Who this notice is for
PrakWay is a careers platform used in many countries. This notice covers prakway.com in all three of its language editions, the employer console, the guardian share links you create, and the email, SMS and WhatsApp messages we send you.
PrakWay is operated by TODO(owner): registered company name, a company registered. Under the Digital Personal Data Protection Act 2023 we are the Data Fiduciary for the personal data described here, and you are the Data Principal. An employer who receives your application becomes responsible for that copy in their own right, and we say so plainly rather than pretending we still control it.
If a sentence here contradicts what a screen in the product tells you, treat this notice as the one that is right and write to the Grievance Officer, because the difference is a bug we need to fix.
The lawful basis we rely on
The DPDP Act lets us process personal data with your consent, or for certain legitimate uses. We rely on the three grounds below and never on a fourth reason invented afterwards.
- Your consent — for creating an account and a public profile, for making that profile visible to employers, and for marketing email or SMS. Each of those is a separate switch and each is recorded separately.
- Performance of a contract — for taking payment, running a subscription, issuing a GST invoice, and giving you the features you paid for.
- Legitimate use — for keeping the service secure, blocking fraudulent sign-ins and abusive postings, meeting a legal obligation such as retaining invoices, and answering a lawful order.
When you consent we store the fact: which consent it was, the version of the document you agreed to — this one is privacy-2026-08 — the time, your browser, and your IP address truncated to its first three octets so it identifies a network rather than a doorstep. Consent you cannot demonstrate is not consent, and consent recorded too precisely is its own privacy problem.
You can withdraw any consent from Settings, as easily as you gave it. Withdrawal stops future processing; it does not undo processing that already happened lawfully.
What we actually collect
This list is written from the database, not from a template. Where a field is optional, leaving it blank is a real option and the product keeps working.
- Identity and sign-in — your email address, your phone number in international format, a hash of your password (never the password itself), the short-lived one-time codes we send to verify you (stored hashed and deleted once used), and the Google or LinkedIn account link if you sign in that way.
- Profile — first and last name, your public handle, headline, bio, photo, city, country, timezone, reading language, and any website, LinkedIn or GitHub link you add.
- Career context — the persona you picked, how many hours a week you have, the goals and motivations you chose during onboarding, years of experience, current and expected CTC, notice period, and whether you are open to work.
- Work history and study — employers, job titles, dates, institutions, degrees, skills with a proficiency level, and endorsements other members give you.
- Resumes — the file you upload, its name and size, the structured text we parse out of it, and the match scores we compute with the reasons behind each one.
- Applications — which role you applied to, which resume you sent, your cover note, the match score at the moment you applied, and every stage change with its date.
- Learning — the courses you enrol in, which lessons you finished and when, certificates earned, and your daily streak.
- Salary reports — company, role, city, years of experience, base, bonus, equity and total in per year, the date of the offer, and the offer letter if you choose to upload one as evidence.
- Interview experiences and practice — the write-up you contribute, the questions you were asked, the answers you type or dictate while practising, how long you took, and the confidence you rated yourself.
- Walk-in drives — which drive you intend to attend, the city you are travelling from, a note if you leave one, and whether you chose to be visible to other attendees.
- Messages — conversations with recruiters and other members, the message text, and which messages you have read or muted.
- Your workspace — goals, milestones, tasks, notes, bookmarks and collections. These are private to you.
- Activity — a log of what you did in the app and when, with the experience points and streaks that the progress screens and the guardian link are calculated from.
- Guardian share links — the link secret, the label you gave it, which of the four things it reveals, how many times it has been opened, and when it was last opened.
- Payments — the Razorpay order and payment identifiers, the amount in paise, GST, the invoice number, and your GSTIN and place of supply if you are buying as a business. Card numbers, UPI handles and bank details go to Razorpay directly and never reach our servers.
- Technical records — the IP address and browser attached to each sign-in session, kept so that you can be told when a new device signs in and so a stolen session can be shut down.
- Employer accounts — company details, who is a member and in what role, and job board credentials. Board credentials are encrypted with AES-GCM and decrypted only inside the background job that publishes a posting.
What each of those is for
Purpose limitation is a legal requirement and also a plain good rule: data collected for one thing is not quietly reused for another.
- Matching you to roles, and telling you honestly why a role does or does not fit.
- Sending your application — with the resume and cover note you chose — to the employer who posted the role.
- Showing you your own progress across applications, learning and streaks, and computing the summary a guardian link shows.
- Turning salary reports into aggregates other people can use, with no name attached.
- Letting you practise real interview questions and see whether your answers improved.
- Sending the notifications, job alerts and digests you asked for, at the frequency you chose.
- Taking payment, running the subscription, and issuing a valid GST invoice.
- Keeping the platform safe: rate limits, fraud checks, and moderation of reported content and postings.
- Fixing the product, using aggregate counts of what is used and what breaks.
What we do not do
Some of the things a careers platform could do with this data, we have decided not to do. They are written down here so they can be held against us.
- We do not sell personal data, and we do not rent or share it with data brokers or advertising networks.
- We do not use your resume or your practice answers to train a general-purpose model.
- We do not attach your name to a salary report shown to anyone else, and the offer letter you upload as evidence is never shown outside PrakWay.
- We do not tell an employer who looked at their posting and did not apply.
- We do not read your private notes or your messages, except where a specific message is reported to us for moderation or a lawful order compels it.
- We do not run advertising trackers or social media pixels on the site.
If any of these ever has to change, it will be a versioned change to this notice with notice given before it takes effect — never a quiet edit.
What is public by default
Your profile page is public and indexable by search engines. That is the point of it: a link you can put in an application. It shows your name, handle, headline, bio, city, skills and the endorsements you have received.
Everything else is private unless you make it otherwise. Applications, resume files, salary submissions, practice answers, notes, goals, tasks, bookmarks and messages are visible only to you, and — for an application — to the employer you sent it to.
Salary reports appear in aggregates without your name. Drive attendance is hidden from other attendees unless you switch visibility on, and it is off when the intent is created.
Guardian share links
A guardian link exists so a student can show a parent that the work is happening without handing over an account password. It reveals a coarse summary — effort, learning, interviews, and offers only if you switch that on — and nothing else. There is no setting that makes it show your messages, your resume or an employer name.
You can see how many times each link has been opened and when it was last opened, set an expiry date, and revoke it at any moment from Settings.
Anyone holding the link can open it without signing in. That is what makes it usable by a parent who will never create an account, and it is also the risk. Treat the link like a password, and revoke it if it reaches the wrong person.
Children and guardians
You must be at least 18 to hold a PrakWay account. Where a student under 18 uses the platform, the DPDP Act requires verifiable consent from a parent or lawful guardian, and the account must be created and held by that adult.
We do not knowingly build behavioural profiles of children, we do not run tracking or targeted advertising at all, and we do not send marketing messages to an account we know belongs to a child.
If you believe a child data is on the platform without proper consent, write to the Grievance Officer and we will act on it.
How long we keep it
Nothing is kept indefinitely by default, and the few things that outlive your account are listed here rather than buried.
- While your account is open — profile, resumes, applications, learning and workspace stay until you delete them or delete the account.
- One-time codes — minutes. They are deleted once used or expired.
- Sign-in sessions — until the refresh token expires or you sign out, whichever comes first.
- A deleted account — erasure runs after a seven-day window. Deletion by accident or in anger is the most common support request there is, and seven days costs nothing while making it recoverable.
- Invoices and payment records — eight years from the end of the financial year, because the Companies Act 2013 requires books of account to be kept that long. These survive account deletion; they have to.
- Consent records and payment webhook events — kept as evidence for as long as the underlying obligation can be questioned.
- Salary aggregates — the statistics survive erasure of your row, because once your identity is removed they are no longer your personal data.
- Moderation records — a report and the decision taken on it are kept so that a decision can be shown to have been consistent.
How it is protected
The controls below are the ones actually in the code, not a list of intentions.
- Passwords are stored as hashes. We cannot read your password, and neither can anyone who steals the database.
- Session and refresh tokens are stored hashed, in rotating families, so a stolen token can be detected and the whole family revoked at once.
- Resumes and salary evidence files sit in private object storage and are reached only through short-lived signed links. There is no public URL for any of them.
- Employer job board credentials are encrypted with AES-GCM and decrypted only inside the worker that uses them.
- Everything travels over TLS, and consent evidence stores a truncated IP address rather than a full one.
- No system is perfectly secure. If a breach affects your personal data we will report it as the DPDP Act requires, and tell you what happened and what to do about it.
Your rights, and how to use them
As a Data Principal under the DPDP Act you have the following rights over everything described above.
- Access — a summary of the personal data we process about you, and who we have shared it with.
- Correction and completion — fix anything wrong or out of date, update it, or complete a partial record.
- Erasure — have your data deleted, except where a law requires us to keep it.
- Nomination — nominate another person to exercise these rights for you if you die or become incapable of exercising them yourself.
- Grievance redressal — a named officer who has to answer you, before you go to the regulator.
- Withdrawal of consent — as easy to withdraw as it was to give.
Settings has an Export and a Delete button. Each creates a tracked request with a status you can watch: an export lands as a file you download from a private link, and an erasure is scheduled after the seven-day window and can be cancelled inside it.
If you cannot reach Settings, write to the Grievance Officer from the email address or phone number on the account and we will verify you another way. We do not act on an unverified request, because that is exactly how an account gets stolen.
Where the data lives
Your data is stored. Some of the processors listed above may process it outside India in the course of running their own service — a monitoring service or a message delivery provider, for example.
The DPDP Act permits transfers outside India except to countries the Central Government restricts by notification. We do not transfer to a restricted country, and we will change providers rather than continue if a country is added to that list.
Changes to this notice
Every version of this notice carries a version string, shown at the top of the page. The one in force is privacy-2026-08.
For a material change — a new purpose, a new category of recipient, a shorter protection — we will tell you before it takes effect and, where the change needs it, ask for fresh consent and record the new version against your account. Wording corrections are published without fresh consent, and the version string still changes so you can see that something moved.
Contact and complaints
For anything about this notice, or about data we hold, write to the Grievance Officer. The contact details, the response times we hold ourselves to, and how to escalate to the Data Protection Board of India are all on the grievance redressal page.
Write from the email address or phone number on the account where you can. It saves a round of identity checks and gets you an answer sooner.
