Privacy Policy

Effective date: 15 July 2026

1. Data Controller

The data controller for personal data collected through the Leveluphired platform (leveluphired.com) is Leveluphired Technologies, an initiative of Libraryminds Technologies ("Leveluphired", "we", "us", "our"). Contact: privacy@leveluphired.com

We do not currently have a designated Data Protection Officer (DPO) as we do not engage in large-scale systematic processing of special-category data under Art. 37 GDPR. Privacy enquiries are handled by our legal team at legal@leveluphired.com.

2. Age Restriction

The Leveluphired platform is intended for users who are at least 18 years old, or at least 13 years old with verified parental or guardian consent. Users in the European Union must be at least 16 years old (or the age set by their EU Member State under Art. 8 GDPR). We do not knowingly collect personal data from children under these thresholds. If you believe a child has provided us with personal data without appropriate consent, contact privacy@leveluphired.com and we will delete it promptly.

3. Personal Data We Collect

3.1 Data you provide directly

3.2 Data collected automatically

3.3 Cookies and similar technologies

See §4 (Cookie Policy) for a full list of cookies set. In summary: we set one authentication session cookie and one UI-state cookie. We set no advertising, retargeting, or cross-site tracking cookies.

4. Cookie Policy

A full cookie disclosure is available at /cookie-policy. Summary:

Cookie namePurposeDurationCategoryConsent required?
rz_sessionKeeps you authenticated (logged in)7 daysStrictly NecessaryNo, essential for service
sidebar_stateRemembers sidebar open/closed state7 daysStrictly NecessaryNo, UI functionality
rz_consent_v1Records your cookie consent choice (stored in localStorage, not a cookie)Until clearedConsent recordNo, legally required record

No third-party cookies are set. Your consent choice is stored in browser localStorage (not a cookie) to avoid the circular problem of setting a cookie before consent.

5. Lawful Basis for Processing (GDPR Art. 6)

Processing activityLawful basisGDPR Article
Account creation and managementPerformance of contractArt. 6(1)(b)
AI mock interview analysisPerformance of contractArt. 6(1)(b)
ATS resume scanning and scoringPerformance of contractArt. 6(1)(b)
Third-party AI sub-processing (Gemini, AssemblyAI)Performance of contract, processed on our behalfArt. 6(1)(b) + Art. 28
Transactional emails (password reset, credit alerts)Performance of contractArt. 6(1)(b)
Platform usage analytics (server-side, no third-party tools)Legitimate interest, improving platform reliabilityArt. 6(1)(f)
Cookie consent recordLegal obligationArt. 6(1)(c)
Marketing or promotional communicationsConsent (opt-in only)Art. 6(1)(a)

6. Third-Party Sub-Processors

We share your personal data with the following third-party processors, each bound by a data processing agreement (DPA) with us. This list is maintained up to date; we will update it before adding any new processor.

6.1 AI Processors

Your resume text and interview transcripts are transmitted to third-party AI providers to generate scores and feedback. These providers act as data processors under Art. 28 GDPR.

We do not authorise AI sub-processors to use your data to train their general foundation models.

6.2 Payment Processors

Leveluphired offers paid subscription plans (Core and Pro) and one-time credit purchases. All payments are processed by our payment gateway, Razorpay, which acts as an independent payment processor.

From Razorpay we receive only what we need to fulfil your order and keep accurate records: a payment or subscription reference, the amount, the plan or credit pack purchased, the payment status, and a masked or tokenised payment identifier. We store these billing records to grant your plan or credits, provide receipts, handle refunds and disputes, and meet tax and accounting obligations.

Billing and transaction records are retained for 7 years to comply with Indian tax and accounting law, as set out in the Data Retention table below. We will update this list promptly if sub-processors change.

7. International Data Transfers

Leveluphired is operated from India. India is not currently recognised by the European Commission as providing an adequate level of data protection under Art. 45 GDPR. For users in the European Economic Area (EEA), transfers of personal data to Leveluphired and to our US-based AI sub-processors are made under EU Standard Contractual Clauses (SCCs) as adopted by the European Commission (Decision 2021/914), or alternatively on the basis that the transfer is necessary for the performance of a contract between you and Leveluphired (Art. 49(1)(b) GDPR).

Copies of applicable SCCs are available on request from legal@leveluphired.com.

8. Data Retention

Data categoryRetention periodReason for retention
Account profile (name, email, college)Until account deletion + 30 daysService delivery; 30-day recovery window
Resume textUntil you delete it, or account deletionRequired for ATS feature; user-controlled
Interview transcripts and scoresUntil you delete them, or account deletionRequired for history and AI features
Raw voice audioDeleted promptly after transcription (typically within minutes); deletion retried on failureOnly used for speech-to-text; not retained
Usage logs (page visits, feature usage)90 daysBug investigation and platform improvement
Server access logs (IP address)30 daysSecurity and fraud prevention
Cookie consent record (localStorage)Until you clear your browser dataLegal obligation to record consent
Financial transaction records7 yearsTax and accounting legal obligations (India)
Support correspondence2 years after resolutionDispute resolution and legal protection

9. Your Rights

9.1 Rights under GDPR (EU / EEA residents)

Under the General Data Protection Regulation, you have the following rights:

To exercise any of these rights, email privacy@leveluphired.com. We will respond within 30 days (GDPR Art. 12). No fee is charged for requests unless they are manifestly unfounded or excessive.

9.2 Rights under India DPDP Act 2023

9.3 California residents (CCPA / CPRA)

California residents have the right to know what personal information is collected, to delete personal information, to opt out of sale (we do not sell personal information), and to non-discrimination for exercising these rights. To submit a CCPA request, email privacy@leveluphired.com with the subject "CCPA Request".

10. Data Security

We implement appropriate technical and organisational security measures including: HTTPS/TLS encryption in transit, data stored securely with access controls restricted to authorised personnel on a need-to-know basis, and regular security reviews. No method of transmission over the internet is 100% secure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by Art. 33 to 34 GDPR within 72 hours of becoming aware.

11. Links to Third-Party Sites

Our platform may contain links to external websites. This Privacy Policy does not apply to those sites. We are not responsible for the privacy practices of third-party websites and encourage you to review their policies.

12. Changes to This Policy

We will post updates to this Privacy Policy on this page and update the "Last updated" date. For material changes, we will notify you via email or an in-app notice at least 14 days before the change takes effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

Last updated: 15 July 2026