Digital Personal Data Protection & Governance Act (DPDP) Act, 2023

Understanding the DPDP Act, 2023: How MyCVBuilders Protects Your Personal Data

This document outlines how MyCVBuilders processes, protects, and governs personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules framed thereunder.

Last Updated

August 2026

Grievance SLA

72 hours

Jurisdiction

The courts of India

1. Overview & Statutory Framework

The Digital Personal Data Protection Act, 2023 establishes a comprehensive legal regime in India for the processing of digital personal data. As a Data Fiduciary , we uphold the core principles of purpose limitation, data minimization, storage limitation, and demonstrable accountability.

2. Data Fiduciary & Data Protection Officer (DPO)

Pursuant to Section 8 and Section 9 of the DPDP Act, the details of the Data Fiduciary and its designated Grievance Officer / Data Protection Officer are published below:

Data Fiduciary:

  • ---
  • Registered office in India

Data Protection Officer (DPO)

  • Grievance & Compliance Office
  • Email: [email protected]
  • Statutory Redressal SLA: Within 72 hours

3. Data Collection & Minimization

In accordance with Section 6(1) of the DPDP Act, we only collect personal data that is strictly necessary for the specified purpose of providing high-performance document parsing and verification runtimes.

Data We Collect

  • Account Identifiers: Name, email address, password hash (Argon2id), and authentication tokens.
  • Uploaded Documents: PDF files, images, and scanned identity artifacts submitted for OCR processing.
  • Accounting & Operational Metrics: Request ID, timestamp, HTTP status, page counts, output tokens, and execution latency.
  • IP Addresses: Kept strictly for abuse prevention, security defense, and rate-limiting. Automatically purged after 30 days.

Data We Never Collect or Process

  • We never perform biometric identification or facial recognition profiling.
  • We do not set third-party cross-site advertising trackers or tracking pixels without active affirmative consent.
  • We never sell or distribute uploaded documents to external brokers or data brokers.

4. Specified Purposes of Processing

Under DPDP Act Section 6, personal data may only be processed for the specific lawful purpose for which the Data Principal has given consent:

  • 1. Core Runtime & Authentication (Mandatory)
  • Verifying API credentials, executing Resume Parsing and ATS processing, and maintaining session security, and generating GST-compliant tax invoices.
  • 2. Model Performance & Error Telemetry (Optional Opt-In )
  • Analyzing aggregated Resume Parsing failure, ATS processing error and API latency patterns to improve inference accuracy and pipeline reliability.
  • 3. Security Advisories & Compliance Notifications (Optional Opt-In)
  • Notifying registered users of security advisories, privacy policy updates, and compliance-related announcements.

5. Technical & Organizational Safeguards

Section 8(5) of the DPDP Act mandates reasonable security safeguards to prevent personal data breaches: :

  • Encryption in Transit & At Rest: All traffic is encrypted using TLS 1.3. Object storage for uploaded documents is protected by authenticated encryption.
  • Key Hashing: API keys are hashed with HMAC-SHA256 and server-side secret peppers. Plaintext keys are never stored in the database.
  • Zero-Plaintext Consent Logs: User consent decisions are logged with pseudonymous HMAC hashes rather than plaintext PII.
  • Isolated Environments: Production parsing sandboxes operate in ephemeral, stateless container environments.

6. Data Principal Rights

Under Chapter III of the DPDP Act, you possess clear, enforceable statutory rights. You can directly exercise your rights to data export, consent withdrawal, or irreversible erasure below:

  • Right to Access & Portability (Section 11): You can request access to your data and export it in a structured, commonly used, and machine-readable format.
  • Right to Correction & Erasure (Section 12): You can request that inaccurate or incomplete data be corrected or deleted.
  • Right to Modify or Withdraw Consent (Section 6(4)): You have the unconditional right to withdraw consent with the same ease with which it was given.

7. Data Retention & Storage Limitation

In compliance with Section 8(7) of the DPDP Act, personal data is not retained beyond the period necessary to satisfy the purpose for which it was processed, except where statutory Indian law mandates preservation.

  • Free and signed-out users: Uploaded documents and associated metadata are automatically purged after 3 days of inactivity.
  • Plus Subscription users: Uploaded documents and associated metadata are automatically purged after 14 days of inactivity.
  • Pro Subscription users: Uploaded documents and associated metadata are automatically purged after 30 days of inactivity.
  • Abuse Investigation IP Addresses: IP addresses are retained for 30 days for abuse prevention and security defense, after which they are automatically purged.
  • Tax Invoices (CGST Act Section 36): Tax invoices and billing records are retained for 72 months in accordance with Indian tax law.

8. Data Processors & Sub-Processors

We engage specialized data processors bound by strict confidentiality and data protection agreements under Section 8(2) of the DPDP Act:

  • Our payment gateway provider Cashfree Payments Private Limited (Cashfree)As a certified Payment Aggregator (RBI compliant), Cashfree manages the secure processing of all payment transactions, including refunds and chargebacks.
  • Our cloud hosting provider Oracle Cloud Infrastructure (OCI), which manages the secure storage and processing of uploaded documents and metadata.
  • Our email service provider Transactional SMTP, which handles the sending of transactional emails related to user accounts and communications.
  • Our AI model inference provider Nvidia NIM, which processes uploaded documents for OCR and ATS parsing.

9. Grievance Redressal & Appellate Escalation

If you have questions, concerns, or grievances regarding your personal data or consent choices, you may submit a formal complaint directly to our Grievance Officer:

  • Grievance Redressal Mechanism

  • Email: [email protected]
  • Turnaround SLA: All grievances receive formal acknowledgment within 24 hours and resolution within 72 hours.
  • Under Section 13 of the DPDP Act, if your grievance is not resolved satisfactorily, you have the right to register a complaint with the Data Protection Board of India.