Public Beta — v0.9.0

Privacy Notice

Effective date: 12 August 2026 · Last updated: 12 August 2026

1. Who we are

Diviplace is operated by Divikriti Technology (“we”, “us”, “our”). We are the data controller for personal data processed through the Diviplace platform.

Divikriti Technology is established in India. We do not currently operate a separate European establishment. Where we process the personal data of people in the European Economic Area we do so as a controller established outside the EEA, and EU data-protection law still applies to that processing. Our appointment of an Article 27 EU representative is under review with external counsel and will be published here before it is required.

Contact: [email protected]

1a. Which country’s rules apply to you

Diviplace is used by recruiters, employers and candidates in different countries, and a single placement routinely spans more than one — an Indian recruiter, a Dutch employer and a candidate in the United States can all touch the same record. Rather than publish one notice per audience, this notice is written to cover every combination, with country-specific clauses stated where the law of that country demands something different.

  • India — our place of establishment. Processing here is governed by Indian law, including the Digital Personal Data Protection Act.
  • European Economic Area (incl. the Netherlands) — where you are in the EEA, the GDPR applies to your personal data regardless of where we are established. Your rights in section 6 apply in full, and the Article 27 position in section 1 applies.
  • United States — state privacy laws may give you additional rights depending on your state of residence. Where they do, we honour them through the same request route in section 6.
  • Anywhere else — this notice applies as written. Countries are added to the platform through the operating-countries configuration, and a country joining that list does not require a new privacy notice: it inherits this one, plus any country-specific clause added here at the same time.

Which country’s clauses apply is determined by where you are, not by where the other parties to a placement are. If two sets of rules both apply to the same record, we apply the stricter one.

2. Public Beta notice

Diviplace is currently in Public Beta. During the beta period:

  • Features and data structures may change without prior notice.
  • Beta data may be migrated, reset, or deleted as part of platform development.
  • We strongly recommend not storing sensitive production data during the beta.
  • We will provide at least 30 days' notice before any data deletion event.

3. What data we collect and why

CategoryExamplesPurposeLegal basis
Account dataName, email address, organisation nameCreate and manage your accountContract (Art. 6(1)(b) GDPR)
Candidate dataCV, contact details, employment history, interview notesRecruitment pipeline managementLegitimate interest (Art. 6(1)(f)); Consent where required
Placement recordsContract dates, hours worked, pay ratesManage placements and timesheetsContract (Art. 6(1)(b))
Usage dataPage views, feature usage, error logsPlatform improvement and debuggingLegitimate interest (Art. 6(1)(f))

4. How long we keep your data

  • Account data: Retained for the duration of your account plus 12 months after closure.
  • Candidate data: Retained for up to 2 years from last activity, or until you request deletion.
  • Placement and timesheet records: Retained for 7 years for tax/legal compliance.
  • Beta data: Subject to the beta retention terms in Section 2 above.

5. Who we share data with

  • Clerk: Identity and authentication provider — stores login credentials.
  • Neon (PostgreSQL): Database provider — stores platform data.
  • Upstash (Redis): Caching provider — stores session-level data.
  • Cloudflare R2: Object storage for documents and files.
  • SendGrid: Email delivery for notifications and campaigns.

All subprocessors are contractually bound to process data only as instructed and maintain appropriate security measures. We do not sell personal data to third parties.

6. Your rights under GDPR

If you are in the EU/EEA or UK, you have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Ask us to correct inaccurate data.
  • Erasure: Request deletion of your data where there is no overriding legal obligation to retain it.
  • Portability: Receive your data in a machine-readable format.
  • Restriction: Ask us to restrict processing in certain circumstances.
  • Objection: Object to processing based on legitimate interest.
  • Withdraw consent: Where processing is based on consent, withdraw it at any time.

To exercise any right, contact [email protected]. We respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

7. Security

We use industry-standard security measures including encryption at rest and in transit, access controls, and regular security reviews. Candidate PII is encrypted in the database using AES-256. No system is perfectly secure; if you discover a vulnerability, please contact [email protected].

8. Changes to this notice

We will post any changes to this page and update the “Last updated” date above. Material changes will be notified by email to registered users at least 14 days in advance.