Privacy Policy
Candidate / Job Seeker
Airation Softtech Private Limited
Legal Basis & Governance
DPDP Act 2023 (India), IT Act 2000, IT (SPDI) Rules 2011 & GDPR aligned principles.
Data Fiduciary
Airation Softtech Private Limited, 8/4, Sector-4, Jankipuram, Lucknow – 226021, UP, India.
Grievance Contact
Official email: airation.it@gmail.com
Privacy Policy (Candidate / Job Seeker)
Airation Softtech Private Limited · Last updated: 24.03.2026 | Version 1.0
This Privacy Policy ("Privacy Policy") is published by Airation Softtech Private Limited, a company incorporated under the Companies Act, 2013, with its registered office at 8/4, Sector-4, Jankipuram, Lucknow – 226021, Uttar Pradesh, India ("Airation", "we", "us", or "our"). This Privacy Policy governs the collection, use, storage, processing, disclosure, and protection of Personal Data submitted by candidates and job seekers ("you", "your", or "User") who access or use our Platform and Services.
This Privacy Policy is issued in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 ("IT Act"), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and all other applicable Indian laws and regulations governing data privacy and protection.
By registering on the Platform, creating a candidate profile, or otherwise using our Services, you acknowledge that you have read, understood, and unconditionally agree to be bound by this Privacy Policy. If you do not agree with any provision of this Privacy Policy, you must immediately discontinue use of the Platform.
This Privacy Policy must be read in conjunction with our Terms and Conditions, Intellectual Property Policy, Cookie Policy, and any other policies published on the Platform. In the event of any conflict between this Privacy Policy and any other policy with respect to data protection matters, this Privacy Policy shall prevail.
This Privacy Policy is compliant with the Digital Personal Data Protection Act, 2023 (India), the Information Technology Act, 2000, the IT (SPDI) Rules 2011, and applicable provisions of international data protection standards including principles aligned with the GDPR where relevant to cross-border data flows involving Indian citizens.
Contact Information:
Airation Softtech Private Limited
Address: 8/4, Sector-4, Jankipuram, Lucknow – 226021, Uttar Pradesh, India
Email: airation.it@gmail.com
BY ACCESSING OR USING THE PLATFORM AND SERVICES, YOU EXPRESSLY AND FREELY CONSENT TO AIRATION SOFTTECH PRIVATE LIMITED’S COLLECTION, RETENTION, ANALYSIS, PROCESSING, USE, AND DISCLOSURE OF YOUR PERSONAL DATA IN ACCORDANCE WITH THIS PRIVACY POLICY. CONSENT OBTAINED UNDER THIS POLICY IS SPECIFIC, INFORMED, UNCONDITIONAL, AND UNAMBIGUOUS AS REQUIRED UNDER THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023.
1. Definitions and Interpretation
The following terms shall have the meanings set out below and shall apply throughout this Privacy Policy and all related policies of Airation.
| Term | Definition |
|---|---|
| "Personal Data" | Any data about an individual who is identifiable by or in relation to such data, as defined under the Digital Personal Data Protection Act, 2023. This includes name, contact information, professional history, biometric data, financial information, and any other data that can identify you directly or indirectly. |
| "Sensitive Personal Data" | Personal Data pertaining to passwords, financial information (bank accounts, credit/debit cards, UPI IDs), health data, official identifier information (Aadhaar, PAN, Passport), biometric data (selfie/photo for verification), and any other data classified as sensitive under applicable Indian law. |
| "Processing" | Any operation or set of operations performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction. |
| "Data Fiduciary" | Airation Softtech Private Limited, in its capacity as the entity that determines the purpose and means of processing your Personal Data, as defined under the DPDP Act, 2023. |
| "Data Principal" | You, the candidate or job seeker whose Personal Data is being processed by Airation. |
| "Consent Manager" | An entity registered with the Data Protection Board of India enabling you to give, manage, review, and withdraw your consent, as applicable under the DPDP Act, 2023. |
| "Data Processor" | Any third party engaged by Airation to process Personal Data on Airation’s behalf, including cloud infrastructure providers, payment gateways, KYC verification vendors, and analytics partners. |
| "Platform" | The website, mobile application, APIs, and all digital services operated by Airation Softtech Private Limited. |
| "Services" | All services offered by Airation to candidates through the Platform, including job matching, profile management, employer communication, identity verification, and related features. |
| "Cookies" | Small text files placed on your device by the Platform to enable functionality, analytics, and personalization, as further described in Section 11 of this Privacy Policy. |
| "Anonymization" | The irreversible process of altering Personal Data in such a manner that you cannot be identified directly or indirectly, resulting in data that is no longer Personal Data under applicable law. |
| "Pseudonymization" | The processing of Personal Data in such a manner that it can no longer be attributed to a specific individual without the use of additional information, which is kept separately and subject to technical and organizational safeguards. |
2. Objective and Scope of This Policy
Airation is committed to maintaining the highest standards of data privacy and security for all candidates using its Platform. The objective of this Privacy Policy is to:
- Provide you with a clear, transparent, and comprehensive understanding of how your Personal Data is collected, used, stored, and shared by Airation;
- Ensure full compliance with the Digital Personal Data Protection Act, 2023, the IT Act, 2000, and all other applicable Indian data protection legislation;
- Establish your rights as a Data Principal and Airation’s obligations as a Data Fiduciary;
- Describe the technical and organizational safeguards implemented by Airation to protect your Personal Data against loss, misuse, unauthorized access, disclosure, alteration, and destruction;
- Set out the legal bases upon which Airation processes each category of your Personal Data.
This Privacy Policy applies to all Personal Data collected through the Platform, whether submitted during registration, profile creation, job applications, identity verification, payment processing, or any other interaction with the Platform or its features. It applies to candidates accessing the Platform from within India and, where applicable, to candidates accessing the Platform from outside India in connection with job opportunities in India.
3. Categories of Personal Data We Collect
Airation collects Personal Data that is adequate, relevant, and limited to what is strictly necessary for the purposes described in this Privacy Policy (the principle of data minimization). The categories of Personal Data we collect, and the specific details of how we collect, use, process, and retain each category, are set out below.
A. Personal Information
| Category | Details |
|---|---|
| What we collect | Full legal name, personal or professional phone number, email address, current residential or professional location (city/state level), and profile photograph. |
| How we collect it | Directly from you during registration, profile creation, or subsequent updates to your account. |
| How we use it | To create, authenticate, and manage your candidate profile; to enable verified employers to identify and contact you; to personalize your experience on the Platform including job recommendations, notifications, and interface preferences; and to send transactional communications such as application updates, interview scheduling, and account alerts. |
| Why we process it | To perform the contract between you and Airation for the provision of candidate services; to operate the candidate account; and to facilitate the job-seeking process. Phone and email are also used for two-factor authentication and account security. |
| Legal basis | Performance of a contract (Article 6(1)(b) equivalent under DPDP Act, 2023); legitimate interests of Airation in operating a secure and functional recruitment platform. |
| Retention Period | Retained for the full duration of your account lifecycle. Upon account deletion, personal identifiers are purged within 30 days, subject to backup retention schedules not exceeding 90 days. Residual anonymised data may be retained indefinitely for platform analytics. |
B. Professional Information
| Category | Details |
|---|---|
| What we collect | Resume or curriculum vitae (CV) including employment history, job titles, responsibilities, and tenure; professional skills and competencies; educational background including institutions, qualifications, and graduation dates; portfolio links, GitHub profiles, or work samples; professional certifications, licences, and accreditations; career objectives and salary expectations (where voluntarily provided). |
| How we collect it | Directly from you via document upload, manual profile entry, or import from LinkedIn or other integrated third-party professional networks (subject to your authorisation). |
| How we use it | To power Airation’s proprietary AI-assisted job matching and candidate ranking algorithms; to generate personalised job recommendations and recruiter-facing candidate summaries; to enable verified employers to search, filter, and evaluate candidate profiles; to improve the Platform’s recommendation accuracy through behavioural feedback loops; and to provide candidates with career insights and job market analytics. |
| Why we process it | To fulfil the core purpose of the Platform — connecting suitable candidates with relevant employers. Processing is necessary for the performance of the candidate services agreement and constitutes a legitimate interest of the Platform. |
| Legal basis | Performance of a contract; legitimate interests of Airation in providing an effective recruitment platform; your explicit consent where applicable. |
| Retention Period | Retained for the duration of the account lifecycle or until you delete specific content. Following account deletion, professional data is purged within 30 days subject to backup schedules. Aggregated, anonymised insights derived from professional data may be retained indefinitely. |
C. Identity and Verification Data (if applicable)
| Category | Details |
|---|---|
| What we collect | Government-issued identity documents including Aadhaar card, PAN card, Passport, Voter ID, or Driving Licence; a live selfie or facial photograph submitted for biometric liveness verification; background verification data including employment history verification, criminal record checks (where consented to), and educational credential authentication. |
| How we collect it | Directly from you when you opt into identity verification or when verification is required to access certain features. Identity document uploads and selfie/liveness checks are processed through Airation’s authorised KYC verification partner. |
| How we use it | To verify that you are who you claim to be, preventing the creation of fraudulent or impersonation profiles; to maintain platform integrity and trust; to comply with applicable regulatory obligations; and to enable features that require verified status, such as premium job applications or salary disclosure. |
| Why we process it | Fraud prevention and platform security constitute legitimate interests of Airation. Processing of government-issued ID and biometric data for identity verification purposes is subject to your explicit prior consent, which may be withdrawn at any time (with the consequence that verified status will be revoked). |
| Legal basis | Explicit consent of the Data Principal for Sensitive Personal Data; legitimate interests (fraud prevention); compliance with applicable regulatory requirements. |
| Retention Period | Identity documents and selfie data are retained for the duration of account activity and for a further period of up to 5 (five) years as required by KYC regulations and applicable financial crime prevention obligations. Background verification reports are retained for up to 3 years. |
Identity documents (Aadhaar, PAN, Passport) and biometric data (selfie/liveness photos) constitute Sensitive Personal Data under the IT (SPDI) Rules, 2011, and Sensitive Data under the DPDP Act, 2023. This data is processed only with your explicit, freely given, informed, and specific consent. You may withdraw consent at any time by contacting airation.it@gmail.com, which will result in the revocation of your verified status on the Platform.
D. Payment Information (if applicable)
| Category | Details |
|---|---|
| What we collect | UPI ID or VPA (Virtual Payment Address); transaction reference numbers and transaction history for premium subscriptions or paid services; billing name, billing address, and GST number (if applicable); bank account details where required for candidate payouts or refunds. Airation does NOT store full debit/credit card numbers, CVV/CVC codes, or net banking passwords. |
| How we collect it | Collected at the time of initiating a payment transaction through the Platform’s integrated payment interface. Full card details are transmitted directly to Airation’s PCI-DSS compliant third-party payment gateway and are never stored on Airation’s servers. |
| How we use it | To process payments for premium subscriptions, job application boosts, or other paid features; to generate transaction receipts and invoices; to manage subscription renewals and cancellations; to process refunds in accordance with Airation’s Refund Policy; and to comply with financial and tax record-keeping obligations. |
| Why we process it | Processing is necessary for the performance of a contract for paid services. Tax and financial record-keeping processing is required by law under the Income Tax Act, 1961, and GST law. |
| Legal basis | Performance of a contract; compliance with financial, taxation, and accounting legal obligations. |
| Retention Period | Transaction records and billing details are retained for a minimum of 8 (eight) years as required under the Companies Act, 2013, the Income Tax Act, 1961, and GST legislation. Payment instrument details (UPI ID, bank account) are retained only for as long as needed for the purpose of the transaction and refund window. |
E. Device and Usage Data
| Category | Details |
|---|---|
| What we collect | IP address, approximate geolocation derived from IP (city/region level), device type (mobile/desktop/tablet), operating system, browser type and version, device identifiers (where applicable and consented to); platform behavioural data including pages visited, job listings viewed, searches conducted, swipe actions, application submissions, session duration, click-through patterns, and feature interactions. |
| How we collect it | Automatically collected through server logs, cookies, web beacons, pixel tags, software development kits (SDKs), and similar tracking technologies when you access and use the Platform. See Section 11 (Cookies and Tracking Technologies) for further details. |
| How we use it | To ensure the technical operation, stability, and performance of the Platform; to diagnose bugs, errors, and security incidents; to analyse aggregate usage patterns for product improvement; to deliver personalised content including job recommendations and UI preferences; to detect anomalous behaviour indicative of fraud, account compromise, or bot activity; and to measure the performance of marketing and recruitment campaigns. |
| Why we process it | Legitimate interests of Airation in operating a secure, functional, and optimised digital platform. Where processing involves targeted analytics or profiling, Airation relies on your consent obtained via the Cookie Consent mechanism. |
| Legal basis | Legitimate interests; consent (for non-essential cookies and profiling analytics). |
| Retention Period | Raw server logs are retained for 90 days. Aggregated, anonymised usage analytics are retained indefinitely. Cookie-derived data is retained in accordance with individual cookie lifespans disclosed in the Cookie Policy. |
F. Communications Data
| Category | Details |
|---|---|
| What we collect | Messages sent between candidates and employers through the Platform’s in-app messaging system; emails and support tickets submitted to Airation’s customer support team; feedback, ratings, or reviews submitted through the Platform; responses to surveys or research studies (where you voluntarily participate). |
| How we collect it | Directly from you when you initiate or respond to communications through the Platform’s communication features. |
| How we use it | To facilitate communication between candidates and employers; to provide customer support and resolve disputes; to improve the quality and safety of the Platform; to detect and prevent abuse, harassment, or policy violations; and to conduct research to enhance Services. |
| Why we process it | Legitimate interests of Airation in maintaining a safe, functional communication environment; performance of a support contract; legal obligations to retain records of certain communications. |
| Legal basis | Legitimate interests; performance of a contract; legal obligation. |
| Retention Period | In-app messages are retained for 2 (two) years or until account deletion. Support communications are retained for 3 (three) years. Survey responses are retained in anonymised form indefinitely. |
4. Legal Bases for Processing Personal Data
Airation processes your Personal Data only where a valid legal basis exists under applicable Indian law, including the DPDP Act, 2023. The primary legal bases relied upon by Airation are:
Consent: Where you have given free, specific, informed, unconditional, and unambiguous consent to the processing of your Personal Data for a stated purpose. You may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal, but may limit your ability to use certain features of the Platform.
Performance of a Contract: Where processing is necessary to perform the candidate services agreement between you and Airation, including account creation, job matching, profile management, and payment processing for premium services.
Legitimate Interests: Where processing is necessary for Airation’s legitimate business interests, provided such interests are not overridden by your fundamental rights and freedoms. Legitimate interests relied upon include platform security, fraud prevention, product improvement, and analytics. Where Airation relies on legitimate interests, a Legitimate Interests Assessment (LIA) has been conducted.
Legal Obligation: Where processing is necessary to comply with a legal obligation under Indian law, including tax record retention, KYC compliance, compliance with court orders, and reporting obligations to regulatory authorities.
Vital Interests: In exceptional circumstances, Airation may process Personal Data to protect the vital interests of you or another natural person, including in life-threatening situations or emergencies.
5. How We Use Your Personal Data
In addition to the specific uses described for each data category in Section 3, Airation uses Personal Data collected from candidates for the following overarching purposes:
Job Matching and Personalised Recommendations: Airation’s proprietary AI-based matching engine analyses your professional profile, skills, experience, location preferences, and behavioural signals to generate ranked lists of relevant job opportunities. The matching algorithm uses statistical and machine-learning models trained on historical recruitment outcomes on the Platform. Candidates may opt out of algorithmic profiling for job matching by contacting airation.it@gmail.com, though this will significantly reduce the relevance of job recommendations.
Identity Verification and Platform Integrity: Verification data is used to authenticate your identity, assign verified status to your profile, and present you as a trustworthy candidate to employers. Verified profiles receive higher visibility in employer search results. Verification also serves to prevent the creation of fake profiles, fraudulent job applications, and impersonation of other candidates.
Employer Communication and Recruitment Facilitation: Your profile data is made available to verified employers in accordance with your visibility settings. Employer-initiated contact through the Platform’s messaging system is facilitated using your registered contact details. Airation does not share your direct contact details with employers without your consent unless you have set your profile to ‘fully visible’.
Payment and Subscription Management: Financial data is used to process payments for premium features, issue invoices, manage subscription renewals, and process refunds. Payment data is transmitted to Airation’s PCI-DSS compliant payment gateway and is never stored in plain text on Airation’s servers.
Platform Security and Fraud Prevention: Device and usage data is continuously analysed by Airation’s AI-powered security systems to detect anomalous access patterns, credential stuffing attacks, account takeover attempts, and other forms of fraud. Suspicious accounts may be temporarily suspended pending investigation.
Legal Compliance and Regulatory Reporting: Airation processes certain Personal Data to comply with its obligations under applicable Indian law, including the DPDP Act, 2023, the IT Act, 2000, the Income Tax Act, 1961, GST laws, and any order or direction issued by a competent court or regulatory authority.
Research, Analytics, and Service Improvement: Anonymised and aggregated data derived from candidate interactions is used to improve the Platform’s features, fix technical issues, conduct market research, and develop new services. No individual candidate is identifiable from such aggregated data.
6. Automated Decision-Making and Profiling
Airation uses automated processing, including machine-learning-based profiling, to facilitate job matching and candidate ranking. This involves creating a candidate ‘match score’ that determines the order in which your profile appears in employer search results and the job recommendations you receive.
Airation acknowledges that automated decision-making may have a significant impact on your employment opportunities on the Platform. Accordingly, Airation provides the following safeguards:
- You have the right to request human review of any automated decision that significantly affects you, including removal of your profile from employer search results or suspension of your account;
- You may contact airation.it@gmail.com to request an explanation of the logic underlying the matching score assigned to your profile;
- You may opt out of algorithmic profiling at any time, though this will affect the personalisation of your experience on the Platform;
- Automated decisions relating to account suspension for fraud are subject to a manual review process triggered by your appeal within 7 (seven) days of notification.
7. Profile Visibility and Data Control
7.1 Visibility Settings
Airation provides candidates with granular controls over the visibility of their profile and the specific data elements within it. The default visibility settings and available options are as follows:
- Profile Visibility: Your profile is, by default, visible only to employers who are registered and verified on the Platform. You may set your profile to ‘Private’ (visible to no employers), ‘Verified Employers Only’ (default), or ‘Public’ (visible to all registered employers).
- Contact Information: Your phone number and email address are masked by default and revealed to employers only when you explicitly choose to share them or accept an employer’s contact request.
- Salary Expectations: Salary data, if provided, is visible only to employers you have directly applied to, unless you change this setting.
- Identity Verification Status: Your verified badge is visible to all employers who view your profile, but the underlying verification documents are never shared with employers.
7.2 Your Data Control Rights
You retain full and continuous control over your Personal Data on the Platform. You may, at any time, exercise the following rights:
- Edit or update your profile, professional information, or account settings through the Platform’s account management interface;
- Delete specific data elements, documents, or your entire profile and account through the Platform’s settings;
- Request a machine-readable export of all Personal Data held by Airation in relation to your account (data portability);
- Withdraw consent to any processing for which consent was the legal basis, with immediate effect;
- Object to processing based on legitimate interests, including profiling for job recommendations.
To exercise any of the above rights, submit a request to airation.it@gmail.com with the subject line ‘Data Rights Request – [Your Full Name]’. Airation will acknowledge your request within 72 hours and respond substantively within 15 (fifteen) business days, subject to verification of your identity.
8. Payments, Financial Data, and Refunds
All payment transactions on the Platform are processed exclusively through Airation’s authorised third-party payment gateway partners, which are certified to the Payment Card Industry Data Security Standard (PCI-DSS). Airation does not process, store, or have access to your full debit or credit card number, CVV/CVC code, net banking credentials, or UPI PIN.
When you initiate a payment, your payment instrument details are transmitted directly to the payment gateway using Transport Layer Security (TLS) encryption. Airation receives only a tokenised transaction reference and the transaction status (success/failure), which are stored in Airation’s encrypted financial records.
Transactions on the Platform may include:
- Premium subscription plans for candidates (e.g., enhanced profile visibility, priority applications, career coaching access);
- One-time purchases of job application credits or value-added services;
- Refundable deposits for certain assessment or verification services.
Refunds, where applicable, are processed in accordance with Airation’s Refund Policy as published on the Platform. Refund requests must be submitted within the period specified in the Refund Policy and will be credited to the original payment instrument within 7 to 10 business days of approval.
Airation’s payment infrastructure is integrated exclusively with PCI-DSS Level 1 certified payment gateways. Card data is never transmitted to or stored on Airation’s servers. All payment API communications use TLS 1.2 or higher encryption.
9. Identity Verification and Document Security
9.1 Document Handling
All identity documents submitted by candidates for KYC or verification purposes are treated as Sensitive Personal Data and are subject to the highest level of security controls applied by Airation. Specifically:
- Identity documents are transmitted to Airation’s KYC verification partner using AES-256 encrypted channels;
- Documents are stored in encrypted form on secure cloud infrastructure with access controls that restrict access to authorised personnel only;
- Identity documents are never displayed to, shared with, or downloadable by employers, recruiters, or any other third party without your explicit written consent;
- Airation’s KYC partners are bound by contractual data processing agreements requiring equivalent security standards and prohibiting secondary use of your documents;
- Physical access to servers hosting identity document data is restricted to authorised personnel and subject to multi-factor authentication.
9.2 Biometric Data
Selfie photographs and liveness check data submitted for verification purposes are classified as biometric Personal Data and constitute Sensitive Personal Data under applicable Indian law. Such data is:
- Processed solely for the purpose of confirming your identity at the time of verification;
- Not used for facial recognition, continuous monitoring, or any other purpose beyond one-time liveness verification;
- Deleted from the KYC partner’s active systems within 30 days of completed verification, with only the verification result (pass/fail) and a reference token retained by Airation;
- Subject to your explicit consent, which may be withdrawn at any time resulting in revocation of verified status.
10. Sharing, Disclosure, and Transfer of Personal Data
10.1 Sharing with Verified Employers
Your candidate profile information is made available to employers who are registered on the Platform and have passed Airation’s employer verification process. The specific data elements shared with employers depend on your visibility settings, as described in Section 7. Airation does not share your Sensitive Personal Data, identity documents, or financial information with employers.
10.2 Sharing with Data Processors
Airation engages the following categories of third-party Data Processors who may access certain elements of your Personal Data on Airation’s behalf, strictly for the purposes described in this Privacy Policy:
- Cloud Infrastructure Providers: Hosting, storage, and computing infrastructure providers (e.g., AWS, Google Cloud, or equivalent) for storing and processing Platform data;
- Payment Gateway Partners: PCI-DSS certified payment processors for handling transaction data;
- KYC and Verification Partners: Authorised identity verification vendors for processing government ID documents and liveness checks;
- Communication Service Providers: Email, SMS, and push notification service providers for delivering transactional and marketing communications;
- Analytics Partners: Privacy-compliant analytics tools for analysing Platform usage in anonymised or pseudonymised form;
- AI and Machine Learning Infrastructure: Third-party ML platforms used in the development and operation of Airation’s job matching algorithms, subject to strict data anonymisation requirements.
All Data Processors are bound by Data Processing Agreements (DPAs) that impose obligations equivalent to or stricter than those applicable to Airation under the DPDP Act, 2023. Airation remains responsible for ensuring that its Data Processors comply with these obligations.
10.3 Disclosure to Legal Authorities
Airation may disclose your Personal Data to law enforcement agencies, regulatory authorities, courts, or government bodies in the following circumstances:
- Where required to do so by a valid court order, statutory obligation, or lawful direction issued by a competent authority under Indian law;
- Where necessary to investigate, prevent, or take action against suspected fraud, cyber crime, or other illegal activity involving the Platform;
- Where necessary to protect the rights, property, or safety of Airation, its employees, its Users, or the public;
- In connection with any legal proceedings, investigation, or regulatory enquiry to which Airation is a party or subject.
Airation will, to the extent permitted by law, notify you of any such disclosure before it is made or as promptly thereafter as circumstances permit.
10.4 Cross-Border Data Transfers
Airation primarily stores and processes your Personal Data within India. To the extent that any Personal Data is transferred to servers or processors located outside India (for example, in connection with the use of internationally hosted cloud services or analytics platforms), Airation shall ensure that such transfers are effected in accordance with the provisions of the DPDP Act, 2023 and any rules or notifications issued by the Central Government specifying approved jurisdictions for cross-border data transfers.
Airation implements appropriate safeguards for cross-border transfers, including standard contractual clauses, adequacy determinations, or binding corporate rules, as applicable. Users may request information about cross-border transfer safeguards by contacting airation.it@gmail.com.
10.5 No Sale of Personal Data
Airation does not sell, rent, or otherwise commercially exploit your Personal Data to third parties. Personal Data is shared only as described in this Section and only to the extent necessary for the stated purposes.
11. Cookies and Tracking Technologies
11.1 Types of Cookies Used
When you access the Platform, Airation and its authorised third-party partners may place the following categories of cookies and similar tracking technologies on your device:
- Strictly Necessary Cookies: Essential for the operation of the Platform, including session management, authentication, and security tokens. These cannot be disabled without rendering the Platform non-functional.
- Performance and Analytics Cookies: Used to collect information about how you interact with the Platform, including pages visited, errors encountered, and session duration, for the purpose of improving Platform performance.
- Functional Cookies: Used to remember your preferences (such as language, location, and display settings) to provide a personalised experience.
- Targeting and Marketing Cookies: Used by Airation and its advertising partners to deliver relevant job advertisements and content based on your browsing behaviour, both on and off the Platform. These are subject to your prior consent.
11.2 Cookie Consent and Control
Upon first accessing the Platform, you will be presented with a Cookie Consent Banner that allows you to accept, reject, or customise your cookie preferences by category. Your consent is recorded and time stamped. Strictly Necessary Cookies are applied without requiring your consent, as they are essential for the Platform to function.
You may change your cookie preferences at any time through the ‘Cookie Settings’ option in the Platform’s footer or account settings. You may also control or delete cookies directly through your browser settings; however, disabling certain cookies may impair the functionality of the Platform.
11.3 Do Not Track
The Platform does not currently respond to browser ‘Do Not Track’ (DNT) signals. Airation is monitoring developments in DNT standards and will update this policy if a widely accepted standard is implemented.
11.4 Third-Party Tracking
Third-party services integrated into the Platform (such as analytics providers and social login providers) may set their own cookies subject to their own privacy policies. Airation does not control third-party cookies and encourages you to review the privacy policies of any third-party service you interact with through the Platform.
12. Safety, Fraud Prevention, and Platform Integrity
Airation is committed to maintaining a safe, trustworthy, and fraud-free environment for candidates. The following technical and procedural safeguards are in place:
- AI-Based Anomaly Detection: Airation’s security system continuously monitors login patterns, application submission rates, and behavioural signals to detect accounts exhibiting bot-like or fraudulent behaviour. Detected anomalies trigger automated temporary holds pending manual security review.
- Fake Job Post Filtering: All employer job postings are subject to automated content analysis and manual spot-checks to identify and remove fake, misleading, or exploitative job advertisements before they reach candidates.
- Report and Block System: Candidates may report suspicious employers, job postings, or communications directly through the Platform interface. Reports are reviewed by Airation’s Trust and Safety team within 48 hours.
- Employer Verification: All employers are required to complete Airation’s employer verification process before being permitted to contact candidates or access full candidate profiles. Unverified employers have restricted access to candidate data.
- Phishing and Impersonation Monitoring: Airation monitors for external websites, social media accounts, or email campaigns that impersonate Airation or the Platform and takes takedown action where possible.
13. Data Retention and Erasure
13.1 General Retention Principles
Airation retains Personal Data only for as long as is necessary to fulfil the purpose for which it was collected, or as required by applicable law. Airation’s data retention framework is based on the following principles:
- Data minimisation: only data that is necessary is collected and retained;
- Purpose limitation: data is retained only for the period required to fulfil the original purpose of collection;
- Legal compliance: retention periods are extended where required by law (e.g., financial records, KYC documents);
- Security during retention: all retained data is subject to the same security controls as active data.
13.2 Specific Retention Periods
The following retention schedule applies to the categories of Personal Data processed by Airation:
- Personal and professional profile data: Duration of account activity + 30 days post-deletion;
- Identity and KYC documents: Up to 5 years from account closure, as required by applicable KYC regulations;
- Payment and transaction records: Minimum 8 years as required by the Companies Act, 2013, Income Tax Act, 1961, and GST laws;
- Communications data (in-app messages): 2 years from creation or account deletion, whichever is earlier;
- Support communications: 3 years from the date of the last communication;
- Device and usage logs: 90 days (raw logs); indefinitely (anonymised aggregates);
- Backup and archival copies: Purged within 90 days of the deletion of the primary data.
13.3 Account Deletion and Erasure Requests
You may request deletion of your account and associated Personal Data at any time by submitting a request to airation.it@gmail.com or through the account deletion function in the Platform’s settings. Airation will process your deletion request within 30 (thirty) days, subject to the following qualifications:
- Airation may retain Personal Data that is required to be retained under applicable law notwithstanding your erasure request;
- Anonymised or de-identified data derived from your account may be retained indefinitely, as it no longer constitutes Personal Data;
- Airation may retain data necessary to defend against legal claims, resolve disputes, or comply with ongoing regulatory obligations;
- Upon completion of the erasure process, Airation will provide written confirmation that your Personal Data has been deleted.
14. Your Rights as a Data Principal under the DPDP Act, 2023
As a Data Principal under the Digital Personal Data Protection Act, 2023, you are entitled to the following rights with respect to your Personal Data processed by Airation. These rights are in addition to any other rights you may have under applicable Indian law.
Right of Access (Section 11, DPDP Act): You have the right to obtain a summary of the Personal Data held by Airation about you, the purposes for which it is being processed, and a list of all Data Processors and third parties with whom your Personal Data has been shared.
Right to Correction and Erasure (Section 12, DPDP Act): You have the right to correct inaccurate, incomplete, or outdated Personal Data and to request erasure of Personal Data that is no longer necessary for the purpose for which it was collected.
Right to Grievance Redressal (Section 13, DPDP Act): You have the right to have your grievances about the processing of your Personal Data addressed by Airation’s designated Grievance Officer within the timeframes specified by law.
Right to Nominate (Section 14, DPDP Act): You have the right to nominate another individual to exercise your data protection rights on your behalf in the event of your death or incapacity.
Right to Withdraw Consent: You may withdraw consent for any processing for which consent was the legal basis at any time. Withdrawal of consent does not affect the lawfulness of processing that occurred prior to withdrawal.
Right to Data Portability: You have the right to receive your Personal Data in a structured, commonly used, and machine-readable format and to transmit that data to another service provider, to the extent technically feasible.
To exercise any of the above rights, submit a written request to airation.it@gmail.com with the subject line ‘DPDP Rights Request’ accompanied by adequate identity verification. Airation will acknowledge your request within 72 hours and respond within 15 (fifteen) business days. Requests that are manifestly unfounded or excessive may be subject to an administrative fee not exceeding a reasonable amount as prescribed by applicable regulations.
If you are not satisfied with Airation’s response to your rights request or grievance, you have the right to escalate your complaint to the Data Protection Board of India, once constituted under the Digital Personal Data Protection Act, 2023.
15. Technical and Organisational Security Measures
15.1 Technical Controls
Airation implements the following technical security measures to protect your Personal Data against unauthorised access, disclosure, alteration, loss, or destruction:
- Encryption in Transit: All communications between your device and Airation’s servers are encrypted using Transport Layer Security (TLS 1.2 or higher). HTTPS is enforced across all Platform endpoints.
- Encryption at Rest: Personal Data stored on Airation’s databases and cloud infrastructure is encrypted at rest using AES-256 encryption. Sensitive Personal Data (identity documents, biometric data, financial records) is subject to additional field-level encryption.
- Access Control: Role-based access control (RBAC) restricts access to Personal Data to authorised personnel only, on a strict need-to-know basis. All access to sensitive databases is logged and audited.
- Multi-Factor Authentication (MFA): All administrative accounts and privileged access to production systems require MFA. Candidate accounts are offered optional MFA for enhanced account security.
- Penetration Testing and Vulnerability Assessments: Airation conducts regular third-party penetration tests and internal vulnerability assessments of its systems, networks, and application code to identify and remediate security weaknesses.
- Intrusion Detection and Prevention: Airation deploys network-level and application-level intrusion detection and prevention systems (IDS/IPS) to monitor for and respond to suspicious activity in real time.
- Data Masking and Tokenisation: Contact details (phone numbers, email addresses) are masked in employer-facing interfaces and tokenised in Airation’s internal systems to reduce the risk of exposure in the event of a security incident.
15.2 Organisational Controls
Airation implements the following organisational measures to support the security of Personal Data:
- Data Protection Training: All Airation employees with access to Personal Data receive mandatory data protection and security awareness training on an annual basis;
- Data Processing Agreements: All third-party Data Processors are required to execute Data Processing Agreements (DPAs) that impose equivalent security obligations;
- Internal Data Protection Policy: Airation maintains an internal Data Protection Policy governing the handling of Personal Data by its employees and contractors;
- Incident Response Plan: Airation maintains a documented Data Breach Incident Response Plan specifying procedures for detection, containment, assessment, notification, and remediation of data security incidents;
- Data Protection Officer: Airation has designated a Data Protection Point of Contact responsible for overseeing compliance with this Privacy Policy and applicable data protection law.
15.3 Security Incident Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, Airation will notify you and the Data Protection Board of India (once constituted) in accordance with the timelines and procedures prescribed under the DPDP Act, 2023 and the IT Act, 2000. Notification will include the nature of the breach, the categories and approximate number of individuals affected, the likely consequences of the breach, and the measures taken or proposed to address the breach.
Notwithstanding the security measures described above, no system of data transmission or storage can be guaranteed to be 100% secure. Airation cannot guarantee the absolute security of your Personal Data against all threats. You are advised to use strong, unique passwords for your Airation account and to enable MFA where available.
16. Children’s Data
The Platform and all Services offered by Airation are intended solely for individuals who are 18 (eighteen) years of age or older. Airation does not knowingly collect, solicit, process, or retain any Personal Data from individuals under the age of 18. The DPDP Act, 2023 imposes additional obligations on the processing of data of children (defined as individuals under the age of 18), including the requirement to obtain verifiable parental consent.
If Airation becomes aware that it has inadvertently collected Personal Data from a person under the age of 18 without verifiable parental consent, it will take immediate steps to delete such data from its systems. If you believe that Airation may have collected Personal Data from a minor, please contact airation.it@gmail.com immediately.
17. Updates to This Privacy Policy
Airation reserves the right to update, modify, or replace this Privacy Policy at any time to reflect changes in applicable law, Platform features, data processing practices, or business operations. The updated Privacy Policy will be published on the Platform with the revised effective date.
Where changes are material (i.e., where they significantly affect your rights, the purposes for which your data is processed, or the parties with whom your data is shared), Airation will provide advance notice of at least 14 (fourteen) days through a prominent in-Platform notification and, where possible, by email to your registered address.
Your continued use of the Platform following the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms. If you do not agree with the updated Privacy Policy, you must cease using the Platform and may request deletion of your account and Personal Data in accordance with Section 13.3.
18. Grievance Officer and Contact Information
For any questions, concerns, complaints, or requests relating to this Privacy Policy or the processing of your Personal Data by Airation, you may contact Airation’s designated Grievance Officer at the following coordinates:
Grievance Officer
Airation Softtech Private Limited
Email: airation.it@gmail.com
Address: 8/4, Sector-4, Jankipuram, Lucknow – 226021, Uttar Pradesh, India
Airation’s Grievance Officer will acknowledge all complaints and requests within 72 hours of receipt and provide a substantive response within 15 (fifteen) business days, in accordance with the requirements of the Digital Personal Data Protection Act, 2023, and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
the requirements of the Digital Personal Data Protection Act, 2023, and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.