- The Section 43A of the Information Technology Act (ITA), 2000;
- The Rule 4 of the Information Technology (Reasonable Security Practices and - Procedures and Sensitive Personal Data or Information) Rules, 2011;
- The Rule 3(1) of the Information Technology (Intermediaries Guidelines) Rules, 2011
1. HOW WE HANDLE YOUR DATA
1.1 Information We Collect
Information from website browsers
What do we collect?
If you are browsing ourWebsite, we collect same basic information that many other websites collect. We also use common internet technologies, such as web server logs, etc.. This is information we collect from everyone who visits our Website, whether they have a registered account or not.
The information that we collect about all our visitors to our Website includes the visitor’s browser type, referring site, language preference, and the date and time of every visitor request. We also collect potentially personally-identifying information like the Internet Protocol (IP) address.
Reason for Collection:
This is done to improve the visitor’s experience and provide them with better content and services to our current as well as any of our prospective customers based on their geography and the potential usage of our product and services.
Information from users uploading files
What do we collect?
If you login, upload file or source any candidate files using our Services, we collect your information such as email address, location, contact information, along with the details of the filename or file URL.
Reason for Collection:
We collect this information to provide our services to you. Without this information, we are unable to upload files andanalyze them to provide you with our service.
Information from users with accounts
What do we collect?
If you create an account on our Website, we willrequire some basic information at the time of account creation/registering. You will have to create your own password, and we will ask you for your full name and your valid email address. We will also collect your billing details, including credit or debit card information (number, card name, expiry date and CVV), a billing address and for some customers a valid GSTnumber for their businesses. You will also have an option to either save the information or delete the information related to your credit or debit card information (card name, number, expiry and CVV) from the Website or Service.
Reason for Collection:
- We need this information in order to set up your account, and to provide services you have requested from our company.
- We also use your email address to identify you on Recru.in and send some important system and account notices to you, which are of importance. We do not use your email address for any marketing purposes unless you have specifically given us consent to do this. We do not share or sell your email address/addresses with any third parties sources.
People who reach out to us with inquiries
What do we collect?
If you contact us with any sales or support enquiry, we will collect the necessary information provided when you correspond with us, such as your Full name, your email address,your addressand your telephone number.
Reason for Collection:
We will also collect, store and use the kind of personal information as set out in the Section 1.1 (“Personal Information”) to deal with any enquiries or issues that you have about our Services, including any questions you might have about how we collect, use and store your Personal Information.
1.2 Information which We Do Not Collect from you We do not intentionally store or collect special categories of personal data, such as birth date, genetic data,religious information, or health information. Although Recru.in does not request or intentionally collect any such special categories of personal information, we realize that you may store this kind of information in your account, through the files that you may upload.
If you ask us to store or upload any files which contain special categories of personal information on our servers, which are located in India.We will only do this on your instructions and consent, as a data processor and service provider and all in accordance with our Terms of Service with you. You are the controller of this data that you share and you must ensure that you have a legal permission to share this data with our company.
1.3 How do our company Use Your Information and our Legal Basis for doing this: We use the information that you provide, including your Personal Information, to help us in a number of ways and we have also set out our legal basis for processing this information. It is as follows:
- To update, provide, improve and maintain the Services that we offer to you
- This use of yourPersonal data in this way is necessary for us to perform our necessary obligations to provide the you with our Services.
- In order to communicate with you by replying to your requests and comments, Support and sales enquiries.
- In case you contact our support team we might use the provided information to help us in responding to your enquiry. Our use of your Personal Data in this way is needed to perform our customer service obligations that we have towards you. If we do not have any contract with you, we may process all your Personal Information for these purposes where it is in our legitimate interests to do so.
For billing, account management and other administrative matters
Recru.in may need to contact you for account management, invoicing and similar reasons and for this, we use account data to administer accounts and keep track of billing. Our use of your Personal Information in this way is necessary to perform our obligations towards you.
As required by the applicable law, legal process or regulations
We may use your information, including your Personal Information, to comply with court orders and/or similar legal or regulatory obligations which apply to our company. This might include where we reasonably consider it is in our legitimate interests or we are legally required to do so.
To investigate and help prevent abuse or any security issues
We might use the information such as your IP address to help us prevent any abuse of the Services that we provide and investigate any case of potential unauthorized use of our Services or any other security breaches. In such circumstances, we believe that we have a legitimate interest in handling your data.
If we rely on our legitimate interests for using any of your Personal Information, we will undertake a balancing test in order to ensure that our legitimate interests are not outweighed by your interests or any fundamental rights which require protection of Personal Information. You can ask us for information regarding this balancing test by using the contact details of our company at section 5.7.
We also use and collect data which is aggregated for certain business purposes, such as creating aggregate statistics. However, no individual will be identifiable from these anonymised details.
Information which we may have access to:
Apart from the Personal Information, we do not collect any other information from our users. However, where you upload your resumes, or any other documents in relation to job posting or interview, we may have access to the information which is contained in such resume or other documents. You hereby agree and give consent to our access to all such information. You are entitled to delete any information, which you feel like, at your sole discretion.
1.4 Information collected inside Recru.in from Google. Recru.in requires Google authorization in order to get access to user email.These emails are also scanned to find a valid attachment (potential resume), once the process is completed Recru.in only keeps the attachment and the email id of the email account used for scanning through email, whose permission is granted by the user.
2. HOW WE SHARE THE DATA
2.1 Sharing Your Information
We do not share, rent, trade or sell your email address with any third parties for commercial purposes.
List of third party vendors with whom we will share your information:
- Godaddy Inc who provides us with domain name services;
- Google Suite, who provide us with customer relationship management (CRM) and customer service tools.
- Amazon Web Services and Digital Ocean, who provide us with server hosting and content distribution networks (CDN’s) services
- With ThomaBravo|MailGun who provide us with email sending services.
When we transfer your data to any of our vendors, we remain responsible for your data. We also try to ensure that any third parties with whom we are sharing your Personal Information with, are limited in their ability to use your Personal Information for any purpose other than to provide services for our company.
We may share the Personal Information where it is in our legitimate interests to do so.In order to run, grow and develop our business and if we are involved in any merger, sale, or acquisition. If any change of ownership takes place, we will ensure that it will preserve the confidentiality of your Personal Information, and we will notify you on our Website or by email before any data transfer.
2.2 Third Party Advertising
We do not host any third party advertising at Recru.in. None of your personal or user data is shared with any of third party advertising.
2.3 Legal Disclosures
Recru.in may disclose any personally-identifying information or any other information thatwe collect about you in response to a validcourt order, subpoena, warrant, or any such similar government order, and/orin cases when we believe in good faith that the disclosure is necessary to protect our property or rights. This may include exchanging Personal Information with other organisations for the purpose of credit risk reduction and fraud protection.
We will also disclose any/all ofyour Personal Information to third parties in order to apply or enforce our terms and conditions or any other agreement to protect our rights or the rights of a third party, to protect the safety of any person or to prevent any illegal activity.
3. HOW DO WE MANAGE DATA
Recru.in gives priority to the security of data, and we work hard to safeguard any information from misuse, loss and prevent any unauthorized access. We take all necessary precautions to safeguard the secrecy of your Personal Information, including through the use of appropriate organisational and technical measures. These measures take into account the sensitivity of data that we collect, process and store, a s well as the current state of technology.
Given the nature of communications and information processing technology, Recru.in cannot assure that data, during transmission or when stored on our systems or otherwise in our care, will be completely safe from intrusion by others, but we try our best to safeguard it. We will use strict measures and security features to prevent unauthorised access to your Personal Information.
As a minimum we take the following measures to secure your data:
- Physical Security: Recru.in infrastructure is only hosted in data centres which fulfill rigorous security standards. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilising video surveillance, intrusion detection systems, and other electronic means.
- Data Transfer Integrity: All traffic to and from Recru.in servers is secured by a Secure Socket Layer (SSL), and secured using an AES 256-bit SSL certificate. This will ensure that data sent between your systems and ours is encrypted using military standard encryption.
- Password Encryption: Recru.in user account passwords are stored in our database after being salted and hashed using the encryption algorithms.
- Firewalls: Recru.in enforces control for access at the network level to the infrastructure through different firewall technologies that ensure different components of its systems are logically isolated from one another.
- Operational Access Controls: Recru.in employees require access to production services for operational purpose. We employ a number of authentication mechanisms to ensure that production systems are not accessed only by any unauthorized members and only authorized access is allowed.
- Software Updates: Recru.in regularly updates software patches to production infrastructure to ensure a strong security posture to known software vulnerabilities.
3.2 Data Retention and Deletion
If you have an account with Recru.in
We store your Personal Information for as long as your account is active or as needed to provide you with requested Services. Upon deactivation of your account we permanently remove any files associated with your account in compliance with our Terms of Service.
We may continue to store data such as contact email, phone number, billing & invoice details, payment, late-payment or non-payment information or any other such related information of the customer to keep record, audit, fraud and reporting in accordance with the applicable laws. For instance, we don't delete inactive user accounts automatically , so unless customer asks us to permanently delete the account we retain some account information to enable the customer return and use our Services conviniently in future.
If you do not register an account with Recru.in
We will store the files you upload or source using our services, in their converted format on our systems for not more than 180 days post upload. After this time they will be permanently deleted from the storage systems.
We will store Personal Information such as your IP address, email address, contact information and browser details for not more than 180 days. Post this time, we will permanently delete your browser data and anonymise your IP address and email address to ensure we can no longer personally identify you.
3.3 International Data Transfers
Recru.in may transfer your personal data to countries other than the one in which you live.
- in the case of the US based entities, entering into European Commission approved standard contractual arrangements with them, or ensuring they have signed up to the EU-US Privacy Shield (see further https://www.privacyshield.gov/welcome); or
- in the case of the entities based in other countries outside the EEA, entering into European Commission approved standard contractual arrangements with them.
Further details on steps we undergo to protect your Personal Information, in these cases, are made available to you on request by contacting us through email at [email protected] at any point of time.
4. YOUR RIGHTS
If you have a user account for the Services you might review and make changes to any of the personal data you have supplied to us in your profile. If you do not have a user account, or in case you have questions about the account information or any other personal data please reach out to us by email at [email protected].
Individuals located in countries like the European Economic Area and Switzerland, have some statutory rights with regards to their personal data. While some of these apply generally, certain rights apply specifically in limited circumstances. We have described these rights below.
Please note that, before taking further action on your request, we may ask you to verify your identity. Also your request and choices may be constrained in certain cases: for e.g., if fulfilling your request reveals any information about another person, or if you ask to delete information for which we are legally permitted or have compelling legitimate interests to keep.
4.1 Right to be Informed
You have the right to be provided with information on the data that we store, our various data processing activities and if we transfer personal data outside of the EEA, along with the methods through which we safeguard such data.
4.2 Right to Access
In some jurisdictions, applicable law may allow you to request copies of your Personal Information held by us.
4.3 Right to Rectification
You have the right to ask us to rectify any inaccurate or out of date or missing Personal Information concerning you (and which cannot be updated by yourself within the offered Services).
4.4 Right to Erasure
We may retain any Personal Information for as long as is necessary for performance of the agreed contract between you and us and to comply with our legal obligations. In case you no longer want us to use your information to provide the Services to you, you might request us to remove your Personal Information and (if you have one) delete your user account. Please note the following if you request the deletion of your Personal Information:
- We may still hold back some of your Personal Information as deemed necessary for our legitimate business interests , for identification purposes, and in the interest of prevention of any fraud, etc..
- We may also retain and use your Personal Information to the extent necessary to comply with our legal obligations.
- Because we maintain the Recru.in Services to safeguard from accidental or malicious data loss or destruction, residual copies of your Personal Information may not be deleted from our backup systems for a limited time period.
4.5 Right to Object / Restrict Processing
Under some jurisdictions, applicable law may entitle you to request Recru.in to not process your Personal Information for some specific purposes where such processing is based on our or another party's legitimate interests. If you object to such processing Recru.in will no longer process any of your Personal Information for these purposes except we can showcase compelling legitimate grounds for such processing or if such processing is required for the establishment, exercise or in defence of the legal claims.
4.6 Right to Data Portability
You may be entitled to request for the copies of your Personal Information provided to us, in a structured, commonly used, in machine-readable format and/or request us to transmit the information to another service provider (if technically feasible). This right only applies where we use the Personal Information as per your consent or performance of a binding contract; and where our use of your information is carried out through automated means.
5. OTHER IMPORTANT INFORMATION
5.1 Data Processing Addendum
As long as we act as a data processor on your behalf in connection with the performance of our offered Services, we will enter into a distinct "Data Processing Addendum" with you. If required, you can find out more information on this Data Processing Addendum by emailing us at [email protected].
5.2 Age Limitations
Persons who are competent to contract within the meaning of the Indian Contract Act, 1872 shall be eligible to access, use or register on the Website and avail the offered Services. In an event that, as a minor you wish to use the Website and / or Services, such use shall be made available to you post the review of these mentioned Terms by your legal guardian or parent(s) and after them consenting to be bound by the Terms. Further, in the event that it is discovered that You are below the age of 18 (eighteen) years and the Terms have not been consented to by your legal guardian or parent(s) in prior, or if the details provided by you are false or not accurate, Recru.in shall not have the responsibility and shall not be held liable if the aforesaid eligibility criteria is not satisfied by you.
5.4 3rd Party Links And Third Party Integration
The Website / Services may host the links to 3rd party websites and their services ("3rd Party Links"). We have no control over any such Third Party Links, which are provided by the persons or companies other than us. We are not responsible for any of the collection or disclosure of your data / information or Personal Information by such companies or persons on such 3rd Party Links thereof.
Certain other features and integrations, including but not restricted to the infrastructure services, the communication integrations, the user visibility and the assessment services, background verification services ("3rd Party Integrations") are available to You through 3rd party platforms and the forums where applications are developed for their integration with the Service(s). These 3rd Party Integrations are governed as per their own terms and privacy policies and that You agree that We are not responsible for Your use of these 3rd Party Integrations where You make the choice to enable these Third Party Integrations and integrate them into Our Service(s). By enabling any Third Party Integrations, You understand and agree that We do not provide any warranties in any way whatsoever for Third Party Integrations and We are not liable for any of the damage or the loss caused or alleged to have been caused by or in connection with Your enablement, access or use of any of such Third Party Integrations, or Your reliance on the privacy practices, the data security processes any other policies and processes of such Third Party Integrations. You understand that We are not responsible for providing the technical support for any such Third Party Integrations and that We are not responsible for the data hosting and the data transfer practices followed by the providers of such Third Party Integrations. To this extent, You shall address any comments, queries, complaints or feedback about such Third Party Integrations to the developers or publishers of the resepective 3rd party as specified on such other platforms or the forums.
You agree and acknowledge that the 3rd Party Links and 3rd Party Integrations have their own privacy policies governing the collection, the storage,the transfer, the retention and / or the disclosure of your information and that you access or use such 3rd Party Links and 3rd Party Integrations at own risk.
5.6 Governing Law
5.7 Contacting Recru.in
14/144, 6th Floor, Ratan Esquire, Chunni Ganj, Kanpur, Uttar PradeshIndia- 208001