Privacy Policy
Last updated:
Placeholder. Replace the sections below with your reviewed policy text. The structure, headings and DPDP framing are here so the page is live, linkable and indexable — but the wording needs legal review before it is relied on.
Who we are
Sivett is a product of Celerinn Technologies Pvt Ltd, Hyderabad, India. This policy explains how we handle personal data across our website and our recruitment platform.
Our role under the DPDP Act
Where a customer uses Sivett to process candidate data, that customer is the Data Fiduciary and determines the purpose of processing. Sivett acts as a Data Processor and processes candidate data only on that customer's documented instruction. A Data Processing Agreement and our full sub-processor list are available on request.
Data we process
- Candidate data supplied by our customers or submitted by candidates — CVs, contact details, screening responses and interview transcripts.
- Customer account data — names, work email addresses and role information for users of the platform.
- Website data — basic analytics and any details you submit when booking a walkthrough.
How we use it
To provide the platform: scoring applicants against customer-defined requirements, conducting screening conversations, running structured first-round interviews, and returning ranked shortlists to the customer.
Model training
Candidate data is never used to train models. Our LLM provider does not train on API inputs or outputs.
Where data is stored
Application and database infrastructure is hosted in an Indian region. Interview recordings are held on object storage; the region is confirmed in writing at contracting.
Retention
State your retention periods for candidate data, interview recordings and account data, and what happens on contract termination.
Sharing and sub-processors
List the categories of sub-processor you use (cloud hosting, LLM provider, WhatsApp Business API provider, analytics) and link to the current sub-processor list.
Your rights
Candidates wishing to access, correct or erase their data should contact the organisation they applied to, as that organisation is the Data Fiduciary. We will support our customers in responding to those requests.
Security
Describe your security controls — encryption in transit and at rest, access control, logging, incident response.
Contact
Add the contact route for privacy queries and the name of your Grievance Officer, which the DPDP Act requires you to publish.