Privacy Policy

This Privacy Policy explains how Talent Networking (a sole-proprietorship registered in Hubli, Karnataka, India), the operator of the InterviewPrep.co.in platform (“we”, “us”, or “InterviewPrep”), collects, uses, stores, and shares your personal data when you use our website and services. We comply with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDP Act).

1. What we collect

  • Account data: name, email address, phone number (if provided), preferred language, password (stored as a salted hash), and a record of email-OTP verification.
  • Resume / CV data: the resume you upload and the parsed structured version of it (roles, companies, education, skills), plus any target job description you paste in.
  • Interview data: interview transcripts (your answers and the interviewer’s questions), audio of your spoken responses during the session, AI-generated per-question scores and STAR analysis, feedback reports, and answer rewrites.
  • Presence / body-language data (optional): If you opt in to video analysis, a set of anonymous numeric metrics (e.g., eye contact %, posture score, smile frequency, blink rate) computed entirely on your device via open-source MediaPipe models. We never receive or store video frames, images, or audio from your webcam.
  • Payment data: we do not store credit card or UPI credentials. Transactions are processed by Cashfree Payments; we only retain the payment ID, plan, amount, and status returned by their API.
  • Technical data: IP address, browser user-agent, device type, time-zone, and pages visited (collected via cookies and server logs for security and analytics).
  • Communications: support tickets you open with us, and emails we send you (sign-up confirmation, OTP, password reset, interview feedback ready, billing receipts).

2. How we use your data

  • To create and operate your account, deliver the interview service, and generate your feedback report.
  • To run AI scoring on your written and spoken responses (we use third-party LLM and STT providers — see Section 5).
  • To compare your CV to the job description you target and produce a gap analysis and tailored questions.
  • To process payments and issue invoices/receipts.
  • To send you transactional emails (OTP, sign-up confirmations, password resets, interview-ready notifications, billing receipts).
  • To prevent fraud, abuse, and comply with legal obligations.
  • To improve the platform — aggregated and anonymised usage analytics only.

3. Lawful basis

Under the DPDP Act, our lawful basis for processing is your consent (collected when you create an account, complete email OTP verification, and accept these terms) and legitimate use for purposes including providing the service you have requested, complying with law, and responding to medical or safety emergencies.

4. How long we keep your data

  • Active accounts: retained while your account is active.
  • Closed accounts: personal data is deleted within 30 days of account deletion request, except where retention is required by law (e.g., GST records — 8 years).
  • Interview audio recordings: retained for 90 days unless you opt to keep them longer for your own progress tracking.
  • Interview transcripts & feedback reports: retained for 365 days unless you delete them earlier from your account.
  • Presence (video-analytics) metrics: retained with the associated interview session. No raw video or frames are ever stored.
  • Email tracking events: retained for 18 months.

5. Sharing with third parties

We share the minimum data required with these processors, all of whom are contractually bound to confidentiality and security standards:

  • Cashfree Payments — payment processing (India).
  • Hostinger — VPS hosting and SMTP email delivery (EU/India).
  • Various LLM inference for scoring, feedback compilation, and interviewer-agent conversation; we send only your interview transcripts and CV text, not your identity.
  • Google (MediaPipe) model CDN — serves computer-vision model files to your browser. MediaPipe runs client-side only; Google does not receive your video.
  • Google Analytics 4 — aggregated traffic analytics (you can opt out via browser settings).

We do not sell your personal data. We do not share your data with advertisers. We never share your resume, interview transcripts, or feedback with recruiters or employers without your explicit instruction.

6. Cross-border transfers

Some of our processors (notably the AI providers) operate servers outside India. By using the service, you consent to your interview responses and CV text being transferred internationally for the purpose of AI scoring and interviewer-agent inference. We do not transfer your name, email, or payment details to these providers.

For users located in the European Economic Area (EEA), the United Kingdom, or Switzerland, such transfers rely on Standard Contractual Clauses (SCCs) approved by the European Commission and, where available, the vendor’s Data Processing Agreement (DPA). See our GDPR addendum (Section 13) for details.

7. Security

We use HTTPS (TLS 1.3) for all traffic, encrypted storage for passwords and SMTP credentials (Fernet symmetric encryption at rest), role-based access controls, and regular security patches. No method of internet transmission is 100% secure; we cannot guarantee absolute security but commit to industry best practices.

8. Your rights

Under the DPDP Act, you have the right to:

  • Access a copy of your personal data we hold.
  • Correct inaccurate or incomplete data (including your parsed resume).
  • Request deletion of your account and associated data.
  • Withdraw consent at any time (without affecting prior lawful processing).
  • Nominate another individual to exercise your rights in case of incapacity.
  • Lodge a grievance with our Grievance Officer (Section 11).

Most of these can be exercised directly from your account settings page (Account → Privacy). For others, contact us at privacy@interviewprep.co.in.

9. Cookies

We use strictly-necessary cookies (for authentication and CSRF protection) and analytics cookies (Google Analytics). Strictly-necessary cookies cannot be disabled. You can disable analytics cookies via your browser’s “Do Not Track” setting or by installing a cookie-blocker extension.

10. Children

Our service is not directed to children under the age of 16. We do not knowingly collect data from children. If you believe a child has provided us with data, contact us and we will delete it within 7 days.

11. Grievance Officer

In accordance with the IT Act 2000 and the DPDP Act, the Grievance Officer is:

Talent Networking
Hubli, Karnataka, India
Email: grievance@interviewprep.co.in
Response within: 30 days

12. Changes to this policy

We may update this policy. Material changes will be notified via email or an in-app banner at least 7 days before they take effect. The “Last updated” date at the top reflects the current version.

13. GDPR addendum — EEA, UK & Switzerland users

This section applies to users located in the European Economic Area (EEA), the United Kingdom, or Switzerland. It supplements — and in case of conflict, prevails over — the general policy above for such users.

13.1 Data Controller

The data controller for your personal data is Talent Networking, Hubli, Karnataka — 580020, India. You can contact us at privacy@interviewprep.co.in.

As we do not routinely process personal data of EU residents at a scale that triggers GDPR Article 27, we have not appointed an EU-based representative. If you believe appointment is required in your case, contact us and we will address it on a case-by-case basis.

13.2 Legal bases under GDPR

We rely on the following lawful bases (GDPR Art. 6) for processing your personal data:

  • Contract (Art. 6(1)(b)) — to provide the mock-interview service you have signed up for (creating your account, running interviews, scoring, issuing receipts).
  • Consent (Art. 6(1)(a)) — for optional marketing emails, the video-based Presence analysis (opt-in on every interview), analytics cookies beyond strictly-necessary, and storage of audio recordings beyond the default 90-day retention.
  • Legal obligation (Art. 6(1)(c)) — tax invoicing, record-keeping, fraud prevention, responses to lawful authorities.
  • Legitimate interests (Art. 6(1)(f)) — securing our service against abuse, preventing account takeover, product improvement via aggregated analytics. You may object at any time (see Section 13.4).

We do not process special-category data (GDPR Art. 9) except where you voluntarily include health- or belief-related information in your free-text interview responses; in that case processing is limited to the purpose of AI scoring and the data is deleted on the standard retention schedule.

13.3 International transfers

Your personal data is stored primarily on servers in India (Hostinger VPS). Interview transcripts and CV text sent to AI providers are transferred to their infrastructure in the United States, the European Union, or India depending on the vendor. These transfers rely on:

  • Standard Contractual Clauses (EU Commission decisions 2021/914 and 2021/915) where the vendor supports them.
  • Vendor DPAs (Data Processing Agreements) which incorporate the UK International Data Transfer Addendum where applicable.
  • Transfer-impact assessments for each vendor, reviewed annually.

A copy of the SCCs or vendor DPA in force is available on request at privacy@interviewprep.co.in.

13.4 Your rights under GDPR

In addition to the rights listed in Section 8, you have the right to:

  • Access (Art. 15) — obtain a copy of the personal data we hold about you.
  • Rectification (Art. 16) — correct inaccurate or incomplete data (including your parsed resume).
  • Erasure “right to be forgotten” (Art. 17) — request deletion of your data, subject to overriding legal obligations.
  • Restriction of processing (Art. 18) — pause processing while a dispute is resolved.
  • Data portability (Art. 20) — receive your data in a structured, machine-readable format.
  • Object (Art. 21) — object to processing based on legitimate interests.
  • Not be subject to automated decision-making (Art. 22) — our AI scoring is advisory; no legal or similarly significant decision is made about you solely by automated means. You can request human review of any AI score by emailing us.
  • Withdraw consent at any time for any processing based on consent, without affecting prior lawful processing.
  • Lodge a complaint with a supervisory authority in your EEA member state. Find yours at edpb.europa.eu. UK users may complain to the ICO (ico.org.uk), Swiss users to the FDPIC (edoeb.admin.ch).

We respond to rights requests within 30 days (free of charge for reasonable requests). Most access, correction, and deletion requests can be served directly from your account settings.

13.5 Cookies & consent under ePrivacy

For visitors from the EEA/UK we set only strictly-necessary cookies by default. Analytics and non-essential cookies are set only after you consent via the cookie banner. You can withdraw consent at any time from the cookie-preferences link in the footer (coming soon — until then, clearing cookies for this domain revokes consent).

13.6 Data breach notification

In the event of a personal-data breach likely to result in a risk to the rights and freedoms of EEA/UK/Swiss users, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and affected users without undue delay where the risk is high.

13.7 Children in the EEA/UK

In the EEA, we do not knowingly offer information-society services to children under the age of 16 (or the lower age set by the member state, where that is different) without verified parental consent. UK: we do not knowingly offer services to users under the age of 13 without parental consent. If you believe a child has provided us with data, email privacy@interviewprep.co.in and we will delete it within 7 days.