Version 3.1 · Effective Sep 03, 2026
HRTailor.AI is operated by SKAD Business Solutions Private Limited ("SKAD", "we", "us"), a company incorporated in India with its registered office at Promenade 3 - 606, 6th Floor, LBS Road, Opp. R City Mall, Ghatkopar (West), Mumbai, Maharashtra 400086, India. CIN U74140MH2021PTC360434.
Version 3.1. Effective from 3 September 2026. Replaces version 3.0 dated 3 September 2026.
This policy is written in plain English. Where it uses a defined term from the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the term has the meaning given in that Act.
1.1 SKAD is the entity responsible for HRTailor.AI, available at hrtailor.ai and its subdomains, the HRTailor.AI web application, and the related APIs (together, the "Service").
1.2 Grievance Officer (DPDP Act section 13 and the Information Technology Rules): Makarand Gaikwad, Director, SKAD Business Solutions Private Limited. Email: [email protected]. Postal address: Promenade 3 - 606, 6th Floor, LBS Road, Opp. R City Mall, Ghatkopar (West), Mumbai, Maharashtra 400086, India. Grievances are handled Monday to Friday, 10:00 to 18:00 IST, excluding public holidays in Maharashtra. Email and post are the only channels; we do not take grievances by phone. We acknowledge grievances within 2 working days and resolve them within 30 days, or sooner where the law requires.
1.3 For questions that are not grievances, write to [email protected].
2.1 SKAD as Data Fiduciary. SKAD is the Data Fiduciary only for the account holder's own account data: the identity, business profile, billing, usage, support and marketing-preference data of the person or business that opens an account with us (employers, HR teams, HR consultants, job seekers), and the data of anonymous visitors who use our free tools. For that data, SKAD decides why and how it is processed, and this policy applies to you directly.
2.2 SKAD as Data Processor. SKAD is the Data Processor for all workforce, candidate and employee data. When an employer, HR team or HR consultant (a "Customer") uploads or invites information about its employees, candidates, contractors or other people (each a "Workforce Data Principal"), the Customer is the Data Fiduciary for that information and SKAD processes it only on the Customer's documented instructions under our Data Processing Agreement. If you are a Workforce Data Principal, your employer is responsible for the lawful basis, the notice you receive, and answering your requests. We help your employer do that, and sections 9 and 10 explain how you can also reach us.
2.3 If you are an HR consultant managing several client companies, each client company is the Data Fiduciary for its own workforce data. You warrant to us that you hold written authority from each client before you add it, and you indemnify SKAD for any claim that you lacked that authority.
3.0 Our legal basis. Where SKAD is the Data Fiduciary, the consent you give at sign-up by ticking the acceptance box is the basis for all of our processing of your account data for the purposes in this section. Where the DPDP Act does not require consent, we rely on "legitimate use" under section 7 of the Act as the fallback basis, for example to provide a service you have asked for, to meet a legal obligation, or to respond to a security incident. Where SKAD is the Data Processor, the Customer's documented instructions are the basis, and the Customer is responsible for its own lawful basis.
The table lists every category we process. "Consent" means you gave it through a clear action such as ticking a box or clicking accept. "Legitimate use" refers to the uses section 7 of the DPDP Act permits without separate consent.
| Category | Examples | Purpose | Basis (SKAD as fiduciary) | Basis (SKAD as processor) |
|---|---|---|---|---|
| Account identity | Name, email, phone, password (hashed), role or persona, country, city | Create and secure your account, sign you in, route features to your role | Consent at sign-up; section 7 legitimate use as fallback | n/a |
| Business profile | Company name, industry, headcount, country, logo, letterhead, signatory | Personalize documents, apply the right statutory rules | Consent at sign-up; section 7 legitimate use as fallback | n/a |
| Billing | Plan, invoice number, amount, currency, subscription status, last four digits of the payment instrument as reported by our payment processor | Charge for paid plans, issue receipts, meet tax and accounting law | Consent at sign-up; section 7 legitimate use (legal obligation) as fallback | n/a |
| Usage and device | IP address (hashed after use for rate limiting), approximate location from IP, browser type, pages used, feature usage, credit balance and consumption | Keep the service secure, prevent abuse, meter credits, improve the product | Consent at sign-up; section 7 legitimate use (security) as fallback | n/a |
| Tool inputs and outputs | Text, files and settings you enter into an AI tool, and the documents produced | Generate the document you asked for and let you retrieve it later | Consent at sign-up; section 7 legitimate use as fallback | Customer instruction |
| Workforce records | Employee name, employee code, work and personal email, phone, job title, department, manager, location, joining date, probation and contract dates, visa expiry, custom fields the Customer defines | Run the Customer's HR operations | n/a | Customer instruction |
| Government identifiers | PAN, UAN, Emirates ID, passport number, visa details, and Aadhaar number where the Customer needs it for statutory registrations and filings (PF, ESIC, professional tax). Identity numbers are stored encrypted and are visible only to the Customer's owner and admin roles (see section 3.3) | Statutory registrations, filings, payroll and identity checks run by the Customer | n/a | Customer instruction; the Customer must have a lawful basis |
| Financial | Salary, CTC and components, bank account number, IFSC or SWIFT, beneficiary name, payroll runs, payslips, loans, expense claims | Payroll and payments run by the Customer | n/a | Customer instruction |
| Attendance and location | Clock-in and clock-out times, shift, notes, and a single location reading captured only at the moment of clock-in (rounded to about 10 meters) when the Customer enables it | Attendance records | n/a | Customer instruction; the employee sees a notice before the first capture |
| Leave and wellbeing | Leave requests, balances and the reason an employee gives, which may include health information | Leave management | n/a | Customer instruction; health details are processed only because the employee chose to state them |
| Documents and signatures | Offer letters, policies, agreements, uploaded ID copies, drawn or typed signatures, signing time, IP address and browser identifier of the signer | Document management and electronic acceptance of documents | Consent at sign-up (for your own documents) | Customer instruction |
| Background verification packs, exit interviews, surveys, performance and goals | The Customer's templates and the answers people give | The Customer's HR processes | n/a | Customer instruction |
| Support and enquiries | Messages you send us, bug reports, feature requests, attachments | Answer you and fix problems | Consent at sign-up; section 7 legitimate use as fallback | n/a |
| Marketing preferences | Your choice to receive product updates, to allow analytics, and to allow your inputs to be used to improve AI prompts and models | Send what you agreed to and nothing else | Separate consent, withdrawable at any time | n/a |
3.1 Special note on AI. When you use an AI feature, the inputs you provide, and where a Customer instructs it, workforce records needed for the task, are sent to an AI provider listed in section 6 to produce the output. We select providers that contractually do not train their models on API inputs for the tools that handle workforce data. Free tools for job seekers may use providers that retain inputs; we tell you this at the point of use and in section 6.
Separately, we may ask whether you allow SKAD to use your tool inputs and outputs to improve our own prompts and AI models. This consent is optional. The box is unticked by default. You can withdraw it at any time from My Account, and withdrawal takes effect for all future use. Giving this consent is never a condition of the free tier or of any plan, and refusing it does not change the features or credits you receive. Workforce data is never used for this purpose without the Customer's separate instruction.
3.2 Sensitive information. We do not ask for and do not need caste, religion, sexual orientation, biometric templates or genetic data. If a Customer or a data principal enters such information into a free-text field, it is processed only as part of that record, under the Customer's responsibility, and is deleted with the record.
3.3 Aadhaar. The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and the regulations under it restrict how private bodies may collect, store and use Aadhaar numbers. For any Aadhaar number entered into the Service:
(a) the employer (the Customer) is the Data Fiduciary and warrants to us that it holds the employee's consent to collect and use the Aadhaar number in the form the Aadhaar Act and the Aadhaar Regulations require;
(b) SKAD is a Data Processor only and does not collect Aadhaar numbers for its own purposes;
(c) the purpose is limited to registrations and filings with the Employees' Provident Fund Organisation, the Employees' State Insurance Corporation, a state professional tax authority, and other statutory registrations and filings that require it;
(d) we store the number encrypted at rest, show it only to the Customer's owner and admin roles, and never send it to an AI provider;
(e) we keep it only for as long as the Customer instructs, and delete it with the employee record or earlier on the Customer's instruction; and
(f) the Customer indemnifies SKAD for any claim, loss or penalty arising from unlawful collection or use of an Aadhaar number, as set out in the Terms of Service.
4.1 From you, when you sign up, use a tool, or contact us.
4.2 From your employer or an HR consultant acting for it, when they add you to their workforce records or invite you to the employee portal.
4.3 From sign-in providers (Google, Microsoft, Facebook) when you choose to sign in with them: your name, email and the provider's account identifier. We do not receive your password.
4.4 From our payment processor: confirmation of payment, plan and invoice details. We never receive or store your full card or bank details.
| Data | Retention | What happens after |
|---|---|---|
| Account data of an active account | While the account is active | See below |
| Account closed by you, or erased through "Erase everything" | Deleted from live systems within 90 days of closure; billing records kept as required by tax law (currently 8 years under the Income-tax Act and the Companies Act) | Backups age out within 14 days of live deletion |
| Inactive accounts | We write to you after 23 months without a sign-in; if there is no sign-in within 30 days after that, the account is treated as closed | As above |
| Workforce records held for a Customer | For as long as the Customer keeps them; when the Customer deletes a person or ends the service, live copies are removed within 30 days | Customer keeps its own statutory copies (see the DPA) |
| Candidate records | Deleted 180 days after last activity unless the Customer converts the candidate to an employee | Automatic purge |
| Clock-in location readings | Coordinates removed after 90 days; the time record stays | Automatic purge |
| Electronic signature evidence | For the life of the signed document held by the Customer, then as above | n/a |
| Policy acceptance records and evidence | Records of which version of each policy you accepted, when, and from which network address, together with the signed evidence chain, are kept for the life of the relationship plus 3 years after the account closes | Deleted |
| AI request logs | We keep a hash and size of each request for metering and abuse prevention, not the content | 12 months |
| Server and security logs | 90 days | Rotated |
| Support enquiries | 24 months after the enquiry is closed | Deleted |
Where a law requires a longer period, that period applies.
5.1 Evidence signing. Acceptance records are hash-chained and signed so that they cannot be altered without detection. The public verification key is published at hrtailor.ai/policies/evidence_key.
We do not sell personal data. We share it only with the following processors, each bound by contract to use it only for the stated purpose.
| Sub-processor | Location | Purpose | Data involved |
|---|---|---|---|
| DigitalOcean LLC | Servers in Bangalore, India | Hosting of the application, database, uploaded files and backups | All categories |
| Cloudflare, Inc. | Global network; data passes through the nearest edge | Content delivery, DDoS and bot protection, TLS | Traffic metadata, page content in transit |
| OpenAI, L.L.C. | United States | AI generation for HR documents, resumes and assistants | The inputs to the tool you use and, for HR OS tools, the workforce fields needed for that task |
| OpenRouter, Inc. (currently switched off; may be enabled for specific free tools) | United States | AI generation through third-party models | Only inputs to free tools for job seekers; never workforce data unless the route is marked no-training |
| Dodo Payments, Inc. | United States, acting as merchant of record | Checkout, invoicing, tax collection, refunds and disputes | Name, email, amount, plan; card details go to Dodo only |
| Zoho Corporation (ZeptoMail) | India | Transactional email | Recipient name and email, and the content of the email including attachments such as payslips or letters sent at a Customer's instruction |
| Google LLC (Maps Platform) | United States and global | Address auto-complete and geocoding when you type a location | The text you type into a location field and coordinates you submit |
| Google LLC (Tag Manager, Analytics), Microsoft Corporation (Clarity), Meta Platforms (Pixel), Google AdSense | United States and global | Analytics and advertising on our public marketing pages only, and only after you allow them in the cookie banner | See the Cookie and Tracking Notice |
| HubSpot, Inc. | United States | Customer relationship records for business customers | Business contact details |
6.1 We may also disclose personal data to a court, regulator or law enforcement body when the law requires it, and to professional advisers under confidentiality.
6.2 If SKAD is acquired or merges with another company, personal data may transfer to the new owner under this policy. We will tell you before that happens.
7.1 Your data is stored in India. Some of the sub-processors in section 6 process personal data outside India. In particular, OpenAI, L.L.C., Dodo Payments, Inc., Cloudflare, Inc. and Google LLC process data in the United States and, through their global networks, in other countries. By accepting this policy you acknowledge these transfers and consent to them. Each transfer is made under a contract that requires the recipient to protect the data to the standard this policy describes.
7.2 Section 16 of the DPDP Act lets the Central Government restrict transfers to named countries. If the Central Government restricts a country in which one of our sub-processors processes personal data, we will suspend the affected sub-processor for that data until the transfer is lawful again or a replacement is in place, and we will tell you. Beyond that, we give no further guarantee about the laws of the countries where sub-processors operate.
7.3 Customers who require workforce data to stay in India can turn off AI features for their company account.
Our Cookie and Tracking Notice explains which cookies and scripts we use, that analytics and advertising scripts are off by default for every visitor and run only on public marketing pages and only after you allow them, and how to change your choice. Logged-in pages that show workforce data carry no advertising or session-recording scripts.
If SKAD is the fiduciary for your data, you can exercise these rights with us directly. If your employer is the fiduciary, send your request to your employer; we will help them respond, and you can copy us so we can make sure it is handled.
| Right | What it means | How | Our timeline |
|---|---|---|---|
| Access | A summary of the personal data we hold about you, what we do with it, and who we have shared it with | "Download my data" in My Account, or write to the Grievance Officer | Within 30 days |
| Correction and updating | Fix inaccurate or incomplete data | Edit in the app, or write to us | Within 15 days |
| Erasure | Delete your personal data where we no longer need it for the purpose or a legal obligation | "Erase everything" in My Account, or write to us | Live deletion within 90 days, subject to section 5 |
| Withdraw consent | Stop processing that relied on your consent, such as marketing, analytics or AI training | Toggle in My Account, unsubscribe link, cookie banner | Immediate for future processing |
| Nominate | Name a person to exercise your rights if you die or cannot act | Write to the Grievance Officer | Recorded within 15 days |
| Grievance | Complain about how we handled your data or your request | Grievance Officer (section 1.2) | Acknowledged in 2 working days, resolved in 30 days |
9.1 If you are not satisfied with our response, you may complain to the Data Protection Board of India in the manner the Board prescribes.
9.2 We may need to verify your identity before acting on a request.
10.1 You can withdraw consent as easily as you gave it. Withdrawing consent does not affect processing done before withdrawal.
10.2 Some processing does not depend on consent. If you withdraw consent for something we need to run your account (for example, storing your email address), we will tell you, and you may need to close the account instead.
10.3 If you are an employee and you object to your employer's processing, raise it with your employer. Some workforce processing is required by employment and tax law and cannot be stopped by withdrawal alone.
11.1 The Service is for adults. When you open an account you declare that you are 18 or older and, if you act for a business, that you have authority to bind it. We rely on that self-declaration only and do not verify age or authority. If we discover that an account holder is under 18 or lacked the authority declared, we terminate the account.
11.2 We do not knowingly process personal data of anyone under 18 as an account holder, and Customers must not add anyone under 18 to their workforce records unless permitted by law and with the consent of a parent or guardian. If you believe we hold data about a minor without such consent, contact the Grievance Officer and we will remove it.
12.1 We use reasonable security safeguards as required by section 8(5) of the DPDP Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. In outline: encryption in transit, encryption of stored credentials and provider keys, tenant isolation checks on every request, signed and expiring download links, role-based access, rate limiting, vulnerability management, daily backups, and logging with personal data removed.
12.2 We restrict staff access to workforce data to what is needed to support you, and staff actions in administrative tools are logged.
12.3 No system is perfectly secure. Section 13 explains what we do if something goes wrong. You are responsible for keeping your password private and for signing out on shared devices.
13.1 If we confirm a personal data breach affecting personal data for which SKAD is the Data Fiduciary, we will notify the Data Protection Board of India and the affected users without undue delay, and we aim to do so within 72 hours of confirming the breach. We notify only on a confirmed breach affecting personal data; suspected incidents that turn out not to involve personal data are not notified.
13.2 Where the breach concerns workforce data, we will notify the affected Customer within 24 hours of confirming the breach so that the Customer, as Data Fiduciary, can meet its own obligations, and we will support the Customer's notification to its employees.
13.3 Our notice will describe what happened, what data was involved, what we have done, and what you can do. A notice is given to inform you and is not an admission of liability by SKAD.
13.4 SKAD bears the cost of the notifications it is itself required to make. The cost of a Customer's own notifications to its employees or to the Board is the Customer's.
14.1 Each version of this policy has a version number and effective date. Old versions are available at hrtailor.ai/policies/history.
14.2 Material changes. We give at least 15 days' notice of a material change by email to your account address and by a notice in the Service before it takes effect. New accounts accept the current version at sign-up by ticking the single acceptance checkbox. Existing account holders accept a material version by a one-time in-app confirmation the next time they sign in after the notice; you may close your account and export your data instead.
14.3 Non-material changes (typographical, clarifying, or required by law) take effect on publication and bind you when you continue to use the Service after the effective date.
15.1 This policy is governed by the laws of India. Disputes are subject to the courts at Mumbai, without prejudice to your right to approach the Data Protection Board or a consumer forum where the law allows.
15.2 If any part of this policy is held unenforceable, the rest continues to apply.
15.3 If this policy and the Terms of Service or the Data Processing Agreement conflict on a data protection matter, this policy and the DPA take precedence.
Change summary (version 3.1): consent at sign-up stated as the fiduciary-side legal basis with section 7 legitimate use as fallback; optional AI-training consent; expanded Aadhaar terms; named cross-border sub-processors and the suspension rule; 72-hour breach target and no-admission wording; acceptance evidence retention and public verification key; self-declared age and authority; 15-day notice and one-time re-acceptance for material changes; processor and fiduciary roles restated; en-US spelling.
Earlier versions are listed on the legal history page.