Recruiter Privacy Policy

For airlines, MROs and aviation organisations · Version 1.0 · Effective [EFFECTIVE DATE]

The short version

This policy has two halves, and the second is the one people miss.

Before this page goes live Complete every [BRACKETED] item, confirm hosting regions against your actual Supabase and Cloudflare configuration, and have this reviewed by a data-protection lawyer. Not legal advice.

1.Who is responsible

[LEGAL ENTITY NAME], of [REGISTERED ADDRESS], is the data controller for the data described in Part A.

Contact: connect@iatas.in
Grievance Officer (India, DPDP Act 2023): [NAME], [EMAIL]
Data Protection Officer (if appointed): [NAME / OR STATE NOT APPLICABLE]

Engineers' own data is covered by the Engineer Privacy Policy.

2.Part A — what we collect about you

CategoryWhat it includes
AccountYour name, work email, password (stored hashed), role
ProfessionalJob title, contact phone, your relationship to the organisation
OrganisationName, type, size, website, description, logo, country and city, registration number and country
VerificationDocuments you upload to prove the organisation is genuine and that you may hire for it
ActivityRoles posted, searches run, candidates viewed, shortlisted or moved through your pipeline, messages sent
Billing[If you charge: billing contact, address, tax identifiers. Card data is handled by the payment provider and never reaches us — confirm and name the provider.]
TechnicalIP address, browser and device type, pages requested, timestamps, error diagnostics

3.Why we use it

PurposeLawful basis
Create and run your account and organisation profilePerformance of a contract
Verify that your organisation is genuineLegitimate interests — protecting engineers from fraudulent recruiters
Publish your roles and organisation details to engineersPerformance of a contract
Show engineers which organisations viewed their profileLegitimate interests — transparency for the individual whose data was accessed
Detect bulk extraction, scraping and misuse of candidate dataLegitimate interests; legal obligation
Service email and, where applicable, billingPerformance of a contract
Product updates and marketingYour consent — unsubscribe any time

We do not sell your data, and we do not use it to train machine-learning models for third parties.

4.What engineers can see about you

Recruiting is not anonymous on IATAS. Engineers can see:

  • your organisation's name, logo, type, location and description;
  • the roles you have posted;
  • that your organisation viewed their profile, and when;
  • your name and job title when you message them.

If profile-view transparency is incompatible with how you recruit, IATAS is not the right platform.

5.Who we share it with

ProviderWhat forWhat they receive
SupabaseDatabase, authentication, file storageAccount, organisation and activity data
CloudflareHosting, DNS, securityTechnical request data
BrevoTransactional emailName and email address
[Payment provider]Billing, if charges apply[Complete or remove]

We also disclose data where legally required, to enforce our Recruiter Terms, or to protect engineers from harm — including informing an engineer, or a regulator, where an organisation has charged a fee in breach of clause 7.

6.Part B — candidate data you access

Through IATAS you will access personal data belonging to engineers. What you can see depends on how far the relationship has gone:

DataIn search resultsOnce in contact
Name, photo, headline, licence, ratings, experience, skills, education, location, availabilityVisibleVisible
Email address and phone numberNot visibleVisible
Salary expectation, service bond detailsVisibleVisible
Talent-pool entries (engineers not yet registered)Masked name, no contact detailsOnly after they claim their profile

Accessing an engineer's profile is recorded and shown to that engineer.

7.When you become a controller

While candidate data stays on IATAS, we are its controller and we are accountable for it.

The moment you take a copy off the platform — printing a profile, pasting details into your applicant-tracking system, exporting a shortlist, screenshotting a profile — you become an independent controller of that copy. From that point our privacy policy does not cover it, and yours must.

We are not your processor for that copy, and this policy is not a data-processing agreement. If your compliance function requires one for the data you extract, contact connect@iatas.in.

8.Your duties for candidate data

For any candidate data you hold outside IATAS you are responsible under applicable law — including India's Digital Personal Data Protection Act 2023 and, where it applies, the UK/EU GDPR — for:

  • Lawful basis — having one, and being able to demonstrate it;
  • Transparency — giving candidates your own privacy notice covering your use of their data;
  • Purpose limitation — using it only for the role it was collected for;
  • Minimisation — holding only what you need;
  • Security — protecting it with appropriate technical and organisational measures;
  • Retention — deleting it when the hiring purpose ends;
  • Individual rights — handling access, correction, erasure and objection requests for your copy. We cannot do this for you and will forward such requests to you;
  • Breach notification — notifying the relevant authority and affected individuals if your copy is compromised;
  • Transfers — putting safeguards in place if you move the data across borders, including to a parent or group company.

Deletion does not propagate. When an engineer deletes their IATAS profile, that removes their data from our systems. It does not touch copies in yours. Acting on that is your legal obligation, and clause 20 of the Recruiter Terms makes you responsible for the consequences of failing to.

9.Where data is stored

Data is held on Supabase infrastructure in [REGION — confirm in the Supabase dashboard] and served through Cloudflare's global network. Where data moves outside your country we rely on [STANDARD CONTRACTUAL CLAUSES / OTHER MECHANISM].

10.How long we keep it

DataRetention
Account and organisation profileWhile your account is open
After account closureRemoved from live systems promptly; backups purged within [e.g. 30 days]
Posted roles and applications[PERIOD] after the role closes
Profile-view recordsRetained so engineers keep visibility of who viewed them — [PERIOD]
MessagesRetained for the engineer participant
Billing and tax recordsAs long as the law requires

11.Your rights

In relation to your own personal data you may request access, correction, deletion, portability, restriction, or object to processing based on legitimate interests, and withdraw consent to marketing at any time. Under India's DPDP Act you may also nominate someone to exercise your rights.

Email connect@iatas.in. We respond within 30 days at no charge.

These rights cover your data. Requests about candidate data held in your own systems must go to you, not to us.

12.How we protect it

  • Encrypted in transit over HTTPS, with HSTS enforced.
  • Passwords hashed by our authentication provider; nobody at IATAS can read them.
  • Row-level security in the database, so an account reaches only the records it is entitled to.
  • Verification documents held in a private bucket, served only through short-lived signed links.
  • Response headers restricting framing and content sources.
  • Administrative access limited to staff who need it.

If a breach affects your data and creates a risk to you, we will notify you and the relevant authority as the law requires.

13.Cookies and local storage

Essential storage only — keeping you signed in and remembering interface preferences such as saved searches — plus a Cloudflare security cookie. No advertising cookies, cross-site trackers or third-party analytics profiling.

14.Changes

We may update this policy. The version and effective date at the top will change, and we will notify you of material changes before they take effect.

15.Contact and complaints

Questions or requests: connect@iatas.in
Grievance Officer: [NAME], [EMAIL]
Postal: [REGISTERED ADDRESS]

If you are not satisfied you may complain to the Data Protection Board of India (once constituted under the DPDP Act 2023), your EU/EEA national supervisory authority, or the UK Information Commissioner's Office.

See also the Recruiter Terms · Engineer Privacy Policy · Back to IATAS