PRIVACY POLICY
(Ultimate Global Compliance Edition – Fully Compliant with GDPR, KVKK, CPRA, LGPD and International Data Protection Standards)
Effective Date: [●]
Last Updated: [●]
Profylee (“Company”, “Platform”, “we”, “us”) processes, stores, and protects users’ personal data in accordance with the highest international privacy and data protection standards. This Privacy Policy explains in detail how your personal data is collected, processed, transferred, and protected when you use the Platform, create an account, share content, or access any module of Profylee.
This Privacy Policy has been prepared in accordance with GDPR (EU 2016/679), KVKK, CPRA/CCPA, LGPD, OECD Privacy Principles, and ISO/IEC 27701, and represents Profylee’s commitment to transparent data processing.
By using the Platform, registering, signing in, or accessing any feature, you acknowledge that you have read and understood this Privacy Policy.
1. SCOPE AND APPLICATION
This Privacy Policy applies to all digital services provided by Profylee, including:
- AI-powered digital identity creation
- Advanced search engine
- Works (Freelance service & job proposal system)
- Flow & Pool (Recruitment pipeline and candidate database)
- Showcase (Company profile & portfolio pages)
- Publish (Article and content posting)
- Wall (Posts, announcements, public content)
- Insight (Feedback & evaluation module)
- Analytics (Performance and visibility analytics)
- Wallet (Credit, balance & payment operations)
- Message (Messaging module)
- Calendar (Google Calendar API integration)
This policy covers all individual users, employers, and businesses registered on the Platform.
2. DATA CATEGORIES COLLECTED & PROCESSED
Personal data categories collected by Profylee are detailed in the Privacy Notice & Consent document. This Privacy Policy complements that notice.
The primary categories include:
- Identity Data
- Contact Data
- Profile & CV Data
- Content Data (Publish, Showcase, Works, Wall)
- Messaging Data
- Wallet & Payment Data
- Technical & Analytics Data
- AI Processing Data
- Calendar (Google API) Data
• Credit card information is never stored by Profylee.
• AI processing is performed using anonymized data.
3. DATA PROCESSING PRINCIPLES
Profylee strictly adheres to the following principles:
3.1. Lawfulness, fairness, and transparency
3.2. Accuracy and keeping data up to date
3.3. Purpose limitation
3.4. Data minimization (processing only what is necessary)
3.5. Storage limitation
3.6. Strong protection against unauthorized access
3.7. Accountability
3.8. Respect for user rights
4. PURPOSES OF PROCESSING PERSONAL DATA
Profylee processes personal data for the following purposes:
- Creating digital CVs and profiles
- Job matching and recommendation algorithms
- AI-powered analysis and scoring
- Job posting, application, offer and hiring processes
- Freelancer–employer interactions
- Content sharing (Publish, Showcase, Wall)
- Managing candidate pipelines (Flow & Pool)
- Platform security and fraud prevention
- Wallet and payment operations
- Calendar-based meeting scheduling
- Performance and behavioral analytics (Analytics & Insight)
- Customer support
- Compliance with legal obligations
- Improving the quality of the services
5. SHARING PERSONAL DATA WITH THIRD PARTIES
Profylee shares personal data only under the following circumstances:
5.1. Service Providers
- OpenAI (with anonymized data)
- PayTR, Paddle (payment processing)
- Google Calendar API
- Cloud hosting & server infrastructure
- Security service providers
All service providers are bound by Data Processing Agreements (DPA).
5.2. Employers and Recruitment Companies
Your profile may be viewed by global employers with your consent.
Profylee strictly prohibits the sale of candidate data.
5.3. Government Authorities
Only when legally required.
5.4. International Data Transfers
Data may be transferred outside the EU only under:
- SCC (Standard Contractual Clauses)
- Anonymization
- Secure transfer mechanisms
6. DATA SECURITY & SAFEGUARDS
Profylee implements the following measures to ensure data protection:
- ISO/IEC 27001 & 27701–aligned infrastructure
- SSL/TLS encryption
- Two-Factor Authentication (2FA)
- Role-Based Access Control (RBAC)
- Data minimization
- Monitoring and reviewing access logs
- Secure server architecture
- Encrypted data transmission
- Anonymization of data used in AI models
- Full compliance with Google Calendar Restricted Scopes
Profylee employs technical and administrative safeguards against unauthorized access, data loss, or data breaches.
7. CHILDREN'S PERSONAL DATA
Profylee does not accept users under the age of 16.
Personal data of individuals below this age is not knowingly collected.
8. COOKIES AND TRACKING TECHNOLOGIES
Profylee uses essential, analytical, and performance cookies.
Details are provided in the Profylee Cookie Policy.
Users may:
- Reject cookies
- Select categories
- Change their preferences at any time
9. USER RIGHTS (GDPR, KVKK, CPRA, LGPD)
Users have the following rights:
- Learn whether data is processed
- Access their data
- Request correction
- Request deletion / right to be forgotten
- Restrict processing
- Data portability
- Object to profiling
- Withdraw consent
- File complaints with data protection authorities
Requests may be submitted to:
📩 [contact@example.com]
10. DATA RETENTION PERIODS
Data is retained for the following durations:
- CV & profile data → Active account + 1 year
- Wallet transactions → As required by financial regulations
- Log data → 15 days
- Flow / Pool data → 1 year
- Message content → Until account deletion
- Calendar data → Until the user requests deletion
- Content data → Until removed by the user
Data is securely destroyed at the end of retention periods.
11. UPDATES TO THIS POLICY
Profylee may update this Privacy Policy from time to time.
Significant changes will be communicated to users.
12. CONTACT
For any privacy-related inquiries:
📩 [contact@example.com]