Skip to content
TestPapas

Privacy Policy

Last updated:

This privacy policy of Testpapas (“Privacy Policy”) describes how TestPapas SIA processes personal data in connection with (i) the operation and security of https://testpapas.com/ website (“Website”), (ii) handling enquiries and requests for proposals and quotes, and (iii) receiving and assessing applications to become testers and/or job candidates (“Applicants”). This Policy applies where TestPapas acts as a controller within the meaning of Regulation (EU) 2016/679 (“GDPR”) and the applicable Latvian data protection legislation.

TestPapas SIA, a private limited liability company duly incorporated and existing under the laws of the Republic of Latvia, registration number 40203510559, registered office at Antonijas iela 8 - 10, Rīga, LV-1010 is the controller (“TestPapas”, “we”, “us”, “our”). We have not appointed a Data Protection Officer. For privacy-related matters you may contact us at info@testpapas.com.

We may amend this Privacy Policy from time to time. The last updated date above indicates when the current version applies.

1. Categories and sources of personal data

We process personal data relating to (a) Website visitors, (b) business contacts acting on behalf of organisations or legal entities, and (c) applicants who apply to quality assurance engineer roles.

We collect personal data primarily from you, including via webforms you fill out and communications you send us. Certain technical and usage data is collected automatically when you use the Website. Depending on the context, we may process the following categories of personal data:

  • Identification and contact data: name, business email, telephone number, messaging handle (e.g., Telegram username), company name, role, address (where provided).
  • Communications data: enquiry content, correspondence, and administrative records of communications.
  • Applicant data: application form entries and supporting materials, languages, devices you can test on, and information generated during the selection process (e.g., test results and interview notes).
  • Technical and usage data: IP address, the country associated with your IP address (provided by our CDN), device and browser information, timestamps, pages viewed, referral URLs, and log data.
  • Cookie and similar technology data: cookie identifiers and preference choices, and (where consent is given) analytics and advertising-measurement data.
  • Technical error data: when part of a page fails to load, the page address, the name of the error and the time — no personal data — used only to find and fix the fault.

If you turn the contact form popup off or back on, we remember that choice in your browser’s local storage; you can change it at any time in Cookie settings. Separately, when the popup is shown, your browser stores the time it was last shown, so that it is not shown again in that browser for at least an hour. Neither record contains personal data, neither is sent to us, and you can remove both by clearing your browser’s site data.

When you visit our site, our CDN (Cloudflare) provides us with the country associated with your IP address. We use this to pre-select a likely country in our contact and application forms, which you can change at any time; we do not store your IP address for that pre-selection. If you then submit either form, we also record your IP address alongside your submission; for the contact form, we record that country too. We retain this data with the rest of the submission, as described in section 4.

We do not intentionally collect special categories of personal data (e.g., health data, biometric data, political opinions). You should not provide such data unless we explicitly request it and an appropriate lawful basis applies.

We do not make decisions producing legal effects or similarly significant effects about you solely by automated means within the meaning of Article 22 GDPR.

Where we request personal data, providing it is generally voluntary. However, certain data is necessary:

  • if you do not provide the requested contact and enquiry details, we may be unable to respond or prepare a proposal/quote.
  • if you do not provide the information needed to assess your application, we may be unable to consider you for a role/engagement.
  • in limited cases, we may be required by law to collect or retain certain data (e.g., for compliance purposes). If such data is not provided, we may be unable to comply with legal requirements.

2. Purposes of processing and legal bases

The principal purposes and bases for processing of personal data are as follows:

  • We process technical and usage data to operate the Website, ensure IT security, prevent misuse and fraud, and diagnose issues. The lawful basis is our legitimate interests in operating a secure and reliable website and protecting our systems, users, and business.
  • We process identification, contact and communications data to respond to your request, communicate with you, and where relevant prepare and discuss a proposal and take steps at your request prior to entering into a contract. The lawful basis is pre-contractual measures and, where applicable, our legitimate interests in conducting B2B communications and developing our business relationships.
  • We process applicant data to receive, review and assess applications, administer selection procedures, and communicate with Applicants. The lawful basis is our legitimate interests in recruitment and selection and, where applicable, pre-contractual measures to the extent an Applicant requests consideration for engagement.
  • We process personal data to comply with legal obligations (including accounting and tax obligations where applicable), and to establish, exercise or defend legal claims. The lawful basis is legal obligation and/or our legitimate interests in legal protection and enforcement.
  • Where you have expressly opted in, or where otherwise permitted by applicable law (particularly in a B2B context with a clear opt-out), we may process your contact data to send communications about our services. The lawful basis is consent and/or legitimate interests, as applicable. You may object to or opt out of marketing at any time.

Where we rely on legitimate interests as the lawful basis, those interests include: operating and securing our Website and systems; preventing fraud and misuse; managing B2B relationships and responding to enquiries; conducting recruitment and selection; and establishing, exercising, or defending legal claims.

3. Recipients and categories of recipients

We may disclose personal data on a need-to-know basis to:

  • our authorised personnel and contractors supporting operations, client communications and recruitment;
  • service providers supporting Website and business operations (such as hosting and infrastructure providers, email and communications providers, CRM and support tooling and analytics providers where enabled);
  • professional advisers (lawyers, accountants, auditors) and consultants; and
  • competent public authorities, regulators, courts or law enforcement where required by law or necessary for legal protection.

Where a recipient acts as a processor, it processes personal data under our documented instructions and subject to contractual obligations designed to ensure confidentiality and security.

4. Security and retention

TestPapas implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, as well as the likelihood and severity of risks to the rights and freedoms of natural persons. Such measures include, as appropriate, access control and authorisation mechanisms, logical and physical security controls, encryption and secure transmission protocols where applicable, segregation of environments, backup and recovery procedures, and internal policies governing access to and handling of personal data. Access to personal data is restricted to authorised persons acting under TestPapas’ authority and subject to confidentiality obligations.

While TestPapas takes reasonable measures to protect personal data, no method of transmission or storage is entirely secure. Accordingly, TestPapas cannot guarantee absolute security of personal data.

If personal data is transferred outside the European Economic Area, we will ensure that an appropriate transfer mechanism is in place. Depending on the circumstances, this may include an adequacy decision, or the European Commission’s Standard Contractual Clauses, supplemented where necessary by additional safeguards.

We retain personal data for no longer than necessary for the purposes described in this Policy. Retention periods are determined based on: (i) the purpose of processing; (ii) the type and sensitivity of the data; (iii) the duration of our relationship/interactions with you; and (iv) applicable limitation periods and legal retention obligations. Where required by law or necessary for legal claims, we may retain data for longer.

5. Data subject rights

If you are a data subject under GDPR, you have the following rights:

  • obtain confirmation as to whether or not personal data concerning you is being processed and, where that is the case, request access to such personal data and information about the processing (Article 15 GDPR);
  • request the rectification of inaccurate personal data concerning you and the completion of incomplete personal data (Article 16 GDPR);
  • request the erasure of personal data concerning you where the conditions of Article 17 GDPR are met;
  • request the restriction of processing of your personal data in the cases set out in Article 18 GDPR;
  • where our processing is based on your consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal;
  • receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and, where technically feasible, to transmit such data to another controller (Article 20 GDPR); and
  • object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on our legitimate interests, including profiling to the extent applicable (Article 21 GDPR).

We may request additional information necessary to verify your identity. We will respond to your request without undue delay and in any event within one month of receipt. Where necessary, taking into account the complexity and number of requests, this period may be extended by up to two further months. If we extend the response time, we will inform you within one month of receipt and explain the reasons for the delay.

The exercise of your rights is generally free of charge. However, where requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may charge a reasonable fee or refuse to act on the request, as permitted by the GDPR.

6. Complaints

You have the right to lodge a complaint with a supervisory authority. In Latvia, the competent supervisory authority is the Datu valsts inspekcija. You may also lodge a complaint with the supervisory authority in your habitual residence or place of work within the EEA, where applicable.

Got questions?

If anything in this policy is unclear, or you want to exercise your GDPR rights, our team is happy to help — reach out and we'll respond within one month.