Privacy notice
We process personal data in line with applicable Indian law, including the Information Technology Act, 2000, the SPDI Rules, 2011, and we align our practices with the Digital Personal Data Protection Act, 2023 (DPDP Act) as rules and enforcement become fully operational. This section explains what we collect, why, your rights as a Data Principal, and how you can reach us about your data.
We act as the organisation responsible for personal data collected through this Site. Our privacy and grievance contact is [email protected].
What personal data we collect
Depending on how you use the Site, we may collect:
- Identity and contact details (such as name, email, phone, city, company name)
- Enquiry or application content (messages, skills, interest areas, portfolio links)
- Files you choose to upload or link (such as a CV or resume)
- Technical and usage data (such as browser type, device type, pages visited, IP-related logs needed for security, abuse prevention, and basic analytics)
- Cookie or similar technology data, as described below
Under the SPDI Rules, sensitive personal data or information can include passwords, financial information, health conditions, sexual orientation, medical records, biometric information, and certain other categories when collected. We do not intentionally collect sensitive personal data through this Site unless you choose to share it in free-text fields or we expressly request it for a formal engagement under separate notice. Please avoid sending passwords, Aadhaar or other government ID numbers, full bank details, or health data through website forms unless we specifically request them through a secure channel.
Purpose, notice, and consent (DPDP / SPDI alignment)
We process personal data only for clear, stated purposes, including:
- Responding to enquiries and providing information about our services
- Reviewing join applications and related recruitment communication
- Operating, securing, and improving the Site (including fraud and abuse prevention)
- Meeting legal, regulatory, or contractual obligations
- Where you have opted in, limited follow-up about services you asked about
Consistent with notice-and-consent expectations under the SPDI Rules and consent / purpose-limitation principles under the DPDP Act:
- We tell you what we collect and why (this Policy and form labels)
- We seek free, specific, informed, unconditional, and clear consent where consent is the lawful ground (for example, accepting this Policy before submitting a form)
- We do not use personal data for a purpose that is incompatible with what you were told, without a fresh lawful ground
- You may withdraw consent for future processing by emailing us, subject to legal limits. Withdrawal does not affect processing already lawfully completed
We may also process data where Indian law permits or requires it without fresh consent (for example, compliance with a court order, or employment-related records after you become an engaged team member under separate terms).
Children’s data
Our services are directed at organisations and adult professionals. We do not knowingly offer services that require processing personal data of children (as defined under the DPDP Act) through this Site. If you believe a child has submitted personal data to us, contact [email protected] and we will take reasonable steps to delete it where appropriate.
Your rights as a Data Principal
Subject to applicable law (including the DPDP Act as it applies and SPDI Rules where relevant), you may request to:
- Access a summary of personal data we hold about you and the processing activities, where the law allows
- Correct incomplete or inaccurate personal data
- Erase personal data that is no longer necessary for the stated purpose, or where you withdraw consent and no other lawful ground applies
- Withdraw consent where processing is based on consent
- Nominate (where the DPDP Act provides) a person to exercise rights on your behalf in the event of death or incapacity, once such mechanisms are operational for our processing
- Raise a grievance about how we handle your personal data (see Grievance section)
To exercise these rights, email [email protected] with enough detail for us to verify your identity and respond. We will aim to acknowledge and address requests within a reasonable time, and in any event within timelines required by law once fully applicable. We may refuse or limit a request only where the law allows (for example, legal hold, overlapping rights of others, or inability to verify the requester).
Security safeguards (IT Act / SPDI / DPDP)
We use reasonable security practices and procedures appropriate to the nature of the data and our size of operations, consistent with expectations under the IT Act, SPDI Rules, and DPDP security obligations. Measures may include access controls, careful handling of form submissions, encrypted transport (HTTPS), security-minded hosting, and internal need-to-know practices.
No method of transmission over the internet is fully secure; you share information at your own residual risk. If we become aware of a personal data breach that requires notice under applicable law, we will take appropriate steps to investigate, contain, and communicate to affected individuals and/or authorities as required.
Sharing with service providers and disclosures
We do not sell personal information. We may share data with trusted service providers who help us run the Site or communicate with you (for example, email, hosting, analytics, or form delivery tools), only as needed for those services and under confidentiality and purpose limitations. Under the DPDP framework, such parties may act as Data Processors processing data on our instructions.
We may also disclose information if required by Indian law, court order, government direction, or to protect rights, safety, or security of persons or systems.
Storage and cross-border transfers
Your information may be processed on systems located in India or in other countries where our service providers operate. Under the DPDP Act, cross-border transfer of personal data is permitted except to countries or territories restricted by the Central Government. We will not transfer personal data to any country or territory that is prohibited by law or government notification. Where data is processed outside India by service providers, we take contractual and practical steps consistent with applicable Indian law for the purposes described in this Policy.
Cookies and similar technologies
The Site may use cookies or similar technologies that are essential for operation, security, and preference memory (for example, theme choice stored locally). We may use limited analytics or measurement tools (including through Google Tag Manager where configured) to understand how the Site is used.
- Essential cookies / storage: needed for basic function and security; these do not require marketing-style consent
- Analytics / non-essential: where personal data is processed beyond pure site operation, we seek to provide clear notice and obtain appropriate consent under applicable law
You can control or delete cookies through your browser settings. Disabling certain cookies may affect how some parts of the Site work. For more on browser controls, use your browser’s help documentation.
How long we keep personal data
We keep personal data only as long as needed for the purposes described above (for example, responding to an enquiry or reviewing an application), or as required by law, dispute resolution, tax, or legitimate business record-keeping. This follows purpose-limitation and storage-limitation principles under the DPDP Act and good practice under the SPDI Rules. When data is no longer needed, we delete or anonymise it using reasonable methods.