Home About Training Career Mapping Stories Jobs Financial Aid Contact Login/Sign Up
GDPR Compliance

GDPR Compliance

Our commitment to protecting your data rights under the General Data Protection Regulation (GDPR) and other applicable data protection laws.

GDPR Compliance Statement

This GDPR Compliance page was last updated on March 15, 2024

Path2Hire is committed to compliance with GDPR and other data protection regulations.

1. GDPR Overview

Understanding the General Data Protection Regulation

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect in the European Union on May 25, 2018. It strengthens the rights of individuals regarding their personal data and imposes strict obligations on organizations that process this data.

Although Path2Hire is based in India, we recognize the importance of data protection and extend GDPR principles to all our users worldwide. We are committed to protecting your personal data and ensuring your privacy rights are respected.

Key GDPR Terminology

Personal Data:
Any information relating to an identified or identifiable natural person
Data Controller:
Path2Hire determines the purposes and means of processing personal data
Data Processor:
Third parties that process data on our behalf
Data Subject:
You, the individual to whom the personal data relates

2. GDPR Principles We Follow

Our commitment to GDPR's core principles

Lawfulness, Fairness & Transparency

We process personal data lawfully, fairly, and transparently. You'll always know what data we collect and why.

Purpose Limitation

We collect data for specified, explicit, and legitimate purposes and don't process it incompatibly with those purposes.

Data Minimization

We only collect data that is adequate, relevant, and limited to what's necessary for our purposes.

Accuracy

We keep personal data accurate and up to date. You can request corrections at any time.

Storage Limitation

We keep personal data only as long as necessary for the purposes for which it was collected.

Integrity & Confidentiality

We process personal data securely, protecting against unauthorized or unlawful processing, loss, destruction, or damage.

Accountability

We take responsibility for complying with GDPR principles and can demonstrate our compliance through appropriate records and measures.

3. Your GDPR Rights

The rights you have over your personal data

Right to Access

Request confirmation and access to your personal data

Right to Rectification

Request correction of inaccurate personal data

Right to Erasure

Request deletion of your personal data ("right to be forgotten")

Right to Restriction

Request restriction of processing under certain conditions

Right to Portability

Receive your data in a structured, commonly used format

Right to Object

Object to processing based on legitimate interests or direct marketing

Exercising Your Rights

To exercise any of these rights, please contact our Data Protection Officer using the information provided in the "Contact DPO" section below. We will respond to your request within 30 days, though this may be extended by two months for complex requests.

Response time: 30 days | No fee for standard requests

4. Lawful Basis for Processing

How we legally process your personal data

We process your data based on:

Consent

You've given clear consent for specific purposes

Contract

Processing is necessary for a contract with you

Legal Obligation

Processing is necessary for legal compliance

Consent Management

Freely Given

Consent is obtained through clear affirmative action. You have genuine choice and control.

Specific & Informed

We specify why we need the data and what we'll do with it. No pre-ticked boxes or implied consent.

Easy to Withdraw

You can withdraw consent at any time, as easily as you gave it. Withdrawal doesn't affect lawfulness of prior processing.

5. International Data Transfers

How we protect your data across borders

Our Approach to Data Transfers

Primary Storage

India-based servers

Our primary data storage and processing occurs on servers located in India. We choose service providers with strong data protection commitments.

Adequate Safeguards

For international transfers

When data must be transferred internationally, we ensure adequate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

Third-Party Processors

We use carefully selected third-party service providers (data processors) who may process your data on our behalf. All such processors are bound by strict data processing agreements that require them to:

  • Process data only per our instructions
  • Implement appropriate security measures
  • Notify us of any data breaches
  • Delete or return data upon contract termination

6. Data Security Measures

How we protect your personal data

Technical Measures

Encryption

Data encrypted in transit (TLS 1.2+) and at rest (AES-256)

Access Controls

Role-based access, multi-factor authentication, and audit logs

Network Security

Firewalls, intrusion detection, and DDoS protection

Organizational Measures

Staff Training

Regular GDPR and data protection training for all employees

Policies & Procedures

Comprehensive data protection policies and incident response plans

Regular Audits

Regular security assessments and vulnerability testing

Continuous Improvement

We regularly review and update our security measures to address evolving threats and maintain compliance with changing regulations.

7. Data Breach Protocol

Our response to personal data breaches

Breach Response Process

1

Detection & Containment

Immediate investigation and containment measures to prevent further unauthorized access or data loss.

2

Assessment

Assessment of the breach's nature, scope, affected individuals, and potential risks.

3

Notification

Where required by law, notification to supervisory authorities within 72 hours and affected individuals without undue delay.

4

Remediation & Review

Implementation of corrective measures and review of security practices to prevent recurrence.

What We Notify

In the event of a data breach affecting your personal data, we will notify you (where required by law) and provide information about:

Nature of the breach
Categories of data affected
Likely consequences
Measures taken or proposed
Contact details for inquiries
Steps you can take to protect yourself

GDPR Compliance Commitment

Path2Hire is committed to maintaining the highest standards of data protection and privacy. We regularly review and update our practices to ensure ongoing compliance with GDPR and other applicable data protection laws.

Last Updated: March 15, 2024 | Version: 1.0 | Next Review: September 15, 2024

Switch to Corporate