01
हम कौन हैं
NextStep ("हम") उस legal entity द्वारा operate होता है जिसके पास NextStep brand है ("Company")। जब आप NextStep website और mobile apps ("Service") use करते हैं, तो हम processed personal data के data controller हैं। Privacy सवालों के लिए: support@nextstep-today.com। EU/UK representative और (जहाँ ज़रूरी) Data Protection Officer उन regions में general launch से पहले इस section में नियुक्त और घोषित होंगे।
02
यह policy क्या कवर करती है
यह policy nextstep.app website (और उसके subdomains) और NextStep के iOS व Android mobile apps पर लागू होती है। यह उन third-party sites, employer career pages, job boards, calendar tools या other external services को cover नहीं करती जिनसे आप Service के अंदर के links से interact करते हैं। उनकी अपनी policies हैं — उन्हें अलग से पढ़ें।
03
हम कौन-सा personal data collect करते हैं
हम personal data की निम्न categories process करते हैं:
- —Account data — email, password hash, account बनाने का timestamp, language preference, country, marketing-email opt-in।
- —Profile data — नाम, current और target role, अनुभव के साल, location, salary range, public social-profile URLs जो आप share करना चुनते हैं।
- —Resume content — हर resume का text और structured fields, जिसमें work history, education, skills, certifications और links शामिल हैं।
- —Job-search content — tracker में save की वैकेंसी, application status, notes, contacts, scheduled interviews।
- —Voice recordings — voice resume और interview rehearsal modules में आपकी upload की audio, साथ ही उनकी generated transcripts।
- —Usage data — कौन से pages देखे, कौन से features use किए, in-product events (जैसे "ATS check चलाया", "onboarding step 3 पूरा") और aggregated session telemetry।
- —Device data — IP address, user-agent, device type, OS version, app version, time zone और एक pseudonymous device identifier।
- —Payment data — billing address, card के अंतिम चार अंक, plan, currency, taxes। पूरा card number हम नहीं देखते और save नहीं करते — यह विशेष रूप से payment processor handle करता है।
- —Communications — support tickets, in-app feedback, हमारे transactional emails के जवाब।
04
Data कहाँ से आता है
हम personal data सीधे आपसे लेते हैं (जब आप sign up, profile fill, resume upload, voice record, vacancy save या support में लिखते हैं) और Service use करने पर automatically (usage और device data)। Google या Apple से sign-in करने पर हम वह email और basic profile information भी पाते हैं जिसे आपने उस provider को share करने की अनुमति दी।
05
हम क्यों process करते हैं और कानूनी basis
हम नीचे दिए purposes के लिए personal data process करते हैं। जहाँ EU/UK GDPR लागू है, कानूनी basis brackets में:
- —Service प्रदान करना — resumes बनाना, analyses generate करना, jobs track करना, coaching nudges बनाना (contract performance, Art. 6(1)(b) GDPR)।
- —Payments process करना, taxes calculate करना और fraud रोकना (contract performance; legal obligation; fraud रोकने में हमारी legitimate interest)।
- —Transactional messages भेजना — billing receipts, security alerts, trial reminders (contract performance; legitimate interest)।
- —Aggregated और pseudonymised analytics व model-output quality evaluation से Service सुधारना (legitimate interest; आप कभी भी object कर सकते हैं)।
- —नए features पर optional marketing emails भेजना (केवल आपकी explicit consent पर; Settings से कभी भी वापस ले सकते हैं)।
- —कानूनी obligations पूरी करना — tax, accounting, authorities के lawful requests (legal obligation)।
06
Voice recordings और AI processing
जब आप voice recordings upload करते हैं (voice resume, interview rehearsal, pronunciation drills), हम audio को text में transcribe करके transcript process करते हैं ताकि feedback दे सकें। हम आपकी voice को biometric identification या voiceprint के लिए use नहीं करते। Default पर voice recordings 90 दिनों तक रहती हैं ताकि आप replay कर सकें; आप Settings से कोई भी recording delete कर सकते हैं, जिसके बाद वह 24 घंटों में हमारे systems से हट जाती है।
आपके resumes और jobs का text हम third-party large-language-model providers के through process करते हैं ताकि माँगे गए analyses और suggestions generate हो सकें। Contract के अनुसार ये providers हमारे API traffic पर अपने models train नहीं कर सकते और हमारे prompts केवल abuse detection के लिए strictly आवश्यक समय तक रखते हैं (आमतौर पर 30 दिनों तक)।
07
Automated decisions
NextStep AI से suggestions, scores, drafts और recommendations generate करता है। ये सलाह देने वाले tools हैं — कौन-सा resume भेजना है, किस job पर apply करना है, interview में कैसे जवाब देना है — यह final decision इंसान (आप) लेते हैं। हम ऐसे केवल automated decisions नहीं लेते जो आप पर legal या उनके बराबर significant असर डालें। हम आपको किसी job, employer या opportunity के लिए screen in/out नहीं करते, और Service का use employers candidates evaluate करने के लिए नहीं करते।
08
किसके साथ share करते हैं
हम personal data केवल नीचे दी गई recipient categories के साथ share करते हैं, और सिर्फ़ उतनी मात्रा में जितनी Service चलाने के लिए strictly ज़रूरी है:
- —Cloud hosting और database providers — आपका data store करने और infrastructure चलाने के लिए।
- —Authentication और sign-in providers — आपकी पहचान verify करने के लिए (social sign-in में Google व Apple भी)।
- —Payment processor — subscriptions, taxes, chargebacks और जहाँ लागू हो refunds के लिए।
- —AI / large-language-model providers — analyses, scores, drafts, transcriptions और coaching messages generate करने के लिए।
- —Email और push-notification providers — transactional और (consent पर) marketing messages deliver करने के लिए।
- —Customer-support tools — आपके support tickets handle करने के लिए।
- —App-store providers (Apple, Google) — in-app purchases, receipt verification और crash reports के लिए।
- —Professional advisers, auditors, regulators और law-enforcement authorities — जहाँ कानून strictly आवश्यक करे।
हम personal data sell नहीं करते और cross-context behavioural advertising के लिए share नहीं करते। नामित sub-processors की updated list support@nextstep-today.com पर request पर उपलब्ध है।
09
International data transfers
हमारी infrastructure मुख्यतः EU और US में चलती है, और कुछ providers globally operate करते हैं। जब personal data EEA, UK या किसी restricted-transfer jurisdiction से बाहर जाता है, हम appropriate safeguards पर निर्भर रहते हैं — European Commission की Standard Contractual Clauses, UK International Data Transfer Addendum, adequacy decisions जहाँ हों, या EU–US Data Privacy Framework जहाँ recipient certified हो। लागू safeguards की copy request पर उपलब्ध है।
10
कितने समय तक रखते हैं
हम personal data केवल उतने समय तक रखते हैं जितना ज़रूरी है:
- —Account, profile, resumes, jobs और analyses — जब तक आपका account active है।
- —Voice recordings — upload से अधिकतम 90 दिन, या जब तक आप पहले delete न कर दें।
- —Billing records — 7 साल तक, जैसा tax व accounting कानून माँगता है।
- —Security और abuse-prevention logs — 12 महीनों तक।
- —Marketing-email engagement data — जब तक आप consent वापस न लें।
आपका account delete करने पर हम 30 दिनों के अंदर personal data delete या anonymise करते हैं, सिवाय उन records के जिन्हें कानून लंबा रखने को कहता है (जैसे billing)।
11
हम data कैसे सुरक्षित रखते हैं
हम industry-standard safeguards use करते हैं: TLS 1.2+ in transit, AES-256 at rest, role-based access controls, audit logging, टीम के लिए least-privilege सिद्धांत, periodic security reviews और documented incident-response process। कोई system पूर्णतः सुरक्षित नहीं होता: किसी भी personal-data breach पर हम कानून के अनुसार बिना अनुचित देरी के आपको और सक्षम supervisory authority को सूचित करेंगे।
12
आपके privacy rights
आप कहाँ रहते हैं इसके अनुसार आपके पास ये अधिकार हो सकते हैं: data access; गलत data correct; data delete; processing पर restrict या object; portable format में data; consent वापस लेना (पिछली lawful processing पर असर बिना); supervisory authority के सामने शिकायत। अधिकांश rights Settings से सीधे exercise किए जा सकते हैं (export, correct, delete)। बाक़ी के लिए: support@nextstep-today.com — हम 30 दिनों में जवाब देते हैं।
13
बच्चे
यह Service बच्चों के लिए नहीं है। NextStep use करने के लिए आपकी उम्र EEA और UK में कम-से-कम 16 साल, भारत में 18 साल, या US में verifiable parental consent के साथ कम-से-कम 13 साल (COPPA) होनी चाहिए। हम लागू न्यूनतम उम्र से कम वालों का personal data जानबूझकर collect नहीं करते। अगर आपको लगे कि किया है, support@nextstep-today.com पर लिखें — हम delete करेंगे।
14
Cookies और similar technologies
हम केवल Service चलाने के लिए strictly आवश्यक cookies और similar local-storage items use करते हैं: एक authentication session cookie, एक language-preference cookie और एक CSRF-protection cookie। Marketing, advertising, retargeting या third-party analytics cookies हम Service पर नहीं use करते। हम third-party tracking pixels embed नहीं करते।
15
California residents (CCPA / CPRA)
अगर आप California resident हैं, तो section 12 के अधिकारों के साथ-साथ आपके पास हैं: हमने कौन-सी personal information collect की और कैसे use करते हैं — यह जानने का अधिकार; deletion request का अधिकार; गलत information correct करवाने का अधिकार; personal information की किसी भी "sale" या "sharing" से opt-out का अधिकार; sensitive personal information के use को सीमित करने का अधिकार; इन अधिकारों के उपयोग पर discrimination न झेलने का अधिकार। हम personal information sell नहीं करते और cross-context behavioural advertising के लिए share नहीं करते। CCPA rights के लिए: support@nextstep-today.com या Settings में in-app tools use करें।
16
इस policy में बदलाव
Service के विकास के साथ हम यह policy update कर सकते हैं। Material changes के लिए हम नई version प्रभाव में आने से कम-से-कम 30 दिन पहले आपको email और in-app banner से सूचित करेंगे। Non-material changes (typos, clarifications, sub-processor list refresh) publication पर प्रभावी हो जाते हैं। पेज के टॉप पर दी "effective" तारीख़ हमेशा current version दर्शाती है।
17
संपर्क और शिकायतें
Privacy सवाल और rights requests: support@nextstep-today.com। EU/UK और EEA users को अपनी local data-protection authority के सामने शिकायत दर्ज करने का अधिकार है। उन regions में general launch से पहले इस section में हमारा EU/UK representative नियुक्त और घोषित होगा।