Privacy Policy
Please review the following agreement carefully.
Effective Date: 14 June 2026
Data Controller: Kunwar Shatrujit Singh (Sole Proprietorship trading as Airborne HRS)
Address: 37A/13, Defence Colony, Agra, Uttar Pradesh – 282001, India
Applicable Frameworks: DPDPA 2023, IT Act 2000 & IT Rules 2021 (India) | Privacy Act 1988 (Australia) | Law No. 13 of 2016 (Qatar)
Table of Contents
- Data Controller & Contact
- Scope and Application
- Information We Collect
- Information We Do NOT Collect
- Biometric Webhook Clarification
- Legal Basis for Processing
- How We Use Your Information
- Sharing of Information
- International Data Transfers
- Cookies & Tracking Technologies
- Authentication & Infrastructure
- Data Retention
- Your Rights
- Security Measures
- Children's Privacy
- Changes to This Policy
- Grievance Officer & Contact
This Privacy Policy ("Policy") describes how Airborne HRS collects, uses, stores, shares, and protects personal information when you use any of our Services — airbornehrs.in, jobs.airbornehrs.in, and the Airborne HRMS platform. By using our Services, you acknowledge that you have read and understood this Policy.
1. Data Controller and Contact
Kunwar Shatrujit Singh (trading as Airborne HRS), 37A/13, Defence Colony, Agra, Uttar Pradesh – 282001, India, is the data controller for all personal data collected through our Services, except where explicitly stated otherwise (e.g. Employee data processed on behalf of HRMS Clients, where the Client is the data controller).
For privacy-related queries, requests, or complaints, contact: legal@airbornehrs.in
2. Scope and Application
EEA / GDPR Notice:
Airborne HRS specifically targets users and organisations in India, Qatar, and Australia. We do not currently target users in the European Economic Area (EEA), nor do we intentionally collect data subject to the General Data Protection Regulation (GDPR).
This Policy applies to all individuals who interact with our Services, including:
- Visitors to airbornehrs.in (including blog readers and newsletter subscribers);
- Employers and Candidates on jobs.airbornehrs.in;
- University placement coordinators and students accessing via the Free Tier;
- HRMS Clients (company administrators and HR managers);
- Employees whose data is managed within the HRMS on behalf of a Client.
For Employee data processed through the HRMS: the Client employer is the data controller, and Airborne HRS is the data processor. We process such data only on documented instructions from the Client and subject to our Data Processing Agreement. The Client's own privacy notices to their Employees govern the primary privacy relationship for Employee data.
3. Information We Collect
3.1 airbornehrs.in — Main Website & Blog
When you visit our website or interact with our blog, we may collect:
- Contact Information: Name, email address, phone number (when submitted via contact forms, newsletter sign-ups, or demo request forms);
- Blog Interactions: Comments, feedback, and responses submitted to published articles;
- Technical Data: IP address, browser type and version, operating system, referral URL, pages visited, time on page, and session duration (collected automatically via server logs and analytics).
3.2 jobs.airbornehrs.in — Job Portal
For Candidates:
- Full name, email address, mobile number;
- Résumé / CV (education, work experience, skills, certifications, and any references voluntarily included);
- Profile photograph (optional, user-uploaded);
- Job preferences, target roles, expected compensation, and career interests;
- Application history, status, and communications with Employers via the platform;
- IP address and browser metadata collected at login and during active sessions.
For Employers:
- Company name, registered address, industry, company size;
- Tax identification number / GST number (where applicable for invoicing);
- Contact person's name, email address, and designation;
- Job listing content, recruitment preferences, and hiring activity;
- Subscription plan details and billing information (processed via Wise — see Section 8);
- IP address and browser metadata at login and during active sessions.
For Universities (Free Tier):
- Institution name, location, and regulatory accreditation details;
- Training and Placement Officer (TPO) / coordinator name, email, and phone number;
- Aggregated placement activity data (student applications, drive outcomes).
3.3 Airborne HRMS — SaaS Platform
The HRMS processes the following categories of data as configured and directed by the Client employer:
- Employee Identity: Full name, employee ID, designation, department, reporting manager;
- Contact Details: Work email address, work phone number;
- Attendance Records: Clock-in and clock-out timestamps, attendance status (present / absent / late / on leave);
- Location Data: GPS coordinates captured at the moment of clock-in/clock-out events (enabled only where configured by the Client and where Employee has been duly informed);
- Login Metadata: Date, time, and IP address of login; device type, browser name and version;
- Leave Records: Leave applications, types, approvals, balances, and HR notes;
- Payroll Data: Gross salary, deductions, net pay, and payment records (as configured by the Client);
- HR Documents: Offer letters, contracts, and other employment documents uploaded by the Client;
- Identity Verification (India only): For Indian employees, identity verification is facilitated via DigiLocker / Meri Pehchaan (NSSO). We receive specific verification tokens/data from the Indian Government's portal to verify identity, but do not store actual Aadhaar numbers unencrypted unless explicitly stated.
- Consent Records: IP addresses and exact server timestamps are securely logged strictly to serve as proof of consent when you agree to our legal terms.
3.4 Automatically Collected Technical Data (All Services)
Across all Services, we automatically collect the following when you access our platforms:
- IP Address: Logged for security monitoring, abuse prevention, and fraud detection;
- Browser Metadata: Browser name and version, operating system type and version, device type (desktop/mobile/tablet), and display language;
- Session Data: Authentication tokens, session identifiers, page navigation path, time-on-page metrics, and interaction events.
4. Information We Do NOT Collect
We are committed to data minimisation. The following data is expressly not collected by Airborne HRS under any circumstance:
- ❌ Biometric Data: We do not capture, receive, store, or process fingerprints, iris scans, facial recognition templates, voice prints, vein patterns, or any other biometric identifier. (See Section 5 for our webhook clarification.)
- ❌ Screen Activity: We do not capture screenshots, record screen video, or monitor on-screen activity on any user device.
- ❌ Keystrokes: We do not log, record, or analyse any keystrokes entered on any device.
- ❌ Email or Message Content: We do not read, access, or store personal or business email or messaging content.
- ✅ Microphone or Camera: We only access your microphone and camera when you explicitly join a video meeting (e.g., recruitment interviews, team meetings) on the platform. We do not record or store these video/audio streams unless explicitly authorized.
- ❌ Full Payment Card Data: We do not store credit/debit card numbers, CVV codes, or full payment credentials. Payment data is handled exclusively by Wise.
- ❌ Continuous Background Location: Location is captured only at designated clock-in/clock-out events — not tracked continuously or in the background.
5. Biometric Webhook Clarification
Airborne HRS offers a webhook-based API integration that enables compatible biometric attendance devices to signal an attendance event to the HRMS system upon successful employee biometric authentication at the device.
How it works: When an employee authenticates on a biometric device (e.g. fingerprint scanner), the device sends an HTTP event notification to our webhook endpoint. This notification contains only: an employee identifier (ID or code), a timestamp, and an event type (e.g. clock-in / clock-out).
What Airborne HRS does not receive: No biometric raw data, no biometric feature templates, no images, scans, or any biometric identifiers are transmitted to or received by Airborne HRS at any point. Biometric data never leaves the Client's on-premise biometric device and its associated vendor system.
Client responsibility: HRMS Clients using biometric-integrated attendance are solely responsible for compliance with all applicable biometric data laws in their jurisdiction — including but not limited to India's proposed biometric data regulations, Australia's Privacy Act 1988 and applicable state surveillance laws, and Qatar's PDPPL (Law No. 13 of 2016). Clients must obtain all necessary Employee consents and provide appropriate disclosures regarding biometric authentication at the device level.
6. Legal Basis for Processing
We process personal data on the following legal bases, as applicable:
- Contractual Necessity: Processing required to fulfil the Services you have requested — including account creation, job portal access, HRMS operations, and payment processing.
- Legitimate Interests: Processing for our legitimate business interests, including platform security, fraud prevention, analytics, and service improvement, where such interests are not overridden by your rights and freedoms.
- Consent: Where you have given explicit, informed consent — including for marketing communications or optional profile features. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal Obligation: Processing necessary to comply with applicable laws, including tax regulations, audit requirements, and responses to lawful government requests.
For HRMS Employee data processed on behalf of Client employers, the applicable legal basis is determined by the Client as the data controller, typically employment contract necessity or legitimate employer interest under applicable employment law.
7. How We Use Your Information
We use collected information for the following purposes:
- Service Delivery: To operate, maintain, and improve the Services — including account management, job matching, HRMS attendance and location features, and platform functionality;
- Communication: To send transactional communications (account confirmations, password resets, invoices, service alerts) and, with your consent, marketing updates or blog newsletters;
- Security and Fraud Prevention: To detect, investigate, and prevent unauthorised access, fraudulent activity, and abuse — IP addresses and browser metadata are used specifically for this purpose;
- Analytics and Improvement: To understand usage patterns and improve the Services — using anonymised or aggregated data wherever possible;
- Legal Compliance: To meet obligations under applicable law, including responding to lawful regulatory, judicial, or government authority requests;
- Payment Processing: To facilitate subscription billing through Wise;
- Recruitment Facilitation: On jobs.airbornehrs.in, to surface relevant job listings to Candidates and relevant Candidate profiles to Employers.
We do not sell, rent, trade, or otherwise share your personal data with third parties for their marketing, advertising, or commercial purposes.
8. Sharing of Information
8.1 Necessary Service Providers (Data Processors)
- Google Firebase / Firestore & Google OAuth: Used for user authentication and database hosting. We utilize Google OAuth to verify user identities and receive basic profile data. Google processes data on our behalf under a Data Processing Agreement.
- Supabase: Used for secure storage of HR documents, resumes, and avatar media. Data is hosted under encrypted, private buckets and processed on our behalf.
- Vercel: Used for hosting the web application, APIs, and edge functions. Vercel acts as a sub-processor to deliver the application infrastructure.
- Wise (Payment Processing): Receives payment-related data (name, email, payment amount) to process transactions. Wise operates as an independent data controller for its payment activities, governed by its own privacy policy.
- Video Infrastructure Providers (Stream, Agora): Used for delivering real-time audio and video streams during live interviews and team meetings. Audio/video data passes through these providers but is not recorded or stored by Airborne HRS unless explicitly initiated by the host.
8.2 Employers and Candidates (Job Portal)
Candidate profiles and résumés are made visible to Employers on the platform for recruitment purposes only. Candidate contact details are shared with an Employer only upon a Candidate actively applying for that Employer's listing, or expressly enabling profile visibility. Employer job listing details (company name, role, description) are visible to all registered Candidates and University users.
8.3 Legal and Regulatory Disclosure
We may disclose personal data to law enforcement agencies, courts, regulatory bodies, or other government authorities where required by applicable law, court order, or in good-faith belief that such disclosure is necessary to protect our rights, prevent fraud, or ensure the safety of users or the public.
8.4 Business Transfers
In the event of a business restructuring, acquisition, merger, or asset sale, user data may be transferred as part of such transaction, subject to the successor entity adopting equivalent data protection obligations. We will notify affected users in advance where required by applicable law.
8.5 No Sale of Personal Data
Airborne HRS does not sell, rent, lease, or otherwise transfer personal data to any third party for their own marketing, commercial, or advertising purposes — under any circumstances.
9. International Data Transfers
Airborne HRS is headquartered in India and currently serves clients in India, Qatar, and Australia. Personal data may be stored and processed in India or on Google Firebase's global infrastructure, which may include servers in regions outside India.
We take appropriate safeguards for international data transfers:
- Australia: Cross-border disclosures are subject to the Australian Privacy Principles (APPs 8) under the Privacy Act 1988 (Cth). We take reasonable steps to ensure that overseas recipients handle data in a manner consistent with the APPs.
- Qatar: We comply with the requirements of Qatar's Personal Data Privacy Protection Law (Law No. 13 of 2016) regarding cross-border transfers of Qatari residents' data, including ensuring adequate protection levels at the destination.
- India: We comply with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
10. Cookies and Tracking Technologies
We use cookies and similar technologies on our web properties. Cookies are small text files stored on your device by your browser. We use the following types:
- Essential / Strictly Necessary Cookies: Required for core platform functionality, including session management and authentication. These cannot be disabled without impairing your ability to use the Services.
- Analytics Cookies: Used to understand how users navigate and interact with our Services (e.g. pages visited, session length). These may be controlled via your browser settings or a future cookie consent banner we will deploy.
- Preference Cookies: Store your settings and preferences (e.g. language, display options) to personalise your experience.
We do not use third-party advertising cookies, tracking pixels for ad retargeting, or cross-site behavioural tracking technologies.
You may manage cookie preferences through your browser settings. Note that disabling cookies may affect certain platform features. Where required by applicable law, we will seek your consent before placing non-essential cookies.
11. Authentication and Infrastructure
User authentication across Airborne HRS Services is handled through Google Firebase Authentication (Firestore) and Google OAuth. We use Google OAuth to securely link and verify identities without managing passwords directly. Firebase processes authentication credentials on our behalf under Google's standard data processing and security terms.
For more information on how Google handles data in Firebase, please review Google's Privacy Policy at policies.google.com/privacy and the Firebase Data Processing and Security Terms.
12. Data Retention
We retain personal data for as long as necessary for the purposes described in this Policy, or as required by applicable law. Specific retention periods are as follows:
- User Account Data: Retained for the duration of the active account plus 2 years after account closure;
- Candidate Profiles and Résumés: Retained while the account is active; deleted or anonymised within 90 days of a verified account deletion request;
- HRMS Employee Records: Retained for the duration of the Client's active subscription plus 3 years, unless an earlier deletion is requested by the Client, subject always to any longer period mandated by applicable employment, tax, or statutory law (such as EPFO regulations or local Shops & Establishments Acts);
- Payment and Invoice Records: Retained for 7 years as required by Indian financial regulations and applicable tax laws;
- Security Logs (including IP address logs): Retained for up to 12 months;
- Attendance and Location Records: Retained for the period configured by the Client, not exceeding 5 years;
- Blog Comments and Contact Form Submissions: Retained for up to 3 years from submission.
At the expiry of applicable retention periods, data is securely and irreversibly deleted or anonymised.
13. Your Rights
13.1 Rights Under Indian Law (All Users)
Under the IT (Reasonable Security Practices and Procedures and SPDI) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (upon commencement of applicable provisions), you have the right to:
- Access the personal data we hold about you, along with a summary of data processing activities;
- Correct, complete, or update inaccurate, incomplete, or misleading personal data;
- Request the erasure (deletion) of your personal data when it is no longer necessary for the purpose for which it was collected or processed;
- Withdraw consent where processing is based on consent (this does not affect the lawfulness of prior processing);
- Nominate an individual to exercise your rights in the event of death or incapacity;
- Lodge a complaint with the Grievance Officer (see Section 17) or the Data Protection Board of India.
13.2 Rights for Australian Users
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:
- Request access to personal information we hold about you;
- Request correction of information that is inaccurate, incomplete, or out of date;
- Request that we not use your information for direct marketing purposes;
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au if you believe we have mishandled your personal information (after first contacting us to resolve the matter).
13.3 Rights for Qatar Users
Under Qatar's Personal Data Privacy Protection Law (Law No. 13 of 2016), you have the right to:
- Access personal data we hold about you;
- Request correction or deletion of inaccurate data;
- Object to processing of your personal data in certain circumstances;
- Lodge a complaint with the Ministry of Communications and Information Technology (MCIT) or the relevant data protection authority in Qatar.
13.4 How to Exercise Your Rights
To exercise any of the above rights, please submit a written request to legal@airbornehrs.in, including your name, the Service(s) to which your request relates, and a description of your request. We will respond within 30 calendar days of receipt (or within the timeframe prescribed by applicable law). We may require identity verification before processing your request.
14. Security Measures
We implement technical and organisational security measures proportionate to the risks associated with the data we process. These include:
- TLS/HTTPS encryption for all data transmitted between users and our Services;
- Firestore security rules enforcing role-based access control;
- Authentication token management and session expiry controls;
- Access logging and real-time monitoring for suspicious or anomalous activity;
- Restricted staff access to personal data on a need-to-know basis;
- Confidentiality obligations for all personnel and contractors;
- Regular security review and vulnerability assessment processes;
- Data minimisation — we collect only what is necessary for stated purposes.
No system is completely secure. While we take reasonable precautions, we cannot guarantee the absolute security of data transmitted over the internet or stored on our systems. In the event of a personal data breach affecting your personal data, we will notify you and the relevant supervisory authorities within 72 hours of becoming aware of the breach, or within such shorter period as mandated by applicable law.
15. Children's Privacy
Our Services are not directed at children. The age floor for data processing consent varies by jurisdiction:
- India (DPDPA 2023): A "child" is defined as any person under the age of 18. Processing the personal data of anyone under 18 in India is prohibited without verifiable parental or lawful guardian consent. We do not knowingly collect or process personal data of individuals under 18 in India without such verifiable consent.
- Australia and Other Jurisdictions: We do not knowingly collect or process personal data of individuals under the age of 13 without verifiable parental/guardian consent.
The job portal (jobs.airbornehrs.in) is intended for individuals aged 18 and above. A limited carve-out is permitted for students aged 16 to 17 in India who access the platform under the Free Tier through an accredited University placement program. This access is permitted strictly under the DPDPA's school/institutional-supervision exception, where the participating University acts as the recognized institutional authority/lawful guardian, assumes responsibility for student data handling, and verifies parental authorization at the institutional level.
If you are a parent or guardian and believe your child has provided us with personal data without appropriate consent, please contact us at legal@airbornehrs.in, and we will promptly delete the data.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features. The updated Policy will be published on this page with a revised effective date. For material changes, we will provide at least 14 days' prior notice to registered users via email or in-platform notification. Continued use of our Services following the effective date of any update constitutes your acceptance of the revised Policy.
We encourage you to review this Policy periodically to stay informed about how we protect your information.
17. Grievance Officer and Contact
In compliance with Rule 5(9) of the Information Technology (SPDI) Rules, 2011, and Rule 4(1)(b) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, Airborne HRS designates the following Grievance Officer for privacy-related complaints:
Name: Kunwar Shatrujit Singh
Designation: Proprietor & Grievance Officer, Airborne HRS
Email: legal@airbornehrs.in
Postal Address: 37A/13, Defence Colony, Agra, Uttar Pradesh – 282001, India
Working Hours: Monday to Friday, 10:00 AM – 6:00 PM IST
Any grievance, complaint, or concern regarding collection, use, storage, or disclosure of your personal data must be submitted in writing to the above address or email. Grievances will be acknowledged within 24 hours and resolved within 15 days of receipt.
General Support: support@airbornehrs.in
Legal, Privacy & Compliance: legal@airbornehrs.in
Kunwar Shatrujit Singh (Sole Proprietorship) trading as Airborne HRS
37A/13, Defence Colony, Agra, Uttar Pradesh – 282001, India
Privacy Policy Version 1.2 | Last reviewed 15 June 2026 | For the most current version, visit airbornehrs.in/legal