Version 2026-09-21.2 · Effective 21 September 2026
This notice explains what personal data GigIt processes, why, the legal bases we rely on under India’s DPDP Act, who processes data for us, how long we keep it, and how you can access, correct, or erase it.
Governing law: Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 to the extent still applicable. This is GigIt’s contract and privacy notice, not legal advice about your engagements with other users.
1. Data fiduciary and scope
GigIt is the data fiduciary for personal data processed to operate the GigIt service for users in India. This policy applies to the GigIt web application, related APIs, and administrative tools used to support your account.
It does not apply to another user’s independent processing once they receive your data in a conversation or contract (for example, a client storing your invoice). Those parties are separate fiduciaries or processors for their own purposes. Share only what you are willing to disclose for that engagement.
If we appoint a Grievance Officer as required for our scale of operations, the name and contact details will be published in this section. Until then, use in-product Privacy and data rights to file access, correction, erasure, and grievance requests so they are logged against your account.
2. Personal data we process
Account and verification: mobile number, OTP verification status, Firebase authentication identifiers, session cookies, and consent receipts (purpose, document version, time, granted/declined).
Profile and onboarding: name, date of birth, state, city, photo if you upload one, professional headline, bio, skills, languages, rates you choose to publish, portfolio items, resume files, and knowledge articles.
Marketplace activity: leads, proposal versions, project records, deliverables metadata, reviews, connection and conversation metadata, and messages and files you send.
Technical and security data: device and browser type, IP address, approximate location derived from IP if collected, timestamps, diagnostic logs, and abuse signals.
AI and search data: embeddings and search indexes derived from published profile, resume, and knowledge text; prompts and model outputs when you use assistants; and match explanations generated for a search.
We do not require your religion, caste, political opinions, or health data to use GigIt. Do not put sensitive personal data in a public bio. If you volunteer it, we treat it as User Content you chose to publish.
3. Purposes and DPDP lawful bases
Consent (DPDP): creating an account after you accept Terms and this Policy; sending SMS OTPs; publishing your profile in search; generating embeddings from published profile, resume, and knowledge text; running AI assistants on content you submit to them.
Legitimate uses recognised under DPDP as applicable: preventing fraud and abuse; securing the service; complying with law and lawful government requests; employing or engaging with you if you work for GigIt; and processing that is necessary for the specified purpose of a voluntary user-initiated transaction (for example, delivering a message you chose to send).
We will not use your personal data for a new unrelated purpose without a fresh notice and, where required, consent. We do not sell personal data. We do not use your private messages to train public foundation models operated by GigIt.
4. Phone numbers and SMS
GigIt sign-in uses an Indian mobile number in +91 format. We send one-time passwords through our authentication provider (Firebase Authentication). Your carrier may charge SMS rates.
Your number is used to authenticate you, recover the session, and show a connected number in settings. It appears on your public profile and to connections only if you turn on phone visibility. Directory visitors do not receive your phone number unless you choose to show it.
5. Search, embeddings, and processors
When your profile is published, GigIt-ai may create vector embeddings of published profile, resume, and knowledge text so other users can find you by meaning, not only by keywords. Hybrid search may combine those embeddings with structured filters (location, specialty, availability).
Model inference and embedding generation may be performed by processors acting on our instructions, including OpenRouter and NVIDIA as model or infrastructure processors. They are not permitted to use that content for their own unrelated advertising. Sub-processors may process data outside India; we remain responsible as data fiduciary for choosing processors and for required safeguards.
Assistant features (profile, requirement, match, quotation, proposal, and trust drafts) send the minimum prompt context needed for that task. Outputs are stored as AI run records so you can see what was generated and so we can debug abuse and quality issues.
Erasure requests fan out to delete or invalidate search embeddings through GigIt-ai (including related cache entries) after we accept a valid request, subject to legal holds.
8. Retention, security, and incidents
We keep account, contract, proposal, and consent records for as long as you have an account and thereafter for a limited period needed for disputes, tax, audit, and legal holds. Embeddings of unpublished or deleted public profile material are invalidated when the source is removed or when an erasure request is completed.
We apply access control, encryption in transit, server-side session handling, and audit logs for consent and data-subject requests. No method of transmission is perfectly secure. You must protect your device and OTP codes.
Where a personal data breach is likely to cause harm, we will follow DPDP breach-intimation duties to the Data Protection Board of India and to affected Data Principals as required.
9. Your rights as a Data Principal
You may request: a summary of personal data we process and the processing activities; correction of inaccurate or incomplete data; erasure of personal data that is no longer necessary for the stated purpose, subject to legal exceptions; access to information about data sharing; and withdrawal of consent for consent-based processing (which may mean we cannot keep a published searchable profile).
Use Settings → Privacy and data rights, or the in-product request tools, to file export, correction, or erasure. We may need to verify the request comes from the same verified account. We may decline or limit a request where another law requires retention, where the request is manifestly unfounded, or where it would adversely affect another person’s rights.
Withdrawing consent does not affect processing already completed while consent was valid. You may nominate another person to exercise rights on your behalf as DPDP allows.
You may complain to us first. You may also approach the Data Protection Board of India after exhausting the grievance process, once that Board’s complaint mechanism is available for your case.
10. Children
GigIt is not directed at children under 18. We do not knowingly create accounts for children. If we learn that we have processed a child’s personal data in breach of DPDP verifiable-consent rules, we will delete the account and associated personal data except where law requires retention.
11. Cross-border processing
Authentication, hosting, and AI processors may process personal data on servers outside India. We will not transfer personal data to a country or territory that the Central Government has restricted under DPDP when such a restriction is in force and applies to us.
By using GigIt from India with processors described in this Policy, you understand that published profile embeddings and authentication data may be processed in those processor locations for the purposes above.
12. Changes to this notice
We will publish a new version number and effective date when this Policy changes. If the change is material to consent-based processing (for example, a new AI processor purpose), we will request a fresh acceptance at sign-in or in product.
The current version identifier is shown at the top of this page and stored on your consent receipt when you accept.