Privacy Policy

Effective date: September 2025

RG Software Services, having its registered office at Plot No 28, H.No 8-3-1110/D, Kesava Nagar, Srinagar Colony, Hyderabad, Telangana, 500073, India (hereinafter referred to as "HRIA"/ "We"/ "us"/ "our"), on behalf of itself and its affiliates/group companies under the brand 'HRIA', operates the websites 'www.hria.io' and 'www.hria.in' and the application 'HRIA' including its constituent products HRIA Recruit, HRIA Core, HRIA Payroll and TalentstaQ (together referred to as "Platform"). This Privacy Policy (hereinafter referred to as "Policy") helps you in using/accessing the Platform, the Services therein, our website and all our products, service offerings and other related applications, and helps you understand the type of information we collect; the purpose for which the information is collected; how the information is used; the intended recipients of such information; when it might be disclosed; and how you can control the collection, correction and/or deletion of your information, and how the information is protected. We take protection and proper use of your information seriously and are committed to protecting such information in our possession. We advise you to read this Policy carefully prior to your access of the Platform, use of Services, or creation of an Account on the Platform, as the case may be. If you do not agree to this Policy, please do not access our Platform, use our Services, or create an Account on our Platform.

If we learn that we have collected Personal Information (defined below) from an individual who is under the age of 18 that was not provided under the supervision and verifiable consent of that minor's parent or lawful guardian, we will promptly delete such information. If you believe that we have collected Personal Information from someone under the age of 18 without such consent, please contact us at connect@hria.io.

This Policy is published and shall be construed in accordance with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and the Digital Personal Data Protection Act, 2023 ("DPDP Act"), together with any rules, regulations, and bye-laws made thereunder from time to time (collectively, "Applicable Laws"), to the extent we collect and process personal data as a business, Data Fiduciary and/or Data Processor operating in India.

HRIA's services are intended primarily for use by businesses ("Clients") for their recruitment, workforce, and payroll operations. Where the Services are made available to you through a Client (for example, because you are a candidate applying to a job posted by a Client, or an employee whose payroll the Client processes through HRIA), that Client is the Data Fiduciary/Controller of your Personal Information, and HRIA acts as a Data Processor on the Client's behalf and instructions. Your data privacy questions and requests to exercise your rights should, in the first instance, be directed to the relevant Client. If you are an individual who interacts with a Client using our Services, you may be directed to contact that Client for assistance with requests or questions relating to your Personal Information. HRIA is not responsible for a Client's own privacy or security practices, which may differ from this Policy. Clients are solely responsible for establishing their own policies for, and ensuring compliance with, all Applicable Laws, as well as their own privacy notices, agreements, or other obligations relating to their collection and use of Personal Information of candidates and employees through the Services. We collect such information under the direction of our Clients and generally have no direct relationship with the individuals whose Personal Information we process on a Client's behalf, except as described below.

With the exception of Personal Information collected when you register for an Account to access or utilise HRIA's Services directly (e.g., as a Client's recruiter/administrator), or when you interact with our own websites (hria.io and hria.in), this Policy describes our practices as a Data Processor acting on a Client's instructions. The Platform may contain links to other websites. If you click on a third-party link, you should read that site's own privacy policy; we encourage you to review the privacy practices of any such site to understand its personal data practices.

If you are a resident of India, you shall be referred to as a "Data Principal" as per the DPDP Act, and/or a "provider of information" as per the SPDI Rules, when we collect and process your Personal Information for providing the Services. Our collection, use, and disclosure of your Personal Information is further limited to the processing permitted under our Terms of Use, and, where you or your employer has subscribed to our Services, under the Master Services Agreement and/or Data Processing Agreement executed between HRIA and the Client.

Definitions

The capitalised terms used in this Policy shall have the meanings set out below. Other capitalised terms used in this Policy shall have the meaning respectively assigned to them elsewhere in this Policy.

"Account" means any account or instance created by or on behalf of a Client or an individual user on the Platform for access to and use of the Platform and Services.

"Consent Manager" means a person registered with the Data Protection Board of India, who acts as a single point of contact to enable a Data Principal to give, manage, review, or withdraw her consent through an accessible, transparent, and interoperable platform, as recognised under the DPDP Act.

"Data Fiduciary" means any person who, alone or in conjunction with other persons, determines the purpose and means of processing of personal data.

"Data Principal" means the individual to whom the personal data relates, and where such individual is a child, includes the parents or lawful guardian of such child.

"Data Processor" means any person who processes personal data on behalf of a Data Fiduciary.

"Personal Information"/"Personal Data" has the meaning assigned under the DPDP Act and the SPDI Rules, and includes any data about an individual who is identifiable by or in relation to such data.

"Sensitive Personal Data or Information" has the meaning assigned under the SPDI Rules and includes, without limitation, passwords; financial information; physical, physiological and mental health condition; biometric information; and any information received for processing under a lawful contract, to the extent such categories apply to information processed on the Platform.

"Client" means the business entity that has subscribed to avail the Services by signing up to the Platform and our Services, and which, in respect of candidate or employee data, acts as the Data Fiduciary.

"End User" means any candidate, employee, or other individual with whom a Client interacts using the Services (for example, a job applicant contacted via WhatsApp, or an employee whose payroll is processed through HRIA Payroll).

"Services" means the functions, responsibilities, cloud services, activities and/or tasks performed or to be performed by HRIA for a Client as mutually agreed under the applicable Master Services Agreement and/or Order Form, and includes the HRIA Recruit, HRIA Core, HRIA Payroll and TalentstaQ products.

Is HRIA a Data Processor or a Data Fiduciary?

Data Fiduciary

While using HRIA to engage with candidates or employees, our Clients are the Data Fiduciaries, because they determine the purpose (for example, recruiting a candidate, or processing an employee's payroll) and the means (using HRIA) of processing the personal data. Separately, HRIA is a Data Fiduciary for the personal data associated with a Client's own HRIA account (for example, a recruiter's business contact information), because we determine the means and purposes of that processing for our own use: invoicing, account communication, and other administrative functions.

Data Processor

HRIA is a "Data Processor" because we process the personal data of candidates and employees on behalf of our Clients, under an agreement in which the Client tells us what data to process, for what purpose(s), for how long we may retain it, and any restrictions the Client imposes on our use of that data.

What Kind of Information Do We Collect?

When a Client's recruiter creates an Account with us, or an End User interacts with the Platform, or you access our website, we may collect the following categories of information.

Personal Information

Any information that relates to you as a natural person, which either directly or indirectly, in combination with other information available or likely to be available to us, is capable of identifying you, including, without limitation, information provided by you or on your behalf when you:

Sensitive Personal Data or Information

Where a Client enables proctored assessments through TalentstaQ, or interview recording through integrated calendar/meeting tools, we may process the following categories of Sensitive Personal Data or Information on the Client's instructions:

This category of information is collected and processed only where a Client has configured and enabled the relevant feature (proctoring, interview recording, etc.) for a specific assessment or interview, and only with appropriate notice to, and consent of, the candidate or employee as facilitated by the Client and/or HRIA at the relevant workflow step.

Separately, where a Client uses HRIA Payroll to administer employee compensation, we process the following as Sensitive Personal Data or Information on the Client's instructions: bank account and IFSC details, PAN and other statutory tax identifiers, provident fund/ESI or equivalent statutory scheme identifiers, and salary/compensation details. This information is used solely to process payroll and statutory filings on the Client's behalf, is subject to the access controls and encryption described under "Protection of Personal Data" below, and is not used for any purpose beyond payroll administration and applicable statutory compliance.

Usage Information

Information that is not Personal Information but is collected in relation to your use of the Platform or is required for its proper functioning and development, including: time, date and extent of your usage; your navigation and search history within the Platform; device settings; time zone, language, and screen resolution; the URL that may have directed you to the Platform; and other device and access information such as IP address, operating system, browser type, and unique device identifiers.

Behavioural Information

Information connected with your activity on the Platform, and your opt-ins and communication preferences.

Location Data

Information about your general location when accessing and/or using the Platform (for example, derived from IP address), and, where applicable, the location/time associated with a QR code scan event.

Cookies

We, our service providers and business partners set essential cookies that enable core functionality such as security, network management, and accessibility. You may not opt out of these cookies, though you may disable them via your browser settings, which may affect how the Platform functions. We may also use analytics cookies (such as those from Google Analytics) to help us understand and improve how the Platform is used. These cookies collect information in a way that does not directly identify anyone.

Transaction and Payment Information

Billing and subscription payments from Clients are processed by our third-party payment processor. We do not directly collect or store full payment card or bank account numbers; our payment processor collects such information directly and provides us only with confirmation of payment status, invoice details, and limited billing information (such as billing name, address, and email) necessary to administer the Client's subscription.

Third-Party Information

Information about you that we may receive from third parties, such as data providers or analytics providers. If a Client links or signs in using a third-party service (such as Google or Zoho, as described below), we may receive information about that account's profile from that service.

How Do We Use Your Information?

We use the information we collect for the following purposes: to structure and provide the Services to Clients through the Platform (including operating the WhatsApp-native candidate intake flow, AI-based candidate scoring and shortlisting, TalentstaQ assessment delivery and proctoring, and HRIA Core/Payroll record-keeping); to fulfil requests for Services, Platform functionality, and support; for internal operations including troubleshooting, data analysis, testing, research, statistical and survey purposes; to communicate with you, including about changes to our Services; for quality assurance and to improve and develop the Platform; to customise the Services you see when you use the Platform; to enforce our Terms of Use and other policies; to verify your identity in order to use certain features; to maintain security and help detect abuse, fraud, and illegal activity on the Platform; to understand how the Platform is used, including across devices; and to send administrative notices and, where you have consented, marketing communications.

Where you have provided us with payment-related information, we use it (via our third-party payment processor) solely to process subscription payments and related billing communications.

We shall not sell or rent your Personal Information to anyone, for any reason, at any time. However, for legitimate business purposes, we may share your Personal Information with our service providers, business partners, or sub-processors, as described below. If we need to process your Personal Information for a purpose incompatible with those described in this Policy, we will provide notice and, where required by law, seek consent.

How Do We Use Artificial Intelligence?

HRIA uses AI-based models to score, rank, and summarise candidates against job-relevant criteria configured by a Client, and to generate assessment results via TalentstaQ. These AI-generated outputs are decision-support tools provided to the Client's recruiters; final hiring or evaluation decisions are made by the Client's human personnel. Data Principals may, subject to Applicable Law and the Client's internal policies, request information about the logic involved in such automated processing and request human review of a significant decision made about them.

With Whom Do We Share Your Information?

When we disclose Personal Information for a business purpose as described above, we do so under a contract that describes the purpose and requires the recipient to keep the information confidential and use it only to perform that contract. Your information may be shared as follows:

Legal Reasons

We may disclose information to respond to summons, court orders, legal process, law enforcement requests, or government inquiries, and to protect and defend the rights, interests, safety, and security of HRIA, the Platform, our Clients, users, or the public, or to comply with Applicable Laws.

Sale, Merger, or Other Business Transfer

We may share information in connection with a substantial corporate transaction, such as the sale of the Platform, a merger, consolidation, asset sale, or in the unlikely event of insolvency, in compliance with Applicable Laws.

Service Providers and Business Partners

We share categories of Personal Information listed above with service providers and business partners who help us perform business operations, including cloud hosting and infrastructure providers, payment processors, customer/technical support providers, communications infrastructure providers (including WhatsApp Business API providers), and analytics providers. Such recipients may receive information you choose to provide, information we obtain from other sources, and information we collect automatically, but do not receive full payment card details.

Clients

Candidate and employee information is shared with the Client that posted the job, employs the individual, or otherwise engages the Data Processing relationship, and with that Client's authorised recruiters/administrators, as this is the core purpose for which the information is collected.

TalentstaQ

As an integrated HRIA product, TalentstaQ receives candidate and employee information necessary to deliver and proctor assessments on the Client's instructions.

WhatsApp Business API / Meta

HRIA Recruit's candidate application flow operates through the WhatsApp Business API, provided by Meta Platforms, Inc. and/or its authorised Business Solution Providers ("WhatsApp Infrastructure Providers"). When a candidate applies via WhatsApp (including by scanning a QR code), messages, media, and metadata exchanged during that conversation (such as message timestamps and delivery/read status) necessarily pass through and are processed by the WhatsApp Infrastructure Providers in order to deliver the messaging functionality, subject to WhatsApp's own Business Terms and Privacy Policy. HRIA uses this channel solely to conduct the candidate screening conversation on the Client's behalf, and does not use WhatsApp conversation data to develop, improve, or train generalised/non-personalised AI or ML models. Candidates should note that their use of WhatsApp to apply is also governed by WhatsApp's own terms, which HRIA does not control.

Google and Zoho Integrations

Where a Client's recruiter connects their Google or Zoho account to schedule interviews or meetings, HRIA requests limited permissions ("scopes") from these providers, used strictly as follows:

Data accessed through these integrations is used only to provide the interview-scheduling functionality described above, is not sold or shared with unrelated third parties, and access is revoked when a recruiter disconnects the integration or is deactivated from the Client's Account. Where Google APIs are used, HRIA's use and transfer of information received from those APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and such data is not used to develop, improve, or train generalised/non-personalised AI or ML models.

Other Third Parties

We may share aggregated or de-identified usage information that does not identify any individual. Absent your or the relevant Client's prior consent (as applicable), we will share Personal Information with third parties only as described in this Policy.

What Legal Basis Do We Rely On to Process Your Personal Information?

Under the DPDP Act, we (or the relevant Client, as Data Fiduciary) process Personal Information principally on the basis of:

Where processing is based on consent, HRIA and/or the relevant Client will provide a notice describing the Personal Data to be collected and the purpose of processing, in or accompanied by a request for consent, in accordance with the DPDP Act.

Rights of Data Principals Under the DPDP Act and SPDI Rules

If you are a resident of India whose Personal Information we process, you have the following rights, which you may exercise (in the first instance, where a Client is the Data Fiduciary, by contacting that Client, and otherwise by contacting us at connect@hria.io):

Right to Access Information

You have the right to obtain, from the Data Fiduciary, a summary of the Personal Data being processed and the processing activities undertaken with respect to such data, the identities of other Data Fiduciaries and Data Processors with whom your Personal Data has been shared, together with a description of the data so shared, and any other information related to your Personal Data as may be prescribed.

Right to Correction and Erasure

You have the right to request correction of inaccurate or misleading Personal Data, completion of incomplete Personal Data, updating of your Personal Data, and erasure of Personal Data that is no longer necessary for the purpose for which it was processed, unless retention is required for a legal purpose.

Right to Grievance Redressal

You have the right to have readily available means of registering a grievance with us regarding the processing of your Personal Data. We will endeavour to respond to and resolve grievances within a reasonable time.

Right to Nominate

You have the right to nominate any other individual to exercise your rights under the DPDP Act, in the event of your death or incapacity, in the manner prescribed under Applicable Law.

Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw such consent at any time, with the withdrawal being as easy as it was to give consent. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal, and you will bear the consequences of such withdrawal to the extent permitted by Applicable Law.

Right to Access a Consent Manager

Where applicable and available, you may give, manage, review, or withdraw your consent through a Consent Manager registered with the Data Protection Board of India.

Rights under the SPDI Rules (to the extent applicable)

To the extent the SPDI Rules continue to apply, you also have the right to review Personal Information/Sensitive Personal Data or Information provided to us and to have it corrected or amended, and the right to withdraw consent to its collection at any time by writing to us, subject to the consequences described in this Policy.

We will endeavour to verify your identity before acting on any request in order to protect your Personal Information from unauthorised access, and will respond to requests within a reasonable time in accordance with Applicable Law, consistent with the timelines set out under "Privacy Officer / Grievance Officer" below.

Right to Complain

If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India, established under the DPDP Act, or such other regulatory authority as may have jurisdiction.

Children's Data

HRIA does not knowingly collect Personal Data from children (individuals below the age of 18) except where necessary and permitted by Applicable Law (for example, where a Client's employment or apprenticeship program lawfully involves individuals close to the age of majority), and only with verifiable parental or lawful-guardian consent as required under the DPDP Act. If you believe we have collected Personal Data from a child without appropriate consent, please contact us at connect@hria.io so we can take appropriate action, including deletion.

Retention of Personal Data

We retain Personal Information for as long as necessary to fulfil the purpose for which it was collected, and in accordance with the retention period agreed with the relevant Client under the applicable Master Services Agreement/Data Processing Agreement. In the absence of a specific contractual retention period, and subject to statutory retention requirements under Applicable Law, we will retain Personal Information for no longer than reasonably necessary for the purposes described in this Policy, after which it will be deleted or anonymised, except where a longer period is required by law (for example, statutory payroll or tax record-keeping requirements) or is necessary for the establishment, exercise, or defence of legal claims.

Our detailed internal Data Deletion Policy, which sets out the technical process and timelines for deleting or anonymising Personal Information upon expiry of the applicable retention period or upon a valid deletion request, is available on request by writing to connect@hria.io.

Significant Data Fiduciary Status

As of the effective date of this Policy, HRIA has not been notified by the Central Government as a "Significant Data Fiduciary" under the DPDP Act, and the additional obligations applicable to Significant Data Fiduciaries (such as mandatory Data Protection Impact Assessments, appointment of a Data Protection Officer based in India, and periodic independent data audits) do not currently apply to us. We will comply with such obligations if and when we are so notified, and will update this Policy accordingly.

Protection of Personal Data

We follow generally accepted standards to protect Personal Information submitted to us, both during transmission and once received, including the use of encryption in transit, access controls, and multi-tenant data isolation between different Clients' Accounts. Since no method of transmission over the internet or method of electronic storage is completely secure, we cannot guarantee absolute security. We enforce access controls so that only authorised personnel who are trained in the proper handling of such information may access Personal Information, and passwords are stored so that they cannot be recovered, even by us. If you have any security-related concerns, please contact us at connect@hria.io.

Storage Location and Cross-Border Transfers

Personal Information collected through the Platform is primarily stored and processed on cloud infrastructure that may be located outside India. Where such storage or processing occurs outside India, we take reasonable steps to ensure the recipient/location provides an appropriate level of protection for Personal Information, and we do not transfer Personal Information to any country or territory that has been restricted by the Central Government under the DPDP Act. Personal Information is not otherwise transferred outside India except as necessary to provide the Services described in this Policy (for example, to a cloud hosting provider) or as required by Applicable Law.

Cookie Policy

Details of the specific cookies and similar technologies used on hria.io and hria.in, their purpose, and how to manage your preferences are set out in our separate Cookie Policy, available on our website. By continuing to use hria.io or hria.in, you agree to the use of cookies as described in that Cookie Policy, except where you have adjusted your browser or cookie-consent settings to disable non-essential cookies.

Links to Third-Party Websites

The Platform may include links to other websites, applications, or services ("Third-Party Sites") whose privacy practices may differ from those described here. Such links do not constitute an endorsement by us of those Third-Party Sites or the products/services they offer. We encourage you to review the privacy policy of any Third-Party Site you visit, as it may differ substantially from this Policy, and we make no representations regarding, and are not responsible for, the privacy practices of any Third-Party Site.

Changes to Personal Information

If your Personal Information changes, please inform the relevant Client or update it through the applicable "Edit" option on the Platform, where available, as soon as reasonably possible, to help ensure it remains current, complete, and accurate.

Email Notifications and Opt-Out

Unless you have requested otherwise, by accepting our Terms of Use and this Policy you agree that we may contact you by email regarding administrative notices, service enhancements, or newsletters relevant to your use of the Platform. You may opt out of marketing communications at any time by following the "unsubscribe" instructions included in such communications, or by contacting us at connect@hria.io.

Confidentiality of Login Credentials

You are responsible for maintaining the security of your login credentials and must not share them with any third party. If you believe your credentials have been compromised, please contact us immediately at connect@hria.io.

Privacy Officer / Grievance Officer

In case of any complaints or concerns regarding the use, processing, or disclosure of your Personal Information, or any enquiries or feedback on our personal data protection policies and procedures, or any breach of this Policy or Applicable Law, please contact our designated Grievance Officer:

Email: connect@hria.io

In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, our Grievance Officer will acknowledge your complaint within twenty-four (24) hours of receipt and will endeavour to resolve it within fifteen (15) days from the date of receipt, save where a longer period is reasonably necessitated by the nature or complexity of the complaint.

Changes to This Policy

We may update this Policy from time to time. When we do, we will notify you by updating the "Effective Date" at the top of this Policy and posting the revised Policy, together with any other notice required by Applicable Law.

Contact Us

If you wish to make a complaint or request concerning your Personal Information or our privacy practices, or have questions, concerns, or comments about this Policy, please contact us at connect@hria.io, and we will endeavour to address your request as soon as possible. This is without prejudice to your right to approach the Data Protection Board of India or any other competent authority, or to follow the dispute-resolution process set forth in our Terms of Use.

RG Software Services
Plot No 28, H.No 8-3-1110/D, Kesava Nagar, Srinagar Colony, Hyderabad, Telangana, 500073, India
Email: connect@hria.io