HireMaze is used by firms to run their people and their clients. That means we hold two very different kinds of information: data about you, the person with an account, and data your firm has entered about other people — its employees and its clients. This policy is explicit about which is which.
1. Who we are
HireMaze is operated by [[COMPANY_LEGAL_NAME]], a company incorporated in India under CIN [[CIN]], with its registered office at [[REGISTERED_ADDRESS]].
In this policy, "HireMaze", "we", "us" and "our" mean that company. "You" means the individual using the service. "Your firm" means the organisation whose HireMaze workspace you belong to.
This policy applies to hiremaze.in, the HireMaze application, and every public firm page and client portal we host on our domain.
2. Our two roles — and why it matters
Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), who decides why data is processed determines who is answerable for it. HireMaze sits on both sides of that line depending on the data:
| The data | Our role | What that means |
|---|---|---|
| Your account — your name, email, phone, login activity, billing details | Data Fiduciary (controller) | We decide why this is processed and are directly answerable to you for it. This policy governs it. |
| Data your firm enters — its employees' attendance and records, its clients' details, documents, invoices | Data Processor | Your firm is the Data Fiduciary. We only process it on your firm's instructions. Your firm's own privacy policy governs it, not this one. |
Your data was given to us by that firm, not collected by us from you. We cannot delete it, correct it or hand it over on your request — we are not permitted to act on your firm's data without their instruction. Contact your employer or the firm you are a client of. If you cannot reach them, write to our Grievance Officer in section 12 and we will route it.
3. What we collect
Information you give us
- Account details — name, work email, phone number, password (stored hashed, never in readable form).
- Firm details — firm name, the address you claim at hiremaze.in/your-firm, firm size, industry, GSTIN where you provide one.
- Anything you enter into the product — see section 5.
- What you send us — enquiries through our contact form, WhatsApp or email, and any support correspondence.
Information we collect automatically
- Technical data — IP address, browser and device type, operating system, referring page, and the pages you view.
- Usage data — features used, actions taken and timestamps, so we can operate, secure and improve the service.
- Cookies and similar technologies — see section 6.
We do not knowingly collect sensitive categories such as caste, religion, biometric identifiers or health data for our own purposes. If your firm chooses to store such information in free-text fields, it does so as the Data Fiduciary and under its own responsibility.
4. Why we process your data
| Purpose | Basis under the DPDP Act |
|---|---|
| Creating and running your account, and providing the service | Consent / performance of the service you asked for |
| Sending transactional messages — OTPs, invites, notifications, service notices | Consent / legitimate use |
| Support and responding to your enquiries | Consent |
| Security, fraud prevention, abuse detection and debugging | Legitimate use |
| Aggregate analytics to understand and improve the product | Consent (you may withdraw — section 6) |
| Billing, invoicing and statutory records | Legal obligation |
| Marketing about HireMaze features | Consent — withdrawable at any time |
We do not sell your personal data. We do not share it with advertisers or data brokers, and we do not use your firm's data to train machine-learning models.
5. Data your firm puts into HireMaze
When your firm uses HireMaze it will enter information about people who never signed up with us — its employees and its clients. Typically:
- Employee records, attendance and check-in times, roles and permissions, tasks and tickets
- Client records and contacts, documents you request and they upload, and invoices
- Candidate and applicant details, where your firm uses the hiring module
For all of that, your firm is the Data Fiduciary and we are its processor. We commit that we:
- process it only to provide the service and only on your firm's instructions;
- do not use it for our own purposes, do not sell it, and do not train models on it;
- keep each firm's data logically separated, and scope every client portal to that client's own record;
- return or delete it on termination, per section 9.
If your firm enters personal data about its employees or clients, your firm is responsible for having a lawful basis to do so, for giving those people notice, and for answering their requests. Publishing an employee's attendance to a client portal is your firm's decision and your firm's disclosure. Please make sure your employment contracts and client agreements cover it.
7. Where your data is stored
Your data is stored in India. HireMaze runs on Amazon Web Services in the ap-south-1 (Mumbai) region — application databases on Amazon RDS for PostgreSQL, and uploaded files in Amazon S3, both in that region.
Some of the supporting services in section 8 are operated by companies outside India and may process limited data (such as analytics events or email delivery metadata) on infrastructure outside India. Where that happens we rely on the provider's contractual protections and on transfers being permitted under the DPDP Act.
8. Subprocessors
We use these third parties to run HireMaze. Each is bound by its own terms and processes data only as needed to provide its service to us.
| Provider | What it does for us | Where |
|---|---|---|
| Amazon Web Services | Application hosting, PostgreSQL database, file storage, CDN | India (ap-south-1) |
| Amazon SES | Transactional email — invites, notifications, password resets | AWS region [[SES_REGION]] |
| Amazon SNS | SMS, including one-time passcodes | AWS region [[SNS_REGION]] |
| Google Analytics 4 (Google) | Website and product usage analytics, IP-anonymised | Global |
| Google Firebase | [[FIREBASE_PURPOSE]] — project hiremaze-f31e2 | Global |
| Zoho Corporation | Our business email at hiremaze.in | India |
| [[PAYMENT_GATEWAY]] | Payment processing, once paid plans launch. We never see or store your full card details. | India |
This list was assembled from your codebase. Verify it is complete and current — an incomplete subprocessor list is one of the first things an enterprise customer's security review will catch, and under the DPDP Act you must be able to account for every processor handling data you are responsible for.
9. How long we keep data
| Data | Kept for |
|---|---|
| Your account and your firm's workspace data | While the account is active |
| After you close your account or we terminate it | [[DELETION_WINDOW]] days, then permanently deleted. You can export before that. |
| Backups | [[BACKUP_RETENTION]] days, after which deleted data ages out of backups too |
| Invoices and financial records | As long as Indian tax and companies law requires — typically 8 years |
| Security and audit logs | [[LOG_RETENTION]] |
Under the DPDP Act we must erase personal data once the purpose it was collected for is served, unless a law requires us to keep it. Where we are your firm's processor, deletion follows your firm's instruction.
10. How we protect data
- Encryption in transit — TLS on every connection to our services.
- Encryption at rest — database and file storage encrypted using AWS-managed keys.
- Passwords — stored only as salted hashes. We cannot read your password, and nobody at HireMaze can tell you what it is.
- Access control — role-based permissions throughout, so people see only what their role allows. Client portals are scoped to a single client record.
- Least privilege internally — staff access to production is restricted and logged.
- Two-factor authentication available on accounts.
No system is perfectly secure, and we will not claim otherwise. We do not currently hold [[CERTIFICATIONS_OR_NONE]].
11. Your rights
As a Data Principal under the DPDP Act, for data where we are the Data Fiduciary (section 2), you have the right to:
- Access — a summary of the personal data we hold about you and how it is processed.
- Correction and completion — have inaccurate or incomplete data fixed.
- Erasure — have your data deleted where we no longer need it and no law requires us to keep it.
- Withdraw consent — as easily as you gave it. Withdrawing may mean we can no longer provide parts of the service.
- Nominate — name someone to exercise these rights on your behalf if you die or become incapacitated.
- Grievance redressal — see section 12. You must raise a grievance with us before approaching the Data Protection Board of India.
To exercise any of these, email privacy@hiremaze.in. We may need to verify your identity first. We will respond within [[RESPONSE_SLA_DAYS]] days.
12. Grievance Officer
In accordance with the DPDP Act, 2023 and the Information Technology Act, 2000, the following person is our designated Grievance Officer:
Name: [[GRIEVANCE_OFFICER_NAME]]
Designation: [[GRIEVANCE_OFFICER_TITLE]]
Email: [[GRIEVANCE_OFFICER_EMAIL]]
Address: [[REGISTERED_ADDRESS]]
We acknowledge within: [[ACK_DAYS]] days · and resolve within: [[RESOLVE_DAYS]] days
The DPDP Act requires a named contact, not a role inbox alone. If you are unsatisfied with our response you may escalate to the Data Protection Board of India.
13. If there is a data breach
If a personal data breach occurs, we will notify the Data Protection Board of India and every affected Data Principal without undue delay, as the DPDP Act requires. Where we are your firm's processor, we will notify your firm promptly so it can meet its own obligations to its employees and clients.
Our notice will describe what happened, the data involved, the likely consequences, and what we are doing about it.
14. Children's data
HireMaze is a workplace tool and is not intended for anyone under 18. We do not knowingly create accounts for children. Under the DPDP Act, processing a child's personal data requires verifiable parental consent, and tracking or behavioural advertising directed at children is prohibited — we do neither.
If you believe a child's data has reached us, contact our Grievance Officer and we will delete it.
15. Changes to this policy
We may update this policy as the product and the law change. The "last updated" date at the top always reflects the current version. If a change materially affects your rights we will tell you by email or an in-product notice before it takes effect.
16. Contact us
Privacy questions: privacy@hiremaze.in
Anything else: info@hiremaze.in or the contact form.
[[COMPANY_LEGAL_NAME]]
[[REGISTERED_ADDRESS]]