ProfileGPT ("ProfileGPT", "we", "us", or "our") respects your privacy and is committed to protecting personal data in accordance with applicable data protection laws, including:
This Privacy Policy explains how we collect, use, store, disclose, and protect personal data when you access or use our platform available at https://www.profilegpt.in (the "Service").
ProfileGPT is the Data Controller for personal data processed through the Service.
Contact for privacy matters:
Email: privacy@profilegpt.in
Grievance Officer (India – DPDP): Mihir Joshi / Director
This policy applies to:
We collect personal data:
We process personal data on the following lawful bases:
| Purpose | Lawful Basis |
|---|---|
| Recruitment intelligence, profile display | Legitimate Interest |
| Platform access & account management | Contract |
| Email sequencing via OAuth | Consent |
| Analytics & product improvement | Legitimate Interest |
| Legal compliance | Legal Obligation |
We process personal data based on:
When you connect your Gmail or Outlook account:
ProfileGPT may use automated systems to rank profiles, enrich professional attributes, and provide recruitment insights. These processes do not produce legal or similarly significant effects on individuals.
| Data Type | Retention |
|---|---|
| User account data | Until account deletion |
| OAuth tokens | Until revoked + 30 days |
| Candidate profiles | 12 months from last activity |
| Logs & audit data | 30–90 days |
GDPR Rights (EU): Access, Rectification, Erasure, Restriction, Objection, Data portability, Withdraw consent
DPDP Rights (India): Access, Correction, Erasure, Grievance redressal, Nomination
Requests may be submitted to privacy@profilegpt.in. We respond within 30 days.
We may share data with cloud infrastructure providers, analytics providers, email delivery services, and compliance vendors. All processors are contractually bound to comply with applicable data protection laws.
Personal data may be processed outside India or the EU. We rely on contractual safeguards, industry-standard security measures, and applicable legal transfer mechanisms.
We implement encryption at rest and in transit, role-based access control, secure credential storage, audit logging, and incident response procedures.
In the event of a personal data breach, we will notify relevant authorities and affected users as legally required.
ProfileGPT does not knowingly process data of individuals under 18.
We may update this policy periodically. Material changes will be notified via the Service.