, or unnecessary personal data.

11. Rights and choices

Subject to the law that applies, a person may request access, correction, deletion, restriction, objection, portability, consent withdrawal, or information about processing. The request should identify the relationship with QAVetted and the information concerned. We may verify identity and authority before disclosing or changing personal data.

Candidates should contact the hiring organisation that invited them. Clients, prospects, and website correspondents can contact data-protection@qavetted.com. Where UK GDPR applies, a person may complain to the UK Information Commissioner's Office. Where EU GDPR applies, a person may complain to the competent supervisory authority. Rights under applicable Indian law remain available as its provisions take effect.

12. Children

QAVetted is a business hiring service and is not directed to children. A client must not invite a person below the legally permitted working or assessment age without first establishing an appropriate lawful basis and obtaining QAVetted's written agreement.

13. Changes and contact

If the information collected, purpose, recipient, retention, or legal context changes, this page and its effective date are updated. Material changes affecting an existing client are communicated before they take effect where reasonably practicable.

General contact: support@qavetted.com. Privacy and rights requests: data-protection@qavetted.com.

QAVetted

QAVetted is a product operated by Om Testing Academy, an Indian sole proprietorship.

  • Support
  • Privacy
  • Terms
  • Refunds & cancellation