Privacy Policy

Effective date: 1 May 2026  ·  Last updated: 18 August 2026

1. Introduction

Hyrefox Consultants Limited (CIN: U74999RJ2018PTC061025, GSTIN: 08AAECH5205M1ZH) ("Company", "we", "us", "our") operates the Easyhyre recruitment marketplace platform ("Platform"). This Privacy Policy explains how we collect, use, disclose, store, and protect personal data in connection with the Platform, and describes the rights available to individuals whose data we process.

This Policy applies to all users of the Platform, including recruitment agency administrators and recruiters ("Agency Users"), vendor recruiters ("Vendor Users"), employer representatives ("Employers"), and candidates seeking employment ("Candidates").

We are committed to complying with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and associated rules, and, where applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR"). Where users are located in the European Economic Area or United Kingdom, the GDPR or UK GDPR applies in addition to Indian law.

By using the Platform, you acknowledge that you have read and understood this Policy. Please also read our Terms of Service.

2. Data Controller

For the purposes of applicable data protection law, the data controller is:

Grievance Officer

Ritika Bagga

Hyrefox Consultants Limited (CIN: U74999RJ2018PTC061025)

828A, Frontier Colony, Adarsh Nagar, Jaipur, Rajasthan – 302004

Email: [email protected]

General enquiries: [email protected]

We aim to acknowledge data-related grievances within 48 hours and resolve them within 30 days.

Where Agency Users process Candidate Data through the Platform for their own purposes (such as managing a talent pool), the Agency User acts as a separate data controller in respect of that processing. The Company acts as a data processor on the Agency User's behalf with respect to the Platform's technical hosting and storage functions.

3. Personal Data We Collect

3.1 Agency and Vendor Users

  • Name, job title, business email address, and phone number;
  • Company name, address, GSTIN, PAN, and KYC documents;
  • Account credentials (email; passwords are stored as salted hashes);
  • Transaction records, invoices, and payment history;
  • Usage data and activity logs within the Platform.

3.2 Candidates

  • Full name, email address, and phone number (including WhatsApp number);
  • Resume / CV, employment history, educational qualifications, and skills;
  • Current and expected salary, notice period, and location preferences;
  • Application data including status, notes, interview feedback, and offer details;
  • AI-generated screening scores, strengths, areas for improvement, and interview question responses;
  • Photographs, where included in a resume or profile.

3.3 Technical and Usage Data

  • IP address, browser type and version, device type, and operating system;
  • Pages visited, features used, click-stream data, and session duration;
  • Cookies and similar tracking technologies (see Section 9);
  • Error reports and diagnostic data automatically submitted by the Platform.

3.4 Communications Data

  • Messages sent through the Platform's integrated WhatsApp Business API channel;
  • Feedback submissions, support tickets, and other correspondence with us.

3.5 Connected Mailbox Data (Agency and Vendor Users only)

Where a recruiter chooses to connect their own Google account so that invitations are sent from their own mailbox, we additionally hold the email address of the connected mailbox and encrypted OAuth tokens issued by Google. Section 14 sets out in full what we request, what we store, how it is used, and how to revoke it.

4. Purposes and Legal Bases for Processing

We process personal data only for the purposes and on the legal bases set out below. Under the DPDP Act, our primary legal basis is the consent of the Data Principal or the legitimate uses specified under the Act. Under the GDPR, applicable bases include consent, contract, legitimate interests, and legal obligation.

PurposeLegal Basis (GDPR / DPDP)
Providing and operating the PlatformPerformance of contract / Legitimate use
Account registration and managementPerformance of contract / Consent
AI-powered candidate screeningLegitimate interests / Consent of Candidate
WhatsApp recruitment communicationsConsent of Candidate
Sending recruitment email from a recruiter’s connected mailboxConsent of the connecting recruiter / Performance of contract
Payment processing and invoicingPerformance of contract / Legal obligation
Preventing fraud and ensuring securityLegitimate interests / Legal obligation
Analytics and Platform improvementLegitimate interests
Responding to support enquiriesPerformance of contract / Legitimate interests
Compliance with legal obligationsLegal obligation
Sending product updates and newslettersConsent (may be withdrawn at any time)

5. Data Sharing and Disclosure

We do not sell personal data. We may share personal data in the following circumstances:

5.1 Within the Platform Ecosystem

Candidate Data submitted by a Vendor User will be visible to the Agency User who assigned the vacancy to that Vendor. Agency Users may share read-only candidate snapshots with Employers via unique public links (see our Terms of Service, clause 8). Agency Users are responsible for ensuring such sharing complies with applicable data protection law.

5.2 Service Providers

We engage carefully selected third-party processors to provide infrastructure, analytics, communications, and AI services. These processors act only on our documented instructions and are bound by data processing agreements. Current categories include:

  • Cloud infrastructure and hosting providers;
  • AI/ML model providers (for candidate screening features);
  • WhatsApp Business API service providers;
  • Payment gateways;
  • Email service providers, including Google LLC where a recruiter has connected their own Google account (see Section 14);
  • Error monitoring and analytics services.

5.3 Legal Requirements

We may disclose personal data where required to do so by law, court order, or in response to valid demands from government or regulatory authorities, or where we believe disclosure is necessary to prevent harm or protect our legal rights.

5.4 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to the acquiring entity, subject to the same level of protection as described in this Policy.

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal obligations, or to resolve disputes and enforce our agreements. Our standard retention periods are:

  • Active accounts: for the duration of the account;
  • Candidate Data (active application): until the application is concluded plus 24 months, to allow legitimate re-engagement;
  • Candidate Data (rejected or withdrawn): 12 months from rejection or withdrawal, unless a longer period is required by law or the Candidate consents to a talent-pool hold;
  • Financial and invoice records: 8 years from the date of the transaction, as required by Indian taxation law;
  • Security and access logs: 90 days;
  • Deleted accounts: up to 30 days to allow for recovery, then permanently deleted unless a longer period is required for legal proceedings.

After the applicable retention period, data is securely deleted or anonymised.

7. Your Rights

Subject to applicable law, you have the following rights in relation to your personal data. To exercise any of these rights, please contact our Grievance Officer (see Section 11).

7.1 Right of Access

You may request confirmation of whether we process personal data about you, and a copy of that data along with information about how it is used.

7.2 Right to Correction

You may request correction of inaccurate or incomplete personal data. Many fields are editable directly through your account settings.

7.3 Right to Erasure

You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent and there is no other lawful basis for processing. This right is subject to overriding legal obligations (e.g., retention required by tax law).

7.4 Right to Withdraw Consent

Where processing is based on your consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

7.5 Right to Data Portability

Where technically feasible and required by applicable law, you may request a copy of your personal data in a structured, machine-readable format.

7.6 Right to Nominate

Under the DPDP Act, you may nominate an individual to exercise your privacy rights on your behalf in the event of your death or incapacity.

7.7 Right to Object / Restrict

Under the GDPR, EEA/UK residents may object to processing based on legitimate interests, and may request restriction of processing in certain circumstances.

We will respond to verified requests within 30 days. Complex requests may require up to 60 days; we will notify you of any extension. We may need to verify your identity before processing a request.

8. International Data Transfers

The Platform is primarily hosted in India. Where we transfer personal data to service providers located outside India, we ensure that appropriate safeguards are in place in accordance with the DPDP Act and, where applicable, the GDPR (such as Standard Contractual Clauses approved by the European Commission, or adequacy decisions). A list of countries to which data may be transferred is available on request.

9. Cookies and Tracking Technologies

We use cookies and similar technologies to operate the Platform, remember your preferences, analyse usage, and improve our services. The types of cookies we use include:

  • Strictly necessary cookies: Required for authentication and core Platform functionality. These cannot be disabled.
  • Functional cookies: Store your preferences such as theme and language settings.
  • Analytics cookies: Help us understand how the Platform is used so we can improve it.

You can control non-essential cookies through your browser settings. Disabling cookies may affect the functionality of the Platform. We do not currently use cookies for advertising or cross-site tracking.

10. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or alteration. Measures include encryption of data in transit (TLS) and at rest, hashed credential storage, access controls, regular security assessments, and incident response procedures.

No transmission over the Internet is 100% secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.

In the event of a personal data breach that is likely to result in risk to individuals, we will notify the relevant authority and affected individuals as required by applicable law.

11. Grievance Mechanism and Contact

In accordance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the DPDP Act, we have appointed a Grievance Officer to address data-related concerns:

Grievance Officer

Ritika Bagga

Hyrefox Consultants Limited (CIN: U74999RJ2018PTC061025)

828A, Frontier Colony, Adarsh Nagar, Jaipur, Rajasthan – 302004

Email: [email protected]

General enquiries: [email protected]

We aim to acknowledge data-related grievances within 48 hours and resolve them within 30 days.

If you are located in the European Economic Area or the United Kingdom and are not satisfied with our response, you may lodge a complaint with your local data protection supervisory authority.

12. Children

The Platform is intended for use by individuals aged 18 or above. We do not knowingly collect personal data from children under 18 years of age. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it promptly.

14. Connected Google Accounts and Google User Data

This Section applies where an Agency User or Vendor User (each, a "Recruiter") chooses to connect their own Google account so that recruitment invitations and outreach emails are sent from their own mailbox instead of a shared Easyhyre address. Connecting a Google account is entirely optional, is never required in order to use the Platform, and may be undone at any time. Candidates are never asked to connect a Google account for this purpose.

14.1 Permissions we request

When a Recruiter connects a Google account, we request exactly two permissions:

  • Send email on your behalf (https://www.googleapis.com/auth/gmail.send) — used solely to deliver the recruitment messages the Recruiter composes or triggers within the Platform. This is a send-only permission. It does not allow us to read, search, browse, download, modify, or delete any message in the mailbox, and we do not do so.
  • Your Google account email address (https://www.googleapis.com/auth/userinfo.email) — used to display which mailbox is connected and to set the sender address on outgoing mail.

We do not request, and cannot obtain, access to Google Contacts, Google Calendar, Google Drive, or any other Google service.

14.2 Google user data we store

  • The email address of the connected mailbox;
  • The OAuth access token and refresh token issued by Google, each encrypted at rest with AES-256-GCM using a unique initialisation vector per write;
  • The token expiry time and the connection status (connected, or expired and needing reconnection). We hold these only while a mailbox is connected — see Section 14.5;
  • For each message sent, a delivery record consisting of the recipient, timestamp, delivery status and the Google message identifier. We do not store the body or subject of the messages sent through a connected mailbox.

14.3 How we use it

Google user data obtained through these permissions is used for one purpose only: to send the recruitment emails that the Recruiter has composed or triggered, and to show the Recruiter which mailbox is connected and whether it is working. We do not use it for advertising, we do not sell it, and we do not use it to develop, improve, or train generalised artificial intelligence or machine-learning models.

The Platform uses third-party artificial-intelligence providers for other features, such as resume parsing and interview scoring. Google user data obtained through the permissions above is never transferred to those providers, and is never used to develop, improve or train any AI or machine-learning model, whether generalised or personalised. It is also never provided to data brokers or to any information-resale service.

14.4 Limited Use commitment

Easyhyre's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, and consistent with those requirements:

  • We do not transfer Google user data to third parties except as necessary to provide or improve this feature, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to affected users;
  • We do not use Google user data for serving advertisements of any kind;
  • We do not allow humans to read Google user data unless we have the Recruiter's explicit consent for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymised for internal operations.

14.5 Withdrawing access and deletion of Google user data

A Recruiter may disconnect their mailbox at any time from Settings → Outreach within the Platform. On disconnection we ask Google to revoke the refresh token and then delete the stored credential from our database outright — the access token, the refresh token and the connected email address are all removed, not merely disabled. Nothing is retained that could be used to access the mailbox, and re-connecting later creates an entirely new record.

Access may also be revoked directly from your Google account permissions page, which takes effect immediately regardless of any action on our side. Because Google does not notify us when this happens, we discover it the next time the mailbox is used; at that point the stored tokens are erased and the mailbox is marked as needing reconnection. The mailbox address is kept in that state only so we can tell the Recruiter which account to reconnect, and it too is removed on disconnection.

Delivery records described in Section 14.2 — recipient, timestamp and delivery status, never message content — are business records of invitations we sent on the Recruiter's behalf and are retained under Section 6. All of it is erased when the Recruiter's Easyhyre account is deleted, or sooner on request to our Grievance Officer under Section 7.3.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or by posting a prominent notice on the Platform at least 30 days before the changes take effect. The "Last updated" date at the top of this Policy reflects the most recent revision. Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.