⚠ This page is not ready to publish. unfilled placeholder(s) remain — search for [[ in the source. Fill every one, then have an Indian lawyer familiar with the DPDP Act 2023 review this document.
Legal

Privacy Policy

How we handle your data — and, separately, the data your firm holds in HireMaze about its own employees and clients. Those are two different things, and this policy treats them differently.

Effective: [[EFFECTIVE_DATE]] Last updated: [[LAST_UPDATED]]

HireMaze is used by firms to run their people and their clients. That means we hold two very different kinds of information: data about you, the person with an account, and data your firm has entered about other people — its employees and its clients. This policy is explicit about which is which.

1. Who we are

HireMaze is operated by [[COMPANY_LEGAL_NAME]], a company incorporated in India under CIN [[CIN]], with its registered office at [[REGISTERED_ADDRESS]].

In this policy, "HireMaze", "we", "us" and "our" mean that company. "You" means the individual using the service. "Your firm" means the organisation whose HireMaze workspace you belong to.

This policy applies to hiremaze.in, the HireMaze application, and every public firm page and client portal we host on our domain.

2. Our two roles — and why it matters

Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), who decides why data is processed determines who is answerable for it. HireMaze sits on both sides of that line depending on the data:

The dataOur roleWhat that means
Your account — your name, email, phone, login activity, billing details Data Fiduciary (controller) We decide why this is processed and are directly answerable to you for it. This policy governs it.
Data your firm enters — its employees' attendance and records, its clients' details, documents, invoices Data Processor Your firm is the Data Fiduciary. We only process it on your firm's instructions. Your firm's own privacy policy governs it, not this one.
If you are an employee or a client of a firm using HireMaze

Your data was given to us by that firm, not collected by us from you. We cannot delete it, correct it or hand it over on your request — we are not permitted to act on your firm's data without their instruction. Contact your employer or the firm you are a client of. If you cannot reach them, write to our Grievance Officer in section 12 and we will route it.

3. What we collect

Information you give us

  • Account details — name, work email, phone number, password (stored hashed, never in readable form).
  • Firm details — firm name, the address you claim at hiremaze.in/your-firm, firm size, industry, GSTIN where you provide one.
  • Anything you enter into the product — see section 5.
  • What you send us — enquiries through our contact form, WhatsApp or email, and any support correspondence.

Information we collect automatically

  • Technical data — IP address, browser and device type, operating system, referring page, and the pages you view.
  • Usage data — features used, actions taken and timestamps, so we can operate, secure and improve the service.
  • Cookies and similar technologies — see section 6.

We do not knowingly collect sensitive categories such as caste, religion, biometric identifiers or health data for our own purposes. If your firm chooses to store such information in free-text fields, it does so as the Data Fiduciary and under its own responsibility.

4. Why we process your data

PurposeBasis under the DPDP Act
Creating and running your account, and providing the serviceConsent / performance of the service you asked for
Sending transactional messages — OTPs, invites, notifications, service noticesConsent / legitimate use
Support and responding to your enquiriesConsent
Security, fraud prevention, abuse detection and debuggingLegitimate use
Aggregate analytics to understand and improve the productConsent (you may withdraw — section 6)
Billing, invoicing and statutory recordsLegal obligation
Marketing about HireMaze featuresConsent — withdrawable at any time

We do not sell your personal data. We do not share it with advertisers or data brokers, and we do not use your firm's data to train machine-learning models.

5. Data your firm puts into HireMaze

When your firm uses HireMaze it will enter information about people who never signed up with us — its employees and its clients. Typically:

  • Employee records, attendance and check-in times, roles and permissions, tasks and tickets
  • Client records and contacts, documents you request and they upload, and invoices
  • Candidate and applicant details, where your firm uses the hiring module

For all of that, your firm is the Data Fiduciary and we are its processor. We commit that we:

  • process it only to provide the service and only on your firm's instructions;
  • do not use it for our own purposes, do not sell it, and do not train models on it;
  • keep each firm's data logically separated, and scope every client portal to that client's own record;
  • return or delete it on termination, per section 9.
Your firm's obligations, not ours

If your firm enters personal data about its employees or clients, your firm is responsible for having a lawful basis to do so, for giving those people notice, and for answering their requests. Publishing an employee's attendance to a client portal is your firm's decision and your firm's disclosure. Please make sure your employment contracts and client agreements cover it.

6. Cookies and analytics

We use a small number of cookies and similar technologies:

TypeWhat forCan you refuse?
Strictly necessaryKeeping you logged in, security, load balancingNo — the service cannot work without them
AnalyticsGoogle Analytics 4, with IP anonymisation enabled, to see which pages and features are usedYes

We do not run advertising or cross-site tracking cookies. You can block cookies in your browser settings, opt out of Google Analytics with the Google Analytics opt-out add-on, or enable "Do Not Track" — we honour it for analytics.

7. Where your data is stored

Your data is stored in India. HireMaze runs on Amazon Web Services in the ap-south-1 (Mumbai) region — application databases on Amazon RDS for PostgreSQL, and uploaded files in Amazon S3, both in that region.

Some of the supporting services in section 8 are operated by companies outside India and may process limited data (such as analytics events or email delivery metadata) on infrastructure outside India. Where that happens we rely on the provider's contractual protections and on transfers being permitted under the DPDP Act.

8. Subprocessors

We use these third parties to run HireMaze. Each is bound by its own terms and processes data only as needed to provide its service to us.

ProviderWhat it does for usWhere
Amazon Web ServicesApplication hosting, PostgreSQL database, file storage, CDNIndia (ap-south-1)
Amazon SESTransactional email — invites, notifications, password resetsAWS region [[SES_REGION]]
Amazon SNSSMS, including one-time passcodesAWS region [[SNS_REGION]]
Google Analytics 4 (Google)Website and product usage analytics, IP-anonymisedGlobal
Google Firebase[[FIREBASE_PURPOSE]] — project hiremaze-f31e2Global
Zoho CorporationOur business email at hiremaze.inIndia
[[PAYMENT_GATEWAY]]Payment processing, once paid plans launch. We never see or store your full card details.India
Confirm before publishing

This list was assembled from your codebase. Verify it is complete and current — an incomplete subprocessor list is one of the first things an enterprise customer's security review will catch, and under the DPDP Act you must be able to account for every processor handling data you are responsible for.

9. How long we keep data

DataKept for
Your account and your firm's workspace dataWhile the account is active
After you close your account or we terminate it[[DELETION_WINDOW]] days, then permanently deleted. You can export before that.
Backups[[BACKUP_RETENTION]] days, after which deleted data ages out of backups too
Invoices and financial recordsAs long as Indian tax and companies law requires — typically 8 years
Security and audit logs[[LOG_RETENTION]]

Under the DPDP Act we must erase personal data once the purpose it was collected for is served, unless a law requires us to keep it. Where we are your firm's processor, deletion follows your firm's instruction.

10. How we protect data

  • Encryption in transit — TLS on every connection to our services.
  • Encryption at rest — database and file storage encrypted using AWS-managed keys.
  • Passwords — stored only as salted hashes. We cannot read your password, and nobody at HireMaze can tell you what it is.
  • Access control — role-based permissions throughout, so people see only what their role allows. Client portals are scoped to a single client record.
  • Least privilege internally — staff access to production is restricted and logged.
  • Two-factor authentication available on accounts.

No system is perfectly secure, and we will not claim otherwise. We do not currently hold [[CERTIFICATIONS_OR_NONE]].

11. Your rights

As a Data Principal under the DPDP Act, for data where we are the Data Fiduciary (section 2), you have the right to:

  • Access — a summary of the personal data we hold about you and how it is processed.
  • Correction and completion — have inaccurate or incomplete data fixed.
  • Erasure — have your data deleted where we no longer need it and no law requires us to keep it.
  • Withdraw consent — as easily as you gave it. Withdrawing may mean we can no longer provide parts of the service.
  • Nominate — name someone to exercise these rights on your behalf if you die or become incapacitated.
  • Grievance redressal — see section 12. You must raise a grievance with us before approaching the Data Protection Board of India.

To exercise any of these, email privacy@hiremaze.in. We may need to verify your identity first. We will respond within [[RESPONSE_SLA_DAYS]] days.

12. Grievance Officer

In accordance with the DPDP Act, 2023 and the Information Technology Act, 2000, the following person is our designated Grievance Officer:

Name: [[GRIEVANCE_OFFICER_NAME]]
Designation: [[GRIEVANCE_OFFICER_TITLE]]
Email: [[GRIEVANCE_OFFICER_EMAIL]]
Address: [[REGISTERED_ADDRESS]]
We acknowledge within: [[ACK_DAYS]] days  ·  and resolve within: [[RESOLVE_DAYS]] days

This must be a real, named person

The DPDP Act requires a named contact, not a role inbox alone. If you are unsatisfied with our response you may escalate to the Data Protection Board of India.

13. If there is a data breach

If a personal data breach occurs, we will notify the Data Protection Board of India and every affected Data Principal without undue delay, as the DPDP Act requires. Where we are your firm's processor, we will notify your firm promptly so it can meet its own obligations to its employees and clients.

Our notice will describe what happened, the data involved, the likely consequences, and what we are doing about it.

14. Children's data

HireMaze is a workplace tool and is not intended for anyone under 18. We do not knowingly create accounts for children. Under the DPDP Act, processing a child's personal data requires verifiable parental consent, and tracking or behavioural advertising directed at children is prohibited — we do neither.

If you believe a child's data has reached us, contact our Grievance Officer and we will delete it.

15. Changes to this policy

We may update this policy as the product and the law change. The "last updated" date at the top always reflects the current version. If a change materially affects your rights we will tell you by email or an in-product notice before it takes effect.

16. Contact us

Privacy questions: privacy@hiremaze.in
Anything else: info@hiremaze.in or the contact form.

[[COMPANY_LEGAL_NAME]]
[[REGISTERED_ADDRESS]]