Frequently asked questions
Split for HR teams and for candidates who upload documents via a link.
For HR teams & agencies
In secure cloud (Supabase infrastructure) over HTTPS. Servers may be located outside Indonesia — the cross-border transfer terms are in the Privacy Policy. Access is isolated at the database level (RLS).
Only your team, and only for that specific vacancy. Files are served via short-lived signed links, and every access is logged.
Yes. A one-page DPA (employer = controller, Doki = processor) is available on request for pilots.
Yes — export is available at any time, with no lock-in.
A candidate can request deletion at any time. You delete your own account self-serve: Settings → Security → Delete account.
For candidates
Only the employer you applied to, and only for that vacancy. We never sell your data.
No. You open the link and upload your files without registering. You can create an account later if you want to keep the documents for yourself.
The sender sets the expiry and limits. The link can be revoked at any time.
The consent says you can request deletion at any time — email [email protected] or use your application status page.
Files live in private storage, served via signed links over HTTPS. If an incident occurs, we notify within 3×24 hours.
Still have questions? Write to us: [email protected]