Privacy Policy

Privacy Policy

How Coodesh and Workdex collect, use, store, share and protect personal data of candidates, employees, management users and visitors.

Workdex is a spin-off brand owned by Coodesh Serviços Tecnológicos Ltda. (Brazilian company ID CNPJ 30.078.586/0001-78), headquartered at Av. Afonso Pena, 3.351, 11th floor, room 1103, Funcionários, Belo Horizonte/MG, Brazil, ZIP 30130-008. All references to Coodesh in this document cover the Workdex operation and the workdex.ai domain.

Last updated:July 2026

This policy describes how Coodesh, the company behind the Workdex brand, processes personal data on www.coodesh.com and workdex.ai and in the assessments, AI interview, hiring and skills services. It is an integral part of the Terms and Conditions of Use.

1. Introduction

This policy describes how Coodesh collects, uses, stores, shares and protects personal data. It applies to candidates, evaluated employees, management users and visitors of www.coodesh.com and related domains, including workdex.ai.

By accessing the services, you acknowledge that you have read and understood this policy, which is an integral part of the Terms and Conditions of Use.

2. Controller and Data Protection Officer (DPO)

Coodesh acts as controller of the data it collects directly, such as account, browsing and commercial-contact data. When evaluating candidates or employees under instructions from a customer company, the customer company acts as controller and Coodesh as processor.

Coodesh has appointed a Data Protection Officer (DPO), pursuant to LGPD art. 41 and GDPR art. 37, reachable at dpo@coodesh.com.

3. Personal data collected

The data collected varies by service (assessments, AI interviews, hiring or skills) and the data subject's role in the flow.

  • Candidates and evaluated employees: name and email (required), geolocation and IP address, assessment answers and, when proctoring is enabled, photos, webcam and audio recordings (optional and disclosed).
  • Candidates in hiring processes: phone, city, public LinkedIn profile, GitHub profile (optional), salary expectation, PDF resume and career information.
  • CPF (Brazilian tax ID): collected exclusively when background check verification is configured by the customer company.
  • Management users (company): name and email (required) and, optionally, role, gender, date of birth and short bio.
  • Automatically collected data: IP address, browser type, operating system, pages visited, time on page, referral data, device data, cookies and similar technologies.
  • Sensitive data: gender, color/race, sexual orientation and disability may be collected optionally, with the data subject's specific and highlighted consent, exclusively for diversity and inclusion purposes (LGPD art. 5, II; GDPR art. 9).

5. Processing purposes

Personal data is processed for the following purposes.

  • Delivery of the contracted services, including assessments, interviews and report generation.
  • Transactional communications and, with consent, marketing communications.
  • Improvement of features and user experience.
  • Sharing of results with the customer companies responsible for the process.
  • Aggregated and anonymized data for statistical, research and market-benchmark purposes.
  • Fraud prevention, platform security and compliance with legal obligations.
  • Background check: the candidate's or employee's CPF is used exclusively for lookups with the specialized provider EXATO DIGITAL LTDA.

6. Use of artificial intelligence

Platform features use artificial intelligence and machine learning, including third-party language models, always grounded on the applicable legal bases.

Personal data processed by AI features is not used to train third-party models.

7. Sharing with third parties

Coodesh does not sell, rent or trade personal data. Sharing happens only with vendors required to operate the service, with the customer company responsible for the process, and in the situations allowed by law.

Data accessed via API remains subject to this policy, and the customer company assumes responsibility as an independent controller. In MCP integrations, when data is accessed by the customer's LLMs, the customer company is fully responsible for the subsequent processing performed by the LLM.

  • Payment processing: Vindi and Stripe.
  • CRM and marketing: RD Station.
  • Digital signature: Clicksign.
  • Artificial intelligence: OpenAI and ElevenLabs.
  • Infrastructure: AWS and Google Cloud Platform.
  • Background check: EXATO DIGITAL LTDA. (CNPJ 12.387.530/0001-13).
  • Public authorities, in compliance with legal obligations or court orders, and corporate transactions (merger, acquisition), with confidentiality preserved.

8. International data transfers

The core infrastructure is located in the United States (AWS and Google Cloud Platform), and some vendors may operate in other countries.

For data subjects in Brazil, transfers comply with LGPD art. 33 through standard contractual clauses, adequacy commitments or countries with an adequate level of protection. For data subjects in the EU/EEA, transfers comply with GDPR Chapter V through Standard Contractual Clauses (SCCs), adequacy decisions or the EU-US Data Privacy Framework.

9. Data retention

After the periods below, data is anonymized or securely deleted, except where retention is required by law or by judicial or administrative proceedings.

  • Account data: while the account is active, plus 12 months after closure.
  • Assessment results contracted by companies: contract term, plus 12 months.
  • Video and audio recordings: the period needed to deliver the service, plus 6 months.
  • Browsing data and logs: up to 12 months.
  • Financial and tax data: per applicable law (minimum of 5 years in Brazil).

10. Data security

We adopt technical and organizational measures to protect personal data, including encryption in transit (TLS/SSL) and at rest, password encryption, role-based access control (RBAC), monitoring with audit logs, regular backups, internal policies and training.

In the event of a security incident with relevant risk, we will notify the ANPD, the applicable supervisory authority (GDPR) and affected data subjects within the legal deadlines.

11. Data subject rights

Data subjects may exercise the rights provided by the LGPD and the GDPR, including confirmation of processing and access, correction of incomplete or inaccurate data, anonymization, blocking or deletion, portability, information about sharing, withdrawal of consent, objection to legitimate-interest processing, and complaints to the ANPD or the competent supervisory authority.

Data subjects in the EU/EEA also have the right to restriction of processing and the right not to be subject to solely automated decisions, including profiling.

  • How to exercise: through the platform (Menu, Settings) or by email at dpo@coodesh.com.
  • Response times: 15 business days (LGPD) or 30 days (GDPR), extendable depending on complexity.
  • Requests tied to processes run by a customer company may require coordination with that company, as controller.

12. Minors' data and third-party sites

The services are not directed at anyone under 18, and we do not knowingly collect data from minors. If we identify improper collection, we will take steps to delete it. Reports can be sent to dpo@coodesh.com.

This policy does not apply to third-party sites and services accessed through links on the platform. We recommend reviewing those third parties' privacy policies.

13. Changes and contact

This policy may be updated periodically. Significant changes will be communicated via in-platform notice, email or a site banner, and the update date appears at the top of the document.

Privacy questions: dpo@coodesh.com. General support: help@workdex.ai. Address: Av. Afonso Pena, 3.351, 11th floor, room 1103, Funcionários, Belo Horizonte/MG, Brazil, ZIP 30130-008.