Effective Date: 13/07/2026 Last Updated: 13/07/2026 Version: [v1.0]
This Policy applies to all users of the Serin AI platform ("Serin," "we," "us," "our"): job candidates ("Talent," "you," "Candidate") and hiring organizations ("Organizations," "Customers"). It governs all personal data collected through serin-ai.com, the Serin web application, and any connected APIs.
Data Controller (for platform-level processing, including proctoring and account data): Serin AI - A 327, Money Plant High Street, Nr BSNL Office, Beside Shell Petrol Pump, Jagatpur Road, S G Road, Ahmedabad- 382470
contact@serin-ai.com
For interview content and hiring-decision data: Serin AI and the hiring Organization are independent controllers, or joint controllers, depending on the configuration described in the Organization Master Agreement. Where joint controllership applies under GDPR Art. 26, the essence of that arrangement is: Serin determines the means of data collection (recording, proctoring, AI scoring infrastructure); the Organization determines the purposes of evaluation (job criteria, hiring decision). A summary of this allocation is available on request.
For platform operation and interview delivery, Serin acts as a processor on the Organization's behalf (see Organization Master Agreement, Schedule A); for certain configurations described in Schedule B, the Parties may act as joint controllers.
Privacy Contact & Regulatory Representatives
For all privacy, data protection, and grievance matters, Serin AI has appointed a unified compliance representative:
Compliance Representative / DPO / Grievance Officer
Serin AI
Email: contact@serin-ai.com
This representative acts as:
This Policy covers two distinct categories of users with materially different data:
Biometric data collection and use is governed in full by the standalone Biometric Data Notice (asked when taking an interview on Serin). Where any provision conflicts, the Biometric Data Notice controls for biometric processing specifically.
Full name, email, phone number, candidate/user ID, username, bio, profile photo, resume(s)/CV(s) (including parsed content), government ID (only if identity verification is enabled for a given interview), LinkedIn/portfolio/GitHub URLs, location, timezone, declared work authorization status, education history, employment history, account tier and subscription status.
If you create or access your account via "Sign in with Google," we receive from Google, with your authorization at the Google consent screen: your name, email address, and profile image. We use this solely to create and authenticate your Serin account. We do not sell this data, do not share it with advertisers, and do not use it for any purpose beyond account creation, authentication, and the candidate-facing features described in this Policy. Use of Google user data by Serin complies with the Google API Services User Data Policy, including its Limited Use requirements. You may revoke Serin's access to your Google account at any time via your Google Account security settings; doing so does not delete data Serin has already lawfully processed but will prevent future syncs.
Application ID, job applied for, organization name, application status, application source, interview ID/session ID, interview schedule, language, duration, custom assessment parameters, invitation metadata, email delivery activity (sent, opened, bounced), timestamps for application, completion, and review.
We do not perform emotion recognition or facial-expression-based personality inference on this footage. This is prohibited under the EU AI Act in the employment/assessment context and is not performed for any candidate, in any jurisdiction.
Facial geometry (for identity verification against an uploaded ID), eye-gaze/eye-tracking data (for proctoring integrity), and voice biometrics (only if speaker verification is enabled — stated per interview). Full detail, retention, and consent requirements are in the Biometric Data Notice.
Mouse movement, click activity, scrolling, tab/window focus changes, keyboard events (if captured for the specific interview format), session timing data, network/connectivity metrics, IP address, browser type and version, operating system, device type, screen resolution, session identifiers, essential cookies (see Section 9), and computer-vision-based multi-person and electronic device detection.
Objective scores, competency scores (technical, communication, domain expertise), confidence scores, AI-generated reasoning and evidence mapping, proctoring/integrity flags, derived skill and competency profiles, interview summaries, and the full conversation/transcript history.
Company name, address, website, domain, logo, recruiter/admin names and emails, role permissions, billing contact, tax/GST/VAT information, invoice and payment history, credits balance, login history.
We do not use a single bundled purpose statement. Each data category has a distinct purpose:
| Data Type | Purpose | Shared With Organization? |
|---|---|---|
| Identity & application data | Account creation, application processing | Yes (application-relevant fields only) |
| Resume / CV | Job matching, AI question generation | Yes |
| Video / audio / screen recording | Proctoring integrity, AI evaluation, manual review | Yes — view-only, time-limited, logged |
| Biometric data | Identity verification, proctoring integrity ONLY | No — never shared with Organization |
| Mouse/eye/behavioral telemetry, multi-person/device detection | Integrity monitoring, detection of unauthorized individuals or devices, AI Act Art. 14 human-oversight evidence | Flag summary only, not raw telemetry |
| AI scores and evaluations | Candidate assessment | Yes — after mandatory human review |
| Google OAuth profile data | Account authentication | No |
| Billing data (Organizations) | Payment processing | N/A |
To provide a superior candidate experience and improve the accuracy, fairness, and relevance of our hiring assessments, Serin uses anonymized and aggregated data collected through our platform to fine-tune our AI models. This process involves identifying patterns and insights that help our models better understand language, skill requirements, and effective communication, ultimately leading to more personalized and accurate assessment tools for all candidates. We employ rigorous anonymization techniques to ensure that this model fine-tuning process does not compromise the privacy or identity of any individual candidate. All data used for this purpose is processed in accordance with our data protection commitments, ensuring that your information remains secure and is used solely to enhance the performance of Serin’s services.
Except as described in Section 4.1 regarding anonymized model fine-tuning, we never use candidate data to train AI models that benefit a different Organization, and never use Organization-submitted job criteria for any purpose beyond that Organization's own hiring process.
| Jurisdiction | Basis Used |
|---|---|
| EU / UK (GDPR / UK GDPR) | Consent (Art. 6(1)(a)) for recording, AI evaluation, and behavioral monitoring; explicit consent (Art. 9(2)(a)) for biometric data; legitimate interest (Art. 6(1)(f)) for platform security and fraud prevention; contractual necessity (Art. 6(1)(b)) for resume processing in furtherance of your application |
| India (DPDP Act 2023) | Explicit, itemized consent under Section 6 for each processing purpose; no "legitimate interest" catch-all is relied upon |
| United States | Consent obtained at point of collection (required in all-party-consent states for recording); BIPA written consent for biometric data; CCPA/CPRA notice-at-collection |
| Other jurisdictions | Consent obtained per local requirement; where no specific statute exists, GDPR-equivalent consent standards are applied as our baseline |
Organizations receive: application data, interview recordings (video/audio/screen — view-only, time-limited, in-platform links; all access logged with user ID, timestamp, and duration; no download capability), AI-generated scores and summaries (after human review), and candidate contact information for hiring communication. Organizations never receive raw biometric data, biometric templates, or eye-tracking raw data. Organizations are contractually bound (Organization Master Agreement) not to store, download, re-share, or use this data for any purpose beyond the specific hiring decision.
| Provider | Data Shared | Purpose | Data Location |
|---|---|---|---|
| Supabase | Resumes, recordings, reports, profile images | Cloud storage | South Asia - Mumbai |
| LiveKit | Live video/audio streams, connection metrics | Real-time interview delivery | eu-west-1 |
| Groq API | Interview transcripts, candidate responses, evaluation prompts | AI question generation and evaluation | Globally Distributed Network |
| Resend | Email address, invitation content | Email delivery | Tokyo - ap-northeast-1 |
| Dodo | Customer ID, subscription status | Payment processing (Organizations only) | India |
| Posthog and Sentry | Aggregated usage metrics | Platform analytics | us-east-1 |
A current list of sub-processors is maintained within internal Documents of Serin and updated with 5-day advance notice to Organizations before any new sub-processor is engaged. In a FedRAMP context, new sub-processors are not engaged until the Significant Change Request process and required agency approvals are complete. All sub-processors are bound by data processing agreements requiring security measures equivalent to our own and prohibiting independent use of the data. For inquiries regarding this list, please contact us at contact@serin-ai.com.
We may disclose data where required by law, to respond to valid legal process, to protect the rights, property, or safety of Serin, our users, or the public, or to investigate fraud or platform misuse.
We do not sell personal data, as that term is defined under the CCPA/CPRA or any other applicable law.
Serin uses artificial intelligence to: conduct portions of the interview (question generation and follow-ups), evaluate your responses, and assist in proctoring/integrity monitoring. No hiring decision is made solely on AI output. The hiring organization is responsible for ensuring that a qualified human reviewer evaluates all AI-generated assessments before any employment decision is communicated. We strongly recommend this best practice, however, the hiring organization is responsible for conducting this mandatory human review. If the organization fails to conduct this review, or if any compromise arises as a result, the entire responsibility and liability for such compromise lies exclusively with the hiring organization, not Serin. Full AI-specific disclosures, your right to explanation, and your right to request human-only evaluation are provided at the pre-interview consent screen and in your Candidate Terms of Service.
Candidate and Organization data may be processed across global jurisdictions, including the United States, the European Union, and India. Where data is processed on behalf of a U.S. federal agency customer within a FedRAMP-authorized environment, it is processed and stored exclusively within that authorized U.S. boundary and is not subject to the cross-border transfers described in this Section. For data transfers originating from the EU, UK, or EEA to countries lacking an adequacy decision, we mandate the use of the European Commission’s 2021 Standard Contractual Clauses, supplemented by a comprehensive Transfer Impact Assessment for each route. For India-origin data, we maintain GDPR-equivalent contractual safeguards as an interim compliance standard, pending the finalization of the Digital Personal Data Protection (DPDP) Act. All approved transfer routes are formally documented in an internal data transfer map, which is maintained and integrated within our broader Internal Policies to ensure consistent global adherence to data protection obligations.
We use:
In-session behavioral monitoring (mouse tracking, eye tracking, screen capture during an interview) is not a cookie and is governed separately by the pre-interview consent screen and the Biometric Data Notice. Manage cookie preferences at any time via serin-ai.com/cookies/
Summary (full operational schedule maintained internally and available to regulators on request):
| Data Type | Retention |
|---|---|
| Session video/audio/screen recording | 30 days from session end (extended only if under active dispute) |
| Eye-tracking / mouse / keyboard logs | 30 days |
| Identity verification image | Deleted immediately after match is confirmed |
| Biometric templates | Deleted at session end |
| AI proctoring event logs | 6 months minimum (EU AI Act Art. 19) |
| AI scoring output | 12 months (audit purposes) |
| Interview transcripts | 12 months |
| Organization access logs | 12 months |
| Payment/invoice records | 7 years (statutory) |
Exception: Routine deletion of session recordings and logs may be suspended upon written notice from a federal Organization-customer in cases of litigation holds, IG inquiries, or FOIA requests.
Right to access, correct, and request deletion of your personal data; right to withdraw consent at any time without penalty; right to lodge a complaint with your local data protection authority.
Rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and the right not to be subject to a decision based solely on automated processing with legal or similarly significant effect (Art. 22) — satisfied through our mandatory human-review process, with a right to obtain that human review explained on request.
Right of access, right to correction and erasure, right to grievance redressal through our Grievance Officer, and the right to nominate another individual to exercise your rights in the event of death or incapacity (Section 14).
Right to know categories and specific pieces of personal information collected, right to delete, right to correct, right to opt out of "sharing" for cross-context behavioral advertising (we do not engage in this), and right to limit use of sensitive personal information (including biometric data, which we use only for the stated identity/integrity purposes).
See Biometric Data Notice for BIPA-specific rights, including the private right of action under 740 ILCS 14.
To exercise any right: contact@serin-ai.com. We respond within 30 days (extendable to 60 days under GDPR with notice; 30 days under DPDP). We will verify your identity before releasing or acting on any request.
Serin is intended for users who meet the minimum working age in their jurisdiction and is not directed at children. We do not knowingly collect data from individuals below this threshold. If we learn we have done so, we will delete the data upon request.
We maintain reasonable administrative, technical, and organizational safeguards to protect personal data against unauthorized access, loss, misuse, or disclosure. These measures include encryption in transit, encryption at rest, access controls based on business need, and ongoing security monitoring and testing. Additional details are available in our internal Security Policy and are summarized for Organizations in the Data Processing Agreement. Where Serin operates within a FedRAMP-authorized environment, all cryptographic modules are FIPS 140-2/140-3 validated per NIST SP 800-53 SC-13, multi-factor authentication complying with NIST SP 800-63B is enforced for privileged and remote access, and audit logs are retained online for a minimum of 90 days.
We will post the effective date of any change at the top of this Policy and, for material changes affecting your rights, notify you by email or in-platform notice before the change takes effect. Continued use after the effective date constitutes acceptance, except where a new consent act is independently required by law (e.g., a new biometric use), in which case we will obtain that consent separately.
General privacy inquiries: contact@serin-ai.com Data Protection Officer (EU/UK): contact@serin-ai.com India Grievance Officer: contact@serin-ai.com Postal address: A 327, Money Plant High Street, Nr BSNL Office, Beside Shell Petrol Pump, Jagatpur Road, S G Road, Ahmedabad- 382470
| Version | Date | Summary of Change |
|---|---|---|
| v1.0 | 13/07/2026 | Initial publication |
*Note: Biometric features described in this policy are not currently implemented and are currently in the development pipeline for future release.
Connecting skills with the opportunities they deserve
©2026 Serin. All rights reserved
Made on Earth, by Humans