This article answers Frequently Asked Questions (FAQs) about Privacy and Security on the Karat platform. Look for your problem and if you are still having problems, reach out to Karat support at support@karat.io.
For general common issues related to the Karat platform, see Karat FAQs.
Is Karat a data controller or data processor?
Karat acts as a data controller for information collected directly from candidates during interviews. This is necessary to perform quality assurance and prevent returning candidates from encountering the same questions or interviewers. Karat is a data processor for any information provided directly by clients.
How can candidates have their data deleted?
Karat’s privacy policy includes instructions on submitting data deletion requests. Candidates can send their requests to privacy@karat.com.
Can a candidate take the Karat assessment if they do not accept the terms of use?
If a candidate does not accept the Candidate Terms of Use that include the interview being recorded, they will not be allowed to schedule an initial Karat Interview.
How long does Karat store data, and is that disclosed somewhere to candidates?
Karat uses U.S.-based AWS cloud storage. Details about this, along with other authorized subprocessors, are available on the Authorized Sub-processors page.
Where/how is this provided to candidates?
Our privacy policy discusses data retention but does not specify time periods. Candidate data is retained for five years, while client-provided data is stored for 90 days after the termination of the relationship.
Language from the Karat privacy page:
We retain Personal Data about you for as long as you have an open account with us or as otherwise necessary to provide you with our Services. In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation. We may further retain information in an anonymous or aggregated form where that information would not identify you personally.
If a data breach were to occur, would the info stored by Karat (name and email) be exposed in an unencrypted format?
All data is encrypted during transit and rest.
Is Karat and the data used compliant with the Security Standards for Encryption?
For transit, Karat uses TLS 1.2+. At rest, Karat uses AES-256, which is a commonly used encryption standard.
Where is data stored?
Karat’s data is hosted in Amazon AWS regions us-west-2 (Northern California) and us-east-1 (Northern Virginia). While the general geographic location is known, Amazon does not disclose the exact physical locations of its servers.
What is the relationship between Karat company and the Karat interviewers? Are these interviewers contractors or direct hires of Karat?
Most Interview Engineers are independent contractors. While some internal Karat engineers have previously conducted interviews, this is rare due to the growth of the Interview Engineer community.
When candidates take a Karat interview, do they acknowledge that the service is provided by Karat (and not provided by the client)?
Yes, candidates are informed both in the scheduling/invite email which links to the Terms & Conditions, where it is noted that Karat is hired to perform interviews for the client. The Interview Engineers performing the interviews work for Karat and not the client, and that the interview format has been selected as an accurate assessment of the skills needed per the job being interviewed for. The formats are determined through a review process between Karat and the client.
What candidate information does the IVE receive?
Interview Engineers receive the following information to confirm the candidate’s identity and contact the candidate should they not show up, or become disconnected in the interview:
- Name
- Email address
- Phone number (encrypted)
- Time zone of the candidate
What resources are available to candidates and clients regarding privacy and security?
What countries do Karat interviewers reside?
Our Interview Engineers are based in 69 countries, but we do not have a breakdown of individual Interview Engineers. Per compliance requirements like QDPR, there are restrictions on where Interview Engineers are located and how/who they can interview. Our Interview Engineers belong to cohorts in order to address this, but if needed, we can request additional details from the legal team.
List of countries IVE's reside in as of September 2022:
- Argentina
- Armenia
- Australia
- Austria
- Bangladesh
- Bolivia
- Brazil
- Bulgaria
- Canada
- Chile
- China
- Colombia
- Costa Rica
- Croatia
- Czech Republic
- Dominican Republic Egypt
- Estonia
- France
- Georgia
- Germany
- Ghana
- Greece
- Hungary
- India
- Ireland
- Israel and the Occupied Territories
- Italy
- Japan
- Kenya
- Korea
- Luxembourg
- Malaysia
- Malta
- Mexico
- Morocco
- Nepal
- Netherlands
- New Zealand
- Nicaragua
- Nigeria
- Pakistan
- Panama
- Peru
- Philippines
- Poland
- Portugal
- Romania
- Senegal
- Serbia
- Singapore
- Slovakia
- Slovenia
- South Africa
- Spain
- Sri Lanka
- Sweden
- Switzerland
- Taiwan (ROC)
- Thailand
- Turkey
- Uganda
- United Kingdom
- United Arab Emirates
- Uruguay
- United States
- Venezuela
- Virgin Islands
- Zimbabwe