1.Who is responsible
[LEGAL ENTITY NAME], of [REGISTERED ADDRESS], is the data controller for the data described in Part A.
Contact: connect@iatas.in
Grievance Officer (India, DPDP Act 2023): [NAME], [EMAIL]
Data Protection Officer (if appointed): [NAME / OR STATE NOT APPLICABLE]
Engineers' own data is covered by the Engineer Privacy Policy.
2.Part A — what we collect about you
| Category | What it includes |
|---|---|
| Account | Your name, work email, password (stored hashed), role |
| Professional | Job title, contact phone, your relationship to the organisation |
| Organisation | Name, type, size, website, description, logo, country and city, registration number and country |
| Verification | Documents you upload to prove the organisation is genuine and that you may hire for it |
| Activity | Roles posted, searches run, candidates viewed, shortlisted or moved through your pipeline, messages sent |
| Billing | [If you charge: billing contact, address, tax identifiers. Card data is handled by the payment provider and never reaches us — confirm and name the provider.] |
| Technical | IP address, browser and device type, pages requested, timestamps, error diagnostics |
3.Why we use it
| Purpose | Lawful basis |
|---|---|
| Create and run your account and organisation profile | Performance of a contract |
| Verify that your organisation is genuine | Legitimate interests — protecting engineers from fraudulent recruiters |
| Publish your roles and organisation details to engineers | Performance of a contract |
| Show engineers which organisations viewed their profile | Legitimate interests — transparency for the individual whose data was accessed |
| Detect bulk extraction, scraping and misuse of candidate data | Legitimate interests; legal obligation |
| Service email and, where applicable, billing | Performance of a contract |
| Product updates and marketing | Your consent — unsubscribe any time |
We do not sell your data, and we do not use it to train machine-learning models for third parties.
4.What engineers can see about you
Recruiting is not anonymous on IATAS. Engineers can see:
- your organisation's name, logo, type, location and description;
- the roles you have posted;
- that your organisation viewed their profile, and when;
- your name and job title when you message them.
If profile-view transparency is incompatible with how you recruit, IATAS is not the right platform.
6.Part B — candidate data you access
Through IATAS you will access personal data belonging to engineers. What you can see depends on how far the relationship has gone:
| Data | In search results | Once in contact |
|---|---|---|
| Name, photo, headline, licence, ratings, experience, skills, education, location, availability | Visible | Visible |
| Email address and phone number | Not visible | Visible |
| Salary expectation, service bond details | Visible | Visible |
| Talent-pool entries (engineers not yet registered) | Masked name, no contact details | Only after they claim their profile |
Accessing an engineer's profile is recorded and shown to that engineer.
7.When you become a controller
While candidate data stays on IATAS, we are its controller and we are accountable for it.
The moment you take a copy off the platform — printing a profile, pasting details into your applicant-tracking system, exporting a shortlist, screenshotting a profile — you become an independent controller of that copy. From that point our privacy policy does not cover it, and yours must.
We are not your processor for that copy, and this policy is not a data-processing agreement. If your compliance function requires one for the data you extract, contact connect@iatas.in.
8.Your duties for candidate data
For any candidate data you hold outside IATAS you are responsible under applicable law — including India's Digital Personal Data Protection Act 2023 and, where it applies, the UK/EU GDPR — for:
- Lawful basis — having one, and being able to demonstrate it;
- Transparency — giving candidates your own privacy notice covering your use of their data;
- Purpose limitation — using it only for the role it was collected for;
- Minimisation — holding only what you need;
- Security — protecting it with appropriate technical and organisational measures;
- Retention — deleting it when the hiring purpose ends;
- Individual rights — handling access, correction, erasure and objection requests for your copy. We cannot do this for you and will forward such requests to you;
- Breach notification — notifying the relevant authority and affected individuals if your copy is compromised;
- Transfers — putting safeguards in place if you move the data across borders, including to a parent or group company.
Deletion does not propagate. When an engineer deletes their IATAS profile, that removes their data from our systems. It does not touch copies in yours. Acting on that is your legal obligation, and clause 20 of the Recruiter Terms makes you responsible for the consequences of failing to.
9.Where data is stored
Data is held on Supabase infrastructure in [REGION — confirm in the Supabase dashboard] and served through Cloudflare's global network. Where data moves outside your country we rely on [STANDARD CONTRACTUAL CLAUSES / OTHER MECHANISM].
10.How long we keep it
| Data | Retention |
|---|---|
| Account and organisation profile | While your account is open |
| After account closure | Removed from live systems promptly; backups purged within [e.g. 30 days] |
| Posted roles and applications | [PERIOD] after the role closes |
| Profile-view records | Retained so engineers keep visibility of who viewed them — [PERIOD] |
| Messages | Retained for the engineer participant |
| Billing and tax records | As long as the law requires |
11.Your rights
In relation to your own personal data you may request access, correction, deletion, portability, restriction, or object to processing based on legitimate interests, and withdraw consent to marketing at any time. Under India's DPDP Act you may also nominate someone to exercise your rights.
Email connect@iatas.in. We respond within 30 days at no charge.
These rights cover your data. Requests about candidate data held in your own systems must go to you, not to us.
12.How we protect it
- Encrypted in transit over HTTPS, with HSTS enforced.
- Passwords hashed by our authentication provider; nobody at IATAS can read them.
- Row-level security in the database, so an account reaches only the records it is entitled to.
- Verification documents held in a private bucket, served only through short-lived signed links.
- Response headers restricting framing and content sources.
- Administrative access limited to staff who need it.
If a breach affects your data and creates a risk to you, we will notify you and the relevant authority as the law requires.
14.Changes
We may update this policy. The version and effective date at the top will change, and we will notify you of material changes before they take effect.
15.Contact and complaints
Questions or requests: connect@iatas.in
Grievance Officer: [NAME], [EMAIL]
Postal: [REGISTERED ADDRESS]
If you are not satisfied you may complain to the Data Protection Board of India (once constituted under the DPDP Act 2023), your EU/EEA national supervisory authority, or the UK Information Commissioner's Office.