LegalPrivacy Policy
Privacy Policy
Edgeryt Hire is a hiring and assessment workspace from Eroforze Systems Private Limited (Edgeryt). This policy explains what personal information we process when you use the platform worldwide, including apply, booking and assessment pages a workspace shares with candidates. Last updated 5 October 2026.
Product-accurate draft pending external counsel review. Entity details and liability clauses may change before launch.
1. Introduction
This Privacy Policy describes how Eroforze Systems Private Limited (“we”, “us”, “our”) collects, uses, shares and protects personal information in connection with Edgeryt Hire and related assessment experiences.
By using the service, you acknowledge this policy. If you do not agree, do not use the service. Candidates who disagree with an assessment’s monitoring notice may decline to start.
2. Who We Are
The service is operated by Eroforze Systems Private Limited (“Eroforze Systems”, “we”, “us”, “our”) under the Edgeryt, Edgeryt Hire, Edgeryt Assessment trading names.
Registered office
180/2, Bharathi Nagar, Sirumugai Post
Mettupalayam, Coimbatore, Tamil Nadu – 641302
India
- Country of incorporation: India
- CIN: U28249TZ2024PTC031297
- GSTIN: 33AAICE1445J1ZR
- Privacy, legal, DPA, security and support: privacy@edgeryt.com
- We have not appointed a separate Data Protection Officer. Privacy, data-subject and DPA requests are handled at privacy@edgeryt.com.
3. Scope of This Privacy Policy
This policy covers:
- People who create or join a workspace (admins, recruiters, interviewers and similar roles).
- Candidates who apply to a job, book an interview, or take an assessment a workspace sends them.
- Visitors to public policy, support and integration pages on the Hire origin.
We offer the service to customers and candidates in India, the United States, the United Kingdom, the European Union and European Economic Area, Australia, and other countries where customers and candidates use the service. Local laws may give you additional rights described in later sections.
It does not replace a hiring company’s own privacy notice where that company is the controller of candidate data. Where a workspace shows its own contact email or policy URL on the apply page, that company’s notice also applies.
4. Information We Collect
Depending on how you use the service, we may process:
- Identity and contact details (name, email, optional phone).
- Account and security data (password hashes, 2FA status, sessions, sign-in IP and approximate location).
- Workspace content (jobs, forms, notes, stages, team membership and roles).
- Application materials (answers, resumes/CVs and other uploaded files).
- Assessment data (answers, scores, integrity events, device and network metadata, optional media).
- Interview metadata (times, interviewers, meeting join links, integration connection status).
- Billing metadata (plan, invoices, payment status from our payment provider).
- Support communications you send to us.
5. How We Collect Information
- Directly from you (sign-up, forms, uploads, assessment consent and browser permissions).
- From the hiring workspace that invites or imports you as a candidate.
- Automatically from your browser or device (device type, screen size, integrity signals, IP and approximate city/country).
- From connected meeting providers when a workspace authorises Google, Microsoft or Zoom.
- From payment processors when a workspace subscribes.
6. How We Use Personal Information
- To provide accounts, jobs, applications, assessments, interviews and related emails.
- To secure accounts, detect abuse and show session/device history.
- To score assessments, surface integrity summaries and store evidence the workspace enabled.
- To run optional AI features (question generation, written-answer grading) under the workspace’s plan.
- To enforce retention, export and erasure settings the workspace configures.
- To bill for paid plans and communicate about the service.
- To comply with law and respond to lawful requests.
We do not sell personal information.
7. Legal Bases for Processing (GDPR)
Where the GDPR or UK GDPR applies, we rely on one or more of:
- Contract — to provide the service to the customer that has an account with us.
- Legitimate interests — security, product integrity, service improvement and support, balanced against your rights.
- Consent — where required for optional monitoring (camera, microphone, screen) or similar processing; candidates may refuse by not starting the assessment.
- Legal obligation — where we must retain or disclose information under applicable law.
When we act as a processor for a customer, the customer is responsible for establishing its own lawful basis for candidate processing.
8. Candidate Data and Assessment Data
The hiring company that owns the workspace determines why candidate information is collected and how long it is kept for hiring. We process that information so the workspace can run applications, assessments and interviews.
Before an assessment starts, the product lists what that assessment will collect. Monitoring stops when the candidate submits. See also our Candidate Assessment Terms.
9. Recruiter / Employer Account Data
Workspace members provide name and email to join. We store role, preferences (such as notification settings), branding assets the workspace uploads, and security logs of sign-ins. Admins may invite or remove members. Removing a member ends their access to that workspace’s hiring data.
10. Resume, CV and Application Data
Resumes and application files are stored in our object storage. The workspace record holds a reference key, not the file bytes in the database. We may parse resumes on the server to extract structured fields (skills, experience, education and similar) and to compute an ATS-style match against the job for sorting and display. Match scores assist recruiters; they are not an automated hiring decision by the platform.
11. Assessment, Proctoring and Interview Data
Assessments may collect, depending on configuration:
- Answers, uploaded answer files, timestamps and scores.
- Browser, device type and screen size; IP address, internet provider and approximate location (city).
- Integrity events (for example leaving fullscreen, switching tabs, copy/paste attempts, extra displays).
- Camera, microphone and/or screen monitoring after browser permission — including photos from the camera about every 30 seconds when the camera is required, and short evidence clips around integrity issues when the assessment says media is recorded (plus continuous screen recording while you work outside the browser on a file question, when that feature is used).
- Identity photos and, when enabled, a photo of a photo ID (including government, college or employee ID types the assessment specifies). Face and voice comparisons for presence and identity run on the candidate’s device; templates used for those checks are not uploaded as raw biometric models for cloud face search.
- Signs that automation tools or AI agents are controlling the browser, when integrity features are on.
Interview records store scheduling metadata and join links. Connected meeting provider tokens are encrypted at rest and deleted when the workspace disconnects the integration.
12. AI-Powered Processing and Automated Decision-Making
Optional AI features may generate assessment questions or grade short and long written answers using third-party language-model providers configured for the deployment. Proctoring “AI” for face, gaze and voice runs primarily on the candidate’s device. Integrity bands and AI grades inform human reviewers; the hiring company decides progression and hiring outcomes.
Details: AI & Automated Decision-Making Notice.
15. Service Providers and Subprocessors
A current list is published at /legal/subprocessors. Categories include:
- Convex, Inc. — Application database and serverless backend
- Cloudflare, Inc. (R2) — Object storage for files and assessment media
- Resend — Transactional email delivery
- Razorpay — Subscription billing and payment processing
Optional and gated providers (AI, sandbox, Zoom, etc.) process data only when enabled for the deployment or workspace.
16. International Data Transfers
Eroforze Systems Private Limited is incorporated in India. Our primary application database runs in United States (Virginia) — primary Convex Cloud deployment for application data. Files and assessment media are stored in Cloudflare R2; see the Subprocessor List for current bucket region details. We and our subprocessors may therefore process data in countries other than where you or the hiring company are located, including the United States and India.
Where required by law (for example in the EEA, UK or Switzerland), we use appropriate transfer mechanisms described in our Data Processing Agreement. Contact privacy@edgeryt.com to request signed transfer documentation.
17. Data Security
We use industry-standard measures including encryption in transit, access controls, encrypted integration tokens, rate limiting, and separation of file storage from database records. No method of transmission or storage is completely secure. See our Trust Center.
18. Data Retention
Each workspace chooses how long to keep rejected candidates, hired candidates, closed-job applications, proctoring media and trash, and whether expired candidate records are deleted or anonymised. Assessment recordings and photos are also deleted within the period shown to the candidate before they start (and may be shortened by the workspace’s media retention setting). Account and billing records are kept as needed to operate the service and meet legal obligations.
19. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, export or restrict processing of personal information, and to object to certain processing. Workspace users can use in-product security and privacy tools where available, or email privacy@edgeryt.com.
Candidates should contact the hiring company that invited them (using the contact shown on the apply page when provided) for requests about hiring decisions and candidate records. You may also contact us; we may forward requests to the relevant customer when we act as their processor.
20. GDPR Rights for EEA/UK Users
Where GDPR or UK GDPR applies, you may have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where processing is consent-based. You may lodge a complaint with your local supervisory authority. When we process candidate data for a customer, that customer is typically the controller you should contact first.
21. California Privacy Rights (CCPA/CPRA)
California residents may have rights to know, delete and correct personal information, and to opt out of sale or sharing for cross-context behavioural advertising. We do not sell personal information and do not use it for cross-context behavioural advertising as those terms are commonly defined. To exercise rights, email privacy@edgeryt.com. We will not discriminate against you for exercising privacy rights.
22. Other U.S. State Privacy Rights
Residents of other U.S. states with comprehensive privacy laws may have similar rights. Contact us at privacy@edgeryt.com and we will respond in accordance with applicable law. Candidate requests about hiring data may be referred to the employer customer.
23. Children’s Privacy
The service is intended for professional hiring and adult candidates. It is not directed at children under 16 (or the higher age required in your jurisdiction). We do not knowingly collect personal information from children for the service. If you believe we have, contact us and we will take appropriate steps.
24. Data of Candidates Submitted by Employers
Employers may import or invite candidates. The employer is responsible for having a lawful basis and providing any notices required before submitting candidate contact details to the platform. We process such data on the employer’s instructions as described in our DPA.
25. Data Controller and Data Processor Roles
- Employer customer — controller (and, where India’s DPDP Act applies, Data Fiduciary) of candidate and hiring data it collects through the workspace.
- Eroforze Systems Private Limited — processor / service provider (Data Processor under the DPDP Act, where applicable) for that candidate data; independent controller of account, billing, security and platform operations data.
- Candidate — data subject (Data Principal under the DPDP Act, where applicable).
26. Data Processing Agreement (DPA)
Business customers that need a DPA for GDPR or similar regimes may review our public DPA at /legal/dpa and request a signed copy by emailing privacy@edgeryt.com.
27. Third-Party Services and Integrations
Optional integrations (Google sign-in, Google Calendar/Meet, Microsoft Teams, Zoom when live, Razorpay checkout, AI providers) are governed by those providers’ terms as well as this policy. We store only the tokens and metadata needed to operate the connection; tokens are encrypted. Disconnecting an integration deletes the tokens we stored for it.
28. Changes to This Privacy Policy
We may update this policy from time to time. The “Last updated” date at the top of the page will change when we do. Continued use after an update constitutes acceptance of the revised policy where permitted by law.
29. Contact Us
Questions about this policy: privacy@edgeryt.com. We aim to reply within one business day, Monday to Friday.
Eroforze Systems Private Limited
180/2, Bharathi Nagar, Sirumugai Post, Mettupalayam, Coimbatore, Tamil Nadu – 641302, India
Email: privacy@edgeryt.com
All legal documents · Terms of Use · Candidate Assessment Terms · Cookie Policy · AI & Automated Decision-Making · Support