Legal
Data processing
Last updated 2026-06-15.
Overview
This page combines three things in one place: the Article 28 data-processing terms that apply between Mockif LTD and customer organisations, the full subprocessor register, and a plain-English statement of the rights available to customers and to individual data subjects.
Mockif LTD is the data controller for personal data described on the privacy page. When a recruiter customer instructs Mockif to process data on its behalf (for example by posting a job description or unlocking a candidate identity), Mockif acts as a processor for that limited scope under the terms below.
Article 28 DPA summary
Where Mockif LTD processes personal data on behalf of a customer (“customer data”), the following terms apply. A signed DPA in the same shape is available on request to any paying customer or prospective enterprise buyer; email privacy@skillbricks.ai.
- Subject matter and duration
- Provision of the SkillBricks platform for the duration of the customer's subscription or credit validity, whichever is longer.
- Nature and purpose
- Hosting, storing, and retrieving customer data; matching job descriptions to candidate walls; recording identity unlocks; routing in-platform messages; generating invoices.
- Types of personal data
- Customer user contact details, job descriptions, credit transactions, unlock records, in-platform messages. No special-category data is deliberately processed.
- Categories of data subjects
- Customer employees (recruiters, administrators) and candidates who become visible to the customer through the platform (aggregate wall data before unlock; name and messaging after unlock).
- Mockif LTD obligations
- Process only on documented customer instructions; ensure authorised personnel are bound by confidentiality; implement the technical and organisational measures in the security page (Article 32); assist the customer with data-subject requests, DPIAs, and breach notifications; delete or return customer data on termination.
- Subprocessors
- Current subprocessors are listed below. Customers are notified at least 30 days before a new subprocessor is added and may object in writing; where an objection cannot be resolved, the customer may terminate the affected service.
- Audits
- Mockif will provide customers on request the certifications held by each subprocessor and the outcome of its own annual penetration test. On-site audits are available to enterprise customers on reasonable notice, scoped to avoid disruption and subject to confidentiality.
Subprocessor register
The third-party processors Mockif LTD relies on. Purpose and transfer basis reflect the current architecture; any change is announced at least 30 days in advance to paying customers by email and on this page.
Supabase Inc.
United States- Purpose
- Postgres database, authentication, storage, realtime channel.
- Data categories
- Account records, assessment events, wall data, payment references.
- Transfer basis
- UK IDTA + SCCs
- Certifications
- SOC 2 Type 2
Stripe Payments Europe Ltd. / Stripe, Inc.
Ireland (EU) and United States- Purpose
- Card payments, subscription billing, invoice generation, UK VAT calculation.
- Data categories
- Recruiter billing data, card token references (Stripe holds card numbers under PCI DSS), transaction history.
- Transfer basis
- UK IDTA + SCCs
- Certifications
- PCI DSS Level 1, SOC 1 / SOC 2
Resend, Inc.
United States- Purpose
- Transactional and marketing email delivery.
- Data categories
- Email addresses, display names, message metadata.
- Transfer basis
- UK IDTA + SCCs
- Certifications
- SOC 2 Type 2
Twilio Inc.
United States- Purpose
- SMS phone verification, VoIP carrier detection at signup.
- Data categories
- Phone numbers submitted at signup; verification SID returned.
- Transfer basis
- UK IDTA + SCCs
- Certifications
- ISO 27001, SOC 2 Type 2
Cloudflare, Inc.
United States- Purpose
- Turnstile anti-abuse challenge, CDN, DNS, bot mitigation.
- Data categories
- Request metadata, IP addresses, user-agent strings, challenge tokens.
- Transfer basis
- UK IDTA + SCCs
- Certifications
- ISO 27001, SOC 2 Type 2
Anthropic PBC
United States- Purpose
- Claude API for the AI examiner, session agent, and challenge generation.
- Data categories
- Assessment prompts and candidate free-text. Real names, emails, and phone numbers are never sent.
- Transfer basis
- UK IDTA + SCCs
- Certifications
- SOC 2 Type 2
OpenAI, L.L.C.
United States- Purpose
- Speech-to-text and text-to-speech for the optional, opt-in voice interview (gpt-4o-transcribe and gpt-4o-mini-tts). Voice input/output only; Claude remains the examiner.
- Data categories
- Candidate spoken audio, transcribed then discarded in memory with no voiceprint or speaker identification, and examiner question text for synthesis. Real names, emails, and phone numbers are never sent. API traffic is not used to train models.
- Transfer basis
- UK IDTA + SCCs
- Certifications
- SOC 2 Type 2
Hetzner Online GmbH
Germany- Purpose
- Infrastructure hosting for the App Cluster, Execution Cluster, observability stack, and Vault.
- Data categories
- All platform data at rest on our behalf; Hetzner does not process as a controller.
- Transfer basis
- Within UK/EEA adequacy; no additional transfer required.
- Certifications
- ISO 27001
GitHub, Inc. (GHCR)
United States- Purpose
- Container image registry for our deployed workloads.
- Data categories
- Container image metadata and our own build artefacts. No candidate or recruiter personal data.
- Transfer basis
- UK IDTA + SCCs
- Certifications
- SOC 2 Type 2
Retention at a glance
Retention windows below are the runtime source of truth, pulled from the platform configuration. Full rationale is in the privacy policy.
- Raw assessment events (command logs, dialogue turns): 90 days.
- Session metadata summaries: 365 days.
- Aggregate scores, walls, and the brick proof trail: retained indefinitely (until account deletion or erasure).
- Payment and tax records: 7 years (UK tax law).
- Administrative audit log: 7 years.
International transfers
Where personal data is transferred outside the United Kingdom or European Economic Area, Mockif LTD relies on the UK International Data Transfer Addendum combined with the European Commission's Standard Contractual Clauses (2021). Transfer impact assessments have been completed for each US-hosted subprocessor and are available to enterprise customers under NDA.
Supplementary measures include encryption at rest (AES-256), TLS 1.3 in transit, PII scrubbing before data leaves the App Cluster for observability, and isolation of candidate sandboxes on infrastructure that holds no identifiable personal data.
Customer rights
Customers (recruiter organisations) and data subjects (candidates, recruiter employees) have the following rights. Customers exercise them via their account owner; individuals can exercise them directly even where they are associated with a customer organisation.
- Right to access. Copy of the personal data we hold, delivered self-service from
/settings/dataor on request to privacy@skillbricks.ai. - Right to rectification. Correct inaccurate profile, wall, or recruiter data.
- Right to erasure. Delete the account and associated personal data, subject to tax-law retention of payment records.
- Right to portability. Machine-readable export of your wall, your assessment history, and your account data.
- Right to restriction and objection. Stop or limit specific processing activities, including automated tier computation under Article 22.
- Right to withdraw consent. For marketing communications and non-essential analytics, at any time.
- Right to lodge a complaint. With the UK Information Commissioner's Office or the equivalent supervisory authority in your country.
Response window: 30 days from verified request. We verify requests using account-ownership checks rather than by collecting new ID data, to avoid creating additional PII exposure.
Subprocessor change policy
Paying customers are notified at least 30 days before a new subprocessor is added. Objections may be raised to privacy@skillbricks.ai. Where an objection cannot be resolved, the customer may terminate the affected service without penalty. The public register on this page is the authoritative list; the internal record of processing activities sits alongside it.
Contact
Mockif LTD - Privacy Team
privacy@skillbricks.ai
A signed countersigned DPA is provided on request. Enterprise customers can request additional documents (transfer impact assessments, SOC 2 reports from subprocessors, the results of our most recent penetration test) under NDA.