generated: '2026-09-19' method: searched probe: true source: https://matchitup.in/privacy-policy entity: Matchitup Tech Private Limited (Gurugram, Haryana, India) — self-described Data Fiduciary under India's DPDPA 2023; privacy policy also states GDPR legal bases fetch_note: >- The site is a React SPA that answers 200 with a JavaScript shell for every non-API path in a browser, but prerenders full page text for crawler user agents. Every legal page below was read with a Googlebot UA; the conventional paths that "hit" (200) with the site's own "404 Page Not Found" body are recorded as soft-404s, not as pages. signals: data_subject_request: url: https://matchitup.in/privacy-policy section: Rights of Users; Data Protection Officer; Grievance Redressal channel: support@matchitup.in (DPO, Gurugram, Haryana, India) rights_named: [access and correction (self-serve in settings), withdrawal of consent (including for AI-enabled matchmaking), erasure / account deletion, grievance redressal to the DPO] stated_sla: 'Match It Up will take reasonable steps to erase such data within 30 days of receiving the request, except where retention is required for compliance with applicable legal, regulatory, or tax obligations.' grievance_sla_stated: 'Match It Up will make reasonable efforts to acknowledge and address such grievances within the timelines prescribed under applicable law.' evidence: - source: https://matchitup.in/privacy-policy http_status: 200 fetched: '2026-09-19' quote: >- "Erasure: Users may request the deletion of their account and associated personal data. Match It Up will take reasonable steps to erase such data within 30 days of receiving the request, except where retention is required for compliance with applicable legal, regulatory, or tax obligations." - source: https://matchitup.in/privacy-policy http_status: 200 fetched: '2026-09-19' quote: >- "Data Protection Officer — In accordance with the GDPR requirements, Match It Up has appointed a DPO responsible for addressing concerns or complaints relating to the processing of personal data. Email: support@matchitup.in. Location: Gurugram, Haryana, India." note: >- A named channel, an enumerated rights list and a 30-day erasure period — the substance of a DSR process, carried in the privacy policy. No dedicated intake form (/privacy/requests not probed as a real route; the SPA would answer 200 regardless) and no API endpoint; agents can delete their own agent record with DELETE /api/protocol/agents/{agent_id}. ai_transparency: url: https://matchitup.in/privacy-policy section: Artificial Intelligence (AI) and Automated Processing evidence: - source: https://matchitup.in/privacy-policy http_status: 200 fetched: '2026-09-19' quote: >- "Match It Up uses artificial intelligence, algorithmic tools, and data-driven technologies to facilitate professional networking and business matchmaking on the Platform. These systems analyse information contained in user profiles, stated interests, and engagement activity in order to generate relevant connection recommendations and networking opportunities. The outputs generated by these systems are recommendations ... [not] decisions, legal obligations, or financial consequences for users." - source: https://matchitup.in/privacy-policy http_status: 200 fetched: '2026-09-19' quote: >- "Profile Embeddings — a 1,536-dimension numerical vector (generated via OpenAI text-embedding-3-small) derived from your agent's public name, description, and capabilities. This is used solely for Intent Radar semantic search." - source: https://matchitup.in/api/docs/agent-instructions.md http_status: 200 fetched: '2026-09-19' quote: 'Public agent profiles at /bot/{agent_id}; the MIU Feed is described as posts "from human Member Agents and external Protocol Agents", and every agent post page carries a "Comment via Agent" control.' note: >- A published statement of what the AI does, what data it reads, that outputs are recommendations rather than decisions with legal effect, and which third-party model produces embeddings. Users can withdraw consent for AI-enabled matchmaking (Rights of Users). Recorded as AI-use transparency; there is no dedicated /ai/transparency page (that path returns the 404 body) and no model card. incident_notification: url: https://matchitup.in/privacy-policy section: Data Security stated_period: 'in accordance with applicable legal requirements' evidence: - source: https://matchitup.in/privacy-policy http_status: 200 fetched: '2026-09-19' quote: >- "In the event of a personal data breach that is likely to cause harm to users, Match It Up will take appropriate steps to notify affected individuals and relevant authorities in accordance with applicable legal requirements." note: >- A published commitment to notify both affected individuals and authorities, with the period left to the applicable law (DPDPA rules / GDPR 72 hours are not named). Recorded verbatim; weaker than a stated number and flagged as such. checked_without_signal: subprocessors: result: no dated subprocessor list detail: >- The privacy policy names categories ("cloud hosting, OTP services, analytics") and some vendors inline (Microsoft Clarity and Microsoft Advertising for session replay/heatmaps, OpenAI for embeddings; docs name Cloudinary for images and Razorpay for payments) but publishes no table with purpose, location and date. /legal/subprocessors returns the 404 body (HTTP 200). data_residency: result: none detail: 'The policy has a "Cross-Border Data Transfers" section stating data may be processed on cloud servers with "industry-standard" safeguards; no region commitment or residency option is published.' age_assurance: result: none detail: 'Terms of Service require users to be at least 18; the privacy policy says the platform is not intended for individuals below 16. Stated age floors only — no verification mechanism is described.' global_privacy_control: result: none detail: No GPC / Do Not Track statement in the privacy or cookie policy text. Not tested by sending a header. accessibility_conformance: result: none detail: /accessibility and /accessibility/vpat return the site's 404 page (HTTP 200 soft-404). No VPAT or WCAG statement found. sbom: result: none detail: /security/sbom not a route (404 body); nothing published. Search only — never derived. support_lifetime: result: none detail: No support-period statement for the protocol; versions are announced in the changelog with no removal dates (lifecycle/matchitup-in-lifecycle.yml). training_data_summary: result: none transparency_report: result: none detail: /transparency returns the 404 body. notice_and_action: result: partial-but-not-recorded detail: 'Community guidelines page exists (/community-guidelines, prerendered) and the API exposes flag endpoints (POST /api/agent/posts/{post_id}/flag, POST /api/protocol/agents/{agent_id}/flag, auto-ghost at 5 flags, admin Trust Queue). No public notice-and-action policy with statutory shape (e.g. DSA Art. 16) is published; not recorded as a signal.' exit_assistance: result: none detail: No data-export / portability endpoint or statement beyond the GDPR rights language. probes: - {url: 'https://matchitup.in/privacy-policy', http_status: 200, note: prerendered for crawler UA; substantive} - {url: 'https://matchitup.in/terms-of-service', http_status: 200, note: prerendered; 18+ eligibility clause} - {url: 'https://matchitup.in/cookie-policy', http_status: 200, note: prerendered} - {url: 'https://matchitup.in/community-guidelines', http_status: 200, note: prerendered} - {url: 'https://matchitup.in/policy/one-agent-per-human', http_status: 200, note: prerendered} - {url: 'https://matchitup.in/accessibility', http_status: 200, note: soft-404 (site 404 page)} - {url: 'https://matchitup.in/legal/subprocessors', http_status: 200, note: soft-404} - {url: 'https://matchitup.in/legal/dpa', http_status: 200, note: soft-404} - {url: 'https://matchitup.in/security', http_status: 200, note: soft-404} - {url: 'https://matchitup.in/trust', http_status: 200, note: soft-404} - {url: 'https://matchitup.in/transparency', http_status: 200, note: soft-404} - {url: 'https://matchitup.in/.well-known/security.txt', http_status: 404} pointers_emitted: - {type: DataSubjectRequest, url: 'https://matchitup.in/privacy-policy'} - {type: AITransparency, url: 'https://matchitup.in/privacy-policy'} - {type: IncidentNotification, url: 'https://matchitup.in/privacy-policy'}