Version 2026-10-03 · Last updated: 03 Oct 2026 · Draft pending legal review
1. Who we are (Data Fiduciary)
Kaamyab is operated by [LEGAL ENTITY NAME], [BUSINESS ADDRESS] ("we"). We decide why and how your personal data is processed and are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act"). Grievance Officer: [GRIEVANCE OFFICER NAME], [PRIVACY EMAIL] .
2. What we collect
- Account: name, email, phone (optional), password (stored only as a one-way hash).
- Job-seeker profile you enter: experience, current and expected CTC, notice period, locations, education, graduation year, links (LinkedIn/GitHub/portfolio), summary, skills and years, job keywords, dealbreakers, excluded companies.
- Resume: the files you upload and the text we extract from them.
- Screening answers you save, and AI suggestions you approve.
- Job-site logins and sessions you choose to connect (Naukri, LinkedIn, Indeed, Glassdoor, Foundit), stored encrypted.
- Activity: jobs found, applications, statuses, agent run logs and short-lived screenshots of agent runs.
- Support and assistant: tickets, contact-form messages, questions to the help assistant.
- Payments: plan, amount, payment reference and status. Card/UPI details are handled by Razorpay, not stored by us.
- Security data: login attempts, IP address in our security log, a salted hash of your IP in consent records. We do not collect government IDs, caste, religion, health or biometric data, and we ask you not to put them in your profile or resume.
3. Why we process it (purposes)
| Purpose | Data | Basis |
|---|---|---|
| Run your account, matching, dashboard and tracking | account, profile, resume, activity | your consent (required to use Kaamyab) |
| Application assistance: agents sign in to the job sites you connect and apply for you | profile, resume, answers, site logins | separate, optional consent |
| AI answer suggestions | minimised profile facts, redacted resume text, the question | separate, optional consent |
| Product news and offers | email/phone | separate, optional consent |
| Payments, invoices, fraud prevention | payment data | contract / legal obligation ⚖️ |
| Security and abuse prevention | security data | legitimate use permitted by law ⚖️ |
Optional purposes are off by default. You can turn each on or off in Privacy & Data (/settings/privacy). |
4. Where data comes from
From you, from the job sites you connect (application statuses you could see yourself), and from payment providers (payment status).
5. AI processing
If you turn on AI suggestions, we send Google Gemini only: total experience, CTC, notice period, locations, relocation preference, education, graduation year, skill years, your resume text with emails, phone numbers and links removed, and the question. We never send your name, email, phone, passwords, OTPs or session cookies. AI suggestions are not submitted until you approve them and are checked against your profile. We do not use your data to train AI models. See AI transparency.
6. Job applications on third-party sites
With Application assistance on, your agents submit your resume and answers to the job sites you connected. Those sites and the employers on them process your data under their own privacy policies. Automated use may be against some sites' terms; you decide whether to use it, and you can stop it any time.
7. Who processes data for us
| Provider | Purpose | Data | Region | When |
|---|---|---|---|---|
| Render | Web hosting (cloud mode) | All data in transit through the website | Singapore | if hosted on Render |
| Neon | Managed PostgreSQL database (cloud mode) | All stored account, profile, resume and job data | [NEON REGION] | if the database is on Neon |
| GitHub (Microsoft) | Runs the job-application agents (cloud mode) | Profile, resume, job-site login and session used during a run; nothing kept after the run | United States / global | if agents run on GitHub Actions |
| Server provider | Website, agents and database (own-server mode) | All data | [SERVER REGION] | if self-hosted |
| Google (Gemini API) | AI answer suggestions and the help assistant | Minimised profile facts, redacted resume text, the question; assistant questions | Global | only with your AI consent / when you use the assistant |
| Razorpay | Online payments | Name, email, phone, amount, payment status | India | when you pay online |
| Google Analytics | Website statistics | Pseudonymous browsing data | Global | only if enabled and you accept analytics cookies |
| Job sites you connect (Naukri, LinkedIn, Indeed, Glassdoor, Foundit) | Recipients of your applications (not our processors; they have their own privacy policies) | Your resume, answers and application details | Various | only with your Application assistance consent |
8. Sharing
We do not sell your data and do not share it for advertising. We share only with the processors above, the job sites you choose, and authorities when the law requires it.
9. Cross-border processing
Some processors (Google, GitHub) process data outside India. We will follow any restrictions the Government notifies under section 16 of the DPDP Act ⚖️.
10. Security
Encryption in transit (HTTPS/HSTS); site passwords and sessions encrypted at rest; passwords hashed (PBKDF2); strict access controls with two-factor authentication for administrators; audit logs; regular automated security testing. See Security.
11. How long we keep data
| Data | Kept for | Why |
|---|---|---|
| Debug screenshots of agent runs | 7 days | troubleshooting only |
| Agent run logs (text) | 90 days | support and troubleshooting |
| AI assistant conversations | 90 days | improve help answers |
| Closed support tickets | 365 days | support history |
| Security/admin audit log | 365 days | security investigations |
| Aggregated, cookie-free page counters (no personal data) | 400 days | analytics |
| Finished queue tasks | 30 days | operations |
| Webhook replay-protection ids | 30 days | payment safety |
| Payment records | until legal review | accounting/tax law legal review |
| Account data after the user deletes it | deleted immediately | deleted immediately; backups expire as below |
| Database backups (own server) | 14 days | disaster recovery; Neon history per Neon plan |
12. Your rights
Access a summary and a copy of your data, correct and update it, erase it, withdraw consent, nominate a person to exercise your rights if you die or become incapable, and raise a grievance. Use Privacy & Data or see Your data rights.
13. Withdrawing consent
Turn off any optional purpose in Privacy & Data; processing for it stops right away (agents are stopped). Withdrawal does not affect processing done before it.
14. Deleting your account
Privacy & Data → Delete my account removes your profile, resumes, answers, jobs, runs, chats, tickets and saved logins at once. Backups roll off within the period above. Payment records are kept as required by law ⚖️. Data already sent to job sites must be deleted with those sites.
15. Cookies and tracking
Only essential cookies to keep you signed in. Optional analytics only if enabled and you accept. See Cookie policy.
16. Children
Kaamyab is for adults (18+) looking for jobs. Do not use it if you are under 18. If we learn that we hold a child's data without verifiable parental consent we will delete it ⚖️.
17. Grievances
Write to our Grievance Officer [GRIEVANCE OFFICER NAME] at [PRIVACY EMAIL] or use Privacy & Data → Privacy request. We aim to respond within the time the DPDP Rules require ⚖️. If you are not satisfied, you may approach the Data Protection Board of India.
18. Data breaches
If a personal data breach happens we will inform affected users and the Data Protection Board as the DPDP Act and Rules require ⚖️.
19. Changes to this notice
We will show you material changes and ask for your consent again where needed. The version is at the top.
20. Contact
[LEGAL ENTITY NAME], [BUSINESS ADDRESS] · (add your contact email in Admin → Website)