Legal
Privacy Policy
Last updated: 22 July 2026
This Privacy Policy explains how PeopleCap handles personal data. It applies to peoplecap.in and to data processed in the course of our advisory engagements with candidates and clients. It is effective as of the "Last updated" date shown above.
PeopleCap is a brand operated by N53 Techworks LLP. Under India's Digital Personal Data Protection Act 2023 (DPDPA), N53 Techworks LLP is the Data Fiduciary responsible for the personal data described in this policy. Individuals whose personal data we process are Data Principals within the meaning of the Act.
1. Who we are
PeopleCap is a brand operated by N53 Techworks LLP (LLPIN: ACI-8879), a limited liability partnership registered in India.
N53 Techworks LLP19th Floor, Tower-B, Alphathum, Sector-90
Noida, Uttar Pradesh 201305, India
Under DPDPA, N53 Techworks LLP is the Data Fiduciary for personal data processed in connection with the PeopleCap practice. This means we determine the purpose and means of that processing and are accountable for it under the Act. This policy applies to peoplecap.in, the operations platform at app.peoplecap.in, and to personal data we process in the course of our advisory services (talent acquisition, fractional HR, talent intelligence, and hiring effectiveness).
The privacy and data-protection contact for this policy is privacy@peoplecap.in. Grievances are handled by our Grievance Officer at grievance@peoplecap.in (see section 11).
2. What data we process
We process personal data in the contexts set out below. Each carries a different purpose and a different legal basis.
2A. Data from website visitors
- Contact form submissions: name, organisation, email address, role or title, and the content of your inquiry.
- Newsletter subscribers (if and when a newsletter is published): email address only.
- Server logs: IP address, user agent, pages visited, request timestamps. Used in aggregate to understand site usage and to investigate technical issues.
- Browser storage: one consent-acknowledgement item described in our Cookie Policy.
2B. Data from candidates engaging with our services
- Name
- Contact details: mobile number and email address, and location
- Professional details: current and previous employer, job title, years of experience, skills, current and expected compensation, work location, and education
- Résumés / CVs and the employment histories, qualifications, and educational background they contain
- Notice periods, location preferences, and role preferences
- References, where provided
- Notes from our conversations and our assessment of fit against specific mandates
2C. Data from client engagements
- Names and contact details of client representatives, including hiring managers, HR teams, and leadership
- Role briefs and hiring requirements shared with us
- Compensation budgets and structures shared during mandate discussions
- Information shared during fractional HR, talent intelligence, or hiring effectiveness engagements, including organisational context, process diagnostics, and people data shared by the client for the purpose of the engagement
2D. Data about our own staff
As an employer, N53 Techworks LLP also processes the personal and employment data of its partners and team members for human-resources, payroll, and statutory-compliance purposes. That processing is governed by our internal employment policies; this notice covers it only to the extent our staff are also Data Principals with the rights described in section 8.
3. Legal basis and consent
Under DPDPA, the primary lawful grounds for processing personal data are the consent of the Data Principal and certain legitimate uses set out in the Act. For candidate data, our processing rests on your consent, or on your voluntary provision of your own professional profile to us for the purpose of being considered for opportunities. We rely on the following grounds.
- Candidate data: the candidate's consent, or the candidate's voluntary provision of their profile to us, for PeopleCap's consideration of the candidate for relevant mandates.
- Client data: legitimate use in the context of an active or prospective engagement, supported by contractual necessity once an engagement letter is in place.
- Website visitors: legitimate use for responding to inquiries; consent for any non-essential storage or processing (see the Cookie Policy).
Consistent with DPDPA's notice requirements, the specific items of personal data we process are itemised in section 2 and the specific purposes for each are set out in section 4. Before we seek your consent, we give you a notice describing this data and these purposes, and telling you how to withdraw consent (section 3B), exercise your rights (section 8), and complain to the Data Protection Board of India (section 11).
3A. How you give consent (self-service)
Candidates give consent themselves, rather than having it recorded on their behalf. When we need your consent, we send you a secure personal link that is unique to you. Opening that link and confirming your choice records your consent. To make sure the request reaches the right person, the link is confirmed by a one-time code emailed to you.
Consent is always voluntary. It is specific to PeopleCap's consideration of your profile for relevant mandates, and it is never assumed from your silence, from inactivity, or from your not responding to a message. You decide what you agree to, and you can decline without giving a reason.
3B. Withdrawing consent
You can withdraw your consent at any time, and it is as easy to withdraw as it was to give. You can do so on your secure consent page (the same personal link), or by writing to privacy@peoplecap.in.
When you withdraw consent, we stop using your data for the purpose you withdrew immediately. If you are not part of any active engagement at that time, we remove your profile. If you are part of an active engagement, for example your profile is already before a hiring client, we review your request case by case, tell you what that means in practice, and act on it as fully as we can while meeting any obligation we are required by law to keep. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
4. How we use your data
We use personal data only for the specific purposes set out below.
Candidate data
- Engaging candidates about opportunities and matching candidates against active and prospective client mandates
- Delivering our services across our practices: talent acquisition, fractional HR, talent intelligence, and hiring effectiveness
- Disclosing candidate shortlists and profiles to prospective employers (hiring clients), only with the candidate's consent for the specific engagement. A hiring client that receives a profile becomes a separate Data Fiduciary, as described in section 5
- Conducting assessment and reference activity as part of evaluating fit
- Retaining candidate profiles in our talent network if the candidate has agreed, so we can contact them about future mandates that fit their profile
Client data
- Delivering the engagement as scoped in the engagement letter
- Billing and accounting in connection with the engagement
- Ongoing business relationship management with returning clients
Website visitor data
- Responding to inquiries submitted via the contact form or directly by email
- Sending newsletter issues to subscribers who have opted in, if and when a newsletter is published
- Understanding aggregate site usage and improving the website
Use of AI in our practice
We use AI tools to assist our team in the following ways:
- Parsing and structuring information from résumés
- Rewriting and formatting résumés that candidates submit to the Resume Rebuilder tool
- Scoring how well a candidate fits a specific mandate
- Suggesting candidates to our consultants
- Sanitising job descriptions before they are published as public listings
- Natural-language search within our internal platform
- Generating hiring-effectiveness gap analyses
This involves limited AI processing of résumé and job-description text by our AI provider (OpenAI). That provider processes the text only to deliver the feature and support our evaluation of a profile. It does so under a data-processing agreement with a zero-retention posture, meaning your information is not retained by the provider and is not used to train its AI models. This processing takes place outside India, as described in section 6.
For Fractional HR engagements, AI summarisation of engagement content is an opt-in feature. It is activated for an engagement only with the client's explicit consent, and the vendor operates under the same contractual zero-retention posture.
AI-derived outputs are reviewed by a member of our practice before they are acted upon for any decision that materially affects a candidate or client. We do not use AI for automated decision-making. Highly sensitive content is excluded from external AI processing entirely.
Candidates and clients can request information about AI-derived processing of their data through the contact channels in section 14.
What we do not do: We do not use personal data for automated decision-making, profiling, or targeted advertising. We do not sell or rent personal data to any party.
5. Sharing and disclosure
5A. With hiring clients (candidate data only)
When we share a candidate's profile with a prospective employer, we do so only with the candidate's consent for that specific engagement. We do not share candidate data with multiple clients simultaneously without separate consent for each.
Once a hiring client receives a candidate's profile, that client decides how it uses the profile within its own recruitment process. At that point the hiring client is a separate Data Fiduciary under DPDPA and is responsible, on its own account, for its processing of the candidate's personal data. The client's handling of your data is governed by the client's own privacy notice, not this one.
5B. With service providers (sub-processors)
We use a small number of service providers to operate the practice. They are bound by confidentiality and data protection obligations, and process personal data only on our instructions and for the specific service they provide. By category and region, they are:
- Cloud database and file storage (India, Mumbai region): our database and storage provider (Supabase) holds the operations platform's personal data, including uploaded résumés, in India.
- Application hosting and compute (Railway, Singapore): our application hosting and compute provider (Railway) runs our application compute in the Singapore region. This covers both the operations platform at app.peoplecap.in and the peoplecap.in marketing site: personal data is processed in Singapore in the course of serving requests and handling form submissions, before it comes to rest in Mumbai.
- Transactional email (United States): an email service provider (Resend) for transactional email, notifications, and the one-time codes used in our consent and login flows.
- Newsletter delivery: a newsletter provider (Brevo) for double opt-in and issues.
- AI processing (outside India): an AI provider (OpenAI) for the AI-assisted features described in section 4, under a data-processing agreement with a zero-retention posture.
- Productivity, document storage, accounting, and finance: providers for internal file storage, calendaring, communication, billing, and statutory compliance.
Where an AI feature sends personal data to OpenAI, we operate under an executed OpenAI Enterprise Data Processing Agreement with a zero-retention posture, so that data is not retained by the provider or used to train models. The Fractional HR AI summarisation feature described in section 4 is offered on an opt-in basis and is activated for an engagement only with the client's explicit consent.
This is the list of sub-processors we currently rely on. We keep it up to date as our providers change, and further detail is available on request to candidates and clients with a legitimate need to know.
5C. With regulators or authorities
We may disclose personal data where required by law, including in response to a valid legal request from a regulator, court, or other competent authority. Where permitted, we will notify the affected Data Principal.
6. Cross-border data transfers
The personal data held in our operations platform is stored in India (Supabase, Mumbai region). The platform's application compute runs in Singapore, so personal data is processed there in the ordinary course of running the platform before it is stored in India. In addition, some features send limited personal data to providers that process it outside India: principally transactional email (Resend, in the United States) and AI text processing (OpenAI), under contract. We conduct any such cross-border processing in compliance with the provisions of DPDPA on cross-border data transfer, and we use providers that maintain appropriate data protection standards consistent with the Act.
As DPDPA implementing rules are finalised by the Ministry of Electronics and Information Technology, we will adjust our cross-border practices to remain aligned with the rules as they take effect.
7. Data retention
In summary, we keep personal data while the recruitment or engagement purpose it was collected for is live, and then erase it, with documents and logs held on defined timers. The periods below are indicative and under review as our processes mature; they reflect current operational practice and will be revised in line with finalised DPDPA rules and our legal advisors' guidance.
- Contact form inquiries: typically 24 months from the last interaction, unless converted into an active engagement
- Active engagement data: the duration of the engagement plus up to 7 years for tax, audit, and statutory compliance
- Candidate profiles in our talent network: 24 months from the candidate's last interaction, refreshable at the candidate's request to remain in our network for longer
- Server logs: 90 days
- Audit logs within the operations platform: 365 days
- Newsletter subscribers: retained until the subscriber unsubscribes; unsubscribe requests are honoured promptly
Within our operations platform, records are deleted logically rather than erased immediately, and are retained for legitimate business, audit, and statutory reasons. When a candidate withdraws consent (section 3B) or asks us to erase their data, we remove or anonymise the personal data once no retention obligation requires us to keep it. Where retention is no longer required for the stated purpose, personal data is deleted or anonymised.
8. Your rights as a Data Principal
Under DPDPA, Data Principals have the following rights in respect of their personal data processed by a Data Fiduciary.
- Right to withdraw consent: where our processing rests on your consent, you can withdraw it at any time, and it is as easy to withdraw as it was to give. Withdraw on your secure consent page, or by writing to privacy@peoplecap.in. See section 3B for what happens when you withdraw.
- Right to access information about your personal data: a summary of the personal data we hold about you and the processing we carry out on it. Request it via your secure link or by writing to privacy@peoplecap.in.
- Right to correction: correction of inaccurate or incomplete data. Update it on your secure profile page, or ask us at privacy@peoplecap.in.
- Right to erasure: erasure of personal data no longer required for the purpose for which it was collected, subject to any retention obligation we are required to comply with. Request it at privacy@peoplecap.in.
- Right of grievance redressal: an accessible mechanism to raise concerns about how we process your personal data (see section 11).
- Right to nominate: nomination of another individual to exercise these rights on your behalf in the event of your death or incapacity.
To exercise any of these rights, use the secure consent and rights link we have sent you, or email privacy@peoplecap.in. We will acknowledge your request promptly and respond substantively within 30 days. Where a request requires longer to complete, we will explain why and provide an expected timeline.
Where the General Data Protection Regulation (GDPR) applies, typically for visitors based in the European Union or the European Economic Area, the corresponding rights under GDPR also apply and can be exercised through the same contact channels.
9. Security
We take technical and organisational measures to protect personal data from unauthorised access, loss, alteration, and misuse.
- N53 Techworks LLP is certified to ISO/IEC 27001:2022 for the information security management system covering the operations under which the PeopleCap practice is run; see our Trust & Security overview
- All data transmitted to and from peoplecap.in is encrypted in transit using HTTPS and TLS
- Access to personal data is restricted to team members with a legitimate need to access it for their role, on a least-privilege basis
- Our handling practices are aligned with DPDPA's requirements for reasonable security safeguards
- In the event of a personal data breach that is likely to cause significant harm to affected Data Principals, we will notify the Data Protection Board of India and the affected individuals in line with DPDPA notification requirements
No method of internet transmission or storage is completely secure. We work to maintain a high standard and to respond promptly to any incident that arises.
10. Children's data
PeopleCap's services are directed at organisations and at working professionals over the age of 18; our Data Principals are working adults. We do not knowingly collect or process the personal data of individuals under 18 (or such other age as DPDPA defines as a child). If we become aware that we hold personal data of an individual under that age, we will delete it promptly unless retention is required by law.
11. Grievance redressal and complaints to the Board
In accordance with DPDPA, the role of Grievance Officer for the PeopleCap practice is held by Kapil Mohan Gupta, Founder, N53 Techworks LLP. If you have a concern about how we process your personal data, contact the Grievance Officer using the details below.
Grievance Officer
Kapil Mohan Gupta
grievance@peoplecap.in
Postal address
Grievance Officer
N53 Techworks LLP
19th Floor, Tower-B, Alphathum, Sector-90
Noida, Uttar Pradesh 201305, India
We will acknowledge grievance communications within 7 working days and respond substantively within 30 days. Where additional time is required to investigate, we will keep you informed of progress and expected resolution.
Complaint to the Data Protection Board of India. If your concern is not resolved to your satisfaction through our grievance process, you have the right, as a Data Principal under DPDPA, to make a complaint to the Data Protection Board of India in the manner provided under the Act.
12. Languages
This notice is published in English. On request, we will make it available to you in other languages, including the languages specified in the Eighth Schedule to the Constitution of India. To request this policy in another language, write to privacy@peoplecap.in.
13. Changes to this policy
We may update this Privacy Policy from time to time as our practices evolve and as DPDPA implementing rules are finalised. The current version is always available at peoplecap.in/privacy-policy/. The "Last updated" date at the top of this page reflects the most recent material change.
When we make a material change, we will notify users by updating the website prominently.
14. Contact
Data protection and privacy inquiries
Grievances (Grievance Officer)
19th Floor, Tower-B, Alphathum, Sector-90
Noida, Uttar Pradesh 201305, India