A candidate's face, voice and ID are the most sensitive data a company will ever hold about someone who does not work there yet. This page covers how we protect that data: the frameworks and certifications we hold ourselves to, the controls we run every day, and the documents your security team can request.
Industry-standard encryption for data at rest and in transit, role-based access controls, and per-feature data minimisation — each product feature processes only the data its job requires, nothing more.
Data residency stated in writing, India included. Zero-retention terms with our model providers. A retention schedule with published deletion timelines, and deletions that are logged and verified.
Every candidate is scored against the same written rubric with the transcript quoted under each score. No emotion, personality or mood inference from face or voice. Human review before any decision that goes against a candidate.
The commitments on this page match the ones in our DPA and security documentation, and the paperwork behind every framework below is available to your security team on request.
The frameworks below cover information security, privacy law on three continents, and AI fairness — and the documentation behind each one is available to your security team on request.
Trust Services Criteria covering security, availability and confidentiality. Reports are shared with your security team under NDA.
Information Security Management System controls implemented across the platform — access, change, incident and vendor management.
EU General Data Protection Regulation. Lawful bases documented per data type, explicit consent for biometrics, data subject rights honoured on request.
California privacy law. Disclosure, deletion and opt-out rights supported through the same request channel as GDPR.
Digital Personal Data Protection Act. Consent, purpose limitation and data principal rights built into the platform; a DPDP-ready data processing agreement is available today.
AI fairness and bias assessment. Bias mitigation through re-weighting, adversarial debiasing and fairness-aware training, with a bias audit summary available on request.
The paperwork behind our practices. Public policies are a click away; audit materials are released on request, most under a mutual NDA.
A summary of the technical and organisational controls in operation today, across security, privacy and AI fairness.
Data residency is stated in writing for every deployment, India included. Residency and the region each data type rests in are named in the DPA rather than left to inference.
30 days after the recruitment or assessment activity completes, by default. A client can instruct retention of up to 120 days in writing for audit or compliance purposes. After deletion, backups and logs are purged within 90 days.
Face, voice and ID data is processed with explicit consent, or under employment and social-protection law where that applies. Candidates are told before the interview that verification will run, and there is an adjustments route for those who need one.
Yes. Verified deletion requests sent to support@berribot.com are processed within 30 days, except where a legal or contractual obligation requires continued retention — and every deletion is logged and verified.
We hold zero-retention terms with our model providers, and each product feature processes only the data its specific job requires.
SOC 2 Type II and ISO 27001 for information security, GDPR, CCPA/CPRA and India's DPDP Act for privacy, and the EU AI Act with ISO/IEC 24027 for AI fairness. The reports and documentation behind each are shared with your security team on request, most under a mutual NDA.
Vendor reviews, DPA questions, audit documentation, or a candidate data request — write to us and a human answers.
support@berribot.com