Privacy Policy

Effective Date: September 22, 2025

Last Updated: August 11, 2026

Entity: Ascentware Private Limited

1. Introduction & Overview

Ascentware Private Limited (“Company”, “we”, “our”, or “us”) respects your privacy and is committed to protecting your personal data. This Privacy Policy outlines how we collect, process, disclose, and safeguard personal information when you visit our website, interact with our services, or enter into business or employment relationships with us.

We process all personal data strictly in accordance with applicable global data protection laws (including GDPR and local statutory compliance frameworks).

2. Information We Collect

We collect personal data directly from you, automatically through your interaction with our platforms, and from third-party sources:

Directly Provided Data:
  • Identity & Contact Details: Full name, business email address, phone number, location, job title, and company name provided via inquiry forms, contact requests, or portal registrations.
  • Employment & Onboarding Data: Resumes, background verification credentials, identity documents, tax identifiers, and statutory compliance information (including Provident Fund, ESI, Gratuity, and Insurance details).
Automatically Collected Technical Data:
  • System Usage & Device Data: IP addresses, browser specifications, operating system details, access timestamps, and session logs recorded through automated access controls.
Third-Party & Vendor Data:
  • Information received from external recruitment platforms, background verification agencies, and business partners.

3. Purpose and Legal Basis for Processing

We process your personal data for clear, purpose-driven reasons under the following legal bases:

Purpose of ProcessingLegal Basis
Providing, operating, and improving our software, websites, and servicesPerformance of a Contract / Legitimate Interest
Managing candidate applications, recruitment, and digital onboardingLegal Obligation / Contractual Necessity
Enforcing IT security measures, VPN policies, and access logsLegitimate Interest (System Security)
Fulfilling legal, statutory, and regulatory audit compliance obligationsCompliance with Law
Responding to customer inquiries and managing vendor relationshipsLegitimate Interest

4. Data Storage, Security, and Protection Controls

  • Encryption & Storage Security: All sensitive personal and business data is stored in secure, encrypted cloud environments and company-maintained databases. Access is strictly limited on a need-to-know basis.
  • Access Controls & Authentication: We enforce Multi-Factor Authentication (MFA), Virtual Private Network (VPN/VDI) access requirements, and periodic credential updates to prevent unauthorized access.
  • Technical Audits: Routine internal and external security audits are conducted to evaluate data storage environments, remediate vulnerabilities, and ensure data integrity.

5. Data Retention & Secure Disposal

  • Retention Criteria: Personal data is retained only for as long as necessary to fulfill the original purpose of collection or as mandated by legal, financial, and regulatory obligations.
  • System Backups: Routine incremental and full backups are maintained in encrypted formats for a minimum of 90 days to ensure disaster recovery and business continuity.
  • Secure Destruction: Upon expiration of retention periods, data is permanently deleted or anonymized using industry-standard secure destruction protocols.

6. Third-Party Data Sharing & International Transfers

We do not sell, rent, or trade personal data. We may share information with trusted third-party service providers (such as cloud hosting partners, IT support vendors, statutory benefits administrators, and background check agencies) under strict confidentiality and data processing agreements.

If data is transferred internationally outside the primary jurisdiction, we implement appropriate safeguards (such as Standard Contractual Clauses) to ensure an equivalent level of protection.

7. Data Subject Rights

Depending on your location, you may exercise the following rights regarding your personal data:

  • Access & Portability: Request a copy of the personal data we hold about you.
  • Correction & Erasure: Request correction of inaccurate data or deletion of data no longer required for business or legal purposes.
  • Restriction & Objection: Object to processing based on legitimate interests or request processing restrictions.
  • Consent Withdrawal: Withdraw consent at any time where processing is based on consent.

8. Incident Response & Breach Notification

In the event of a suspected security incident or data breach, our IT Security Lead and Data Protection team execute a structured incident response plan. Compromised systems are isolated immediately, and notifications are sent to affected individuals and relevant regulatory authorities as required by law.

9. Contact Information & Grievances

For inquiries, data protection concerns, or exercising your privacy rights, please contact our Data Protection / HR team:

  • Entity: Ascentware Private Limited
  • Data Protection & HR Contact: hr@ascentware.com (or designated security email)