Your information, handled with care.
Last updated: 28 August 2026 · Questions or requests: hello@pathrecruiters.com
This Privacy Policy explains how Path Recruiters (“Path Recruiters”, “we”, “us”) collects, uses, discloses, and protects personal data belonging to candidates, employer contacts, and other users (“you”) of pathrecruiters.com and our recruitment services (together, the “Services”). It is framed in accordance with India’s Digital Personal Data Protection Act, 2023 and the rules made under it. By using the Services, you acknowledge this Policy.
1. Personal data we collect
- Candidate data: name, contact details, CV/résumé, work history, skills, location, salary expectations, availability, and notes from our conversations with you.
- Employer data: business contact details, hiring briefs, role requirements, and correspondence.
- Workspace data: account and authentication records for the small number of Path Recruiters staff who operate the private recruitment workspace.
- Website data: employer brief submissions and, only where you consent, aggregated analytics.
2. How we collect it
We collect personal data directly from you when you submit a CV, apply for a role, complete an employer brief, or speak with a consultant. Where you have authorised it, we also collect data from CVs and attachments forwarded to us for a specific application. We do not purchase candidate contact lists.
3. How we use it
- to assess and discuss your suitability for a role;
- to communicate about applications, interviews, offers, hiring briefs, and service requests;
- to prepare a candidate profile for an employer, only after we have spoken with you about that specific opportunity;
- to operate, secure, and improve the Services; and
- to meet our legal, tax, and accounting obligations.
We do not sell personal data and we do not use candidate data for advertising. An employer never receives your direct contact details or your original CV merely by virtue of a shortlist being shared with them. They receive only the profile we have prepared, after speaking with you.
4. Disclosure to third parties
We disclose candidate data to an employer only where relevant to a specific recruitment process you have agreed to be considered for. We engage service providers for cloud hosting, storage, authentication, email delivery, and consent-based analytics, who process personal data solely to provide those services to us and are bound by confidentiality and data-processing obligations. We may also disclose personal data where required by law, regulation, or a valid order of a court or government authority.
5. Your rights and how to exercise them
Subject to applicable law, you may ask us to give you access to your personal data, correct or update it, erase it, or withdraw consent you have previously given, and you may nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. Write to hello@pathrecruiters.com with your request. We will verify your identity and respond within 30 days. Withdrawing consent or requesting erasure does not affect processing already lawfully carried out, and does not override our need to retain certain records for legal or accounting purposes.
6. Grievance redressal
If you have a grievance about how we have handled your personal data, write to hello@pathrecruiters.com with the word “Grievance” in the subject line. We will acknowledge your grievance promptly and resolve it within 30 days of receipt.
7. Retention and security
We retain candidate and employer data for as long as it is relevant to an active or reasonably foreseeable recruitment relationship, and thereafter only as required to meet legal, tax, or accounting obligations, after which it is deleted or anonymised. CVs and contact details are held in access-controlled systems restricted to authorised Path Recruiters staff; the public-facing parts of our Services are designed to never expose a candidate’s direct contact details or original CV to an employer. No system is completely secure, and we cannot guarantee absolute security of information transmitted to us.
8. Cross-border processing
Our infrastructure providers may process personal data in India and in other countries in which they operate data centres. Where personal data is transferred outside India, we require our service providers to maintain safeguards consistent with the Digital Personal Data Protection Act, 2023 and to comply with any applicable government restrictions on cross-border transfer.
9. Children
Our Services are directed at working adults and are not intended for use by children. If you believe a child has provided us with personal data, please contact us so that we can delete it.
10. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices or in applicable law. We will revise the “Last updated” date above when we do, and material changes will be brought to your attention.