HRTailor.AI
Start free
Legal

Privacy Policy

Version 3.3 · Effective 30 Sept 2026

HRTailor.AI is operated by SKAD Business Solutions Private Limited ("SKAD", "we", "us"), a company incorporated in India with its registered office at Promenade 3 - 606, 6th Floor, LBS Road, Opp. R City Mall, Ghatkopar (West), Mumbai, Maharashtra 400086, India. CIN U74140MH2021PTC360434.

Version 3.3. Effective from 30 September 2026. Replaces version 3.2 dated 29 September 2026.

This policy is written in plain English. Where it uses a defined term from the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the term has the meaning given in that Act.


1. Who we are and how to reach us

1.1 SKAD is the entity responsible for HRTailor.AI, available at hrtailor.ai and its subdomains, the HRTailor.AI web application, and the related APIs (together, the "Service").

1.2 Grievance Officer (DPDP Act section 13 and the Information Technology Rules): Makarand Gaikwad, Director, SKAD Business Solutions Private Limited. Email: grievance@hrtailor.ai. Postal address: Promenade 3 - 606, 6th Floor, LBS Road, Opp. R City Mall, Ghatkopar (West), Mumbai, Maharashtra 400086, India. Grievances are handled Monday to Friday, 10:00 to 18:00 IST, excluding public holidays in Maharashtra. Email and post are the only channels; we do not take grievances by phone. We acknowledge grievances within 2 working days and resolve them within 30 days, or sooner where the law requires.

1.3 For questions that are not grievances, write to support@hrtailor.ai.

2. Two roles: when we decide and when your employer decides

2.1 SKAD as Data Fiduciary. SKAD is the Data Fiduciary only for the account holder's own account data: the identity, business profile, billing, usage, support and marketing-preference data of the person or business that opens an account with us (employers, HR teams, HR consultants, job seekers), and the data of anonymous visitors who use our free tools. For that data, SKAD decides why and how it is processed, and this policy applies to you directly.

2.2 SKAD as Data Processor. SKAD is the Data Processor for all workforce, candidate and employee data. When an employer, HR team or HR consultant (a "Customer") uploads or invites information about its employees, candidates, contractors or other people (each a "Workforce Data Principal"), the Customer is the Data Fiduciary for that information and SKAD processes it only on the Customer's documented instructions under our Data Processing Agreement. If you are a Workforce Data Principal, your employer is responsible for the lawful basis, the notice you receive, and answering your requests. We help your employer do that, and sections 9 and 10 explain how you can also reach us.

2.3 If you are an HR consultant managing several client companies, each client company is the Data Fiduciary for its own workforce data. You warrant to us that you hold written authority from each client before you add it, and you indemnify SKAD for any claim that you lacked that authority.

3. Personal data we process, why, and on what basis

3.0 Our legal basis. Where SKAD is the Data Fiduciary, the consent you give at sign-up by ticking the acceptance box is the basis for all of our processing of your account data for the purposes in this section. Where the DPDP Act does not require consent, we rely on "legitimate use" under section 7 of the Act as the fallback basis, for example to provide a service you have asked for, to meet a legal obligation, or to respond to a security incident. Where SKAD is the Data Processor, the Customer's documented instructions are the basis, and the Customer is responsible for its own lawful basis.

The table lists every category we process. "Consent" means you gave it through a clear action such as ticking a box or clicking accept. "Legitimate use" refers to the uses section 7 of the DPDP Act permits without separate consent.

Category Examples Purpose Basis (SKAD as fiduciary) Basis (SKAD as processor)
Account identity Name, email, phone, password (hashed), role or persona, country, city Create and secure your account, sign you in, route features to your role Consent at sign-up; section 7 legitimate use as fallback n/a
Business profile Company name, industry, headcount, country, logo, letterhead, signatory Personalize documents, apply the right statutory rules Consent at sign-up; section 7 legitimate use as fallback n/a
Billing Plan, invoice number, amount, currency, subscription status, last four digits of the payment instrument as reported by our payment processor Charge for paid plans, issue receipts, meet tax and accounting law Consent at sign-up; section 7 legitimate use (legal obligation) as fallback n/a
Usage and device IP address (hashed after use for rate limiting), approximate location from IP, browser type, pages used, feature usage, credit balance and consumption Keep the service secure, prevent abuse, meter credits, improve the product Consent at sign-up; section 7 legitimate use (security) as fallback n/a
Tool inputs and outputs Text, files and settings you enter into an AI tool, and the documents produced Generate the document you asked for and let you retrieve it later Consent at sign-up; section 7 legitimate use as fallback Customer instruction
Workforce records Employee name, employee code, work and personal email, phone, job title, department, manager, location, joining date, probation and contract dates, visa expiry, custom fields the Customer defines Run the Customer's HR operations n/a Customer instruction
Gender (optional) Female, male, other, or "prefer not to say", entered only if the Customer or you choose to Used only for statutory calculations that differ by gender, such as the Maharashtra Professional Tax exemption for women Consent at the point of use (the take-home pay calculator); never stored from that tool Customer instruction
Government identifiers PAN, UAN, Emirates ID, passport number, visa details, and Aadhaar number where the Customer needs it for statutory registrations and filings (PF, ESIC, professional tax). Identity numbers are stored encrypted and are visible only to the Customer's owner and admin roles (see section 3.3) Statutory registrations, filings, payroll and identity checks run by the Customer n/a Customer instruction; the Customer must have a lawful basis
Financial Salary, CTC and components, bank account number, IFSC or SWIFT, beneficiary name, payroll runs, payslips, loans, expense claims Payroll and payments run by the Customer n/a Customer instruction
Attendance and location Clock-in and clock-out times, shift, notes, and a single location reading captured only at the moment of clock-in (rounded to about 10 meters) when the Customer enables it Attendance records n/a Customer instruction; the employee sees a notice before the first capture
Leave and wellbeing Leave requests, balances and the reason an employee gives, which may include health information Leave management n/a Customer instruction; health details are processed only because the employee chose to state them
Documents and signatures Offer letters, policies, agreements, uploaded ID copies, drawn or typed signatures, signing time, IP address and browser identifier of the signer Document management and electronic acceptance of documents Consent at sign-up (for your own documents) Customer instruction
Background verification packs, exit interviews, surveys, performance and goals The Customer's templates and the answers people give The Customer's HR processes n/a Customer instruction
Support and enquiries Messages you send us, bug reports, feature requests, attachments Answer you and fix problems Consent at sign-up; section 7 legitimate use as fallback n/a
Marketing preferences Your choice to receive product updates, to allow analytics, and to allow your inputs to be used to improve AI prompts and models Send what you agreed to and nothing else Separate consent, withdrawable at any time n/a

3.1 Special note on AI. When you use an AI feature, the inputs you provide, and where a Customer instructs it, workforce records needed for the task, are sent to an AI provider listed in section 6 to produce the output. We select providers that contractually do not train their models on API inputs for the tools that handle workforce data. Free tools for job seekers may use providers that retain inputs; we tell you this at the point of use and in section 6.

Separately, we may ask whether you allow SKAD to use your tool inputs and outputs to improve our own prompts and AI models. This consent is optional. The box is unticked by default. You can withdraw it at any time from My Account, and withdrawal takes effect for all future use. Giving this consent is never a condition of the free tier or of any plan, and refusing it does not change the features or credits you receive. Workforce data is never used for this purpose without the Customer's separate instruction.

3.2 Sensitive information. We do not ask for and do not need caste, religion, sexual orientation, biometric templates or genetic data. If a Customer or a data principal enters such information into a free-text field, it is processed only as part of that record, under the Customer's responsibility, and is deleted with the record.

3.3 Aadhaar. The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and the regulations under it restrict how private bodies may collect, store and use Aadhaar numbers. For any Aadhaar number entered into the Service:

(a) the employer (the Customer) is the Data Fiduciary and warrants to us that it holds the employee's consent to collect and use the Aadhaar number in the form the Aadhaar Act and the Aadhaar Regulations require;

(b) SKAD is a Data Processor only and does not collect Aadhaar numbers for its own purposes;

(c) the purpose is limited to registrations and filings with the Employees' Provident Fund Organisation, the Employees' State Insurance Corporation, a state professional tax authority, and other statutory registrations and filings that require it;

(d) we store the number encrypted at rest, show it only to the Customer's owner and admin roles, and never send it to an AI provider;

(e) we keep it only for as long as the Customer instructs, and delete it with the employee record or earlier on the Customer's instruction; and

(f) the Customer indemnifies SKAD for any claim, loss or penalty arising from unlawful collection or use of an Aadhaar number, as set out in the Terms of Service.

4. Where the data comes from

4.1 From you, when you sign up, use a tool, or contact us.

4.2 From your employer or an HR consultant acting for it, when they add you to their workforce records or invite you to the employee portal.

4.3 From sign-in providers (Google, Microsoft, Facebook) when you choose to sign in with them: your name, email and the provider's account identifier. We do not receive your password.

4.4 From our payment processor: confirmation of payment, plan and invoice details. We never receive or store your full card or bank details.

5. How long we keep personal data

Data Retention What happens after
Account data of an active account While the account is active See below
Account closed by you, or erased through "Erase everything" Deleted from live systems within 90 days of closure; billing records kept as required by tax law (currently 8 years under the Income-tax Act and the Companies Act) Backups age out within 14 days of live deletion
Inactive accounts We write to you after 23 months without a sign-in; if there is no sign-in within 30 days after that, the account is treated as closed As above
Workforce records held for a Customer For as long as the Customer keeps them; when the Customer deletes a person or ends the service, live copies are removed within 30 days Customer keeps its own statutory copies (see the DPA)
Candidate records Deleted 180 days after last activity unless the Customer converts the candidate to an employee Automatic purge
Clock-in location readings Coordinates removed after 90 days; the time record stays Automatic purge
Electronic signature evidence For the life of the signed document held by the Customer, then as above n/a
Policy acceptance records and evidence Records of which version of each policy you accepted, when, and from which network address, together with the signed evidence chain, are kept for the life of the relationship plus 3 years after the account closes Deleted
AI request logs We keep a hash and size of each request for metering and abuse prevention, not the content 12 months
Server and security logs 90 days Rotated
Support enquiries 24 months after the enquiry is closed Deleted

Where a law requires a longer period, that period applies.

5.1 Evidence signing. Acceptance records are hash-chained and signed so that they cannot be altered without detection. The public verification key is published at hrtailor.ai/policies/evidence_key.

6. Who we share personal data with

We do not sell personal data. We share it only with the following processors, each bound by contract to use it only for the stated purpose.

Sub-processor Location Purpose Data involved
DigitalOcean LLC Servers in Bangalore, India Hosting of the application, database, uploaded files and backups All categories
Cloudflare, Inc. Global network; data passes through the nearest edge Content delivery, DDoS and bot protection, TLS Traffic metadata, page content in transit
OpenAI, L.L.C. United States AI generation for HR documents, resumes and assistants The inputs to the tool you use and, for HR OS tools, the workforce fields needed for that task
Dodo Payments, Inc. United States, acting as merchant of record Checkout, invoicing, tax collection, refunds and disputes Name, email, amount, plan; card details go to Dodo only
Zoho Corporation (ZeptoMail) India Transactional email Recipient name and email, and the content of the email including attachments such as payslips or letters sent at a Customer's instruction
Google LLC (Maps Platform) United States and global Address auto-complete and geocoding when you type a location The text you type into a location field and coordinates you submit
Google LLC (Tag Manager, Analytics), Microsoft Corporation (Clarity), Meta Platforms (Pixel), Google AdSense United States and global Analytics and advertising on our public marketing pages only, and only after you allow them in the cookie banner See the Cookie and Tracking Notice
HubSpot, Inc. United States Customer relationship records for business customers Business contact details

6.1 We may also disclose personal data to a court, regulator or law enforcement body when the law requires it, and to professional advisers under confidentiality.

6.2 If SKAD is acquired or merges with another company, personal data may transfer to the new owner under this policy. We will tell you before that happens.

7. Cross-border transfers

7.1 Your data is stored in India. Some of the sub-processors in section 6 process personal data outside India. In particular, OpenAI, L.L.C., Dodo Payments, Inc., Cloudflare, Inc. and Google LLC process data in the United States and, through their global networks, in other countries. By accepting this policy you acknowledge these transfers and consent to them. Each transfer is made under a contract that requires the recipient to protect the data to the standard this policy describes.

7.2 Section 16 of the DPDP Act lets the Central Government restrict transfers to named countries. If the Central Government restricts a country in which one of our sub-processors processes personal data, we will suspend the affected sub-processor for that data until the transfer is lawful again or a replacement is in place, and we will tell you. Beyond that, we give no further guarantee about the laws of the countries where sub-processors operate.

7.3 Customers who require workforce data to stay in India can turn off AI features for their company account.

8. Cookies and tracking

Our Cookie and Tracking Notice explains which cookies and scripts we use, that analytics and advertising scripts are off by default for every visitor and run only on public marketing pages and only after you allow them, and how to change your choice. Logged-in pages that show workforce data carry no advertising or session-recording scripts.

9. Your rights

If SKAD is the fiduciary for your data, you can exercise these rights with us directly. If your employer is the fiduciary, send your request to your employer; we will help them respond, and you can copy us so we can make sure it is handled.

Right What it means How Our timeline
Access A summary of the personal data we hold about you, what we do with it, and who we have shared it with "Download my data" in My Account, or write to the Grievance Officer Within 30 days
Correction and updating Fix inaccurate or incomplete data Edit in the app, or write to us Within 15 days
Erasure Delete your personal data where we no longer need it for the purpose or a legal obligation "Erase everything" in My Account, or write to us Live deletion within 90 days, subject to section 5
Withdraw consent Stop processing that relied on your consent, such as marketing, analytics or AI training Toggle in My Account, unsubscribe link, cookie banner Immediate for future processing
Nominate Name a person to exercise your rights if you die or cannot act Write to the Grievance Officer Recorded within 15 days
Grievance Complain about how we handled your data or your request Grievance Officer (section 1.2) Acknowledged in 2 working days, resolved in 30 days

9.1 If you are not satisfied with our response, you may complain to the Data Protection Board of India in the manner the Board prescribes.

9.2 We may need to verify your identity before acting on a request.

10. Withdrawing consent and what changes

10.1 You can withdraw consent as easily as you gave it. Withdrawing consent does not affect processing done before withdrawal.

10.2 Some processing does not depend on consent. If you withdraw consent for something we need to run your account (for example, storing your email address), we will tell you, and you may need to close the account instead.

10.3 If you are an employee and you object to your employer's processing, raise it with your employer. Some workforce processing is required by employment and tax law and cannot be stopped by withdrawal alone.

11. Age and authority

11.1 The Service is for adults. When you open an account you declare that you are 18 or older and, if you act for a business, that you have authority to bind it. We rely on that self-declaration only and do not verify age or authority. If we discover that an account holder is under 18 or lacked the authority declared, we terminate the account.

11.2 We do not knowingly process personal data of anyone under 18 as an account holder, and Customers must not add anyone under 18 to their workforce records unless permitted by law and with the consent of a parent or guardian. If you believe we hold data about a minor without such consent, contact the Grievance Officer and we will remove it.

12. How we protect personal data

12.1 We use reasonable security safeguards as required by section 8(5) of the DPDP Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. In outline: encryption in transit, encryption of stored credentials and provider keys, tenant isolation checks on every request, signed and expiring download links, role-based access, rate limiting, vulnerability management, daily backups, and logging with personal data removed.

12.2 We restrict staff access to workforce data to what is needed to support you, and staff actions in administrative tools are logged.

12.3 No system is perfectly secure. Section 13 explains what we do if something goes wrong. You are responsible for keeping your password private and for signing out on shared devices.

13. If a data breach happens

13.1 If we confirm a personal data breach affecting personal data for which SKAD is the Data Fiduciary, we will notify the Data Protection Board of India and the affected users without undue delay, and we aim to do so within 72 hours of confirming the breach. We notify only on a confirmed breach affecting personal data; suspected incidents that turn out not to involve personal data are not notified.

13.2 Where the breach concerns workforce data, we will notify the affected Customer within 24 hours of confirming the breach so that the Customer, as Data Fiduciary, can meet its own obligations, and we will support the Customer's notification to its employees.

13.3 Our notice will describe what happened, what data was involved, what we have done, and what you can do. A notice is given to inform you and is not an admission of liability by SKAD.

13.4 SKAD bears the cost of the notifications it is itself required to make. The cost of a Customer's own notifications to its employees or to the Board is the Customer's.

14. Changes to this policy

14.1 Each version of this policy has a version number and effective date. Old versions are available at hrtailor.ai/policies/history.

14.2 Material changes. We give at least 15 days' notice of a material change by email to your account address and by a notice in the Service before it takes effect. New accounts accept the current version at sign-up by ticking the single acceptance checkbox. Existing account holders accept a material version by a one-time in-app confirmation the next time they sign in after the notice; you may close your account and export your data instead.

14.3 Non-material changes (typographical, clarifying, or required by law) take effect on publication and bind you when you continue to use the Service after the effective date.

15. Other terms

15.1 This policy is governed by the laws of India. Disputes are subject to the courts at Mumbai, without prejudice to your right to approach the Data Protection Board or a consumer forum where the law allows.

15.2 If any part of this policy is held unenforceable, the rest continues to apply.

15.3 If this policy and the Terms of Service or the Data Processing Agreement conflict on a data protection matter, this policy and the DPA take precedence.


Change summary (version 3.3): one row added to the table in section 3 for an optional gender field on employee records and in the take-home pay calculator, used only for statutory calculations that differ by gender (for example the Maharashtra Professional Tax exemption for women). No other change.

Change summary (version 3.2): OpenRouter, Inc. removed from the list of service providers. HRTailor.AI now uses the OpenAI API directly and no longer routes any request through OpenRouter. No other change.

Change summary (version 3.1): consent at sign-up stated as the fiduciary-side legal basis with section 7 legitimate use as fallback; optional AI-training consent; expanded Aadhaar terms; named cross-border sub-processors and the suspension rule; 72-hour breach target and no-admission wording; acceptance evidence retention and public verification key; self-declared age and authority; 15-day notice and one-time re-acceptance for material changes; processor and fiduciary roles restated; en-US spelling.

Earlier versions are listed on the legal history page.