Legal
Privacy Policy
Effective 10 August 2026
This Privacy Policy explains how CENITPRO (Proprietor: Alok Kumar), operating HR Sight ('we', 'us', 'our'), collects, uses, discloses, and protects personal data through the Platform. It is written to align with the Digital Personal Data Protection Act, 2023 ('DPDPA') and the Information Technology Act, 2000. It applies to HR Users, Member Organizations, and Candidates alike.
1. Who this applies to and the roles involved
Under the DPDPA, HR Sight acts as the Data Fiduciary for personal data processed through the Platform, and you — whether an HR User or a Candidate — are the Data Principal. Where a Member Organization initiates a Verification Case about a Candidate, that organization is also a data fiduciary in its own right for the information it receives; this Policy covers HR Sight's handling of your data, not each Member Organization's independent obligations once it lawfully receives your data.
2. What we collect
From HR Users and Member Organizations
- Account details: name, work email, phone number, password (stored as a bcrypt hash, never in plain text).
- Organization details: legal name, display name, city, industry, and (for billing) GST/legal identity where provided.
- Payment-related information: transaction reference/UTR you submit, and an optional receipt or screenshot you upload — we never collect card, net-banking, or UPI PIN credentials, since all Membership payments are manual bank transfers you initiate from your own banking app or portal.
- Community activity: posts, comments, templates, resources, and event RSVPs you create or engage with.
From Candidates
Candidates only interact with HR Sight through a case-specific link. What is collected exists to let a Candidate declare their own information and let a Member Organization verify it with the Candidate's consent:
- Identity details: full name, date of birth, gender, father's/spouse's name, marital status, and a government identity document you choose to upload for verification.
- Contact details: phone number (OTP-verified) and email address.
- Declared history: employment records, education records, address history, and references you provide, plus any supporting documents you optionally attach to each.
- Criminal declaration: where a Verification Case requests it, a self-declaration of any criminal record, provided only with your explicit, separate consent.
- Consent records: what you agreed to share, with whom, and when — kept as part of the audit trail described in Section 6.
Collected automatically
Standard technical data needed to operate the Platform securely: IP address, browser/device information, and session/authentication cookies. We do not use third-party advertising or cross-site tracking cookies.
3. Why we collect it (purpose limitation)
We use personal data only for the purposes it was collected for, consistent with the DPDPA's purpose-limitation principle:
- To create and operate your account and your organization's presence on the Platform.
- To run the declare → consent → verify → respond → compare workflow that is the core of the Service.
- To confirm Membership payments, generate GST tax invoices, and administer renewals.
- To operate community features you choose to participate in (posts, comments, events, templates).
- To detect fraud, abuse, or violations of our Terms & Conditions.
- To send you service communications (verification-case updates, renewal/grace-period reminders, security notices) and, where you have not opted out, product updates.
- To comply with applicable law, including tax, audit, and grievance-redressal obligations.
4. Consent
Where the DPDPA requires consent as the basis for processing, we ask for it in a way that is free, specific, informed, unconditional, and unambiguous, with a clear affirmative act — never a pre-ticked box or bundled default. This applies with particular care to a Candidate's data:
Withdrawing consent is as easy as giving it: a Candidate can decline at the consent screen, or contact us using the details in Section 10 to request withdrawal of any consent already given, where the underlying processing is not otherwise required by law or an already-completed Verification Case record we are obliged to retain.
5. Retention
- Raw uploaded documents (identity proofs, education/employment certificates, address proofs, payment receipts) are automatically and permanently purged 45 days after the related Verification Case is closed, or 45 days after a Membership renewal is confirmed for payment receipts — by an automated process, not a manual step.
- Declared and verified field data(the comparison of what was declared vs. what was confirmed) is retained for as long as your account or your organization's account remains active, and for a reasonable period after closure to satisfy legal, tax, audit, and dispute-resolution requirements.
- Audit trail recordsof consent and state-changing actions are retained indefinitely in append-only form — this is a deliberate design choice (see Section 6) and is not user-erasable, consistent with the DPDPA's allowance for retention needed for legal compliance.
- Account data for HR Users and Member Organizations is retained while the account is active and deleted or anonymized within a reasonable period after a verified deletion request, net of the exceptions above.
6. Audit trail
Every state-changing action on the Platform — approvals, consent grants, payment confirmations, moderation decisions, and more — is written to an append-only audit log with no update or delete path. This exists specifically so that neither HR Sight staff nor any Member Organization can alter the record of what was consented to or what happened, and it is the mechanism that lets us honestly tell you exactly what was done with your data and when, if you ask.
7. Your rights as a Data Principal
Under the DPDPA, you have the right to:
- Access a summary of the personal data we hold about you and how it has been processed.
- Correct inaccurate or incomplete personal data, and update outdated data.
- Request erasure of personal data that is no longer necessary for the purpose it was collected, subject to the retention exceptions in Section 5.
- Withdraw consent at any time, as described in Section 4.
- Nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
- Register a grievance and have it addressed, as described in Section 10.
To exercise any of these rights, contact us using the details in Section 10. We will verify your identity before acting on a request, and respond within a reasonable time.
8. Disclosure to third parties
- To other Member Organizations: only Candidate data the Candidate has explicitly consented to share, for the specific Verification Case it was requested in.
- To service providers: infrastructure providers strictly necessary to operate the Platform — our database host (Neon), hosting provider (Vercel), file storage (Cloudflare R2), and transactional email provider (Zoho ZeptoMail) — each processing data solely on our instructions and under contractual confidentiality.
- For legal reasons: where required by law, court order, or a lawful request from a government or regulatory authority.
- We do not sell personal data, and we do not share it for third-party advertising or marketing purposes.
9. Cross-border data storage and transfer
Our infrastructure providers may process or store data outside India as part of their normal cloud operations. Consistent with the DPDPA's approach, we do not restrict transfer to any specific country except where the Central Government notifies restrictions; we have not identified any such restriction applicable to our current providers as of the effective date above, and we will revisit our provider choices if that changes.
10. Grievance Officer
In accordance with the DPDPA and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, our Grievance Officer is:
Alok Kumar
Grievance Officer, CENITPRO (HR Sight)
5/23, Netaji Nagar, Regent Park, Kolkata, West Bengal 700040, India
Email: care@hrsight.org
You may also reach us via our contact page. We will acknowledge grievances promptly and work to resolve them within a reasonable time.
11. Security
Data in transit is encrypted (TLS). Passwords are hashed with bcrypt, never stored in plain text. Uploaded documents are stored in access-controlled, private object storage — not publicly accessible — and served only via short-lived signed URLs to authorized parties. Access to organization data is governed by role-based permissions, and every state-changing action is recorded in the append-only audit trail described in Section 6. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Cookies
We use strictly necessary cookies for authentication and session management. We do not use third-party advertising or analytics cookies that track you across other websites.
13. Children's data
The Platform is intended for use by individuals aged 18 and above. We do not knowingly collect personal data from children. If you believe a child's data has been submitted to the Platform, contact us using the details in Section 10 and we will take appropriate action.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the Platform or by email where practicable, at least 15 days before taking effect. The "Effective" date at the top of this page reflects the latest revision.
15. Contact
For any privacy-related question or request, write to care@hrsight.org, reach us via our contact page, or write to our Grievance Officer at the address in Section 10.
Questions about this document?
Reach us through our contact form or email care@hrsight.org for data-related requests.
