Legal & Compliance

Privacy Policy & Data Protection

Your privacy is our priority. Learn how Verifitech collects, processes, and protects your personal data in accordance with global data protection regulations.

Last Updated: 19th December 2025
Overview

Introduction

Verifitech Solutions Private Limited ("Verifitech", "we", "our", or "us") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, process, use, disclose, retain, transfer, and protect your personal information when you visit our website, use our services, or interact with us.

Important Notice

By accessing or using our website and services, you agree to the terms of this Privacy Policy. If you do not agree with our policies and practices, please do not use our services or provide us with your personal data.

Scope & Applicability

This Privacy Policy applies to:

Website Visitors

All individuals who visit our website, browse our content, or interact with our online platforms without necessarily creating an account or submitting personal information.

Registered Users

Clients, partners, job applicants, and individuals who register for our services, submit inquiries, or create accounts on our platforms.

Note for Stakeholders: Candidates, employees, clients, and vendors should refer to our separate Stakeholder Privacy Notice for specific processing activities related to background verification services.
Definitions

Key Terms & Definitions

Understanding the terminology used in this Privacy Policy

Applicable Data Protection Law

Any law, regulation, or statute governing the processing of personal data, including but not limited to the Information Technology Act, 2000, GDPR, and other relevant privacy regulations.

Personal Data

Any information relating to an identified or identifiable natural person ("Data Subject"), including name, address, email, phone number, or online identifiers.

Sensitive Personal Data

Personal data revealing racial or ethnic origin, political opinions, religious beliefs, biometric data, health information, or financial account details requiring special protection.

Data Subject / Data Principal

The individual to whom the personal data relates, who can be identified directly or indirectly through the data we process.

Processing

Any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, or erasure.

Data Controller / Fiduciary

The natural or legal person, public authority, agency, or other body which determines the purposes and means of processing personal data.

Consent

Freely given, specific, informed, and unambiguous indication of the data subject's wishes through a statement or clear affirmative action.

Data Processor

A natural or legal person who processes personal data on behalf of the data controller, governed by contractual agreements and data protection obligations.

Personal Data Breach

A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.

Data Collection

What Personal Data We Collect

Categories of information we collect and process

We may collect basic identification details including:

  • Full name, title, and company/organization name
  • Contact information (email address, phone number, postal address)
  • Professional credentials and job titles
  • Account login credentials (username, encrypted password)
  • IP addresses and device identifiers

For job applicants and recruitment processes:

  • Resume/CV content and employment history
  • Educational qualifications and certifications
  • Professional references and background information
  • Interview notes and assessment results
  • Salary expectations and availability

Automatically collected information via cookies and similar technologies:

  • Browser type, version, and operating system
  • Device information and screen resolution
  • Pages visited, time spent, and navigation paths
  • Referral sources and exit pages
  • Server logs and error reports

Preferences and consent records:

  • Newsletter subscription preferences
  • Marketing communication opt-ins/outs
  • Event registration and attendance data
  • Survey responses and feedback
  • Communication history with our team

Important: We do not routinely collect sensitive personal data through our website. Any sensitive data collection occurs only:

  • With your explicit consent
  • When necessary for specific verification services
  • Under separate contractual agreements
  • With enhanced security measures in place
Please do not submit sensitive personal information (such as government ID numbers, financial details, or health information) unless explicitly requested through secure channels.
Data Usage

How We Use Your Personal Data

Purposes and legal bases for processing your information

Purpose Legal Basis Description
Service Delivery Contractual Necessity To provide background verification services, manage accounts, and fulfill our contractual obligations
Legal Compliance Legal Obligation To comply with applicable laws, regulations, court orders, and government requests
Business Operations Legitimate Interest To manage our business operations, improve services, and ensure network security
Marketing Consent To send promotional materials, newsletters, and updates (with your explicit consent)
Communication Legitimate Interest To respond to inquiries, provide customer support, and maintain business relationships
Recruitment Consent / Legitimate Interest To process job applications, conduct interviews, and manage hiring processes
Website Improvement Consent / Legitimate Interest To analyze usage patterns, debug issues, and enhance user experience
Data Sharing

How We Share Your Personal Data

Third parties and circumstances under which data may be disclosed

Group Companies

Personal data may be shared with Verifitech subsidiaries and affiliated entities for operational efficiency and service delivery, all bound by this privacy policy.

Service Providers

Third-party vendors providing IT services, cloud hosting (AWS Mumbai), email services (Gmail Enterprise), and analytics, under strict contractual obligations.

Legal & Regulatory

Disclosure to government authorities, regulatory bodies, or law enforcement when required by law or to protect our legal rights.

Professional Advisors

Legal consultants, auditors, and insurance providers who require access to data for professional services, bound by confidentiality agreements.

(

Business Transfers

In the event of a merger, acquisition, or asset sale, personal data may be transferred as a business asset, with notice to affected individuals.

With Your Consent

We may share data with third parties when you have given explicit consent for specific sharing purposes not covered above.

Security

How We Protect Your Data

We implement robust technical and organizational measures to ensure the security of your personal data:

Certifications & Compliance

ISO/IEC 27001:2022 certified and SOC-2 Type II compliant, ensuring internationally recognized security standards.

Technical Safeguards

Encryption in transit and at rest, secure server infrastructure, firewalls, and regular vulnerability assessments.

Organizational Measures

Strict access controls, employee training, confidentiality agreements, and regular security audits.

Security Highlights

256-bit
Encryption
ISO 27001
Certified
24/7
Monitoring
AWS
Hosting
Retention

Data Retention Period

We retain personal data only as long as necessary for the purposes outlined in this policy

Personal data is retained based on the following criteria:

  • Contractual Period: Duration of our business relationship plus applicable limitation periods for legal claims
  • Legal Obligations: Periods required by tax, employment, or corporate laws (typically 3-7 years)
  • Consent Basis: Until consent is withdrawn or the purpose is fulfilled
  • Legitimate Interests: While the legitimate interest persists and is not overridden by your rights

When personal data is no longer required, we securely delete or anonymize it using industry-standard methods:

  • Cryptographic erasure for encrypted data
  • Secure overwriting of storage media
  • Physical destruction of paper records
  • Anonymization techniques for data analytics
Your Rights

Data Subject Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

Right of Access

Request copies of your personal data and information about how we process it.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data under certain conditions.

Right to Restrict

Request limitation of processing in specific circumstances.

Right to Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests or direct marketing.

Withdraw Consent

Withdraw previously given consent at any time without affecting lawful processing.

Right to Nominate

Nominate another person to exercise rights on your behalf in certain circumstances.

Non-Discrimination Notice

We will not discriminate against you for exercising any of your privacy rights. This includes denying services, charging different prices, or providing a different level of service quality.

Children's Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected personal data from a child without appropriate parental or guardian consent, we will take steps to delete such information promptly.

Parents or guardians who believe their child has provided us with personal data should contact us immediately at privacy@verifitech.com.

Contact Us

Privacy Inquiries & Grievances

If you have questions about this Privacy Policy, wish to exercise your data subject rights, or want to file a privacy complaint, our Data Privacy Team is here to help.

Email
privacy@verifitech.com
Postal Address
Verifitech Solutions Private Limited
Data Privacy Office
[Company Address Line]
[City, State, ZIP]
Response Time
We aim to respond to all privacy-related inquiries within 48 hours.

Exercise Your Privacy Rights

Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make significant changes, we will notify you through our website or via email. We encourage you to review this policy periodically to stay informed about how we protect your information.

Current Version Effective: 19th December 2025