Talent Radar · Cybersecurity — India needs 250K+ security pros by 2028; supply covers about a third.

Get the report
Legal · Privacy

How we handle your data.

The full statement of what we collect, why, who we share it with, and the rights you have — wherever you are. We operate in India, Europe, the United States, and across Asia, and this notice covers all of them. Written to be read, not just to comply.

Last updated 2 July 2026Version 4.0Applies to India · EU/UK · US · Asia

Draft for legal review

This notice has been expanded to cover our launch in India, the European Union, the United Kingdom, the United States, and wider Asia. Entity names, the EU/UK representatives, and the regional privacy contacts marked […] below are placeholders to be confirmed and finalised by counsel before launch.

01 Who we are, and what this notice covers

The version that matters

We collect the data we actually need to do the work — match candidates to mandates, run our intelligence platform, and stay in touch. We don’t sell it. We don’t run ad networks on it. Depending on where you live, you can ask what we hold, correct it, port it, object to how we use it, or have us erase it — and we honour those rights wherever you are. The rest of this page is the detail.

This Privacy Notice explains how the Recruise group of companies collects, uses, shares, and protects personal data when you interact with us — as a candidate, client, subscriber, event attendee, or visitor to our websites at recruiseglobal.com and recruiseindia.com.

Which Recruise company is responsible for your data (the controller, or Data Fiduciary under Indian law) depends on where you are:

India & wider Asia
Recruise India Consulting Pvt. Ltd., a private company incorporated in India with its registered office at 5M-671, M M Square, OMBR Layout, Banaswadi, Bengaluru, Karnataka 560043.
European Union & United Kingdom
[Recruise EU/UK entity name], [registered office / address]. If no local entity is established at the time you read this, Recruise India Consulting Pvt. Ltd. is the controller and has appointed the representatives named in section 14.
United States
[Recruise US entity name], [registered office / address], or Recruise India Consulting Pvt. Ltd. where no US entity is established.

Together we are “Recruise” or “Recruise Global”, “we”, “us”, “our”. Where this notice refers to “you”, we mean the individual the data is about — the Data Principal under India’s DPDP Act, the data subject under the GDPR, or the consumer under US state privacy laws.

If anything here is unclear, write to us at privacy@recruiseglobal.com. We will reply in plain English.

02 Which law applies to you

We hold ourselves to the same standards everywhere, but the specific law that governs your data — and the exact rights you can exercise — depends on where you are. This notice covers all of them in one place so you don’t have to guess:

India
The Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (notified 13 November 2025, coming into force in phases through 2027). Your rights are in section 08.
European Union
The EU General Data Protection Regulation (GDPR) and applicable national law. Your rights are in section 09.
United Kingdom
The UK GDPR and the Data Protection Act 2018. Your rights mirror the EU rights in section 09.
United States
State privacy laws including the California Consumer Privacy Act as amended (CCPA/CPRA) and the comprehensive privacy laws now in force in Virginia, Colorado, Connecticut, Texas, and other states. Your rights are in section 10.
Wider Asia
Local data-protection law where you are — for example Singapore’s PDPA. We apply the protections in this notice as a baseline and meet any additional local requirement that applies.

03 What personal data we collect

We collect different kinds of personal data depending on how you interact with us. We do not collect data we do not need.

If you are a candidate

  • Identity and contact data — name, professional email, mobile number, location, LinkedIn URL.
  • Professional data — your CV, career history, current and expected compensation, notice period, qualifications, references where you provide them.
  • Mandate-specific data — interview notes, assessment scores, feedback we share with clients on your behalf, offer details where applicable.
  • Special-category / sensitive data — collected only where strictly necessary (for example, immigration status for relocation roles, or information relevant to a reasonable accommodation) and only with your explicit consent or another lawful basis. In the EU/UK this is “special category data” under Article 9 GDPR; in the US, “sensitive personal information.”

If you are a client or prospective client

  • Business contact data — name, role, work email, work mobile, company.
  • Engagement data — mandate details, hiring criteria, feedback on candidates, contract and commercial terms.

If you subscribe to The Signal or another publication

  • Subscription data — email address, first name where given, role focus where given, audience preference (enterprise / individual), open and click signals from emails we send you.

If you visit our website

  • Technical data — IP address, device type, browser, pages visited, time on page, referring URL.
  • Cookie data — see our Cookie Policy for the cookies we use and how to manage them. In the EU/UK, non-essential cookies load only after you opt in.

04 How we use your data

We use personal data for the following specific purposes, and no others:

  • To run our search and placement work — matching candidates to client mandates, presenting profiles with appropriate consent, coordinating interviews, supporting offer and onboarding stages.
  • To build and maintain our market intelligence — anonymised and aggregated salary, hiring velocity, and sector trend data drawn from our placement work. We never publish data that identifies an individual without explicit consent.
  • To deliver subscriptions and publications — sending you The Signal, sector reports, and event invitations you have opted in to.
  • To respond to enquiries — replying to messages you send us via the website, email, or LinkedIn.
  • To meet our legal and contractual obligations — accounting, tax, statutory reporting, and dispute resolution.
  • To keep our systems safe — preventing fraud, abuse, and unauthorised access to our platforms.

05 Lawful basis for processing

We only process personal data where we have a lawful basis to do so. The specific basis depends on the purpose and on the law that applies to you.

Under India’s DPDP Act

Consent
For subscription to The Signal and other publications; for sharing your candidate profile with a specific client; for participating in research interviews; for receiving event invitations.
Legitimate use
For replying to enquiries you initiate; for delivering services under a contract you have signed with us; for our internal record-keeping, security, and dispute resolution.
Legal obligation
Where Indian law requires us to retain, disclose, or process specific data — for example, tax filings or response to lawful requests from public authorities.

Under the EU / UK GDPR

Consent (Art. 6(1)(a))
Subscriptions, non-essential cookies and analytics, sharing your candidate profile with a named client, and research participation. You can withdraw it at any time.
Contract (Art. 6(1)(b))
Delivering services under a contract with you, or taking steps at your request before entering one.
Legitimate interests (Art. 6(1)(f))
Running and securing our business, responding to enquiries, and building anonymised market intelligence — balanced against your rights, which you can object to (see section 09).
Legal obligation (Art. 6(1)(c))
Accounting, tax, and lawful requests from authorities.

Where we process special-category data, we rely on your explicit consent or another Article 9 condition.

You can withdraw consent at any time, for any consent-based purpose, without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, write to privacy@recruiseglobal.com or use the unsubscribe link in any email we send you.

06 Who we share data with

We share personal data only with the parties listed below, and only for the purposes described.

  • Clients — we share candidate profiles with clients you have agreed we may approach. We tell you which client we are presenting you to, and we never present you to a client without your knowledge.
  • Service providers (processors / Data Processors) — we use a small number of trusted vendors to run our operations: our applicant tracking system, our email and productivity stack, our customer relationship management platform, and our cloud hosting providers. Each processes data under a written agreement that binds them to our standards.
  • Group companies — the Recruise entities named in section 01 may share data with one another to serve you across regions, under intra-group agreements.
  • Professional advisors — our auditors, lawyers, and accountants, where necessary and only to the extent required.
  • Authorities — where we are required to disclose data by law, court order, or in response to a lawful request from a regulator.

We do not sell personal data, and we do not “share” it for cross-context behavioural advertising as those terms are defined under US state privacy laws. We do not share data with advertisers. We do not use personal data to train external AI models.

07 How long we keep data

We keep personal data only for as long as we need it for the purposes set out in this notice, or as required by law.

Candidate data
Active candidate profiles: kept until 36 months from last meaningful contact, after which we delete or anonymise unless you ask us to retain you for future opportunities.
Client engagement data
Kept for the duration of the engagement plus 7 years (statutory accounting and dispute-resolution requirements).
Subscription data
Until you unsubscribe or ask us to delete you. We re-confirm subscriptions every 24 months.
Website analytics
Aggregated and anonymised after 14 months.

08 Your rights in India (DPDP Act)

If you are in India, you have the following rights as a Data Principal. We will respond within 30 days, free of charge, in plain English.

Right to access
Ask us for a summary of the personal data we process about you and the purposes for which we process it.
Right to correction
Ask us to correct inaccurate, incomplete, or outdated data.
Right to erasure
Ask us to delete data we no longer need, or for which you have withdrawn consent, subject to any retention obligation we have under law.
Right to nominate
Nominate another individual to exercise your rights in the event of your death or incapacity.
Right to grievance redressal
Raise a complaint with our Grievance Officer (see section 14). If you are not satisfied with our response, you may escalate to the Data Protection Board of India under section 27 of the DPDP Act.

09 Your rights in the EU & UK (GDPR)

If you are in the European Union or the United Kingdom, you have the following rights. We will respond within one month, free of charge, and will tell you if we need to extend that for complex requests.

Access
Obtain a copy of the personal data we hold about you and information about how we process it.
Rectification
Have inaccurate or incomplete data corrected.
Erasure (“right to be forgotten”)
Have your data deleted where there is no overriding reason for us to keep it.
Restriction
Ask us to pause processing while a concern is resolved.
Portability
Receive the data you gave us in a structured, machine-readable format, or have it sent to another controller.
Objection
Object to processing based on legitimate interests, and to any direct marketing at any time.
Withdraw consent
Withdraw any consent you have given, at any time, without affecting prior processing.
Complain to a supervisory authority
Lodge a complaint with your local Data Protection Authority — in the UK, the Information Commissioner’s Office (ICO). We’d appreciate the chance to resolve it first.

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

10 Your rights in the United States

If you are a resident of California or another US state with a comprehensive privacy law, you have the following rights, which we honour regardless of which state you live in. We will not discriminate against you for exercising them.

Right to know / access
Learn what personal information we collect, use, and disclose, and request a copy.
Right to correct
Have inaccurate personal information corrected.
Right to delete
Request deletion of personal information we hold about you, subject to legal exceptions.
Right to opt out
Opt out of any “sale” or “sharing” of personal information and of targeted advertising. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of — but the choice is yours if that ever changes.
Right to limit sensitive information
Direct us to limit our use of sensitive personal information to what is necessary to provide our services.

We honour browser Global Privacy Control (GPC) signals as a valid opt-out. To exercise any right, use the “Your Privacy Choices” link in our footer or email privacy@recruiseglobal.com. You may use an authorised agent, and we will verify your identity before acting. We will respond within 45 days.

11 International data transfers

We operate across India, Europe, the United States, and Asia, so your data may be processed in a country other than the one you live in — including in the United States and the European Union. Wherever data goes, we apply the same standard of protection and use a lawful transfer mechanism:

  • From the EU/UK — we rely on adequacy decisions where they exist, and otherwise on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with any additional safeguards a transfer requires.
  • From India — we transfer data outside India only where such transfers are not restricted by the Central Government under section 16 of the DPDP Act.
  • Everywhere — our processors are bound by written data-processing agreements that hold them to the protections in this notice.

12 Children’s data

Recruise’s services are aimed at adult professionals. We do not knowingly collect personal data from children — meaning anyone under 18 in India, under 16 in the EU/UK (subject to national law), or under 13 in the United States. If you believe we hold data about a child, write to privacy@recruiseglobal.com and we will delete it.

13 Changes to this notice

We update this notice when our practices change or when the law requires us to. The “Last updated” date at the top of this page tells you when we last changed it. Material changes will be notified to subscribers and active candidates by email at least 14 days before they take effect.

14 How to contact us

For all privacy-related matters, contact our Grievance Officer, who coordinates data-protection enquiries across all regions:

Grievance Officer / Data Protection contact

For data rights, complaints, and privacy enquiries

[Grievance Officer / DPO name]

Recruise India Consulting Pvt. Ltd.

5M-671, M M Square, OMBR Layout, Banaswadi, Bengaluru, Karnataka 560043

Email: privacy@recruiseglobal.com

Response time: within 30 days.

EU / UK representative
[Name and EU address of Art. 27 GDPR representative] · [Name and UK address of UK representative] — to be appointed where required and named here before EU/UK launch.
United States privacy requests
Use the “Your Privacy Choices” link in the footer, or email privacy@recruiseglobal.com.

If you are not satisfied with our response: in India, you may complain to the Data Protection Board of India (section 27, DPDP Act); in the EU, to your local Data Protection Authority; in the UK, to the ICO; in the US, to your state Attorney General.

Let's build what's next.