Privacy Policy
AuraSync ATS — AI Recruitment Platform
1. Introduction
Genesis Technologies Private Limited ("we", "our", or "us") builds and operates AuraSync ATS, an enterprise-grade AI-powered Applicant Tracking System. This Privacy Policy explains how we collect, use, store, and protect personal data across all touchpoints of our platform — including the core ATS, the companion AI Assessment system, Salesforce AppExchange integration, ServiceNow integration, and all related services.
This policy applies to all users of AuraSync ATS including HR professionals, recruiters, hiring managers, system administrators, and job candidates.
2. What AuraSync ATS Does
AuraSync ATS is a full-cycle recruitment management platform. Its core capabilities include:
- Job Requisition Management — create, approve, and manage job postings across departments
- Candidate Pipeline Tracking — track candidates across configurable hiring stages
- AI-Powered Assessments — automatically generate job-specific assessments, personality evaluations, and psychometric tests
- Interview Scheduling — coordinate interviews with calendar integration via 100ms video infrastructure
- Email Campaign Management — outreach campaigns with Outlook/Gmail integration
- Resume Parsing and Building — AI-assisted resume analysis and candidate profile creation
- Analytics and Dashboards — hiring pipeline analytics, job-fit scoring, and recruiter performance metrics
- Enterprise SSO — Salesforce Canvas and ServiceNow OAuth/OIDC single sign-on
- AI Assistant (Second Brain) — LLM-powered recruitment assistant using OpenAI, Groq, and Google Generative AI
3. System Architecture and Data Flow
3.1 Core ATS
The ATS platform is hosted on AWS EC2 running Django 4.2. All recruitment data is stored in a MySQL database. The system uses multi-tenant architecture where each company's data is isolated in a separate database resolved by subdomain.
3.2 AI Assessment System
A companion assessment service (assessment_aurasync) handles all candidate evaluation workflows. It communicates with the ATS via internal REST APIs using shared service keys. The assessment system uses TensorFlow, PyTorch, InsightFace, and OpenCV for personality signal processing.
3.3 Data Flow: Candidate Assessment Journey
- Recruiter creates a job post in ATS
- ATS calls Assessment API to generate job-specific questions
- Candidate receives tokenized assessment invite link
- Assessment system validates the invite token against ATS
- Candidate completes assessment — responses, facial signals, personality data are captured
- Assessment pushes scores, personality vectors (HSV), and reports back to ATS
- Recruiter views consolidated candidate profile with assessment results in ATS
3.4 Salesforce Integration
The Salesforce AppExchange package contains only a Lightning Web Component that renders an iframe pointing to https://ats.aurasync.ai. No ATS recruitment data is stored in Salesforce objects. Salesforce acts purely as a UI host.
4. Personal Data We Collect
4.1 Recruiter and HR User Data
| Data Category | Specific Data Points |
|---|---|
| Identity | Full name, username, profile picture |
| Contact | Email address, phone number |
| Organization | Company name, department, job title, role |
| Location | Country, city, address, timezone |
| Authentication | Password hash, OAuth tokens (Microsoft/Google) |
| Enterprise SSO | Salesforce org context, ServiceNow session data |
| Activity Logs | Login history, actions taken, audit trail |
4.2 Candidate Data
| Data Category | Specific Data Points |
|---|---|
| Identity | Full name, email, phone, LinkedIn profile URL |
| Professional Profile | Work experience, education, projects, skills |
| Application Data | Applied jobs, pipeline stage, status history |
| Interview Data | Schedule details, video room IDs, interview notes |
| Assessment Scores | Final scores, job-fit ratings, personality scores |
| Personality Signals | Human State Vector (HSV), personality trait vectors |
| Biometric Data | Facial embeddings (for fraud detection during assessments) |
| Report Assets | Assessment report images and PDF exports |
4.3 Assessment Process Data
| Data Category | Specific Data Points |
|---|---|
| Session Data | Test attempt records, timing, session metadata |
| Responses | Question answers, transcripts, personality responses |
| Emotion Analysis | Facial emotion signals during assessment sessions |
| Fraud Detection | Face similarity scores, fraud flags, fraud logs |
| Audio/Video | Audio signals captured during assessment sessions |
| Psychometric | Trait scores, scale responses, psychometric results |
5. Legal Basis for Processing
For candidates and users in India, processing is governed by the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the rules made under it, together with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- Roles: the customer organisation that invites a candidate is the Data Fiduciary and decides the purpose of processing. Genesis Technologies acts as a Data Processor on that organisation's instructions, except for platform security, fraud prevention, model development and billing, where it acts as an independent Data Fiduciary.
- Consent (section 6): candidates give consent separately for taking part in an assessment, for camera and microphone monitoring, and for facial verification. Consent is recorded per purpose together with the version of the notice shown.
- Withdrawal (section 6(4)–(6)): consent can be withdrawn at any time, as easily as it was given. Withdrawing facial verification consent erases the stored facial and audio baselines.
- Rights (sections 11–14): access, correction and completion, erasure, nomination, and grievance redressal — see sections 11 and 15A below.
Within that framework the Act provides two routes and no others:
- Consent (Section 6) — for purposes beyond the one you provided your data for, including biometric capture during a proctored assessment.
- Certain legitimate uses (Section 7) — principally Section 7(a), where you voluntarily provided your data for a purpose you specified, such as applying for a particular role; and Section 7(i), for employment-related processing and protecting an employer from loss or liability.
6. How We Use Personal Data
6.1 Recruiter/HR Data
- Authenticate and authorize platform access
- Enable Salesforce/ServiceNow SSO integration
- Send recruitment workflow notifications
- Generate analytics and performance reports
6.2 Candidate Data
- Process job applications through hiring pipeline
- Schedule and conduct interviews
- Generate and deliver AI-powered assessments
- Create candidate fit scores and personality profiles
- Communicate application status updates via email
6.3 AI/ML Processing
Candidate data is processed through AI inference pipelines for scoring and personality analysis. We use external AI providers (OpenAI, Groq, Google Generative AI) for specific tasks including question generation and text analysis. Candidate data submitted to these providers is subject to their respective data processing agreements.
We do not use candidate personal data to train our own foundational AI models without explicit consent.
7. Third-Party Services and Data Sharing
| Service Provider | Purpose | Data Shared |
|---|---|---|
| AWS (EC2, S3, Secrets Manager) | Hosting, storage, credential management | All platform data |
| Microsoft/Office365 | Email integration, OAuth login | Email content, identity tokens |
| Email integration, OAuth login, AI (Gemini) | Email content, identity tokens, prompts | |
| OpenAI | Assessment question generation, AI assistant | Job descriptions, anonymized prompts |
| Groq | LLM inference for recruitment tasks | Job/assessment content |
| 100ms | Video interview infrastructure | Interview session identifiers |
| Salesforce | Enterprise SSO, AppExchange UI host | User org context, session data |
| ServiceNow | Enterprise SSO integration | Identity/session data |
| Qdrant | Vector search/semantic indexing | Embeddings of job/candidate content |
8. Biometric and Sensitive Data
During AI assessment sessions, AuraSync collects biometric-adjacent data including facial embeddings for fraud detection and emotion analysis signals. This data is:
- Collected only during active assessment sessions with candidate awareness
- Used solely for fraud detection and personality scoring purposes
- Stored encrypted in our assessment database
- Not shared with third parties except as required by law
- Deleted within 90 days of capture by an automated purge (see Data Retention below)
Biometric data requires your consent under Section 6 of the DPDPA. To ask what biometric data we hold about you, or to ask us to delete it, contact support@genesistechnologies.io.
9. Data Storage and Security
- All data stored on AWS EC2 with MySQL databases using encryption at rest
- Multi-tenant architecture ensures strict data isolation between companies
- All data transmission uses HTTPS/TLS 1.2 or higher
- Service-to-service communication (ATS ↔ Assessment) uses shared secret key authentication
- Access to production systems restricted to authorized personnel only
- AWS Secrets Manager used for credential management
- Regular security audits and vulnerability assessments conducted
10. Data Retention
| Data Type | Retention Period |
|---|---|
| Active recruiter/HR accounts | Duration of subscription + 30 days |
| Candidate application data | Duration of hiring cycle + 1 year |
| Assessment results and scores | Duration of application + 90 days |
| Facial/biometric embeddings | Deleted within 90 days of capture by an automated purge. Records captured before 20 July 2026 predate that purge and are being cleared separately; contact the Grievance Officer if you need confirmation for a specific record. |
| Talent pool profile (kept with your consent) | 2 years from the date you agreed. We then ask you to confirm; if we hear nothing within 30 days your details are deleted. |
| Audit logs and activity data | 2 years |
| Email integration data | Duration of integration + 30 days |
| Backup data | 90 days after primary deletion |
11. Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
- Access — request a copy of all personal data we hold about you
- Correction — request correction of inaccurate or incomplete data
- Erasure — request deletion of your personal data (DPDPA Section 12)
- Portability — request export of your data in machine-readable format
- Objection — object to processing of your data for specific purposes
- Restriction — request restriction of processing in certain circumstances
- Withdraw Consent — withdraw consent for biometric/sensitive data processing at any time
To exercise these rights, email: support@genesistechnologies.io
If you applied for a role and we emailed you a link to manage your data, that page also lets you make any of these requests directly. Each one is recorded with a reference and answered within 30 days.
What deletion means. If you asked us to keep your details on file for future roles, deleting your application removes your assessment results, biometric data, interview records and application history, and keeps the profile you asked us to keep. If you did not ask us to keep you on file, everything personal is destroyed — your name, contact details, résumé, education, work history and projects. What remains in that case is a record carrying no name or contact details, kept only so that decisions made about applications can be audited. We issue a deletion certificate recording what was removed and anything that was retained.
12. Special Rights for Job Candidates
- Know that your application is being processed through an AI-assisted system
- Request human review of any AI-generated assessment score or recommendation
- Request deletion of your assessment data including facial embeddings
- Opt out of biometric data collection (may affect assessment completion)
- Receive a copy of your assessment results upon request
Contact the recruiting company directly or email support@genesistechnologies.io to exercise these rights.
13. International Data Transfers
Our servers are located in the United States (AWS). If you access AuraSync from outside the US, your data will be transferred to and processed in the US. We ensure appropriate safeguards are in place for international transfers in compliance with applicable data protection laws.
14. Children's Privacy
AuraSync ATS is a B2B platform for HR professionals processing adult job candidates. We do not knowingly collect data from individuals under 18 years of age.
15. Security Incidents
Different laws set different clocks for a security incident, so we treat them separately rather than applying a single deadline:
- CERT-In (India): reportable cyber security incidents affecting the platform are reported to the Indian Computer Emergency Response Team within six (6) hours of us becoming aware of them, under section 70B(6) of the Information Technology Act, 2000 and the CERT-In Directions of 28 April 2022.
- Affected individuals and the Data Protection Board of India: where a personal data breach occurs, affected individuals are informed without delay, and the Board is notified within the period required by the Digital Personal Data Protection Act, 2023 and the rules made under it.
- Customers: where a breach affects a customer's data, we notify that customer without undue delay and in any event within 24 hours of becoming aware, so they can meet their own obligations as data fiduciary.
15A. Grievance Officer
If you have a concern about how your personal data has been handled, you may raise it with our Grievance Officer, as provided for by section 13 of the Digital Personal Data Protection Act, 2023 and rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
Grievance Officer
Genesis Technologies Private Limited
Pune, Maharashtra, India
Email: grievance@genesistechnologies.io
We acknowledge grievances within 48 hours and respond with an outcome within 30 days. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India.
16. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email to account administrators and in-platform notifications. Continued use of the platform after changes constitutes acceptance.
17. Contact Us
Genesis Technologies Private Limited
Privacy Email: support@genesistechnologies.io
Website: https://aurasync.ai
Address: Pune, Maharashtra, India