Invigile

Privacy Policy

This policy explains how Invigile collects and uses personal data when you visit our website, create a customer account, or when candidates participate in integrity-monitored sessions powered by our platform.

Last updated: 2026-07-27

1. Roles

For customer users (HR/admin): Invigile is the data controller of account and billing data.

For candidates in a monitored session: the inviting organization is the data controller; Invigile acts as a data processor on their instructions.

2. Data we collect

  • Account: name, email, company name, authentication logs.
  • Product usage: interview configuration, session metadata, integrity signals, evidence timeline entries.
  • Candidate session (when enabled): browser signals, optional camera metadata, optional identity verification via Didit, optional OS agent signals.
  • Website: cookies and analytics (see Cookie Policy).

3. Purposes & legal bases

  • Provide and secure the service (contract / legitimate interest).
  • Integrity monitoring requested by the customer (customer’s legal basis + candidate consent where required).
  • Compliance, fraud prevention, and support.

4. Processors & transfers

We use vetted subprocessors including cloud hosting (Vercel, Supabase), identity verification (Didit), email (Resend), and optional AI summarization (OpenAI). Data may be processed in the EU/UK and other regions with appropriate safeguards.

5. Retention

Customer account data is kept while the subscription is active and as required by law.

Session evidence defaults to up to 12 months unless the customer configures otherwise.

Opt-in blurred violation frames are retained for up to 14 days.

6. Your rights

Depending on your jurisdiction (GDPR/KVKK), you may request access, correction, deletion, restriction, or objection. Contact us at the email below. Candidates should contact the organization that invited them first.

7. Contact

Email: privacy@invigile.com