Privacy

Last updated: [DATE] — Draft for legal review before launch (India’s Digital Personal Data Protection Act, 2023). Not legal advice.

1. Who this policy covers

This Privacy Policy explains what personal data Onyx UX Studio (“Onyx”, “we”) collects through UX Jobs (uxjobs.onyxdigi.com), why, and what rights you have over it. Onyx acts as the Data Fiduciary for this data under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).

2. What we collect

  • From Google sign-in: your name, email address, and profile photo (via Google’s own consent screen — we never see your Google password).
  • If you upload a CV: the PDF file itself, and any headline, portfolio link or LinkedIn URL you choose to add.
  • Membership & billing status: your plan, renewal date, and payment status. Card, UPI and bank details are collected and processed directly by Razorpay, our payment processor — we do not receive or store them.
  • Usage data: saved jobs, jobs you’ve clicked “Apply” on, alert searches you’ve created, and basic activity needed to run the paywall and your Account page correctly.

3. Why we collect it

To create and run your account; to verify membership and show you the right version of the site; to let you save jobs, set alerts, and maintain a CV share page if you turn one on; to send you service emails (welcome/receipt, payment issues, membership status); and to maintain the security and integrity of the service.

4. Consent

We process your Google profile data on the basis of the consent you give at Google’s sign-in screen and by creating an account. We process your CV on the basis of the consent you give by choosing to upload it — uploading a CV is always optional and only required to use CV-related features.

5. Who we share data with

We do not sell personal data. We share the minimum necessary with:

  • Google — for sign-in authentication only.
  • Razorpay — to process your subscription payment; they act as an independent data processor for payment details under their own privacy policy.
  • Our email delivery provider — to send transactional emails (receipts, alerts, account notices).
  • Employers — only if you click “Apply,” which takes you to the employer’s own site; we do not hand your CV or profile to an employer automatically.

6. Your CV, specifically

CV files are stored outside the public web folder with randomised file names, not browsable or indexable. Your CV share page is private (not public) by default, and is automatically switched off if your membership lapses. You can delete your CV at any time from My CV, which deletes the file immediately.

7. How long we keep data

We keep account and membership data for as long as your account is active, and for a reasonable period afterwards for accounting, tax (GST) and fraud-prevention purposes. Your CV is kept until you delete it or delete your account. You can delete your account and associated data at any time from your Account page.

8. Your rights

Under the DPDP Act, you have the right to access, correct, and request erasure of your personal data, and to withdraw consent at any time (which may mean you can no longer use features that depend on it). You can exercise most of this yourself: edit your profile details via Google, manage or delete your CV from My CV, or delete your entire account and data from your Account page. For anything else, contact us using the details below.

9. Security

We use Google’s own authentication (no passwords for us to lose), store CVs outside the public web root, and restrict members-only data (company names, full job descriptions, apply links) to server-side checks that never expose it to non-members, search engines, or the public API.

10. Cookies

We use essential cookies to keep you signed in and to remember basic preferences. We do not use third-party advertising or tracking cookies at this time.

11. Children

This service is not directed at, and should not be used by, anyone under 18.

12. Grievance Officer

Under the DPDP Act, you can raise a complaint about how we handle your personal data with our Grievance Officer:

[GRIEVANCE OFFICER NAME]
Onyx UX Studio
[REGISTERED ADDRESS]
Email: [SUPPORT EMAIL]

13. Changes to this policy

We’ll update the “Last updated” date above whenever this policy changes materially, and post the new version here.

14. Contact

For any privacy question or request, see our Contact page.