Effective 26 September 2026. EvalFlo is operated by EvalFlo Technologies Private Limited, Kolkata, West Bengal, India. Questions about this document: [email protected].
Who we are
EvalFlo is operated by EvalFlo Technologies Private Limited, a company incorporated in India with its registered office in Kolkata, West Bengal, India ("EvalFlo", "we", "us"). This policy covers evalflo.com, the EvalFlo workspace and candidate assessment links.
Privacy questions and requests: [email protected]. Our Grievance Officer, appointed under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, can be reached at [email protected]. We acknowledge every request within two business days.
Who is responsible for what
Employer accounts and organizations. When you create an account or an organization, EvalFlo decides how your account data is used and is responsible for it (a data fiduciary under Indian law, a controller under the GDPR): your name, email, role memberships, billing records and audit logs.
Candidates in a flo. When an employer runs you through a flo, the employer decides what to collect and why. The employer is responsible for your assessment data and EvalFlo processes it on the employer's instructions. Questions about a specific assessment go to the employer first; we help them answer.
Visitors. For the marketing site, EvalFlo is responsible.
What we collect
Account data: name, email address and sign-in details handled by Clerk, our authentication provider. We never see or store your password; Clerk owns authentication and sessions.
Organization data: the organization name, branding fields, members and their roles, plan, invoices and payment status. Card and bank details are held by our payment providers, never by us.
Candidate assessment data, collected only inside a flo an employer built and only at the stages the employer enabled:
- Your answers and submissions, including how they developed: edits, pastes and the order of events inside registered assessment fields. We capture only fields explicitly registered as assessment inputs, never account forms, passwords or private fields.
- Browser observations while an assessment is open: focus and visibility changes, tab switches, fullscreen exits, developer tools opening, paste counts and sizes, connected device changes and timing. These are counts and metadata, not recordings of your screen.
- Camera snapshots, short event-triggered clips and microphone-derived features (speech segments, counts and durations, never a stored audio recording) only when the employer enabled camera or microphone proctoring for that stage and you gave separate consent on the capture screen.
- A photo of you, or of an identity document, only at a stage that asks for one. We store the image; we never scan it, extract a face template from it or match it against anything.
- Form answers, uploaded files such as a CV, and interview bookings.
Technical data needed to run the service: IP address, browser type, device type and request logs, kept for security and troubleshooting.
What we use it for
- Running the assessment an employer configured and showing the employer the results, the work behind them and the evidence they chose to collect.
- Letting a reviewer see integrity findings as evidence. Findings are tiers with the evidence attached, never a cheating verdict, and camera or microphone findings never feed an automated rule.
- Sending the emails a flo is configured to send, in the employer's name with our identity in the footer, plus account, security and billing messages.
- Billing organizations by candidate runs, and keeping audit records of privileged actions such as overrides, reveals and role grants.
- Keeping the service secure and improving it from aggregate usage. We do not sell personal data and we do not show advertising.
Why we are allowed to: performance of our contract with you for accounts, billing and running the flo you were invited to; your consent, which you can withdraw, for camera, microphone and identity capture and for marketing email; legitimate uses permitted by law for security, fraud prevention and meeting legal obligations; and, for visitors in the EEA and UK, our legitimate interest in running and improving the service.
What a candidate is told, and when
Before you commit time, the invitation lists what the process involves: the stages, their durations, and whether camera, audio or an identity document is part of it. At any capture screen you see what is collected, that the employer receives it, when it is deleted and how to delete it sooner, and you can ask for an alternative route to a person.
Reaching the end of a flo tells you that your submission is complete and the employer has it. It never shows a verdict or a score mid-flo. If an employer wants to tell you more, they send it themselves.
How long we keep things
- Assessment data: for the retention period of the employer's plan (3 months on Free, 6 on Lite, 18 on Pro, 24 on Growth, or the period in a Scale contract), then deleted. An employer can choose a shorter period.
- Identity document photos: deleted 30 days after capture on every plan, whatever the plan's retention.
- Uploaded files and photos: deleted with the rest of the run's assessment data, or earlier when the employer or you ask.
- Account data: while the account exists, then deleted within 90 days of closing it, except what we must keep by law.
- Invoices and payment records: for as long as Indian tax and company law require us to keep them.
- Security and request logs: 12 months.
- Audit records of privileged actions: for the life of the organization's account, because they are what a challenged decision is read against.
Security, without slogans
Data is encrypted in transit and at rest. Access inside EvalFlo is deny-by-default and scoped to an organization, a flo or a run, and privileged reads such as revealing a sealed question are logged per reveal. Candidate code runs in an isolated execution service, never alongside your data.
No system is perfectly secure. If a breach affects your data we will notify the Data Protection Board of India and the organization responsible, and you where required, within the timelines the law sets. Report a vulnerability to [email protected].
Your rights
You can ask for a summary of the data we hold about you and who we shared it with, a copy of it, correction, completion, deletion, or a restriction on how it is used; you can withdraw a consent you gave; and you can nominate someone to exercise these rights for you if you die or become unable to. People in the EEA and UK can also object to processing based on legitimate interest and ask to move their data.
Send requests to [email protected]. We answer within 30 days. For assessment data the employer decides, and we pass your request to them the same day. If you are not satisfied, write to our Grievance Officer at [email protected]; you may also complain to the Data Protection Board of India or, in the EEA and UK, to your local data protection authority.
EvalFlo itself makes no automated decisions about you with legal effect. Employers may configure rules inside their own hiring process; where they do, the rule, the threshold and the values that fired it are recorded and available to the employer when you ask them to explain a decision.
Children
EvalFlo is for people aged 18 and over. Employers must not run anyone under 18 through a flo, and we delete accounts and data we learn belong to a child.
Where data is processed
We store data in India, in the Amazon Web Services Asia Pacific (Mumbai) region. Some of our providers, such as our authentication and email providers, process data in other countries, including the United States. Where the law requires it we rely on approved transfer mechanisms, and organizations can ask us for the current list of providers and regions.
Changes to this policy
We post changes here with a new effective date. For a material change we email account holders at least 30 days before it takes effect.
Contact: [email protected] for privacy, [email protected] for grievances, [email protected] for everything else.