Effective [TODO: date] · Last updated [TODO: date]

This page describes ApriCOT’s organisational compliance posture under the DPDP Act, 2023 — written for client organisations and their legal teams. If you are a candidate or employee looking for how your own data is handled, see the Privacy Policy.

1. Our Role — Data Fiduciary or Data Processor

[TODO: This is the first thing a buyer’s legal team looks for — state it plainly and early. Needs: the specific circumstances in which ApriCOT acts as Data Processor (processing candidate data on instruction from a client organisation, which is the Data Fiduciary), versus the circumstances in which ApriCOT is itself the Data Fiduciary (e.g. its own marketing contacts, website visitors, direct account holders). Where the boundary sits determines who owes what obligation, so ambiguity here is worse than brevity. Source: legal, with engineering input on which data flows exist in practice.]

2. Lawful Basis and Consent Architecture

[TODO: The lawful basis relied on for each processing purpose, and how consent is actually captured in the product — who presents the consent request to the candidate (client organisation or ApriCOT), at what point in the flow, and how the record of that consent is stored and produced on request. Note whether any processing relies on a legitimate-use ground rather than consent. Source: legal + engineering.]

3. Notice Provided to Data Principals

[TODO: What notice candidates receive, when they receive it, and in which languages. DPDP requires notice to be available in English and the Eighth Schedule languages — confirm which are actually supported in-product today, not which are planned. Also state who is responsible for serving the notice where ApriCOT acts as Processor. Source: legal + product.]

4. Data Principal Rights and How We Support Them

[TODO: For each right below — the mechanism by which a candidate exercises it, the turnaround commitment, and specifically how ApriCOT supports a client organisation in honouring it when ApriCOT is the Processor and the client is the Fiduciary. A buyer needs to know what they can promise their own candidates. Source: legal + engineering + support.]

  1. Right to Information about processing
  2. Right to Correction, Completion, Updating and Erasure
  3. Right to Grievance Redressal
  4. Right to Nominate

6. Data Retention and Deletion Schedule

[TODO: Retention period in days per data category — assessment transcripts, generated reports, account records, logs, backups — and the deletion process for each, including how deletion propagates to backups and any sub-processors. State whether retention is configurable per client contract. Source: engineering + legal.]

7. Security Safeguards

[TODO: Concrete safeguards only — encryption in transit and at rest with the actual standards used, access control and least-privilege model, logging and monitoring, personnel vetting, and any certifications or audits held (or an honest statement that none are held yet). Do not describe aspirational controls. Source: engineering + security.]

8. Cross-Border Transfer Position

[TODO: Where data is physically stored and processed, including the regions of any model/inference providers in the pipeline — this is frequently the deciding factor in an enterprise procurement review. State the position on transfers to restricted territories and any contractual safeguards in place. Source: engineering + legal.]

9. Breach Notification Process and Timelines

[TODO: The internal detection-to-notification process, the committed timeline for notifying an affected client organisation, and how notification to the Data Protection Board of India and to affected Data Principals is handled and by whom. Give hours or days, not “promptly.” Source: engineering + legal.]

10. Grievance Officer

[TODO: DPDP requires a named grievance contact — a person, with a name and a direct contact route. A generic inbox such as privacy@ does not satisfy this and will be flagged in due diligence. Needs: the officer’s name, designation, email and postal address, the response-time commitment, and the escalation path to the Data Protection Board of India if the grievance is not resolved. Source: legal — this requires an actual internal appointment, not a copy decision.]

Grievance Officer

[TODO: named individual — name, designation, email, postal address]

11. Sub-Processors

[TODO: The current sub-processor list — each entity, what it processes, and where. Model and infrastructure providers belong here. Also state how clients are notified of changes to this list and whether they may object. Buyers routinely require this as a maintained, dated list rather than prose. Source: engineering + legal.]

12. Children and Persons with Disabilities

[TODO: State the position on processing data of persons under 18 and of persons with a lawful guardian — including whether the product is intended for such users at all, how age is established, and the verifiable-consent mechanism where a guardian’s consent is required. If ApriCOT is not intended for under-18 use, say so explicitly; that is itself the answer a buyer needs. Source: legal + product.]