Privacy Policy

Effective date: 03/14/19

We at Karat, Inc. (“Karat,” “we” and “us”) know you care about how your Personal Data is used and shared, and we take your privacy seriously. Please read the following to learn more about our Privacy Policy. This Privacy Policy is a binding contract between you and Karat. By using or accessing our website(s), products, services and applications (“Services”) in any manner, you acknowledge that you accept the practices and policies outlined in this Privacy Policy, and you hereby consent that we will collect, use, and share your information in the following ways.

If you are a resident of the European Union (“EU”), Switzerland, United Kingdom, Lichtenstein, Norway, or Iceland, you may have additional rights under the EU General Data Protection Regulation (the “GDPR”) with respect to your Personal Data, as outlined herein. If you have any questions about this Privacy Policy or whether any of the following applies to you, please contact us at privacy@karat.io. Remember that if you are a candidate participating in interviews with prospective employers conducted via Karat’s online interviewing platform (the “Interview Services”), your use of Karat’s Services is at all times subject to the Job Candidate Interview Agreement (the “Candidate Agreement”) which incorporates this Privacy Policy. Any terms we use in this Policy without defining them have the definitions given to them in the Candidate Agreement.

What does this Privacy Policy cover?

This Privacy Policy covers our treatment of personally identifiable information, including “Personal Data” as it is defined in the GDPR (“Personal Data”), that we gather when you are accessing or using our Services, but not to the practices of companies we don’t own or control, or people that we don’t manage. For this Privacy Policy, we also use the term “processing” as it is defined in the GDPR, which generally covers actions that can be performed in connection with data such as collection, use, storage and disclosure. We will be the controller of your Personal Data processed in connection with the Services. Note that, in connection with our provision of Services to our partners who utilize Karat’s Services (“Partners”), we may also process Personal Data of our Partners’ end users, employees, or past or current candidates for employment who have not participated in Karat’s Interview Services or agreed to the Candidate Agreement, in which case we are the processor of Personal Data. If we are the processor of your Personal Data (i.e., not the controller), please contact the controller party in the first instance to address your rights with respect to such data.

We gather various types of Personal Data from our users, as explained in more detail below, and we use this Personal Data internally in connection with our Services, including to personalize, provide, and improve our Services, to allow you to set up a user account and profile, to contact you and allow other users to contact you, to fulfill your requests for certain products and services, and to analyze how you use the Services. In certain cases, we may also share some Personal Data with third parties, but only as described below.

We do not knowingly collect or solicit Personal Data from anyone under the age of 16. If you are under 16, please do not attempt to register for the Services or send any Personal Data about yourself to us. If we learn that we have collected Personal Data from a child under age 16, we will delete that information as quickly as possible. If you believe that a child under 16 may have provided us Personal Data, please contact us at privacy@karat.io.

Will Karat ever change this Privacy Policy?

We’re constantly trying to improve our Services, so we may need to change this Privacy Policy from time to time as well, but we will alert you to changes by placing a notice on the Services, by sending you an email, and/or by some other means. Please note that if you’ve opted not to receive legal notice emails from us (or you haven’t provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes.

What Information does Karat Collect?

Information You Provide to Us:

We receive and store any information you knowingly provide to us. For example, through the registration process for the Interview Services and/or through your account settings, we may collect Personal Data, including without limitation, the following:

  • First and last name
  • Email address
  • Telephone number
  • Age and birthday
  • Demographic information
  • User content, for example, job prospect information, interview schedule, resume information, work history, social media links/URL (e.g. LinkedIn, GitHub, etc.), demographic information, and other information you directly upload to the Services as an interviewee, etc. (which can include Personal Data if you include Personal Data in such content)

Certain information may be required to register with us or to take advantage of some of our features.

If you are not participating in the Interview Services, but you have signed up to receive email communications from Karat or have otherwise given us your name, email, or other contact information, any such information that you share with us will be subject to this Privacy Policy.

We may communicate with you if you’ve provided us the means to do so. For example, if you’ve given us your email address, we may email you about your use of the Services. We may also send you emails on behalf of our Partners regarding opportunities that may interest you. Also, we may receive a confirmation when you open an email from us. This confirmation helps us make our communications with you more interesting and improve our Services. If you do not want to receive communications from us, please indicate your preference by contacting us at privacy@karat.io.

Information Collected Automatically

Whenever you interact with our Services, we automatically receive and record information on our server logs from your browser or device, which include the following:

  • IP address
  • Cookies and other tracking technologies (e.g. web beacons, pixel tags, SDKs, etc.) — For more information, please review our Cookie Policy in the following paragraph.
  • Device identifiers
  • Web browser information
  • Page view statistics
  • Usage information
  • Location information (e.g. IP address)

“Cookies” are identifiers we transfer to your browser or device that allow us to recognize your browser or device and tell us how and when pages and features in our Services are visited and by how many people. You may be able to change the preferences on your browser or device to prevent or limit your device’s acceptance of cookies, but this may prevent you from taking advantage of some of our features. If you click on a link to a third party website or service, such third party may also transmit cookies to you. Again, this Privacy Policy does not cover the use of cookies by any third parties, and we aren’t responsible for their privacy policies and practices. Please be aware that cookies placed by third parties may continue to track your activities online even after you have left our Services, and those third parties may not honor “Do Not Track” requests you have set using your browser or device.

We may use this data to customize content for you that we think may be useful to you, based on your usage patterns. We may also use it to improve the Services – for example, this data can tell us how often users use a particular feature of the Services, and we can use that knowledge to make the Services useful to as many users as possible.

Information Collected From Other Websites and Do Not Track Policy

Through cookies we place on your browser or device, we may collect information about your online activity after you leave our Services. Just like any other usage information we collect, this information allows us to improve the Services and customize your online experience, and otherwise as described in this Privacy Policy. Your browser may offer you a “Do Not Track” option, which allows you to signal to operators of websites and web applications and services that you do not wish such operators to track certain of your online activities over time and across different websites. Our Services do not support Do Not Track requests at this time, which means that we collect information about your online activity both while you are using the Services and after you leave our Services.

Information Collected from Third Parties

We collect Personal Data about you when third parties, such as our business partners or service providers, provide us with Personal Data about you. Such third parties provide us with Personal Data about you, such as the following:

  • Information from prospective employers and partners: We receive information about you from entities you applied to for an employment or consulting position (“Prospective Employer.”) The information we receive from such Prospective Employer relates to your job candidacy, your qualifications, your interview process, and your application generally. We may also receive information about you from the applicant tracking system of your Prospective Employer(s) or another Karat Partner. This may include information related to your past applications for positions with Prospective Employer(s) or Partners, even if you did not participate in Karat’s Interview Services in connection with such entity or application.
  • Information from recruiters: We may receive information about you from individuals or entities who serve as recruiters to help you obtain positions with Prospective Employers. The information we receive from such recruiters relates to your job candidacy, your qualifications and credential, your interview process, and your application generally.
  • Information from publicly available sources: We collect information about you from publicly available sources. For example, if we conduct an internet search and see from a publicly available third party website that you have prior job experience that is applicable to a Prospective Employer, we may use such information for our business purposes. Aside from publicly available information collected from such public sources, we may also collect information about you from your social media sites (even if such information is not publicly available), such as LinkedIn and GitHub, if you give us permission to do so.
Information Collected During Interview

We collect Personal Data about you when you use our Services to interview for a position with a Prospective Employer. During the interview, we collect information about you, including but not limited to a video recording, photo, a coding exercise, updated resume information, answers to interview questions, and Personal Data provided during the interview.

How do we use Personal Data?

We process Personal Data to operate, improve, understand and personalize our Services. For example, we use Personal Data to:

  • Create and manage user profiles and content
  • Communicate with you about the Services
  • Conduct interviews and assess your skills as they relate to the job opportunities you apply for in connection with the Interview Services
  • Track your interviews with different Prospective Employers to optimize your interview experience (for example, we make sure you won’t see the same question or problem in different interviews)
  • Analyze and report the results of your interviews and assessments to your Prospective Employers
  • Contact you about Service announcements or updates
  • Provide support and assistance for the Services
  • Personalize and calibrate content and communications based on your preferences, needs, and experiences
  • Perform analytics and benchmarking to provide information and insights to our Partners regarding their applicant pools and their recruiting and hiring practices
  • Meet contract or legal obligations
  • Comply with our legal or contractual obligations
  • Resolve disputes
  • Protect against or deter fraudulent, illegal or harmful actions

We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others, as further described below.

  • Contractual Necessity: We process the following categories of Personal Data as a matter of “contractual necessity,” meaning that we need to process the data to perform under this Privacy Policy with you as well as any other agreements with you, which enables us to provide you with the Services. When we process data due to contractual necessity, failure to provide such Personal Data will result in your inability to use some or all portions of the Services that require such data.
    • Your full name
    • Your email address
  • Legitimate Interest: We process the following categories of Personal Data when we believe it furthers the legitimate interest of us or third parties.
    • Your phone number
    • Your resume
    • Your IP address
    • Your work history
    • Your job application and other information you provide as part of the assessment
    • Your photo and a video recording of your interview
    • The results and analysis of your interview and assessment
    • Your gender, age, race/ethnicity

    Examples of these legitimate interests include:

    • Operation and improvement of our business, products and Services, including the Interview Services
    • Assisting you with your job application and interview process
    • Mitigating and eliminating biases in hiring and recruiting processes
    • Increasing job opportunities for qualified applicants
    • Assessing your skills and competencies
    • Assisting our Partners with their recruiting and hiring processes
    • Provision of customer support
    • Protection from fraud or security threats
    • Compliance with our legal obligations
    • Assisting our Partners with compliance with their legal obligations
    • Completion of corporate transactions
  • Consent: In some cases, we process Personal Data based on the consent you expressly grant to us at the time we collect such data. When we process Personal Data based on your consent, it will be expressly indicated to you at the point and time of collection.
  • Other Processing Grounds: From time to time we may also need to process Personal Data to comply with a legal obligation, if it is necessary to protect the vital interests of you or other data subjects, or if it is necessary for a task carried out in the public interest.

Will Karat Share Any of the Personal Data it Receives?

We may share your Personal Data with third parties as described in this below:

Prospective Employers and Recruiters: We may share your Personal Data with your Prospective Employers and your recruiters in connection with providing our Services to your Prospective Employers.

Information that’s been de-identified. We may de-identify your Personal Data so that you are not identified as an individual, and provide that information to our Partners. We may also provide aggregate statistics and other analytics information to our Partners, including your Prospective Employers and our other Partners, who may use such information to assist with their recruiting and hiring processes and gain insights about their applicant pools. However, except for when we share information about you with your Prospective Employer as part of the Interview Services, we never disclose aggregate usage or de-identified information to a Partner (or allow a Partner to collect such information) in a manner that would identify you as an individual.

Analytics: We may use third party analytics service providers, such as Google Analytics for our business purposes, including but not limited to improving and developing our Services, monitoring and analyzing use of our Services, and increasing the functionality and user-friendliness of our Services. Google Analytics may collect and retain some information about you by planting a persistent cookie or identifier on your web browser or device. You may opt out of Google Analytics by visiting https://tools.google.com/dlpage/gaoptout/. Google’s ability to use and share information collected by Google Analytics about your use of the Services is restricted by the Google Analytics Terms of Service and the Google Privacy Policy. You may find additional information about Google’s ability to use and share information collected by Google Analytics by visiting www.google.com/policies/privacy/partners/.

Our Agents: We employ other companies and people, such as vendors and third party service providers, who work on our behalf and provide us with services related to the purposes described in this Privacy Policy. These parties include:

  • Interviewers who conduct and review your interviews
  • Payment processors (e.g. to pay interviewers)
  • Fraud prevention service providers
  • Analytics service providers
  • Staff augmentation and contract personnel
  • Hosting service providers
  • Co-location service providers
  • Telecommunications service providers

Unless we tell you differently, our agents do not have any right to use the Personal Data we share with them beyond what is necessary to assist us.

User Profiles and Submissions: Certain user profile information, including your name, employment prospects, interview schedule, social media links/URLs (e.g. LinkedIn), resume information, and any content that you have uploaded to the Services, may be displayed to Karat and its agents, Prospective Employers and their agents, recruiters, and the interviewer who will conduct your interview to facilitate providing the Services.

Business Transfers: We may choose to buy or sell assets, and may share and/or transfer user information in connection with the evaluation of and entry into such transactions. Also, if we (or our assets) are acquired, or if we go out of business, enter bankruptcy, or go through some other change of control, Personal Data could be one of the assets transferred to or acquired by a third party, and we would share Personal Data with the party that is acquiring our assets. You acknowledge that such transfers may occur, and that any acquirer of us or our assets may continue to use your Personal Data as set forth in this policy.

Protection of Karat and Others: We reserve the right to access, read, preserve, and disclose any information that we believe is necessary to:

  • comply with applicable law, court order, or respond to valid legal process, including from law enforcement or other government agencies;
  • enforce or apply our Candidate Agreement, Privacy Policy and other agreements;
  • maintain the security of our products and Services;
  • protect the rights, property, or safety of Karat, our employees, our users, or others.

Consent: We also share information with third parties when you give us consent to do so.

Affiliates: we share Personal Data with our affiliates or other members of our corporate family.

Is Personal Data about me Secure?

Your account is protected by a password for your privacy and security. You must prevent unauthorized access to your account and Personal Data by selecting and protecting your password appropriately and limiting access to your computer or device and browser by signing off after you have finished accessing your account.

We seek to protect Personal Data using appropriate technical and organizational measures based on the type of Personal Data and applicable processing activity. Our information is stored on secure servers in the United States. Our security measures vary based on the sensitivity of the Personal Data we collect, process and store and the current state of technology. We also take measures to ensure subprocessors that process Personal Data on our behalf also have appropriate security controls in place.

We endeavor to protect the privacy of your account and other Personal Data we hold in our records, but unfortunately, we cannot guarantee complete security. Unauthorized entry or use, hardware or software failure, and other factors, may compromise the security of user information at any time. We take various steps to protect your information, including, but not limited to, the following:

  • We implement technical measures to prevent unauthorized access, and keep security patches and software up-to-date
  • We restrict and audit employee access to your information
  • We store sensitive Personal Data in encrypted form
  • We encrypt all Personal Data during transfer

What Personal Data can I access?

Through your account settings, you may access, and, in some cases, edit or delete the following information you’ve provided to us:

  • name and password
  • email address
  • telephone number
  • user profile information

The information you can view, update, and delete may change as the Services change. If you have any questions about viewing or updating information we have on file about you, please contact us at privacy@karat.io.

Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to contact us to prevent disclosure of Personal Data to third parties for such third parties’ direct marketing purposes; in order to submit such a request, please contact us at privacy@karat.io.

What Rights Do You Have Regarding Your Personal Data?

If you are a resident of the EU, Switzerland, United Kingdom, Lichtenstein, Norway, or Iceland, you have certain rights with respect to your Personal Data, including those set forth below. For more information about these rights, or to submit a request, please email privacy@karat.io. Please note that in some circumstances, we may not be able to fully comply with your request, such as if it is frivolous or extremely impractical, if it jeopardizes the rights of others, or if it is not required by law, but in those circumstances, we will still respond to notify you of such a decision. In some cases, we may also need to you to provide us with additional information, which may include Personal Data, if necessary to verify your identity and the nature of your request.

  • Opt not to Disclose: You can always opt not to disclose information to us, but keep in mind some information may be needed to register with us or to take advantage of some of our features.
  • Access: You can request more information about the Personal Data we hold about you and request a copy of such Personal Data.
  • Rectification: If you believe that any Personal Data we are holding about you is incorrect or incomplete, you can request that we correct or supplement such data. When you update information, however, we may maintain a copy of the unrevised information in our records.
  • Erasure: You can request that we erase some or all of your Personal Data from our systems.
  • Withdrawal of Consent: If we are processing your Personal Data based on your consent (as indicated at the time of collection of such data), you have the right to withdraw your consent at any time. Please note, however, that if you exercise this right, you may have to then provide express consent on a case-by-case basis for the use or disclosure of certain of your Personal Data, if such use or disclosure is necessary to enable you to utilize some or all of our Services.
  • Portability: You can ask for a copy of your Personal Data in a machine-readable format. You can also request that we transmit the data to another controller where technically feasible.
  • Objection: You can contact us to let us know that you object to the further use or disclosure of your Personal Data for certain purposes.
  • Restriction of Processing: You can ask us to restrict further processing of your Personal Data.
  • Right to File Complaint: You have the right to lodge a complaint about Karat’s practices with respect to your Personal Data with the supervisory authority of your country or EU Member State.

How Long Do We Retain Your Personal Data?

We retain Personal Data about you for as long as you have an open account with us or as otherwise necessary to provide you Services. In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation. Afterwards, we retain some information in a depersonalized or aggregated form but not in a way that would identify you personally.

Do we transfer EU or Swiss Users’ Personal Data Outside the EU?

The Services are hosted and operated in the United States (“U.S.”) through Karat and its service providers, and if you do not reside in the U.S., laws in the U.S. may differ from the laws where you reside. By using the Services, you acknowledge that any Personal Data about you, regardless of whether provided by you or obtained from a third party, is being provided to Karat in the U.S. and will be hosted on U.S. servers, and you authorize Karat to transfer, store and process your information to and in the U.S., and possibly other countries. You hereby consent to the transfer of your data to the U.S. as set forth herein.

Karat complies with the Principles of the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of Personal Information transferred from the EU, which consist of (1) notice, (2) consent, (3) accountability for onward transfer, (4) security, (5) data integrity and purpose limitation, (6) access and (7) recourse, enforcement and liability with respect to all Personal Information received from within the EU and Switzerland in reliance on the Privacy Shield. The Privacy Shield Principles require that we remain potentially liable if any third party processing Personal Information on our behalf fails to comply with these Privacy Shield Principles (except to the extent we are not responsible for the event giving rise to any alleged damage). Karat’s compliance with the Privacy Shield is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission. Karat has certified to the Department of Commerce that it adheres to the Privacy Shield Principles. If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. For more information about the Privacy Shield Program and to view our certification, please visit www.privacyshield.gov.

In compliance with the Privacy Shield Principles, Karat commits to resolve complaints about our collection or use of your personal information. Please contact us at privacy@karat.io with any questions or concerns relating to the Privacy Shield. If you do not receive timely acknowledgment of your Privacy Shield-related complaint from us, or if we have not resolved your complaint, you may also resolve a Privacy Shield-related complaint through JAMS, an alternative dispute resolution provider located in the United States. You can visit https://www.jamsadr.com/file-an-eu-us-privacy-shield-or-safe-harbor-claim for more information or to file a complaint, at no cost to you. Under certain conditions, you may also be entitled to invoke binding arbitration for complaints not resolved by other means.

What if I have questions about this policy?

If you have any questions or concerns regarding this Privacy Policy or our data practices generally, please send us a detailed message using the following information, and we will try to resolve your concerns.

  • Name: Neil Kumar
  • Physical address: 1100 NE Campus Parkway Suite 200 Seattle, WA 98105
  • Email address for contact: privacy@karat.io