← Back to home

Frequently asked questions

Split for HR teams and for candidates who upload documents via a link.

For HR teams & agencies

Where is our candidates' data stored?

In secure cloud (Supabase infrastructure) over HTTPS. Servers may be located outside Indonesia — the cross-border transfer terms are in the Privacy Policy. Access is isolated at the database level (RLS).

Who can see the documents a candidate uploads?

Only your team, and only for that specific vacancy. Files are served via short-lived signed links, and every access is logged.

Is there a Data Processing Agreement (DPA)?

Yes. A one-page DPA (employer = controller, Doki = processor) is available on request for pilots.

Can we export candidate documents and statuses?

Yes — export is available at any time, with no lock-in.

How is data deleted?

A candidate can request deletion at any time. You delete your own account self-serve: Settings → Security → Delete account.

For candidates

Who will see my KTP and documents?

Only the employer you applied to, and only for that vacancy. We never sell your data.

Do I need an account to upload?

No. You open the link and upload your files without registering. You can create an account later if you want to keep the documents for yourself.

How long does the link live?

The sender sets the expiry and limits. The link can be revoked at any time.

How do I delete my documents?

The consent says you can request deletion at any time — email [email protected] or use your application status page.

Is my data safe?

Files live in private storage, served via signed links over HTTPS. If an incident occurs, we notify within 3×24 hours.

Still have questions? Write to us: [email protected]

Frequently asked questions — doki.help · doki.help