Effective date: 15 July 2026
The data controller for personal data collected through the Leveluphired platform (leveluphired.com) is Leveluphired Technologies, an initiative of Libraryminds Technologies ("Leveluphired", "we", "us", "our"). Contact: privacy@leveluphired.com
We do not currently have a designated Data Protection Officer (DPO) as we do not engage in large-scale systematic processing of special-category data under Art. 37 GDPR. Privacy enquiries are handled by our legal team at legal@leveluphired.com.
The Leveluphired platform is intended for users who are at least 18 years old, or at least 13 years old with verified parental or guardian consent. Users in the European Union must be at least 16 years old (or the age set by their EU Member State under Art. 8 GDPR). We do not knowingly collect personal data from children under these thresholds. If you believe a child has provided us with personal data without appropriate consent, contact privacy@leveluphired.com and we will delete it promptly.
See §4 (Cookie Policy) for a full list of cookies set. In summary: we set one authentication session cookie and one UI-state cookie. We set no advertising, retargeting, or cross-site tracking cookies.
A full cookie disclosure is available at /cookie-policy. Summary:
| Cookie name | Purpose | Duration | Category | Consent required? |
|---|---|---|---|---|
| rz_session | Keeps you authenticated (logged in) | 7 days | Strictly Necessary | No, essential for service |
| sidebar_state | Remembers sidebar open/closed state | 7 days | Strictly Necessary | No, UI functionality |
| rz_consent_v1 | Records your cookie consent choice (stored in localStorage, not a cookie) | Until cleared | Consent record | No, legally required record |
No third-party cookies are set. Your consent choice is stored in browser localStorage (not a cookie) to avoid the circular problem of setting a cookie before consent.
| Processing activity | Lawful basis | GDPR Article |
|---|---|---|
| Account creation and management | Performance of contract | Art. 6(1)(b) |
| AI mock interview analysis | Performance of contract | Art. 6(1)(b) |
| ATS resume scanning and scoring | Performance of contract | Art. 6(1)(b) |
| Third-party AI sub-processing (Gemini, AssemblyAI) | Performance of contract, processed on our behalf | Art. 6(1)(b) + Art. 28 |
| Transactional emails (password reset, credit alerts) | Performance of contract | Art. 6(1)(b) |
| Platform usage analytics (server-side, no third-party tools) | Legitimate interest, improving platform reliability | Art. 6(1)(f) |
| Cookie consent record | Legal obligation | Art. 6(1)(c) |
| Marketing or promotional communications | Consent (opt-in only) | Art. 6(1)(a) |
We share your personal data with the following third-party processors, each bound by a data processing agreement (DPA) with us. This list is maintained up to date; we will update it before adding any new processor.
Your resume text and interview transcripts are transmitted to third-party AI providers to generate scores and feedback. These providers act as data processors under Art. 28 GDPR.
We do not authorise AI sub-processors to use your data to train their general foundation models.
Leveluphired offers paid subscription plans (Core and Pro) and one-time credit purchases. All payments are processed by our payment gateway, Razorpay, which acts as an independent payment processor.
From Razorpay we receive only what we need to fulfil your order and keep accurate records: a payment or subscription reference, the amount, the plan or credit pack purchased, the payment status, and a masked or tokenised payment identifier. We store these billing records to grant your plan or credits, provide receipts, handle refunds and disputes, and meet tax and accounting obligations.
Billing and transaction records are retained for 7 years to comply with Indian tax and accounting law, as set out in the Data Retention table below. We will update this list promptly if sub-processors change.
Leveluphired is operated from India. India is not currently recognised by the European Commission as providing an adequate level of data protection under Art. 45 GDPR. For users in the European Economic Area (EEA), transfers of personal data to Leveluphired and to our US-based AI sub-processors are made under EU Standard Contractual Clauses (SCCs) as adopted by the European Commission (Decision 2021/914), or alternatively on the basis that the transfer is necessary for the performance of a contract between you and Leveluphired (Art. 49(1)(b) GDPR).
Copies of applicable SCCs are available on request from legal@leveluphired.com.
| Data category | Retention period | Reason for retention |
|---|---|---|
| Account profile (name, email, college) | Until account deletion + 30 days | Service delivery; 30-day recovery window |
| Resume text | Until you delete it, or account deletion | Required for ATS feature; user-controlled |
| Interview transcripts and scores | Until you delete them, or account deletion | Required for history and AI features |
| Raw voice audio | Deleted promptly after transcription (typically within minutes); deletion retried on failure | Only used for speech-to-text; not retained |
| Usage logs (page visits, feature usage) | 90 days | Bug investigation and platform improvement |
| Server access logs (IP address) | 30 days | Security and fraud prevention |
| Cookie consent record (localStorage) | Until you clear your browser data | Legal obligation to record consent |
| Financial transaction records | 7 years | Tax and accounting legal obligations (India) |
| Support correspondence | 2 years after resolution | Dispute resolution and legal protection |
Under the General Data Protection Regulation, you have the following rights:
To exercise any of these rights, email privacy@leveluphired.com. We will respond within 30 days (GDPR Art. 12). No fee is charged for requests unless they are manifestly unfounded or excessive.
California residents have the right to know what personal information is collected, to delete personal information, to opt out of sale (we do not sell personal information), and to non-discrimination for exercising these rights. To submit a CCPA request, email privacy@leveluphired.com with the subject "CCPA Request".
We implement appropriate technical and organisational security measures including: HTTPS/TLS encryption in transit, data stored securely with access controls restricted to authorised personnel on a need-to-know basis, and regular security reviews. No method of transmission over the internet is 100% secure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by Art. 33 to 34 GDPR within 72 hours of becoming aware.
Our platform may contain links to external websites. This Privacy Policy does not apply to those sites. We are not responsible for the privacy practices of third-party websites and encourage you to review their policies.
We will post updates to this Privacy Policy on this page and update the "Last updated" date. For material changes, we will notify you via email or an in-app notice at least 14 days before the change takes effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
Last updated: 15 July 2026