Platform-Wide Policy

PRIVACY POLICY & TERMS OF USE

Applies to candidates, individual users, and business customers.

Last Updated2026-09-27
Versionv1.6
JurisdictionEstonia (EU)

This public, platform-wide document applies to candidates, individual users and business customers. By creating an account, requesting or participating in an assessment, or otherwise using the Services, the relevant user agrees to the Terms of Use. Privacy processing is governed by applicable law and this Privacy Policy; where consent is the lawful basis, consent is requested separately and may be withdrawn as described below.

0. Document Hierarchy & Related Agreements

This Policy is the general platform-wide privacy and use framework. Purpose-specific agreements may also apply: the AI Transparency & Disclosure Notice; B2B Services Agreement; Data Processing Agreement (DPA) for Customer-controlled candidate processing; B2C Agreement; Candidate Consent / Privacy Notice; Refunds Policy; and, where applicable, a signed Enterprise Pricing Addendum. If a signed purpose-specific agreement conflicts with these Terms on a matter it specifically governs, that signed agreement prevails for that matter. For data-protection matters governed by a DPA, the DPA prevails to the extent required by applicable data-protection law.

Part A

Privacy Policy

1. Scope and Roles

MeritLense provides digital workforce-readiness assessment and related reporting and verification services. MeritLense may act as an independent Controller for platform accounts, service administration, security, billing records, direct candidate interactions, and limited public certificate/report verification. For candidate Personal Data processed solely on documented instructions of a B2B Customer, the Customer is Controller and MeritLense is Processor under the applicable DPA.

2. Personal Data We Process

Depending on the Service used, we may process: account and contact data; business and billing information; candidate identity and professional information supplied by the Customer or candidate; assessment responses; audio where voice assessment is enabled; transcripts and extracted evidence; assessment/readiness outputs; identity-verification status and supporting images/documents where enabled; support communications; payment status and transaction references (not full card credentials); and technical/security data such as IP address, device/browser information, timestamps, cookies and audit logs. Location data is processed only where a feature requires it and the user provides or enables it.

3. Purposes and Lawful Bases

We process Personal Data only where a lawful basis applies. Depending on the activity, the basis may be: performance of a contract or steps requested before a contract; compliance with legal obligations; legitimate interests such as platform security, fraud prevention, service administration, auditability and proportionate service improvement, subject to applicable balancing requirements; or consent where consent is appropriate and specifically requested. Where MeritLense acts as Processor, the Customer determines the applicable lawful basis and MeritLense processes on documented instructions. We do not rely on a candidate’s acceptance of general Terms as a substitute for consent where GDPR requires valid consent.

4. AI-Assisted Processing and Assessment Outputs

Some Services may use AI-assisted tools for transcription, translation, language processing and evidence extraction. MeritLense’s assessment methodology and configured rules are then used to produce structured assessment outputs. AI-assisted processing does not itself make the Customer’s final hiring decision. Assessment outputs are decision-support information; the employer remains responsible for employment decisions and any human review required by law. MeritLense does not disclose proprietary prompts, algorithms, scoring logic, rule-engine configuration, indicator libraries, source code or trade secrets except where disclosure is legally required.

5. Sharing and Service Providers

We may disclose Personal Data to service providers that support hosting/infrastructure, AI/speech/language functions, identity verification where enabled, transactional communications, support, analytics using aggregated or de-identified data where appropriate, and payment processing. Such providers receive only data reasonably necessary for their function and are subject to appropriate contractual/data-protection obligations. We may also disclose information where required by law or a competent authority. MeritLense does not sell candidate or user Personal Data for advertising or unrelated commercial purposes.

6. International Transfers

Some service providers may process Personal Data outside the EEA. Where GDPR Chapter V restricts a transfer, MeritLense uses an applicable lawful transfer mechanism, which may include an adequacy decision, the European Commission Standard Contractual Clauses, or another lawful safeguard, together with supplementary measures where required. Further information about applicable safeguards may be requested at the privacy contact above, subject to confidentiality and security restrictions.

7. Candidate and Data-Subject Rights

Subject to GDPR and applicable exceptions, Data Subjects may have rights of access, rectification, erasure, restriction, objection, and data portability, and the right to withdraw consent at any time where processing is based on consent without affecting prior lawful processing. Requests may be sent to info@meritlense.com. Where MeritLense acts only as Processor, we may refer the request to the relevant Customer/Controller and assist that Customer as required. Data Subjects also have the right to lodge a complaint with a competent supervisory authority, including the Estonian Data Protection Inspectorate where it is competent.

8. Retention and Deletion

We retain Personal Data only for as long as reasonably necessary for the relevant purpose, contractual service, auditability, security, dispute handling and legal obligations. Different data categories may have different retention periods. Candidate-identifying information is deleted or de-identified when no longer required for the applicable assessment/service, subject to Customer instructions where MeritLense acts as Processor and any overriding legal requirement. Limited de-identified assessment or verification records may be retained where reasonably necessary for audit, authenticity, fraud prevention or legal recordkeeping. Backup copies may persist temporarily until overwritten under normal backup cycles.

9. Security

MeritLense maintains technical and organizational measures designed to protect Personal Data, taking into account the nature and risks of the processing. Measures may include access and authentication controls, role-based permissions, encryption in transit where appropriate, logging, infrastructure safeguards, confidentiality controls, monitoring and incident-response procedures. No internet-based service can guarantee absolute security, and users are responsible for protecting their account credentials.

10. Personal Data Breaches

MeritLense handles Personal Data Breaches in accordance with applicable law. Where MeritLense acts as Controller, it will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a breach when GDPR requires such notification. Affected Data Subjects will be informed without undue delay where GDPR requires communication because the breach is likely to result in a high risk to their rights and freedoms. Where MeritLense acts as Processor, it will notify the relevant Customer/Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

11. Cookies and Technical Data

The Platform may use cookies and similar technologies that are necessary for authentication, security and core functionality, and may use optional analytics technologies where permitted and appropriately disclosed. Users may control non-essential cookies through available settings where applicable. Technical logs may be retained for security, troubleshooting and audit purposes.

Part B

Terms of Use

12. Platform Nature and Service Scope

MeritLense is an independent digital assessment platform focused on workforce readiness and operational, technical and non-academic competency assessment. MeritLense is not a recruitment agency, manpower supplier, immigration service, employer of candidates, or the party making the Customer’s hiring decision. The Services provide assessment and decision-support tools; they do not guarantee employment, candidate suitability, regulatory approval or future performance.

13. Intellectual Property

All rights in the Platform and MeritLense materials, including assessment methodologies, question structures, indicator libraries, evaluation frameworks, scoring models, rule-engine logic and configuration, reports, certificate designs, software, branding and content, are reserved to MeritLense or its licensors. Users receive only the limited right to use the Services for the purpose permitted by the applicable Agreement. Copying, reverse engineering, extracting, republishing, benchmarking for replication, or using the Services or outputs to reproduce a competing assessment methodology is prohibited except to the extent such restriction is prohibited by mandatory law.

14. User Obligations

Users must use the Services lawfully; provide information they are authorized to provide; protect account credentials; avoid unauthorized access, interference, scraping or misuse; comply with applicable employment, privacy and anti-discrimination laws when using assessment outputs; and comply with the applicable Agreement. Services are intended for adults aged 18 or over unless MeritLense expressly enables a lawful alternative workflow with required authorization.

15. Assessment Outputs and Liability

Reports and readiness indicators reflect the evidence available and candidate performance at the time of assessment. They are decision-support information and should not be treated as a guarantee of future performance, professional advice, legal advice or a final employment decision. To the maximum extent permitted by applicable law and subject to any signed Agreement, MeritLense is not responsible for hiring, rejection, placement, immigration or employment decisions made by users, or for events outside MeritLense’s reasonable control.

16. Payments, Fees and Refunds

Available payment methods may include card payment, bank transfer or other methods shown in the applicable checkout, invoice or Agreement. Payment providers process payment credentials under their own applicable terms; MeritLense does not intentionally store full payment-card credentials. Prices, taxes, currency, package entitlements, payment timing and any volume terms are those shown at purchase or stated in the applicable Agreement, invoice or Pricing Addendum. Refund eligibility is governed by the Refunds Policy and any signed Agreement or Pricing Addendum; where they conflict, the signed purpose-specific commercial document governs the relevant account.

17. External Services and Links

The Platform may link to or interoperate with third-party services. Third parties are responsible for their own services, content and independent privacy practices. MeritLense is not responsible for third-party content or services outside its reasonable control, except to the extent applicable law or a signed Agreement provides otherwise.

18. Changes and Versioning

MeritLense may update this Policy and these Terms when reasonably necessary. Material changes will be communicated through the Platform, email or another appropriate channel before they take effect where required by law or contract. Where re-acceptance or re-signature is legally or contractually required, the Platform may require it before continued use of affected Services. Historical acceptance/signature records may be retained for legal, audit and evidentiary purposes in accordance with applicable retention requirements.

19. Governing Law, Severability and No Waiver

These Terms and this Policy are governed by the laws of the Republic of Estonia and applicable European Union law, without prejudice to mandatory rights that apply independently. Disputes are subject to the competent courts of Estonia unless mandatory law or a signed Agreement requires otherwise. If a provision is invalid or unenforceable, it will be limited to the minimum extent necessary and the remaining provisions remain effective. Delay in enforcing a provision is not a waiver.

20. Contact and Language

Privacy, data-rights and Terms inquiries: info@meritlense.com. Legal entity: MeritLense OÜ, registry code 17607462, registered address Ruunaoja tn 3, Lasnamäe linnaosa, Tallinn, Harju maakond, 11415, Estonia. MeritLense may provide translations for convenience. In the event of inconsistency between a translation and the English version, the English version controls to the extent permitted by applicable law.

END OF DOCUMENT — Version v1.6