Legal · GDPR
GDPR Compliance
1. Scope
The General Data Protection Regulation (GDPR) applies when we offer services to individuals in the EEA, UK, or Switzerland, or when we monitor their behaviour within those regions.
GoGrabJob is the data controller for personal data processed through your account. Our Privacy Policy describes categories of data we collect and why.
2. Your GDPR rights
Right of access
Request a copy of personal data we hold about you. Use Settings → Export data or email support@gograbjob.com.
Right to rectification
Correct inaccurate profile or resume information directly in your account or via support.
Right to erasure
Delete your account from Settings. We will remove personal data unless retention is legally required.
Right to restrict processing
Ask us to limit how we use your data in certain circumstances (e.g. while a dispute is resolved).
Right to data portability
Receive your data in a structured, machine-readable format (JSON export available in Settings).
Right to object
Object to processing based on legitimate interests or direct marketing. We will assess and respond promptly.
3. Lawful bases
- Performance of a contract — providing the Service you subscribed to.
- Legitimate interests — security, analytics, and product improvement, where not overridden by your rights.
- Consent — non-essential cookies and optional communications.
- Legal obligation — compliance with tax, accounting, or regulatory duties.
4. International transfers
Data may be processed in India and in countries where our subprocessors operate. Where GDPR requires safeguards for transfers outside the EEA/UK, we rely on adequacy decisions, Standard Contractual Clauses (SCCs), or equivalent mechanisms.
5. Data Protection Officer
For GDPR enquiries or to exercise your rights:
Data Protection contact: support@gograbjob.com
Zykes Technologies LLP, Bengaluru, India
8. Automated decision-making
GoGrabJob uses AI to suggest resume edits and scores. These outputs assist your decisions — they do not automatically apply to jobs or reject candidates. You review and approve all content before use.
9. Records and accountability
- We maintain records of processing activities as required by GDPR.
- Data processing agreements are in place with subprocessors.
- We conduct periodic privacy reviews when we launch new features.
10. Data breach notification
If a personal data breach is likely to pose a risk to your rights, we will notify the relevant supervisory authority within 72 hours where required and inform affected users without undue delay when the risk is high.