Privacy Policy
CVDB ("we", "us", or "our") is committed to protecting the privacy and personal data of our users. This Privacy Policy describes how we collect, use, store, share, and protect your personal data when you use the CVDB platform, mobile applications, website, and associated services (the "Services").
This policy follows a global privacy baseline designed to protect all users worldwide, supplemented by specific regional compliance provisions (including the India Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, and applicable international data protection standards).
1. Platform Operator & Contact Information
For the purposes of applicable data protection laws, the platform operator and Data Fiduciary / Data Controller is:
- Platform: CVDB
- Official Support & Privacy Email: support@thecvdb.com
- Operations Base: India
If you have any questions regarding your data rights, privacy preferences, or this Privacy Policy, please contact us at support@thecvdb.com.
2. Personal Data We Collect
We collect different categories of personal data depending on whether you register as a Candidate or a Recruiter.
2.1 From Candidates (Job Seekers)
- Registration & Identity Data: Full name, verified email address, encrypted password, phone number, LinkedIn profile URL, nationality, and work authorization / visa status.
- Resume & Professional Data: Information contained in your uploaded CV/resume (PDF or DOCX), including work experience, internships, education history, technical skills, certifications, and project portfolios.
- Job Preferences & Availability: Current country and state/region, preferred work locations, relocation willingness, preferred work modes (remote/hybrid/onsite), notice period, expected annual salary, and active job-seeking availability status.
- Platform-Generated & Device Data: Compatibility match scores, AI Job Match Scanner evaluations, skill gap feedback reports, application pipeline history, availability activity timestamps, and Firebase Cloud Messaging (FCM) device push tokens.
2.2 From Recruiters (Employers)
- Corporate & Account Details: Full name, business email address, phone number, company name, company website, industry, company size, office address/location, and corporate tax identification (such as GSTIN, CIN, PAN, or regional Tax ID) used for Anti-Phishing Shield verification.
- Billing Information: Payment transaction metadata for candidate match quotas (processed securely via third-party payment gateways; we do not store raw credit/debit card numbers).
- Job Posting Data: Job titles, descriptions, required and preferred skills, experience bounds, education/certification requirements, and salary brackets.
3. How We Process Your Personal Data
We process your personal data strictly for providing and securing the recruitment matchmaking platform under the following bases:
| Purpose of Processing | Data Categories Used | Legal Basis |
|---|---|---|
| Account Creation, OTP Verification & Security | Registration Data, Email | Explicit Consent / Account Setup |
| AI Resume Parsing & Structured Profiling | Uploaded Resume, Extracted Text | Explicit User Consent |
| Automated Job Match Scoring & Ranking | Skills, Experience, Preferences, Location, Availability | Explicit User Consent |
| AI Job Match Scanner (External JD Testing) | Candidate Profile Data, Pasted Job Descriptions | Explicit User Action & Consent |
| Displaying Profile Summaries to Recruiters | Headline, Skills, Match Score, Experience, Preferences, Nationality/Work Auth | Core Platform Functionality |
| Unlocking Contact Details & CVs | Phone Number, Email, Evaluated Resume Document | Verified Recruiter Quota & Consent |
| Real-Time Push Notifications & Market Digests | FCM Device Token, Email, Match Telemetry | Explicit User Consent |
4. How Our AI & Matching Engine Work
4.1 AI Parsing & Job Match Scanner
We use secure, enterprise-grade AI APIs to extract structured career fields from uploaded resumes and to power the candidate AI Job Match Scanner. Your resume data and personal identifiers are never sold or used to train public third-party AI models.
4.2 Deterministic & Weighted Match Scoring
Our matching engine calculates compatibility out of 100% across two primary dimensions:
- Technical Fit (65% Weight): Evaluates Core Required Skills (35%), Experience Bounds (10%), Certifications (10%), and Project Keywords (10%).
- Role Fit (35% Weight): Evaluates Availability Status (20%), Location & Work Mode Compatibility (10%), and Education Match (5%).
- Fair Comparison Safeguards: Expected salary is decoupled (0% weight) from the match score so candidates are judged on merit and role alignment. Overqualification flags are raised if experience exceeds the maximum bound by 2 or more years.
4.3 Human-in-the-Loop & Anti-Phishing Shield
Match scores are advisory rankings to help recruiters discover relevant talent. Final outreach invitations and hiring pipeline transitions are performed by human recruiters. Furthermore, our Anti-Phishing Shield masks candidate phone numbers and restricts CV downloads until a recruiter is verified via a corporate domain or registered Tax ID.
5. Data Sharing & Third-Party Sub-Processors
We do not sell your personal data to data brokers or advertisers. We share data only with essential infrastructure sub-processors required to operate CVDB:
- Supabase (Cloud Database & Storage): Hosts our relational PostgreSQL database, authentication services, and encrypted storage buckets for resume documents.
- Enterprise AI Processing APIs: Processes unstructured resume text and job descriptions into structured data fields.
- Google Firebase Cloud Messaging (FCM): Delivers real-time mobile and web push notifications for invitations, pipeline updates, and reminders.
- Email Delivery Services (Resend / SMTP): Dispatches OTP verification codes, password resets, and support ticket confirmations.
- Verified Recruiters: Recruiters who post matching jobs (≥40% compatibility) can view structured candidate profile summaries, and upon verification and quota activation, access full contact details and resumes for recruitment evaluation.
6. Data Retention & Instant Account Erasure
- Active Accounts: We retain your personal data for as long as your account remains active on the Platform.
- Inactivity & Availability Decay: To keep recruiter feeds accurate, candidate availability status may automatically adjust to "Open to Work" after 7 days of inactivity or 72 hours of unresponded invitations, which you can restore with 1 tap at any time.
- Right to Erasure (Delete Profile & Account): You can permanently delete your account at any time directly inside the app (Settings → Delete Profile & Account). Deleting your account triggers an immediate cascade deletion of your profile records, skills, invitations, applications, and credentials, and purges your uploaded resume file from storage.
7. Your Global Data Rights
Regardless of your location, we provide all users with the following core privacy rights:
- Right to Access & Portability: View and download your profile information and uploaded CV at any time through your dashboard.
- Right to Correction: Edit and update your skills, experience, preferences, and personal details instantly in the app.
- Right to Visibility Control: Switch your profile visibility between Public, Private, or Hidden to pause recruiter discovery whenever you choose.
- Right to Withdraw Consent & Delete: Withdraw your consent to data processing at any time by deleting your account in Settings or emailing support@thecvdb.com.
8. Country-Specific Provisions: India Supplement
If you are located in or accessing the Services from the Republic of India, the following additional provisions apply to you in accordance with the Digital Personal Data Protection Act, 2023 ("DPDPA") and the Information Technology Act, 2000 ("IT Act") and rules made thereunder:
- 8.1 Data Fiduciary & Data Principal: Under the DPDPA, CVDB acts as the Data Fiduciary and you (the user) act as the Data Principal. We process your digital personal data based on your free, specific, informed, unconditional, and unambiguous consent provided via explicit checkboxes during registration (recording UTC timestamps for Terms, Privacy, and AI Processing consent).
- 8.2 Rights of Data Principals in India: In addition to the global rights in Section 7, you have the statutory right under the DPDPA to:
- Obtain a summary of the personal data being processed and the processing activities undertaken by us;
- Obtain the identities of all other Data Fiduciaries and Data Processors with whom your personal data has been shared;
- Nominate any other individual who shall, in the event of your death or incapacity, exercise your data protection rights; and
- Seek grievance redressal through our Grievance Officer and, if unresolved, approach the Data Protection Board of India.
- 8.3 Children's Data Protection: The Services are strictly intended for individuals aged 18 years and older. We do not knowingly collect or process personal data of individuals under 18 years of age.
- 8.4 Cross-Border Data Processing: Our cloud database and AI infrastructure sub-processors may process and store data on secure servers located in India or in global cloud regions permitted by the Central Government of India under the DPDPA.
- 8.5 Grievance Officer (India IT Rules & DPDPA Compliance): In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDPA 2023, any discrepancies, privacy concerns, or grievances regarding data processing may be addressed to our designated Grievance Officer:
- Designation: Grievance Officer — CVDB Platform
- Email: support@thecvdb.com (Please include "Grievance Officer / Privacy" in the subject line)
- Resolution Timeline: We acknowledge all grievances within 24 hours and resolve them within 15 days from the date of receipt.