Competencio

Legal

Privacy Policy

This policy explains who is responsible for your data, what Competencio processes, why it is processed, and the rights available to you.

Last updated: September 2026

1. Controller and service provider

worksnap GmbH operates Competencio and is the controller under Art. 4(7) GDPR for this website, account administration, billing, security, and direct communication with customers. Full provider identification is available in the Imprint.

worksnap GmbH
Paulsborner Str. 85
10709 Berlin
Germany

Represented by Managing Director Niklas Babel

Commercial register: District Court of Charlottenburg (Berlin), HRB 256516

Email: hello@competencio.com

When a Competencio customer is the controller

Organisations use Competencio to run assessments, recruiting workflows, and interviews. For personal data they enter or collect for those purposes, that organisation normally decides why and how the data is processed and is therefore the controller. worksnap GmbH processes that customer content on its documented instructions as a processor under Art. 28 GDPR. If you participate in an assessment or apply for a role, direct requests about that process to the organisation named in your invitation, job posting, or processing notice. We support the organisation in responding to your request.

2. Data we process

Website and technical data

IP address, request time, requested URL, referrer, browser and device information, and security or error diagnostics. These data are generated when your device communicates with our servers.

Accounts and service use

Name, email address, organisation, membership and role, authentication and session data, support messages, configuration, billing status, and audit events. Required account fields are needed to create and secure an account; without them we cannot provide access.

Assessment data

Participant and assessor details, schedules, exercises, observations, ratings, evidence, competency analyses, facilitator decisions, and reports entered or generated by authorised users.

Recruiting and interview data

Candidate contact details, job history, CVs and other documents, application source, interview answers, recordings, transcripts, reviewer notes, scorecard evidence, workflow status, and decisions made by the customer's authorised users. Data may come directly from you, from the customer, or from an integration the customer configures, such as email intake or an ATS.

Contact and payment data

Information you include in enquiries and support conversations. For paid subscriptions, Stripe processes payment details; Competencio receives identifiers, status, and invoice-related information but does not store complete card details.

3. Purposes and legal bases

Providing the service and taking pre-contractual steps (Art. 6(1)(b) GDPR): creating accounts, authenticating users, operating requested workflows, support, and billing where you are the contracting party.

Legitimate interests (Art. 6(1)(f) GDPR): secure and reliable operation, fraud and abuse prevention, troubleshooting, product improvement, and communication with a customer's personnel. Our interests are operating a secure B2B service and improving it without overriding the rights of affected people. You may object as described below.

Legal obligations (Art. 6(1)(c) GDPR): tax, commercial, accounting, compliance, and lawful authority requests.

Consent (Art. 6(1)(a) GDPR): where we expressly ask for consent, for example for optional communications. You may withdraw consent at any time with effect for the future; this does not affect processing before withdrawal.

For assessment, application, and interview content processed on behalf of a customer, the customer determines the applicable legal basis and provides the process-specific privacy information. Where special-category data under Art. 9 GDPR are involved, the customer must also establish an Art. 9 condition. Please do not provide such data unless the process requires it and you have been instructed how it will be handled.

4. AI-assisted processing and human decisions

Competencio includes AI-assisted functions such as document extraction, transcription, evidence structuring, score suggestions, and draft reports. Depending on the feature and configuration, relevant input may be sent to a configured AI provider, including Google Gemini, OpenAI, or Anthropic. Only data needed for the requested function should be sent.

AI output is advisory. Competencio does not make hiring or assessment decisions based solely on automated processing, and authorised humans remain responsible for reviewing evidence and making decisions. Candidate video interviews do not use image, facial, emotion, or biometric analysis. Where the customer enables report synthesis, application documents and interview transcripts may be used to infer BFI-2-based personality traits with an explicit confidence level. These inferences are evidence for human review, not diagnoses or autonomous decisions. The direct-application form and each process-specific interview notice identify this processing before data are collected, together with the customer controller, purpose, available alternatives, and retention settings where applicable.

5. Recipients and international transfers

Data are available only to authorised users of the relevant customer and to personnel who need access to operate and support Competencio. We use processors for hosting and content delivery, file and video storage, transactional email, payment processing, AI functions, and application monitoring. Current providers may include Cloudflare, Postmark, Stripe, Google, OpenAI, Anthropic, AppSignal, and Honeybadger. Customer-configured integrations receive data only when the customer instructs Competencio to use them.

When a page is opened, your browser may retrieve web fonts or front-end modules directly from Google Fonts, jsDelivr, or JSPM. Those providers receive technical request data such as your IP address, browser information, and the requested resource. We use these resources to deliver a consistent and secure interface on the basis of our legitimate interests under Art. 6(1)(f) GDPR.

Some providers are established outside the European Economic Area or may process data there. Where no adequacy decision applies, transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where necessary, supplementary measures. Contact us for information about the safeguards relevant to a particular transfer.

We disclose data to public authorities or professional advisers only where required by law or necessary to establish, exercise, or defend legal claims. We do not sell personal data.

6. Retention and security

Retention

Website logs are kept only as long as needed for security and troubleshooting. Account and customer content remain for the contract term and are then deleted or anonymised under the customer's instructions, subject to backups, legal holds, and statutory retention duties. Commercial and tax records remain for the period required by law.

Unsubmitted interview media are scheduled for deletion after 24 hours. Submitted interview media are retained for the customer's configured period, normally 7โ€“180 days; transcripts normally 30โ€“365 days. A customer may shorten these periods, and a documented legal hold may temporarily suspend deletion.

Security

We use TLS in transit, access controls, account isolation, encrypted storage or application-level encryption where appropriate, signed and expiring access tokens, audit records, backups, and monitoring designed to protect confidentiality, integrity, and availability. No online service can guarantee absolute security.

7. Cookies and device storage

Competencio uses strictly necessary signed cookies to maintain authenticated sessions and, on candidate interview pages, to recognise the invited browser. These cookies are HTTP-only and are not used for advertising. Local storage is used for requested interface preferences, dismissed notices, and to resume an unfinished browser upload. These functions are necessary to provide the service or preference you request within the meaning of § 25(2) TDDDG.

Competencio does not currently load optional analytics, referral, or marketing scripts. The dormant administrative script registry is not rendered by the application. Before introducing technology that accesses or stores non-essential information on your device, we will implement the consent controls required by § 25 TDDDG and the GDPR and update this policy. This policy itself is not consent.

8. Your rights

Subject to the applicable conditions, you have the right to:

  • Access your personal data and receive a copy (Art. 15 GDPR).
  • Rectify inaccurate or incomplete data (Art. 16 GDPR).
  • Erase data (Art. 17 GDPR).
  • Restrict processing (Art. 18 GDPR).
  • Receive or transfer portable data (Art. 20 GDPR).
  • Object to processing based on legitimate interests (Art. 21 GDPR).
  • Withdraw consent at any time with effect for the future.

You may also lodge a complaint with a supervisory authority, particularly in the EU member state of your residence, workplace, or the alleged infringement. Our lead authority is the Berlin Commissioner for Data Protection and Freedom of Information.

To protect your data, we may need to verify your identity. If a Competencio customer controls the relevant assessment or recruiting data, we will forward or coordinate the request with that customer.

9. Contact and changes

For privacy questions or to exercise a right, email hello@competencio.com.

We update this policy when the service or legal requirements change. Material changes will be communicated through an appropriate channel. The date above identifies the current version.