Privacy Policy
DRAFT — review with a CA-DPO/lawyer before commercial use. This document captures product intent for design-partner conversations and Razorpay onboarding. It is not yet legal counsel-reviewed.
Effective date: 2 May 2026 Last updated: 2 May 2026
This Privacy Policy explains how TrustGraph ("we", "us", "our") collects, uses, stores, and shares your personal data. It is written to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable rules thereunder.
1. Data Fiduciary
TrustGraph is the Data Fiduciary for personal data you provide to us. We determine the purposes and means of processing.
- Entity: TrustGraph (sole-proprietor venture, India)
- Address on record: to be populated before commercial launch
- Grievance Officer: the founder (see §10 below)
Where a Company posts a job and we surface candidates to it, that Company becomes a co-Data Fiduciary for the candidate data it receives. The terms of that joint processing are set out in our Data Processing Agreement.
2. Lawful basis
Under DPDP §6, all processing on the platform proceeds on the lawful basis of your explicit, informed consent, captured at signup and re-confirmed when this policy materially changes.
You may withdraw consent at any time by deleting your account (see §8 below). Withdrawal does not affect processing already lawfully completed.
3. Categories of personal data we collect
| Category | Examples | Why we need it |
|---|---|---|
| Identifiers | Email, full name, phone (optional), avatar URL, LinkedIn ID, Google ID | Account creation, authentication |
| Resume PII | Uploaded resume PDF, parsed structured fields (work history, education, skills, location) | Match candidates to jobs |
| Professional graph | LinkedIn connection list (Connections.csv from your LinkedIn data export) | Compute warmth paths between candidates and hiring employees |
| Payment identifiers | UPI VPA, bank account name, PAN (encrypted) | Disburse bounty payouts |
| Behavioural | Intro requests, accepts/declines, vouches given/received, ledger entries | Operate the chain-payout state machine; audit trail |
We do not collect or process Sensitive Personal Data (DPDP §2(36)) such as religious belief, caste, biometrics, or health information.
4. Purposes of processing
We process your data only for these purposes:
- Operating the hiring platform (matching, ranking, intros, payouts).
- Communicating with you about your account and platform activity.
- Complying with legal obligations (tax, anti-fraud, financial-record retention).
- Improving the platform (aggregated, de-identified analytics).
We do not use your data for advertising, profiling unrelated to hiring, or sale to third parties.
5. Recipients of your data
| Recipient | Country | Purpose | Safeguards |
|---|---|---|---|
| You and other authenticated users you opt to share with | India | Intros, chain-payout history | App-level access controls |
| Resend | EU/US | Transactional email delivery | DPA in place; minimal payload (recipient + template variables) |
| Google Generative AI (Gemini) | US | Resume parsing | API call only; no training-set retention; resume not retained on their side |
| Razorpay / RazorpayX (when activated) | India | Payment processing | RBI-regulated; standard merchant DPA |
| UPI rails (PhonePe, etc.) | India | Disbursement at MVP scale | Out-of-band; we hold only the VPA, not the bank credentials |
| Government authorities | India | When compelled by valid legal process | Documented and minimised |
We do not sell your data, and we do not allow these recipients to use it for purposes beyond what we instruct.
6. Cross-border processing
Resend and Google Gemini are based outside India. Under DPDP §16, transfers proceed under the Central Government's notified country list (or absent that, on the basis of your consent under §6). We require contractual safeguards from each processor.
7. Retention
- Account data is retained while your account is active.
- After you request deletion (see §8), data is retained for a 30-day grace period during which you may cancel deletion. After grace, your account is anonymised (PII scrubbed) but financial records (ledger entries) are retained as required by Income Tax Act and the Companies Act for up to 8 years.
- Intro chains involving you are preserved (with your identifier anonymised) so other participants' history remains intact.
8. Your rights as a Data Principal
Under DPDP §11–§14 you have the right to:
- Access — receive a JSON export of your data at any time. Use the Export my data button at
/settings/privacy. - Correction — edit your profile data in-product, or email the Grievance Officer for fields not editable in the UI.
- Erasure — use the Delete my account button at
/settings/privacy. Anonymisation completes after the 30-day grace. - Grievance redressal — contact the Grievance Officer (§10). We will acknowledge within 7 days and respond within 30.
- Withdraw consent — equivalent to erasure; you can re-create an account later if you wish.
- Nominate — you may nominate another individual to exercise your rights in the event of your death or incapacity. Email the Grievance Officer.
9. Security
We secure your data using industry-standard practice: TLS in transit, password hashing (bcrypt), encryption-at-rest for sensitive fields like PAN, audit logs on every payout-relevant write, and least-privilege access by default.
In the event of a personal-data breach we will notify the Data Protection Board of India and affected users within 72 hours of becoming aware, as required by DPDP §8(6).
10. Grievance Officer
| Field | Value |
|---|---|
| Name | To be populated; the founder serves as Grievance Officer until a separate designation is filed. |
| grievance@trustgraph.in (mailto link in the footer) | |
| Response SLA | Acknowledgement ≤ 7 days, resolution ≤ 30 days |
11. Children
The platform is restricted to users 18 and over. We do not knowingly process the data of minors; if we discover such an account it will be terminated and the data deleted.
12. Changes to this policy
We may update this policy. Material changes bump the version: string at the top, which triggers a re-consent gate on your next authenticated visit.
13. Contact
Email the Grievance Officer (§10) for any privacy-related question. We read every message.