Legal
Privacy Policy
This policy describes what Paddoq (KvK 57715610, Netherlands) collects when you use our apps — currently Can You Build — and what we do with it. It applies to paddoq.ai and every per-app site we operate, including canyoubuild.paddoq.ai.
1. Data controller
Paddoq, registered with the Netherlands Chamber of Commerce (KvK 57715610), is the data controller for the personal data of the people who use our apps — the account holders at an organisation. Reach us at privacy@paddoq.ai.
For candidate assessment data, the organisation running the hiring process is the controller and Paddoq acts as its processor, under a Data Processing Agreement. See §3.
2. What we collect
Account data (the organisation's users)
- Email address (used to identify you and to log in)
- Display name (if you set one)
- The contents you create in our apps (e.g. assessment campaigns and results in Can You Build)
Payment data
- Stripe (our payment processor) handles your card. We never see or store full card numbers.
- We receive: payment amount, currency, the last 4 digits of the card, a card fingerprint (Stripe’s abuse-prevention signal), and the Stripe customer/charge IDs.
Technical data
- IP address (logged briefly for security/abuse prevention; not used for marketing).
- Standard server logs: HTTP method, path, status code, timestamp, user agent.
- Error reports via Sentry — stack traces and request metadata captured when something breaks.
3. Candidate data — the short list
This is the part most people want to know about, so here it is in full.
We never receive a candidate's identity. There is no field anywhere in Can You Build for a candidate's name, email address, phone number, or CV, and we never ask for one. A candidate reaches their assessment through an opaque link and is known to us only by the token in that link. The mapping from a link to a real person is held by the hiring organisation, in its own systems. We never see it.
What we do hold about a candidate is:
- the opaque link token;
- the challenge they were given;
- their conversation with the AI assistant (the transcript);
- timing — when they started, when they submitted;
- a handful of timing figures the AI judge derives from that transcript, and stores with the score: how many prompts they sent, how long before their first one, the average gap between prompts, and how long the stage took. A reviewer sees these next to the transcript. They come from the transcript itself — we do not watch the candidate's browser to produce them;
- the AI judge's per-criterion scores and written reasons (including the judge's raw response, kept so a score can be audited);
- the reviewer's decision on the assessment — pass / fail / maybe, a shortlist flag, and any notes they write — stamped with which of the organisation's people decided;
- the hiring organisation's own private label for them, if it chose to set one (e.g. "req-42 · A") — never shown to the candidate;
- operational metadata about the AI calls the assessment made: which model, how many tokens, what it cost us to run. This is our own cost accounting; it contains no assessment content.
That is the complete list. What we do not collect:
- no webcam, no microphone, no photo, no video;
- no screen recording or screenshots;
- no keystroke logging;
- no biometrics or identity verification;
- no browser, focus, or copy/paste tracking — no proctoring of any kind (we removed this deliberately);
- no CV, no application form, no candidate account.
Is this personal data? Yes. A transcript tied to a persistent token is pseudonymised personal data, not anonymous data — the hiring organisation can re-identify it, so the law treats it as personal. We would rather say that plainly than claim otherwise. It does mean the amount of personal data on our platform is unusually small, and that a breach here would expose transcripts and scores, not a directory of candidates.
The hiring organisation is the controller; we are its processor. It is responsible for telling candidates that the assessment is recorded and AI-scored before they take it, and for handling their requests. We support it in doing so, and will delete or export any assessment on request. Assessment data from a pilot is deleted at pilot end + 90 days.
4. How we use it
- To operate the apps you signed up for (run assessments, store results, etc.).
- To bill you and process refunds.
- To detect and prevent abuse of the service.
- To debug crashes and improve reliability.
- To respond when you contact us.
- To learn whether this method works. Can You Build is an experiment, and we study how the assessment and the AI judge perform — for example, whether the judge scores the same transcript consistently, and where it disagrees with human reviewers. Anything we publish is aggregated and de-identified: no organisation is named without written permission, and no transcript or excerpt is ever published without separate, explicit consent. This use is set out in the research addendum to each pilot agreement.
We do not sell your personal data. We do not run ad networks, and we do no browser or proctoring tracking. We do not train AI models on your content.
5. Third parties we share data with
- Stripe (payments) — card processing, fraud prevention. stripe.com/privacy.
- Anthropic (AI evaluation for Can You Build) — candidate responses are sent to Anthropic's API to generate assessments and scores. Anthropic's API terms state they do not train on API data by default.
- Cloudflare (hosting, CDN, DNS) — handles network-level traffic and TLS termination. cloudflare.com/privacypolicy.
- Hetzner (server hosting, EU) — runs our production infrastructure.
- Sentry (error tracking) — receives stack traces and request metadata when something breaks.
6. Where we store data
Production data is stored on servers physically located in the European Union (Hetzner Germany). Stripe and Anthropic process data on their own infrastructure under their respective terms.
7. How long we keep data
- Account + content: for as long as your account is active, plus 30 days after deletion (so we can recover from accidents).
- Payment records: 7 years (Dutch tax-law minimum).
- Server logs: 30 days.
- Error reports: 90 days.
8. Your rights (GDPR)
Under the General Data Protection Regulation you have the right to access, correct, delete, restrict, or port your personal data, and to object to processing. Email privacy@paddoq.ai and we'll respond within 30 days. You can also file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
9. Cookies
We use a single first-party cookie (ts_session) to
keep you logged in. It's HttpOnly,
SameSite=Lax, Secure on HTTPS, and
expires after 7 days. We do not use tracking cookies or
third-party analytics cookies.
10. Changes
We may update this policy. The "Last updated" date at the top reflects the most recent change. Material changes will be announced by email to active users.