AuditCV
Back to Home
🔒 PRIVACY

Privacy Policy

Last updated: October 4, 2026
Legal NoticeThis English translation is provided for informational purposes only. The original Turkish version is legally binding.

At AuditCV.io, we strictly collect only the personal data necessary to execute reference checks; we never sell this data to third parties or monetize it for advertising. Below is an executive summary, followed by the complete policy text.

Data we collect: Candidate and referee full name, email, phone number, questionnaire responses, and limited security telemetry used exclusively for fraud detection.
Legal basis: All data processing is strictly grounded in digital explicit consent obtained from the candidate and referee (GDPR Art. 6 / KVKK Art. 5).
Right to erasure: Referees can withdraw consent and file an erasure request via the link at the bottom of their form; once an HR admin completes the request, personal fields are anonymized (not instant). Candidate and company data erasure requests are processed via customer support.
Activity history (audit trail): actions are retained up to 12 months and view logs up to 6 months for security and accountability; personal details are redacted upon erasure requests.
Data sharing: Your data is never shared with third parties or sold for marketing, except for hosting and transactional email infrastructure providers essential to deliver the service.
Data transmission is encrypted (TLS/HTTPS); access is restricted to personnel strictly required to operate the service.
View Full Text
1. Scope

This policy applies to personal data processed across the AuditCV.io website and cloud platform (auditcv.io) regarding HR users, candidates, and referees.

2. Data We Collect

For HR/Company users: full name, corporate email address, organization name, and billing details.

For Candidates: full name, email, target role, and (where submitted) uploaded resume contents.

For Referees: full name, corporate email/phone, and responses provided in the digital evaluation form.

Limited technical telemetry for security: non-public digital signals compared between submissions to identify fraudulent or impersonated references.

3. Purpose of Processing

We process data exclusively to execute candidate reference checks, generate verification reports and digital certificates, detect fraudulent submissions, and fulfill legal compliance mandates (GDPR/KVKK consent logs).

Your data is never used for profiling, automated behavioral advertising, or third-party marketing.

4. Retention Period

Data is retained for a reasonable window following completion of the reference process or until a data subject submits an erasure request. When consent is withdrawn the related process is stopped; an erasure request is filed and, once completed by an HR admin, personal fields are anonymized.

5. Data Subject Rights

Under GDPR Articles 15-22 and KVKK Article 11, you have the right to access, rectify, erase, restrict processing of, and revoke consent for your personal data. Referees can exercise these rights via the one-click link at the bottom of their form; for other requests, please contact support@auditcv.io.

6. Security Standards

All data in transit is encrypted using modern TLS/HTTPS protocols. Access is restricted by role-based controls, and proprietary technical signals of our fraud-detection engine remain confidential to maintain platform integrity.

7. Activity History (Audit Trail)

Actions performed on the platform are logged in an audit trail for information security, accountability, internal auditing, abuse prevention, and verification of consent and erasure requests under GDPR and KVKK.

Logged data includes: the actor's first name, last name, and role; action type and summary; record identifier/name; previous and updated values for modifications (including email and phone number, preserved as entered); deletion reason; IP address; approximate device and browser telemetry; and country. In addition, read logs (views of verification reports, PDF downloads, candidate/request listings, and history); login, explicit logout, and failed login events; and unauthorized access attempts are recorded. User email addresses are tracked solely as an event tag during login events. Session timeout expiration is not recorded; only explicit user logout actions are logged.

Under this feature, the customer acts as the data controller and AuditCV acts as the data processor. Company administrators can view only audit records pertaining to their own organization. Granular audit details (diffs of previous/updated values, read logs, IP/device telemetry) are available under paid tiers (Pro and Enterprise tiers are currently marked as upcoming, with the Free tier currently active). System-level events remain accessible only to platform administrators. Customer support sessions (impersonation) are logged and displayed to the company with timestamp, duration, and stated reason.

General activity records are retained for a maximum of 12 months, and read logs are retained for 6 months, after which they are automatically purged. In-app feedback messages are retained for 24 months.

Upon an erasure request under GDPR or KVKK by a candidate or referee, their personal values in historical logs are redacted (preserving only name initials). Users should not enter personal data into free-text reason notes.

8. Contact Us

For questions regarding privacy, data protection, or exercising your statutory rights, please contact support@auditcv.io or submit our contact form.