Overview
GetReady is a career-readiness and recruitment platform. Candidates build resumes, rehearse AI interviews and apply to roles. Recruiters and organizations post those roles, screen applicants and run structured interviews. Both sides depend on personal data, so how we handle it matters.
This policy covers the https://getready.com.np website, the GetReady web application and every dashboard within it (candidate, recruiter, organization and administrator). It applies whichever role your account holds.
The short version
GetReady Technologies operates GetReady and is the controller responsible for the personal data described in this policy.
- Legal entity
- GetReady Technologies
- Registered office
- [Registered office address], Kathmandu, Nepal
- Registration
- [Company registration number]
- Privacy contact
- privacy@getready.dev
Where employers are the controller
We group the data we hold by how it reaches us: what you give us, what your use of the platform generates, and what we receive from others.
Data you provide directly
- Account details. Name, email address, a securely hashed password, your selected role, and an optional profile image. We store password hashes only, never the password itself.
- Candidate profile. Headline, biography, phone number, address, and links to LinkedIn, GitHub or a personal site. Also your structured education history, work experience and skills.
- Resumes and documents. Resume content you build or upload, generated PDFs, and any supporting files. Uploaded PDF and DOCX files are parsed so their text can be analysed.
- Interview responses. Your answers to mock and scheduled interview questions, together with the questions asked and the session metadata.
- Applications. The role you applied to, the resume you attached, cover material and answers to employer questions.
- Recruiter and organization details. Company name, department, designation, team membership, job descriptions, interview templates and question banks.
- Support correspondence. Anything you send us by email or through in-product support.
Data generated by your use of the platform
- AI outputs about you. Resume analyses including ATS scores, skill-match percentages, strengths, weaknesses, missing skills and recommendations; interview feedback reports; and screening results generated for employers.
- Application activity. Status changes, recruiter notes and evaluations, scheduled interviews, offers and your responses to them.
- Plan and credit records. Your current plan, credit balance and a ledger of every credit granted, spent, refunded or adjusted.
- Notifications. In-app notifications and whether they have been read.
- Technical and security logs. Session records, IP address, browser and device information, timestamps and error diagnostics. We use these to keep accounts secure and to debug faults.
Data from third parties
- Google sign-in. If you choose single sign-on, Google sends us your name, email address and profile image. We do not receive your Google password.
- Payment gateways. Stripe, eSewa and Khalti confirm whether a transaction succeeded and return a reference, amount and status.
- Employer-supplied data. A recruiter may upload a resume for screening. If that resume is yours, the data in it reaches us through them.
We never see your card number
Every use below is tied to running the platform. We do not repurpose your data for unrelated ends.
| Purpose | What this involves |
|---|---|
| Providing the service | Creating your account, authenticating you, rendering your dashboard and storing your work. |
| Career tools | Building and formatting resumes, running mock interviews and producing feedback. |
| Applications and hiring | Delivering your application to the employer, tracking its status and coordinating interviews. |
| AI features | Analysing resumes, matching you to roles, generating interview questions and scoring responses. |
| Payments | Processing plan purchases and credit top-ups, issuing receipts and maintaining billing records. |
| Communication | Sending transactional email and in-app notifications about your account, applications and interviews. |
| Safety and integrity | Detecting fraud and abuse, enforcing our Terms, and investigating security incidents. |
| Improving the product | Understanding which features are used and where they fail, using aggregated or de-identified data wherever it will do. |
| Legal compliance | Meeting tax, accounting and other obligations, and responding to lawful requests. |
What we do not do
AI is central to GetReady, so it deserves a section of its own rather than a footnote.
What gets sent to an AI model
- Resume text, when you request an analysis, an AI writing suggestion or a job-match score.
- Job descriptions and requirements, so a role can be compared against a resume.
- Interview questions and your answers, so feedback and scores can be produced.
- Question documents an organization uploads to generate an interview set.
Who processes it
Requests are routed to OpenRouter, with NVIDIA as a fallback when the primary provider is unavailable. Both process the content only to return a response. Prompts are not used to train their models.
Automated decision-making
AI output on GetReady is advisory. Scores, rankings and screening summaries are decision support for a human reviewer. No application is rejected, shortlisted or advanced by a model acting alone, and employers agree to this when they use the platform.
AI can be wrong
Nothing in your candidate profile is broadcast to employers by default. Visibility follows your actions.
| Action you take | What becomes visible |
|---|---|
| You create a profile | Nothing. Your profile and resumes stay private to your account. |
| You apply to a job | The employer that posted it sees your profile, the resume you attached, your answers and the AI screening result for that role. |
| You mark a resume public | Anyone holding the link can view that resume. You can turn this off at any time. |
| A recruiter saves you to a talent pool | That recruiter and their organization retain a record of you, along with their own notes and category. |
| You accept an interview or offer | The employer sees your response, schedule and any interview record produced. |
| You run a mock interview | Nothing. Practice sessions and their feedback are yours alone and are never shown to employers. |
Recruiter notes and internal evaluations belong to the employer that wrote them. They are not shown to you inside the product, and requests to see them should go to that employer.
Where data protection law requires a legal basis, we rely on the following.
- Contract
- Processing needed to give you the service you signed up for , your account, resumes, applications, interviews and paid features.
- Legitimate interests
- Keeping the platform secure, preventing fraud and abuse, and improving how the product works, balanced against your privacy.
- Consent
- Optional additions such as marketing email, making a resume public, or providing sensitive details we did not ask for. You may withdraw consent at any time.
- Legal obligation
- Retaining financial records and responding to valid legal process.
These providers process personal data on our behalf. We keep the list current as our stack changes.
| Provider | Purpose | Data involved | Region |
|---|---|---|---|
| Supabase | Managed PostgreSQL database hosting and storage | All account, profile, application and platform records | Asia Pacific (Sydney) |
| Uploadcare | File upload, storage and CDN delivery | Resume files, profile images, question documents | Global CDN |
| OpenRouter | AI model routing for interviews, resume analysis and screening | Resume text, interview responses, job descriptions | United States |
| NVIDIA | Fallback AI inference when the primary provider is unavailable | Resume text, interview responses, job descriptions | United States |
| Optional single sign-on authentication | Name, email address, profile image | Global | |
| Stripe | Card payment processing and recurring subscriptions | Billing details, transaction records | United States |
| eSewa | Digital wallet payment processing | Transaction references and amounts | Nepal |
| Khalti | Digital wallet payment processing | Transaction references and amounts | Nepal |
Each provider operates under a data processing agreement that limits them to our instructions and requires appropriate security measures.
GetReady is operated from Nepal, and some of our providers are located elsewhere , our database is hosted in Asia Pacific, and our AI and card-payment providers operate from the United States. Using the platform involves transferring your data to those countries.
Where a transfer leaves a jurisdiction with data-export rules, we rely on the safeguards available to us, including standard contractual clauses with the provider and an assessment of the protections they apply.
We keep data for as long as it serves the purpose it was collected for, then delete or anonymise it.
| Data | Retention |
|---|---|
| Account and profile | For the life of your account, then deleted within 30 days of a deletion request. |
| Resumes and uploaded files | Until you delete them, or 30 days after account deletion. |
| Mock interviews and feedback | Until you delete them, or 30 days after account deletion. |
| Job applications and screening results | Retained by the employer for their hiring and compliance needs, typically up to 24 months after the role closes. |
| Talent pool entries | Until the recruiter removes the entry or you ask us to remove it. |
| Payment and credit records | Up to 7 years, as financial and tax rules require. |
| Security and audit logs | Up to 12 months, unless retained longer for an active investigation. |
| Support correspondence | Up to 24 months after the matter is closed. |
Backups roll off on their own schedule, so a deleted record may persist in an encrypted backup for a short period after removal from the live database.
- Passwords are hashed with Argon2, a memory-hard algorithm built for credential storage. We cannot read your password.
- Data is encrypted in transit with TLS, and at rest by our database and storage providers.
- Access to production data is restricted to staff who need it and is authenticated per person.
- Role-based authorization is enforced on the server for every request, so a candidate cannot read recruiter records and one organization cannot read another’s.
- Payment card data never touches our infrastructure.
No system is perfect
Subject to the law that applies to you, you can exercise the following rights over your personal data.
- 1.Access. Get a copy of the data we hold about you.
- 2.Correction. Fix anything inaccurate. Most profile and resume fields are editable directly in your dashboard.
- 3.Deletion. Ask us to erase your account and associated data, subject to records we must keep.
- 4.Portability. Receive your data in a structured, machine-readable format.
- 5.Objection and restriction. Object to processing based on legitimate interests, or ask us to pause processing while a dispute is resolved.
- 6.Withdraw consent. Turn off anything you opted into, including marketing email and public resume links.
- 7.Human review. Ask a person to review any AI output that affected you.
- 8.Complain. Raise a concern with your local data protection authority. We would appreciate the chance to resolve it first.
Email privacy@getready.dev to exercise any of these. We respond within 30 days and will verify your identity before acting, so that nobody else can make a request in your name. Exercising a right never costs you anything and will not degrade your service.
GetReady is built for people in or entering the workforce and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact privacy@getready.dev and we will remove the account and its data.
We update this policy as the product and the law change. The date at the top always reflects the current version. For material changes , a new purpose, a new category of sharing , we will notify you in the product or by email before the change takes effect, and where consent is required we will ask for it.
Continuing to use GetReady after a change takes effect means you accept the updated policy.
Privacy questions, requests and complaints all reach a person who can act on them.
- Privacy requests
- privacy@getready.dev
- Legal notices
- legal@getready.dev
- Security reports
- security@getready.dev
- General support
- support@getready.dev
- Post
- GetReady Technologies, [Registered office address], Kathmandu, Nepal
See also our Terms of Service, which govern your use of the platform.