Privacy Policy

    Last updated 18 January 2026

    This Privacy Policy explains how preppito collects, uses, shares, and protects personal data when you visit our website and when you use our interview practice platform. preppito provides a practice environment only. We do not run hiring processes and we do not make selection decisions for employers.

    1. Scope

    This policy covers the preppito website and the interview practice platform, including accounts, sessions, transcripts, generated questions, and related features such as feedback and reports.

    2. What data we process

    We process only what we need to deliver the service, to keep it secure, and to meet our legal duties.

    Account data

    Name, email address, preferred language, authentication data, settings.

    Documents you provide

    Your CV or resume and the job post link you choose to share. We use these to generate practice questions. The CV file is processed to extract text content, which is stored with your job records. The original CV file is not stored, only the extracted text content.

    Generated content

    The interview questions created from your CV and job post, the full transcript of your practice interview, the feedback and tips that the system generates for you, and session metadata such as date, time, duration, and features used.

    Audio handling

    Your voice is processed in real time during the session to run the conversation and to create the transcript. We do not store audio for playback in our systems.

    Device and usage data

    Log files, browser and device information, event data, and approximate location derived from the IP address. We use this for security, service reliability, and product improvement in an anonymous or de identified form.

    Support and communications

    Messages that you send to our support channels, including message content and metadata.

    Cookies and similar tracking technologies

    We do not use cookies, pixels, device fingerprinting, or similar tracking technologies on our website or in the web app. If this ever changes we will update this policy and, where required, request your consent first.

    We do not intentionally collect data about you from third parties, other than retrieving the job posting you point us to.

    3. Purposes and legal bases

    We process personal data in accordance with the GDPR.

    Provide the service

    Register your account, run practice sessions, generate questions from your CV and the job post, create and display your transcript and feedback, and let you review previous sessions.

    Legal basis: Contract performance under GDPR.

    Special category data that you may choose to share

    During a session you might mention information that reveals special categories of data, for example health or religious beliefs. Because the transcript and the generated questions must reflect what you actually said in order to produce meaningful feedback, we process such information if you choose to share it. By accepting this Privacy Policy when creating your account, you give your explicit consent for us to process special category data that you may reveal during interview sessions.

    Legal basis: Explicit consent under GDPR.

    4. Where processing takes place

    We work with trusted service providers to deliver the interview practice experience. We configure these services to process and store customer data in European Union regions where available. Our design intent is that personal data for core processing activities remains in the European Union.

    We instruct our providers to act on our documented instructions through our contracts and service settings. We do not permit our providers to use your prompts or outputs to train their models for other customers. We do not grant such permission for preppito user content.

    5. Retention

    We keep personal data only for as long as needed for the stated purposes.

    • CV files are processed to extract text content, which is stored with your job records. The original CV file is not stored, only the extracted text content. Job descriptions are stored with your job records.
    • Generated questions and transcripts are stored permanently. This permanent storage is beneficial for candidates, enterprises, and preppito, as it allows for long-term tracking of progress, historical analysis, and continuous improvement of the platform
    • You can delete your transcript and generated questions at any time from your account, which removes the content from our active systems
    • Consent logs that evidence your explicit consent are retained for compliance purposes
    • Security logs are retained for up to 90 days unless a longer period is needed to investigate incidents
    • Support tickets are retained for up to 12 months unless a longer period is required by law
    • Backups follow fixed rotation schedules and are overwritten. When you delete content we remove it from active systems and it will fall out of backups on the normal cycle

    If law requires a longer retention we may retain the minimum necessary information for that period.

    6. Your rights

    Subject to conditions and exceptions in the GDPR, you have the following rights:

    • Right of access and to obtain a copy of your data
    • Right to rectification
    • Right to deletion
    • Right to restriction
    • Right to object where we rely on legitimate interests
    • Right to data portability

    Note: For enterprise data sharing, you can withdraw your consent at any time in your account settings (see Enterprise Workspaces section above). For other processing based on consent, withdrawal is exercised through account deletion.

    You can exercise these rights from within your account where features are available or by contacting info@preppito.com. We may need to verify your identity. We will respond without undue delay and within one month where possible.

    You also have the right to lodge a complaint with your local supervisory authority. In the Netherlands the authority is Autoriteit Persoonsgegevens at autoriteitpersoonsgegevens.nl.

    7. Children

    Our service is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe that a child provided us with personal data please contact us and we will delete it.

    8. Security

    We use technical and organisational measures intended to protect personal data. These include encryption in transit and at rest, role based access control, least privilege, logging and audit trails, vulnerability management, and staff training. If we become aware of a personal data breach we will notify affected users and regulators where legally required.

    9. Automated decision making and fairness

    We do not make automated decisions that produce legal or similarly significant effects for you. Our feedback is advisory for practice purposes only. We monitor for bias and quality issues as part of our model governance.

    10. Transparency about AI

    You practice with an AI system that generates questions and feedback. We clearly label AI generated content in the product. If you have questions about how the system works, contact info@preppito.com.

    11. Who we share data with

    We share personal data only with:

    • Our processors who act on our instructions to deliver the service
    • Professional advisers and auditors under a duty of confidentiality
    • Authorities where required by law
    • Enterprise customers, but only with your explicit consent and only for practice sessions linked to jobs created by that enterprise (see Enterprise Workspaces below)

    We do not sell personal data.

    11a. Enterprise Workspaces

    preppito offers enterprise workspaces that allow companies to create practice jobs and invite candidates to practice. If you are invited to practice jobs created by an enterprise, we will ask for your explicit consent before sharing any of your practice results with that enterprise.

    What is shared with enterprises

    If you consent, we share the following information with the enterprise for practice sessions linked to their jobs:

    • Your practice performance report generated by preppito for the session
    • Your transcript of the session
    • Session metadata, such as the job identifier, session date and time, session duration, and language

    No audio is shared. We do not share practice results from jobs not created by that enterprise.

    Consent and withdrawal

    Enterprise data sharing requires your explicit consent, which you can give or withdraw at any time in your account settings. If you withdraw consent, we will stop sharing new practice results with that enterprise, and you will no longer be able to practice jobs created by that enterprise. You can still use preppito to practice other jobs that are not created by that enterprise.

    Purpose and use restrictions

    Enterprises receive your practice performance and transcript only to review your practice performance and to help improve candidate performance. Enterprises may not use the shared information for unrelated profiling, marketing, or employment decisions.

    12. How we make decisions about data

    We follow the principles of data minimisation, purpose limitation, and storage limitation. We review this policy and our records of processing at least once a year.

    13. Changes to this policy

    We may update this policy from time to time. Significant changes will be announced on the website or by email. You can see the date of the latest update at the top of this page. If changes materially affect how we process your data we will ask for consent again where required.

    Annex A consent text used in the product

    Explicit consent for transcript and generated questions

    I give preppito explicit consent to process the full transcript of my practice interview and the interview questions that are generated from my CV and the job post, including any special category information that I choose to reveal, only to generate practice questions and personalised feedback. I understand that processing is configured to run in European Union regions where available. This consent is required in order to provide the service because feedback must be based on what I actually said and on the questions built from my CV. Withdrawing this consent requires account deletion.