AuraSync ATS
Back to App

Privacy Policy

AuraSync ATS — AI Recruitment Platform

Version 2026.08.2 · effective 2026-08-22 · earlier versions: 2026.08.1, 2026.05.1

1. Introduction

AuraSync INC ("we", "our", or "us") builds and operates AuraSync ATS, an enterprise-grade AI-powered Applicant Tracking System. This Privacy Policy explains how we collect, use, store, and protect personal data across all touchpoints of our platform — including the core ATS, the companion AI Assessment system, Salesforce AppExchange integration, ServiceNow integration, and all related services.

This policy applies to all users of AuraSync ATS including HR professionals, recruiters, hiring managers, system administrators, and job candidates.

2. What AuraSync ATS Does

AuraSync ATS is a full-cycle recruitment management platform. Its core capabilities include:

3. System Architecture and Data Flow

3.1 Core ATS

The ATS platform is hosted on AWS EC2 running Django 4.2. All recruitment data is stored in a MySQL database. The system uses multi-tenant architecture where each company's data is isolated in a separate database resolved by subdomain.

3.2 AI Assessment System

A companion assessment service (assessment_aurasync) handles all candidate evaluation workflows. It communicates with the ATS via internal REST APIs using shared service keys. The assessment system uses TensorFlow, PyTorch, InsightFace, and OpenCV for personality signal processing.

3.3 Data Flow: Candidate Assessment Journey

  1. Recruiter creates a job post in ATS
  2. ATS calls Assessment API to generate job-specific questions
  3. Candidate receives tokenized assessment invite link
  4. Assessment system validates the invite token against ATS
  5. Candidate completes assessment — responses, facial signals, personality data are captured
  6. Assessment pushes scores, personality vectors (HSV), and reports back to ATS
  7. Recruiter views consolidated candidate profile with assessment results in ATS

3.4 Salesforce Integration

The Salesforce AppExchange package contains only a Lightning Web Component that renders an iframe pointing to https://ats.aurasync.ai. No ATS recruitment data is stored in Salesforce objects. Salesforce acts purely as a UI host.

4. Personal Data We Collect

4.1 Recruiter and HR User Data

Data CategorySpecific Data Points
IdentityFull name, username, profile picture
ContactEmail address, phone number
OrganizationCompany name, department, job title, role
LocationCountry, city, address, timezone
AuthenticationPassword hash, OAuth tokens (Microsoft/Google)
Enterprise SSOSalesforce org context, ServiceNow session data
Activity LogsLogin history, actions taken, audit trail

4.2 Candidate Data

Data CategorySpecific Data Points
IdentityFull name, email, phone, LinkedIn profile URL
Professional ProfileWork experience, education, projects, skills
Application DataApplied jobs, pipeline stage, status history
Interview DataSchedule details, video room IDs, interview notes
Assessment ScoresFinal scores, job-fit ratings, personality scores
Personality SignalsHuman State Vector (HSV), personality trait vectors
Biometric DataFacial embeddings (for fraud detection during assessments)
Report AssetsAssessment report images and PDF exports

4.3 Assessment Process Data

Data CategorySpecific Data Points
Session DataTest attempt records, timing, session metadata
ResponsesQuestion answers, transcripts, personality responses
Emotion AnalysisFacial emotion signals during assessment sessions
Fraud DetectionFace similarity scores, fraud flags, fraud logs
Audio/VideoAudio signals captured during assessment sessions
PsychometricTrait scores, scale responses, psychometric results

5. Legal Basis for Processing

For candidates and users in India, processing is governed by the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the rules made under it, together with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

Within that framework the Act provides two routes and no others:

6. How We Use Personal Data

6.1 Recruiter/HR Data

6.2 Candidate Data

6.3 AI/ML Processing

Candidate data is processed through AI inference pipelines for scoring and personality analysis. We use external AI providers (OpenAI, Groq, Google Generative AI) for specific tasks including question generation and text analysis. Candidate data submitted to these providers is subject to their respective data processing agreements.

We do not use candidate personal data to train our own foundational AI models without explicit consent.

7. Third-Party Services and Data Sharing

Service ProviderPurposeData Shared
AWS (EC2, S3, Secrets Manager)Hosting, storage, credential managementAll platform data
Microsoft/Office365Email integration, OAuth loginEmail content, identity tokens
GoogleEmail integration, OAuth login, AI (Gemini)Email content, identity tokens, prompts
OpenAIAssessment question generation, AI assistantJob descriptions, anonymized prompts
GroqLLM inference for recruitment tasksJob/assessment content
100msVideo interview infrastructureInterview session identifiers
SalesforceEnterprise SSO, AppExchange UI hostUser org context, session data
ServiceNowEnterprise SSO integrationIdentity/session data
QdrantVector search/semantic indexingEmbeddings of job/candidate content

8. Biometric and Sensitive Data

During AI assessment sessions, AuraSync collects biometric-adjacent data including facial embeddings for fraud detection and emotion analysis signals. This data is:

Biometric data requires your consent under Section 6 of the DPDPA. To ask what biometric data is held about you, or to have it deleted, contact the organisation you applied to — they are the Data Fiduciary for it — or use the manage-your-data link they sent you. Withdrawing biometric consent erases the stored facial and audio baselines; it does not merely stop future capture.

9. Data Storage and Security

10. Data Retention

Data TypeRetention Period
Active recruiter/HR accountsDuration of subscription + 30 days
Candidate application dataDuration of hiring cycle + 1 year
Assessment results and scoresDuration of application + 90 days
Facial/biometric embeddingsDeleted within 90 days of capture by an automated purge. Records captured before 20 July 2026 predate that purge and are being cleared separately; contact the Grievance Officer if you need confirmation for a specific record.
Talent pool profile (kept with your consent)2 years from the date you agreed. We then ask you to confirm; if we hear nothing within 30 days your details are deleted.
Audit logs and activity data2 years
Email integration dataDuration of integration + 30 days
Backup data90 days after primary deletion

11. Your Rights

Under the Digital Personal Data Protection Act, 2023 you have the following rights:

This list is exhaustive. Rights found in other laws — to receive your data in a machine-readable form for transfer elsewhere, to have processing paused, or to object to processing — are not granted by the Act, and we do not claim to offer them. An earlier version of this policy listed them in error.

Who you exercise these rights against. If you applied for a job, the organisation you applied to is the Data Fiduciary for your application: they decide why your data is processed, and the rights above are owed by them. Contact them directly. Their privacy contact is published on the careers page you applied through and appears in the correspondence they have sent you. If you were emailed a link to manage your data, that page lets you make any of these requests, and it tells you which organisation will answer it.

Every request made through this platform is recorded with a reference and a date, and is answered within 30 days. Before data is sent to you or erased, the organisation responsible will confirm the request came from you — acting on an unverified request is how one person's data reaches another.

Nomination is exercised against that same organisation. Where they instruct us to give effect to a nomination, we act on that instruction and record it.

For personal data we hold about you as a user of the platform itself — a recruiter, hiring manager or administrator account — AuraSync INC is the Data Fiduciary, and you exercise these rights against us at grievance@genesistechnologies.io.

What deletion means. If you asked us to keep your details on file for future roles, deleting your application removes your assessment results, biometric data, interview records and application history, and keeps the profile you asked us to keep. If you did not ask us to keep you on file, everything personal is destroyed — your name, contact details, résumé, education, work history and projects. What remains in that case is a record carrying no name or contact details, kept only so that decisions made about applications can be audited. We issue a deletion certificate recording what was removed and anything that was retained.

12. Special Rights for Job Candidates

Exercise these rights with the recruiting organisation you applied to. They decide how your application is assessed and what happens to the result, so they are the ones who can answer — a human review of a score is their decision to make, not this platform's.

13. International Data Transfers

Our servers are located in the United States (AWS). If you access AuraSync from outside the US, your data will be transferred to and processed in the US. We ensure appropriate safeguards are in place for international transfers in compliance with applicable data protection laws.

14. Children's Privacy

AuraSync ATS is a B2B platform for HR professionals processing adult job candidates. We do not knowingly collect data from individuals under 18 years of age.

15. Security Incidents

Different laws set different clocks for a security incident, so we treat them separately rather than applying a single deadline:

15A. Grievance Officer

If you have a concern about how your personal data has been handled, you may raise it with our Grievance Officer, as provided for by section 13 of the Digital Personal Data Protection Act, 2023 and rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

If your concern is about an application you made for a job, raise it first with the organisation you applied to: they are the Data Fiduciary for your application and they hold the decision you are asking about. Our Grievance Officer answers for the platform itself — how it stores and secures data, and how we act on a customer's instructions — and will pass a complaint to the responsible organisation where it belongs to them, telling you that we have done so.

Grievance Officer
AuraSync INC
Pune, Maharashtra, India
Email: grievance@genesistechnologies.io

We acknowledge grievances within 48 hours and respond with an outcome within 30 days. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India.

16. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email to account administrators and in-platform notifications. Continued use of the platform after changes constitutes acceptance.

17. Contact Us

For a job application, contact the organisation you applied to — see section 11. The address below reaches AuraSync INC about the platform itself.

AuraSync INC
General enquiries: support@genesistechnologies.io
Grievance Officer: grievance@genesistechnologies.io
Website: https://aurasync.ai
Address: Pune, Maharashtra, India