1. Who We Are
futurein.ai Ltd. ("we", "us", "our") operates the futurein.ai platform. For questions about this Privacy Policy, contact our Data Protection Officer at privacy@futurein.ai.
2. What Data We Collect
2.1 Data You Provide
- Account data: Email address, name, and password when you register
- Resume data: Skills, work history, education, and other information extracted from uploaded resumes or LinkedIn profiles
- Payment data: Billing details processed by Stripe (we never store raw card data)
- Communications: Emails, support messages, or feedback you send us
2.2 Data We Collect Automatically
- IP address and approximate location (country/city level)
- Browser type, device type, and operating system
- Pages visited, time on site, and click behaviour (via analytics cookies)
- Referral source (how you found us)
3. How We Use Your Data
- To provide and personalise the career assessment service
- To process payments and manage your subscription
- To send transactional emails (receipts, assessment results, account alerts)
- To send marketing communications if you have opted in (you can unsubscribe at any time)
- To improve our AI models and platform (using anonymised, aggregated data only)
- To comply with legal obligations
We process your personal data on the following legal bases: contract performance, legitimate interests, consent (for marketing), and legal obligation.
4. Resume and Profile Data
Resume content is processed by our AI systems to extract skills and experience. This data is stored securely and associated with your account. We do not share your resume with employers, recruiters, or job boards without your explicit written consent. You can delete your uploaded files at any time from your account settings.
5. Cookies
We use the following categories of cookies:
- Essential cookies: Required for the platform to function (authentication, session management). Cannot be disabled.
- Analytics cookies: We use privacy-respecting analytics (no fingerprinting) to understand how users interact with the platform. You may opt out.
- Marketing cookies: Only set if you consent. Used to measure the effectiveness of our advertising campaigns.
You can manage cookie preferences via the cookie banner on your first visit or at any time through your browser settings.
6. Data Sharing
We share your data only with:
- Stripe: Payment processing (they are a data processor acting on our instructions)
- Cloud infrastructure providers: Secure hosting (e.g., AWS or equivalent), with data processed under EU standard contractual clauses
- Email service providers: For transactional and marketing emails
- Legal authorities: Where required by law or to protect our legal rights
We never sell your personal data. We never share your resume or career data with employers without your consent.
7. International Data Transfers
We may process data in countries outside your country of residence. Where we transfer data outside the EEA or UK, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses or adequacy decisions).
8. Data Retention
We retain your personal data only as long as necessary for the purposes described in this policy. Specific retention periods:
- Resume analysis results β 24 months from creation, then automatically deleted. Raw resume files are never stored.
- Chat messages β 12 months from creation, then automatically deleted.
- Activity logs β 24 months from creation, then automatically deleted.
- Security event logs β 12 months from creation, then automatically deleted.
- Account data (email, name, score) β Until account deletion.
- Payment records β 7 years as required by financial regulations (held by Stripe).
- Consent records β 7 years as required by law (anonymised after account deletion).
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of all personal data we hold about you
- Rectification: Correct any inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a machine-readable format
- Objection: Object to processing based on legitimate interests
- Restriction: Request we restrict processing in certain circumstances
- Withdraw consent: For any processing based on consent, withdraw it at any time
To exercise any of these rights, email privacy@futurein.ai. We will respond within 30 days.
10. Security
We implement industry-standard security measures including AES-256 encryption at rest, TLS 1.3 for data in transit, regular security audits, access controls limiting who can access your data, and secure development practices. Despite these measures, no system is completely secure. Please report any suspected security vulnerabilities to security@futurein.ai.
11. Children's Privacy
The Service is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe we have collected data from a person under 18, please contact privacy@futurein.ai immediately and we will delete it. If you believe we have collected data from a child, please contact us immediately.
12. Changes to This Policy
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware, as required by applicable law. If the breach is likely to result in a high risk to you personally, we will also notify you directly without undue delay.
India β Digital Personal Data Protection Act 2023
If you are located in India, we process your personal data in accordance with the Digital Personal Data Protection Act 2023 (DPDP Act). You have the right to access, correct, and erase your personal data, and to nominate a representative to exercise these rights. Contact privacy@futurein.ai to exercise your rights under the DPDP Act.
Global Privacy Laws
Depending on where you are located, additional privacy rights and obligations may apply:
United States β California (CCPA/CPRA)
California residents have the right to know what personal information we collect, request deletion of their data, opt out of the sale of personal information (we do not sell personal information), and non-discrimination for exercising these rights. To exercise your California privacy rights, contact privacy@futurein.ai.
Canada β PIPEDA
Canadian users have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA). You may access, correct, or request deletion of your personal information by contacting privacy@futurein.ai.
Brazil β LGPD
Brazilian users have rights under the Lei Geral de ProteΓ§Γ£o de Dados (LGPD), including access, correction, deletion, portability, and the right to information about data sharing. Contact privacy@futurein.ai to exercise these rights.
UAE β PDPL
Users in the United Arab Emirates have rights under the Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL). Contact privacy@futurein.ai for data access or deletion requests.
China β PIPL
If you are located in the People's Republic of China, we process your personal data in accordance with the Personal Information Protection Law (PIPL). You have rights to access, correct, delete, and transfer your personal information. Contact privacy@futurein.ai to exercise these rights.
Australia β Privacy Act 1988
If you are located in Australia, we handle your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You have the right to access and correct your personal information. Contact privacy@futurein.ai to exercise these rights.
We may update this Privacy Policy from time to time. We will notify you of material changes by email to your registered address at least 30 days before they take effect. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
13. Contact & Complaints
For privacy questions: privacy@futurein.ai
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the UK this is the ICO (ico.org.uk). In Australia this is the Office of the Australian Information Commissioner (oaic.gov.au). In the EU, contact your national supervisory authority.