This Privacy Policy explains how DIGYUG LLP ("we", "us", "our"), which operates TooHR (the "Service"), handles personal data. It is written to align with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made under it.
1. Our two roles
TooHR is used by recruitment and staffing agencies to manage their hiring. Depending on whose data is involved, we act in one of two capacities under the DPDP Act:
- As a Data Fiduciary — for personal data of our own prospects, customers and their staff: people who submit our enquiry form, register a workspace, sign in as agency users, or contact our support.
- As a Data Processor — for the candidate, client-contact and related records that our customer agencies enter into the Service ("Customer Data"). Here the agency is the Data Fiduciary and decides the purposes of processing; we process this data on their instructions under our agreement with them (see section 10).
2. Personal data we collect
Where we are the Data Fiduciary
- Enquiries / leads: name, work email, phone, company, your message, and the IP address of the submission.
- Workspace registration & accounts: your name, work email, phone, organisation name, chosen subdomain, and team size.
- Billing: business name, GSTIN and billing address for invoices; payment and order identifiers returned by our payment processor (never your full card or bank details).
- Support: the content of tickets and messages you send us.
- Technical & security data: IP address, device/browser information, sign-in and session records, and — for the "remember this device" feature — a hashed device token with IP and user-agent.
Where we are the Data Processor (Customer Data)
- Candidate records entered by agency users: name, phone(s), email(s), current employer and designation, education, city/state, current and expected compensation, notice period, offer details, résumé/CV files, LinkedIn URL, and free-text notes, call remarks and interview feedback.
- Client-company contact details and mandate information.
Candidates are typically added to the Service by an agency, which is responsible for having a lawful basis to do so. If you are a candidate, please read section 9.
3. Purposes and legal basis
We process personal data on the basis of your consent, and for certain legitimate uses permitted by the DPDP Act (for example, responding to a request you initiate, and safeguarding our Service against fraud and misuse). Purposes include:
- Providing, maintaining, securing and improving the Service.
- Responding to enquiries and support requests you send us.
- Creating and administering your workspace and processing subscriptions and payments.
- Sending you service-related communications (for example, email verification and important notices).
- Complying with legal, tax and regulatory obligations.
4. Cookies and analytics
Essential cookies (for sign-in sessions and security) are always used, as they are strictly necessary to operate the Service. Non-essential analytics and marketing technologies are used only if you opt in via our cookie banner; you can decline, and no such tracker is loaded unless and until you accept. We do not run third-party analytics inside the signed-in application where candidate data is displayed.
5. How we share personal data
We do not sell personal data. We share it only with:
- Processors / service providers who help us run the Service, under confidentiality and data-protection obligations — currently: cloud hosting (in India), transactional email delivery, our payment processor (Razorpay Software Private Limited, India), and an IP-based country lookup used to show the right pricing. Optional analytics providers receive data only where you have consented.
- Authorities, where required by law or to protect rights and safety.
- A successor entity in a merger, acquisition or asset sale, subject to this Policy.
6. Storage and cross-border transfer
Personal data is stored on servers located in India. Where a processor operates outside India, any transfer is limited to what is necessary to deliver the Service and is permitted under the DPDP Act (we do not transfer personal data to any territory restricted by the Central Government).
7. Data retention
We keep personal data only for as long as needed for the purpose it was collected, then delete it. Our current default periods are:
- Enquiries / leads: up to 12 months from submission.
- Unverified/abandoned registrations: deleted within 7 days.
- Employee activity/presence logs: up to 6 months.
- Customer Data (candidate records): retained while the agency's workspace is active; candidate records with no activity may be flagged for review and erasure after 24 months. Agencies control retention of their own Customer Data.
- Billing and tax records: retained as long as required by applicable law.
After account closure we retain only what the law requires, then delete or anonymise the rest.
8. Your rights as a Data Principal
Subject to the DPDP Act, you have the right to:
- Access a summary of the personal data we process about you and how we process it.
- Correction, completion and updation of your personal data.
- Erasure of your personal data where it is no longer needed for the purpose it was collected, or where you withdraw consent.
- Grievance redressal — to raise a concern with us and receive a response.
- Nomination — to nominate another individual to exercise your rights in the event of death or incapacity.
To exercise any right, use our data-request form or contact our Grievance Officer (section 11). We will verify your identity and respond within the timelines required by law.
9. Withdrawing consent
Where we rely on your consent, you may withdraw it at any time — it is as easy to withdraw as it was to give. You can change your cookie choice via the banner, and you can withdraw other consents by contacting the Grievance Officer. Withdrawal does not affect processing already carried out, and some data may be retained where the law requires.
10. If you are a candidate or a client contact
For candidate and client-contact records, the recruitment agency that entered your data into the Service is the Data Fiduciary, and TooHR acts only as its Data Processor. To access, correct or erase such data, please contact the agency directly. If you are unsure who holds your data, or you contact us, we will help route your request to the relevant agency and support them in actioning it. We do not use Customer Data for our own purposes.
11. Grievance Officer
In accordance with the DPDP Act, you may contact our Grievance Officer with any question, request or complaint about your personal data:
Tanmay Agrawal, Product Director
DIGYUG LLP
501, Centura Square, Rd. no. 27, Wagle Estate, Thane West, Maharashtra 400604, India
Email: tanmay@digyug.com
If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India.
12. Security
We use reasonable technical and organisational safeguards, including tenant isolation, role-based access controls, encryption in transit, hashed credentials, private storage for uploaded files, and rate limiting. No system is perfectly secure, but we take steps to protect personal data and to notify affected individuals and the Data Protection Board of a personal-data breach as required by law.
13. Children
The Service is intended for business use and is not directed to individuals under 18. We do not knowingly process the personal data of children without verifiable parental consent.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the Service or by email, and the "last updated" date above will be revised.
15. Contact
DIGYUG LLP
501, Centura Square, Rd. no. 27, Wagle Estate, Thane West, Maharashtra 400604, India
Email: support@toohr.com