Privacy & Security Policy
This Privacy & Security Policy ("Policy") describes how KaaryaSatya Verify (the "Service") collects, uses, discloses and protects personal data ("Personal Data"), and the rights available to a Candidate, a Customer, or a visitor to this website.
Effective and last updated: 1 August 2026. This Policy is published by Prathibha's Make My Designz LLP, trading as PriveSecure ("PriveSecure," "we" or "us"), the operator of KaaryaSatya Verify. This Policy applies generally to the Service. Where a signed agreement between PriveSecure and a Customer addresses the same subject matter, that agreement governs as between the parties. A detailed mapping of this Policy against India's Digital Personal Data Protection Act, 2023 is available at Data Protection & DPDP Act Compliance.
1. Scope and definitions
1.1 This Policy applies to three categories of individual.
- Candidate: an individual whose employment history and identity details are submitted to the Service for verification, whether by a Customer or by the individual directly.
- Customer: a recruiting organisation that holds an account on the Service, together with its authorised users.
- Visitor: any other individual accessing this website prior to account creation.
1.2 Where a Candidate's data is submitted by a Customer for a specific hiring decision, the Customer determines the purpose of the screening and is responsible, as between the Customer and the Candidate, for the underlying hiring relationship. PriveSecure processes the data submitted for the purpose of providing the Service, on the Customer's instructions.
2. Information collected
2.1 PriveSecure collects the following categories of Personal Data.
- Contact and identity details: name, postal address, phone number and email address.
- Aadhaar number: subject to masking by default. Clause 5 sets out the precise scope of what is stored.
- Universal Account Number (UAN), where supplied, used to verify employment history against EPFO-linked records.
- Resume or supporting documents submitted by or on behalf of a Candidate, and the employment and education details extracted from them.
- Verification outcomes: the result of each check performed and its supporting detail.
- Consent records: the manner, timing and current status of consent.
- Account and security information: authentication credentials, stored as a one-way hash, and two-factor authentication configuration.
2.2 PriveSecure does not collect Personal Data beyond these categories, and does not retrieve or aggregate information about a Candidate from LinkedIn, other social platforms or the public internet. Where a Customer submits ancillary evidence from such sources, it is entered as a labelled manual note and is not obtained by automated means.
3. Use of information
3.1 Personal Data described in Clause 2 is used solely to:
- perform the identity and employment verification checks requested by a Candidate or a Customer, and generate a result;
- operate account functionality, including authentication and access to a Candidate's or Customer's own records;
- bill a Customer for checks performed and maintain the records required to do so accurately;
- respond to support requests and to requests made under Clause 8; and
- meet PriveSecure's legal and security obligations, including the investigation of misuse or a security incident.
3.2 Personal Data is not used for advertising, is not sold, and is not used to build a profile of a Candidate beyond the specific screening for which consent has been given.
4. Consent requirement
4.1 No identity or employment check is submitted or processed without a recorded, valid consent from the Candidate. This requirement is enforced by the Service's technical architecture. A verification request submitted against a Candidate record with no granted consent is rejected automatically, independent of this Policy.
4.2 Consent is obtained in one of two ways. A Customer may capture consent through its own hiring process and supply a reference to it, comprising a unique identifier, timestamp and the version of the consent text presented. Alternatively, PriveSecure sends the Candidate a plain-language, itemised request, identifying the data source, the purpose and the intended retention period, confirmed by a one-time code. A decline or non-response is recorded, and no further processing occurs for that check.
4.3 Consent may be withdrawn at any time, which halts any further check. Withdrawal does not affect a check already completed. Re-verification of a previously checked Candidate requires fresh consent.
5. Security safeguards
5.1 PriveSecure applies the following safeguards to the Service.
- Mandatory multi-factor authentication. Every account, whether Candidate, Customer or administrator, requires two-factor authentication before use. No role is exempt.
- Encryption in transit and at rest. All traffic to and from the Service is transmitted over HTTPS, and unencrypted requests are rejected. Data at rest is encrypted by the database provider as a standard platform feature.
- Aadhaar masking by default. Where a Customer enters a Candidate's Aadhaar number on the Candidate's behalf, it is masked on receipt: only the last four digits and a one-way cryptographic hash are stored, and the full number is not persisted. Where identity verification instead proceeds through a DigiLocker-based flow, PriveSecure does not receive the raw Aadhaar number, and only a verified, masked confirmation is returned to the Service.
- Role-based, tenant-isolated access. A Candidate may access only their own record, and a Customer may access only its own Candidates. Administrative access is provisioned through a controlled internal process rather than public registration, with database-level access restrictions applied as an additional control beneath the application layer.
- Provider confidentiality. The identity of the underlying verification provider and its raw response are not disclosed to the Candidate or the Customer. Only the verification result is disclosed.
5.2 PriveSecure maintains a written information security programme describing these controls in further detail, available to Customers on request.
7. Retention
7.1 The default retention period is 180 days following completion of a Candidate's verification, or immediate deletion upon withdrawal of consent if earlier. This period is stated to every Candidate as part of the consent notice presented before a check is performed.
7.2 A Customer may configure a different retention period appropriate to its own requirements by specifying this in its engagement with PriveSecure. A Candidate may likewise request early deletion under Clause 8.
8. Rights and requests
8.1 A Candidate may exercise the following rights by submitting a request to the contact address at Clause 13.
- Access: a summary of the Personal Data held and its processing history.
- Correction: of inaccurate or outdated Personal Data.
- Erasure: of Personal Data no longer necessary for the purpose for which it was collected, subject to any overriding legal or contractual record-keeping requirement.
- Withdrawal of consent, at any time, with prospective effect only.
- Grievance redressal, whereby a request is reviewed directly by PriveSecure.
- Nomination of another individual to exercise these rights on the Candidate's behalf in the event of death or incapacity.
8.2 PriveSecure targets acknowledgement of a request within five business days and resolution within thirty days. Where a request concerns a check performed for a specific Customer, PriveSecure may confirm relevant details with that Customer prior to acting on the request, given the Customer's own responsibilities in respect of the underlying hiring decision.
9. Cookies and tracking
9.1 The Service does not employ advertising or analytics trackers. As of the date of this Policy, the website sets no cookies. Session authentication is maintained in browser local storage and is cleared on sign-out or session expiry.
9.2 Infrastructure providers may set limited, non-identifying technical cookies for security or performance purposes. No cookie or similar technology is used for tracking or advertising on this website.
10. Location of processing
10.1 Personal Data is processed using secure cloud infrastructure operated by established third-party providers, with encryption applied to all data in transit and at rest.
10.2 The database in which Personal Data is stored is located within India. Other components of the Service may use cloud infrastructure located outside India.
11. Children's privacy
11.1 The Service is intended for the screening of adult job candidates and is not directed at, marketed to, or intended for use by children. PriveSecure does not knowingly collect the Personal Data of a child through the Service, and will delete any such data promptly upon becoming aware of it.
12. Amendment of this Policy
12.1 This Policy is reviewed no less than annually, and upon any material change to the processing of Personal Data by the Service. The date at the top of this Policy indicates the date of last revision. A material amendment will be indicated on this page.
This Policy is not a substitute for independent legal advice. A Customer with its own compliance obligations should have this Policy reviewed by counsel alongside its services agreement with PriveSecure.
13. Contact
13.1 Questions concerning this Policy, and requests under Clause 8, may be directed to:
13.2 A request should include sufficient detail to identify the relevant record, for example the name and the phone number or email address used at the time of submission, and the Customer involved, if known.
