1. Statutory Compliance (DPDP Act 2023)
As a Data Fiduciary operating in India, we adhere strictly to the Digital Personal Data Protection Act, 2023. We enforce purpose limitation, notice requirements, data minimization, and timely deletion upon consent withdrawal.
2. Encryption & Data Transit Security
All communications between mobile applications, web browsers, and backend servers are encrypted using Transport Layer Security (TLS 1.3). Sensitive credentials and tokens are hashed using industry-standard bcrypt and key derivation functions. Data at rest is encrypted using AES-256.
3. Role-Based Access Controls (RBAC)
Access to candidate phone numbers, employer GST details, and transaction history is restricted via strict Role-Based Access Controls. Internal staff members (Telecallers, Operations Managers, Administrators) operate under principle of least privilege.
4. Cloud Infrastructure & Auditing
Our backend infrastructure is hosted in secure data centers operating within India. Automated vulnerability scanning, application firewall rules, and structured system log auditing are maintained 24/7.
5. Incident Management & Breaches
In the event of a security incident or data breach affecting personal information, our incident response team executes immediate containment procedures and notifies statutory authorities and affected data principals in compliance with applicable law.