Trust Center
Data Protection
The lifecycle of your data at Competency Labs — from the moment it is collected to the moment it is deleted.
Data categories
- Account dataRetained while the account is active and for a limited period after closure to support security investigations and legal obligations.
- Assessment responsesRetained to support scoring, credential issuance, dispute resolution, and reviewer audit trails.
- Passport recordsRetained as the system of record for issued credentials, including versioned history for verification integrity.
- Operational logsRetained for a rolling window sufficient for security monitoring and incident response.
Deletion
You can request deletion at any time via our data deletion request form. When deletion is processed, account data and private assessment responses are removed. Issued Passports remain resolvable at their verification URL — deletion of a credential record is handled through revocation, not removal, so employers cannot be misled by a disappeared credential.
Encryption
Data is encrypted in transit (TLS 1.2+) and at rest using provider-managed keys. Database access is restricted to the application service role and to explicitly authorized administrators.
Subprocessors
Competency Labs uses a small set of subprocessors to run the platform — including managed cloud hosting, transactional email delivery, and AI inference. Subprocessors are bound by contract to process data only on our instructions and not to train models on our inputs. A current subprocessor list is available on request from support@competencylabs.com.
Maintained by Competency Labs. Contact support@competencylabs.com for corrections or questions.
Contact us