Resuvia — Legal

Privacy Policy

Effective Date: June 6, 2026  ·  Last Updated: July 19, 2026

1. Scope

This Privacy Policy applies to the Resuvia — Career Guide+ mobile application ("App") published by XentarAI Inc. ("we," "us," or "our"), a company incorporated in Canada. It does not apply to the xentarai.com website (covered separately at Site Privacy Policy).

This policy covers users in all regions where the App is available, including the United States, Canada, the United Kingdom, the European Union and European Economic Area (including Austria, Belgium, Denmark, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Luxembourg, the Netherlands, Norway, Poland, Portugal, Spain, and Sweden), Switzerland, Argentina, Australia, Brazil, Hong Kong, India, Indonesia, Israel, Japan, Malaysia, New Zealand, the Philippines, Saudi Arabia, Singapore, South Africa, South Korea, Thailand, Türkiye, the United Arab Emirates, Kenya, Bangladesh, Egypt, the Maldives, Mexico, Nigeria, Russia, Sri Lanka, Tanzania, Vietnam, Angola, Antigua and Barbuda, Azerbaijan, Cambodia, Dominica, the Dominican Republic, Fiji, Ghana, Grenada, Jamaica, Jordan, Myanmar, Nepal, Peru, Trinidad and Tobago, and Ukraine. Where applicable law provides additional rights or imposes specific obligations, those are addressed in the jurisdiction-specific sections below.

By installing or using the App you agree to the practices described here. If you do not agree, please do not use the App.

Résidents du Québec : La version française complète de cette politique est disponible en cliquant sur FR ci-dessus.

2. Information We Collect

2.1 Account Information

When you create an account we collect your first name, last name, email address, and a display name. You can sign up and sign in either with a password you choose or with Google Sign-In. We never store your password in readable form — our authentication provider (Supabase Auth) keeps only a salted, hashed version — and we never receive your Google account password. We also use one-time passcodes (OTPs) sent to your email to verify your email address, reset a forgotten password, and confirm account deletion. If you sign in with Google, we receive your name, email address, and Google account identifier from Google to create your account (see Section 5.11). You may also use the App as an anonymous Guest without providing any personal information.

2.2 Résumé File Name

We store the file name of your uploaded résumé on our servers (e.g., "my_resume.pdf") solely to display it back to you. The actual PDF content is never uploaded to our servers. PDF parsing and text extraction happen entirely on your device.

2.3 Résumé and Job Description Content (AI Processing)

When you run an analysis, the text extracted from your résumé and the job description you provide are transmitted to third-party AI providers to generate your ATS score, improvement suggestions, and career guidance. See Section 5 for the specific providers. This content is sent over an encrypted channel and is subject to those providers' data handling terms. We do not use your résumé or job description content to train our own models.

You decide what information to include in the résumé and job description you submit for analysis. We do not select or control their contents, and you are responsible for the data you choose to provide, including any personal or sensitive information it contains and any third-party personal information you include. See Section 10 of our Terms of Use for the related responsibilities and warranties that apply to content you submit.

Multilingual processing and interface. The App can process résumés and job descriptions written in English, French, Spanish, or German, and the AI providers may return your analysis and career guidance in the language of your document. The App's interface is also available in English, French, Spanish, and German: it follows your device language automatically, and you can override this at any time in Settings → Account Preferences → Appearance → Language. Your language preference is stored locally on your device only and is not transmitted to our servers. No additional personal information is collected for multilingual support, and no recipients beyond the AI providers listed in Section 5 are involved. Interface and output translations into languages other than English are provided on a best-effort basis for convenience only and are not legally binding on XentarAI Inc.; see Section 9 of our Terms of Use for the full translation disclaimer. This policy is published in English and French; in the event of any discrepancy, the English version prevails to the extent permitted by applicable law.

2.4 Locally Cached Data

Your résumé file and, for Pro subscribers, up to 20 résumé versions are stored locally on your device in the app's private storage directory, encrypted with AES-256-GCM. This data never leaves your device except as described in Section 2.3 for AI analysis. Cached résumé files are automatically deleted after 60 days.

2.5 Usage and Analytics Data

We use PostHog (product analytics) to understand how features are used. Data collected includes feature interactions, screen views, and anonymised device and platform information. This data is linked to a randomly generated UUID, not your name or email. Analytics collection is consent-gated: users in the EU, EEA, UK, Switzerland, Brazil, and Canada are asked for explicit opt-in consent before any analytics data is collected. All other users may opt out at any time via in-app settings.

2.6 Crash Reports

We use Sentry for crash reporting. If the App crashes, a report including the stack trace, device model, OS version, and App version is sent. No personally identifiable information (name, email, résumé content) is included in crash reports. Crash reporting is consent-gated in the same jurisdictions listed above.

2.7 In-App Purchases

Pro subscriptions are purchased through the Apple App Store (iOS) or Google Play Store (Android). All billing and payment processing is handled entirely by Apple or Google. We do not collect, process, or store credit or debit card numbers or billing addresses. We receive only a non-reversible transaction receipt and a randomly generated account token from the platform to verify your subscription status.

2.8 Advertising Data (Free Tier Only)

The free tier of the App displays advertisements served by Google AdMob, including interstitial ads and optional rewarded video ads (which, when watched, grant bonus usage credits such as an additional AI analysis and résumé download). Google AdMob may collect your device's advertising identifier (IDFA on iOS, GAID on Android) and use it to serve personalised ads. On iOS, this collection requires your explicit consent under Apple's App Tracking Transparency (ATT) framework, and we will prompt for this before any identifier is shared. In the EEA, UK, and Switzerland, we display a Google-certified consent message (via Google's User Messaging Platform) before serving personalised ads; if you decline, only non-personalised ads are shown. This collection constitutes sharing of personal information for cross-context behavioural advertising purposes, which may be treated as a "sale" or "sharing" under the California Consumer Privacy Act (see Section 11) and analogous state laws. Pro subscribers do not see ads and are not subject to this data collection.

Notice for Quebec residents (Law 25, s. 8.1): The App uses profiling technology (Google AdMob, free tier only) that may identify or profile you for advertising purposes. You have the right to be informed of this and to opt out at any time. To opt out: deny ATT consent on iOS, or reset your advertising ID on Android (Settings → Privacy → Ads). Upgrading to Pro also removes all advertising and profiling entirely.

2.9 Biometric Authentication

If you enable biometric login (Face ID / fingerprint), your biometric credentials are handled entirely by your device's operating system (iOS Keychain, Android Keystore). We never have access to your raw biometric data. We store only a boolean flag indicating that biometric authentication is enabled for your account.

2.10 Technical and Device Information

We collect minimal technical information necessary to operate the App, including your device's platform (iOS/Android), App version, session identifiers, and whether your device is a physical device or an emulator/simulator (used only as a signal to detect automated abuse of our free tier). IP addresses used during network requests are processed by our backend infrastructure but are not stored long-term as part of your user record; for fraud and abuse prevention we also process a one-way hash of your IP address in short-lived daily counters as described below.

For fraud and abuse prevention, when you create a permanent account we record that this device has held an account. On Android this uses a device identifier provided by the operating system (the Android ID / SSAID); on iOS it uses a randomly generated app-specific identifier. This identifier is sent to our backend over an encrypted connection and stored only as a one-way salted hash — we cannot recover the original identifier from it, and it is never linked to your name, email, or any other personal information. Its sole purpose is to prevent abuse of our free guest tier (for example, repeatedly creating and deleting accounts to obtain unlimited free analyses). Because this safeguard would be defeated if the record were erased, this hashed value is retained even after you delete your account (see Section 8). It cannot be used to identify you and contains no personal information.

To enforce our free guest-tier usage limits, we also apply a one-way salted hash of the same device identifier, together with a one-way hash of your IP address, to short-lived daily counters — for example, the number of guest sessions or analyses originating from a given device or network on a given day. This processing applies to Guest (anonymous) usage as well, even if you never create an account. Unlike the account-history hash described above, these counters are not tied to any account, contain no personal information, and are automatically deleted within a few days. Their sole purpose is to prevent automated abuse — such as cycling guest accounts or reinstalling the App to obtain unlimited free analyses.

2.11 Job Search Preferences

When you use the Job Matches feature, the App collects and uses the following information to retrieve relevant listings:

  • Job search query — derived from your analysis results (target role and key skill gaps). This is a short text string such as "Software Engineer Python" and does not include your résumé content, name, or email address.
  • Location preference — a city or region you optionally enter (e.g., "New York" or "London"), together with your device's country code inferred from your locale setting. This is stored locally on your device and sent to our backend to filter job search results geographically. You can update or clear your location preference at any time via the Location filter in Job Matches.
  • Approximate device location (optional) — to help pre-fill your job search location, the App may ask your permission to access your device's approximate (coarse) location through your operating system's location services. If you grant permission, your device's location is used only on your device and is immediately converted by the operating system into a city name and country code; the underlying GPS coordinates are never stored or transmitted to our servers. Only the resulting city and country code are used (and may be sent to our backend to filter job listings), exactly as if you had typed them yourself. Granting location access is entirely optional — if you deny it, the App falls back to your résumé-derived location or your device's locale country code. You can grant or revoke this permission at any time in your device settings.
  • Job search usage count — a per-user daily counter linked to your account ID is maintained server-side to enforce daily quota limits. This record contains only your account ID, the date, and the request count — not the content of your searches.

2.12 Referral Program

If you invite a friend using your personal referral code or link, or apply a referral code you received, we record a referral relationship between the two accounts in order to grant the associated bonus credits and prevent abuse. Specifically, we generate a unique referral code for your account and — when a code is applied — store a record linking the referred account to the referring account (the account identifiers of the two parties and the code used). We do not access your contacts or address book; sharing a referral link is performed entirely through your device's own share sheet, and you choose who to send it to. The reward consists solely of free in-app analysis credits with no monetary value. Because this safeguard would be defeated if the record were erased, the referral relationship record is retained even after account deletion (see Section 8); it contains only account identifiers and the referral code, and no other personal information.

3. How We Use Your Information

  • To create and manage your account and authenticate your identity
  • To provide AI-powered résumé analysis, ATS scoring, and career guidance
  • To verify and fulfil your Pro subscription
  • To display your résumé history and analysis results
  • To send transactional emails (OTP codes, account notifications)
  • To diagnose crashes and fix bugs (with consent, where required)
  • To understand feature usage and improve the App (with consent, where required)
  • To serve advertisements on the free tier (iOS: only with ATT consent)
  • To comply with legal obligations and enforce our Terms of Use
  • To retrieve location-relevant job listings via third-party job search providers using your pseudonymised search query and location preference (which may, with your permission, be pre-filled from your device's approximate location)
  • To operate our referral program — generating referral codes, attributing referrals between accounts, granting bonus credits, and preventing referral fraud
  • To detect and prevent fraud, abuse, and security threats

4. Legal Bases for Processing (GDPR / UK GDPR)

For users in the EU, EEA, UK, and Switzerland, we rely on the following legal bases:

  • Contract performance — account creation, authentication (password or Google Sign-In), résumé analysis, subscription management
  • Consent — analytics (PostHog), crash reporting (Sentry), and personalised advertising (AdMob / ATT). You may withdraw consent at any time in Settings → Account Preferences → Privacy & Consent.
  • Legitimate interests — fraud prevention, abuse detection, improving service reliability. We have assessed that these interests are not overridden by your fundamental rights and freedoms.
  • Legal obligation — disclosures or processing required by applicable law

We have not appointed a Data Protection Officer (DPO) as we do not meet the thresholds requiring mandatory appointment under Article 37 GDPR. Privacy questions may be directed to contactus@xentarai.com.

5. Third-Party Services and Data Sharing

We do not sell your personal information to data brokers or advertising networks (other than as described in Section 2.8 regarding AdMob). We share data only with the following categories of recipients:

5.1 Backend Infrastructure

Supabase (Supabase Inc., USA) hosts our database and backend APIs. Your account information, résumé file name, analysis results, and subscription status are stored on Supabase infrastructure in the US-East region. Transfers from the EEA are governed by Standard Contractual Clauses (EU SCCs, 2021). Transfers from the UK are governed by the UK International Data Transfer Addendum (UK IDTA) to those SCCs. Transfers from Australia, New Zealand, and South Africa are subject to the cross-border transfer safeguards described in Sections 15–17.

5.2 AI Providers

Résumé text and job description text are transmitted to one or more of the following AI services depending on your subscription tier and region:

  • Anthropic (USA — Pro tier fallback) — Claude Haiku model
  • Google (USA — Free and Pro tiers) — Gemini Flash models
  • Mistral AI (France — Free and Pro tiers) — Mistral Small model

These providers process your résumé and job description content solely to generate the analysis returned to you. They do not use this content to train their models (subject to each provider's current data processing terms). API calls are routed through our own backend; AI API keys are never exposed client-side.

5.3 Job Description Scraping

When you provide a job posting URL, the App may transmit that URL to one or more of the following third-party services to retrieve the job description text: Jina AI Reader, Wayback Machine / archive.today (Internet Archive), ScrapingAnt, Apify, or Firecrawl. Only the URL is shared; your personal information and résumé content are not transmitted to these services. You can paste the job description text directly to avoid URL scraping entirely.

5.4 Email Delivery

Resend (USA), Brevo (France), and ZeptoMail (Zoho Corporation, India) deliver OTP authentication codes and account-related emails to your email address. These providers are used on a rotating basis; only your email address and the message content are shared with them.

5.5 Analytics

PostHog (PostHog Inc., USA) — product analytics, consent-gated as described in Section 2.5.

5.6 Crash Reporting

Sentry (Functional Software, Inc., USA) — crash diagnostics, consent-gated as described in Section 2.6.

5.7 Advertising

Google AdMob (Google LLC, USA) — interstitial ads on the free tier only. See Section 2.8.

5.8 App Stores

Apple App Store and Google Play Store handle all in-app purchases. Your payment data is governed by Apple's and Google's respective privacy policies.

5.9 Legal Requirements and Business Transfers

We may disclose personal information if required by law, court order, or governmental authority. In the event of a merger, acquisition, or asset sale, your information may be transferred to the successor entity subject to the same protections described here, and we will provide notice before any such transfer.

5.10 Job Search Providers

The Job Matches feature is powered by multiple job search providers. When you view Job Matches, a pseudonymised search query (job role and key skills derived from your analysis results) and your location preference (country code and optional city or region text) are shared with the following providers:

  • Adzuna (Adzuna Ltd, United Kingdom) — primary job search provider, queried via our backend; delivers location-aware, active job listings
  • Jooble (global operations) — fallback job search provider, queried via our backend; supplements results when Adzuna listings are insufficient
  • The Muse (USA) — queried directly from your device
  • Arbeitnow (Germany) — queried directly from your device
  • Remotive (global operations) — queried directly from your device; remote-job listings

Providers queried directly from your device also receive your device's IP address as an inherent part of the network request. None of these providers receive your résumé content, name, email address, or other account information. API keys for the backend-routed providers (Adzuna, Jooble) are stored in our backend vault and are never embedded in the App binary.

5.11 Authentication Provider

Google (Google LLC, USA) — if you choose Google Sign-In, Google authenticates you and provides us with your name, email address, and Google account identifier to create or access your account. Google's handling of your data in connection with sign-in is governed by Google's own privacy policy. You can use email-and-password sign-in instead if you prefer not to use Google Sign-In. Our authentication and database provider, Supabase (Section 5.1), stores your account credentials only as a salted hash.

6. Data Security

We implement the following technical and organisational measures:

  • All data in transit is encrypted using TLS 1.2 or higher
  • Locally cached résumé files are encrypted at rest using AES-256-GCM with a per-user 256-bit key stored in the device's secure element (iOS Keychain / Android Keystore) with first-unlock-only access
  • Account passwords are never stored in readable form — only a salted hash is held by our authentication provider; one-time passcodes (OTP) are required for email verification, password reset, and account deletion
  • API keys for AI services are stored in our backend vault and are never embedded in the App binary
  • Row-Level Security restricts all database access to the authenticated user's own data
  • Account deletion requires OTP verification and is rate-limited
  • Sign-in attempts are rate-limited with progressive delays after repeated failures

No method of electronic transmission or storage is 100% secure. While we use commercially reasonable measures, we cannot guarantee absolute security.

7. Data Breach Notification

In the event of a personal data breach we will:

  • EU/EEA (GDPR) — notify the relevant supervisory authority within 72 hours of becoming aware of the breach if it is likely to result in a risk to your rights and freedoms, and notify affected individuals without undue delay if the breach is likely to result in a high risk.
  • UK (UK GDPR) — notify the ICO within 72 hours and notify affected individuals where required.
  • Canada — PIPEDA — notify the Office of the Privacy Commissioner and affected individuals as soon as feasible when a breach creates a real risk of significant harm.
  • Canada — Quebec Law 25 — notify the Commission d'accès à l'information (CAI) and affected individuals within 72 hours of becoming aware of a confidentiality incident presenting a risk of serious injury. We maintain a confidentiality incident register as required by Law 25.
  • Australia (NDB Scheme) — notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable where a breach is likely to result in serious harm.
  • New Zealand — notify the New Zealand Privacy Commissioner and affected individuals as soon as reasonably practicable where a breach is likely to cause serious harm.
  • South Africa (POPIA) — notify the Information Regulator and affected data subjects as soon as reasonably possible after becoming aware of a compromise.
  • Singapore (PDPA) — where a breach is assessed as notifiable (likely to result in significant harm to affected individuals, or affecting 500 or more individuals), notify the Personal Data Protection Commission (PDPC) within 3 business days and notify affected individuals as soon as practicable.
  • UAE (UAE PDPL) — notify the UAE Data Office without undue delay where required by Federal Decree-Law No. 45 of 2021, and notify affected individuals where required.
  • Japan (APPI) — where a breach meets the APPI's mandatory notification criteria (including breaches involving sensitive data, or affecting 1,000 or more individuals), report to the Personal Information Protection Commission (PPC) and notify affected individuals within 30 days (within 60 days for breaches involving improper third-party disclosure).
  • Argentina (Law 25.326) — notify the Agencia de Acceso a la Información Pública (AAIP) and, where appropriate, affected individuals without undue delay, in line with AAIP guidance on security incidents.
  • Brazil (LGPD) — notify the Autoridade Nacional de Proteção de Dados (ANPD) and affected individuals within a reasonable time period where a breach may create a risk or relevant harm to data subjects.
  • Indonesia (PDP Law) — notify affected data subjects and the supervisory authority within 3 × 24 hours (72 hours) of becoming aware of a personal data protection failure, as required by Law No. 27 of 2022.
  • India (DPDP Act 2023) — on becoming aware of a personal data breach, intimate each affected Data Principal and the Data Protection Board of India, in the manner and within the timelines prescribed by the DPDP Rules.
  • Malaysia (PDPA) — notify the Personal Data Protection Commissioner as soon as practicable (and within 72 hours where the breach causes or is likely to cause significant harm), and notify affected individuals without unreasonable delay, as required by the Personal Data Protection (Amendment) Act 2024.
  • Philippines (Data Privacy Act 2012) — notify the National Privacy Commission (NPC) and affected individuals within 72 hours of knowledge of a breach involving sensitive personal information that is likely to give rise to a real risk of serious harm.
  • Kenya (Data Protection Act, 2019) — notify the Office of the Data Protection Commissioner (ODPC) within 72 hours of becoming aware of a breach, and notify affected data subjects without unreasonable delay where the breach is likely to result in a risk of significant harm, as required by the Data Protection (General) Regulations 2021.
  • Saudi Arabia (PDPL) — notify the Saudi Data & AI Authority (SDAIA) within 72 hours of becoming aware of a breach, and notify affected individuals without undue delay where the breach may cause harm to their data or rights.
  • South Korea (PIPA) — notify affected individuals without delay and report to the Personal Information Protection Commission (PIPC) within 72 hours where the breach affects 1,000 or more individuals or involves sensitive or unique identifying information.
  • Thailand (PDPA) — notify the Personal Data Protection Committee (PDPC) within 72 hours of becoming aware of a breach, and notify affected data subjects where the breach is likely to result in a high risk to their rights and freedoms.
  • Israel (Protection of Privacy Law) — notify the Privacy Protection Authority (PPA) of a severe data security incident, and notify affected individuals where required, as provided under the Protection of Privacy Law as amended by Amendment 13.
  • Türkiye (KVKK) — notify the Personal Data Protection Authority (KVKK Board) at the earliest opportunity (board guidance indicates within 72 hours) and notify affected data subjects, in accordance with Law No. 6698.
  • Hong Kong (PDPO) — notify the Office of the Privacy Commissioner for Personal Data (PCPD) and affected individuals as soon as practicable, in line with PCPD data breach handling guidance.
  • Nigeria (NDPA 2023) — notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of a breach likely to result in a risk to the rights and freedoms of individuals, and notify affected data subjects without undue delay.
  • Sri Lanka (PDPA 2022) — notify the Data Protection Authority of Sri Lanka and, where the breach is likely to cause harm, affected data subjects without undue delay.
  • Egypt (Law No. 151 of 2020) — notify the Personal Data Protection Center within 72 hours of becoming aware of a breach, and notify affected individuals within 3 days where the breach may cause harm.
  • Vietnam (Decree No. 13/2023/ND-CP) — notify the Ministry of Public Security (A05) within 72 hours of becoming aware of a personal data protection violation, in the prescribed form.
  • Tanzania (PDPA 2022) — notify the Personal Data Protection Commission and affected data subjects without undue delay after becoming aware of a breach.
  • Mexico (LFPDPPP) — notify affected data owners without delay of security breaches that materially affect their property or moral rights, so they can take steps to protect their interests.
  • Russia (Federal Law No. 152-FZ) — notify Roskomnadzor of a breach within 24 hours (initial notice) and of the results of the internal investigation within 72 hours, as required by law.
  • Ghana (Data Protection Act, 2012) — notify the Data Protection Commission and the affected data subject where personal data has been accessed or acquired by an unauthorised person.
  • Jamaica (Data Protection Act, 2020) — notify the Office of the Information Commissioner and affected individuals without undue delay after becoming aware of a breach.
  • Jordan (Law No. 24 of 2023) — notify the competent authority and affected individuals of a personal data breach likely to cause harm, within the prescribed timeline.
  • Bermuda (PIPA 2016) — notify the Privacy Commissioner and affected individuals without undue delay of a breach likely to adversely affect them.
  • Peru (Law No. 29733) — notify the ANPD within 48 hours of becoming aware of a security incident and affected individuals where required, in line with the data protection regulations.

Breach notifications will describe the nature of the breach, the data affected, likely consequences, and the steps we are taking to address it.

8. Data Retention

  • Account data — retained for the lifetime of your account, then deleted upon account deletion
  • Analysis results — retained in your account; signed-in users retain up to 20 résumé versions in History Vault
  • Locally cached résumé files — automatically deleted after 60 days, or immediately upon account deletion
  • Analytics data (PostHog) — retained per PostHog's default retention period; you may request erasure via in-app consent settings
  • Crash reports (Sentry) — retained per Sentry's default retention period
  • Deleted account data — account records are deleted from our servers upon confirmed account deletion; encrypted backups may retain data for up to 30 additional days
  • Anonymised billing records — a minimal, fully anonymised billing record (containing no personal information) may be retained for up to 7 years after account deletion as required by applicable tax and financial regulations. This record cannot be used to identify you.
  • Fraud-prevention device hash — the one-way salted hash of a device identifier described in Section 2.10 is retained indefinitely after account deletion, solely to prevent abuse of our free guest tier. It contains no personal information and cannot be used to identify you.

You may request deletion of your account at any time from within the App (Settings → Profile → Delete Account), or via our web-based account deletion page at xentarai.com/products/resuvia/delete-account.html. Both options are available without needing to contact us. In-app deletion is immediate and irreversible; web-based deletion is processed within 30 days. Both methods require identity verification.

9. Children's Privacy

The App is a career tool intended for adult job seekers. Minimum age requirements by jurisdiction:

  • South Africa / United Arab Emirates / Saudi Arabia / Indonesia / India / Nigeria — minimum age 18 years (POPIA, UAE PDPL, the Saudi PDPL, Indonesia's PDP Law, India's DPDP Act, and Nigeria's NDPA require guardian consent for minors under 18)
  • EU / EEA / UK / Switzerland — minimum age 16 years (GDPR / UK GDPR digital services threshold)
  • South Korea — minimum age 14 years (PIPA requires legal guardian consent for children under 14)
  • All other jurisdictions — minimum age 13 years (including Argentina, Brazil, Kenya, Malaysia, the Philippines, Singapore, Thailand, Japan, Bangladesh, Egypt, the Maldives, Mexico, Russia, Sri Lanka, Tanzania, Vietnam, Angola, Antigua and Barbuda, Azerbaijan, Cambodia, Dominica, the Dominican Republic, Fiji, Ghana, Grenada, Jamaica, Jordan, Myanmar, Nepal, Peru, Trinidad and Tobago, and Ukraine; where local law requires guardian consent for minors — for example under 16 in Vietnam — such users must use the App only with parental consent and supervision)

Where local law sets a higher age of majority or requires guardian consent for minors (for example, in Thailand), users below the applicable age must use the App only with the consent and supervision of a parent or legal guardian. We do not knowingly collect personal information from anyone below the applicable minimum age. If you believe a minor has created an account, contact us at contactus@xentarai.com and we will promptly delete it.

10. Your Rights — EU / EEA / UK / Switzerland (GDPR & UK GDPR)

If you are in the European Union, European Economic Area, United Kingdom, or Switzerland, you have the following rights:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate or incomplete data
  • Erasure — request deletion of your personal data (subject to legal retention requirements)
  • Restriction — request that we limit how we process your data
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests or for direct marketing
  • Withdraw consent — withdraw any consent at any time via Settings → Account Preferences → Privacy & Consent, without affecting the lawfulness of prior processing
  • Automated decision-making — the right not to be subject to solely automated decisions producing significant legal effects. Our ATS scoring uses AI but is not used to make legally binding decisions about you.
  • AI transparency (EU AI Act) — Resuvia uses artificial intelligence to generate your ATS score, résumé suggestions, and career guidance, and we disclose this to you here and in the App. Resuvia is a consumer self-assessment tool used by you, the job seeker; it is not used by an employer or recruiter to screen, filter, or make hiring decisions about candidates, and therefore does not operate as a high-risk employment AI system under Annex III of Regulation (EU) 2024/1689 (the EU AI Act). Its outputs are informational and advisory only, and you remain free to disregard them. Where the AI Act's transparency obligations apply, we will continue to inform you that you are interacting with, and receiving content generated by, an AI system.

To exercise any of these rights, contact us at contactus@xentarai.com. We will respond within 30 days (one calendar month), extendable by a further two months for complex requests. You also have the right to lodge a complaint with your local supervisory authority: your national Data Protection Authority in the EU/EEA, the ICO in the UK, or the FDPIC in Switzerland.

11. Your Rights — California Residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides the following rights:

  • Right to Know — request disclosure of the categories and specific pieces of personal information collected, the sources, the business purpose, and the categories of third parties with whom we share it
  • Right to Delete — request deletion of personal information we have collected, subject to certain exceptions
  • Right to Correct — request correction of inaccurate personal information
  • Right to Opt-Out of Sale / Sharing — the sharing of your device advertising identifier (IDFA/GAID) with Google AdMob for personalised advertising may constitute a "sale" or "sharing" under CCPA. To opt out: on iOS, deny or revoke ATT consent in iOS Settings → Privacy & Security → Tracking. On Android, opt out of your advertising ID in Android Settings → Privacy → Ads. Pro subscribers are not subject to AdMob data collection.
  • Right to Limit Use of Sensitive Personal Information — we do not use sensitive personal information for purposes beyond what is necessary to provide the App
  • Right to Non-Discrimination — we will not discriminate against you for exercising your CCPA rights

To submit a verifiable consumer request, contact us at contactus@xentarai.com. We will respond within 45 days. You may designate an authorised agent to make requests on your behalf.

CalOPPA disclosure: We will notify you of material changes to this Privacy Policy by updating the "Last Updated" date above. A link to this policy is available from within the App and on the Resuvia product page.

12. Your Rights — Other US State Privacy Laws

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), Oregon (OCPA), and other US states with comprehensive privacy laws have rights that broadly parallel the CCPA rights in Section 11, including the right to access, correct, delete, and obtain a copy of your personal data, as well as the right to opt out of targeted advertising. To exercise these rights, contact us at contactus@xentarai.com. We will respond within the time period required by your state's applicable law (typically 45 days). We do not make decisions that have significant legal or similarly significant effects on consumers solely through automated means without appropriate safeguards.

13. Your Rights — Brazil (LGPD)

If you are in Brazil, the Lei Geral de Proteção de Dados (LGPD) provides rights including access, correction, deletion, portability, information about sharing, and the right to withdraw consent. Analytics and crash reporting require your explicit consent in Brazil. To exercise your rights, contact us at contactus@xentarai.com. You may also lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).

14. Your Rights — Canada (PIPEDA & Quebec Law 25)

XentarAI Inc. is a Canadian company subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and, for residents of Quebec, the Act respecting the protection of personal information in the private sector (Law 25 / Bill 64).

  • Consent — we collect personal information only with your knowledge and consent, or as permitted by law. You may withdraw consent at any time, subject to legal or contractual restrictions, by contacting us.
  • Limiting collection — we collect only what is necessary for the purposes identified here.
  • Access and correction — you have the right to access your personal information and request correction of inaccuracies.
  • Right to de-indexing (Quebec) — Quebec residents may request that we cease disseminating personal information or de-index any hyperlinks attached to their name, where technically feasible.
  • Automated profiling (Quebec) — our ATS scoring uses AI-based automated processing. You have the right to be informed of this and to request human review of results.
  • Technology-based profiling (Quebec — Law 25, s. 8.1) — the App uses Google AdMob (free tier only) which may profile your advertising interests. We disclose this as required by Law 25. You may opt out at any time as described in Section 2.8.
  • Confidentiality incidents (Quebec — Law 25) — we maintain a register of all confidentiality incidents as required by Law 25. In the event of an incident presenting a risk of serious injury, we will notify the CAI and affected individuals within 72 hours.
  • Breach notification (PIPEDA) — we will report breaches creating real risk of significant harm to the Office of the Privacy Commissioner and notify affected individuals as required by PIPEDA.
  • Privacy Officer — XentarAI Inc. has designated Bidisha Das, Founder & Director as Privacy Officer responsible for compliance with PIPEDA and Quebec Law 25. Contact: contactus@xentarai.com (subject: "Privacy Officer — Privacy Request").

If unsatisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (OPC) or, for Quebec residents, the Commission d'accès à l'information du Québec (CAI).

15. Your Rights — Australia (Privacy Act 1988 / Australian Privacy Principles)

We handle personal information of Australian residents in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

  • Access (APP 12) — you may request access to the personal information we hold about you by contacting us. We will respond within a reasonable period (generally 30 days). We may charge a reasonable fee for access requests in limited circumstances.
  • Correction (APP 13) — if information we hold is inaccurate, out of date, incomplete, or misleading, you may request correction. We will correct or associate a statement of disagreement with the record.
  • Anonymity (APP 2) — where lawful and practicable, you may use the App anonymously (Guest mode).
  • Cross-border disclosure (APP 8) — we disclose personal information to overseas recipients (Supabase, Anthropic, Google, Mistral AI, PostHog, Sentry, Resend, Brevo, Adzuna, Jooble, and others listed in Section 5), located in the United States, United Kingdom, France, and other countries where our service providers operate. Before doing so, we take reasonable steps to ensure these recipients do not breach the APPs in relation to your information, including by relying on contractual data processing agreements with those providers. By using the App, you acknowledge that we may not be accountable under the Privacy Act if an overseas recipient handles your information in breach of the APPs, and that you may not be able to seek redress from the OAIC in respect of that overseas handling.
  • Direct marketing (APP 7) — we do not use your personal information for direct marketing beyond transactional communications (OTP, account notices). You may opt out of any non-essential communications at any time.
  • Notifiable Data Breaches (NDB Scheme) — see Section 7 for our breach notification obligations.

To exercise your rights or make a privacy complaint, contact us at contactus@xentarai.com. We will respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

16. Your Rights — New Zealand (Privacy Act 2020)

We handle personal information of New Zealand residents in accordance with the Privacy Act 2020 and the Information Privacy Principles (IPPs).

  • Access (IPP 6) — you have the right to request access to personal information we hold about you. We will provide access within a reasonable period.
  • Correction (IPP 7) — you have the right to request correction of inaccurate personal information.
  • Transborder data flows (IPP 12) — we transfer personal information to overseas recipients in the United States, United Kingdom, France, and other countries (listed in Section 5). We take reasonable steps to ensure those recipients are subject to privacy obligations comparable to the IPPs, including through contractual data processing agreements. New Zealand does not currently maintain a list of "adequate" countries, so transfers rely on these contractual safeguards.
  • Notifiable privacy breaches — see Section 7. Where a breach is likely to cause serious harm to New Zealand individuals, we will notify both the New Zealand Privacy Commissioner and the affected individuals as soon as reasonably practicable.

To exercise your rights or raise a privacy concern, contact us at contactus@xentarai.com. If you are not satisfied with our response, you may contact the New Zealand Privacy Commissioner at privacy.org.nz.

17. Your Rights — South Africa (POPIA)

We process personal information of South African data subjects in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).

Minimum age: In South Africa, the App is available only to users aged 18 years and older. POPIA defines a "child" as a person under the age of 18. We do not knowingly collect personal information from persons under 18 in South Africa.

Your rights under POPIA include:

  • Right to be notified — you have the right to be notified when your personal information is being collected (this policy serves that purpose).
  • Right of access — you may request a description of the personal information we hold about you and be told for what purpose it is held.
  • Right to correction or deletion — you may request that we correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained.
  • Right to object — you may object to the processing of your personal information on reasonable grounds. We will cease processing unless legitimate grounds override your objection or it is necessary for a legal claim.
  • Right not to be subject to automated decision-making — you have the right not to be subject to a decision based solely on automated processing if it significantly affects you. Our ATS scoring is advisory and does not make legally binding decisions about you.
  • Cross-border transfer (Section 72 POPIA) — we transfer personal information to recipients in the United States, United Kingdom, France, and other countries (Section 5). We do so on the basis that we have put in place contractual data processing agreements requiring those recipients to apply standards of protection substantially similar to the conditions for the lawful processing of personal information under POPIA.
  • Breach notification — see Section 7. We will notify the Information Regulator and affected data subjects as soon as reasonably possible upon becoming aware of a compromise of personal information.
  • Information Officer — XentarAI Inc. has designated Bidisha Das, Founder & Director as Information Officer as required by POPIA. Contact: contactus@xentarai.com.

To exercise your rights or lodge a complaint, contact us at contactus@xentarai.com. If you are not satisfied with our response, you may lodge a complaint with the Information Regulator (South Africa) at justice.gov.za/inforeg/.

18. Your Rights — Singapore (Personal Data Protection Act 2012)

We collect, use, and disclose personal data of Singapore residents in accordance with the Personal Data Protection Act 2012 (PDPA), as amended by the Personal Data Protection (Amendment) Act 2020.

  • Purpose notification — we will inform you of the purposes for which we collect, use, or disclose your personal data (this policy serves that purpose).
  • Access (s. 21) — you may request access to your personal data held by us and information about how it has been used or disclosed in the preceding year.
  • Correction (s. 22) — you may request correction of your personal data that is inaccurate or incomplete.
  • Withdrawal of consent — you may withdraw consent for collection, use, or disclosure of your personal data at any time with reasonable notice via Settings → Account Preferences → Privacy & Consent. Withdrawal may affect our ability to provide certain services.
  • Data portability — where the PDPA portability obligation applies, you may request that your personal data be transmitted to another organisation in a structured, machine-readable format.
  • Cross-border transfers (s. 26) — we transfer your personal data to recipients in the United States, United Kingdom, France, and other countries (Section 5). We ensure such transfers comply with the PDPA transfer limitation obligation by putting in place contractual data protection clauses or other appropriate safeguards requiring comparable protection.
  • Data breach notification — where a breach is assessed as notifiable (likely to result in significant harm to affected individuals, or affecting 500 or more individuals), we will notify the Personal Data Protection Commission (PDPC) within 3 business days and notify affected individuals as soon as practicable.

To exercise your rights or raise a concern, contact us at contactus@xentarai.com. If you are not satisfied with our response, you may contact the Personal Data Protection Commission (PDPC) at pdpc.gov.sg.

19. Your Rights — United Arab Emirates (Federal Decree-Law No. 45 of 2021)

We process personal data of residents of the United Arab Emirates in accordance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL).

Minimum age: In the UAE, the App is available only to users aged 18 years and older. Processing of personal data of minors requires guardian consent under the UAE PDPL. We do not knowingly collect personal data from individuals under 18 in the UAE.

Your rights under the UAE PDPL include:

  • Right to be informed — you have the right to be informed about the collection and processing of your personal data (this policy serves that purpose).
  • Right of access — you may request access to the personal data we hold about you.
  • Right to rectification — you may request correction of inaccurate or incomplete personal data.
  • Right to erasure — you may request deletion of your personal data where it is no longer necessary for the stated purposes, or where you withdraw consent and no other legal basis applies.
  • Right to portability — you have the right to receive your personal data in a structured, commonly used format and to have it transmitted to another data controller where technically feasible.
  • Right to object — you may object to the processing of your personal data on legitimate grounds.
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time via Settings → Account Preferences → Privacy & Consent. Withdrawal does not affect the lawfulness of prior processing.
  • Cross-border transfers — we transfer personal data to recipients in the United States, United Kingdom, France, and other countries (Section 5). We take reasonable steps to ensure adequate protection through contractual safeguards meeting the requirements of the UAE PDPL.
  • Data breach notification — in the event of a notifiable breach, we will notify the UAE Data Office without undue delay as required by the UAE PDPL, and notify affected individuals where required.

To exercise your rights or raise a concern, contact us at contactus@xentarai.com. If you are not satisfied with our response, you may contact the UAE Data Office at uaedataoffice.gov.ae.

20. Your Rights — Japan (Act on the Protection of Personal Information)

We handle personal information of residents of Japan in accordance with the Act on the Protection of Personal Information (個人情報の保護に関する法律, APPI), as amended in 2022.

  • Notification of purpose of use — we identify and notify you of the purposes for which your personal information is used (this policy serves that purpose). We will not use your personal information beyond the stated purposes without your consent.
  • Disclosure (Art. 33) — you may request disclosure of your retained personal data held by us, including the purposes of use and the categories of third parties to whom it has been provided.
  • Correction, addition, or deletion (Art. 34) — where your retained personal data is factually inaccurate, you may request correction, addition, or deletion within the scope necessary to achieve the stated purposes.
  • Cessation of use or erasure (Art. 35) — you may request that we cease using or erase your retained personal data if it was obtained unlawfully or is no longer required for the stated purposes.
  • Cessation of third-party provision (Art. 37) — you may request that we cease providing your personal data to third parties where processing is based on consent and consent is withdrawn.
  • Third-party provision — we do not provide your personal data to third parties without your consent, except as necessary to provide the App's core services (outsourcing to sub-processors under supervision), or as otherwise permitted by the APPI.
  • Cross-border transfers — we transfer personal data to recipients in the United States, United Kingdom, France, and other countries (Section 5). Such transfers are made on the basis that we have confirmed those recipients have established appropriate personal information protection systems equivalent to Japan's APPI requirements, including through contractual data processing agreements.
  • Data breach notification — where a breach meets the APPI's mandatory notification criteria (including breaches involving sensitive data, or affecting 1,000 or more individuals), we will report to the Personal Information Protection Commission (PPC) and notify affected individuals within 30 days (or within 60 days for breaches involving improper third-party disclosure).

To exercise your rights, contact us at contactus@xentarai.com. We will respond within a reasonable period. If you are not satisfied with our response, you may contact the Personal Information Protection Commission (PPC) at ppc.go.jp.

21. Your Rights — Argentina (Personal Data Protection Act, Law 25.326)

If you are in Argentina, we process your personal data in accordance with the Ley de Protección de los Datos Personales (Law No. 25.326) and the constitutional habeas data right. The supervisory authority is the Agencia de Acceso a la Información Pública (AAIP).

  • Access — you may request information about the personal data we hold about you, free of charge at intervals of not less than six months (unless a legitimate interest justifies a shorter interval).
  • Rectification, update, and suppression — you may request correction, updating, or deletion of personal data that is inaccurate, outdated, or processed in breach of the law.
  • Confidentiality and objection — you may object to processing on legitimate grounds and request that we keep your data confidential.
  • Cross-border transfers — Argentina restricts transfers to countries without adequate protection; we rely on your consent and on contractual safeguards requiring comparable protection for the recipients listed in Section 5.

To exercise your rights, contact us at contactus@xentarai.com. If you are not satisfied with our response, you may file a claim with the AAIP at argentina.gob.ar/aaip.

22. Your Rights — India (DPDP Act 2023)

If you are in India, we process your personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and its rules, as brought into force. The supervisory authority is the Data Protection Board of India. The App is available only to users aged 18 years and older; processing a child's personal data requires verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.

  • Right to access — to obtain a summary of the personal data we process and the processing activities, and the identities of other entities with whom it has been shared.
  • Right to correction and erasure — to request correction, completion, updating, and erasure of your personal data.
  • Right to grievance redressal — to a readily available means of grievance redressal; contact us first at the address below.
  • Right to nominate — to nominate another individual to exercise your rights in the event of death or incapacity.
  • Right to withdraw consent — where processing relies on consent, you may withdraw it at any time as easily as it was given.
  • Cross-border transfers — we may transfer your personal data outside India (Section 5) except to any territory restricted by the Central Government, with contractual safeguards applied to recipients.

To exercise your rights or raise a grievance, contact us at contactus@xentarai.com. If unresolved, you may approach the Data Protection Board of India.

23. Your Rights — Saudi Arabia (PDPL)

If you are in the Kingdom of Saudi Arabia, we process your personal data in accordance with the Personal Data Protection Law (PDPL, Royal Decree M/19) and its Implementing Regulations, enforced by the Saudi Data & AI Authority (SDAIA).

Minimum age: In Saudi Arabia, the App is available only to users aged 18 years and older. Processing of a minor's personal data requires guardian consent under the PDPL.

  • Right to be informed — of the legal basis and purpose of collecting your personal data (this policy serves that purpose).
  • Right of access and to obtain a copy — you may access and request a copy of your personal data.
  • Right to correction — you may request correction of inaccurate, incomplete, or outdated data.
  • Right to destruction — you may request deletion of your personal data when it is no longer needed.
  • Right to withdraw consent — where processing relies on consent, you may withdraw it at any time.
  • Cross-border transfers — transfers outside the Kingdom (Section 5) are made in accordance with the PDPL's transfer conditions and appropriate safeguards.

To exercise your rights, contact us at contactus@xentarai.com. If you are not satisfied, you may contact SDAIA at sdaia.gov.sa.

24. Your Rights — South Korea (PIPA)

If you are in the Republic of Korea, we process your personal information in accordance with the Personal Information Protection Act (PIPA), as amended. The supervisory authority is the Personal Information Protection Commission (PIPC).

Minimum age: processing of the personal information of children under 14 years requires the consent of a legal guardian; we do not knowingly collect such information without that consent.

  • Right to be informed and to consent — you are informed of, and consent to, the collection and use of your personal information, and may withdraw consent at any time.
  • Access — you may request access to your personal information and records of its provision to third parties.
  • Correction and deletion — you may request correction or deletion of your personal information.
  • Suspension of processing — you may request that we suspend the processing of your personal information.
  • Rights regarding automated decisions — you may refuse or request an explanation of decisions made solely by automated systems that significantly affect your rights; our ATS scoring is advisory and not used for legally binding decisions.
  • Cross-border transfers — we transfer personal information overseas (Section 5) with your consent or under contractual and other safeguards required by PIPA.

To exercise your rights, contact us at contactus@xentarai.com. If you are not satisfied, you may contact the PIPC at pipc.go.kr or the KrCERT/PrivacyComplaint Center (privacy.go.kr).

25. Your Rights — Indonesia (PDP Law)

If you are in Indonesia, we process your personal data in accordance with Law No. 27 of 2022 on Personal Data Protection (PDP Law). The App is available only to users aged 18 years and older; processing a child's personal data requires verifiable parental or guardian consent.

  • Right to information and access — to be informed about, and to obtain, your personal data and clarity on its processing.
  • Right to rectification — to update or correct your personal data.
  • Right to erasure — to request deletion and/or destruction of your personal data.
  • Right to withdraw consent — to withdraw consent to processing at any time.
  • Right to object to automated processing — to object to decisions based solely on automated processing that produce legal effects or significantly affect you.
  • Right to portability — to obtain and transmit your personal data in an interoperable format.
  • Cross-border transfers — transfers outside Indonesia (Section 5) are made on the basis of adequate protection or contractual safeguards consistent with the PDP Law.

To exercise your rights, contact us at contactus@xentarai.com. You may also contact the supervisory authority responsible for personal data protection in Indonesia.

26. Your Rights — Malaysia (PDPA 2010)

If you are in Malaysia, we process your personal data in accordance with the Personal Data Protection Act 2010 (PDPA), as amended by the Personal Data Protection (Amendment) Act 2024. The supervisory authority is the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi).

  • Right of access — you may request access to your personal data held by us.
  • Right to correction — you may request correction of inaccurate, incomplete, or out-of-date personal data.
  • Right to withdraw consent — you may withdraw consent to the processing of your personal data.
  • Right to prevent processing for direct marketing — we do not use your personal data for direct marketing beyond transactional communications.
  • Data portability — where the PDPA's portability provisions apply, you may request transmission of your data to another data controller.
  • Cross-border transfers — transfers outside Malaysia (Section 5) are made where the recipient provides protection comparable to the PDPA, consistent with the amended cross-border transfer requirements.

To exercise your rights, contact us at contactus@xentarai.com. If you are not satisfied, you may contact the Personal Data Protection Department at pdp.gov.my.

27. Your Rights — Philippines (Data Privacy Act 2012)

If you are in the Philippines, we process your personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules. The supervisory authority is the National Privacy Commission (NPC).

  • Right to be informed — about the collection and processing of your personal data (this policy serves that purpose).
  • Right to access — to reasonable access to your personal data and information about its processing.
  • Right to rectification — to dispute and correct inaccurate or erroneous personal data.
  • Right to erasure or blocking — to suspend, withdraw, or order the blocking, removal, or destruction of your personal data in the circumstances set out in the Act.
  • Right to data portability — to obtain a copy of your data in an electronic or structured format.
  • Right to object — to object to processing, including for direct marketing or automated processing.
  • Right to damages — to be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, or unlawfully obtained or unauthorised use of personal data.

To exercise your rights or file a complaint, contact us at contactus@xentarai.com. If you are not satisfied, you may contact the NPC at privacy.gov.ph.

28. Your Rights — Thailand (PDPA)

If you are in Thailand, we process your personal data in accordance with the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The supervisory authority is the Personal Data Protection Committee (PDPC).

  • Right of access — to access and obtain a copy of your personal data.
  • Right to rectification — to have your personal data kept accurate, complete, and up to date.
  • Right to erasure — to request deletion or anonymisation of your personal data.
  • Right to restriction and objection — to restrict or object to the processing of your personal data in the circumstances set out in the Act.
  • Right to data portability — to obtain and reuse your personal data across services.
  • Right to withdraw consent — to withdraw consent at any time where processing relies on consent.
  • Cross-border transfers — transfers outside Thailand (Section 5) are made to recipients with adequate protection or under appropriate safeguards as required by the PDPA.

Where required, users below the age of majority in Thailand must obtain the consent of a parent or legal guardian. To exercise your rights, contact us at contactus@xentarai.com. If you are not satisfied, you may contact the PDPC at pdpc.or.th.

29. Your Rights — Israel (Protection of Privacy Law)

If you are in Israel, we process your personal data in accordance with the Protection of Privacy Law 5741-1981, as amended (including Amendment 13). The supervisory authority is the Privacy Protection Authority (PPA).

  • Right of access — you may request access to the personal data we hold about you.
  • Right to correction — you may request correction of inaccurate, incomplete, unclear, or out-of-date personal data.
  • Right to deletion — you may request deletion of your personal data where it is no longer required for the stated purposes or where processing is not lawful.
  • Right to object — you may object to the use of your personal data, including for direct mailing purposes.
  • Right to withdraw consent — where processing relies on consent, you may withdraw it at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — transfers outside Israel (Section 5) are made on the basis of the safeguards permitted under the Privacy Protection Regulations (Transfer of Data Abroad).

To exercise your rights, contact us at contactus@xentarai.com. If you are not satisfied, you may contact the Privacy Protection Authority at gov.il.

30. Your Rights — Türkiye (KVKK, Law No. 6698)

If you are in Türkiye, we process your personal data in accordance with the Law on the Protection of Personal Data No. 6698 (KVKK). The supervisory authority is the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).

  • Right to be informed — to learn whether your personal data is processed and to request information about the processing (this policy serves that purpose).
  • Right of access — to access your personal data and learn the purposes of processing and whether it is used accordingly.
  • Right to correction and erasure — to request rectification of incomplete or inaccurate data, and deletion or destruction of your data where the grounds for processing no longer exist.
  • Right to object — to object to outcomes that arise from automated analysis of your data and that work against you.
  • Right to withdraw consent — where processing relies on consent, you may withdraw it at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — transfers outside Türkiye (Section 5) are made on the basis of explicit consent, adequacy, or a written undertaking / standard contract as required by the KVKK.

To exercise your rights, contact us at contactus@xentarai.com. If you are not satisfied, you may apply to the KVKK at kvkk.gov.tr.

31. Your Rights — Hong Kong (Personal Data (Privacy) Ordinance)

If you are in Hong Kong, we handle your personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) (PDPO) and the Data Protection Principles. The supervisory authority is the Office of the Privacy Commissioner for Personal Data (PCPD).

  • Right of access — you may request access to the personal data we hold about you (a data access request).
  • Right to correction — you may request correction of inaccurate personal data (a data correction request).
  • Use for direct marketing — we do not use your personal data for direct marketing beyond transactional communications without your consent.
  • Withdraw consent — you may withdraw consent to non-essential processing at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — transfers outside Hong Kong (Section 5) are made with contractual safeguards consistent with PCPD guidance on cross-border data transfers.

To exercise your rights, contact us at contactus@xentarai.com. If you are not satisfied, you may contact the PCPD at pcpd.org.hk.

32. Your Rights — Kenya (Data Protection Act, 2019)

If you are in Kenya, we process your personal data in accordance with the Data Protection Act, 2019 (Act No. 24 of 2019) and the Data Protection (General) Regulations 2021. The supervisory authority is the Office of the Data Protection Commissioner (ODPC).

  • Right to be informed — you have the right to be informed about the collection and processing of your personal data (this policy serves that purpose).
  • Right of access — you may request access to your personal data held by us and information about how it is processed.
  • Right to rectification — you may request correction of inaccurate, incomplete, or outdated personal data.
  • Right to erasure and blocking — you may request deletion or restriction of processing of your personal data where the grounds for processing no longer exist or where processing is unlawful.
  • Right to restrict processing — you may request that we restrict processing of your personal data in certain circumstances, including while we consider a correction or objection request.
  • Right to object — you may object to the processing of your personal data on legitimate grounds, including where processing is based on our legitimate interests.
  • Right to data portability — you may request to receive your personal data in a structured, machine-readable format and to have it transmitted to another controller where technically feasible.
  • Right not to be subject to automated decision-making — you have the right not to be subject to a decision based solely on automated processing that produces legal effects or significantly affects you. Our ATS scoring is advisory and does not make legally binding decisions about you.
  • Cross-border transfers — transfers outside Kenya (Section 5) are made to recipients with adequate protection or under appropriate contractual safeguards consistent with the Data Protection Act, 2019 and the Data Protection (General) Regulations 2021.

To exercise your rights, contact us at contactus@xentarai.com. We will respond within 30 days. If you are not satisfied with our response, you may contact the Office of the Data Protection Commissioner (ODPC) at odpc.go.ke.

33. Your Rights — Bangladesh

Bangladesh does not yet have a comprehensive personal data protection statute in force (a Personal Data Protection Act has been under legislative development). In the meantime, your privacy is protected under the constitutional right to privacy and applicable provisions of the Information and Communication Technology Act, 2006 and related laws. As a baseline, we voluntarily extend to users in Bangladesh the core protections described in this policy:

  • Transparency — this policy informs you of what we collect and why.
  • Access and correction — you may request access to, and correction of, the personal information we hold about you.
  • Deletion — you may delete your account and associated personal data at any time (Section 8).
  • Withdraw consent — you may withdraw consent to analytics, crash reporting, and advertising at any time via Settings → Account Preferences → Privacy & Consent.

We will update this section once a national data protection authority and statutory framework become operative. To exercise your rights, contact us at contactus@xentarai.com.

34. Your Rights — Sri Lanka (Personal Data Protection Act No. 9 of 2022)

If you are in Sri Lanka, we process your personal data in accordance with the Personal Data Protection Act, No. 9 of 2022 (PDPA), whose operative provisions are being phased into effect. The supervisory authority is the Data Protection Authority of Sri Lanka.

  • Right of access — you may request confirmation of, and access to, the personal data we process about you.
  • Right to rectification — you may request correction of inaccurate or incomplete personal data.
  • Right to erasure — you may request deletion of your personal data where the grounds for processing no longer apply.
  • Right to withdraw consent — where processing relies on consent, you may withdraw it at any time.
  • Right to object to automated processing — our ATS scoring is advisory and does not make legally binding decisions about you.
  • Cross-border transfers — transfers outside Sri Lanka (Section 5) are made with safeguards consistent with the PDPA.

To exercise your rights, contact us at contactus@xentarai.com. You may also lodge a complaint with the Data Protection Authority of Sri Lanka.

35. Your Rights — Maldives

The Maldives does not yet have a dedicated, operative personal data protection statute (data protection provisions have been under development). Your privacy is protected under Article 24 of the Constitution of the Maldives and applicable law. As a baseline, we voluntarily extend to users in the Maldives the core protections described in this policy — including transparency, access, correction, deletion (Section 8), and the right to withdraw consent to analytics, crash reporting, and advertising at any time via Settings → Account Preferences → Privacy & Consent. We will update this section once a national framework and authority become operative. To exercise your rights, contact us at contactus@xentarai.com.

36. Your Rights — Nigeria (Nigeria Data Protection Act 2023)

If you are in Nigeria, we process your personal data in accordance with the Nigeria Data Protection Act, 2023 (NDPA) and the Nigeria Data Protection Regulation 2019 (NDPR). The supervisory authority is the Nigeria Data Protection Commission (NDPC).

  • Right of access — you may request access to the personal data we hold about you and information about how it is processed.
  • Right to rectification — you may request correction of inaccurate or incomplete data.
  • Right to erasure — you may request deletion of your personal data where permitted by the NDPA.
  • Right to restrict and object — you may restrict or object to certain processing, including processing based on legitimate interests.
  • Right to data portability — you may request your data in a structured, machine-readable format.
  • Right to withdraw consent — you may withdraw consent at any time via Settings → Account Preferences → Privacy & Consent.
  • Automated decision-making — you have the right not to be subject to solely automated decisions with legal or significant effects; our ATS scoring is advisory only.
  • Cross-border transfers — transfers outside Nigeria (Section 5) are made to recipients offering adequate protection or under contractual safeguards consistent with the NDPA and NDPC guidance.

To exercise your rights, contact us at contactus@xentarai.com. If you are not satisfied, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.

37. Your Rights — Russia (Federal Law No. 152-FZ)

If you are in the Russian Federation, we process your personal data in accordance with Federal Law No. 152-FZ "On Personal Data". The supervisory authority is Roskomnadzor.

  • Right of access — you may request information about the personal data we process about you and the purposes of processing.
  • Right to rectification and blocking — you may request correction or blocking of personal data that is incomplete, outdated, inaccurate, or unlawfully processed.
  • Right to deletion — you may request deletion of your personal data and delete your account at any time (Section 8).
  • Right to withdraw consent — you may withdraw consent at any time via Settings → Account Preferences → Privacy & Consent.

Data localisation notice. Federal Law No. 152-FZ (Article 18(5)) requires that the recording, systematisation, accumulation, storage, updating, and retrieval of personal data of Russian citizens be performed using databases located within the Russian Federation. The App's backend infrastructure is located outside Russia (primarily the United States; see Section 5.1 and Section 60) and we do not operate localised databases within the Russian Federation. If compliance with the data-localisation requirement is mandatory for you, you should not use the App. By using the App from within the Russian Federation you acknowledge this notice. To exercise your rights, contact us at contactus@xentarai.com.

38. Your Rights — Egypt (Personal Data Protection Law No. 151 of 2020)

If you are in Egypt, we process your personal data in accordance with Law No. 151 of 2020 on the Protection of Personal Data. The competent authority is the Personal Data Protection Center (PDPC), whose executive regulations and licensing regime are being implemented.

  • Right to be informed and to access — you may know what personal data we hold and how it is processed.
  • Right to rectification — you may request correction of inaccurate personal data.
  • Right to erasure — you may request deletion of your personal data (Section 8).
  • Right to withdraw consent and to object — you may withdraw consent or object to processing, including profiling for advertising (Section 2.8).
  • Right to portability — you may request your data in a readable, machine-processable format.
  • Cross-border transfers — transfers outside Egypt (Section 5) are made with safeguards consistent with Law No. 151 of 2020, which requires an adequate level of protection.

To exercise your rights, contact us at contactus@xentarai.com. You may also lodge a complaint with the Personal Data Protection Center once operational.

39. Your Rights — Vietnam (Decree No. 13/2023/ND-CP)

If you are in Vietnam, we process your personal data in accordance with Decree No. 13/2023/ND-CP on Personal Data Protection and the Law on Personal Data Protection. The competent authority is the Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention, A05).

  • Right to be informed and to access — you may know about and access the personal data we process about you.
  • Right to correction — you may request correction of your personal data.
  • Right to deletion — you may request deletion of your personal data (Section 8).
  • Right to withdraw consent and to object — you may withdraw consent or object to, or restrict, processing at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — the App transfers personal data outside Vietnam (Section 5). We maintain transfer documentation consistent with Decree No. 13/2023/ND-CP.

To exercise your rights, contact us at contactus@xentarai.com.

40. Your Rights — Tanzania (Personal Data Protection Act No. 11 of 2022)

If you are in Tanzania, we process your personal data in accordance with the Personal Data Protection Act, No. 11 of 2022 and its 2023 Regulations. The supervisory authority is the Personal Data Protection Commission (PDPC).

  • Right of access — you may request access to your personal data.
  • Right to rectification — you may request correction of inaccurate or incomplete data.
  • Right to erasure — you may request deletion of your personal data (Section 8).
  • Right to object and to withdraw consent — you may object to processing or withdraw consent at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — transfers outside Tanzania (Section 5) are made with safeguards consistent with the Act and its Regulations.

To exercise your rights, contact us at contactus@xentarai.com. If you are not satisfied, you may lodge a complaint with the Personal Data Protection Commission.

41. Your Rights — Mexico (LFPDPPP)

If you are in Mexico, we process your personal data in accordance with the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), as revised in 2025. Following the 2025 reform, oversight of data protection transferred from the former INAI to the Secretaría Anticorrupción y Buen Gobierno (through Transparencia para el Pueblo). You have the following ARCO rights:

  • Access — request access to the personal data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Cancellation — request deletion of your personal data (Section 8).
  • Opposition — object to the processing of your personal data for specific purposes, including profiling for advertising (Section 2.8).
  • Withdraw consent — you may withdraw consent at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — transfers outside Mexico (Section 5) are made subject to this privacy notice and the safeguards required by the LFPDPPP.

To exercise your ARCO rights, contact us at contactus@xentarai.com. If you are not satisfied, you may lodge a complaint with the competent Mexican data protection authority.

42. Your Rights — Ghana (Data Protection Act, 2012)

If you are in Ghana, we process your personal data in accordance with the Data Protection Act, 2012 (Act 843). The supervisory authority is the Data Protection Commission (DPC).

  • Right of access — you may request access to the personal data we hold about you.
  • Right to correction — you may request correction or deletion of inaccurate, out-of-date, or misleading personal data.
  • Right to prevent processing — you may object to processing likely to cause unwarranted damage or distress, and to processing for direct marketing.
  • Right to withdraw consent — you may withdraw consent at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — transfers outside Ghana (Section 5) are made with safeguards consistent with the Data Protection Act, 2012.

To exercise your rights, contact us at contactus@xentarai.com. You may also lodge a complaint with the Data Protection Commission at dataprotection.org.gh.

43. Your Rights — Angola (Personal Data Protection Law No. 22/11)

If you are in Angola, we process your personal data in accordance with Law No. 22/11 on the Protection of Personal Data. The supervisory authority is the Agência de Proteção de Dados (APD).

  • Right of access — you may request access to your personal data and information on its processing.
  • Right to rectification — you may request correction of inaccurate or incomplete data.
  • Right to erasure and objection — you may request deletion of, or object to, the processing of your personal data where permitted by law.
  • Right to withdraw consent — you may withdraw consent at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — transfers outside Angola (Section 5) are made with the safeguards required by Law No. 22/11, which may require authorisation from the APD.

To exercise your rights, contact us at contactus@xentarai.com. You may also lodge a complaint with the Agência de Proteção de Dados.

44. Your Rights — Nepal (Privacy Act, 2018)

If you are in Nepal, we process your personal data in accordance with the Privacy Act, 2018 (2075) and the Privacy Regulation, which protect personal information and require consent for its collection and use. Nepal does not yet have a single dedicated data protection authority; oversight is exercised through the courts and applicable bodies.

  • Consent — we collect and use your personal information with your consent, as required by the Privacy Act.
  • Access and correction — you may request access to, and correction of, the personal information we hold about you.
  • Deletion — you may delete your account and associated personal data at any time (Section 8).
  • Protection from unauthorised disclosure — we do not disclose your personal information except as described in this policy or as permitted by law.

To exercise your rights, contact us at contactus@xentarai.com.

45. Your Rights — Myanmar

Myanmar does not yet have a comprehensive, operative personal data protection statute of general application (data protection provisions appear in sectoral and cybersecurity legislation, which continues to develop). Your privacy is protected under applicable law and the constitutional protection of privacy. As a baseline, we voluntarily extend to users in Myanmar the core protections described in this policy — including transparency, access, correction, deletion (Section 8), and the right to withdraw consent to analytics, crash reporting, and advertising at any time via Settings → Account Preferences → Privacy & Consent. We will update this section as a national framework becomes operative. To exercise your rights, contact us at contactus@xentarai.com.

46. Your Rights — Cambodia

Cambodia does not yet have a comprehensive personal data protection law in force (a Personal Data Protection Law has been under development; consent and confidentiality provisions currently appear in the E-Commerce Law and related legislation). As a baseline, we voluntarily extend to users in Cambodia the core protections described in this policy — including transparency, access, correction, deletion (Section 8), and the right to withdraw consent to analytics, crash reporting, and advertising at any time via Settings → Account Preferences → Privacy & Consent. We will update this section once a national framework and authority become operative. To exercise your rights, contact us at contactus@xentarai.com.

47. Your Rights — Peru (Law No. 29733)

If you are in Peru, we process your personal data in accordance with the Personal Data Protection Law, Law No. 29733 and its regulations. The supervisory authority is the Autoridad Nacional de Protección de Datos Personales (ANPD). You have the following ARCO rights:

  • Access — request access to the personal data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Cancellation — request deletion of your personal data (Section 8).
  • Opposition — object to processing for specific purposes, including profiling for advertising (Section 2.8).
  • Withdraw consent — you may withdraw consent at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — transfers outside Peru (Section 5) are made with the safeguards required by Law No. 29733.

To exercise your rights, contact us at contactus@xentarai.com. You may also lodge a complaint with the ANPD.

48. Your Rights — Dominican Republic (Law No. 172-13)

If you are in the Dominican Republic, we process your personal data in accordance with Law No. 172-13 on the Protection of Personal Data (habeas data). You have the following ARCO rights: access, rectification, cancellation (deletion — Section 8), and opposition to processing for specific purposes, including profiling for advertising (Section 2.8). You may withdraw consent at any time via Settings → Account Preferences → Privacy & Consent, and transfers outside the Dominican Republic (Section 5) are made with the safeguards required by Law No. 172-13. To exercise your rights, contact us at contactus@xentarai.com.

49. Your Rights — Jamaica (Data Protection Act, 2020)

If you are in Jamaica, we process your personal data in accordance with the Data Protection Act, 2020. The supervisory authority is the Office of the Information Commissioner (OIC).

  • Right of access — you may request access to your personal data and information about its processing.
  • Right to rectification — you may request correction of inaccurate or incomplete data.
  • Right to erasure — you may request deletion of your personal data (Section 8).
  • Right to prevent processing — you may prevent processing likely to cause damage or distress, and object to direct marketing.
  • Right to withdraw consent — you may withdraw consent at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — transfers outside Jamaica (Section 5) are made with safeguards consistent with the Data Protection Act, 2020.

To exercise your rights, contact us at contactus@xentarai.com. You may also lodge a complaint with the Office of the Information Commissioner.

50. Your Rights — Antigua and Barbuda (Data Protection Act, 2013)

If you are in Antigua and Barbuda, we process your personal data in accordance with the Data Protection Act, 2013, overseen by the Information Commissioner. You may request access to, and correction or deletion of, the personal data we hold about you (Section 8), object to processing likely to cause damage or distress, and withdraw consent at any time via Settings → Account Preferences → Privacy & Consent. Transfers outside Antigua and Barbuda (Section 5) are made with safeguards consistent with the Act. To exercise your rights, contact us at contactus@xentarai.com.

51. Your Rights — Dominica

Dominica does not yet have a comprehensive, operative personal data protection statute of general application. Your privacy is protected under the constitutional protection of privacy and applicable law. As a baseline, we voluntarily extend to users in Dominica the core protections described in this policy — including transparency, access, correction, deletion (Section 8), and the right to withdraw consent to analytics, crash reporting, and advertising at any time via Settings → Account Preferences → Privacy & Consent. To exercise your rights, contact us at contactus@xentarai.com.

52. Your Rights — Grenada

Grenada's comprehensive data protection framework is still developing and not yet fully operative. Your privacy is protected under the constitutional protection of privacy and applicable law. As a baseline, we voluntarily extend to users in Grenada the core protections described in this policy — including transparency, access, correction, deletion (Section 8), and the right to withdraw consent to analytics, crash reporting, and advertising at any time via Settings → Account Preferences → Privacy & Consent. We will update this section as a national framework becomes operative. To exercise your rights, contact us at contactus@xentarai.com.

53. Your Rights — Trinidad and Tobago (Data Protection Act, 2011)

If you are in Trinidad and Tobago, we process your personal data in accordance with the Data Protection Act, 2011 (Act No. 13 of 2011), whose provisions are being brought into force in phases, and the general information privacy principles it establishes. Oversight is to be exercised by the Information Commissioner. As a baseline — including for provisions not yet proclaimed — we voluntarily extend to you the core protections described in this policy, including transparency, access, correction, deletion (Section 8), and the right to withdraw consent at any time via Settings → Account Preferences → Privacy & Consent. Transfers outside Trinidad and Tobago (Section 5) are made with appropriate safeguards. To exercise your rights, contact us at contactus@xentarai.com.

54. Your Rights — Bermuda (Personal Information Protection Act 2016)

If you are in Bermuda, we process your personal data in accordance with the Personal Information Protection Act 2016 (PIPA), which came fully into force on 1 January 2025. The supervisory authority is the Privacy Commissioner for Bermuda (PrivCom).

  • Right of access — you may request access to your personal information and information about its use.
  • Right to rectification — you may request correction of inaccurate or incomplete information.
  • Right to erasure — you may request deletion of your personal information (Section 8).
  • Right to stop or restrict processing — you may object to, or request that we cease, certain processing, including for direct marketing.
  • Right to withdraw consent — you may withdraw consent at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — transfers outside Bermuda (Section 5) are made with safeguards consistent with PIPA, under which we remain responsible for the protection of your information.

To exercise your rights, contact us at contactus@xentarai.com. You may also lodge a complaint with the Privacy Commissioner for Bermuda at privacy.bm.

55. Your Rights — Jordan (Personal Data Protection Law No. 24 of 2023)

If you are in Jordan, we process your personal data in accordance with Personal Data Protection Law No. 24 of 2023. The competent authority is the Personal Data Protection Council (with the Ministry of Digital Economy and Entrepreneurship).

  • Right of access — you may request access to your personal data and information about its processing.
  • Right to rectification — you may request correction of inaccurate or incomplete data.
  • Right to erasure — you may request deletion of your personal data (Section 8).
  • Right to object and to withdraw consent — you may object to processing or withdraw consent at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — transfers outside Jordan (Section 5) are made with safeguards consistent with Law No. 24 of 2023.

To exercise your rights, contact us at contactus@xentarai.com. You may also lodge a complaint with the Personal Data Protection Council.

56. Your Rights — Azerbaijan (Law on Personal Data)

If you are in Azerbaijan, we process your personal data in accordance with the Law of the Republic of Azerbaijan on Personal Data (2010). Oversight is exercised by the Ministry of Digital Development and Transport.

  • Right of access — you may request information about the personal data we process and the purposes of processing.
  • Right to rectification and blocking — you may request correction or blocking of inaccurate or unlawfully processed data.
  • Right to deletion — you may request deletion of your personal data (Section 8).
  • Right to withdraw consent — you may withdraw consent at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — transfers outside Azerbaijan (Section 5) are made with safeguards consistent with the Law on Personal Data.

To exercise your rights, contact us at contactus@xentarai.com.

57. Your Rights — Ukraine (Law No. 2297-VI)

If you are in Ukraine, we process your personal data in accordance with the Law of Ukraine "On Protection of Personal Data" No. 2297-VI. The supervisory authority is the Ukrainian Parliament Commissioner for Human Rights (Ombudsman).

  • Right of access — you may request access to your personal data and information about its processing.
  • Right to rectification — you may request correction of inaccurate or incomplete data.
  • Right to erasure — you may request deletion of your personal data (Section 8).
  • Right to object and to withdraw consent — you may object to processing or withdraw consent at any time via Settings → Account Preferences → Privacy & Consent.
  • Cross-border transfers — transfers outside Ukraine (Section 5) are made to recipients providing adequate protection or under appropriate safeguards consistent with Law No. 2297-VI.

To exercise your rights, contact us at contactus@xentarai.com. You may also lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights.

58. Your Rights — Fiji

Fiji does not yet have a comprehensive, operative personal data protection statute of general application. Your privacy is protected under section 24 of the Constitution of Fiji (right to personal privacy) and applicable law. As a baseline, we voluntarily extend to users in Fiji the core protections described in this policy — including transparency, access, correction, deletion (Section 8), and the right to withdraw consent to analytics, crash reporting, and advertising at any time via Settings → Account Preferences → Privacy & Consent. We will update this section as a national framework becomes operative. To exercise your rights, contact us at contactus@xentarai.com.

59. Analytics Consent and Opt-Out

You can manage analytics and crash reporting consent at any time from within the App: Settings → Account Preferences → Privacy & Consent. Revoking consent stops all future collection and closes the active PostHog and Sentry sessions immediately. Previously collected data is subject to those providers' own retention policies.

Users in the EU, EEA, UK, Switzerland, Brazil, and Canada are presented with an explicit consent prompt during onboarding. No analytics data is collected before consent is granted. All other users may opt out at any time via the same in-app setting.

60. International Data Transfers

XentarAI Inc. is incorporated in Canada. Your personal information may be transferred to and processed in the United States (Supabase, Anthropic, Google, PostHog, Sentry, ScrapingAnt, Apify, Firecrawl, Resend, AdMob, Jooble, The Muse), the United Kingdom (Adzuna), France (Mistral AI, Brevo), Germany (Arbeitnow), India (ZeptoMail), and potentially other countries where our service providers operate (including Remotive, which operates globally).

Safeguards governing these transfers:

  • From EU/EEA — Standard Contractual Clauses (EU SCCs, 2021)
  • From UK — UK International Data Transfer Addendum (IDTA) to EU SCCs, or equivalent UK-approved mechanism
  • From Switzerland — Standard Contractual Clauses as recognised by the FDPIC
  • From Canada — contractual obligations requiring comparable protection; Canada is recognised by the EU as providing adequate protection under PIPEDA
  • From Australia — contractual data processing agreements (APP 8 safeguards)
  • From New Zealand — contractual safeguards providing comparable protection to the IPPs
  • From South Africa — contractual safeguards meeting the requirements of Section 72 POPIA
  • From Singapore — contractual data protection clauses meeting the PDPA transfer limitation obligation (s. 26 PDPA)
  • From UAE — contractual safeguards meeting the requirements of Federal Decree-Law No. 45 of 2021 (UAE PDPL)
  • From Japan — contractual data processing agreements confirming recipients maintain appropriate personal information protection systems equivalent to Japan's APPI requirements
  • From Argentina — consent and contractual safeguards requiring protection comparable to Law 25.326
  • From Brazil — contractual safeguards (standard clauses) and, where applicable, your consent, consistent with the LGPD
  • From India — transfers permitted except to territories restricted by the Central Government, with contractual safeguards under the DPDP Act 2023
  • From Saudi Arabia — transfer conditions and appropriate safeguards under the PDPL and its Implementing Regulations
  • From South Korea — your consent or contractual and other safeguards required by PIPA
  • From Indonesia — adequate protection or contractual safeguards under Law No. 27 of 2022 (PDP Law)
  • From Malaysia — recipient protection comparable to the PDPA, consistent with the amended cross-border transfer requirements
  • From the Philippines — contractual safeguards and accountability measures under the Data Privacy Act 2012
  • From Thailand — adequate protection or appropriate safeguards as required by the PDPA
  • From Israel — safeguards permitted under the Privacy Protection Regulations (Transfer of Data Abroad)
  • From Türkiye — explicit consent, adequacy, or a written undertaking / standard contract as required by the KVKK
  • From Hong Kong — contractual safeguards consistent with PCPD guidance on cross-border data transfers
  • From Kenya — adequate protection or contractual safeguards consistent with the Data Protection Act, 2019 and the Data Protection (General) Regulations 2021
  • From Nigeria — adequate protection or contractual safeguards consistent with the Nigeria Data Protection Act, 2023 and NDPC guidance
  • From Sri Lanka — appropriate safeguards as required by the Personal Data Protection Act, No. 9 of 2022
  • From Egypt — an adequate level of protection or the safeguards required by Law No. 151 of 2020
  • From Vietnam — transfer documentation (impact assessment) maintained as required by Decree No. 13/2023/ND-CP
  • From Tanzania — adequate protection or contractual safeguards under the Personal Data Protection Act, No. 11 of 2022 and its 2023 Regulations
  • From Mexico — transfers made under this privacy notice and the safeguards required by the LFPDPPP
  • From Russia — subject to the data-localisation notice in Section 37; where applicable, transfers rely on your consent or other bases permitted by Federal Law No. 152-FZ
  • From Ghana — safeguards consistent with the Data Protection Act, 2012
  • From Angola — safeguards required by Law No. 22/11, which may require APD authorisation
  • From Peru — safeguards required by Law No. 29733 and its regulations
  • From the Dominican Republic — safeguards required by Law No. 172-13
  • From Jamaica — safeguards consistent with the Data Protection Act, 2020
  • From Antigua and Barbuda — safeguards consistent with the Data Protection Act, 2013
  • From Trinidad and Tobago — appropriate safeguards under the Data Protection Act, 2011
  • From Bermuda — safeguards consistent with PIPA, under which we remain accountable for the transferred information
  • From Jordan — safeguards consistent with Law No. 24 of 2023
  • From Azerbaijan — safeguards consistent with the Law on Personal Data
  • From Ukraine — adequate protection or appropriate safeguards under Law No. 2297-VI
  • From Nepal — safeguards consistent with the Privacy Act, 2018
  • From Bangladesh, the Maldives, Myanmar, Cambodia, Dominica, Grenada, Fiji, and other jurisdictions without a comprehensive framework yet in force — we apply the contractual and organisational safeguards described above as a voluntary baseline

61. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last Updated" date at the top of this page and, where required by applicable law, by providing in-app notification or direct email notice. We encourage you to review this policy periodically. Continued use of the App after changes are posted constitutes your acceptance of the updated policy.

62. Contact Us

For questions, concerns, or data rights requests related to this Privacy Policy, please contact:

XentarAI Inc.
Privacy & Legal
Email: contactus@xentarai.com
Website: https://xentarai.com
Country of incorporation: Canada

Response timelines: 30 days for GDPR / UK GDPR requests; 45 days for CCPA / US state law requests; 30 days for Australian, New Zealand, South Africa, Singapore, UAE, Japan, and Kenya requests; and within the period required by applicable law (or otherwise a reasonable period) for Argentina, Brazil, Hong Kong, India, Indonesia, Israel, Malaysia, the Philippines, Saudi Arabia, South Korea, Thailand, Türkiye, and all other jurisdictions. Complex requests may be extended with notice.