Privacy Notice
Effective date: 12 August 2026 · Last updated: 12 August 2026
1. Who we are
Diviplace is operated by Divikriti Technology (“we”, “us”, “our”). We are the data controller for personal data processed through the Diviplace platform.
Divikriti Technology is established in India. We do not currently operate a separate European establishment. Where we process the personal data of people in the European Economic Area we do so as a controller established outside the EEA, and EU data-protection law still applies to that processing. Our appointment of an Article 27 EU representative is under review with external counsel and will be published here before it is required.
Contact: [email protected]
1a. Which country’s rules apply to you
Diviplace is used by recruiters, employers and candidates in different countries, and a single placement routinely spans more than one — an Indian recruiter, a Dutch employer and a candidate in the United States can all touch the same record. Rather than publish one notice per audience, this notice is written to cover every combination, with country-specific clauses stated where the law of that country demands something different.
- India — our place of establishment. Processing here is governed by Indian law, including the Digital Personal Data Protection Act.
- European Economic Area (incl. the Netherlands) — where you are in the EEA, the GDPR applies to your personal data regardless of where we are established. Your rights in section 6 apply in full, and the Article 27 position in section 1 applies.
- United States — state privacy laws may give you additional rights depending on your state of residence. Where they do, we honour them through the same request route in section 6.
- Anywhere else — this notice applies as written. Countries are added to the platform through the operating-countries configuration, and a country joining that list does not require a new privacy notice: it inherits this one, plus any country-specific clause added here at the same time.
Which country’s clauses apply is determined by where you are, not by where the other parties to a placement are. If two sets of rules both apply to the same record, we apply the stricter one.
2. Public Beta notice
Diviplace is currently in Public Beta. During the beta period:
- Features and data structures may change without prior notice.
- Beta data may be migrated, reset, or deleted as part of platform development.
- We strongly recommend not storing sensitive production data during the beta.
- We will provide at least 30 days' notice before any data deletion event.
3. What data we collect and why
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account data | Name, email address, organisation name | Create and manage your account | Contract (Art. 6(1)(b) GDPR) |
| Candidate data | CV, contact details, employment history, interview notes | Recruitment pipeline management | Legitimate interest (Art. 6(1)(f)); Consent where required |
| Placement records | Contract dates, hours worked, pay rates | Manage placements and timesheets | Contract (Art. 6(1)(b)) |
| Usage data | Page views, feature usage, error logs | Platform improvement and debugging | Legitimate interest (Art. 6(1)(f)) |
4. How long we keep your data
- Account data: Retained for the duration of your account plus 12 months after closure.
- Candidate data: Retained for up to 2 years from last activity, or until you request deletion.
- Placement and timesheet records: Retained for 7 years for tax/legal compliance.
- Beta data: Subject to the beta retention terms in Section 2 above.
5. Who we share data with
- Clerk: Identity and authentication provider — stores login credentials.
- Neon (PostgreSQL): Database provider — stores platform data.
- Upstash (Redis): Caching provider — stores session-level data.
- Cloudflare R2: Object storage for documents and files.
- SendGrid: Email delivery for notifications and campaigns.
All subprocessors are contractually bound to process data only as instructed and maintain appropriate security measures. We do not sell personal data to third parties.
6. Your rights under GDPR
If you are in the EU/EEA or UK, you have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct inaccurate data.
- Erasure: Request deletion of your data where there is no overriding legal obligation to retain it.
- Portability: Receive your data in a machine-readable format.
- Restriction: Ask us to restrict processing in certain circumstances.
- Objection: Object to processing based on legitimate interest.
- Withdraw consent: Where processing is based on consent, withdraw it at any time.
To exercise any right, contact [email protected]. We respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
7. Security
We use industry-standard security measures including encryption at rest and in transit, access controls, and regular security reviews. Candidate PII is encrypted in the database using AES-256. No system is perfectly secure; if you discover a vulnerability, please contact [email protected].
8. Changes to this notice
We will post any changes to this page and update the “Last updated” date above. Material changes will be notified by email to registered users at least 14 days in advance.