AuraSync ATS
Back to App

Privacy Policy

AuraSync ATS — AI Recruitment Platform

Effective Date: 28 May 2026 | Last Updated: 28 May 2026

Superseded version 2026.05.1. This is kept for reference because consent records point at it. It is not the policy in force — read the current policy.

1. Introduction

Genesis Technologies Private Limited ("we", "our", or "us") builds and operates AuraSync ATS, an enterprise-grade AI-powered Applicant Tracking System. This Privacy Policy explains how we collect, use, store, and protect personal data across all touchpoints of our platform — including the core ATS, the companion AI Assessment system, Salesforce AppExchange integration, ServiceNow integration, and all related services.

This policy applies to all users of AuraSync ATS including HR professionals, recruiters, hiring managers, system administrators, and job candidates.

2. What AuraSync ATS Does

AuraSync ATS is a full-cycle recruitment management platform. Its core capabilities include:

3. System Architecture and Data Flow

3.1 Core ATS

The ATS platform is hosted on AWS EC2 running Django 4.2. All recruitment data is stored in a MySQL database. The system uses multi-tenant architecture where each company's data is isolated in a separate database resolved by subdomain.

3.2 AI Assessment System

A companion assessment service (assessment_aurasync) handles all candidate evaluation workflows. It communicates with the ATS via internal REST APIs using shared service keys. The assessment system uses TensorFlow, PyTorch, InsightFace, and OpenCV for personality signal processing.

3.3 Data Flow: Candidate Assessment Journey

  1. Recruiter creates a job post in ATS
  2. ATS calls Assessment API to generate job-specific questions
  3. Candidate receives tokenized assessment invite link
  4. Assessment system validates the invite token against ATS
  5. Candidate completes assessment — responses, facial signals, personality data are captured
  6. Assessment pushes scores, personality vectors (HSV), and reports back to ATS
  7. Recruiter views consolidated candidate profile with assessment results in ATS

3.4 Salesforce Integration

The Salesforce AppExchange package contains only a Lightning Web Component that renders an iframe pointing to https://ats.aurasync.ai. No ATS recruitment data is stored in Salesforce objects. Salesforce acts purely as a UI host.

4. Personal Data We Collect

4.1 Recruiter and HR User Data

Data CategorySpecific Data Points
IdentityFull name, username, profile picture
ContactEmail address, phone number
OrganizationCompany name, department, job title, role
LocationCountry, city, address, timezone
AuthenticationPassword hash, OAuth tokens (Microsoft/Google)
Enterprise SSOSalesforce org context, ServiceNow session data
Activity LogsLogin history, actions taken, audit trail

4.2 Candidate Data

Data CategorySpecific Data Points
IdentityFull name, email, phone, LinkedIn profile URL
Professional ProfileWork experience, education, projects, skills
Application DataApplied jobs, pipeline stage, status history
Interview DataSchedule details, video room IDs, interview notes
Assessment ScoresFinal scores, job-fit ratings, personality scores
Personality SignalsHuman State Vector (HSV), personality trait vectors
Biometric DataFacial embeddings (for fraud detection during assessments)
Report AssetsAssessment report images and PDF exports

4.3 Assessment Process Data

Data CategorySpecific Data Points
Session DataTest attempt records, timing, session metadata
ResponsesQuestion answers, transcripts, personality responses
Emotion AnalysisFacial emotion signals during assessment sessions
Fraud DetectionFace similarity scores, fraud flags, fraud logs
Audio/VideoAudio signals captured during assessment sessions
PsychometricTrait scores, scale responses, psychometric results

5. Legal Basis for Processing

6. How We Use Personal Data

6.1 Recruiter/HR Data

6.2 Candidate Data

6.3 AI/ML Processing

Candidate data is processed through AI inference pipelines for scoring and personality analysis. We use external AI providers (OpenAI, Groq, Google Generative AI) for specific tasks including question generation and text analysis. Candidate data submitted to these providers is subject to their respective data processing agreements.

We do not use candidate personal data to train our own foundational AI models without explicit consent.

7. Third-Party Services and Data Sharing

Service ProviderPurposeData Shared
AWS (EC2, S3, Secrets Manager)Hosting, storage, credential managementAll platform data
Microsoft/Office365Email integration, OAuth loginEmail content, identity tokens
GoogleEmail integration, OAuth login, AI (Gemini)Email content, identity tokens, prompts
OpenAIAssessment question generation, AI assistantJob descriptions, anonymized prompts
GroqLLM inference for recruitment tasksJob/assessment content
100msVideo interview infrastructureInterview session identifiers
SalesforceEnterprise SSO, AppExchange UI hostUser org context, session data
ServiceNowEnterprise SSO integrationIdentity/session data
QdrantVector search/semantic indexingEmbeddings of job/candidate content

8. Biometric and Sensitive Data

During AI assessment sessions, AuraSync collects biometric-adjacent data including facial embeddings for fraud detection and emotion analysis signals. This data is:

Candidates in jurisdictions with biometric privacy laws (Illinois BIPA, GDPR) have additional rights regarding this data. Contact support@genesistechnologies.io to exercise these rights.

9. Data Storage and Security

10. Data Retention

Data TypeRetention Period
Active recruiter/HR accountsDuration of subscription + 30 days
Candidate application dataDuration of hiring cycle + 1 year
Assessment results and scoresDuration of application + 90 days
Facial/biometric embeddingsDuration of assessment session + 90 days
Audit logs and activity data2 years
Email integration dataDuration of integration + 30 days
Backup data90 days after primary deletion

11. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

To exercise these rights, email: support@genesistechnologies.io

12. Special Rights for Job Candidates

Contact the recruiting company directly or email support@genesistechnologies.io to exercise these rights.

13. International Data Transfers

Our servers are located in the United States (AWS). If you access AuraSync from outside the US, your data will be transferred to and processed in the US. We ensure appropriate safeguards are in place for international transfers in compliance with applicable data protection laws.

14. Children's Privacy

AuraSync ATS is a B2B platform for HR professionals processing adult job candidates. We do not knowingly collect data from individuals under 18 years of age.

15. Security Incidents

In the event of a data breach affecting your personal data, we will notify affected users and relevant authorities within 72 hours of discovery as required by applicable law.

16. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email to account administrators and in-platform notifications. Continued use of the platform after changes constitutes acceptance.

17. Contact Us

Genesis Technologies Private Limited
Privacy Email: support@genesistechnologies.io
Website: https://aurasync.ai
Address: Pune, Maharashtra, India