Benchmark.games · GDPR Art. 13

Privacy notice for candidates

Last updated: 6 September 2026

About this notice

This page is the controller's disclosure to you under Article 13 of the EU General Data Protection Regulation (GDPR). It explains what personal data Benchmark.games processes when you create an account, apply, or participate in a video interview or assessment on this platform, why we process it, the legal basis for each purpose, who receives it, how long we keep it, and which rights you can exercise, and how. Read this together with the screen shown immediately before your first video question, which sets out what is recorded and what is done with the recording.

Scope: this notice covers candidate-side processing only. If you are an HR user, partner administrator, or platform operator, separate notices apply.

Who is the data controller

The controller of your personal data is:

  • Legal entity: Gravitalent Kft.
  • Registered office: 4400 Nyíregyháza, Nyár utca 7. 2/2., Hungary
  • Company registration number (cégjegyzékszám): 15-09-063630
  • Tax number (adószám): 11490096-2-15
  • General contact: support@benchmark.games

In some cases, the HR organisation you applied to is a joint controller with us for the purposes of evaluating your application (Art. 26 GDPR). The HR organisation's identity is shown to you on the application page and on the screen before your first video question. The HR organisation is independently responsible for its hiring decision; Benchmark.games is responsible for the platform, the AI processing pipeline, and the audit trail.

Privacy contact and Data Protection Officer

The single privacy contact channel for all rights requests, complaints, and questions under this notice is:

privacy@benchmark.games

Gravitalent Kft. has not formally appointed a Data Protection Officer under GDPR Art. 37, on the basis that our core activities do not meet the criteria in Art. 37(1)(b)-(c). The general privacy contact for all data-subject requests under Articles 12-22 is the address above, which is monitored by trained staff.

We respond to substantive requests within 30 calendar days as required by Art. 12(3) GDPR, and will tell you in writing if we need to extend this by up to two further months for complex cases, with reasons (Art. 12(3)).

Why we process your data and on what legal basis

We process your personal data for four distinct purposes. Each purpose has its own legal basis under GDPR Art. 6 and, where applicable, Art. 9.

(a) Conducting the video interview or assessment itself.

We capture your video and audio response, your typed answers, your CV (if uploaded), and basic profile data so that you can complete the interview and so that the HR organisation can evaluate your application. Where screen recording is switched on for the assessment you are taking, we also record your screen for the length of that assessment, and you are told so on the screen before you start it.

  • Art. 6(1)(b) GDPR, performance of a contract with you (the candidate-platform agreement you enter when you start the assessment), and steps taken at your request prior to entering into a contract with the HR organisation.
  • Art. 9(2)(a) GDPR, your explicit consent to the processing of biometric data (the recording of your face and voice). You give this consent by continuing past the screen before your first video question, which sets out what is recorded and what is done with the recording. If you do not want to be recorded, decline the camera and microphone access your browser asks for: the question then offers you a way to skip it, and you can go on with the rest of the assessment. Nothing is recorded for a question you skip.

(b) AI-assisted transcription and competency scoring for the HR organisation's evaluation.

We send your recorded answers to an EU-hosted large language model for automatic transcription and competency scoring. The output is an advisory report shown to the HR reviewer (glass-box: the reviewer sees the score, the underlying transcript, the prompts, and the model identity). AI assists the scoring, it never decides: a human recruiter makes the final decision. AI-assisted scoring is switched on for everyone by default, and you can switch it off for any assessment at any time in your candidate account, under Settings, then Privacy. When it is off, no AI score is produced for you and the recruiter reviews your answers without one. Your recorded answers are still transcribed automatically, because the recruiter reads what you said; only the AI scoring stops.

  • Art. 9(2)(a) GDPR, explicit consent, given for the recording and for the analysis of it together, at the screen before your first video question. There is no second, separate AI consent step during the assessment: AI-assisted scoring is on for everyone by default, and the way you refuse it is to switch it off in Settings, then Privacy (see Section 10).
  • Art. 6(1)(a) GDPR, the same consent covers the automated processing of the resulting scores. See Section 13 on automated decision-making safeguards.

(c) Compliance, audit trail, and integrity of the hiring process.

We retain a tamper-evident log of consents granted, scores generated, model versions used, who reviewed what, and what decision was made. This is necessary to meet our and the HR organisation's legal obligations (e.g. equal-treatment audit, anti-discrimination regulations, EU AI Act record-keeping) and to enable you to exercise your Art. 22(3) right to contest a decision.

  • Art. 6(1)(c) GDPR, compliance with legal obligations to which the controller is subject.

(d) Fraud detection and assessment integrity.

We compute a suspicion score for each session using signals such as IP intelligence, device fingerprint, session timing, and behavioural patterns, in order to detect impersonation, multi-account abuse, and answer-leak attempts.

  • Art. 6(1)(f) GDPR, legitimate interests pursued by us and by the HR organisation in safeguarding the integrity of the assessment process and preventing fraud. See Section 5 for the balancing test.

We do not process your data for any other purpose without first informing you and, where required, obtaining a fresh legal basis.

Legitimate-interest balancing test (fraud detection)

For purpose (d) above, we rely on Art. 6(1)(f), legitimate interests. The balancing test we performed is as follows.

  • Interest pursued: detecting and preventing assessment fraud (impersonation, account sharing, automated answer-bot use, answer-leak). Fraud undermines the validity of every candidate's score, damages the integrity of hiring outcomes, and creates discriminatory effects against honest candidates.
  • Necessity: no less intrusive measure achieves the same outcome. Manual human review of every session is not scalable; behavioural and device signals are the established industry method.
  • Impact on the candidate: the signals we use (IP geolocation at country/city granularity, device fingerprint hash, session timing, behavioural patterns) are not used for advertising, profiling for any external party, or any decision other than the suspicion score itself. The suspicion score is one input to the HR reviewer, never the sole basis for a hiring decision.
  • Safeguards: (i) the suspicion score has a calibrated threshold (60) above which manual human review is triggered and an "under review" status is shown to you; (ii) you may object to this processing under Art. 21(1) GDPR (see Section 9); (iii) raw fraud signals are retained for the shorter of 30-90 days at the processor (FingerprintJS: 90 days; IPQS: 30 days) or the session retention period; (iv) the score itself is part of the audit trail and disclosable to you on request.

Conclusion: the interest is overriding, but conditional on the safeguards listed.

Who receives your data

Your personal data is shared only with the following categories of recipients.

(a) The HR organisation you applied to.

The HR organisation named on the application page, and on the screen before your first video question, receives your CV, your interview responses (video, audio, transcript), your AI-generated competency scores, the reviewer's notes, and your screen recording where the assessment was screen-recorded. The HR organisation is a joint or independent controller (depending on the contractual setup) and is independently bound by GDPR.

(b) Microsoft Ireland Operations Limited (Azure OpenAI).

Microsoft acts as our data processor under a Data Processing Agreement. Your audio and transcript are sent to an Azure OpenAI deployment in the Sweden Central Azure region for transcription (Whisper-class model) and scoring (GPT-4o-class model). Microsoft is contractually prohibited from using your data to train its models and is bound by EU Standard Contractual Clauses where applicable.

(c) Benchmark.games internal staff.

Trained staff at Benchmark.games can access your data to provide platform support, investigate disputes, respond to your rights requests, and audit AI behaviour. This includes your video answers and, where the assessment was screen-recorded, the screen recording. Our own administrators are not limited to one HR organisation, so this access is not confined to the organisation you applied to.

(d) Platform infrastructure processors.

The following sub-processors host or transmit your data on our behalf under data processing agreements:

  • Supabase (Supabase Inc.), primary database and storage; EU region eu-central-1 (Frankfurt, Germany).
  • Vercel (Vercel Inc.), application hosting; EU edge. Compute region pinned to fra1 (Frankfurt, Germany) in vercel.json.
  • SendGrid (Twilio Inc.), transactional email delivery (sub-processor: US).
  • Trigger.dev, background job orchestration. Your video, audio and transcript never leave the EU: media stays in Supabase Frankfurt and is sent only to Azure OpenAI Sweden Central for AI inference. Run-orchestration metadata (job IDs, task names, payload references, log lines) transits Trigger.dev's managed cloud, which is operated outside the EEA under EU Standard Contractual Clauses.
  • DocuSense (docusense.work), CV document extraction. Receives your CV file and returns its structured contents on our behalf under a data processing agreement. It uses an AI sub-processor operated outside the EEA to read the document (see section 7).
  • Anthropic PBC (United States), Claude models. Receives your CV, or the employment history and summary extracted from it, in order to structure it and to infer transversal competencies. Contractually prohibited from using your data to train its models, and bound by EU Standard Contractual Clauses.
  • Voyage AI (United States), text embeddings. Receives the skills and role descriptions extracted from your CV, as text, to turn them into the numeric vectors we match roles with. Bound by EU Standard Contractual Clauses.
  • Groq, Inc. (United States), fast inference. Receives the text of your CV when our primary extractor is unavailable, in order to structure it. Bound by EU Standard Contractual Clauses.
  • OpenAI, Inc. (United States), GPT and embedding models. Receives your written quiz answers, to check whether an answer appears to have been generated by AI, and a numeric profile derived from your assessment behaviour. Contractually prohibited from using your data to train its models, and bound by EU Standard Contractual Clauses.
  • Sentry / BetterStack: error monitoring and uptime; only pseudonymised diagnostic data.
  • FingerprintJS, IPQS, Matomo, fraud detection signals (see also our fairness and bias monitoring report).

(e) Disclosures required by law.

Where we are legally compelled to disclose data (e.g. a court order or a competent supervisory authority's request), we will do so to the minimum extent necessary and will notify you unless legally prohibited.

We do not sell your data. We do not share your data with advertising networks. We do not disclose your data to third parties beyond the categories listed above.

International transfers of data

Your interview recordings, transcripts and scores are stored and processed in the European Union. Your CV is read by AI sub-processors operated outside the EEA, as set out below. Specifically:

  • Primary database and object storage: EU region eu-central-1 (Frankfurt, Germany).
  • AI transcription and scoring of your interview: Azure OpenAI Sweden Central (EU).
  • Application hosting: EU edge regions.

Transfers outside the EEA:

  • CV reading and competency inference: DocuSense, Anthropic (US) and Voyage AI (US). Your CV file, or the employment history, summary and skill list extracted from it, is processed outside the EEA under EU Standard Contractual Clauses. Your interview video, audio, transcript and AI scores are not part of this transfer.
  • Quiz answer checks and behavioural profiling: OpenAI (US). Your written answers and a numeric profile derived from how you took the assessment are processed outside the EEA under EU Standard Contractual Clauses.
  • SendGrid (US): transactional email metadata (your email address, subject, delivery status). Twilio relies on EU Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework where applicable.
  • FingerprintJS (US) and IPQS (US): fraud-detection lookup payloads (IP, device fingerprint hash). SCCs in place; retention 30-90 days at the processor.
  • Sentry: error monitoring is configured against Sentry's EU instance (Frankfurt; ingest.de.sentry.io), so diagnostic data remains in the EEA. Pseudonymised diagnostic data only.

We do not transfer your interview video or transcript outside the EEA. Your CV, your written quiz answers, and a numeric profile derived from your assessment behaviour are processed by AI sub-processors operated outside the EEA, as described above. Where transfers occur, we rely on Art. 46 GDPR safeguards (EU SCCs) and, where available, Art. 45 adequacy decisions.

How long we keep your data

Each data category has its own retention period.

Data categoryDefault retentionNotes
Video recording365 days from session completionPer-project configurable by the HR organisation; minimum 30 days, maximum 730 days, default 365 days if the HR organisation does not set a value. Values outside the 30-730 day range are silently clamped to the nearest bound.
Audio + transcriptSame as videoDeleted together with the video.
AI-generated competency scoresSame as videoRetained as long as the underlying recording exists.
CV / uploaded documentsSame as video, or until you withdraw, whichever is sooner-
Email address + name (account)Until you delete your account, plus a 30-day grace period-
Audit log (consents, decisions, model versions, reviewer access)Up to 5 years from event dateRetained on the basis of Art. 6(1)(c) for legal-obligation compliance (anti-discrimination audit, EU AI Act record-keeping). Scoring audit entries are append-only at the database level (no UPDATE or DELETE permitted, per EU AI Act Art. 12) and outlive the underlying media: once the video and transcript are deleted at the end of the retention period, the pseudonymised audit metadata survives so the historical hiring record can be reconstructed.
Fraud / suspicion-score signals (raw)30-90 days at the processor (FingerprintJS: 90 days; IPQS: 30 days)Shorter of the figure and the session retention.
Fraud / suspicion score (computed)Same as audit logPart of the decision record.

After the retention period we apply anonymisation in line with Art. 17(3)(b) GDPR, identity-linking columns (name, email, IP, CV) are deleted or hashed beyond reversibility, but the pseudonymised audit-trail entry survives so that the integrity of the historical hiring record (for legal-obligation purposes) is preserved.

Per-project overrides: the HR organisation can choose a shorter retention than the default, never a longer one. The active retention setting for your session is shown on your data-export download under "Active retention".

Your rights and how to exercise them

You have the following rights under the GDPR. To exercise any of them, write to privacy@benchmark.games with your name, the email address associated with your account, and a description of your request. We respond within 30 calendar days (Art. 12(3)).

  • Art. 15, Right of access. You can request a copy of all personal data we hold about you, including AI-generated scores, transcripts, the reviewer's notes (where lawful), and the audit trail. A self-service export is also available at /api/v1/candidates/{candidateId}/export-data (Settings → Privacy → Download my data).
  • Art. 16, Right to rectification. You can ask us to correct inaccurate personal data and to complete incomplete personal data (e.g. CV details, email address). For the AI-generated score itself, which is an opinion, not a fact, please use the contest channel in Section 13.
  • Art. 17, Right to erasure ("right to be forgotten"). You can request deletion of your video, transcript, scores, and CV at any time.

    Carve-out: once a session has reached a scored, under_review, or decided state, the audit trail entry (consent grants, decision metadata, pseudonymised score) is retained on the basis of Art. 6(1)(c) and Art. 17(3)(b), legal-obligation and public-interest archiving exemption, but the underlying video, audio, transcript, and CV will be deleted. This carve-out is also explained in Section 8.

  • Art. 18, Right to restriction. You can ask us to suspend processing while we verify the accuracy of your data, while we examine an Art. 21 objection, or while you contest the lawfulness of processing.
  • Art. 20, Right to data portability. Where processing is based on consent or contract (Sections 4(a) and 4(b)), you can receive your data in a structured, commonly used, machine-readable format (JSON), and have it transmitted to another controller where technically feasible.
  • Art. 21, Right to object. You can object at any time, on grounds relating to your particular situation, to processing based on legitimate interests, specifically the fraud detection in Section 4(d). If you object, we will cease that processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
  • Art. 22(3), Right to human review of automated decisions. Even though every hiring decision on this platform is made by a human, the AI-generated score is an automated input. You have the right to request human review of the AI-generated score by a Benchmark.games staff member independent of the original review; to express your point of view in writing; and to contest the score. See Section 13 for the procedure.

How to exercise any right: email privacy@benchmark.games, or use the self-service tools in your candidate settings. We do not charge for processing rights requests except in the case of manifestly unfounded or excessive requests (Art. 12(5)). We may ask you to verify your identity before disclosing data.

Withdrawing your consent

Where processing is based on your consent (Sections 4(a) and 4(b), biometric data and AI scoring), you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR).

You can withdraw in two ways:

  • Self-service: Candidate dashboard → Settings → Privacy. Every assessment you have taken is listed there with its own AI switch. Switching it off deletes the AI analysis already produced for that assessment and stops any further AI scoring of it, at once and without asking anyone. It does not delete the recordings themselves; for that, use the email route below.
  • By email: privacy@benchmark.games with the subject "Consent withdrawal, video interview". We will action your request within 30 days.

Withdrawal is per assessment, and the two halves are separate. Switching AI scoring off leaves your recordings in place for the recruiter to watch and read; asking us to delete the recordings removes the AI scores with them, because there is nothing left to score. Neither one withdraws your application, and neither one is held against you.

Consequences of withdrawal: the HR organisation will no longer have an AI-generated score or video for you. Depending on the HR organisation's evaluation process, this may mean your application cannot be assessed using this platform. This consequence is purely procedural, there are no fines or penalties.

Right to lodge a complaint with a supervisory authority

If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a data protection supervisory authority under Art. 77 GDPR.

Hungarian supervisory authority (lead authority for Benchmark.games):

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)

Address: Falk Miksa utca 9-11, 1055 Budapest, Hungary

Postal: 1363 Budapest, Pf. 9

Phone: +36 1 391 1400

Email: ugyfelszolgalat@naih.hu

Web: https://naih.hu

You can also lodge a complaint with the supervisory authority in the EU/EEA Member State of your habitual residence, your place of work, or the place of the alleged infringement. For Hungary, that is NAIH; for Germany, the BfDI; for Poland, the UODO; etc. A full list is published by the European Data Protection Board at https://edpb.europa.eu.

Lodging a complaint with a supervisory authority does not affect any other administrative or judicial remedy you may have.

Is providing your data mandatory?

Providing your personal data and giving consent to biometric and AI processing is entirely voluntary. There is no statutory or contractual obligation that requires you to participate in the video interview on this platform.

Consequence of not providing data or refusing consent: the HR organisation may not be able to assess your application using this platform's video interview and AI-scoring features. The HR organisation may offer alternative assessment paths (e.g. text-only assessment, in-person interview); whether such alternatives are available depends on the HR organisation and the role you applied to, not on Benchmark.games.

There are no penalties. Refusing consent does not result in fines, blacklisting on this platform, automatic rejection for other roles, or any consequence beyond the procedural one described above.

You can still complete non-video parts. If you decline the camera and microphone access your browser asks for, the video question offers you a way to skip it and you can complete the text-based elements where they are offered. You also keep the ability to apply directly to the HR organisation through any channel they make available outside this platform.

Automated processing and your right to human review

Scope. Benchmark.games uses AI systems at three points in this pipeline. First, when you submit your CV, we classify how relevant your work history is to the role, and combine that with other CV-derived factors into a weighted score and a tier from A to D that the recruiter sees when reviewing applications. Second, we transcribe your video answers and generate competency scores on a defined competency rubric. Third, we cross-check what you said in your video interview against your CV and against the job details published for the role, producing a consistency signal and an indicator of any mismatch with your stated expectations. All of these AI outputs are advisory, every hiring decision on this platform is made by a human reviewer at the HR organisation, and none of them results in an automatic rejection. The AI does not autonomously accept, reject, or rank candidates without human involvement (so Art. 22(1) does not strictly apply on its face), but because the AI output strongly informs the human decision, we apply Art. 22 safeguards as a matter of policy.

Logic involved. CV pre-screen: we compare the tasks and keywords in your CV against the role's requirements, and classify the industry of the employers on your CV using records we already hold and, when those do not resolve it, an AI classification step. These signals, together with your job tenure and CV quality, are combined into a weighted score and a tier from A to D, always shown to the recruiter together with a verbatim quote from your CV as supporting evidence. Video scoring: the AI used is a large-language-model (GPT-4o class) hosted on Azure OpenAI Sweden Central. Inputs: your transcript and the HR organisation's competency rubric. Outputs: a score per competency on a defined scale, supporting evidence excerpts from your transcript, and a short reasoning paragraph. Interview cross-check: an AI system compares your transcript against your CV and against the job details published for the role, producing a consistency signal and an indicator of whether your stated expectations match what was published, shown to the recruiter alongside the transcript passages they are based on. The model identity, prompt version, and rubric version are recorded in the audit trail for every one of these steps.

Spoken language. On campaigns that switch them on, two further measures are taken from the same video answers you already recorded, and each is only used where the employer has given it a weight. Spoken English accuracy counts grammatical points in what you said, and only in three narrow categories of verb and noun form; a point is counted only where two independent transcription systems heard the same words, and a person reviews the points before any of them reaches an employer. Spoken fluency measures how the answers were delivered: your speaking rate, how much of the answering time carried speech, how many words you spoke between pauses, and how often you paused. It is worked out purely from where the word boundaries fall in the recording, with no AI model involved. Neither measure makes any claim about your accent, your pronunciation, your vocabulary, your comprehension, or your level of English, and neither is used as a language qualification. Both contribute to the Fit Score for the role, at the weight the employer set, and both are dropped entirely rather than counted as zero when there was not enough speech to measure. The employer is never shown a fluency number, and is shown a spoken English point only after a person has confirmed it. Your right to human review, set out below, applies to both.

Significance and consequences for you. The score directly informs the HR reviewer's evaluation of your fit for the role. A low score does not by itself reject your application; a high score does not by itself accept it. The human reviewer sees the score, the transcript, your CV, and the reasoning paragraph (glass-box).

Safeguards under Art. 22(3): you have the right to -

  1. Request human review by a Benchmark.games staff member independent of the original review. We will re-examine the AI score against the underlying transcript and the rubric and produce a written outcome.
  2. Express your point of view in writing, your statement will be added to the candidate record and shared with the HR reviewer.
  3. Contest the AI score. If we agree the score was generated in error (e.g. transcription error, rubric misapplication, model malfunction), we will correct it and notify the HR organisation. If the HR organisation has already made a final hiring decision based on an erroneous score, we will inform them and recommend reconsideration; the HR organisation is independently responsible for the final outcome.

How to invoke these safeguards. Email privacy@benchmark.games with the subject "Art. 22(3), request for human review". Include your name, the session identifier (visible in your candidate dashboard), and a brief description of your concern. We respond within 30 days (Art. 12(3)).

Profiling. We do not profile you for marketing, advertising, credit-scoring, insurance-underwriting, or any other purpose unrelated to the assessment you are taking.

AI-assisted interview preparation. With a recruiter's explicit action, we may generate suggested interview questions and a one-page interview companion from your CV and assessment results, to help a human interviewer prepare. These are suggestions for a person, they are not automated decisions and do not determine any outcome. You can request a copy of any such material generated about you under your right of access.

See also: our fairness and bias monitoring report.