Privacy Policy
Roshanee
Owned and Operated by IndiHire Private Limited
INTRODUCTION, APPLICABILITY, DEFINITIONS, DATA COLLECTION & PURPOSES
IndiHire Private Limited (“IndiHire”, “Company”, “we”, “our”, or “us”), the owner and operator
of the Roshanee platform (“Platform”), values your privacy and is committed to protecting your
Personal Data in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”),
the Digital Personal Data Protection Rules, as applicable, the Information Technology Act, 2000,
CERT-In Directions and other applicable laws.
This Privacy Policy explains how we collect, use, store, disclose, retain and otherwise process
Personal Data when you use our Platform, including our website located at roshanee.co,
associated mobile applications (if any), community portals, knowledge hubs, recruitment services,
events, webinars, newsletters and all related services.
This Privacy Policy forms an integral part of the Terms of Use governing access to the Platform.
By accessing or using the Platform, creating an account, registering for events,
subscribing to newsletters, applying for opportunities, participating in community
discussions or otherwise submitting your Personal Data, you acknowledge that you
have read and understood this Privacy Policy.
Where your consent is required under applicable law, we shall seek such consent before
processing your Personal Data.
1. OUR DETAILS
The Platform is owned and operated by:
IndiHire Private Limited
Corporate Identification Number (CIN):
U74140DL2011PTC215157
Registered Office:
709, Bhandari House 91,
Nehru Place,
New Delhi – 110019
Email:
info@roshanee.co
Website:
roshanee.co
For the purposes of the DPDP Act, IndiHire Private Limited acts as the
Data Fiduciary.
2. SCOPE
This Privacy Policy applies to every individual interacting with the Platform including,
but not limited to:
- Registered users
- Community members
- Talent Acquisition professionals
- HR professionals
- Recruiters
- Hiring managers
- Advisory board members
- Speakers
- Trainers
- Mentors
- Event attendees
- Newsletter subscribers
- Job applicants
- Employers
- Business partners
- Vendors
- Visitors browsing the Platform
This Privacy Policy applies irrespective of whether you access the Platform through:
- Desktop
- Mobile browser
- Mobile application
- Tablet
- APIs
- Third-party integrations
- Email communications
- Event registration pages
- Knowledge Hub
- Community forums
3. DEFINITIONS
Account means a registered account created by a User on the Platform.
Applicable Law means all laws, regulations, notifications, circulars and governmental directions applicable to the processing of Personal Data.
Consent shall have the meaning assigned under the DPDP Act.
Cookies means small text files placed on your browser or device for remembering preferences, authentication, analytics and improving user experience.
Data Fiduciary means IndiHire Private Limited.
Data Principal means the individual to whom Personal Data relates.
Personal Data means any data about an individual who is identifiable by or in relation to such data.
Processing includes collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, sharing, transmission, alignment, restriction, deletion or destruction of Personal Data.
Platform means the website, applications, community portals and services operated under the brand “Roshanee”.
User means any person accessing or using the Platform.
4. APPLICABILITY
This Privacy Policy applies whenever you:
- Visit our website
- Register an account
- Edit your profile
- Subscribe to newsletters
- Join the community
- Download resources
- Register for webinars
- Register for conferences
- Attend events
- Participate in surveys
- Participate in discussion forums
- Upload documents
- Apply for jobs
- Apply to become a mentor
- Contact us
- Contact support
- Communicate with us through email
- Use any feature offered through the Platform
5. PRINCIPLES OF DATA PROCESSING
We process Personal Data in accordance with the following principles:
- Lawfulness
- Transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Security safeguards
- Accountability
- Privacy by Design
- User autonomy
- Respect for Data Principal rights
We collect only such Personal Data that is reasonably necessary for the purposes
identified in this Privacy Policy.
6. CATEGORIES OF PERSONAL DATA WE COLLECT
Depending upon your interaction with the Platform, we may collect the following categories of Personal Data.
A. Identity Information
- First Name
- Last Name
- Preferred Name
- Profile Photograph
- Gender (if voluntarily provided)
- Date of Birth (if required for specific services)
B. Contact Information
- Email address
- Mobile number
- Alternate phone number
- City
- State
- Country
- Postal address (where applicable)
C. Professional Information
- Current designation
- Current employer
- Years of experience
- Industry
- Department
- Functional expertise
- Seniority level
- Professional certifications
- Recruitment specialization
- Hiring industries
- Organization type
- Organization size
- Skills
- Areas of specialization
D. Community Profile Information
As visible in your profile page, we may collect information such as:
- LinkedIn profile
- Current role
- Experience level
- Company size
- Industries hired for
- Topics of interest
- What you wish to gain from the community
- Biggest talent acquisition challenges
- Community contributions
- Areas of expertise
- Professional interests
- Speaker interests
- Volunteer interests
E. Recruitment Information
Where recruitment features become available, we may collect:
- Resume / CV
- Cover letter
- Portfolio
- Employment history
- Educational qualifications
- Professional references
- Interview feedback
- Recruiter interactions
- Application history
- Preferred locations
- Expected compensation
- Notice period
- Employment preferences
F. Communication Information
- Emails exchanged
- Support tickets
- Chat messages
- Feedback
- Survey responses
- Poll responses
- Event queries
- Webinar registrations
G. Technical Information
When you use the Platform, we may automatically collect:
- IP address
- Browser type
- Browser version
- Device identifier
- Operating system
- Screen resolution
- Device language
- Time zone
- Date and time stamps
- Crash reports
- Error logs
- Diagnostic information
H. Usage Information
- Pages visited
- Knowledge Hub articles viewed
- Searches performed
- Events attended
- Downloads
- Time spent
- Scroll depth
- Clickstream information
- Session duration
- Navigation path
- Referral source
- User preferences
I. Authentication Information
- Username
- Password (stored only in encrypted / hashed form)
- Multi-factor authentication details (where enabled)
- Login history
- Failed login attempts
- Account recovery information
J. Cookies and Similar Technologies
We may collect:
- Session cookies
- Persistent cookies
- Authentication cookies
- Security cookies
- Preference cookies
- Performance cookies
- Analytics cookies
Details regarding cookies are provided in the Cookie Notice forming part of this Privacy Policy.
7. PERSONAL DATA WE DO NOT INTENTIONALLY COLLECT
Unless specifically required for a lawful purpose, we do not intentionally collect:
- Aadhaar numbers
- PAN
- Passport details
- Driving licence details
- Biometric identifiers
- Financial account information
- Credit card information
- Debit card information
- Health records
- Medical information
- Caste
- Religion
- Political opinions
- Sexual orientation
- Criminal history
If such information is inadvertently received, we shall take appropriate measures to securely delete or anonymize it unless retention is required under applicable law.
8. HOW WE COLLECT YOUR PERSONAL DATA
We collect personal data through multiple channels.
A. Information You Provide Directly
Examples include:
- Account registration
- Profile creation
- Editing profile
- Contact forms
- Event registration
- Newsletter subscriptions
- Community participation
- Surveys
- Applications
- Support requests
B. Information Automatically Collected
We automatically collect technical and usage information through:
- Cookies
- Web beacons
- Pixels
- Server logs
- Device identifiers
- Browser technologies
C. Information Received from Third Parties
Subject to applicable law, we may receive Personal Data from:
- LinkedIn integrations
- Business partners
- Event organizers
- Employers
- Recruitment partners
- Publicly available professional sources
- Identity verification providers
- Analytics providers
9. PURPOSES FOR WHICH WE PROCESS PERSONAL DATA
Your Personal Data may be processed for one or more of the following purposes:
Account Management
- Creating accounts
- Authenticating users
- Managing profiles
- Password recovery
Community Services
- Facilitating networking
- Connecting professionals
- Enabling discussions
- Managing memberships
Recruitment Services
- Displaying opportunities
- Matching professionals
- Processing applications
- Facilitating recruiter interactions
Knowledge Hub
- Providing articles
- Delivering resources
- Managing subscriptions
- Recommending relevant content
Events
- Webinar registrations
- Conferences
- Community meetups
- Certifications
- Attendance management
Communication
- Service announcements
- Platform updates
- Newsletters
- Marketing communications (where permitted)
- Customer support
Security
- Preventing fraud
- Detecting abuse
- Monitoring suspicious activities
- Maintaining platform integrity
- Incident investigation
Platform Improvement
- Analytics
- Product development
- Feature optimization
- User experience enhancement
Compliance
- Complying with legal obligations
- Regulatory reporting
- Court orders
- Government requests
- Internal audits
- Risk management
10. PURPOSE LIMITATION
We shall process Personal Data only for the purposes specified in this Privacy Policy or such other purposes as may be notified to you at the time of collection, unless otherwise required or permitted under applicable law.
We will not process your Personal Data for purposes incompatible with those for which it was originally collected without obtaining fresh consent where required under applicable law.
11. CONSENT
Roshanee processes your Personal Data in accordance with the Digital Personal Data Protection Act, 2023.
Where required under applicable law, we shall seek your free, specific, informed,
unconditional and unambiguous consent before processing your Personal Data.
Your consent may be obtained through one or more of the following methods:
- Selecting an acceptance checkbox during registration.
- Creating a user account.
- Completing your profile.
- Registering for an event or webinar.
- Applying for opportunities available through the Platform.
- Subscribing to newsletters or updates.
- Providing information through forms available on the Platform.
- Responding to requests for additional information.
- Providing consent through any electronic or digital mechanism made available by the Company.
Where consent is sought, the request shall:
- Be presented in clear and plain language.
- Specify the categories of Personal Data to be processed.
- Specify the purposes of processing.
- Identify IndiHire Private Limited as the Data Fiduciary.
- Explain your rights under applicable law.
- Provide an accessible mechanism to withdraw consent.
Consent shall remain valid until withdrawn, unless otherwise required by law or where
continued processing is necessary for a lawful purpose.
12. WITHDRAWAL OF CONSENT
You may withdraw your consent at any time by:
- Updating your privacy preferences within your account (where available).
- Contacting the Grievance Officer (Saurabh Kumar) via email at info@roshanee.co
Withdrawal of consent shall not affect the lawfulness of processing undertaken before such withdrawal.
Where withdrawal of consent makes it impossible for us to continue providing certain services,
your access to those services may be suspended or discontinued.
Upon withdrawal, we shall cease processing your Personal Data unless processing is required:
- By applicable law.
- For establishment, exercise or defence of legal claims.
- For fraud prevention.
- For security purposes.
- For compliance with statutory obligations.
- For any legitimate use recognized under applicable law.
13. ACCURACY OF PERSONAL DATA
You represent and warrant that:
- All Personal Data submitted by you is accurate, complete and current.
- You are authorized to provide such information.
- The information does not infringe the rights of any third party.
You agree to promptly update your profile whenever there is any material change to your information.
The Company shall not be responsible for losses arising from inaccurate or outdated information provided by you.
14. USER RESPONSIBILITIES
By using the Platform you agree that you shall not:
- Impersonate another person.
- Create multiple fraudulent accounts.
- Submit false employment information.
- Upload malicious files.
- Upload unlawful content.
- Misuse another person’s Personal Data.
- Publish confidential information without authorization.
- Attempt unauthorized access to Platform systems.
Users remain solely responsible for Personal Data voluntarily published in public areas of the Platform.
15. COOKIES AND SIMILAR TECHNOLOGIES
The Platform uses Cookies and similar technologies to improve functionality,
maintain security, personalize user experience and generate analytical insights.
Cookies may be temporary (Session Cookies) or remain on your device after your browsing session (Persistent Cookies).
The Platform may also use:
- Local Storage
- Web Beacons
- Pixel Tags
- SDKs
- Device Identifiers
- Similar Tracking Technologies
16. TYPES OF COOKIES
A. Strictly Necessary Cookies
These Cookies are essential for:
- Account authentication
- Fraud prevention
- Secure login
- Session management
- Security monitoring
Without these Cookies certain Platform functions may not operate.
B. Functional Cookies
These Cookies remember your preferences including:
- Preferred language
- Login status
- Profile settings
- Accessibility preferences
- Dashboard configuration
C. Performance Cookies
These Cookies enable us to understand:
- Page performance
- Feature usage
- Response times
- User interactions
- Navigation behaviour
D. Analytics Cookies
These Cookies help us measure:
- Unique visitors
- Repeat visitors
- Traffic sources
- Session duration
- Conversion metrics
- Feature adoption
Analytics information is aggregated wherever reasonably possible.
E. Security Cookies
Security Cookies assist in:
- Detecting malicious activity
- Preventing unauthorized access
- Identifying suspicious login attempts
- Maintaining Platform integrity
17. MANAGING COOKIES
You may control Cookies through:
- Browser settings
- Operating system settings
- Cookie consent banner
- Third-party cookie management tools
Disabling certain Cookies may affect the functionality of the Platform.
18. ANALYTICS
We may use analytical tools to understand how users interact with the Platform.
Analytics may include:
- Page visits
- User journeys
- Engagement metrics
- Search behaviour
- Content popularity
- Referral traffic
- Geographic trends
- Browser statistics
- Operating system usage
- Device categories
Where possible, analytics information is aggregated or pseudonymised.
Analytics information is used to:
- Improve user experience
- Enhance Platform performance
- Develop new features
- Understand community interests
- Improve recruitment services
- Improve Knowledge Hub content
19. EMAIL COMMUNICATIONS
We may send communications relating to:
- Account verification
- Password reset
- Security alerts
- Platform updates
- Policy changes
- Event reminders
- Webinar confirmations
- Invoices (where applicable)
- Customer support
- Newsletters
- Product announcements
Operational communications necessary for providing Platform services may continue even if you opt out of promotional communications.
20. MARKETING COMMUNICATIONS
Subject to applicable law and your communication preferences, we may send:
- Newsletters
- Educational content
- Industry reports
- Event invitations
- Surveys
- Feature announcements
- Promotional campaigns
You may opt out of promotional communications at any time by:
- Using the unsubscribe link.
- Updating account preferences.
- Contacting us.
Opting out shall not affect mandatory service-related communications.
21. COMMUNITY CONTENT
The Platform enables users to participate in professional networking and community engagement.
Information voluntarily posted in public sections of the Platform may become visible to other users.
Such information may include:
- Profile details
- Comments
- Discussions
- Articles
- Questions
- Answers
- Recommendations
- Event participation
- Achievements
- Community contributions
Users should exercise caution before publishing Personal Data in publicly accessible areas.
The Company cannot guarantee that information voluntarily disclosed in public forums will remain private.
22. USER GENERATED CONTENT
You retain ownership of content submitted by you.
However, by uploading or publishing content on the Platform, you grant IndiHire a
non-exclusive, worldwide, royalty-free, revocable licence to:
- Host
- Reproduce
- Display
- Distribute
- Format
- Store
- Index
- Moderate
- Remove where required by law or Platform policies
This licence exists solely for operating, maintaining and improving the Platform.
23. ARTIFICIAL INTELLIGENCE AND AUTOMATED PROCESSING
The Platform may use artificial intelligence, machine learning or automated systems to improve user experience.
Such systems may be used for:
- Recommending relevant content
- Suggesting networking opportunities
- Recommending events
- Recommending learning resources
- Matching users with employment opportunities
- Fraud detection
- Spam prevention
- Content moderation
- Security monitoring
- Improving search results
Automated systems are intended to support human decision-making and not replace independent human judgment in material decisions affecting users, unless otherwise permitted under applicable law.
24. PROFILING
The Platform may create user profiles based upon:
- Professional interests
- Industry
- Experience
- Engagement history
- Webinar participation
- Learning preferences
- Recruitment preferences
Profiling enables us to:
- Personalize recommendations
- Improve Knowledge Hub relevance
- Suggest suitable events
- Improve networking opportunities
- Recommend employment opportunities
We do not sell profiling information to third parties.
25. THIRD-PARTY SERVICES
The Platform may integrate with trusted third-party service providers for operational purposes.
Such providers may include:
- Cloud hosting providers
- Analytics providers
- Email delivery providers
- Customer relationship management platforms
- Webinar platforms
- Event management software
- Customer support software
- Authentication providers
- Recruitment technology providers
- Payment processors (if introduced)
- Marketing automation providers
Each third-party service provider is contractually required to implement appropriate security measures and process Personal Data only in accordance with our instructions and applicable law.
26. SOCIAL MEDIA INTEGRATIONS
Where enabled, you may choose to interact with the Platform using third-party social networking services including professional networking platforms.
If you voluntarily link your account, we may receive information authorized by you or permitted by the relevant platform, such as:
- Name
- Email address
- Profile photograph
- Public profile URL
- Professional headline
- Employment information
- Publicly available profile information
The collection and processing of such information remain subject to this Privacy Policy.
Your interactions with third-party platforms are governed by their respective privacy policies.
27. THIRD-PARTY LINKS
The Platform may contain links to websites operated by third parties.
We do not control such websites and are not responsible for:
- Their privacy practices
- Security measures
- Content
- Availability
- Accuracy
Users should review the privacy policies of third-party websites before providing Personal Data.
28. BUSINESS COMMUNICATIONS
Where you interact with IndiHire in a business or professional capacity, we may process business contact information for purposes including:
- Responding to enquiries
- Managing partnerships
- Vendor onboarding
- Contractual communications
- Business development
- Networking
- Event collaboration
- Advisory board coordination
Such processing shall remain limited to the purposes for which the information was provided.
29. LEGAL BASIS FOR PROCESSING UNDER APPLICABLE LAW
Depending upon the circumstances, Personal Data may be processed on the basis of:
- Your consent
- Voluntary provision of information by you
- Compliance with statutory obligations
- Legal proceedings
- Prevention and detection of fraud
- Enforcement of contractual rights
- Protection of Platform security
- Other lawful uses recognized under the DPDP Act or any other applicable law
30. NO SALE OF PERSONAL DATA
The Company does not sell Personal Data to data brokers or unrelated third parties for monetary consideration.
Where Personal Data is shared with service providers, such sharing is undertaken solely for the purposes described in this Privacy Policy and subject to appropriate contractual and technical safeguards.
31. DISCLOSURE OF PERSONAL DATA
We do not disclose your Personal Data except as described in this Privacy Policy,
with your consent, or as otherwise permitted or required under applicable law.
Any disclosure shall be limited to the minimum Personal Data reasonably necessary
for the applicable purpose.
32. CATEGORIES OF RECIPIENTS
Subject to this Privacy Policy, we may disclose Personal Data to the following
categories of recipients.
A. Group Companies
Personal Data may be shared with IndiHire Private Limited and its subsidiaries,
affiliates, holding companies, successor entities, or companies under common
control for purposes including:
- Account administration
- Customer support
- Service delivery
- Security
- Compliance
- Analytics
- Business continuity
All such entities shall process Personal Data in accordance with this Privacy
Policy and applicable law.
B. Authorized Employees
Access to Personal Data is restricted to employees who require such access for
legitimate business purposes.
Such personnel may include:
- Customer support
- Technology teams
- Information security personnel
- Recruitment teams
- Event management personnel
- Finance
- Compliance
- Legal
- Senior management
Access is governed through role-based access controls and the principle of least privilege.
C. Service Providers
We may engage third-party service providers for functions including:
- Cloud hosting
- Website hosting
- Content delivery
- Cybersecurity
- Analytics
- Customer relationship management
- Email communications
- Webinar hosting
- Event management
- Customer support
- Payment processing (where applicable)
- Document storage
- Authentication services
- Infrastructure monitoring
Each service provider is required by written agreement to:
- Process Personal Data only on documented instructions.
- Implement appropriate technical and organizational security measures.
- Maintain confidentiality.
- Notify us of security incidents without undue delay.
- Delete or return Personal Data upon completion of services where applicable.
D. Professional Advisors
Personal Data may be disclosed where reasonably necessary to:
- External legal counsel
- Auditors
- Tax consultants
- Compliance advisors
- Insurance providers
- Forensic investigators
Such recipients are bound by legal or contractual confidentiality obligations.
E. Regulatory Authorities
We may disclose Personal Data where required to:
- Courts
- Tribunals
- Law enforcement agencies
- Regulatory authorities
- Statutory bodies
- Government agencies
Such disclosures shall only occur where required by applicable law or pursuant
to a valid legal process.
F. Business Partners
Where a webinar, event, certification programme or community initiative is jointly
organized with a business partner, limited Personal Data may be shared strictly
for administering such programme.
Where required by law, separate consent shall be obtained before sharing Personal Data
for such purposes.
33. NO UNAUTHORIZED DISCLOSURE
We shall not:
- Sell Personal Data.
- Rent Personal Data.
- Commercially exploit Personal Data unrelated to the purposes disclosed in this Privacy Policy.
- Disclose personal data to unrelated third parties for their independent marketing without obtaining consent where required.
34. CROSS-BORDER TRANSFER OF PERSONAL DATA
The Platform may utilize infrastructure, cloud hosting, analytics providers,
or technology partners located outside India.
Accordingly, your Personal Data may be transferred to, stored in, or processed
in jurisdictions outside India, subject to applicable law.
Where cross-border transfers occur, we shall ensure that:
- Transfers comply with the DPDP Act and any restrictions notified by the Central Government.
- Recipients maintain reasonable security safeguards.
- Contractual obligations protect Personal Data.
- Only the minimum necessary Personal Data is transferred.
Where applicable law restricts transfers to specified jurisdictions, the Company
shall comply with such restrictions.
35. DATA LOCALIZATION
Where any category of Personal Data is required by applicable law or regulatory
direction to remain within India, the Company shall ensure compliance with such requirement.
Nothing in this Privacy Policy shall be interpreted as permitting transfers prohibited by law.
36. SECURITY OF PERSONAL DATA
The Company implements reasonable technical and organizational measures designed
to protect Personal Data against:
- Unauthorized access
- Accidental disclosure
- Alteration
- Destruction
- Misuse
- Unauthorized processing
- Loss
Security measures are periodically reviewed and enhanced in light of technological
developments and evolving risks.
No security system is completely immune from compromise. While we strive to protect
Personal Data, we cannot guarantee absolute security.
37. TECHNICAL SECURITY MEASURES
Depending on operational requirements, the Company may implement safeguards including:
- Encryption of data in transit using industry-standard protocols.
- Encryption of sensitive data at rest where appropriate.
- Password hashing using strong cryptographic algorithms.
- Multi-factor authentication for privileged accounts.
- Secure session management.
- Firewalls.
- Intrusion detection and prevention systems.
- Malware protection.
- Endpoint security controls.
- Vulnerability assessments.
- Penetration testing.
- Continuous monitoring.
- Security logging.
- Backup and disaster recovery mechanisms.
Security controls are reviewed periodically based on risk assessments.
38. ORGANIZATIONAL SECURITY MEASURES
We maintain administrative safeguards including:
- Information security policies
- Employee confidentiality obligations
- Access authorization procedures
- Periodic security awareness training
- Vendor due diligence
- Incident response procedures
- Change management
- Internal audits
- Risk assessments
39. ACCESS CONTROLS
Personal Data is accessible only to authorized personnel on a need-to-know basis.
Access rights are:
- Role-based
- Periodically reviewed
- Revoked upon role changes or separation
- Monitored for unauthorized activity
40. DATA MINIMIZATION
The Company seeks to collect only the Personal Data reasonably necessary for
identified purposes.
We periodically review Personal Data holdings to remove information that is:
- Unnecessary
- Excessive
- Obsolete
- Inaccurate
- No longer required
41. STORAGE OF PERSONAL DATA
Personal Data may be stored using secure infrastructure operated by:
- The Company
- Cloud service providers
- Managed hosting providers
- Authorized technology vendors
Storage architecture may include redundancy, backups and disaster recovery systems designed to enhance resilience.
42. RETENTION OF PERSONAL DATA
Personal Data shall be retained only for as long as necessary to:
- Fulfil the purposes described in this Privacy Policy.
- Provide Platform services.
- Comply with statutory obligations.
- Resolve disputes.
- Enforce legal rights.
- Maintain business records.
- Satisfy regulatory requirements.
Where Personal Data is no longer required, it shall be securely deleted, anonymized or irreversibly de-identified, unless retention is required by law.
43. INDICATIVE RETENTION PERIODS
Unless a longer retention period is required by law or necessary for legal proceedings, Personal Data may generally be retained as follows:
| Category | Typical Retention |
|---|---|
| User Account Information | Until account deletion plus up to 180 days for operational and backup purposes. |
| Customer Support Records | Up to 3 years. |
| Event Registration Records | Up to 3 years. |
| Webinar Attendance Records | Up to 3 years. |
| Newsletter Subscription Data | Until unsubscribed or consent withdrawn. |
| Security Logs | Up to 365 days. |
| Authentication Logs | Up to 365 days. |
| Audit Logs | Up to 7 years where required for compliance. |
| Financial Records | As required under applicable tax and corporate laws. |
| Recruitment Records (where applicable) | Up to 2 years from last interaction unless consent is withdrawn earlier. |
These periods are indicative and may be modified where required by law or legitimate operational needs.
44. ACCOUNT DELETION
You may request deletion of your account by contacting us through the mechanisms provided on the Platform or by emailing the Grievance Officer.
Upon verification of the request, we shall:
- Deactivate your account.
- Delete or anonymize Personal Data that is no longer required.
- Retain only such information as required under applicable law or for the establishment, exercise or defence of legal claims.
Deletion from live systems may occur before deletion from encrypted backups, which are overwritten in accordance with our backup lifecycle.
45. BUSINESS CONTINUITY AND BACKUPS
To maintain operational resilience, Personal Data may be included in secure backup systems.
Backup copies are:
- Encrypted where appropriate.
- Access restricted.
- Maintained for disaster recovery.
- Deleted or overwritten in accordance with defined retention schedules.
Backup data is not ordinarily restored except where necessary for recovery or legal compliance.
46. CHILDREN’S PERSONAL DATA
The Platform is intended primarily for professionals, recruiters, employers, and individuals aged eighteen (18) years or above.
We do not knowingly collect Personal Data from children where prohibited under applicable law.
Where processing of a child’s Personal Data is permitted or required under applicable law, such processing shall be undertaken only after obtaining verifiable consent from the parent or lawful guardian and in compliance with applicable statutory requirements.
If we become aware that Personal Data has been collected from a child without the required authorization, we shall take reasonable steps to delete such information.
47. FRAUD PREVENTION
We may process Personal Data for the purposes of:
- Preventing fraud.
- Detecting abuse.
- Identifying unauthorized access.
- Investigating suspicious activities.
- Protecting users.
- Safeguarding Platform integrity.
Such processing may include monitoring login behaviour, unusual account activity and security events.
48. SECURITY INCIDENTS AND PERSONAL DATA BREACHES
The Company maintains documented procedures for identifying, assessing, containing, investigating and responding to security incidents involving Personal Data.
Where a Personal Data breach is likely to trigger reporting obligations under applicable law, the Company shall:
- Assess the nature and scope of the breach.
- Take reasonable steps to contain and mitigate the incident.
- Notify the appropriate regulatory authorities where required.
- Notify affected Data Principals where required under applicable law or where necessary to reduce the risk of harm.
- Document the incident and corrective actions taken.
49. BUSINESS REORGANIZATION
In the event of:
- Merger
- Acquisition
- Amalgamation
- Restructuring
- Demerger
- Insolvency
- Sale of assets
- Change in control
Personal Data may be transferred to the successor entity, subject to applicable law and appropriate safeguards.
The successor entity shall be required to honor the commitments contained in this Privacy Policy or provide an equivalent level of protection.
50. PRIVACY BY DESIGN
The Company endeavors to incorporate privacy considerations throughout the lifecycle of its products and services.
Privacy considerations may include:
- Data minimization
- Least privilege access
- Secure software development practices
- Encryption
- Audit logging
- Periodic reviews of processing activities
- Security testing
- Vendor due diligence
51. ACCOUNTABILITY
The Company maintains internal governance measures to promote compliance with applicable privacy and data protection laws.
These measures may include:
- Documented policies and procedures
- Employee training
- Periodic compliance reviews
- Internal audits
- Vendor assessments
- Risk management processes
- Maintenance of processing records where appropriate
52. RIGHTS OF DATA PRINCIPALS
IndiHire recognizes and respects the rights available to Data Principals under the Digital Personal Data Protection Act, 2023 and other applicable laws.
Subject to applicable law, you may exercise the following rights:
A. Right to Access Information
You may request information regarding the processing of your Personal Data, including:
- The categories of Personal Data being processed
- The purposes for which such Personal Data is processed
- The categories of recipients with whom such Personal Data has been shared
- Information regarding your rights under applicable law
B. Right to Correction and Completion
If your Personal Data is inaccurate, incomplete or outdated, you may request that it be corrected, updated or completed.
You may also update certain information directly through your account settings where such functionality is available.
C. Right to Erasure
Subject to applicable law, you may request deletion of your Personal Data where:
- The Personal Data is no longer required for the purposes for which it was collected
- Consent has been withdrawn
- Processing is no longer necessary
- Continued retention is not required by law
The Company may retain certain information where retention is necessary to:
- Comply with legal obligations
- Establish, exercise or defend legal claims
- Prevent fraud
- Maintain security records
- Comply with regulatory requirements
D. Right to Withdraw Consent
Where processing is based on your consent, you may withdraw such consent at any time through the mechanisms described in this Privacy Policy.
Withdrawal of consent shall not affect processing undertaken before such withdrawal.
E. Right to Grievance Redressal
You have the right to seek redressal of grievances relating to the processing of your Personal Data by contacting the Grievance Officer designated by the Company.
The Company shall endeavor to acknowledge and address grievances within the timelines prescribed under applicable law.
F. Right to Nominate
Where provided under applicable law, you may nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity.
The Company may require reasonable documentation before acting upon such requests.
53. EXERCISING YOUR RIGHTS
Requests relating to Personal Data may be submitted through:
- Your account settings (where available)
- Designated privacy request forms made available on the Platform
- Email to the Grievance Officer
- Any other mechanism notified by the Company
Before processing any request, the Company may require verification of your identity to prevent unauthorized disclosure, alteration or deletion of Personal Data.
Where a request is submitted by an authorized representative, additional proof of authority may be required.
54. RESPONSE TIMELINES
Upon receipt of a valid request, the Company shall:
- Acknowledge receipt within a reasonable period
- Verify the identity of the requester
- Evaluate the request in accordance with applicable law
- Respond within the timelines prescribed by law
Where additional time is reasonably required due to the complexity or volume of requests, the Company shall communicate the expected timeframe to the requester.
55. LIMITATIONS ON RIGHTS
The exercise of rights under this Privacy Policy may be limited where:
- Disclosure would adversely affect the rights of another person
- Disclosure is prohibited by law
- The information is subject to legal privilege
- Retention is required by statute
- Disclosure would compromise ongoing investigations or legal proceedings
- Disclosure would materially prejudice fraud prevention or security measures
Any refusal to act on a request shall be based on applicable law and communicated with appropriate reasons where legally permissible.
56. DATA PRINCIPAL RESPONSIBILITIES
As a user of the Platform, you agree to:
- Provide accurate and complete information
- Keep your account credentials confidential
- Promptly update inaccurate information
- Use the Platform lawfully
- Respect the privacy rights of other users
- Refrain from uploading unlawful or infringing content
- Refrain from collecting or misusing Personal Data of other users without authorization
You remain responsible for all activities conducted through your account unless unauthorized use is promptly reported to the Company.
57. USER CONTENT AND PROFESSIONAL INFORMATION
The Platform is intended to facilitate professional networking and knowledge sharing.
Information that you intentionally make visible to other users, such as:
- Profile information
- Professional experience
- Skills
- Comments
- Articles
- Discussion posts
- Webinar participation
- Speaker profiles
May be accessible to other users of the Platform in accordance with your privacy settings and the functionality of the relevant feature.
You should avoid publishing confidential, proprietary or sensitive Personal Data in publicly accessible sections of the Platform.
58. COMPLIANCE WITH APPLICABLE LAW
The Company shall process Personal Data in accordance with applicable legal and regulatory requirements.
Nothing in this Privacy Policy shall limit the Company’s ability to:
- Comply with lawful governmental requests
- Cooperate with regulatory authorities
- Enforce contractual rights
- Protect the rights, property or safety of the Company, its users or third parties
59. CHANGES TO THIS PRIVACY POLICY
The Company reserves the right to amend this Privacy Policy from time to time to reflect:
- Changes in applicable law
- Regulatory guidance
- Technological developments
- Business operations
- Platform functionality
- Security practices
Where material changes are made, the Company shall take reasonable steps to notify users through appropriate means, including:
- Email notifications (where appropriate)
- Notices on the Platform
- Updates to the effective date
- Account notifications
Continued use of the Platform after the effective date of the revised Privacy Policy constitutes acknowledgment of such revised Privacy Policy to the extent permitted by law.
60. GRIEVANCE OFFICER
In accordance with applicable law, the Company has designated a Grievance Officer to address concerns relating to the processing of Personal Data.
Grievance Officer
Name: Saurabh Kumar
Designation: Grievance Officer
Company: IndiHire Private Limited
Address:
709, Bhandari House 91,
Nehru Place,
New Delhi – 110019
Email:
info@roshanee.co
The Grievance Officer shall endeavor to respond to grievances within the timelines prescribed under applicable law.
61. CONTACT US
For questions relating to this Privacy Policy or the processing of your Personal Data, please contact:
Privacy Team
Company: IndiHire Private Limited
Email:
info@roshanee.co
Website:
www.roshanee.co
62. GOVERNING LAW
This Privacy Policy shall be governed by and construed in accordance with the laws of India.
63. DISPUTE RESOLUTION
Any dispute arising out of or relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the competent courts at Bengaluru, Karnataka, unless otherwise required by applicable law.
Nothing contained herein shall restrict the rights of a Data Principal to seek remedies available under applicable law.
64. SEVERABILITY
If any provision of this Privacy Policy is held to be invalid, unlawful or unenforceable by a competent court or authority, the remaining provisions shall continue in full force and effect.
65. WAIVER
Failure by the Company to enforce any provision of this Privacy Policy shall not constitute a waiver of such provision or any other provision.
66. ENTIRE PRIVACY POLICY
This Privacy Policy constitutes the entire privacy notice governing the processing of Personal Data through the Platform and supersedes prior versions of the Privacy Policy to the extent of any inconsistency.







