Trust Center
Security, Privacy & Compliance
Everything an enterprise procurement, legal, or security team needs to evaluate EditingTests.com, in one place.
Privacy Policy
GDPR, UK GDPR, CCPA, PIPEDA, and Australian Privacy Act coverage.
Data Processing Agreement
Standard DPA available to every paying client on request. Free of charge. Response within 5 business days.
Sub-processors
Full list of vendors that may process candidate or client data.
Data Retention
How long we keep what. Candidate PII auto-scrubbed after 24 months.
Security Practices
Encryption, access controls, secret management, incident response.
Service Level Agreement
Uptime commitments, support response times, incident SLAs.
Accessibility Statement
WCAG 2.2 Level AA conformance commitment, known issues, contact.
Fairness & Adverse Impact
Where the adverse-impact obligation sits, what we do and do not measure, and why.
Human & Automated Scoring Notice
Every written test is human-assessed. Click-based tests (M/C, T/F) are automated. Candidate rights & re-review process.
Acceptable Use Policy
What the platform may and may not be used for.
Regulatory position
Where we stand against the regimes that apply to an assessment platform. We hold no third-party security certification — no SOC 2, no ISO 27001 — and we are not currently pursuing one. If that matters to your procurement process, tell us early.
| GDPR & UK GDPR | Compliant. DPA available on request. |
| CCPA / CPRA | Compliant. "Do Not Sell" rights honored. |
| PIPEDA (Canada) | Compliant. EditingTests.com is operated by EditFast, an unincorporated business based in British Columbia, Canada. |
| NYC Local Law 144 (AEDT) | No independent bias audit has been carried out. We hold no candidate demographic data. The LL144 audit obligation sits with the employer — see our bias auditing page. |
| Colorado AI Act | Candidate disclosure published at /ai-notice. |
| EU AI Act (high-risk) | Transparency obligations (Art. 50) met via AI Notice. Assessed as an Annex III(4) employment use case; Art. 13 information duties and the Art. 10 data-governance duty are tracked against the phased application in 2026–2027. |
| WCAG 2.2 Level AA | Partial conformance; statement & known issues. |
Reporting a security issue
If you believe you have found a vulnerability in EditingTests.com, please email us at [email protected] with the subject line "Security issue" and full details. We respond to credible reports within 5 business days and do not pursue legal action against researchers acting in good faith (safe-harbor terms available on request).
For data subject requests (access, correction, deletion), email [email protected] with the subject line "Data subject request".
Trust Center last reviewed: April 2026.