IMPORTANT NOTICE: This Privacy Policy outlines how MployD processes personal data in strict compliance with the Digital Personal Data Protection (DPDP) Act, 2023, the Information Technology Act, 2000, and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. MployD operates as a Data Fiduciary, providing candidate anonymity during initial discovery and ensuring explicit consent-based data disclosure.
1. Who We Are
MployD (mployd.in, hereinafter referred to as the "Platform" or "Marketplace") is a specialized talent discovery and matchmaking platform owned and operated by Sama.Ai (OPC) Private Limited. Under the Digital Personal Data Protection (DPDP) Act, 2023, Sama.Ai acts as the Data Fiduciary (or Data Controller) responsible for determining the purposes and means of processing personal data collected through the Platform.
Registered & Correspondence Office
- SAMA.AI (OPC) PRIVATE LIMITED, Registered Address: 101, Block C1, Akshaya Halton Apartments, Sundarapuram, Coimbatore South, Coimbatore - 641024, Tamil Nadu, India.
Privacy & Compliance Office
- Office: Legal & Compliance Cell / Data Protection Officer
- Email: compliance@mployd.in
- Official portal: https://mployd.in/privacy
2. Personal Data We Collect
We collect and process various categories of personal data provided directly by Data Principals (Candidates and Recruiters) or generated automatically during platform usage:
- a) Candidate Identifiable Data (PII): Full name, verified mobile number, personal email address, identity verification credentials, and gender. Gender is a required field: an answer must be selected, and "Prefer not to say" is one of the available answers. Unlike the other items in this category, gender is not masked from recruiters - verified recruiters can filter candidate search results by it.
- b) Candidate Professional & Assessment Data: Work experience, employment history, current employer details, job titles, technical skill sets, educational qualifications, certifications, portfolio links, notice period, and compensation details (expected benchmark ranges).
- c) Recruiter & Employer Profile Data: Recruiter full name, verified corporate email domain address, phone number, designation, corporate department, and hiring authority status.
- d) Business & Verification Credentials: Corporate name, Goods and Services Tax Identification Number (GSTIN), Corporate Identification Number (CIN), registered business address, billing address, and authorized incorporation/statutory business documents.
- e) Financial & Billing Data: Payment transaction IDs, credit purchase histories, package tier allocations, GST invoicing records, and billing contact details. Credit card and bank details are processed securely via PCI-DSS compliant third-party gateways and are not stored by MployD.
- f) Platform Communication & Interactions: In-platform messaging, feedback on candidates, proposal history, interview schedules, anti-ghosting feedback logs, customer support tickets, and communication metadata.
- g) Consent & Audit Logs: Timestamped consent logs, click-through agreement approvals, terms acceptance records, notice versioning logs, and explicit unmasking approvals.
- h) Technical & Telemetry Data: IP address, browser type and version, device identifier, operating system, login timestamps, session durations, referring URLs, platform activity logs, and cookies.
3. Why We Process Your Data
We process personal data strictly for specified, explicit, and legitimate purposes as outlined below:
| Data Category | Purpose of Processing | Legal Basis / Mandate |
|---|---|---|
| Candidate Profile & Skills | Automated candidate-recruiter matching, 28-day hiring cycle orchestration, upfront proposal evaluation, pre-vetting checks. | Explicit Consent (DPDP Act) |
| Candidate Gender | Displayed to verified recruiters as a search and filter criterion on candidate discovery. "Prefer not to say" is available and is treated as an answer, not as a blank. | Explicit Consent (DPDP Act) |
| Candidate PII (Contact Data) | Unmasking contact details to recruiters ONLY upon mutual match or explicit soft-lock activation. | Explicit Consent (DPDP Act) |
| Recruiter Corporate Credentials | Corporate verification, enforcing corporate domain restrictions, preventing fake job postings and data scraping. | Legitimate Interest & T&C Compliance |
| Business & GSTIN Data | Tax compliance, tax invoice generation, corporate account validation, statutory GST reporting. | Legal Obligation (GST Act / Tax Laws) |
| Financial & Credit Data | Processing credit package purchases, credit consumption tracking, package validity management, fee accounting. | Contractual Performance |
| Technical & Audit Data | Platform security, fraud prevention, audit trail maintenance under IT Act, system troubleshooting and analytics. | Legal Obligation & Legitimate Interest |
4. How We Obtain and Record Consent
In compliance with Section 6 of the DPDP Act, 2023, consent is obtained through explicit, affirmative action:
- Explicit Notice & Affirmative Action: Consent is requested through clear, granular, and prominent notice during account creation, profile publication, and proposal evaluation.
- Candidate Consent Mechanism: Candidates must actively click an explicit checkbox granting consent for MployD to process their personal data and unmask their profile to verified recruiters upon mutual match or soft-lock activation. Pre-ticked boxes are strictly prohibited.
- Consent Audit Evidence: Every consent action is logged in an immutable electronic audit trail capturing the User ID, exact timestamp (UTC), IP address, notice version, and checkbox state.
- Notice Versioning: Whenever this Privacy Policy or Platform Terms are updated, users are presented with a version-controlled notice requiring renewed acknowledgement upon their next login.
5. Candidate Anonymity and Recruiter Disclosure
MployD enforces a robust candidate privacy framework designed to eliminate unsolicited spam and protect job seeker confidentiality:
- Initial Discovery Anonymity: During Phase 1 (Talent Discovery - 7 Days), recruiter searches display only anonymized or semi-anonymized candidate profiles. Personally Identifiable Information (PII) - including candidate full name, phone number, personal email, and current employer name - remains masked.
- Unmasking Triggers: PII is unmasked and disclosed to a recruiter ONLY when a "Mutual Match" occurs (the candidate explicitly accepts an Upfront Proposal) and a "Soft-Lock" is activated with the recruiter under active credit consumption terms.
- Recruiter Verification Mandatory: Recruiters must undergo mandatory corporate verification (verified business domain and GSTIN/CIN checks) prior to receiving unmasked candidate data.
- Contractual No-Scraping & Onward Use Restrictions: Contractually, recruiters are strictly prohibited from harvesting, scraping, extracting, or storing candidate data in external CRM systems or agency pools, or soliciting candidates outside MployD to bypass commercial mechanics.
6. Who We Share Data With
We do not sell, rent, or trade personal data. We disclose personal data only to the following authorized entities for legitimate business and operational purposes:
- Verified Recruiters & Employers: Verified recruiters and hiring managers who have established a mutual match or activated a soft-lock, strictly for interview and hiring evaluation.
- Pre-Vetting & Verification Service Providers: Trusted third-party background screening partners and skill assessment platforms operating under strict non-disclosure obligations.
- Cloud Infrastructure & Hosting Partners: Secure cloud hosting providers, data centers, and database management infrastructure vendors (e.g., AWS/GCP nodes localized within India).
- Payment Gateways & Communication Vendors: PCI-DSS compliant payment gateways, invoice processing services, and SMS/Email communication delivery service providers.
- Professional Advisers: Legal consultants, auditors, tax advisors, and compliance experts bound by professional duties of confidentiality.
- Statutory Authorities & Law Enforcement: Government bodies, statutory authorities, law enforcement agencies, or courts of competent jurisdiction when required by law or judicial summons.
7. Retention and Deletion
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to satisfy statutory obligations:
| Data Type | Retention Trigger & Period | Deletion / Anonymization Approach |
|---|---|---|
| Active Candidate Profiles | Maintained until the candidate specifically requests account closure. | Soft-deletion followed by permanent hard deletion within 30 days of account closure. |
| Inactive Account Data | 24 months of continuous account inactivity. | Automated email notice sent; if unconfirmed, account PII is anonymized for historical statistics. |
| Billing & GST Records | 7 years from the end of the relevant financial year. | Retained in secure archived storage as required by Indian Tax & Companies Act mandates. |
| Consent & Audit Logs | 5 years from the date of consent recording/withdrawal. | Immutable archived logs maintained for legal defensibility under IT Rules and the DPDP Act. |
| Platform Telemetry & Logs | 180 days on a rolling basis. | Automated purge/overwriting of server log files. |
8. Security Safeguards
MployD implements robust technical and organizational security measures to protect personal data against unauthorized access, loss, alteration, or disclosure:
- Data Encryption Standards: Data at rest is encrypted using AES-256 standards, and data in transit is protected using TLS 1.3 cryptographic protocols.
- Access Controls: Strict Role-Based Access Controls (RBAC) ensure that staff and systems access personal data on a strict need-to-know basis.
- Infrastructure Security: Infrastructure is hosted in Tier-III secure data centers featuring multi-factor authentication, perimeter firewalls, and continuous Intrusion Detection Systems (IDS).
- Security Assessments: Automated vulnerability scanning, code audits, and third-party penetration testing are conducted periodically.
- Incident Management & Breach Notification: In the event of a personal data breach, MployD will notify the Data Protection Board of India and affected Data Principals in accordance with statutory timelines prescribed under the DPDP Act, 2023.
9. Children's Data
MployD is an exclusive professional talent recruitment platform designed strictly for adult job seekers and corporate recruiters:
- Age Restriction (18+ Mandate): Registration on MployD is restricted to individuals who are at least 18 years of age. MployD does not knowingly collect or process personal data of minors.
- Parental Consent & Account Purge: If MployD discovers that an account has been created by a minor without verifiable parental or legal guardian consent (or statutory exemption under DPDP rules), the account and all associated personal data will be purged immediately.
10. Data Principal Rights
Under the Digital Personal Data Protection (DPDP) Act, 2023, Candidates and Recruiters enjoy specific statutory rights as Data Principals:
- Right to Access Information: The right to obtain a summary of personal data processed, processing activities, and identities of third parties with whom data has been shared.
- Right to Correction and Updating: The right to request correction of inaccurate data, completion of incomplete profiles, and updating of outdated personal information.
- Right to Erasure / Deletion: The right to request erasure of personal data that is no longer necessary for the purpose collected or upon consent withdrawal, subject to statutory retention exceptions.
- Right to Withdraw Consent: The right to withdraw consent at any time, easily and without cost.
- Right of Grievance Redressal: The right to readily available grievance redressal mechanisms provided by the Data Fiduciary.
- Right to Nominate: The right to nominate an individual who shall, in the event of death or incapacity of the Data Principal, exercise these statutory rights.
11. How to Withdraw Consent
Data Principals have the right to withdraw consent for data processing at any time through the following channels:
- Direct platform self-service path: Sign in to your MployD account and open Privacy & Data Controls from the account menu. "Withdraw Consent" revokes processing consent and deactivates your profile from the marketplace while retaining your login credentials, so you can grant consent again later without rebuilding your profile. The same screen offers "Pause Engagement", which stops new proposals for the current hiring cycle and masks your salary, assessment score and rating while leaving your profile listed to recruiters as Inactive for engagement, and "Delete Account", which erases your records permanently.
- Alternative written email method: Send a written request from your registered email address to compliance@mployd.in with the subject line "Consent Withdrawal Request".
- Impact of withdrawal: Withdrawal of consent will not affect the lawfulness of processing based on consent prior to its withdrawal. However, withdrawing consent for core profile processing will result in account deactivation and inability to participate in active hiring cycles. Your consent record is not deleted when you withdraw: the withdrawal is added to it, so both the permission you gave and the moment you revoked it remain on file.
12. Grievance Redressal Mechanism
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, MployD has established a dedicated Grievance Redressal Cell to resolve user concerns efficiently:
- Designation: Legal & Compliance Officer
- Address: SAMA.AI (OPC) PRIVATE LIMITED, Registered Address: 101, Block C1, Akshaya Halton Apartments, Sundarapuram, Coimbatore South, Coimbatore - 641024, Tamil Nadu, India.
- Email: compliance@mployd.in
- Resolution Period: We acknowledge grievance complaints within 24 hours of receipt and provide final resolution within 15 days from the date of receipt.
13. Complaint to the Data Protection Board
If a Data Principal is unsatisfied with the grievance resolution provided by MployD's Grievance Officer, or if MployD fails to respond within the stipulated 15-day timeline, the Data Principal has the statutory right to escalate the matter by filing a complaint directly with the Data Protection Board of India in accordance with the procedures established under the DPDP Act, 2023.
14. Cross-Border Processing
MployD primarily stores and processes personal data on secure server infrastructure located within the Republic of India. Should cross-border data transfer or processing become necessary (e.g., using global cloud services or communicating with international recruiters), MployD ensures that such transfers comply with Section 16 of the DPDP Act, 2023 and only occur to countries or territories that are not restricted by Central Government notifications.
15. Changes to This Privacy Notice
MployD reserves the right to modify or update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or platform features.
- Version & Effective Date Tracking: Every version of this policy features a prominent Effective Date and Version Tag at the top of the document.
- Material Change Notification: In the event of material changes affecting user rights or processing purposes, registered users will be notified via email or a prominent banner upon login at least 7 days prior to the changes taking effect.
- Acknowledgement: Continued use of the MployD Platform following notification of changes constitutes acceptance of the updated Privacy Policy.