Privacy Policy
This Privacy Policy explains how [LEGAL ENTITY NAME] (“Atllanta”, “we”, “us”, “our”), the operator of the Atllanta Business Operating System available at atllanta.vercel.app and its mobile/installable app (together, the “Platform”), collects, uses, discloses, retains and protects personal data. We are committed to processing personal data in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and applicable rules made thereunder.
Contents
1. Our role & scope
Atllanta is a business software platform used by organisations (“Customers”) to manage hiring, employees, attendance, leave and customer relationships. Under the DPDP Act, roles differ depending on the data:
- Where we act as a Data Processor: For personal data of a Customer’s employees, candidates and contacts that the Customer uploads or generates on the Platform, the Customer is the Data Fiduciary and determines the purposes of processing. We process such data on the Customer’s instructions under our agreement with them. If you are an employee, candidate or contact of a Customer, please direct data requests to that organisation in the first instance; we will assist them.
- Where we act as a Data Fiduciary: For account registration, billing, Platform usage, support and marketing data relating to Customers and their administrators, we determine the purposes and act as the Data Fiduciary.
“Data Principal” means the individual to whom the personal data relates. “Personal data” means any data about an individual who is identifiable by or in relation to such data.
2. Data we collect
2.1 Data you or your organisation provide
- Account & profile: name, work email, phone, password (stored only as a salted hash), role, designation, department, organisation, date of joining.
- Employee & candidate records: profile details, resumes/CVs and extracted text, job applications, interview feedback, documents you upload.
- Attendance data: check-in/out timestamps, and — only where enabled and permitted — a selfie photo and GPS location captured at check-in for verification. This may constitute sensitive personal data and is collected with consent for attendance verification only.
- Leave, HR & CRM data: leave requests and balances, approvals, customer/partner accounts, contacts, leads, deals, visits and calls logged on the Platform.
- Communications: messages you send us for support, and content you submit through forms.
2.2 Data collected automatically
- Usage & device data: log data, IP address, browser/device type, pages viewed, and actions taken, used for security, diagnostics and improving the Platform.
- Cookies & local storage: strictly necessary cookies/tokens to keep you signed in and to operate the installable/offline app. See Cookies.
We do not knowingly collect more personal data than is necessary for the purposes described below.
3. How & why we use data
We use personal data for the following purposes:
- To provide, operate and secure the Platform and its features (recruitment, attendance, leave, CRM, notifications).
- To authenticate users and enforce role- and organisation-based access controls.
- To provide AI-assisted features (e.g. matching a resume to a job description) at the Customer’s instruction.
- To send transactional communications (e.g. approvals, reminders, password resets).
- To provide customer support and respond to requests and grievances.
- To maintain audit logs, prevent fraud/abuse and comply with legal obligations.
- With consent, to send product updates or marketing to Customer administrators (you can opt out anytime).
We do not sell personal data. We do not use employee, candidate or customer data uploaded by a Customer to train our own or third parties’ general-purpose AI models.
4. Consent & lawful basis
Where we act as a Data Fiduciary, we process personal data based on your consent or on certain legitimate uses permitted by the DPDP Act (for example, providing a service you have requested, or for employment-related purposes). Our request for consent is accompanied by a clear notice describing the personal data and purpose. Consent is free, specific, informed, unconditional and unambiguous, and may be withdrawn at any time (see Your rights); withdrawal does not affect processing carried out before withdrawal.
Where we act as a Data Processor, the Customer is responsible for obtaining any consent required from its Data Principals and for issuing lawful instructions to us.
6. Cross-border transfers
Some sub-processors may store or process personal data outside India. Where this occurs, we do so consistent with the DPDP Act (which permits transfer except to territories restricted by the Central Government) and apply appropriate contractual safeguards. We will honour any restrictions notified by the Government from time to time. Your primary application data — the database, authentication and file storage — is hosted in India (Supabase, ap-south-1); only limited processing (AI inference and transactional email) occurs outside India, as listed above.
7. Data retention
We retain personal data only for as long as necessary to fulfil the purposes above, to provide the Platform to the Customer, and to meet legal, accounting or reporting requirements. When a Customer’s account is closed, we delete or de-identify the associated personal data within 90 days, except where retention is required by law. Data Principals may request erasure as described below.
8. Security
We implement reasonable security practices and procedures under the SPDI Rules and the DPDP Act, including:
- Tenant isolation via database Row-Level Security, so each organisation can access only its own data.
- Encryption of data in transit (TLS) and at rest at the infrastructure layer.
- Authentication controls, hashed passwords, role-based access, and audit logging of key actions.
- Least-privilege access to production systems and periodic security review.
No method of transmission or storage is completely secure. In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act.
9. Your rights as a Data Principal
Subject to the DPDP Act, you have the right to:
- Access a summary of the personal data we process about you and the processing activities.
- Correction, completion and updating of your personal data, and erasure where it is no longer necessary for the purpose.
- Withdraw consent at any time, as easily as it was given.
- Grievance redressal — a readily available means to raise grievances (see below).
- Nominate another individual to exercise your rights in the event of death or incapacity.
To exercise these rights, contact us using the details below. If your data is held on behalf of your employer/organisation (Customer), we will refer your request to them or act on their instruction. We may need to verify your identity before acting on a request.
You also have a duty under the DPDP Act not to impersonate another person, suppress material information, or file false or frivolous grievances or requests.
10. Grievance redressal
In accordance with the DPDP Act and the Information Technology Act, 2000, we have appointed a Grievance Officer / Data Protection point of contact to address your concerns:
Grievance Officer: Sachin V Anchan
Email: anchansachinv99@gmail.com
Phone: +91 80731 63762
Address: [REGISTERED ADDRESS]
We will acknowledge grievances promptly and endeavour to resolve them within the timelines prescribed under applicable law (typically within 30 days). If you are not satisfied, you may escalate to the Data Protection Board of India.
11. Children’s data
The Platform is intended for use by businesses and their adult personnel and is not directed at children. We do not knowingly process the personal data of children (individuals under 18) except as permitted by law and with verifiable parental/guardian consent. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified through the Platform or by email, and the “Last updated” date above will change. Your continued use of the Platform after an update constitutes acceptance of the revised policy where permitted by law.
14. Governing law & jurisdiction
This Privacy Policy is governed by the laws of India. Subject to applicable law and the jurisdiction of the Data Protection Board of India, the courts at [CITY, STATE] shall have exclusive jurisdiction over any disputes arising out of or relating to this policy.
15. Contact us
[LEGAL ENTITY NAME] (Atllanta)
Email: anchansachinv99@gmail.com
Phone: +91 80731 63762
Registered address: [REGISTERED ADDRESS]