Grafixo

Privacy Policy

Last updated: September 10, 2025

This Privacy Policy describes how Grafixo ("we," "us," or "our") collects, uses, and protects your personal information when you use our website and services at grafixo.net (the "Service").

1. Company Information

Service Provider: Grafixo
Location: Jaipur, Rajasthan, India
Email: support@grafixo.net
Website: https://grafixo.net

2. Data Controller and Processing Location

Grafixo acts as the data controller for all personal information collected through our Service. While our business is located in Jaipur, India, our servers are hosted in Germany to ensure optimal performance and security for our global users.

3. Information We Collect

3.1 Account Information

When you create an account, we collect:

  • Full name
  • Email address
  • Encrypted password (we never store plain text passwords)

3.2 Service Usage Data

When you use our AI-powered resume optimization service (Resumify), we collect and process:

  • Resume documents you upload
  • Extracted data from your resume including work experience, education, skills, and other professional information
  • Job descriptions you provide for optimization purposes
  • AI-processed content and optimization results

3.3 Payment and Billing Information

When you purchase our services, we collect through our payment processor DodoPayments:

  • Billing address (street, city, state, country, postal code)
  • Payment transaction details (processed and stored by DodoPayments)

3.4 Technical Information

We automatically collect:

  • IP address
  • Browser type and version
  • Device information
  • Usage analytics through Google Analytics
  • Access logs and session data (JWT tokens valid for 7 days)

4. How We Use Your Information

We use your personal information to:

4.1 Provide Services

  • Process and optimize your resume using AI technology
  • Provide personalized recommendations and improvements
  • Maintain your account and service access
  • Process payments and billing

4.2 Service Improvement

  • Analyze service usage to improve functionality
  • Develop new features and services
  • Ensure platform security and prevent abuse

4.3 Communication

  • Send service-related notifications
  • Provide customer support
  • Send important updates about our services

4.4 Legal Compliance

  • Comply with applicable laws and regulations
  • Protect our rights and interests
  • Respond to legal requests

5. Third-Party Services and Data Sharing

5.1 OpenAI Integration

We use OpenAI's API services to power our AI resume optimization features. When you use Resumify:

  • Your resume content and related data are processed by OpenAI's systems
  • OpenAI may retain API data for up to 30 days for abuse detection purposes
  • OpenAI operates under their Data Processing Addendum and privacy policies
  • We are bound by OpenAI's data handling requirements

5.2 Payment Processing

We use DodoPayments as our payment processor:

  • Payment transactions are processed directly by DodoPayments
  • Billing information is collected as required by DodoPayments
  • We store billing addresses locally to avoid repeated data collection
  • DodoPayments handles all payment card data according to PCI DSS standards

5.3 Analytics

We use Google Analytics to understand how our service is used:

  • Google Analytics collects usage patterns and website interactions
  • Data is processed according to Google's privacy policy
  • You can opt out of Google Analytics tracking using browser settings or opt-out tools

5.4 No Other Data Sharing

We do not sell, rent, or share your personal information with any other third parties except as described above or as required by law.

6. Data Security

We implement comprehensive security measures including:

  • HTTPS encryption for all data transmission
  • Password encryption using industry-standard methods
  • JWT-based authentication with 7-day expiration
  • Secure server infrastructure in Germany
  • Regular security monitoring and access controls
  • Data segregation and controlled access protocols

7. Data Retention

7.1 Account Data

  • We retain your account information and service data until you request account deletion
  • Resume data and extracted information remain accessible unless you delete your account
  • Subscription data is retained for billing and service continuity purposes

7.2 Subscription Continuity

  • If your subscription expires or is cancelled, your data remains accessible
  • Account deletion must be requested by emailing support@grafixo.net

7.3 Legal Requirements

  • We may retain data longer if required by law or legal proceedings
  • Security logs and access records are retained for one year for abuse detection

8. Your Rights

Under applicable data protection laws, you have the right to:

8.1 Access and Control

  • Access your personal information
  • Correct inaccurate information
  • Delete your account and associated data
  • Export your data in a portable format

8.2 Processing Rights

  • Object to data processing for legitimate interests
  • Restrict processing in certain circumstances
  • Withdraw consent where processing is based on consent

8.3 Exercising Rights

To exercise these rights, contact us at support@grafixo.net. We will respond within 30 days of receiving your request.

9. International Data Transfers

9.1 Cross-Border Processing

  • Our servers are located in Germany within the European Economic Area
  • Data transfers from India to Germany are conducted with appropriate safeguards
  • OpenAI processing may involve international transfers according to their policies

9.2 Adequacy and Safeguards

  • We ensure adequate protection for international data transfers
  • Appropriate technical and organizational measures are implemented
  • Transfers comply with applicable data protection requirements

10. Legal Basis for Processing

We process your personal information based on:

  • Contract Performance: To provide our services and fulfill our obligations
  • Legitimate Interests: For service improvement, security, and business operations
  • Consent: Where explicitly provided for specific processing activities
  • Legal Compliance: To meet regulatory and legal requirements

11. Children's Privacy

Our services are intended for job seekers and working professionals. We do not knowingly collect personal information from children under 18 years of age. If we become aware that we have collected personal information from a child, we will take steps to delete such information.

12. Cookies and Tracking

We use minimal tracking technologies:

  • Essential cookies for service functionality and user authentication
  • Google Analytics cookies for usage analysis
  • No third-party advertising or marketing cookies
  • You can control cookie settings through your browser

13. Changes to Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or applicable laws. Material changes will be communicated through:

  • Email notification to registered users
  • Prominent notice on our website
  • Update date modification at the top of this policy

Continued use of our Service after changes constitutes acceptance of the updated Privacy Policy.

14. Governing Law

This Privacy Policy is governed by the laws of India. Any disputes related to privacy matters will be subject to the jurisdiction of courts in Jaipur, Rajasthan, India, or resolved through binding arbitration as specified in our Terms of Service.

15. Contact Information

For privacy-related questions, concerns, or requests:

Email: support@grafixo.net
Subject Line: Privacy Inquiry

We are committed to addressing your privacy concerns promptly and transparently.


This Privacy Policy forms part of our comprehensive legal framework designed to protect your privacy while enabling us to provide innovative AI-powered services. We encourage you to review this policy regularly and contact us with any questions.