Recruitment Privacy Policy
Company: CDNA Technologies Private Limited
Contact: people@gonuclei.com Office: Bangalore, Karnataka, India
1. About This Policy
This policy explains how CDNA Technologies Private Limited ("Nuclei", "we", "us") collects, uses, and protects your data during our hiring and onboarding processes.
We are committed to safeguarding your privacy in compliance with:
- India's Digital Personal Data Protection Act (DPDP Act), 2023
- The General Data Protection Regulation (GDPR), where applicable
We are currently working toward full GDPR compliance and continuously improving our practices.
Applies to:
- Job applicants
- Internal applicants
- Prospective hires in our Talent Pool
2. What Personal Data We Collect
We collect the following types of personal data:
During Application Stage
- Basic identifiers (name, email, phone number, date of birth)
- Resume/CV, cover letter, LinkedIn profile or application form data
- Educational and professional history
- Current and expected salary details
- Interview notes, feedback (including recordings if applicable and consented to)
- References you provide
After Shortlisting / Offer Stage
- Identity and address proof (Aadhaar, PAN, Passport)
- Educational credentials
- Employment history verification
- Salary verification (where relevant)
Optional (Consent-based, future-ready)
- Talent Pool inclusion for future roles
3. Purpose of Collection
We use this data to:
- Assess your suitability for employment
- Conduct interviews and evaluations
- Carry out background verifications
- Evaluate compensation alignment
- Contact you for future job openings (if you opt into the Talent Pool)
- Comply with applicable employment, tax, and IT laws
4. Legal Basis for Processing
| Purpose | Legal Basis |
|---|---|
| Candidate assessment, background checks | Contractual Necessity |
| Offer preparation, salary verification | Contractual Necessity |
| Identity/address/employment proof | Legal Obligation |
| Inclusion in Talent Pool | Consent |
| Process improvement (non-PII analytics) | Legitimate Interest |
5. Consent Handling
We seek explicit consent before storing candidate data in our Talent Pool. Consent, where required, is collected via application forms or email confirmations. You can withdraw your consent anytime by writing to: privacy@nuclei.com
6. Data Sharing
We only share personal data with:
- Internal hiring managers involved in recruitment
- SpringVerify (for background verification for offered candidates)
- Freshteam (applicant tracking system)
- Keka (for employee onboarding and payroll)
All third parties process data under Data Processing Agreements (DPAs) and handle data solely for authorized purposes.
7. Data Retention
| Category | Retention Duration | Justification |
|---|---|---|
| Hired candidates | Employment period + 7 years | Tax & labor compliance (Income Tax Act, Shops & Establishments Act) |
| Rejected candidates | 12 months | Legitimate Interest (audit/legal defense) |
| Talent Pool (if opted in) | 3 years or until withdrawal | Consent |
| Background verification data | 7 years | Legal retention for payroll/IT scrutiny |
We aim to securely delete or anonymize data within a reasonable period (typically within 3 months) after the end of its retention duration, unless legally required to retain it longer.
8. Your Rights
You may have certain rights under applicable data protection laws in relation to your personal data. For more information on these rights and how to exercise them, please refer to https://www.gonuclei.com/privacy-policy
- We will consider all requests to exercise such rights in accordance with applicable laws and our internal policies.
- Where fulfilling a request is not feasible, would require disproportionate effort, or would adversely affect the rights and freedoms of others, Nuclei reserves the right to limit or deny such a request, in line with applicable legal provisions.
If you wish to exercise any rights, or have questions, please email us at privacy@nuclei.com. We will respond without undue delay and within 1 month of receiving your request. In complex cases, we may extend this by up to 2 additional months and will inform you of any extension within the initial month, along with reasons for the delay. If you believe that we have not handled your data in accordance with applicable data protection laws, you have the right to lodge a complaint with a Data Protection Authority.
9. No Automated Decision-Making
We do not use AI-based or automated decision-making tools to shortlist or reject candidates. All evaluations are performed manually by our recruitment team.
10. Data Security
We protect your data using:
- Encryption (at rest and in transit)
- Role-based access control
- Multi-factor authentication
- Regular audits and employee access reviews
- Alignment with ISO 27001:2022 practices
11. Breach Notification
In the unlikely event of a data breach affecting your information, we will notify affected individuals and, where applicable, report the incident to relevant authorities as per our legal obligations.
12. Policy Updates
We review this policy at least once every 12 months, or earlier if changes in law or internal processes require it. Significant changes will be communicated via our careers portal or through direct communication.
By applying to Nuclei, you acknowledge that you have read and understood this Privacy Policy.