Security & Data Trust

How Yupcha Protects Candidate Data

Yupcha handles sensitive candidate information on behalf of hiring teams. This page is an honest, plain-language overview of the practices we actually follow — encryption, access controls, configurable retention, GDPR-aligned processing, and an evaluation design built to reduce bias.

Encryption at rest & in transitGDPR-aligned processingNo data selling

We only claim what we do. This page describes the security and privacy practices Yupcha follows today. It does not assert any specific third-party certification or audit attestation. For the full legal detail, read our Privacy Policy, Data Retention Policy, and Data Processing Addendum.

Six ways we earn your trust

Each pillar maps to a real, documented practice — not a marketing claim.

Encryption in Transit & at Rest

Candidate data is stored on secure cloud infrastructure with encryption at rest and in transit. Payment details are handled by PCI-DSS-compliant processors — we do not store full card numbers on our servers.

Strict Access Controls

Multi-level identity access controls and need-to-know permissions limit who can reach systems that process personal data, backed by confidentiality obligations and security-awareness training for personnel.

Configurable Retention & Deletion

Published, category-by-category retention periods with secure disposal. On termination we delete or return data at the controller's choice, and erasure requests are processed within 30 days.

GDPR & Data-Processing Alignment

A controller/processor model with a Data Processing Addendum, documented security measures, Standard Contractual Clauses for international transfers, and 72-hour breach notification.

Candidate Data Handling & Consent

We process candidate data only on documented client instructions. Clients act as the controller and warrant they hold the necessary consents; we assist them in honoring data-subject rights.

Fairer AI Evaluation

Structured questions, one calibrated rubric, and integrity signals reduce inconsistency and bias — with human review on significant decisions. We aim to reduce bias, not claim it's eliminated.

Data lifecycle

Kept only as long as needed — then securely removed

We follow the GDPR principles of storage limitation and data minimisation: data is retained only as long as necessary for the purpose it was collected, then deleted or anonymised. Each data category has a defined retention period and disposal method, and backups containing expired data are purged on their next overwrite cycle.

On termination of a client agreement, we delete or return personal data at the controller's choice. Individual erasure requests under Article 17 are processed within 30 days.

Read the full Data Retention Policy
Customer account detailsUntil deletion or 24 months after last activity
Support tickets & communications2 years from ticket closure
System & access logs12 months unless needed for a security audit
Anonymized data for AI trainingPersonal identifiers removed before retention
Fairer evaluation

Designed to reduce bias — honestly stated

No system is perfectly objective, and we won't pretend otherwise. What we can do is remove the inconsistency that drives a lot of human bias: every candidate gets the same questions, scored on the same rubric, with integrity checks and a human in the loop on important decisions.

Same structured questions

Every candidate for a role answers the same core questions, so evaluations are comparable rather than dependent on who they spoke to.

One calibrated rubric

Answers are scored against a single, consistent rubric instead of ad-hoc human impressions that vary interviewer to interviewer.

Integrity signals

Anti-cheat signals reduce manipulation that would otherwise distort scores — so a result reflects the candidate's actual performance.

Human in the loop

You can request human review of significant AI decisions. We strive to avoid solely automated decisions with legal effects.

FAQ

Security & Data Trust — FAQs

Candidate data is stored on secure cloud infrastructure with encryption at rest and in transit. Access is limited through strict access controls and multi-level identity permissions, so only authorized personnel can reach the systems that process personal data. We also run regular security audits and data-integrity checks.
No. Yupcha does not sell personal data. As a data processor, we handle candidate data only on the documented instructions of our business clients (the controllers). Limited sharing happens only with authorized subprocessors — for example hosting or payment processing — under confidentiality agreements that impose data-protection obligations equivalent to our own.
Retention is configurable and tied to the controller's instructions and the term of their agreement. We publish category-by-category retention periods and disposal methods in our Data Retention Policy, and on termination we will delete or return personal data at the controller's choice. Data-subject deletion requests (Article 17, right to erasure) are processed within 30 days.
We operate on a controller/processor model with a Data Processing Addendum, follow GDPR principles of storage limitation and data minimisation, use Standard Contractual Clauses (SCCs) for international transfers, and notify controllers of any personal-data breach without undue delay and within 72 hours of discovery. We do not claim any third-party certification on this page — only the practices we actually follow.
Yupcha asks every candidate for a role the same structured questions and scores answers against one calibrated rubric, so comparisons don't depend on who a candidate happened to speak to. Integrity signals reduce cheating that would otherwise distort results. This is designed to reduce inconsistency and human bias — not to eliminate it. We keep humans in the loop and never make solely automated decisions with legal effects.
Our business clients act as the data controller and are responsible for obtaining the necessary rights, permissions, and consents before sending candidate data to Yupcha. We process that data on their behalf. Candidates exercising their rights are directed to the controller, and we assist the controller in responding through appropriate technical and organizational measures.
Built on trust

Hire with AI you can defend.

Screen and interview candidates with a platform that treats their data — and your compliance obligations — seriously.

Start Free