1. Data controller
Berrypie Ltd is the data controller for personal data we collect about Candidates.
Contact our Data Protection Officer at
[email protected].
2. Categories of personal data we collect
- Account data: name, email, password hash, profile photo.
- Identity data (KYC): government-issued ID document, selfie, date of birth — collected via our processor Persona.
- Right to Work data: share code, date of birth (for HMRC checks).
- Address data: uploaded utility bill / bank statement, extracted city/postcode/country.
- Employment history: employer names, job titles, dates, peer-confirmation contact details.
- Skills assessment data: AI-graded responses, screen recordings, webcam recordings, microphone recordings, second-device telemetry.
- Psychometric data: Likert-scale answers and derived dimension scores.
- Location data: coarse geolocation (city/country) from your device.
- Payment data: handled by Stripe; we store Stripe customer IDs and the date you paid the KYC fee, never card numbers.
- Usage data: IP address, device, pages viewed, actions taken.
3. Lawful bases (UK GDPR Art 6)
- Contract (Art 6(1)(b)): account creation, processing applications, taking payment.
- Legitimate interests (Art 6(1)(f)): fraud prevention, anti-cheating in skills assessments, platform analytics.
- Consent (Art 6(1)(a)): publishing your profile via the share-link feature, optional marketing emails.
- Legal obligation (Art 6(1)(c)): retaining payment records for tax purposes.
For special-category data (e.g. KYC documents that may indicate biometric data), we rely on
your explicit consent (Art 9(2)(a)) collected at the verification step.
4. How we use your data
- Verify your identity and right to work.
- Match you to relevant jobs and surface your profile to employers when you apply.
- Score your skill assessments and proctor for cheating.
- Enable the public share-link feature when you opt in.
- Process payments.
- Detect fraud, abuse, and security incidents.
- Comply with legal obligations.
5. Sub-processors
We share data with the following processors under signed Data Processing Agreements:
- Stripe (US/IE) — payment processing.
- Anthropic (US) — AI grading and challenge generation. Inputs are not used to train Claude models.
- Persona (US) — KYC identity verification.
- Google (Maps & Places) (US/IE) — geocoding and location autocomplete.
- Cloudflare (US/IE) — bot mitigation (Turnstile) and edge delivery.
- HMRC / GOV.UK (UK) — Right to Work checks.
6. International transfers
Some processors are located outside the UK/EEA (primarily in the United States). For these
transfers we rely on the UK International Data Transfer Agreement and the EU Standard
Contractual Clauses, supplemented by additional safeguards where required.
7. Retention
- Account data: while your account is active, plus 30 days after deletion request.
- KYC documents: 5 years after collection (anti-money-laundering obligations).
- Skill assessment recordings: 12 months.
- Payment records: 7 years (UK tax law).
- Usage logs: 12 months.
8. Your rights
Under UK GDPR you have the right to:
- Access your personal data (Art 15).
- Correct inaccurate data (Art 16).
- Erase your data (Art 17), subject to legal-retention exceptions.
- Restrict processing (Art 18).
- Receive your data in a portable format (Art 20).
- Object to processing based on legitimate interests (Art 21).
- Withdraw consent at any time (Art 7) — including revoking your share link.
- Not be subject to fully automated decision-making with significant effects (Art 22). AI-graded skill scores are reviewed by our team on request.
Email [email protected] to
exercise any of these rights. You may also lodge a complaint with the UK Information
Commissioner's Office at
ico.org.uk/make-a-complaint.
9. Cookies
We use strictly-necessary cookies for session management and CSRF protection. We use one
optional analytics cookie that you may decline at first visit. We do not run third-party
advertising trackers.
10. Children
Berrypie is not intended for users under the age of 18. We do not knowingly collect data from
children. Contact us immediately if you believe we have done so.