Back to Home
GDPR Compliant

Privacy Policy

Effective Date: July 29, 2025

Welcome to TalentAI, a product of DokimAI ("we," "our," or "us"). We are committed to protecting the privacy and security of the personal data of candidates and recruiters. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use our asynchronous video interview SaaS platform and services (collectively, the "Services").

1. Who is Responsible for Your Data?

For the purposes of the GDPR, the data controller is:

DokimAI (TalentAI Operator)
24 Aghmashenebeli Avenue.
Kutaisi, 4600, Georgia
Email: info@dokim.ai

If you are a B2B user, your organization (the "Client") acts as a separate data controller for the personal data of the candidates taking asynchronous video interviews through your account. In such cases, DokimAI acts as a data processor on behalf of the Client. Our obligations as a data processor are further detailed in a separate Data Processing Addendum (DPA) that we enter into with our B2B Clients.

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person ("data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or online identifier.
  • Processing: Any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, storage, adaptation, retrieval, use, disclosure, or deletion.
  • Controller: The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processor: A natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
  • Data Subject: The identified or identifiable natural person to whom personal data relates.
  • Services: Our SaaS platform, website, video recording modules, and all related asynchronous interview and AI evaluation services.

3. What Personal Data Do We Collect and Why?

We collect different types of personal data depending on how you interact with our Services.

a) For B2C Users (Direct Controller Relationship)

  • Account Data: Name, email address, password (encrypted), and country of residence. Used to create accounts, provide access, and ensure security. (Legal Basis: Contractual performance).
  • Interview Data: Responses to interview questions, video/audio recordings, transcription data, assessment results, and performance metrics. Used to generate evaluation reports and summary reviews. (Legal Basis: Explicit consent and contractual performance).
  • Usage Data: IP address, browser type, operating system, page visits, and device identifiers. Used to analyze performance and troubleshoot issues. (Legal Basis: Legitimate interests).
  • Communication Data: Content of communications with us (e.g., support requests). Used to resolve issues and provide customer support. (Legal Basis: Contractual performance).

b) For B2B Users (Processor Relationship)

When a B2B Client uses our Services to run recruitment campaigns and assess candidates, the Client is the Data Controller, and DokimAI acts as a Data Processor. We process all candidate video recordings and evaluation transcripts strictly according to the Client's instructions.

  • Client Account Data: Business name, contact person name, email, phone, billing information. Used to manage the account and process payments. (Legal Basis: Contractual performance).
  • Interview Data (Assessed Candidates): Names, email addresses, video recordings, audio tracks, written answers, and evaluation reports of individuals taking asynchronous interviews facilitated by the Client. We process this strictly under the Client's instructions. (Legal Basis: Contract with the B2B Client).

c) For All Users (Aggregated & Anonymized Data)

We may aggregate and anonymize personal data so it can no longer be associated with an individual. This is used for product development, research, and improving our AI assessment engines. Once fully anonymized, it is no longer considered personal data under GDPR.

4. How We Use Artificial Intelligence (AI)

Our Services utilize AI to analyze asynchronous candidate interview responses:

  • The AI processes candidate responses (voice transcripts and video answers) to generate competency scores, feedback summary reviews, and key recruitment insights.
  • We use anonymized and aggregated data to train and improve our AI evaluation models, ensuring the ongoing accuracy and fairness of our assessment engine.

5. How We Share Your Personal Data

We only share personal data in limited circumstances and with appropriate safeguards:

  • With B2B Clients: If you are an individual taking an assessment through a B2B Client's account, your assessment data and results will be shared directly with that B2B Client.
  • With Third-Party Service Providers (Processors): We use trusted third-party service providers to help us operate our Services. These include cloud hosting providers (e.g., AWS, Google Cloud), payment processors (Stripe), support platforms, and email communication services.
  • For Legal Reasons: We may disclose personal data if required to do so by law, court order, or to protect the rights, property, and safety of DokimAI, our users, or the public.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your personal data may be transferred as part of the transaction.

6. International Data Transfers

Our servers and service providers may be located outside of the European Economic Area (EEA). When we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place to protect your data, such as:

  • Standard Contractual Clauses (SCCs): Implementing the European Commission's approved Standard Contractual Clauses.
  • Adequacy Decisions: Relying on countries deemed by the European Commission to provide an adequate level of data protection.

7. Your Data Protection Rights (GDPR)

Under the GDPR, you have the following rights concerning your personal data:

  • Right to Information (Art. 13 & 14): You have the right to be informed about the collection and use of your personal data.
  • Right of Access (Art. 15): You have the right to request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
  • Right to Erasure (Art. 17): You have the right to request the deletion of your personal data under certain conditions (e.g., if the data is no longer necessary).
  • Right to Restriction of Processing (Art. 18): You have the right to request that we restrict the processing of your personal data under certain conditions.
  • Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object (Art. 21): You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing.
  • Right to Withdraw Consent (Art. 7): Where we rely on your consent as the legal basis, you have the right to withdraw your consent at any time.

How to Exercise Your Rights: To exercise any of these rights, please contact us at info@dokim.ai. B2B assessed individuals should primarily contact their employer or prospective employer (the Data Controller).

8. Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing your personal data, including:

  • Encryption: Encryption of data at rest and in transit.
  • Access Controls: Restricting access to personal data to authorized personnel only.
  • Regular Security Audits: Conducting periodic assessments to identify and resolve vulnerabilities.
  • Data Minimization: Collecting only the data necessary for the stated purposes.

9. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements:

  • Account Data: Retained for as long as your account is active and for a reasonable period thereafter.
  • Interview Data: Retained for a period consistent with providing your interview results and campaign historical access, typically 2-5 years, or until deletion is requested by you or the managing Client.
  • B2B Client Data: Retained as per the terms of our agreement and Data Processing Addendum with the B2B Client.

10. Children's Privacy

Our Services are not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from a child under 18 without parental consent, we will take steps to delete that information promptly.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on our website and/or by other reasonable means (e.g., email notification for significant changes).

12. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact our Data Protection Officer (DPO) at:

Data Protection Officer: Paata Sirbiladze
Email: info@dokim.ai