Skip to main content
TE

Testlify

GDPR evidence

testlify.comLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Testlify and GDPR

CertReports found no public GDPR evidence for Testlify as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
7 Dec 2023
Scope
Purpose of Data Processing Testlify processes personal data in reliance on the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) for the following purposes: 1. Service Delivery o To administer talent assessments, surveys, and evaluations that assist organizations in evaluating candidates’ skills, knowledge, and competencies. o To calculate and provide assessment results to authorized recipients, such as employers or recruiters. 2. User Account Management o To create, authenticate, and manage user accounts on the Platform. o To enable secure access and maintain user preferences. 3. Communication o To send assessment results, service updates, and notifications to users. o To respond to inquiries, feedback, or complaints submitted by users. 4. Platform Optimization and Analytics o To analyze data for improving Platform functionality and user experience. o To use aggregated and anonymized data for benchmarking and service enhancement. 5. Compliance and Security o To comply with applicable legal obligations and regulatory requirements. o To monitor, detect, and prevent fraud, unauthorized access, and security threats. ________________________________________ Types of Personal Data Processed Testlify processes the following categories of personal data: • Candidate Data: Assessment responses, test scores, names, email addresses, and demographic data (optional). • Customer Data: Organization details, user contact information, and account preferences. • Visitor Data: Metadata such as IP addresses, browser types, and session timestamps. • HR Data: Employment records, performance evaluations, and related data (for internal operations). ________________________________________ Disclosure of Personal Information Testlify discloses personal data to the following third parties for the specified purposes: 1. Service Providers (Subprocessors): o Hosting and Storage: AWS, Azure, and Google Cloud Platform (GCP) for secure data hosting. o Email Services: Twilio SendGrid for communication delivery. o Analytics and Monitoring: MixPanel, OpenReplay, and Sentry for performance analysis and issue resolution. o Support Services: Intercom for customer support interactions. o Payment Processors: ChargeBee for subscription and billing management. 2. Authorized Customers: o Assessment results and related data are shared with employers and recruiters explicitly authorized by candidates during the application process. 3. Regulatory Authorities: o Personal data may be disclosed to law enforcement or regulatory bodies as required by applicable law. Testlify ensures that all third parties receiving personal data adhere to strict confidentiality agreements and process the data only for authorized purposes in compliance with DPF principles.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Testlify, Inc.: Inactive
Live pagesha256 0c8495e872
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Testlify GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.

No same-category vendor has GDPR evidence in the index yet.