Privacy Policy

Version v1.0Effective
Show table of contents

Genesis Technologies Private Limited ("Genesis Technologies", "we", "our", "us") operates aurasync.ai and the AuraSync platform — the Applicant Tracking System (ATS), the Assessment module, and the AI assistants that support them.

This policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and how you can get it deleted. It covers both this website and the AuraSync product.

If you only want the Google section, jump to Google account data.

Who is responsible for your data

AuraSync is a business-to-business platform. That means two different organisations may be responsible for data about you, and which one you contact depends on how your data reached us.

  • When your employer or a prospective employer uses AuraSync, that organisation decides what data is collected and why. Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") they are the Data Fiduciary and Genesis Technologies acts as a Data Processor on their instructions. Requests about your candidate profile, application, or assessment are usually best directed to them, but you can always start with us and we will route it.
  • When you deal with us directly — you browse aurasync.ai, request a demo, apply for a job at Genesis Technologies, or buy a subscription — we are the Data Fiduciary and answer for that data ourselves.
  • We are also an independent Data Fiduciary for platform security, fraud prevention, service improvement, and billing, because those purposes are ours rather than our customers'.

Data we collect on this website

  • Demo and contact requests — your name, work email, company, phone number where you give it, and anything you type into the message field.
  • Job applications to Genesis Technologies — the details and files you submit through the careers pages, including your CV.
  • Payments — subscription purchases are processed by Stripe. Card details go directly to Stripe and never reach our servers; we keep the resulting subscription and invoice records.
  • Cookies and local storage — a strictly necessary session cookie for signed-in areas, and a aurasync-cookie-consent entry in your browser's local storage that remembers your cookie choice so we stop asking. You can change that choice at any time from the cookie banner.
  • Server logs — IP address, user agent, requested URL and timestamp, kept for security and abuse prevention.

We do not sell personal data, and we do not run advertising trackers or cross-site advertising pixels on this website.

What the platform is made of

AuraSync has two products, and they collect different things for different reasons. Which sections below apply to you depends on which one you are dealing with.

  • The ATS — the Applicant Tracking System recruiters work in. It holds job requisitions,

candidate pipelines, correspondence, interviews and offers. This is the only part of the platform that ever connects to a Google account.

  • The Assessment module — the separate service candidates complete an assessment in. It

captures answers, spoken audio, camera signals and integrity checks, and returns scores to the ATS. It has no Google connection of any kind.

Each customer organisation's data is held in its own database, resolved by that organisation's subdomain, so one customer's data is never reachable from another's workspace.

The ATS module

What we collect about recruiters and administrators

Name, username, profile picture, work email, phone number, employer, department, job title and role, country, city, timezone, password hash, OAuth tokens for any mailbox connected, and an audit trail of sign-ins and significant actions.

What we collect about candidates

Name, email, phone, LinkedIn profile URL, work experience, education, projects and skills, uploaded CVs, the jobs applied for, pipeline stage and status history, interview schedules and notes, offer records, assessment scores and job-fit ratings returned by the Assessment module, and email correspondence a recruiter has linked to the candidate.

Where ATS data goes

  • Resume parsing and the resume builder send the text of an uploaded CV — and, on the voice

path, a candidate's recorded audio — to Groq (or OpenAI, where a deployment is configured to use it) for structured extraction, drafting and transcription.

  • Interview question generation, job-description automation and market benchmarking send

role, resume and assessment data to the same providers.

  • Video interviews run through 100ms rooms, which carry live interview audio and video.
  • The connected mailbox and calendar — Google or Microsoft — as described in the next

section.

  • Salesforce and ServiceNow, where a customer uses them, act as sign-on or as a UI host.

The Salesforce AppExchange package renders the ATS in an iframe and does not read, write, or transmit any Salesforce CRM object data.

We maintain an internal register of every one of these flows — which vendor receives what, what triggers it, and where it is processed — so these statements can be checked against the code rather than taken on trust.

AI in the ATS

Where a customer has enabled AI features, we use Groq and OpenAI for specific tasks: resume parsing, resume drafting, speech transcription, interview question generation, job-description summarisation and market benchmarking. These providers act as processors under contract and may not use the data for their own purposes.

We do not use Google as an AI provider. Google account data is excluded from every AI pipeline described here — see the next section.

Google account data (Gmail and Calendar)

Connecting a Google account is entirely optional. AuraSync is fully usable without it — this section applies only if a recruiter chooses to connect their mailbox.

This is an ATS-only feature. The Assessment module has no Google connection, and no data obtained from Google APIs is ever sent to it, to any AI provider, or to any other module.

Why we ask for access

Recruiting happens in email and on calendars. Connecting Google lets AuraSync show candidate correspondence next to the candidate's profile, send recruiter mail from the recruiter's own address rather than a no-reply address, check interviewer availability, and put interviews on the calendar. Without the connection, recruiters have to copy mail between two systems by hand.

Exactly which permissions we request

  • openid, email, profile — to identify the Google account being connected and show which mailbox is in use.
  • https://www.googleapis.com/auth/gmail.readonly — to read messages from the connected mailbox's Inbox and Sent folders so candidate correspondence appears in the ATS.
  • https://www.googleapis.com/auth/gmail.send — to send recruiter mail, interview invitations and offer correspondence from the recruiter's own address.
  • https://www.googleapis.com/auth/calendar.readonly — to check free/busy availability and display the interview calendar.
  • https://www.googleapis.com/auth/calendar.events — to create and update interview events.

We request no other Google scopes.

What we do with Gmail data, and what we store

Gmail messages from the connected mailbox's Inbox and Sent folders are synchronised into the customer's own AuraSync database. For each message we store the subject, body, sender, recipients (including Cc and Bcc), the time it was received, the thread identifier, and which folder it came from.

Each message is then labelled as hiring-related or not. That labelling is deterministic — it matches sender and recipient addresses against candidate records, follows message threads, and looks for recruitment keywords in the subject line. No language model or AI system reads your Gmail content. Gmail data is not used to train, retrain, or improve any AI or machine-learning model, ours or anyone else's.

Messages that are not hiring-related stay in the recruiter's own mailbox view and are not attached to any candidate record.

What we do with Calendar data

Calendar access is used for three things: looking up free/busy windows when scheduling an interview, listing events in the date range the recruiter is viewing so the interview calendar shows real availability, and creating or updating interview events with the chosen attendees.

We do not store the contents of your calendar. Events are fetched from Google when you open a calendar view and rendered in your browser. The only calendar information we retain is what we need to manage interviews we created: the event identifier, the meeting link, and the interview date and time.

How long Google data is kept

  • OAuth tokens are kept for as long as the integration is connected and are deleted the moment it is disconnected.
  • Synchronised Gmail messages are kept while the mailbox is connected. Disconnecting deletes the cached copy of that mailbox's mail from the AuraSync database immediately — it is a cache of your mailbox and is not allowed to outlive the connection it came from. The same purge runs automatically if you switch to a different mailbox without disconnecting first.
  • Interview records created through Calendar follow the customer's normal recruitment retention schedule, since they are hiring records rather than calendar data.
  • Encrypted backups are retained for up to 90 days after deletion from the live system, then expire.

Who can see it

  • The recruiter who connected the mailbox, within their own AuraSync workspace.
  • Other authorised users of that same customer organisation, where the mail has been linked to a candidate they work on.
  • A small number of authorised Genesis Technologies engineering and support staff, only where access is needed to operate the service or resolve a support request, under access controls and logging.

Every AuraSync customer's data lives in a separate database resolved by their own subdomain, so one customer's Google data is never reachable from another customer's workspace.

We do not share Google data with third parties

Data obtained through Google APIs is not sold, rented, or traded. It is not shared with advertisers, data brokers, or AI providers. It is not passed to any third party for that party's own purposes. The only disclosures are to infrastructure providers acting purely as processors under contract (our cloud hosting), and to anyone we are legally compelled to disclose to by a valid legal order.

AuraSync's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How OAuth tokens are protected

  • Access and refresh tokens are encrypted with AES-256-GCM before they are written to the database. The encryption key is held in the platform's secret store, separate from the database, so a database copy on its own does not yield usable tokens.
  • Tokens are never sent to the browser, never written to application logs, and never exposed through any API.
  • The OAuth callback is protected with a signed, time-limited state parameter and is refused over a non-HTTPS connection.
  • If Google refuses a stored grant — because it was revoked, or an administrator withdrew it — the stored credential is discarded rather than retried.

How to disconnect Google

Two routes, and either is enough:

  • In AuraSync — go to Settings → Configurations and press Disconnect on the Google integration. This deletes the stored tokens and purges the cached copy of your mail immediately.
  • In your Google Account — visit myaccount.google.com/permissions and remove AuraSync's access. This revokes the grant at Google's end.

Disconnecting stops all further access. It does not delete interview records or candidate correspondence that has already been attached to a candidate file by a recruiter — to remove those, use the deletion route below.

How to request deletion

Email [email protected] from the address associated with the account, or use Settings → Configurations to disconnect, which deletes the Google data automatically. For a full erasure request covering data beyond the Google integration, see Your rights below. We respond within 30 days.

The Assessment module

Candidates reach the Assessment module from a tokenised invite link sent by the organisation they applied to. That organisation decides that an assessment should happen, sets the criteria, receives the results and makes the hiring decision. AuraSync runs the assessment on their behalf.

What an assessment session collects

  • Name, email and the job applied for — to match the assessment to the application.
  • Answers to the questions — to produce the assessment result.
  • Audio of spoken answers, and the text transcribed from it — to score spoken answers.
  • Video and still images from the camera — to check the assessment is completed fairly.

Whether video is retained depends on the organisation's settings; in some assessments the camera is used for live verification only and nothing is stored.

  • Facial verification data — a mathematical representation of a face, not a photograph — to

confirm the person taking the assessment is the person who was invited.

  • Behavioural and psychometric signals, including response timing and expression cues.
  • Integrity flags raised during the session.
  • Technical information about device, browser and connection, to run the session and

diagnose faults.

Taking part in an assessment, being monitored by camera, and having a face verified are three different things, and a candidate agrees to each separately on the consent screen. Every consent is recorded together with the version of the notice shown at the time, so it is always possible to say what was agreed to and in what words.

Consent can be withdrawn at any time, as easily as it was given. Withdrawing facial verification consent erases the stored facial and audio baselines.

How AI is used, and what it does not do

AI generates questions relevant to the role, transcribes spoken answers, scores answers, and raises integrity flags. It does not make hiring decisions. Scores are advisory indicators — not measurements of worth or ability, and not a medical, psychological or clinical assessment of any kind. A person at the organisation reviews them and decides.

Results can be affected by audio and video quality, accent, connection, device, and by disability or assistive technology. Any candidate may ask for a human to review a score or recommendation, and may challenge it.

An integrity flag is an automated signal, not a finding of misconduct. Flags are raised by ordinary things — someone walking behind the candidate, poor lighting, a dropped connection. A person reviews them, and the candidate is entitled to explain what happened.

Who sees assessment data

Results go to the organisation the candidate applied to. Facial verification data is not shared with that organisation — it exists only to confirm identity during the session. To run the assessment we use service providers for hosting, video, speech-to-text and AI processing; they act on our instructions and may not use the data for their own purposes.

We do not sell assessment data, and we do not use it to train our own AI models.

How long assessment data is kept

  • Facial embeddings — deleted within 90 days of capture by an automated purge, and

immediately on withdrawal of that consent.

  • Answers, transcripts, scores and integrity flags — kept with the application, under the

retention schedule of the organisation the candidate applied to.

  • Recordings — kept with the application where the organisation has recording enabled.

Adjustments

If any part of the assessment format is difficult because of a disability or for any other reason, a candidate can ask for an adjustment. Contact the organisation, or email us and we will pass the request on and record it.

How we use your data

  • To provide the AuraSync platform and the features a customer has enabled.
  • To respond to demo requests, support questions, and sales enquiries.
  • To assess applications for jobs at Genesis Technologies.
  • To bill for subscriptions and keep the financial records the law requires.
  • To keep the platform secure, prevent fraud and abuse, and investigate incidents.
  • To improve the service, using aggregated or de-identified information wherever it will do.

Candidate data is processed through AI inference pipelines for scoring and personality analysis in the Assessment module, and for resume parsing, question generation and text analysis in the ATS. The providers are Groq and OpenAI, engaged under data processing agreements. Google account data is excluded from all of this — see the Google section above.

Who we share data with

  • Amazon Web Services — hosting, storage and backups for both modules.
  • Groq, Inc. and OpenAI, L.L.C. — resume parsing and drafting, speech transcription, question generation, job-description automation and market benchmarking. Google account data is never sent to either.
  • 100ms Inc. — live audio and video for video interviews.
  • Google LLC and Microsoft Corporation — only for the mailbox and calendar a user has chosen to connect, and only for the purposes described in the Google section above.
  • Stripe — payment processing for subscriptions. Card details go directly to Stripe and never reach our servers.
  • Salesforce, Inc. and ServiceNow, Inc. — where a customer uses them for sign-on or as a UI host, in their own instance under their own agreement.
  • Legal and regulatory recipients — where we are required to disclose by law and the request is valid.

Each of these is engaged as a sub-processor under a written contract that imposes obligations no less protective than this policy, and we remain responsible to our customers for their acts and omissions. We give customers at least 30 days' notice before adding or replacing a sub-processor, during which they may object on reasonable data-protection grounds.

We do not sell personal data, and we do not use candidate or Google data to train our own AI models.

Security

  • Passwords are hashed; OAuth tokens and other credentials are encrypted at rest.
  • All traffic uses HTTPS with TLS 1.2 or higher.
  • Each customer's data is isolated in a separate database.
  • Service-to-service calls are authenticated with shared service keys.
  • Production credentials are held in a managed secret store, not in code.
  • Access to production systems is restricted to authorised personnel and is logged.

How long we keep data

  • Active recruiter and administrator accounts — for the subscription term plus 30 days.
  • Candidate application data — the hiring cycle plus one year, unless the customer sets a shorter period.
  • Assessment results and scores — the application plus 90 days.
  • Facial embeddings for identity verification — deleted within 90 days of capture by an automated purge, and immediately if the candidate withdraws that consent.
  • Audit and activity logs — two years.
  • Google and Microsoft mailbox data — see the Google section; deleted on disconnect.
  • Assessment answers, transcripts and integrity flags — kept with the application by the organisation the candidate applied to.
  • Website enquiry and demo records — three years from last contact.
  • Backups — up to 90 days after deletion from the live system.

Your rights

Under the DPDP Act and comparable laws you may:

  • Access a copy of the personal data we hold about you.
  • Correct or complete data that is wrong or out of date.
  • Erase your personal data, subject to records we must keep by law.
  • Nominate someone to exercise your rights if you are unable to.
  • Withdraw consent at any time, as easily as you gave it — including consent for camera monitoring and facial verification.
  • Raise a grievance with our Grievance Officer, and escalate to the Data Protection Board of India if our answer does not satisfy you.

Candidates additionally have the right to know that an application is being processed with AI assistance, to ask for human review of any AI-generated score or recommendation, and to receive a copy of their assessment results.

To exercise any of these, email [email protected]. We acknowledge within 48 hours and respond within 30 days.

Grievance Officer

  • Grievance Officer, Genesis Technologies Private Limited
  • Pune, Maharashtra, India
  • Email: [email protected]

Grievances are acknowledged within 48 hours and answered within 30 days. If our response does not satisfy you, you may escalate to the Data Protection Board of India.

International transfers

Our production infrastructure runs on cloud regions that may be outside India, and connected mailbox providers route data through regions of their own choosing. Where personal data leaves India we rely on contractual safeguards with the receiving provider. We maintain an internal register of every flow that crosses a trust boundary, including which vendor receives it and what triggers it.

Children

AuraSync is a business platform for HR professionals assessing adult candidates. We do not knowingly collect data from anyone under 18. If you believe a child's data has reached us, contact us and we will delete it.

Security incidents

Reportable cyber security incidents are reported to CERT-In within six hours of us becoming aware of them. Where a personal data breach occurs, affected individuals are informed without delay and the Data Protection Board of India is notified within the period the DPDP Act requires. Affected customers are notified within 24 hours so they can meet their own obligations.

Changes to this policy

We may update this policy. Material changes are announced by email to account administrators and in-product notifications, and the effective date at the top of this page is updated. Continued use after a change means you accept the revised policy.

Contact us