DRAFT — review before launch

Privacy Policy

This is a draft template. It must be reviewed by legal counsel and updated to match the implemented data practices before launch.

About this draft

This draft describes the contact and recruitment features of M2K Global. It is not a final privacy policy. The website provides a contact form and, for open roles, an application form with a PDF resume upload.

Contact enquiries

The contact form requests a name, email address, optional phone number and organization, service interest, and an enquiry message. The purpose is to receive and respond to the enquiry. A privacy-consent checkbox is required.

Recruitment applications

Applications request the selected role, name, email address, optional phone number, LinkedIn URL and cover message, and a PDF resume. A privacy-consent checkbox is required. The intended purpose is to review an application and communicate about the role.

Storage, delivery and retention

Submissions are stored in Supabase Postgres. Resumes are stored in a private Supabase Storage bucket with generated keys. The server generates resume download links that expire within ten minutes. Email notifications are attempted after a submission is stored. In development, notification summaries are logged instead of emailing; production email requires a configured SMTP provider. Request identifiers and diagnostic information support operation of the service. Temporary upload files are removed after validation. Access responsibilities, production email providers, retention/deletion periods and the process for privacy requests must be confirmed before public launch.

Contacting us directly

If you choose to contact us by email or telephone, that communication takes place outside the website forms. The final policy must explain the actual handling of those communications.

Questions

Contact M2K Global at inquiry@m2kglobal.com. Requests and the applicable process should be described in the final reviewed policy.

Before publication

Legal counsel must review this template against the actual services, providers, applicable requirements and data-handling procedures. Do not use this draft as a statement of completed compliance.