Privacy Policy
Last updated : 31st July 2026
1. Who We Are And Who This Policy Covers
Profound Club Private Limited, incorporated under the Companies Act, 2013, ("Profound", "we", "us"), operates the platform at profound.me and the Profound applications (the "Platform"). For personal data covered by this Policy, we are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and, where the EU or UK General Data Protection Regulation applies ("GDPR"), the controller.
This Policy covers three kinds of people:
- (a) Applicants/Platform Users — professionals who register, hold Voice Interactions with our automated representative (the "Rep"), and build a professional profile;
- (b) Recruiters — founders, hiring managers and their organisations who register to describe roles and receive introductions to Applicants; and
- (c) Collaborators — people an Applicant names or describes who have not themselves registered.
Applicants/Platform Users and Recruiters are together "Users". A "Voice Interaction" is a recorded conversation with the Rep together with its transcript and derived output; "Career Content" is the professional narrative built from it; "Match Output" is any automated ranking, shortlist or introduction. Terms defined in the DPDP Act or GDPR carry the meanings given there.
2. Information We May Collect
- From Applicants/ Platform Users: your profile and career information (name, contact details, photograph, location, and work and education history), and — importantly — the recorded voice conversations you hold with the Rep, which we transcribe and analyse to build your Career Content, together with your matching preferences.
- From Recruiters: your name, work email, organisation and role, and recorded voice conversations in which you describe your hiring needs, which we transcribe into hiring briefs. Billing is handled by our payment processors; we do not store card details.
- From everyone: basic usage and device data, such as the pages you visit, the features you use, and standard technical information about your device, together with your communications with us.
- About Collaborators: what an Applicant tells us about you — your name, employer, role and described contribution — and the contact details needed to invite you, as described in Clause 5. If you accept an invitation and register, we then collect information from you directly, in the same way we do for other users, including any voice conversations you choose to hold with the Rep.
3. Why We Use Your Information & Consent Mechanisms
We use your information to run Profound and verify your identity, to hold Voice Interactions and build your Career Content or hiring briefs, to generate matches and make introductions between Applicants and Recruiters, to keep the Platform secure and prevent fraud, to provide support, and to meet our legal obligations. This includes showing an Applicant's profile to Recruiters, as described in Clause 6.
If you are in India: we process on the basis of your consent, given by clear affirmative action — continued browsing is not consent — or on the legitimate uses permitted by Section 7 of the DPDP Act (for example, where you volunteered the data for a purpose and have not objected, or where the law requires processing). Consent to recording Voice Interactions is sought separately from opening an account, and consent to being shown to Recruiters is sought separately again. You can withdraw any consent easily by writing to us at help@profound.me and keep using the rest of the Services.
If you are in the EEA or UK: our legal grounds under the GDPR are — contract (running your account and delivering the Services you signed up for); consent (recording Voice Interactions, non-essential cookies, marketing); legitimate interests (matching Applicants with Recruiters, securing and improving the Platform, and inviting Collaborators — in each case balanced against your rights, with an opt-out from matching available at any time in your settings); and legal obligation (where the law requires us to act). You may object to any processing based on legitimate interests — see Clause 11.
4. Voice Conversations and AI
The Rep is an AI system, not a person, and says so at the start of every conversation. We tell you before recording begins. We transcribe and analyse what you say; we do not create voiceprints and do not use your voice to identify or authenticate you.
Raw audio is deleted within 365 days of transcription. Internal access to recordings and transcripts is limited to staff handling quality, safety, security or your grievance, and is logged. You can request a copy of, or delete, any individual conversation.
We use your conversations, transcripts and other content to operate the Platform and to train, fine-tune and improve our and our providers' artificial intelligence models, so that the Rep and our matching become more accurate over time. Wherever practicable we anonymise, pseudonymise or aggregate this data so it does not directly identify you. We rely on your consent for this use; you can withdraw that consent or ask us to stop at any time by writing to us, and withdrawal applies going forward and does not undo improvements already made where reversing them is not technically feasible. We do not sell your data, and our providers may not use it for their own purposes.
5. People Named By Applicants
Because Applicants describe work done with others, we hold personal data about people who have not registered. Those people have the full protection of this Policy, the DPDP Act and, where it applies, the GDPR, as the case maybe.
When we first contact a Collaborator — and in the EEA/UK, no later than one month after receiving their data — we tell them who we are, that a named Applicant has described work with them, what data we hold, why we are writing, our legal ground, and, with equal prominence, that they can decline, object, or require erasure. Objection means we erase everything we hold about them and stop contacting them, without requiring them to create an account.
6. Who We Share The Data With
We share personal data with service providers acting on our written instructions ("processors"), each contractually barred from using your data for their own purposes.
We also disclose data: to Recruiters, as described in Clauses 3 and 6; to authorities where the law requires, telling you where we lawfully can; and to a successor in a merger, acquisition or asset sale, on equivalent protections and with notice to you. We do not sell, rent or trade personal data, and we remain responsible for what our processors do.
7. Where Your Data Goes
We operate from India and serve Users in India, the United States and elsewhere; our processors may process data in other countries. For data covered by the DPDP Act, transfers outside India follow Section 16 and are never made to a country restricted by the Central Government. For data covered by the GDPR, transfers outside the EEA/UK are protected by an adequacy decision where one exists or by Standard Contractual Clauses with supplementary measures where needed; you can request a copy of the relevant safeguards via the contacts in Clause 11.
8. Security And Breaches
We maintain reasonable security safeguards under Section 8(5) of the DPDP Act and Rule 6 of the DPDP Rules, 2025, and Article 32 of the GDPR: encryption in transit and at rest (including audio and transcripts), role-based need-to-know access, monitoring and access logging with logs retained for twelve (12) months, tested backups, a documented incident-response process, and contractual security obligations on our processors. Payments run through authorised processors; we do not store card or banking details.
If a personal data breach occurs we will contain and investigate it, and notify in two stages under Rule 7 of the DPDP Rules, 2025: first, the Data Protection Board of India as soon as we become aware, with a description of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures we are taking; and second, each affected individual within 72 hours (or a longer period the Board allows), in plain language, telling them what happened, what data was affected, what steps they can take, and how to reach us. Where the GDPR applies, we will also notify the competent supervisory authority within 72 hours of becoming aware, and affected individuals without undue delay where the breach is likely to result in a high risk to them. If Voice Interaction data is affected we will say so expressly. We record all breaches, including those not requiring notification.
9. How Long We Keep It
We keep personal data only as long as needed for its purpose and as the law requires.The same periods apply where an account is closed by you, or suspended or terminated by us under the Terms of Service, counted from closure — except data we need to retain for the investigation that led to the termination, for legal compliance, live proceedings, an unresolved dispute, or fraud prevention. Erasure is by cryptographic or certified secure deletion. You can request erasure by contacting us, we acknowledge within five (5) working days and complete within ninety (90) days, as required under Rule 14 of the DPDP Rules, 2025, unless a legal ground for retention applies, in which case we explain it.
10. Your Rights
10.1 If you are in India (DPDP Act): you may obtain confirmation that we process your data, a summary of it, and the identities of everyone we have shared it with; require correction, completion, updating or erasure; nominate someone to exercise your rights if you die or become incapacitated; withdraw consent at any time; and raise a grievance under Clause 11, escalating to the Data Protection Board of India if unresolved.
10.2 If you are in the EEA or UK (GDPR): you may access your data and receive a copy; rectify it; erase it; restrict processing; receive it in a portable, machine-readable format; object to processing based on legitimate interests, including matching, and to any direct marketing (which we will stop without needing a reason); withdraw consent at any time without affecting prior processing.
10.3 If you are in the United States: depending on your state, you may have rights to know, access, correct, delete, and opt out of certain sharing of personal information under state privacy laws. We honour verified requests as those laws require; contact us as in Clause 11.
11. GRIEVANCE OFFICER AND CONTACTS
Under Section 13 of the DPDP Act and the Information Technology Act, 2000, our Grievance Officer is:
| Designation | Details |
|---|---|
| Grievance Officer | Anuj Rathi |
| legal@profound.me | |
| Response Time | Within thirty (30) days |
If we are notified as a Significant Data Fiduciary under Section 10 of the DPDP Act, we will appoint a Data Protection Officer in India. If we are required to designate an EU or UK representative under Article 27 GDPR, their details will be published here.
12. Cookies and Tracking
We use cookies and similar tracking technologies to track activity on our platform and hold certain information. Cookies are files with a small amount of data that are sent to your browser from a website and stored on your device. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, some portions of our service may not function properly.
13. Minors
The Services are for working professionals. We do not knowingly collect data from anyone under eighteen (18), we apply an age check at registration, and we will erase such data promptly if we find we have it. We do not track, monitor, profile or advertise to children.
14. CHANGES, GOVERNING LAW AND CONTACT
We may update this Policy, publishing the revised version here with a new "Last Updated" date. Where a change materially expands what we do with your data, adds new categories of recipient, or affects the model-training position in Clause 4, we will give at least fifteen (15) days' notice by email and obtain fresh consent where the law requires it; in those cases continued use will not amount to consent.
This Policy is governed by Indian law. Disputes are subject to the exclusive jurisdiction of the courts at Bangalore, Karnataka — save that nothing here limits any right you have under the GDPR or other mandatory law to bring proceedings or complain to a supervisory authority where you live.
Questions can be sent to hey@profound.me or to the Grievance Officer at Clause 11