TheProfile360 Executive
Privacy policy
Effective 26 August 2026
Controller and scope
TheProfile360 Executive is the controller for this isolated Executive service. Executive users, sessions, cookies, databases and storage are not shared with the Professional application or Recruit OS.
Information we process
We process verified email identity, account and security events, master and mandate profile content, CVs and evidence, private references, AI results and usage, payment and invoice records, and email delivery events. Conversation requests collect name, organisation, designation, official email, purpose, context, consent timestamp and optional telephone.
Verified email identity in version one means control of an email verification link; it is not formal identity verification.
How information is used
Information is used to authenticate the account, build and store the dossier, scan files, provide Blake suggestions, process verified payments, publish explicitly selected mandates, route QR links, verify private contact requests, deliver service email, prevent abuse and meet billing/security obligations.
Service providers
MongoDB Atlas provides the isolated Executive database; AWS provides private object storage and on-demand malware scanning; OpenAI is an AI service provider/subprocessor for Blake; Razorpay processes payments; Vercel hosts the application; and the approved email transport delivers transactional mail.
Only the minimum relevant text is sent to OpenAI. Private references or confidential evidence are not sent unless the executive explicitly selects and consents to that processing. Uploaded document instructions are ignored and treated only as untrusted career evidence.
Public and private boundaries
Public mandate pages receive only approved profile fields. Sensitive documents and private references are never returned by public-profile endpoints. A public page may state “Confidential references available on request.” Controlled tokens are scoped, revocable and time-limited.
Viewer contact details remain encrypted and undisclosed until the viewer verifies the official email. Public browsing itself requires no verification.
Security and retention
Private files use encrypted, non-public object storage and short-lived signed links. Malware scanning fails closed. Sensitive viewer and private-reference content is encrypted at the application layer where practical. QR analytics retain no raw IP address.
Unverified viewer requests expire after one day; rejected/quarantined files after seven days; orphaned uploads after 30 days; and privacy-safe QR analytics after 90 days. Billing invoices and audit events are append-only and retained as required for legal, tax, fraud and security purposes. Private dossier deletion requests are assessed against lawful retention obligations.
Your choices
You can edit manual profile content, reject Blake suggestions, pause or rotate QR access, remove private files, decline or block conversation requests, and request account data access, correction or deletion by emailing support@theprofile360.in. Login email changes require re-verification, recent authentication and notice to the previous email.