Findo HR Privacy Policy
Updated On: December 27, 2025
Introduction and Consent
Mandatory Acceptance To access the FindoHR Platform or utilize our Services, you must explicitly agree to the practices and policies outlined in this Privacy Policy. Your continued use of the Platform signifies your informed consent to the collection, storage, and processing of information as described herein.
Scope of Policy This Privacy Policy applies to all interactions with Hidden Leaf Technologies, including:
- (a) Use of the FindoHR web-based platform and mobile interfaces.
- (b) Attendance or participation in in-person recruitment or networking events ("Events") conducted by us.
- (c) Professional communications via email, SMS, or WhatsApp related to our Services.
Right to Decline If you do not agree with any part of this Privacy Policy, you must immediately cease all access to the Platform and refrain from using any Services.
1. General Provisions
1.1 Basis of Processing The legal basis for processing your personal information is your clear affirmative action in accepting this Privacy Policy. By ticking the "I Agree" box during registration or by continuing to use the Services, you provide your informed, specific, and unconditional consent for Hidden Leaf Technologies to collect, use, and process your data as described in this document and our Terms of Service.
1.2 Interpretation This Privacy Policy is an integral part of our Terms of Service. Any capitalized terms used but not defined herein shall have the meaning assigned to them in the Terms of Service.
1.3 Third-Party Links Our Platform may contain APIs or links to third-party websites (such as LinkedIn, ATS platforms, or payment gateways). These external sites are not governed by this Privacy Policy. We have no control over, and assume no responsibility for, the content or privacy practices of any third-party services. We strongly recommend that you review the privacy statements of any external website you visit.
1.4 Policy Updates We reserve the right to modify this Privacy Policy at any time to reflect changes in Law (including the DPDP Act 2023) or our business practices.
- (a) Notification: We will notify you of material changes via email or a prominent notice on the Platform.
- (b) Acceptance: Your continued use of the Platform after such updates are posted constitutes your acceptance of the revised Policy. We encourage you to check this page periodically for the latest information on our privacy practices.
2. About FindoHR and Your Rights
2.1 Data Fiduciary Identity FindoHR is a proprietary product of Hidden Leaf Technologies, registered in India, with its principal place of business at:
Wolfpack Workspaces, 39, 8th Main Rd, Vasanth Nagar, Bengaluru, Karnataka 560001. Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), Hidden Leaf Technologies acts as a Data Fiduciary regarding the personal data provided by Users.
2.2 Data Protection Officer (DPO) In compliance with Data Regulations, we have appointed a Data Protection Officer to oversee our privacy framework. For any grievances, requests to exercise your rights, or questions regarding your data, you may contact:
- Name: RM Vijayadhitya
- Email: vijayadhitya@findohr.com
- Role: Data Protection Officer / Grievance Officer
2.3 Withdrawal of Consent You (the "Data Principal") have the right to withdraw your consent for the processing of your personal information at any time by notifying our Data Protection Officer in writing.
2.4 Consequences of Withdrawal Please be advised of the following upon withdrawal of consent:
- (a) Termination of Access: Since the processing of certain data is essential to the functionality of the Platform, the withdrawal of consent will result in the immediate suspension or termination of your access to the Services and the Platform.
- (b) Past Processing: The withdrawal of consent shall not affect the legality of any data processing performed by us prior to such withdrawal.
- (c) Statutory Retention: We may continue to retain certain information if required by Applicable Law or for legitimate business purposes (such as financial record-keeping or legal defense) even after consent is withdrawn.
3. Information We Collect
We collect information directly from you, through automated tracking technologies, and from third-party sources. We may aggregate or de-identify data to create statistical insights that do not identify specific individuals. While some areas of the Platform are accessible without registration, utilizing our core recruitment intelligence requires the collection of the following:
3.1 Categories of Data Collected
- (a) Identity & Contact Data: Includes your full name, professional email address, corporate telephone number, and job designation. For authentication, we may collect date of birth or other identifiers to verify your authority to represent your organization.
- (b) Professional & Organization Data: Includes your company's legal name, corporate URL, registered address, and invoicing details.
- (c) Candidate Intelligence (Employment Data): Includes information you provide regarding candidates in your recruitment pipeline, such as names, professional history, "Intent Markers," "Offer Status," and "Notice Period" details.
- (d) Financial Data: We utilize secure, encrypted third-party payment gateways for all transactions. We do not directly store your full credit card or bank account details on our servers.
- (e) Technical & Usage Data: Includes your IP address, login patterns, browser type, time zone, and details of how you interact with the Platform's features.
- (f) Cookies & Tracking: We use cookies, web beacons, and log files to gather diagnostic information, device identifiers, and imprecise geographical location data (e.g., city-level) to ensure account security and optimize UI/UX.
3.2 Data from Other Sources We may receive information from:
- Strategic Partners: Analytics providers, search information providers, and technical subcontractors.
- Inter-User Activity: Data triggered by other Employers in the FindoHR network that may relate to candidates in your pipeline.
3.3 Interest-Based Advertising & Audience Matching We and our partners may use tracking technologies to deliver relevant content or "Matched Ads" based on your interactions with our Services. These third-party vendors act as independent data controllers; we encourage you to review their respective privacy policies.
4. Cookies and Web Tracking Technologies
4.1 Core Technologies To provide a secure and functional experience, we use cookies, pixel tags (web beacons), and browser-based tracking technologies. These allow us to automatically collect information about your device and how you interact with our Platform.
- Cookies: Small text files stored in your browser. We use "First-Party Cookies" for essential session management (e.g., keeping you logged in) and "Third-Party Cookies" for analytics and interest-based content.
- Pixels & Web Beacons: Invisible code snippets embedded in our web pages and emails. We use these to track "conversions" (e.g., if a recruiter successfully completes a verification) and to understand the effectiveness of our communications.
4.2 Categories of Cookies Used
- Strictly Necessary: Required for the Platform to function (e.g., authentication, security, and load balancing). These do not require separate consent as they are essential for the Service you have requested.
- Performance & Analytics: Help us understand visitor behavior (e.g., which pages are most popular) so we can improve the platform.
- Functional: Remember your preferences (such as language or specific dashboard filters) to provide a personalized experience.
- Targeting & Advertising: Used by us and our partners to show you relevant professional content or advertisements both on and off the FindoHR platform.
4.3 Your Control and Choice In compliance with the DPDP Act 2023, we follow an "Opt-In" model for all non-essential tracking.
- Consent Banner: Upon your first visit, you will be presented with a choice to accept or manage your cookie preferences. Non-essential cookies will remain blocked until you provide explicit consent.
- Browser Settings: You can configure your browser to reject all cookies or notify you when a cookie is set. However, disabling "Strictly Necessary" cookies may prevent the Platform from functioning correctly.
- Withdrawal: You may withdraw your consent for non-essential tracking at any time through our [Cookie Settings] link in the footer.
4.4 Location Data (Web-Based) Since we do not currently offer a mobile application, we do not collect precise GPS coordinates. We may, however, collect your imprecise location (at a city or postal code level) derived from your IP address to verify that your account is being accessed from an authorized region and to prevent unauthorized login attempts.
5. Basis for Processing Personal Data
5.1 Lawful Basis for Processing In accordance with the DPDP Act 2023, we process your personal data based on the following lawful grounds:
- (a) Consent: Your explicit consent obtained through acceptance of this Privacy Policy and our Terms of Service.
- (b) Legitimate Interest: To provide, maintain, and improve our Services, ensure platform security, prevent fraud, and comply with legal obligations.
- (c) Legal Obligation: To comply with applicable laws, regulations, court orders, or governmental requests.
- (d) Contractual Necessity: To perform our contractual obligations to you under the Terms of Service.
5.2 Purpose Limitation We process personal data only for the specified purposes outlined in this Privacy Policy and our Terms of Service. We will not use your data for purposes incompatible with those for which it was originally collected without obtaining your additional consent.
6. How We Use Your Information
We use the information we collect to:
- (a) Provide, operate, and maintain the FindoHR Platform and Services.
- (b) Process your registration, authenticate your identity, and manage your account.
- (c) Deliver recruitment intelligence, risk assessments, and candidate verification services.
- (d) Process payments and manage subscriptions.
- (e) Send you service-related communications, including updates, security alerts, and support messages.
- (f) Improve and personalize your experience on the Platform.
- (g) Detect, prevent, and address technical issues, fraud, or security threats.
- (h) Comply with legal obligations and enforce our Terms of Service.
- (i) Conduct analytics and research to enhance our Services.
6.1 Marketing Communications With your consent, we may send you marketing communications about our Services, events, or industry insights. You can opt-out of these communications at any time by clicking the unsubscribe link in our emails or contacting us directly.
7. Disclosure and Sharing of Information
7.1 No Sale of Data We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
7.2 Service Providers and Processors We may share your information with trusted third-party service providers who assist us in operating the Platform, conducting our business, or serving our users. These providers are contractually bound to:
- (a) Use your information only for the purposes specified by us.
- (b) Implement appropriate security measures to protect your data.
- (c) Comply with applicable data protection laws, including the DPDP Act 2023.
7.3 Categories of Service Providers We work with the following types of service providers:
- Payment Processors: To handle payment transactions (e.g., Razorpay).
- Cloud Infrastructure Providers: To host and store our Platform and data.
- Analytics Providers: To help us understand how users interact with our Platform.
- Communication Services: To send emails, SMS, and other communications.
- Security and Fraud Prevention: To protect the Platform and detect unauthorized access.
We require these providers to maintain the same level of confidentiality and anonymity as outlined in this Policy.
7.4 Statutory and Legal Disclosures In accordance with Section 7 of the DPDP Act 2023, we may disclose your identity only if required by a court order, government subpoena, or to protect the safety and integrity of the Service.
8. Data Security and Breach Notification
8.1 Security Infrastructure Hidden Leaf Technologies implements robust physical, electronic, and procedural safeguards designed to protect your information and Candidate data from unauthorized access, loss, or misuse. Our security framework follows generally accepted industry standards, including:
- (a) Encryption: Use of Secure Sockets Layer (SSL/TLS) encryption for data in transit and industry-standard encryption for data at rest.
- (b) Access Controls: Strict authentication protocols, including the use of One-Time Passwords (OTP) and personal credentials for all User Accounts.
- (c) Perimeter Defense: Deployment of firewalls and intrusion detection systems to block malicious attacks.
- (d) Continuous Monitoring: Routine security audits, vulnerability scans, and the timely patching of servers and software.
8.2 Limitation of Guarantee While we utilize professional-grade measures to secure your information, you acknowledge that no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security or that unintended disclosures will never occur.
8.3 Security Breach Protocols In the event that Hidden Leaf Technologies becomes aware of a data breach or unauthorized disclosure that impacts your personal information:
- (a) Notification: We will notify you of the nature and extent of the breach as soon as reasonably possible and in accordance with the timelines mandated by the DPDP Act 2023 and other Applicable Laws.
- (b) Delivery: Such notifications will be delivered via the email address associated with your Account or through a prominent notice on the Platform.
- (c) Mitigation: We will take immediate steps to contain the breach and minimize any potential harm to Users and Data Principals.
9. Data Retention and Deletion
9.1 Specified Purpose of the Integrity Network The personal data and professional intelligence processed by FindoHR are collected for the Specified Purpose of maintaining a verified, real-time "Recruitment Integrity Network." The purpose of this data is to provide ongoing, cross-platform verification of candidate professional conduct and intent during the Pre-Joining Lifecycle.
9.2 Perpetual Retention for Network Intelligence
- (a) Permanent Record: To ensure the integrity of the FindoHR network, certain professional data points—including "Intent Markers," "Status Updates," and "Verification Notes"—are retained as part of a permanent professional record.
- (b) Shared Utility: This data is retained to assist future prospective Employers in the FindoHR network in making informed hiring decisions and preventing fraudulent recruitment practices.
- (c) Employer Anonymity: While the candidate's professional intelligence is retained for the network, the identity of the Employer who provided that intelligence is never disclosed to other Employers.
9.3 Statutory and Legal Exceptions Notwithstanding the above, we may retain your personal data where such retention is necessary for:
- (a) Legal Obligations: Fulfilling statutory obligations under Indian Law, including tax and audit regulations.
- (b) Dispute Resolution: Protecting our legal rights in the event of a complaint or if we reasonably believe there is a prospect of litigation.
10. Post-Hiring Visibility and Data Restrictions
10.1 The "Current Employer" Blind Spot To prevent the misuse of the Platform for unauthorized employee surveillance, Hidden Leaf Technologies implements strict technical "Blind Spots":
- (a) Restricted Access: Once you mark a Candidate as "Joined" or "Hired," you are the "Current Employer." The Platform will immediately terminate your ability to see any new updates, "Intent Markers," or status changes regarding that individual.
- (b) Search Blocking: If a Current Employer searches for their own hired employee within the Platform, the system will not permit them to view any updates generated by other employers during the term of that candidate's association with them.
10.2 Network Continuity for Prospective Employers While the Current Employer is restricted, the Candidate's professional journey remains visible to others:
- (a) Prospective Visibility: If the Candidate applies to a new organization, that prospective Employer will see the "Joined" status as one of the last verified update, along with any new markers generated by other organizations the candidate interacts with.
- (b) Last Known Status: For the rest of the network, the Candidate's profile will reflect the "Joined" status, providing critical intelligence that the candidate is currently off the active market.
10.3 Prohibition of Unfair Tracking Users are strictly prohibited from using "unfair means" or colluding with third parties to circumvent these visibility restrictions:
- (a) Collusive Monitoring: You shall not utilize another User's account or a partner organization to monitor the activity of an individual currently employed by you.
- (b) Consequences: Any attempt to bypass these "Blind Spots" is a material breach of our Terms and the DPDP Act, resulting in immediate account termination.
11. Your Rights under Data Regulations
In accordance with the Digital Personal Data Protection (DPDP) Act, 2023, you (the "Data Principal") possess specific rights regarding the personal data processed by Hidden Leaf Technologies.
11.1 Right to Information and Summary You have the right to request:
- (a) A summary of the personal data currently being processed by us and a description of the processing activities undertaken.
- (b) The identities of other Data Fiduciaries or Data Processors with whom your personal data has been shared, along with a description of the data shared.
11.2 Right to Correction and Updating You have the right to correct inaccurate data, complete incomplete records, or update outdated information.
Procedure: To update your professional profile or corporate details, please contact support@findohr.com.
11.3 Right to Erasure You may request the erasure of your personal data. However, please note:
- (a) Legitimate Exceptions: Hidden Leaf Technologies may retain certain data if it is necessary for a "Specified Purpose" (such as maintaining the integrity of the recruitment network) or for compliance with Applicable Law.
- (b) Request Process: To initiate an erasure request, please contact our Data Protection Officer, RM Vijayadhitya, at vijayadhitya@findohr.com.
11.4 Right to Grievance Redressal If you believe your data rights have been violated or if you are dissatisfied with our response to a request, you have the right to register a grievance with our Data Protection Officer. If the grievance is not resolved within the statutory period, you may approach the Data Protection Board of India.
11.5 Right to Nominate In the event of death or incapacity, you have the right to nominate another individual to exercise your rights under this Privacy Policy on your behalf.
12. Updates and Changes to this Privacy Policy
12.1 Right to Modify Hidden Leaf Technologies reserves the right to update or modify this Privacy Policy at any time to reflect changes in our Services, business practices, or evolving legal requirements in India.
12.2 Notification of Material Changes In the event of significant changes to how we process your personally identifiable information or substantial updates to the Policy itself, we will notify you through one or more of the following channels:
- (a) Platform Notice: A prominent announcement displayed on the FindoHR Platform.
- (b) Direct Communication: An email sent to the professional email address associated with your Account.
12.3 Review Period and Continued Use We will provide such notices in advance of the changes taking effect whenever possible, allowing you to review the revised terms before continuing to use the Services. Your continued use of the Platform or Services after the effective date of any modification constitutes your legally binding acceptance of the updated Privacy Policy.
12.4 Responsibility to Review While we strive to provide direct notifications for major updates, you are encouraged to review this Privacy Policy periodically to stay informed about how we are protecting your information.
13. Contact Us / Grievance Redressal
If you have any questions about this Privacy Policy, our data practices, or if you wish to exercise your rights under the DPDP Act 2023, please contact us:
By Email: support@findohr.com
Data Protection Officer: RM Vijayadhitya (vijayadhitya@findohr.com)
By Post: Hidden Leaf Technologies, Wolfpack Workspaces, 39, 8th Main Rd, Vasanth Nagar, Bengaluru, Karnataka 560001