RecruitSphere is a B2B hiring platform sold to organisations (each a "Customer") that use it to source, screen, interview, and hire candidates. Most personal data we process is provided by Customers, by their recruiters, or by candidates who apply to a Customer's jobs. We act as a data fiduciary for our own Customer account holders and as a data processor on behalf of Customers for the candidate data they bring into the platform.
1. Scope of this policy
This policy covers personal data we collect when you:
- Visit our marketing website at recruitsphere.space.
- Create or use a workspace inside the RecruitSphere application.
- Apply to a job posted by a Customer via a careers page powered by RecruitSphere, or take part in a screening conversation or assessment we host on a Customer's behalf.
- Email, call, or otherwise contact us about a sales, support, or pilot enquiry.
If you are a candidate, the organisation you are applying to is the primary controller of your data. This policy describes our role in that flow. For requests about your candidate profile, please contact the hiring organisation first.
2. Data we collect
2.1 Account and workspace data
When a Customer signs up, we collect name, work email, password hash, organisation name, role, country, and basic billing information.
2.2 Candidate data
When candidates apply to jobs hosted on RecruitSphere or when Customers upload candidate records, we process: name, contact details, resume or CV file, work history, education, skills, location, application answers, written and spoken interview responses, coding assessment submissions, AI screening scores, interviewer notes, and similar hiring artefacts.
2.3 Communications
If a Customer connects an inbox to RecruitSphere, we ingest and store the hiring-related email threads needed to keep candidate conversations in sync with the ATS. We do not read or index unrelated mailbox content.
2.4 Voice, video, and proctoring
Round-one AI interviews and proctored coding assessments may record voice, video, screen frames, and browser-tab focus events. Candidates are informed before recording starts and may decline, in which case the Customer's recruiter handles the step manually.
2.5 Telemetry and product analytics
We collect device, browser, IP, page, and feature-usage events to keep the product secure and to improve it. We log certain in-app actions to an internal Activity Log so recruiters and administrators can audit who did what inside their workspace.
2.6 Marketing site visitors
On the marketing website we collect basic page-view analytics and the contact form data you submit. See our Cookie Policy for details.
3. Why we process personal data
We use personal data to:
- Provide the RecruitSphere platform, including AI screening, scheduling, assessments, ATS workflows, and analytics.
- Authenticate users, secure accounts, prevent fraud and abuse, and meet our security obligations.
- Send transactional messages such as password resets, interview invites, assessment links, and pilot status updates.
- Improve the product, debug issues, and develop new features. Where we use product data to train or fine-tune our own models, we do so on aggregated or de-identified data, or with the Customer's explicit instruction.
- Run our business, including invoicing, accounting, and tax compliance.
- Comply with applicable law and respond to lawful requests from authorities.
4. Legal basis
Under the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), we process data on the lawful bases of consent and certain "legitimate uses", including performance of a contract, employment-related processing on behalf of Customers, and compliance with law. Where the EU General Data Protection Regulation applies, we rely on contract performance, legitimate interests, and consent, as appropriate.
6. AI features and model training
RecruitSphere uses AI to screen resumes, conduct round-one interviews, grade assessments, and suggest recruiter actions. These features rely on a mix of our own models and selected third-party model providers listed in our subprocessor list.
We do not use Customer data to train foundational models of third-party providers, except where the provider's enterprise terms with us already prohibit such training by default. We may use de-identified, aggregated signals from product usage to improve our own ranking, retrieval, and grading models. A Customer can opt out of any product-improvement use of its workspace data by writing to privacy@recruitsphere.space.
AI outputs (screening scores, interview summaries, assessment grades) are advisory. A human recruiter must make the final shortlisting and hiring decisions. RecruitSphere is not designed to make automated decisions that produce legal or similarly significant effects without human review.
7. How long we keep data
We retain personal data for as long as a Customer's workspace is active and for a reasonable period afterwards for backup, audit, and legal-defence purposes. Default retention windows are:
| Data type | Default retention |
|---|---|
| Active workspace and candidate records | Lifetime of the Customer subscription |
| Workspace data after termination | 30 days, then deleted from production |
| Encrypted backups | Up to 90 days |
| Interview and assessment recordings | 12 months unless Customer sets a shorter window |
| Marketing site analytics | 13 months |
| Billing and tax records | As required by Indian tax law (typically 8 years) |
A Customer can configure shorter retention for assessments, recordings, and candidate archives from inside the workspace.
8. Security
We use the safeguards described in our Security overview. In short: encryption in transit (TLS 1.2+) and at rest, scoped role-based access, short-lived credentials for backend services, audited admin actions, principle-of-least-privilege for our team, and regular vulnerability scanning. Despite our best efforts, no system is perfectly secure. We will notify Customers and, where required, regulators and individuals, of a personal data breach as required by applicable law.
9. International transfers
Customer data is stored primarily in data centres operated by our cloud providers in India. Some subprocessors (for example, certain AI model providers) may process data in the United States or the European Union. We rely on the contractual and technical safeguards offered by these providers, including Standard Contractual Clauses where the GDPR applies, and on the cross-border transfer provisions of the DPDP Act once notified by the Government of India.
10. Your rights
Subject to applicable law, you can ask us to access, correct, update, or delete your personal data, withdraw consent, or receive a copy in a portable format. To exercise any of these rights:
- If you applied to a job through RecruitSphere, contact the hiring organisation first. We will support them in handling your request.
- If you have a RecruitSphere account, use the account settings inside the application, or write to privacy@recruitsphere.space.
- For grievances or DPDP Act requests addressed to a Data Protection Officer, write to grievance@recruitsphere.space or to our Privacy & Grievance Officer, RecruitSphere at the registered address below.
We respond within 30 days, and earlier where the law requires it. If you are not satisfied with our response, you can complain to the Data Protection Board of India.
11. Children
RecruitSphere is built for organisational hiring. We do not knowingly collect data from children under 18. If you believe a child has provided data to us, please contact privacy@recruitsphere.space and we will delete it.
12. Changes to this policy
We will update this policy from time to time. We will post the new version here and update the "Last updated" date. For material changes, we will notify Customers in-app or by email at least 15 days before the change takes effect, unless the change is required by law to take effect sooner.
13. Contact us
Darwix AI Technologies
Bengaluru, Karnataka, India
Email: privacy@recruitsphere.space
Grievance Officer: grievance@recruitsphere.space
Reach our legal and privacy team at legal@recruitsphere.space. For data protection and DPDP Act requests, write to grievance@recruitsphere.space.