AI Efficiency

Candidate Experience

Psychometric Test

Collaboration

Insights & Analytics

Data Security

Privacy Policy

Last Updated: 18-06-2026
1. INTRODUCTION

NDimensionZ Solutions Pvt Ltd. and its affiliates (“NDimensionZ”, “We”, “Our”, or “Us”) are committed to protecting and respecting your privacy. This Privacy Policy (“Policy”) explains how we collect, use, process, and disclose your personal data when you use our website, service offerings, and platform solutions, including YVI (collectively, the “Services”).

Our Services, powered by YVI, enable enterprises to conduct digital hiring to identify and onboard talent using AI technology. This Policy applies to all users of our Services, including candidates, clients (employers), and website visitors (“You” or “Your”).

We have designed this Policy to be compliant with applicable data protection laws, including the General Data Protection Regulation (GDPR). We reserve the right to amend this Policy at any time. We may update this Privacy Policy from time to time to reflect changes in our
business practices, technologies, legal requirements, or the Services. The updated Privacy Policy will be made available through our website and/or application and will indicate the date of the latest revision. Users are encouraged to review this Privacy Policy periodically. Where required by applicable law, or where changes materially affect the manner in which Personal Data is collected, used, disclosed, or otherwise processed, we may provide additional notice and, where necessary, obtain fresh consent before such changes take effect.

2. OUR ROLE: DATA CONTROLLER AND DATA PROCESSOR

Under the GDPR, an entity can be a Data Controller or a Data Processor.

  • A Data Controller determines the purposes and means of processing personal data.
  • A Data Processor processes personal data on behalf of the Controller.

Our role depends on the context:

  • NDimensionZ as Data Controller: When we collect your personal data for our own purposes, such as when you visit our website, request a demo, or subscribe to our marketing communications, we act as the Data Controller.
  • NDimensionZ as Data Processor: When you use our Services as a candidate for an assessment initiated by one of our clients (e.g., an employer or an academic institution), our client is the Data Controller. They determine the purpose of the data processing (e.g., recruitment or evaluation). In this scenario, we act as a Data Processor, processing your data on their instructions. For any requests regarding your data in this context, you should first contact the relevant Data Controller (the employer or institution).
3. LAWFUL BASIS FOR PROCESSING

We only collect and process your personal data where we have a lawful basis to do so under applicable law. Our lawful bases include:

  • Consent: Where you have given us clear and explicit consent for a specific purpose (e.g., subscribing to our newsletter). You can withdraw your consent at any time.
  • Contract: Where processing is necessary for the performance of a contract with you (e.g., to provide you with the Services you have registered for).
  • Legitimate Interests: Where processing is necessary for our legitimate interests or the legitimate interests of a third party, provided these interests are not overridden by your rights and interests. This includes improving our Services, analytics, and fraud prevention.
  • Legal Obligation: Where processing is necessary for us to comply with the law.
4. PERSONAL DATA WE COLLECT

We may collect and process the following categories of personal data:

a. Information You Provide Voluntarily:
  1. Contact and Identity Data: Name, email address, phone number, postal address.
  2. Professional Data: Resume/CV data, employment history, educational background, knowledge, skills, and abilities.
  3. Account Data: Username, password, and other registration information.
  4. Assessment Data: Your responses to assessment questions, which may be captured via text, audio, or video recordings.
  5. Biometric Data: Where required for proctoring and identity verification, this may include facial geometry data (face capture) and voiceprints. We will always seek your explicit consent for processing biometric data.
  6. Enquiry Data: Information you provide when you request a demo, contact customer support, or make other inquiries.
b. Information We Collect Automatically:
  1. Technical Data: IP address, browser type and version, device type, unique device identification numbers, operating system, and broad geographic location (e.g., country or city).
  2. Usage Data: Information about how you interact with our Services, including pages visited, features used, time spent, and referring/exit pages. We collect this information using cookies and similar tracking technologies.
c. Information We Receive from Third Parties:
  1. We may receive your personal data from our clients (the Data Controllers), such as your name and email address, to invite you to an assessment.
  2. We may receive information from publicly available sources or third-party data providers for marketing or sales purposes, where permitted by law.
5. HOW WE USE YOUR PERSONAL DATA

We use your personal data for the following purposes, based on the lawful bases described above:

  1. To Provide and Manage the Services: To create and maintain your account, facilitate assessments, and deliver our contractual obligations to you and our clients. (Lawful Basis: Contract; Legitimate Interests)
  2. To Communicate with You: To respond to your inquiries, send service-related announcements, provide customer support, and request feedback. (Lawful Basis: Contract; Legitimate Interests)
  3. For Analytics and Improvement: To understand how our Services are used, monitor performance, and improve the functionality, user experience, and relevance of our Services. (Lawful Basis: Legitimate Interests)
  4. For Marketing and Promotions: To send you marketing communications about our products and services that may interest you. We will only do this with your explicit consent. You can opt-out at any time. (Lawful Basis: Consent)
  5. For Security and Compliance: To verify identity, prevent fraud and unauthorized activity, enforce our terms, and comply with legal obligations, court orders, or law enforcement requests. (Lawful Basis: Legal Obligation; Legitimate Interests)
6. DATA SHARING AND DISCLOSURE

We do not sell your personal data. We may share your personal data with third parties only in the following circumstances:

  1. With Our Clients (Data Controllers): If you are a candidate, your assessment data and results will be shared with the client (employer or institution) who initiated the assessment.
  2. With Service Providers and Sub-processors: We engage third-party service providers to perform functions on our behalf, such as cloud hosting (e.g., AWS, Google Cloud), proctoring services, and analytics tools. These providers are contractually bound to protect your data and may only use it for the purposes we specify.
  3. With Affiliates: We may share information with other companies within the NDimensionZ group for operational purposes.
  4. In Connection with a Business Transfer: In the event of a merger, acquisition, dissolution, or sale of assets, your personal data may be transferred. We will notify you via email and/or a prominent notice on our website of any change in ownership or use of your personal data.
  5. To Comply with Laws: We may disclose your information to law enforcement, government authorities, or other third parties if we believe it is necessary to comply with a legal obligation, protect our rights or property, or ensure the safety of our users.
7. INTERNATIONAL DATA TRANSFERS
  1. Your personal data may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different from the laws of your country.
  2. Specifically, our servers are located in various jurisdictions, and our group companies and third-party service providers operate globally.
  3. For transfers of personal data from the European Economic Area (EEA) to countries outside the EEA, we have taken appropriate safeguards to ensure that your personal data remains protected in accordance with this Policy and applicable law. These safeguards include implementing the European Commission’s Standard Contractual Clauses (SCCs) for transfers of personal data or relying on other legally provided mechanisms.
8. DATA RETENTION

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for
the purposes of satisfying any legal, accounting, or reporting requirements.

  1. When acting as a Data Processor, we retain your data according to the instructions of the Data Controller (our client).
  2. When acting as a Data Controller, we determine the retention period based on the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use, the purposes for processing, and applicable legal requirements.

When we no longer have a legitimate business need to process your personal data,
we will either delete or anonymize it. If this is not possible
(for example, because your data is stored in backup archives), we will securely store your data and
isolate it from any further processing until deletion is possible.

9. YOUR DATA PROTECTION RIGHTS

Depending on your location and applicable law, you may have the following rights regarding your personal data:

  1. Right to Access: You have the right to request a copy of the personal data we hold about you.
  2. Right to Rectification: You have the right to request the correction of inaccurate or incomplete personal data.
  3. Right to Erasure (‘Right to be Forgotten’): You have the right to request the deletion of your personal data under certain conditions.
  4. Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data under certain conditions.
  5. Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
  6. Right to Object: You have the right to object to the processing of your personal data, particularly for direct marketing purposes.
  7. Right to Withdraw Consent: If we are processing your data based on your consent, you have the right to withdraw that consent at any time.
  8. Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data infringes applicable data protection laws.

To exercise any of these rights, please contact us at [email protected]. If your request pertains to data for which we are a Data Processor, we will forward your request to the relevant Data Controller.

10. COOKIES AND TRACKING TECHNOLOGIES

We use cookies, web beacons, and similar technologies to operate and improve our Services. A cookie is a small text file stored on your device. Some cookies are essential for the website to function, while others are used for analytics and personalization.

You can control the use of cookies at the individual browser level. If you reject cookies, you may still use our website, but your ability to use some features may be limited.

11. DATA SECURITY

We have implemented appropriate technical and organizational security measures designed to protect your personal data from accidental loss and from unauthorized access, use, alteration, or disclosure. These measures include encryption (such as SSL), access controls, and physical security safeguards.

You are responsible for keeping your account credentials confidential. We will never ask you for your password. While we strive to protect your personal data, no method of transmission over the Internet is 100% secure. Therefore, we cannot guarantee its absolute security.

12. CHILDREN’S PRIVACY

Our Services are not directed at children under the age of 18, unless the service is provided through an academic institution. If we process data of a person under the age of 18 (or the applicable age of consent in a jurisdiction) as part of a service to an academic institution, it is the institution’s responsibility as the Data Controller to obtain the necessary consent from a parent or legal guardian.

If we become aware that we have inadvertently collected personal data from a child without verifiable parental consent, we will take steps to delete the information as soon as possible.

13. THIRD-PARTY LINKS

Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices or the content of these third-party sites. This Privacy Policy does not apply to them. We encourage you to read the privacy policies of any third-party sites you visit.

14. CONTACT US

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer at:

NDimensionZ Solutions Pvt Ltd
Attn: Data Protection Officer
0503 & 0504, 5th Floor, A Wing, SCK01, SmartCity,
Infopark P.O., Cochin – 682042, Keralam, India
Email: [email protected]

We will respond to your inquiry within a reasonable timeframe and in accordance with applicable law.