Draft for legal review
This notice has been expanded to cover our launch in India, the European Union, the United Kingdom, the United States, and wider Asia. Entity names, the EU/UK representatives, and the regional privacy contacts marked […] below are placeholders to be confirmed and finalised by counsel before launch.
01 Who we are, and what this notice covers
The version that matters
We collect the data we actually need to do the work — match candidates to mandates, run our intelligence platform, and stay in touch. We don’t sell it. We don’t run ad networks on it. Depending on where you live, you can ask what we hold, correct it, port it, object to how we use it, or have us erase it — and we honour those rights wherever you are. The rest of this page is the detail.
This Privacy Notice explains how the Recruise group of companies collects, uses, shares, and protects personal data when you interact with us — as a candidate, client, subscriber, event attendee, or visitor to our websites at recruiseglobal.com and recruiseindia.com.
Which Recruise company is responsible for your data (the controller, or Data Fiduciary under Indian law) depends on where you are:
- India & wider Asia
- Recruise India Consulting Pvt. Ltd., a private company incorporated in India with its registered office at 5M-671, M M Square, OMBR Layout, Banaswadi, Bengaluru, Karnataka 560043.
- European Union & United Kingdom
- [Recruise EU/UK entity name], [registered office / address]. If no local entity is established at the time you read this, Recruise India Consulting Pvt. Ltd. is the controller and has appointed the representatives named in section 14.
- United States
- [Recruise US entity name], [registered office / address], or Recruise India Consulting Pvt. Ltd. where no US entity is established.
Together we are “Recruise” or “Recruise Global”, “we”, “us”, “our”. Where this notice refers to “you”, we mean the individual the data is about — the Data Principal under India’s DPDP Act, the data subject under the GDPR, or the consumer under US state privacy laws.
If anything here is unclear, write to us at privacy@recruiseglobal.com. We will reply in plain English.
02 Which law applies to you
We hold ourselves to the same standards everywhere, but the specific law that governs your data — and the exact rights you can exercise — depends on where you are. This notice covers all of them in one place so you don’t have to guess:
- India
- The Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (notified 13 November 2025, coming into force in phases through 2027). Your rights are in section 08.
- European Union
- The EU General Data Protection Regulation (GDPR) and applicable national law. Your rights are in section 09.
- United Kingdom
- The UK GDPR and the Data Protection Act 2018. Your rights mirror the EU rights in section 09.
- United States
- State privacy laws including the California Consumer Privacy Act as amended (CCPA/CPRA) and the comprehensive privacy laws now in force in Virginia, Colorado, Connecticut, Texas, and other states. Your rights are in section 10.
- Wider Asia
- Local data-protection law where you are — for example Singapore’s PDPA. We apply the protections in this notice as a baseline and meet any additional local requirement that applies.
03 What personal data we collect
We collect different kinds of personal data depending on how you interact with us. We do not collect data we do not need.
If you are a candidate
- Identity and contact data — name, professional email, mobile number, location, LinkedIn URL.
- Professional data — your CV, career history, current and expected compensation, notice period, qualifications, references where you provide them.
- Mandate-specific data — interview notes, assessment scores, feedback we share with clients on your behalf, offer details where applicable.
- Special-category / sensitive data — collected only where strictly necessary (for example, immigration status for relocation roles, or information relevant to a reasonable accommodation) and only with your explicit consent or another lawful basis. In the EU/UK this is “special category data” under Article 9 GDPR; in the US, “sensitive personal information.”
If you are a client or prospective client
- Business contact data — name, role, work email, work mobile, company.
- Engagement data — mandate details, hiring criteria, feedback on candidates, contract and commercial terms.
If you subscribe to The Signal or another publication
- Subscription data — email address, first name where given, role focus where given, audience preference (enterprise / individual), open and click signals from emails we send you.
If you visit our website
- Technical data — IP address, device type, browser, pages visited, time on page, referring URL.
- Cookie data — see our Cookie Policy for the cookies we use and how to manage them. In the EU/UK, non-essential cookies load only after you opt in.
04 How we use your data
We use personal data for the following specific purposes, and no others:
- To run our search and placement work — matching candidates to client mandates, presenting profiles with appropriate consent, coordinating interviews, supporting offer and onboarding stages.
- To build and maintain our market intelligence — anonymised and aggregated salary, hiring velocity, and sector trend data drawn from our placement work. We never publish data that identifies an individual without explicit consent.
- To deliver subscriptions and publications — sending you The Signal, sector reports, and event invitations you have opted in to.
- To respond to enquiries — replying to messages you send us via the website, email, or LinkedIn.
- To meet our legal and contractual obligations — accounting, tax, statutory reporting, and dispute resolution.
- To keep our systems safe — preventing fraud, abuse, and unauthorised access to our platforms.
05 Lawful basis for processing
We only process personal data where we have a lawful basis to do so. The specific basis depends on the purpose and on the law that applies to you.
Under India’s DPDP Act
- Consent
- For subscription to The Signal and other publications; for sharing your candidate profile with a specific client; for participating in research interviews; for receiving event invitations.
- Legitimate use
- For replying to enquiries you initiate; for delivering services under a contract you have signed with us; for our internal record-keeping, security, and dispute resolution.
- Legal obligation
- Where Indian law requires us to retain, disclose, or process specific data — for example, tax filings or response to lawful requests from public authorities.
Under the EU / UK GDPR
- Consent (Art. 6(1)(a))
- Subscriptions, non-essential cookies and analytics, sharing your candidate profile with a named client, and research participation. You can withdraw it at any time.
- Contract (Art. 6(1)(b))
- Delivering services under a contract with you, or taking steps at your request before entering one.
- Legitimate interests (Art. 6(1)(f))
- Running and securing our business, responding to enquiries, and building anonymised market intelligence — balanced against your rights, which you can object to (see section 09).
- Legal obligation (Art. 6(1)(c))
- Accounting, tax, and lawful requests from authorities.
Where we process special-category data, we rely on your explicit consent or another Article 9 condition.
You can withdraw consent at any time, for any consent-based purpose, without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, write to privacy@recruiseglobal.com or use the unsubscribe link in any email we send you.
06 Who we share data with
We share personal data only with the parties listed below, and only for the purposes described.
- Clients — we share candidate profiles with clients you have agreed we may approach. We tell you which client we are presenting you to, and we never present you to a client without your knowledge.
- Service providers (processors / Data Processors) — we use a small number of trusted vendors to run our operations: our applicant tracking system, our email and productivity stack, our customer relationship management platform, and our cloud hosting providers. Each processes data under a written agreement that binds them to our standards.
- Group companies — the Recruise entities named in section 01 may share data with one another to serve you across regions, under intra-group agreements.
- Professional advisors — our auditors, lawyers, and accountants, where necessary and only to the extent required.
- Authorities — where we are required to disclose data by law, court order, or in response to a lawful request from a regulator.
We do not sell personal data, and we do not “share” it for cross-context behavioural advertising as those terms are defined under US state privacy laws. We do not share data with advertisers. We do not use personal data to train external AI models.
07 How long we keep data
We keep personal data only for as long as we need it for the purposes set out in this notice, or as required by law.
- Candidate data
- Active candidate profiles: kept until 36 months from last meaningful contact, after which we delete or anonymise unless you ask us to retain you for future opportunities.
- Client engagement data
- Kept for the duration of the engagement plus 7 years (statutory accounting and dispute-resolution requirements).
- Subscription data
- Until you unsubscribe or ask us to delete you. We re-confirm subscriptions every 24 months.
- Website analytics
- Aggregated and anonymised after 14 months.
08 Your rights in India (DPDP Act)
If you are in India, you have the following rights as a Data Principal. We will respond within 30 days, free of charge, in plain English.
- Right to access
- Ask us for a summary of the personal data we process about you and the purposes for which we process it.
- Right to correction
- Ask us to correct inaccurate, incomplete, or outdated data.
- Right to erasure
- Ask us to delete data we no longer need, or for which you have withdrawn consent, subject to any retention obligation we have under law.
- Right to nominate
- Nominate another individual to exercise your rights in the event of your death or incapacity.
- Right to grievance redressal
- Raise a complaint with our Grievance Officer (see section 14). If you are not satisfied with our response, you may escalate to the Data Protection Board of India under section 27 of the DPDP Act.
09 Your rights in the EU & UK (GDPR)
If you are in the European Union or the United Kingdom, you have the following rights. We will respond within one month, free of charge, and will tell you if we need to extend that for complex requests.
- Access
- Obtain a copy of the personal data we hold about you and information about how we process it.
- Rectification
- Have inaccurate or incomplete data corrected.
- Erasure (“right to be forgotten”)
- Have your data deleted where there is no overriding reason for us to keep it.
- Restriction
- Ask us to pause processing while a concern is resolved.
- Portability
- Receive the data you gave us in a structured, machine-readable format, or have it sent to another controller.
- Objection
- Object to processing based on legitimate interests, and to any direct marketing at any time.
- Withdraw consent
- Withdraw any consent you have given, at any time, without affecting prior processing.
- Complain to a supervisory authority
- Lodge a complaint with your local Data Protection Authority — in the UK, the Information Commissioner’s Office (ICO). We’d appreciate the chance to resolve it first.
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.
10 Your rights in the United States
If you are a resident of California or another US state with a comprehensive privacy law, you have the following rights, which we honour regardless of which state you live in. We will not discriminate against you for exercising them.
- Right to know / access
- Learn what personal information we collect, use, and disclose, and request a copy.
- Right to correct
- Have inaccurate personal information corrected.
- Right to delete
- Request deletion of personal information we hold about you, subject to legal exceptions.
- Right to opt out
- Opt out of any “sale” or “sharing” of personal information and of targeted advertising. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of — but the choice is yours if that ever changes.
- Right to limit sensitive information
- Direct us to limit our use of sensitive personal information to what is necessary to provide our services.
We honour browser Global Privacy Control (GPC) signals as a valid opt-out. To exercise any right, use the “Your Privacy Choices” link in our footer or email privacy@recruiseglobal.com. You may use an authorised agent, and we will verify your identity before acting. We will respond within 45 days.
11 International data transfers
We operate across India, Europe, the United States, and Asia, so your data may be processed in a country other than the one you live in — including in the United States and the European Union. Wherever data goes, we apply the same standard of protection and use a lawful transfer mechanism:
- From the EU/UK — we rely on adequacy decisions where they exist, and otherwise on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with any additional safeguards a transfer requires.
- From India — we transfer data outside India only where such transfers are not restricted by the Central Government under section 16 of the DPDP Act.
- Everywhere — our processors are bound by written data-processing agreements that hold them to the protections in this notice.
12 Children’s data
Recruise’s services are aimed at adult professionals. We do not knowingly collect personal data from children — meaning anyone under 18 in India, under 16 in the EU/UK (subject to national law), or under 13 in the United States. If you believe we hold data about a child, write to privacy@recruiseglobal.com and we will delete it.
13 Changes to this notice
We update this notice when our practices change or when the law requires us to. The “Last updated” date at the top of this page tells you when we last changed it. Material changes will be notified to subscribers and active candidates by email at least 14 days before they take effect.
14 How to contact us
For all privacy-related matters, contact our Grievance Officer, who coordinates data-protection enquiries across all regions:
Grievance Officer / Data Protection contact
For data rights, complaints, and privacy enquiries
[Grievance Officer / DPO name]
Recruise India Consulting Pvt. Ltd.
5M-671, M M Square, OMBR Layout, Banaswadi, Bengaluru, Karnataka 560043
Email: privacy@recruiseglobal.com
Response time: within 30 days.
- EU / UK representative
- [Name and EU address of Art. 27 GDPR representative] · [Name and UK address of UK representative] — to be appointed where required and named here before EU/UK launch.
- United States privacy requests
- Use the “Your Privacy Choices” link in the footer, or email privacy@recruiseglobal.com.
If you are not satisfied with our response: in India, you may complain to the Data Protection Board of India (section 27, DPDP Act); in the EU, to your local Data Protection Authority; in the UK, to the ICO; in the US, to your state Attorney General.