Purpose-limited collection
SkillCort collects only what the assessment requires: responses, evaluation records, and — when the delivery's security settings call for it — integrity signals such as recordings or event logs. Every form of monitoring is disclosed to the candidate at the consent gate before the attempt starts, so nothing is collected that the candidate was not told about.
GDPR and KVKK aligned processing
Processing follows GDPR and KVKK principles: data is collected for a stated purpose, limited to that purpose, and held under controls your workspace configures. Combined with purpose-limited collection and disclosed monitoring, this keeps candidate data handling consistent with the expectations of both European and Turkish data protection frameworks.
Encryption in transit and at rest
Candidate data is encrypted in transit and stored on infrastructure with encryption at rest. This applies across the record — responses, scores, notes, and integrity events — so evidence is protected both while it moves between the candidate, evaluators, and the platform, and while it is stored.
Retention for monitoring data
Monitoring data has a per-workspace retention window: your organization sets how long camera and screen captures and integrity events are kept, and a daily sweep deletes them on schedule. A manual erase is also available per attempt for cases where monitoring data should go sooner. The assessment record itself — responses, scores, notes, and decisions — is kept as your decision evidence for a per-workspace window too (default 24 months after the session completes, configurable in Settings → Data), then deleted by the same daily sweep family.
No cross-client candidate data
A candidate's data belongs to the workspace that assessed them, full stop. SkillCort never shares candidate data across clients and never builds cross-client reputation scores. A candidate who applies through two different organizations is, as far as each workspace can see, two unrelated records — prior attempts elsewhere cannot follow them.
At a glance
- Collection is purpose-limited: data is gathered for the assessment at hand, not for profiling.
- Processing is aligned with GDPR and KVKK principles.
- Data is encrypted in transit and stored on infrastructure with encryption at rest.
- Monitoring data has a per-workspace retention window, enforced by a daily sweep, plus a manual per-attempt erase.
- Candidate data is never shared across clients, and there are no cross-client reputation scores.