Enterprise Privacy Policy
This document contains legally binding terms governing your rights, remedies, and obligations under Indian Law. Please read all sections and sub-clauses with care.
This Enterprise Privacy Policy ("Privacy Policy", "Policy") governs the privacy practices of RUGABA RAAMATU KYNIGOS SYSTEMS PRIVATE LIMITED (CIN: U74999HR2020PTC085123), operating under the trade style and operating brand Helix Human Capital ("Company", "We", "Us", or "Our").
1. Scope, Purpose & Data Fiduciary Role
1.1 Statutory Role: For the purposes of the Digital Personal Data Protection Act, 2023 of India, RUGABA RAAMATU KYNIGOS SYSTEMS PRIVATE LIMITED operates as a Data Fiduciary with respect to user account data, client corporate contact information, and platform telemetry, and as a Data Processor with respect to Candidate dossiers submitted by third parties.
1.2 Applicability: This Policy applies to all personal data collected through helixhumancapital.com, bearsystems.in, candidate evaluation forms, client dashboards, API integrations, and official corporate communications.
2. Categorization of Collected Data
We collect and process distinct categories of Personal Data necessary for providing high-volume talent sourcing, executive evaluation, and fractional HR consulting services:
- 2.1 Corporate Client Representative Data: Full legal name, corporate designation, business email address, official phone number, company registration details, billing address, tax identification numbers (GSTIN/PAN), and transaction history.
- 2.2 Candidate & Talent Pipeline Data: Full name, contact telephone numbers, primary residential address, email address, complete employment history, curriculum vitae (CV/resume), past salary slips, current Cost-To-Company (CTC) breakdown, expected CTC, notice period duration, professional references, skill evaluation scores, educational diplomas, and interview recordings (where explicit prior consent is granted).
- 2.3 Technical Telemetry & Network Information: Internet Protocol (IP) address, operating system specifications, browser user-agent strings, unique device hardware identifiers, session logs, clickstream sequences, referral URLs, time-zone offsets, and system latency metrics.
- 2.4 Financial & Gateway Transaction Data: Transaction reference IDs, payment gateway transaction status, order numbers, and settlement timestamps processed through Cashfree Payment India Private Limited. We do not store raw credit card numbers or banking PINs.
3. Lawful Grounds & Specific Purposes of Processing
Personal Data is collected and processed strictly under lawful grounds specified under Section 4 and Section 7 of the DPDP Act 2023:
- Execution of Contractual Obligations: Processing Client hiring briefs, generating candidate matches, processing payment transactions via Cashfree, issuing invoices, and managing replacement candidate guarantees.
- Legitimate Uses & Talent Acquisition: Evaluating candidate suitability for client job openings, conducting pre-vetting interviews, verifying employment credentials, and presenting shortlisted dossiers to hiring authorities.
- Legal & Regulatory Compliance: Maintaining corporate audit trails under Indian tax laws, complying with statutory GST filings, responding to court orders, and adhering to CERT-In cybersecurity directives.
- Platform Security & Fraud Prevention: Detecting unauthorized system access, preventing candidate profile scraping, enforcing rate-limiting, and protecting intellectual property.
4. Consent Mechanism & Withdrawal Framework
4.1 Express Consent: Consent for processing personal data is obtained electronically at the point of account registration, brief submission, or candidate application.
4.2 Consent Withdrawal: Data Principals possess the statutory right under the DPDP Act 2023 to withdraw consent for data processing at any time by issuing a formal notice to privacyhhc@helixhumancapital.in. Upon receipt of valid consent withdrawal, processing shall cease within seven (7) business days, save for records required to be retained under mandatory tax, statutory audit, or legal defense obligations.
5. Disclosure & Sharing of Data with Third Parties
We do not sell, monetize, lease, or trade personal data to third-party data brokers or marketing agencies. Data is disclosed strictly to authorized entities under written confidentiality agreements:
- 5.1 Corporate Employer Clients: Candidate profiles and resumes are disclosed exclusively to vetted client organizations who have executed active search briefs for specific roles.
- 5.2 Payment Gateway Partners: Client billing metadata and transaction amounts are securely transmitted to Cashfree Payment India Private Limited for processing payment card, UPI, and net banking orders under PCI-DSS v4.0 standards.
- 5.3 Infrastructure & Cloud Sub-Processors: Data is hosted on enterprise cloud infrastructure (e.g., AWS, Vercel, Cloudflare) operating under strict encryption protocols and contractual data protection addenda.
- 5.4 Law Enforcement & Legal Authorities: Personal data may be disclosed where mandated by applicable Indian laws, court summons, search warrants, or directives issued by competent statutory authorities under the Information Technology Act, 2000.
6. Reserve Bank of India (RBI) Data Localization & Gateway Compliance
In adherence to Reserve Bank of India (RBI) guidelines on Payment System Data Storage:
- All transaction processing logs, settlement data, and payment tokens are stored exclusively within server infrastructure situated inside the territorial boundaries of the Republic of India.
- Card security parameters (such as CVV and card passwords) are handled directly by payment gateway processors compliant with global PCI-DSS standards.
7. Data Security, Technical Safeguards & Encryption Standards
We implement multi-layered administrative, physical, and technical security measures to protect personal data against unauthorized access, loss, destruction, alteration, or disclosure:
- Transport Layer Encryption: All platform data in transit is encrypted using Transport Layer Security (TLS 1.3) with RSA-4096 / ECC certificate chains.
- Storage Encryption: Candidate databases and document stores are encrypted at rest using AES-256 bit encryption keys managed under cloud Key Management Services (KMS).
- Access Control Controls: Strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) enforce least-privilege administrative access to stored candidate dossiers.
8. Cross-Border Transfers & Data Localization
Candidate personal data is primarily processed within India. Where cross-border data transmission occurs (e.g., presenting a candidate to an international client headquarter), such transfer complies strictly with Section 16 of the DPDP Act 2023 and non-blacklisted geographical jurisdiction rules established by the Central Government of India.
9. Data Archiving & Purging Retention Schedules
Personal data is retained only for as long as necessary to fulfill the specific recruitment engagement, or to comply with statutory legal retention periods:
| Data Category | Statutory Retention Period | Purging Action |
|---|---|---|
| Client Billing & Invoices | 7 Years (Statutory Tax Law) | Archived in secure offline cold storage |
| Candidate Sourcing Dossiers | 24 Months from last active update | Permanent erasure or anonymization |
| Server Access & IP Logs | 180 Days (CERT-In Mandate) | Automated log recycling |
10. Statutory Data Principal Rights (DPDP Act 2023)
Under the Digital Personal Data Protection Act, 2023, Data Principals possess the following statutory rights regarding their personal data:
- 10.1 Right to Access Summary: The right to receive a summary of personal data being processed and the identities of all Data Fiduciaries with whom such data has been shared.
- 10.2 Right to Correction & Erasure: The right to request correction of inaccurate or misleading data, updating of incomplete records, or erasure of personal data no longer necessary for the original processing purpose.
- 10.3 Right of Grievance Redressal: The right to readily available means of grievance redressal provided by the Data Fiduciary.
- 10.4 Right to Nominate: The right to nominate an individual who, in the event of death or incapacity of the Data Principal, shall exercise their data rights.
11. Cookies, Tracking & Analytics Policies
We utilize essential session cookies and performance telemetry to maintain security, preserve user dashboard state, and optimize load speeds. Users may disable non-essential cookies via browser settings, though certain interactive portal features may become unavailable.
12. Cyber Security Incident Response (CERT-In Protocol)
In accordance with the Indian Computer Emergency Response Team (CERT-In) Cyber Security Directions, any confirmed cybersecurity incident or data breach impacting platform servers shall be reported to CERT-In within six (6) hours of confirmation, and affected Data Principals shall be notified without undue delay.
13. Protection of Minors
The Platform is designed strictly for commercial enterprise recruitment and adult professional employment. We do not knowingly collect or process personal data of individuals under eighteen (18) years of age.
14. Policy Revisions & Notification
We reserve the right to modify this Privacy Policy at any time. Updated versions shall be published on this page with a revised effective date code. Continued use of the Platform following updates constitutes acceptance of the modified Policy.
15. Data Protection Officer & Grievance Redressal Officer
For any privacy inquiries, data access requests, consent withdrawal notices, or grievances under the DPDP Act 2023, please contact our designated Privacy Compliance Department:
Data Protection Officer (DPO) & Privacy Officer
RUGABA RAAMATU KYNIGOS SYSTEMS PRIVATE LIMITED
Brand Division: Helix Human Capital
Email: privacyhhc@helixhumancapital.in / information@helixhumancapital.in
Address: Gurgaon, Haryana, India
Official Contact Channel: Helix Contact Us Page