LEGAL · PRIVACY
Privacy policy
How Cyphertree collects, uses, and protects your personal data.
Draft, pending legal review. This document is published for transparency and is being finalised with counsel. For a binding agreement, contact support@cyphertree.com.
Data Controller
Note: This policy complies with the EU General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act 2023 (DPDP Act), and Google API Services User Data Policy.
Cyphertree Technologies
[Your Registered Address], Pune, Maharashtra, India
Email: privacy@cyphertree.com
Under GDPR, Cyphertree is the data controller. Under DPDP, Cyphertree is the Data Fiduciary.
Data We Collect
| Category | Data elements | When collected |
|---|---|---|
| Account Data | Name, email, password (hashed), profile photo (via Google OAuth) | Registration |
| Company Data | Business name, registration number, address, tax IDs (KVK, BTW) | Client onboarding |
| Employee Data | Name, contact details, employment terms, salary, bank details, PAN, Aadhaar | Employee onboarding |
| Recruitment Data | Resumes, cover letters, assessments, AI ranking scores, interview notes | Job application |
| Financial Data | Payment information, invoices, payroll records, TDS filings | Billing & payroll |
| Contract & Signature Data | Electronic signatures, signed documents, RFC-3161 timestamps | Contract execution |
| Performance Data | Reviews, goals, feedback, ratings | Performance cycles |
| Technical Data | IP address, browser type, device info, access logs, session tokens | Platform usage |
| Google Account Data | Email, name, profile picture (OAuth); Calendar events (Calendar API) | OAuth consent |
Google API Services
Note: Google API Services User Data Policy Compliance
Cyphertree's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we access:
- Google OAuth 2.0 — Your Google account name, email address, and profile picture solely for authentication and account creation.
- Google Calendar API — With your explicit consent, we read and write calendar events to schedule interviews and HR-related meetings.
How we use Google data:
- Authentication and account identity verification
- Scheduling interviews and HR-related calendar events
- Displaying your name and profile picture within the platform
We do NOT:
- Transfer Google user data to third parties except as necessary to provide platform features or as required by law
- Use Google user data for advertising, marketing, or profiling purposes
- Use Google user data to train AI or machine learning models
- Allow humans to read Google user data unless (a) you give explicit consent, (b) it is necessary for security, (c) required by law, or (d) data has been anonymised
- Store Google OAuth refresh tokens beyond active platform use — tokens are revoked upon account deletion
Note: You can revoke Cyphertree's access to your Google data at any time via Google Account Permissions.
Legal Basis
| Processing activity | GDPR basis | DPDP basis |
|---|---|---|
| Account creation & authentication | Art. 6(1)(b) — Contract | Sec. 7(a) — Deemed consent |
| Google OAuth sign-in | Art. 6(1)(a) — Consent | Sec. 4 — Consent |
| Google Calendar integration | Art. 6(1)(a) — Consent | Sec. 4 — Consent |
| Payroll & tax processing | Art. 6(1)(c) — Legal obligation | Sec. 7(b) — Legal obligation |
| Employee lifecycle management | Art. 6(1)(b) — Contract | Sec. 7(a) — Deemed consent |
| Electronic signatures | Art. 6(1)(b) — Contract | Sec. 7(a) — Deemed consent |
| Performance management | Art. 6(1)(f) — Legitimate interest | Sec. 7(a) — Deemed consent |
| Recruitment / ATS | Art. 6(1)(b) — Pre-contractual steps | Sec. 7(a) — Deemed consent |
| AI candidate ranking | Art. 6(1)(a) — Consent | Sec. 4 — Consent |
| Transactional emails (Resend) | Art. 6(1)(b) — Contract | Sec. 7(a) — Deemed consent |
| Marketing emails | Art. 6(1)(a) — Consent | Sec. 4 — Consent |
| Platform security | Art. 6(1)(f) — Legitimate interest | Sec. 7(f) — Legitimate use |
AI-Powered Processing
Our ATS uses AI to rank and screen applicants. This assists human recruiters — it does not make autonomous hiring decisions. You have the right to: human review, explanation of AI logic, contest the outcome, and opt out of AI screening entirely.
Data Storage & Security
| Measure | Details |
|---|---|
| Database | Neon (PostgreSQL) — EU Frankfurt region |
| Hosting / CDN | Cloudflare — global edge with EU processing |
| Resend — transactional and marketing emails | |
| Encryption in transit | TLS 1.3 on all connections |
| Encryption at rest | AES-256 for sensitive fields (PAN, Aadhaar, bank details) |
| Access control | Multi-tenant RBAC with PostgreSQL Row-Level Security |
| Audit logging | All PII access logged with user, action, timestamp |
| Breach response | 72-hour notification (GDPR Art. 33 / DPDP Sec. 8) |
Cross-Border Transfers
| Transfer | Safeguard | Mechanism |
|---|---|---|
| EU → India (operations) | Standard Contractual Clauses (2021) | GDPR Art. 46(2)(c) |
| Via Cloudflare | Cloudflare DPA + SCCs | GDPR Art. 46(2)(c) |
| Via Neon (EU Frankfurt) | Data stays in EU | No transfer required |
| Via Resend | Resend DPA + SCCs | GDPR Art. 46(2)(c) |
| Via Google APIs | Google DPA + SCCs | GDPR Art. 46(2)(c) |
Data Retention
| Data type | Retention | Basis |
|---|---|---|
| Account data | Duration + 30 days after deletion | Contract |
| Payroll & TDS records | 8 years post-employment | Indian IT Act |
| Employee contracts | Duration + 3 years | Indian Limitation Act |
| Rejected candidates | 24 months from rejection | Proportionality |
| Electronic signatures | 7–10 years | Indian IT Act / eIDAS |
| Performance reviews | Duration + 3 years | Dispute limitation |
| Google OAuth tokens | Duration of active account | Revoked on deletion |
| Google Calendar data | Not stored — real-time API access only | N/A |
| Audit logs | 5 years | Compliance |
Your Rights
| Right | GDPR | DPDP | How |
|---|---|---|---|
| Access | Art. 15 | Sec. 11 | Request a copy of all data we hold |
| Rectification | Art. 16 | Sec. 12 | Correct inaccurate data |
| Erasure | Art. 17 | Sec. 13 | Request account and data deletion |
| Portability | Art. 20 | — | Export in JSON/CSV |
| Restriction | Art. 18 | — | Pause processing |
| Objection | Art. 21 | — | Object to legitimate interest processing |
| Withdraw consent | Art. 7(3) | Sec. 6(4) | Withdraw at any time |
| Grievance | — | Sec. 13 | File with Grievance Officer |
| Nomination | — | Sec. 14 | Nominate a representative |
Exercise your rights: Email privacy@cyphertree.com with subject "Data Subject Request — [Your Name]". We respond within 30 days.
Account deletion: Email support@cyphertree.com. Processed within 30 days, subject to legal retention.
Google data: Revoke at myaccount.google.com/permissions.
Third-Party Processors
| Processor | Purpose | Location | DPA |
|---|---|---|---|
| Neon | Database hosting | EU (Frankfurt) | ✅ |
| Cloudflare | CDN, DNS, security | Global (EU processing) | ✅ |
| Resend | Email delivery | US (with SCCs) | ✅ |
| OAuth, Calendar API | Global (with SCCs) | ✅ | |
| AI model provider | Resume screening | API only, no retention | ✅ |
We do not sell personal data to any third party.
Marketing Communications
Marketing emails require explicit consent and include an unsubscribe link. Transactional emails (account notifications, payroll confirmations) do not require marketing consent.
Children's Data
Our platform is for users aged 18+. We do not knowingly collect data from minors. Under DPDP Sec. 9, processing children's data requires verifiable parental consent.
Supervisory Authorities
EEA residents: Autoriteit Persoonsgegevens (Netherlands).
Indian residents: Data Protection Board of India, after exhausting our internal grievance mechanism.
Changes
Material changes notified 14 days in advance via email or platform notice.
Contact
Privacy: privacy@cyphertree.com
Grievance Officer (DPDP): grievance@cyphertree.com
Related documents: Terms of Use · Cookie Policy · Applicant Privacy Notice