Introduction
The Grasshire Platform is operated by Quantum Evolution Technologies trading as QevolveX (“we”, “us”). You create an account here, build a profile, apply to jobs across many different employers, book interviews and respond to offers.
Behind it sits Grasshire Recruitment OS, the applicant tracking system those employers use to run their hiring. This policy covers your side: your account, your profile, your documents and what happens to them when you apply. The employers’ own staff are covered by a separate policy on their portal, which will not answer your questions.
Who is responsible for your data
We act in two different capacities, and which one applies decides who you should approach.
- As the controller, for your account. Your login, your profile, your uploaded documents, the optional demographic answers you may give, and your Talent Directory consent exist independently of any one employer. We decide how that is handled and we answer for it.
- As a processor, for each application. When you apply to a job, the employer decides why and how your application is assessed. They are the controller of that hiring record — the application, your answers, interview notes, scorecards, offers and the screening output. We process it on their instructions and to operate the service.
Information We Collect
The lists below name the actual fields the software stores, not categories in the abstract. Almost everything is optional; where a field is required to use a feature at all, it says so.
Account information
- Your account: first and last name, email address, and an authentication identifier issued by Firebase Authentication when you sign in with Google or with an email and password. Name and email are mandatory; we never receive or store your Google password.
- Email verification: if you register with an email and password, we email you a six-digit code before the account is created. We hold your email address with a one-way scrambled (hashed) form of the code, never the code itself, together with its expiry and a count of attempts. A code expires after ten minutes. Once you redeem it, your account records that your email address is verified, and employers see that as a “verified” badge.
Your profile
All of it optional beyond your name and email:
- Contact and identity: phone number, postal address, LinkedIn, portfolio and GitHub URLs, and a one-line headline describing yourself.
- Profile photo: a picture you upload, or — if you sign in with Google — the photo on your Google account, captured once when you first sign in. It is shown to employers wherever your profile appears, as explained in the warning below.
- Career: current company, designation and industry, total and relevant years of experience, skills — both as a flat list and as structured entries with a category and years — notice period, work preference (remote, hybrid or onsite) and whether you are open to relocating.
- Compensation: your current salary and your expected salary, each with a currency. These are shown to recruiters and are also sent to the AI model that writes your profile summary.
- Location: the country you are in, the city you live in, and any number of preferred work locations. Your country matters beyond geography — it sets your retention period and which privacy regime applies to you.
- Work authorisation: one entry per country, each recording a status — citizen, permanent resident, work permit, requires sponsorship, or none — and an optional permit expiry date. This is indexed so that recruiters can filter and sort candidates by it. Saying nothing is recorded as “not stated”, which is not the same as “not authorised”.
- History: education (degree, university, institution, graduation year, percentage or CGPA); work experience (company, designation, employment type, start and end dates, technologies, free-text description); certifications (name, issuer, issue and expiry dates, credential ID and URL); projects; awards; languages and proficiency.
- Activity: jobs you have saved, application drafts you have not submitted, and your applications with their stage history.
Demographic information (special category)
You may optionally provide your gender and date of birth. These are the only demographic fields that exist anywhere in the platform — there is no field for ethnicity, race, disability, veteran status or religion, and none is collected by any route.
They are held in a separate table from the rest of your profile, readable and writable only by you. They are never joined to a screening, matching, ranking or projection query, and they are never included in the data sent to an employer. §10 explains the guarantee and how it is enforced.
Your resume and other documents
- The document file itself — PDF, DOC or DOCX for resumes; PNG and JPEG are also accepted for other document types — with its filename, declared content type, size and a version number. Documents are typed as resume, cover letter, certificate, ID proof or experience letter.
- The contents of the document, which we do not control. A resume is free-form. If you include a photograph, a date of birth, a marital status, a national identifier or anything else, it is stored and it is sent to the AI model along with the rest of the file.
- What the model extracts from it: name, role, email, phone, location, LinkedIn and portfolio URLs, total years of experience, seniority level, skills, employment history, education, certifications and projects.
Applications, interviews and offers
- Applications: the job, your answers to that employer’s form, the resume you attached, the stage your application has reached and its history, and the screening result.
- Interviews: round, type, scheduled time, duration, mode, the interviewer’s name, a meeting link and the recruiter’s notes to you. Where you self-schedule, the booking link token, the slots you were offered and the one you chose. Where an interview is cancelled, the reason given.
- Offers: the offer details, your acceptance or decline, and — where an offer is withdrawn — the reason the employer gave.
- Consent records: for each application, the employer, the privacy regime that applies to your country, the exact version of the wording you were shown and when you agreed. See §10.
Communication data
- Outbound email: recipient name and address, subject, and the full rendered body of the message, with delivery status and any error.
- In-app notifications: type, title, message text, link and read state. Delivered live over an authenticated WebSocket to your own private channel; no notification is ever broadcast.
Device and technical information
- Standard server logs generated by our hosting provider in the course of serving requests. We run no third-party analytics or telemetry product — the only measurement we do is the job-view count described below, and it is ours alone.
- One short-lived exception: when you request or resend a signup verification code, we read your IP address to limit how many codes can be sent from one network. It is held only in the running server’s memory for that purpose, is never written to a database or log we keep, and is gone when the server restarts.
- The site’s fonts are served from our own servers, so loading a page sends nothing to a font provider.
Usage data
We record much less than a typical consumer site. There is no third-party analytics, no session recording and no behavioural profiling — nothing here builds a picture of you or decides what you are shown. What exists is:
- Job view statistics. When any job posting is opened we count it, so an employer can tell a job nobody applied to from a job nobody saw. The record contains the job, a timestamp and the channel the link named if it named one — and, only if you accepted the analytics question, a random number identifying your browser so that opening the same job twice is not counted as two people. That number is not built from your name, email, phone or account. There is no IP address and no user-agent either way, and an employer sees a count on their own posting — never a list of what you read. Decline and the count still happens without you in it; see §10.
- Hiring metrics computed from applications for an employer’s own reports.
Cookies and browser storage
Enumerated exhaustively in the Cookie Policy. In summary: one session cookie, one CSRF cookie, a few interface preferences, your analytics answer (and, only if you accepted, a random browser number), and Google’s sign-in storage. Nothing else.
How We Collect Information
- Directly from you. Registration, profile editing, the application form, document upload, interview booking and offer response.
- From your identity provider. Signing in with Google returns your name, email address and a stable account identifier. This happens in your browser and the resulting token is exchanged once for our own session.
- Generated about you by an employer’s team. Recruiter notes, interview notes, scorecards, ratings, rejection reasons and stage changes are written by people at the employer, not by you, and you will not ordinarily see them. They are held on the employer’s side; ask them.
- Derived by automated analysis. The scores, extracted fields, summaries, strengths, risk areas and recommendations described in §5 are produced from your resume and answers rather than collected from you.
- Passed between our own services. This careers site and the employers’ portal are separate services with separate databases. They exchange messages so each holds the copy it needs — your profile is copied to the employer’s side when you apply, and stage changes, interviews and offers are copied back to you. Your demographic answers are never included in these messages.
- Automatically, in a very limited way. The session cookie and CSRF token on every request, and the job-view count described above. Nothing else.
How We Use Information
| What we use | What it does |
|---|---|
| Account details and credentials | Authenticate you, keep you signed in for a short period, and let you get back into your account. |
| Profile, career history and skills | Pre-fill application forms, present you to employers you apply to, and — only with your consent, and only the parts you choose to share — list you in the Talent Directory. |
| Profile photo | Shown next to your name wherever an employer you applied to sees you, and in the Talent Directory only if you share it. It is not sent to the AI model. |
| Compensation expectations | Shown to recruiters on your candidate record — and in the Talent Directory if you share them — and sent as context to the model that writes your profile summary. |
| Work authorisation | Lets an employer establish whether you can be hired for a role in a given country. Recruiters can filter and sort by it. |
| Resume and application answers | Assessed by the employer; screened automatically against the job’s rules; analysed by an AI model as described in §5. |
| Your country | Determines your retention period, which privacy regime governs your application, and the consent wording you are shown. It is never taken from the employer’s country. |
| Demographic answers | Nothing, currently. They are stored for you, isolated from assessment, and are not used for reporting, screening or any other purpose. |
| Interview and offer data | Coordinate interviews, show you what is scheduled and with whom, and let you accept or decline an offer. |
| Contact details | Send transactional email about your application — stage changes, interview invitations, booking links, offers — and in-app notifications. Separately, and only if you switch it on, marketing email about the platform. See §10. |
We do not use personal data for advertising, for cross-site tracking, to train general-purpose AI models, or for any purpose unrelated to a hiring process you started or a marketing email you asked us to send.
AI and Automated Processing
Every application you submit is analysed automatically. This section describes it in full, because it can affect whether your application progresses.
What runs, and on what
When you submit an application, a background worker is given your resume file, the job description and the free-text answers you gave on the application form. It reads the document from our storage and sends it, with that context, to Google’s Gemini model on Vertex AI.
The model returns, and we store against your application:
- An overall score out of 100 and a skill-match percentage.
- Sub-scores for skill match, experience, education, project relevance, resume parsability and career stability.
- Extracted contact and identity details — name, email, phone, location, LinkedIn and portfolio.
- Extracted skills, matched skills, missing skills, employment history, education, certifications, projects and impact metrics.
- Total years of experience and an inferred seniority level.
- Strength areas, risk areas and red flags — narrative judgements about you, generated by the model.
- A salary recommendation and suggested interview questions.
- A final recommendation expressed in hiring terms, ranging from a strong hire to a rejection, with the model’s reasoning.
Separately, a profile summary feature sends your whole profile — designation, experience, skills, current and expected salary, notice period, locations, work preference, education, employment history, certifications and languages, but no resume and no job description — to the same model to produce a prose summary for recruiters.
Automated screening rules
Independently of the model, each job may carry knockout and flag rules set by the recruiter — for example a minimum experience threshold. These are evaluated deterministically, not by AI, and the outcome is recorded on your application. The rules themselves are never shown to candidates.
How this affects a decision
The analysis is advisory. It is presented to recruiters, who move applications through the pipeline themselves. No stage transition, rejection or offer is executed automatically on the strength of a model output. That said, a low score, a stated risk or a rejection recommendation is visible to the person deciding, and can influence them — which is why it is described here rather than buried.
If the AI worker is unavailable or disabled, a deterministic fallback runs instead: it compares the job’s required and preferred skills against your answers using fixed weightings, makes no network call and involves no model.
Data Sharing and Disclosure
Employers
- The employer whose job you apply to receives your application, your profile including your photo (kept up to date as you edit it), your resume, your answers and the analysis described in §5.
- Every employer on the platform can see the parts of your profile you choose to share if — and only if — your Talent Directory consent is on. It is pre-selected when you register, and applied automatically to an account created with Google from the log-in page. See §10.
- Nothing about you reaches an employer you have not applied to and not consented to. There is no browsing of candidates, no sourcing database and no way for a recruiter to add you to anything.
Service providers
These are the only third parties that receive personal data, and this is what each receives:
| Provider | What it receives | Why |
|---|---|---|
| Google Cloud Platform | Your documents and photo at rest, and all application data while it is processed and passed between our services | Application hosting, file storage and internal messaging. Located in the United States (us-central1). |
| Neon (managed PostgreSQL) | Every database record: your account, profile, applications, consents and the employer-side copies described in this policy | Hosting our databases. Neon operates on cloud infrastructure; see §12. |
| Firebase Authentication (Google) | Email address, password or Google account, authentication identifier | Sign-in. Used at authentication only; every later request is authenticated by our own session token. |
| Google Vertex AI (Gemini) | Your resume file, the job description, your application answers; separately your profile including salary figures | The automated analysis in §5. |
| Google reCAPTCHA Enterprise | Your IP address, browser user-agent and how you interacted with the page — only on the sign-in, registration and password-reset pages, and never while you browse or search jobs | Telling a person from a script, so that accounts cannot be created in bulk and our signup form cannot be used to send mail to addresses that never asked for it. It returns a score and nothing else; it is not used to profile you, to decide what you are shown, or for advertising. See the Cookie Policy §7. |
| ZeptoMail | Your name and address, subject, message body | Delivering transactional email. |
| Zoho Campaigns | Your name and email address, and the fields a particular message merges — but only if you have switched marketing email on. Nothing is sent to them for a candidate who has not. | Delivering marketing email, and reporting which messages were opened and which links were followed. The same company as ZeptoMail above — both are Zoho products — but a separate service holding a separate list; the transactional mail about your applications does not go through it. |
| Slack | Operational messages about processing volumes and errors | Internal engineering alerting. Not intended to carry candidate data. |
What we do not do
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- We run no advertising or third-party tracking services. There is no Google Analytics, tag manager, advertising pixel, session-recording tool or product-analytics SDK on this site. An unused Google Analytics measurement identifier is present in our published configuration, but no analytics code is initialised and no measurement data is collected or sent. The job-view count in §2 is first-party, stays between us and the employer whose job it is, and is the only measurement on this site.
- We do not share your profile with data brokers, CV databases or job aggregators. Your profile leaves this service only towards an employer you applied to, or — while your Talent Directory consent stands — to the directory.
- We do not integrate a video-conferencing provider. An interview meeting link is text a recruiter pastes in; if you follow it, that provider’s own privacy terms apply and we are not involved.
Jobs listed from other websites
Alongside jobs posted directly by employers who use our platform, we list openings gathered from public job sources. Jobs posted directly are marked Quick Apply and are applied to here, under this policy. For a job listed from another website, the Apply button takes you to that website. We send it nothing about you: you apply there, under that website’s own privacy terms, and your application does not appear in your applications here.
Legal disclosure
We may disclose personal data where we are legally required to — a binding request from a competent authority, or to establish, exercise or defend legal claims — and in connection with a merger, acquisition or asset sale, in which case this policy continues to apply to data transferred until the recipient issues its own notice.
Data Storage and Security
Authentication and sessions
- Your identity provider is used once, at sign-in. We then issue our own signed session token and validate that on every subsequent request; we do not call the provider again per request.
- The session token is held in an HttpOnly cookie — it cannot be read by JavaScript, which is what limits the damage a cross-site scripting bug could do. In production it is also
Secure,SameSite=NoneandPartitioned. - Session tokens are short-lived — fifteen minutes — and renewed silently while you are active. Two limits stop that renewal going on forever: after seven days without using the site, or thirty days after you last signed in with your password or Google account, you must sign in again.
- Signing out ends both halves of your sign-in. We clear our session cookie and also revoke the sign-in that Firebase keeps in your browser, so a shared computer is not left able to sign back in as you.
- This site and the employers’ portal are cryptographically separate. Each service has its own signing key, cookie name and user table, and validates the token’s audience, so your session here can never authenticate a request on an employer’s portal.
- Every state-changing request must additionally echo a CSRF token from a second cookie, which is checked server-side.
Encryption and storage
- Data is encrypted in transit with TLS, and at rest by our hosting providers’ managed encryption.
- Your documents are never publicly accessible. Your resume and other uploads live in private storage and are served only through time-limited signed links valid for fifteen minutes — long enough to open a document, not long enough to circulate one. Your browser never communicates with the storage service directly, and there is no public URL for your resume that could be guessed or shared.
- Uploads are limited to 10 MB and to PDF, DOC, DOCX, PNG and JPEG.
Access control
- Each employer’s records are scoped to that employer, and every query is filtered by that scope. One employer cannot see another’s pipeline, and an employer you have not applied to holds nothing about you.
- Within an employer, who can see your application follows their roles — administrator, recruiter, hiring manager, interviewer — enforced at the API rather than only hidden in their interface.
- Live updates run over an authenticated WebSocket. You receive messages only on your own private channel; nothing about you is broadcast.
Limitations we would rather state than imply
No system is perfectly secure. We aim to notify affected users and the relevant authorities of a personal data breach within the timeframes applicable law requires.
Data Retention
The retention clock is yours, not the employer’s
How long your data is kept is determined by your own country, never the country of the employer you applied to. A German applicant to a company in the United States is governed by the German period. The clock runs from your last activity — the most recent of an account change, a profile update, an application or a document upload — and not from when you signed up.
| Your country | Retention period after last activity |
|---|---|
| Germany | 6 months |
| United Kingdom | 6 months |
| United States, Canada, India, Singapore, Australia, United Arab Emirates | 12 months |
| Anywhere else | No period is configured, so no automated deletion is scheduled. You can still request erasure at any time (§9). |
What deletion does
When a retention period is reached, or when we action an erasure request:
- Your files are deleted from storage first, then the database records — in that order deliberately, so that a failure part-way through cannot leave the documents behind with only the index of them removed.
- Your account is deleted, taking with it your profile, uploaded photo, education, work experience, certifications, projects, awards, languages, preferred locations, work authorisation, demographic answers, documents, saved jobs, notifications, interviews, offers, booking links, application drafts and your consent records.
- The employer’s hiring record is anonymised rather than deleted. Your name, email address, application answers and the references to your resume are removed and the application is marked as anonymised. What remains is the shell of the process — the stage it reached, the dates, the outcome and the screening result — because an employer has its own obligation to be able to account for hiring decisions, and a vanishing application would silently rewrite its records.
- Your profile copy on the employer’s side is deleted outright, along with the AI analyses, the AI-written summaries, the resume reference, recruiter notes about you, and any Talent Directory listing.
- A minimal deletion record survives — your identifier, your country, the period applied and when it happened — because it is the only remaining evidence that the deletion was authorised. It describes the erasure, not you.
What outlives an erasure
How the automatic deletion runs
A scheduled job checks every night for accounts whose retention period has passed and deletes them as described above. It handles a limited number of accounts per night, so deletion may complete a few days after your period ends rather than on the exact day. Before erasing anyone it records who is due and why, and that record is what the minimal deletion record above is kept from. You never need to wait for it: you can request erasure at any time (§9).
Other periods
- Talent Directory consent expires automatically after 24 months if you do not renew it.
- In-app notifications you have read are deleted 90 days after they were sent, and all notifications — read or not — after 180 days.
- Application drafts you never submitted are deleted after 90 days without changes.
- Signup verification codes expire after 10 minutes. Document download links expire after 15 minutes. Session tokens expire after 15 minutes and are renewed while you are active (§7).
Your Rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict or object to the processing of your personal data, to withdraw consent, and to complain to a supervisory authority. We honour these regardless of whether your jurisdiction compels us to.
Being straightforward about how each one is actually exercised today:
You can do these yourself, now
- Correct anything in your profile — every field, and every education, experience, certification and language entry can be edited or deleted individually.
- Withdraw your demographic answers. Clearing both gender and date of birth deletes the record rather than storing two blanks, so the withdrawal is genuine.
- Withdraw Talent Directory consent at any time, from your profile. You are asked to confirm once, the same as when you switch it on, and nothing else stands in the way. Your listing is removed from every employer’s directory.
- Remove saved jobs and delete unsubmitted application drafts.
These we handle on request
There is currently no self-service export and no self-service account deletion in the product. Contact us and a person will action it. We will confirm your identity first, and we will not charge you or ask why.
- Access — a copy of what we hold about you.
- Export / portability — that copy in a structured, machine-readable format.
- Erasure — deletion of your account and data, subject to what §8 says survives.
- Restriction and objection — including objecting to the automated analysis in §5.
- Human review of an automated decision.
If you are in the EEA or the UK you may complain to your national data protection authority. If you are in California, you may exercise your rights under the CCPA/CPRA; we do not sell or share personal data for cross-context behavioural advertising and we will not discriminate against you for exercising a right.
Your Consents and Choices
Applying requires an account
Browsing jobs is public and anonymous. Submitting an application requires a registered, signed-in account — we do not accept guest applications, so every application is attached to an account you control and can see.
Analytics — the one question we ask an anonymous visitor
On your first visit a banner asks one question: may we count you as a returning reader rather than a new one when you open a job. Accept and Decline are the same size and the same prominence, and there is no second screen. Accepting stores a random number in your browser; declining stores your refusal and nothing else.
Consent, per application
Each time you submit an application we record a separate consent: the employer, the privacy regime that applies to your country, the exact version of the wording you were shown, and the moment you agreed. The wording is produced by our server and displayed to you verbatim — if it cannot be loaded, the form will not let you submit, rather than record your agreement to something you were not shown.
The regimes we recognise and tailor the notice to: GDPR, UK GDPR, India’s DPDP Act, Singapore’s PDPA, Canada’s PIPEDA, the Australian Privacy Act, the UAE PDPL, US sectoral law and the California CCPA.
The Talent Directory — read this before you register
Talent Directory consent is a single toggle in your profile. When you register, the “Let recruiters find me” box is already ticked, so unless you untick it your account starts with consent on. If you create your account with “Continue with Google” on the log-in page, there is no box: the notice under that button tells you, and your account starts with consent on. Either way you can switch it off at any time from your profile. It is not an application and it does not apply to one employer.
- It makes you visible to every employer on the platform, not only those you have applied to.
- Always shown: your name, headline, current company and designation and how long you have held it, the city you live in, total experience, notice period and skills. These cannot be hidden, because a listing without them tells an employer nothing.
- Shown unless you switch them off: your photo; your contact details (email, phone, address and verification badges); your LinkedIn, GitHub and portfolio links; your current salary; your expected salary; your work history, industry and relevant experience; education; certifications; languages; projects; awards; your work preferences (remote/hybrid/onsite, relocation and preferred locations); and your work authorisation status. Each is a separate switch. When consent is first turned on — including when you create your account — they all start as shared, so check them in your profile straight after you register. Anything we add to this list later starts switched off until you choose to share it.
- A section you have not shared is marked to employers as not shared, not left blank. Recruiters can read your listing; they cannot edit it.
- It is the only reason your profile is held for employers you have not applied to. Withdraw it and the record is deleted outright — not flagged, not archived. There is no such thing as a withdrawn-but-retained listing.
- It expires after 24 months and you will be asked again rather than being left listed indefinitely.
Marketing email — off unless you switch it on
Separately from the Talent Directory, and separately again from your applications, you can ask us to email you about the platform: new features, and opportunities we think are worth your time. It is off unless you turn it on, it has its own switch in your profile under Email preferences, and it can be offered as a tick box when you register — which is always separate from, and never bundled into, agreeing to the Terms.
- It is not the same as email about your applications. Interview invitations, booking links, offers and stage changes are sent because you applied, not because you opted in, and they keep coming if you turn marketing email off. Unsubscribing does not silence anything you need.
- Turning it on is the only thing that lets us email you this way. The list of who receives a given campaign is built by asking, in a single database query, who has this consent standing right now — there is no second route in, no imported list and no way for a recruiter or an operator to add you.
- Being in the Talent Directory does not opt you in, and opting in does not put you in the Talent Directory. They are separate permissions with separate switches; the Directory even lets you withhold your contact details from recruiters entirely.
- Your name and email address are sent to Zoho Campaigns (§6) when a campaign includes you, along with any field that message merges. Nothing is sent to them for anyone who has not switched this on.
- These messages report opens and link clicks — see §11. Email about your applications does not.
- You can turn it off from your profile or from any message we send, and unsubscribing from a message withdraws the consent itself rather than merely suppressing that one list.
Demographic data is walled off from assessment
Your gender and date of birth, if you provide them, are held in a separate table with its own access rule: readable and writable only by you. They are never joined into a screening, matching, ranking or projection query, and they are never included in the profile sent to an employer. This is enforced by an automated test that fails the build if a demographic field appears in the data crossing that boundary — not by a convention someone could overlook.
Questions an employer is not allowed to ask you
Application forms are built by recruiters, so we filter them before they reach you. Based on the jurisdictions a job is posted in, we remove questions touching age, date of birth, gender, race, ethnicity, nationality, religion, caste, marital status, pregnancy, disability, health, sexual orientation, criminal record and photographs — and we disable requests for salary history where that is banned.
- The prohibitions are the union across every location a job is posted in, not the narrowest one: a question banned in Germany is not asked of applicants in Bangalore either, because you are all answering the same form.
- The filter is deliberately over-eager. A near miss is removed rather than kept, and it does not interpret context — so an innocuous question that merely mentions one of these words may disappear from a form.
- This happens before the form is published, so a prohibited question has no path to you even if a recruiter writes one.
Where a jurisdiction requires a salary range to be published, we block the job from being posted at all unless one is disclosed. Where a range is withheld, it is omitted from what we send rather than blanked out, so there is nothing for the public job page to leak.
International Data Transfers
Our application services, file storage and messaging run in the United States (Google Cloud region us-central1). If you are outside the United States — including in the EEA, the United Kingdom, India, Singapore, Canada, Australia or the UAE — your personal data is transferred there and processed there.
Our databases are operated by Neon, a managed PostgreSQL provider, which stores every database record described in this policy.
The same applies to the other providers in §6: Firebase Authentication, Vertex AI, ZeptoMail, Zoho Campaigns (only if you switched marketing email on) and Slack all process data outside your country in the ordinary course.
Note that this does not change your retention period or which privacy regime governs your application: both follow your country, not where the servers are.
Children’s Privacy
The Grasshire Platform is intended for adults in the labour market. It is not directed at children, and we do not knowingly collect personal data from anyone under 16 — or under the higher minimum working or digital-consent age where local law sets one.
We do not operate an age gate. Date of birth is optional and, where given, is isolated from assessment (§10), so it is not available to be used as one.
If you believe a child has given us personal data, contact us and we will delete the account and its data promptly.
Changes to this Privacy Policy
We may update this policy as the product changes or the law does. Each version carries an effective date and a version number at the top of the page, and the current one is always published here.
Where a change materially affects how we handle your personal data, we will give notice before it takes effect — by email or in the product — rather than relying on you noticing a new date.
The consent wording shown when you apply, and the wording of Talent Directory consent, each carry their own version. When either is revised, we can ask you to confirm the new wording rather than treating your earlier agreement as covering it.
Contact Information
For any privacy question, or to make a request under §9:
| Controller | Quantum Evolution Technologies (trading as QevolveX) |
| Registered address | Pune, Maharashtra, India (we work remotely) |
| Privacy contact | privacy@[your-domain] |
| Data Protection Officer | [DPO name and contact, if appointed] |
| EU / UK representative | [Representative name and address, if appointed] |
| General enquiries | [Support email] |
If you are in the EEA or the UK and are not satisfied with our response, you may complain to your national data protection authority. If your question concerns a specific application, the employer you applied to is the controller and we will direct you to them.