Privacy Policy
Privacy Policy
Siddhanath Resources LLP
Effective date: 9 September 2026
Last updated: 9 September 2026
1. INTRODUCTION
Siddhanath Resources LLP (“Siddhanath Resources LLP”, “the LLP”, “we”, “us” or “our”) respects the privacy of individuals and is committed to protecting personal data and personal information entrusted to us.
The LLP is engaged in the business of human resource management and consultancy, recruitment, placement, employment, staffing, outsourcing, manpower supply, workforce deployment, labour contracting support, people management, training and development and related support services.
Our activities may involve collecting, receiving, recording, organising, storing, using, disclosing, transferring and otherwise processing personal data relating to job seekers, workers, employees, prospective employees, client representatives, vendors, contractors, business contacts and other individuals.
This Privacy Policy explains how we collect and process such information, the purposes for which it is used, the circumstances in which it may be disclosed, the safeguards we apply, retention principles and the rights and choices available to individuals under applicable law.
This Privacy Policy applies to personal data collected through our website, recruitment and work-registration channels, business enquiries, telephone calls, emails, WhatsApp communications, physical forms, employment and staffing processes, client interactions and other legitimate business activities.
2. ABOUT SIDDHANATH RESOURCES LLP
Siddhanath Resources LLP provides workforce and manpower solutions and connects business requirements with suitable workforce categories.
Our services may include, among other activities:
- recruitment and placement;
- manpower supply;
- labour contracting support;
- staffing and outsourcing;
- worker registration;
- workforce deployment;
- candidate screening and selection;
- employment and workforce administration;
- training and development;
- facility management;
- housekeeping, sanitation and cleaning services;
- office and operational support services;
- event and other workforce-related support services; and
- activities incidental or ancillary to the above.
Our current primary service area includes Pune, Pimpri-Chinchwad and surrounding areas in Maharashtra, India, subject to business requirements and workforce availability.
3. SCOPE OF THIS PRIVACY POLICY
This Privacy Policy applies to personal data and personal information relating to:
3.1 Job Seekers and Candidates
Individuals who register with us, apply for employment, enquire about work opportunities or otherwise seek recruitment or placement assistance.
3.2 Workers and Personnel
Individuals recruited, placed, contracted, deployed or otherwise associated with the LLP for workforce or manpower-related services.
3.3 Employees and Former Employees
Persons employed or previously employed by the LLP, including information relating to employment administration.
3.4 Clients and Employer Representatives
Individuals acting for companies, firms, institutions, establishments or other organisations that seek manpower, staffing, recruitment or workforce services.
3.5 Vendors, Contractors and Business Contacts
Persons who communicate or transact with the LLP in connection with business, professional or contractual activities.
3.6 Website Users
Visitors and users of our website and individuals who submit enquiries, forms or other information through online channels.
4. APPLICABLE LEGAL FRAMEWORK
The LLP's privacy practices are intended to operate in accordance with the Indian legal framework applicable to the relevant processing activity, including, as applicable:
- the Information Technology Act, 2000;
- the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to the extent applicable;
- the Digital Personal Data Protection Act, 2023;
- the Digital Personal Data Protection Rules, 2025, from their respective applicable commencement dates;
- applicable employment, labour, tax, accounting, social-security and statutory requirements;
- applicable contractual and confidentiality obligations;
- applicable requirements concerning government-issued identification and Aadhaar, where relevant; and
- other applicable laws, rules, regulations, notifications and governmental directions concerning privacy, personal data, cybersecurity and electronic records.
The DPDP Act, 2023 expressly provides for phased commencement of its provisions. Accordingly, the LLP will comply with provisions from their respective applicable commencement dates and will update its policies, procedures and controls as necessary to reflect legal and regulatory developments.
Nothing in this Privacy Policy is intended to reduce or exclude any right or protection that cannot lawfully be excluded under applicable law.
5. WHAT IS PERSONAL DATA
For purposes of this Policy, “personal data”, “personal information” and related expressions include information that identifies or is reasonably capable of identifying an individual, either directly or in combination with other information, to the extent recognised under applicable law.
Depending on the relationship with the LLP and the services involved, personal data may include identity, contact, employment, educational, professional, financial, attendance, deployment and other information described in this Policy.
6. PERSONAL DATA WE MAY COLLECT
We may collect only such information as is reasonably necessary for the relevant purpose.
6.1 Candidate and Worker Information
Depending on the recruitment or deployment requirement, we may collect:
- full name;
- date of birth or age;
- gender, where relevant and lawfully obtained;
- photograph;
- contact number;
- email address;
- residential and correspondence address;
- preferred work location;
- educational qualifications;
- professional and technical qualifications;
- skills and trade;
- employment history;
- work experience;
- previous employer information;
- job preferences;
- availability;
- salary or remuneration expectations;
- references;
- language or communication information where relevant to the role;
- identification and verification information;
- work eligibility information;
- information relating to training or certifications;
- information concerning deployment and assignment;
- attendance information;
- payroll and remuneration information;
- bank/payment details where necessary;
- statutory registration information;
- emergency contact information; and
- any other information reasonably necessary for lawful recruitment, employment, staffing or deployment purposes.
6.2 Employee Information
For employees and former employees, information may include:
- employment and joining information;
- identification information;
- educational and professional qualifications;
- payroll and remuneration information;
- bank account details;
- attendance and leave records;
- performance and assignment information;
- statutory and social-security information;
- benefits information;
- emergency contacts;
- disciplinary or grievance records where relevant;
- exit and separation records; and
- other information required for legitimate employment administration or statutory compliance.
6.3 Client and Business Information
For clients, employers and business representatives, we may collect:
- name;
- designation;
- organisation name;
- business address;
- email address;
- telephone/mobile number;
- workforce requirements;
- project or assignment details;
- location of work;
- workforce category and skill requirements;
- operational requirements;
- contract-related information;
- billing and payment information;
- correspondence and communication records; and
- other information required to provide our services.
6.4 Website and Technical Information
When you visit our website, certain technical information may be generated or recorded automatically, depending on the website infrastructure and services used, such as:
- IP address;
- browser type;
- device type;
- operating system;
- date and time of access;
- pages visited;
- referring website;
- approximate technical location information;
- diagnostic data;
- security and access logs; and
- other technical information reasonably required for website operation and security.
7. INFORMATION RELATING TO SENSITIVE CATEGORIES
Certain information may require additional protection under applicable law.
Depending on the circumstances, the LLP may receive information concerning financial details, health or medical information, biometric information, genetic information, passwords or other categories recognised as sensitive under applicable law.
Where the LLP identifies that information falling into a sensitive category (including financial, health, biometric, genetic or credential-related information) is collected or held, such information is classified and flagged as sensitive within the LLP's internal records and data inventory at the point of collection or as soon as reasonably practicable thereafter. This classification is documented and reviewed periodically so that sensitive personal data can be distinguished from other personal data throughout its lifecycle, including for the purposes of access control, retention and disposal.
Personal data classified as sensitive is subject to heightened safeguards over and above the general measures described in this Policy. These heightened controls are documented internally and may include: restricting access to a smaller, named group of personnel on a strict need-to-know basis; applying additional encryption or access-authentication requirements; maintaining separate or clearly marked storage and file-naming conventions for sensitive records; requiring additional approval before sensitive information is shared internally or with a third party; applying shorter or more closely monitored retention periods; and logging access to sensitive records for review. The LLP periodically reviews these heightened controls to confirm they remain appropriate to the sensitivity of the information concerned.
The LLP will endeavour to collect such information only where there is a legitimate and reasonable requirement and where collection and processing are legally permitted.
Such information may be processed for purposes including:
- recruitment and selection;
- employment or deployment;
- statutory compliance;
- payroll and payment;
- workplace safety;
- verification;
- benefits administration;
- contractual requirements; or
- other lawful purposes.
Individuals should not voluntarily submit unnecessary sensitive information.
8. IDENTITY DOCUMENTS AND AADHAAR INFORMATION
Where identity verification is reasonably necessary for recruitment, employment, deployment, statutory compliance or another lawful purpose, the LLP may request appropriate identification documents.
Where Aadhaar information is requested, the LLP will process it only in accordance with applicable legal requirements and only for a lawful and reasonably necessary purpose.
The LLP may request alternative identification or appropriate redaction/masking where legally permissible.
Individuals should not send Aadhaar information or other identity documents through public channels or unsecured communications unless requested by an authorised representative of the LLP.
The LLP does not require and will never intentionally request:
- Aadhaar OTP;
- UPI PIN;
- ATM PIN;
- internet banking password;
- card CVV;
- account password; or
- similar authentication credentials.
9. SOURCES FROM WHICH PERSONAL DATA MAY BE COLLECTED
Personal data may be collected from:
- the individual directly;
- application or registration forms;
- our website;
- emails;
- telephone calls;
- WhatsApp communications;
- client organisations;
- employers;
- references;
- background verification agencies;
- publicly available professional information;
- authorised service providers;
- government or statutory records, where lawfully accessible;
- employment or educational institutions, where verification is authorised; and
- other lawful sources.
Where information is obtained from a third party, we will seek to process it only for a lawful and relevant purpose.
10. COLLECTION THROUGH THE WEBSITE
Our website may enable individuals to:
- request manpower;
- register for work;
- make recruitment-related enquiries;
- contact the LLP;
- communicate business requirements; or
- submit other information relating to our services.
Information submitted through website forms may be used for the purpose stated in or reasonably apparent from the relevant form.
The LLP will endeavour to provide an appropriate notice at or before the point at which information is collected, particularly where such notice or consent is required under applicable law.
11. COLLECTION THROUGH WHATSAPP AND ELECTRONIC COMMUNICATION
The website may contain links or contact options that allow individuals to communicate with the LLP through WhatsApp.
Opening a WhatsApp link does not by itself mean that a message has been sent to the LLP. The individual determines whether to send a message.
Once a message or attachment is voluntarily sent to the LLP, information contained in that communication may be received, stored and processed for the relevant enquiry or service.
WhatsApp and other third-party communication platforms have their own terms, privacy policies and security practices, which are outside the control of the LLP.
Individuals should avoid sending unnecessary sensitive information through ordinary messaging channels.
12. PURPOSES OF PROCESSING PERSONAL DATA
The LLP may collect and process personal data for one or more of the following purposes:
12.1 Recruitment and Placement
To identify, assess, contact, shortlist and place candidates for employment or workforce opportunities.
12.2 Candidate Registration
To create and maintain candidate or worker records and consider individuals for suitable current or future opportunities.
12.3 Workforce Deployment
To deploy, manage, coordinate, supervise and administer workers and personnel.
12.4 Client Workforce Requirements
To understand client requirements and identify appropriate personnel.
12.5 Background Verification
To verify identity, qualifications, employment history, experience, references, professional information and other information reasonably necessary for recruitment or deployment.
12.6 Employment Administration
To manage joining, onboarding, attendance, leave, payroll, benefits, statutory requirements, workplace administration and separation.
12.7 Payment and Accounting
To process lawful payments, reimbursements, payroll, invoices, taxes and financial records.
12.8 Communication
To communicate regarding applications, vacancies, assignments, workforce requirements, contracts, enquiries, appointments and other business matters.
12.9 Training and Development
To administer training, development programmes, seminars, orientations and skill-related activities.
12.10 Compliance
To comply with applicable labour, employment, tax, accounting, social-security, regulatory, statutory and legal requirements.
12.11 Security
To maintain website, network, system and workplace security and to prevent fraud, misuse, unauthorised access and unlawful activity.
12.12 Legal Claims and Dispute Resolution
To establish, exercise, protect or defend legal rights, claims and interests.
12.13 Business Administration
For internal management, auditing, record keeping, quality control, risk management, professional advice and business operations.
12.14 Future Opportunities
To contact candidates concerning other employment or workforce opportunities that may reasonably match their qualifications, skills, experience or preferences.
12.15 Other Lawful Purposes
For any additional purpose that is disclosed to the individual or otherwise permitted by applicable law.
13. LEGAL BASIS / AUTHORITY FOR PROCESSING
Depending on the nature of the activity and applicable law, the LLP may process personal data on the basis of:
- consent;
- requested services or recruitment activities;
- taking steps at the request of an individual before entering into an arrangement;
- performance or administration of a contract;
- compliance with applicable law or legal obligations;
- prevention, detection or investigation of fraud or unlawful activity;
- protection of legal rights;
- other legitimate and lawful business purposes recognised by applicable law; and
- other grounds permitted under the DPDP Act or other applicable law when the relevant provisions are in force.
The LLP will not rely upon consent where the law permits or requires processing on another lawful basis.
14. CONSENT
Where consent is required, the LLP will seek consent in an appropriate manner and for a specified purpose.
Consent may be provided electronically or through other lawful means.
Where applicable:
- consent will be capable of being demonstrated;
- an individual may withdraw consent;
- withdrawal will not affect processing lawfully carried out before withdrawal;
- withdrawal may affect our ability to provide certain services where the relevant processing is necessary and no alternative lawful basis exists; and
- a consent request will not be unnecessarily combined with unrelated purposes.
Where the DPDP Act and Rules apply, the LLP will provide notices and consent mechanisms in accordance with the applicable statutory requirements.
15. NOTICE AT THE POINT OF COLLECTION
Where personal data is collected directly from an individual, the LLP will endeavour to provide information concerning:
- the categories of personal data being collected;
- the purpose for which the information is processed;
- the manner in which the information may be used or shared;
- applicable rights and grievance mechanisms; and
- other information required by applicable law.
For online forms such as “Register for Work” or “Request Manpower”, the LLP may provide a short-form Privacy Policy in addition to this detailed Privacy Policy.
16. RECRUITMENT AND CANDIDATE DATA
Because recruitment and workforce management are core activities of the LLP, candidate information may be used throughout the recruitment lifecycle.
This may include:
- registration;
- candidate assessment;
- vacancy matching;
- client submission;
- interviews;
- reference checks;
- background verification;
- selection;
- onboarding;
- deployment;
- payroll or remuneration administration;
- statutory compliance; and
- consideration for future opportunities.
Candidates should ensure that all information provided is true, accurate, complete and not misleading.
17. SHARING CANDIDATE INFORMATION WITH CLIENTS
Where reasonably necessary for recruitment, placement or deployment, the LLP may share relevant candidate information with an existing or prospective employer/client.
Information may include, depending on the role:
- name;
- profile;
- qualifications;
- skills;
- experience;
- employment history;
- location;
- availability;
- professional information;
- remuneration expectations; and
- other relevant recruitment information.
The LLP will endeavour to limit such disclosure to information relevant to the position or workforce requirement.
Where required by applicable law, consent or other lawful authority will be obtained before such disclosure.
18. BACKGROUND VERIFICATION AND REFERENCE CHECKS
The LLP may perform or arrange appropriate background checks where reasonably necessary for recruitment, staffing, employment or deployment.
These may include:
- identity verification;
- educational qualification verification;
- professional qualification verification;
- previous employment verification;
- reference checks;
- experience verification;
- employment history verification;
- licence or certification verification;
- work eligibility verification; and
- other legally permissible checks relevant to the role.
Where a third-party verification provider is used, the LLP may share only information reasonably necessary for the relevant verification activity.
Any background verification will be carried out in accordance with applicable law.
19. EMPLOYEE AND WORKER DATA
For employees and workers, personal data may be processed for:
- recruitment;
- joining and onboarding;
- employment administration;
- attendance;
- deployment;
- payroll;
- statutory deductions and benefits;
- insurance and welfare administration;
- workplace safety;
- training;
- assignment management;
- client reporting where appropriate;
- leave administration;
- performance management;
- grievance administration;
- disciplinary matters;
- separation; and
- compliance with applicable employment and labour requirements.
20. FINANCIAL AND PAYMENT INFORMATION
Where required, the LLP may collect bank account and other payment-related information for:
- salary or wages;
- reimbursements;
- contractor payments;
- vendor payments;
- client billing;
- refunds; and
- accounting and statutory purposes.
The LLP will endeavour to restrict access to financial information to persons who require it for authorised purposes.
The LLP will not request authentication credentials such as OTPs, UPI PINs, passwords, ATM PINs or card CVVs.
21. DATA SHARING WITH THIRD PARTIES
Personal data may be shared with third parties where reasonably necessary and legally permissible, including:
21.1 Clients and Employers
For recruitment, placement, staffing and workforce deployment.
21.2 Service Providers
For hosting, cloud storage, software, recruitment technology, payroll, accounting, communication, cybersecurity, IT support and other authorised services.
21.3 Background Verification Agencies
For identity, education, employment, professional and reference verification.
21.4 Professional Advisers
Lawyers, accountants, auditors, consultants, insurers and other professional advisers.
21.5 Government and Statutory Authorities
Where disclosure is required or permitted by law.
21.6 Courts and Law-Enforcement Authorities
In response to lawful requests, orders, notices or proceedings.
21.7 Business Transaction Counterparties
In connection with a merger, restructuring, transfer, sale, acquisition, financing or similar transaction, subject to applicable law.
21.8 Other Persons
Where disclosure is necessary to protect the rights, property, safety or legitimate interests of the LLP or another person and such disclosure is legally permitted.
22. DATA PROCESSORS AND SERVICE PROVIDERS
The LLP may engage third parties to process personal data on its behalf.
Such parties may include:
- website hosts;
- cloud service providers;
- software providers;
- recruitment platforms;
- payroll providers;
- accounting service providers;
- background verification providers;
- communication service providers;
- technology consultants;
- cybersecurity service providers; and
- other professional or administrative service providers.
Where appropriate, the LLP may impose contractual confidentiality, security and purpose limitations on such providers.
Where the LLP processes data on behalf of a client under contractual instructions, the relationship between the LLP and the client may allocate the parties' respective responsibilities concerning personal data.
23. CLIENT DATA PROCESSING ARRANGEMENTS
Where the LLP acts in relation to personal data supplied by or controlled by a client, the applicable service agreement, work order or data-processing terms may prescribe:
- the purpose of processing;
- categories of personal data;
- categories of data subjects;
- permitted processing;
- confidentiality;
- security requirements;
- retention;
- deletion/return;
- data breach obligations; and
- rights and responsibilities of the parties.
Where contractual arrangements impose stricter requirements than this Policy, the applicable contractual requirements may govern the relevant processing activity.
24. DATA MINIMISATION
The LLP aims to collect and process only such personal data as is reasonably necessary for the specific purpose for which it is required.
Individuals should not submit information that is unrelated to:
- recruitment;
- employment;
- staffing;
- deployment;
- business enquiries;
- contractual obligations;
- statutory compliance; or
- another legitimate purpose identified by the LLP.
25. ACCURACY OF INFORMATION
Individuals are responsible for ensuring that information supplied to the LLP is accurate, complete and up to date.
The LLP may request clarification or updated information where necessary.
Where an individual believes that information held by the LLP is inaccurate or incomplete, a correction request may be made through the contact details provided in this Policy.
26. DATA RETENTION
The LLP does not intend to retain personal data indefinitely.
Personal data may be retained for the period reasonably necessary to:
- fulfil the purpose for which it was collected;
- maintain a recruitment or employment relationship;
- consider candidates for future opportunities;
- perform contractual obligations;
- comply with statutory or regulatory requirements;
- meet tax, accounting, labour or employment obligations;
- establish, exercise or defend legal claims;
- investigate fraud or security incidents;
- maintain necessary business records; or
- comply with lawful directions.
When personal data is no longer required, the LLP will take reasonable steps to delete, anonymise, archive or securely dispose of it, subject to applicable legal or contractual retention requirements.
| Category | Retention principle |
|---|---|
| Website enquiries | Until the enquiry is resolved and for a reasonable administrative period |
| Unsuccessful applications | Reasonable period for future opportunities, subject to applicable law |
| Candidate profiles | While relevant for recruitment/business purposes and for a reasonable future-opportunity period |
| Selected candidates/workers | During the relevant employment/deployment relationship and applicable statutory period |
| Employee records | As required by applicable law and legitimate business requirements |
| Payroll/payment records | Applicable statutory/accounting retention period |
| Client records | Contractual and statutory retention period |
| Complaints/grievances | Until resolution and for the legally required or reasonably necessary period |
| Security logs | Reasonable period required for security, troubleshooting and investigation |
The actual retention period may vary depending upon the nature of the data and applicable legal requirements.
27. SECURITY OF PERSONAL DATA
The LLP implements reasonable technical, organisational and administrative safeguards appropriate to the nature of the information processed.
These may include:
- controlled access;
- role-based access restrictions;
- authentication controls;
- confidentiality obligations;
- secure storage;
- backups;
- cybersecurity protections;
- logging and monitoring;
- access review;
- secure disposal;
- device and system safeguards;
- employee awareness and confidentiality measures; and
- contractual safeguards applicable to third-party processors.
Personal data that has been classified and flagged as sensitive children (including financial, health, biometric and genetic information) is subject to the heightened, documented controls, in addition to the general safeguards set out below.
The level of safeguards may depend upon the nature and sensitivity of the information, the technology used and the risks associated with processing.
No internet transmission, electronic communication or storage system can be guaranteed to be completely secure. Accordingly, although reasonable safeguards are used, absolute security cannot be guaranteed.
28. PERSONAL DATA BREACHES
The LLP maintains processes intended to detect, assess, contain, investigate and address suspected or actual personal data breaches.
Depending on the nature and severity of an incident, the LLP may:
- identify and contain the incident;
- investigate the nature and extent of the incident;
- assess potential impact and risk;
- take corrective and preventive measures;
- notify relevant persons or authorities where required;
- document the incident and response; and
- review controls to prevent recurrence.
Where the DPDP Act and Rules or other applicable law prescribe specific breach-notification requirements, the LLP will follow those requirements from their applicable commencement dates.
29. CROSS-BORDER PROCESSING
Some service providers, technology systems, cloud platforms or business counterparties may be located outside India.
Where personal data is processed or transferred outside India, the LLP will do so only as permitted by applicable law and subject to applicable restrictions, contractual safeguards and security requirements.
The LLP may revise its cross-border transfer practices to comply with restrictions or requirements notified by the Central Government or other competent authorities.
30. CHILDREN'S PERSONAL DATA
The LLP's principal services are intended for adults of working age, employers and organisations.
The LLP does not intentionally seek to collect personal data of children for ordinary recruitment, employment or manpower placement activities.
Where processing of a child's personal data becomes necessary for a lawful purpose, such processing will be carried out in accordance with applicable law and any additional requirements applicable to children.
Where there is reasonable doubt as to whether an individual seeking to interact with the LLP is a child under applicable law, the LLP will apply reasonable age-verification measures such as requesting confirmation of date of birth or a government-issued identity document before continuing to collect or process personal data through the relevant channel.
Where the LLP determines that processing a child's personal data is necessary for a lawful purpose, the LLP will not proceed with such processing until it has obtained verifiable consent from the child's parent or lawful guardian. This consent will be sought, recorded and administered through a documented parental consent process maintained by the LLP, setting out the purpose of processing, the categories of personal data involved, and the manner in which consent may be withdrawn.
As part of the parental consent process, the LLP will take reasonable steps to verify the identity of the parent or lawful guardian providing consent and their relationship to the child, which may include requesting a copy of a government-issued identification document or other reasonable proof of identity, before relying on the consent given.
Parental consent forms and related consent mechanisms used by the LLP will be reviewed periodically, including by or in consultation with legal counsel, to confirm they remain consistent with the requirements of the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, and other applicable law, and will be updated as necessary to reflect legal or regulatory developments.
31. COOKIES
The website may use cookies or similar technologies for purposes such as:
- enabling website functionality;
- security;
- session management;
- website performance;
- technical diagnostics;
- understanding usage; and
- improving the user experience.
Where non-essential analytics, advertising or other tracking technologies are used, the LLP may provide additional information and consent controls where required.
Users may change their browser settings to restrict cookies. Certain website functions may not operate correctly if cookies are disabled.
32. THIRD-PARTY WEBSITES AND SERVICES
The website may contain links to third-party websites, applications or services.
Examples may include:
- WhatsApp;
- social media platforms;
- recruitment platforms;
- payment services;
- maps;
- communication tools; or
- other external websites.
The LLP does not control the privacy practices of such third parties.
Use of a third-party service is subject to that third party's own privacy policy and terms.
33. DIRECT COMMUNICATIONS AND JOB ALERTS
The LLP may contact candidates or business contacts for purposes connected with:
- recruitment opportunities;
- job vacancies;
- workforce requirements;
- interview schedules;
- deployment;
- service enquiries;
- contractual matters;
- business communications; or
- other communications reasonably connected with the relationship.
Where promotional or other communications require consent under applicable law, the LLP will obtain appropriate consent.
An individual may request that non-essential communications be discontinued.
34. YOUR PRIVACY RIGHTS
Subject to applicable law and the commencement of relevant statutory provisions, individuals may have rights including:
- the right to obtain information concerning processing;
- the right to request correction of inaccurate or incomplete personal data;
- the right to request erasure where legally available;
- the right to withdraw consent where processing is based on consent;
- the right to raise a grievance;
- the right to nominate another person where such right is applicable;
- other rights provided under applicable law.
The DPDP Act, 2023 expressly provides for rights relating to access to information, correction and erasure, grievance redressal and nomination. These rights will operate in accordance with the applicable commencement dates, regulations and statutory conditions.
35. WITHDRAWAL OF CONSENT
Where processing is based upon consent, an individual may request withdrawal of consent through the contact details provided in this Policy or through any specific mechanism provided by the LLP.
Withdrawal of consent:
- will not affect processing lawfully carried out before withdrawal;
- may not be possible where processing is required under another lawful basis;
- may affect eligibility for certain services or opportunities where the relevant data is necessary; and
- will be handled subject to applicable law.
36. GRIEVANCE REDRESSAL
Individuals may contact the LLP regarding:
- privacy concerns;
- personal-data processing;
- requests for correction;
- requests for deletion;
- withdrawal of consent;
- unauthorised disclosure concerns;
- security concerns;
- candidate-data concerns; or
- other data-protection grievances.
Subject line may be stated as:
“Privacy / Data Protection Request”
The LLP may request reasonable information to verify the identity and authority of the person making a request before acting upon it.
37. REPRESENTATIVES AND AUTHORISED PERSONS
Where permitted under applicable law, an individual may exercise a privacy right through an authorised representative.
The LLP may request evidence of such authority before disclosing, correcting or deleting personal data.
38. LEGAL AND REGULATORY DISCLOSURES
The LLP may disclose personal data where reasonably necessary to:
- comply with law;
- comply with a court order;
- comply with a government or regulatory direction;
- respond to lawful demands;
- fulfil tax, labour, employment or social-security obligations;
- prevent or investigate fraud;
- protect the rights or property of the LLP;
- defend legal claims;
- protect a person's safety; or
- comply with other legally recognised requirements.
Where law permits discretion, disclosure will be limited to what is reasonably necessary for the relevant purpose.
39. CORPORATE TRANSACTIONS
In connection with:
- restructuring;
- merger;
- acquisition;
- sale of business;
- transfer of assets;
- financing;
- investment;
- reorganisation; or
- similar corporate transactions,
personal data may be disclosed to professional advisers, counterparties, investors, lenders, transaction advisers or other relevant parties where reasonably necessary and legally permissible.
Appropriate confidentiality and data-protection safeguards may be applied depending on the circumstances.
40. CONFIDENTIALITY
The LLP treats personal data as confidential information and seeks to limit access to persons who require the information for an authorised purpose.
Employees, partners, consultants, contractors, service providers and other persons with access to personal data may be subject to confidentiality obligations.
Confidentiality obligations may continue after the end of an employment, contractual or business relationship where appropriate.
41. DATA OF FORMER CANDIDATES, EMPLOYEES AND WORKERS
The LLP may continue to retain limited information relating to former candidates, employees or workers after the conclusion of a relationship where necessary for:
- future employment opportunities;
- statutory records;
- tax and accounting;
- legal claims;
- audits;
- dispute resolution;
- compliance;
- business records; or
- another lawful purpose.
Retention will remain subject to the principles and requirements set out in this Policy
42. PROFESSIONAL AND STATUTORY ADVISERS
The LLP may disclose relevant information to its:
- advocates;
- chartered accountants;
- company secretarial professionals;
- auditors;
- consultants;
- insurers;
- tax advisers;
- compliance professionals; and
- other professional advisers,
where necessary for lawful business, regulatory, financial, legal or compliance purposes.
43. FRAUD, MISUSE AND SECURITY
The LLP may process and disclose relevant information where reasonably necessary to:
- detect fraud;
- investigate suspected misconduct;
- prevent abuse of the website or recruitment process;
- protect systems and networks;
- detect security incidents;
- investigate unauthorised access;
- protect workers, candidates, clients or staff; or
- cooperate with lawful investigations.
44. DATA RELATING TO CLIENT EMPLOYEES AND WORKERS
Where services are provided to a client, the LLP may receive personal data relating to workers, employees or representatives of that client.
Such data may be processed for:
- workforce deployment;
- contract administration;
- attendance;
- site access;
- scheduling;
- reporting;
- payroll;
- safety;
- compliance;
- statutory obligations; and
- other services specifically agreed with the client.
The relevant contract may contain additional requirements governing the handling of such data.
45. SECURITY OF PHYSICAL DOCUMENTS
Where personal data is maintained in physical records, the LLP may use administrative and physical safeguards appropriate to the nature of the records, including:
- controlled access;
- secure storage;
- restricted circulation;
- confidentiality procedures;
- secure filing;
- controlled disposal; and
- other reasonable protective measures.
46. ELECTRONIC COMMUNICATION SECURITY
The LLP may use email, messaging applications, online systems, cloud services and electronic records for business activities.
Individuals should be aware that electronic communications can carry security risks.
The LLP will take reasonable measures to protect information but does not guarantee that electronic communications are completely immune from interception or unauthorised access.
47. YOUR RESPONSIBILITIES
Individuals using the LLP's services or submitting personal data should:
- provide accurate information;
- keep information updated where necessary;
- submit only information relevant to the stated purpose;
- avoid sharing authentication credentials;
- avoid sending unnecessary sensitive data;
- promptly notify the LLP of suspected misuse of their information; and
- use only authorised communication channels for sensitive submissions where instructed.
48. NO SALE OF PERSONAL DATA
The LLP does not sell personal data as a commercial product.
The sharing of candidate or worker information with clients for recruitment, placement, staffing or deployment does not constitute a sale of personal data merely because the LLP is compensated for its lawful recruitment or manpower services.
Any disclosure will remain subject to the purpose, contractual arrangements and applicable law.
49. AUTOMATED DECISION-MAKING
Unless specifically stated otherwise in connection with a particular service, the LLP does not intend to make decisions concerning candidates solely through automated processing without appropriate human involvement.
Where technology or software tools are used to assist recruitment or workforce administration, they may support human decision-making rather than necessarily replacing it.
50. DATA PROTECTION FOR BUSINESS CONTACTS
Personal data relating to client representatives, vendors and other professional contacts may be processed for:
- business communication;
- contract management;
- service delivery;
- meetings;
- quotations;
- invoicing;
- relationship management;
- compliance; and
- other legitimate business purposes.
51. UPDATES TO THIS PRIVACY POLICY
The LLP may revise this Privacy Policy from time to time due to:
- changes in applicable law;
- regulatory developments;
- changes to the DPDP framework;
- new or modified website functionality;
- changes in our business;
- changes in data-processing practices;
- introduction of new services; or
- changes in technology or security practices.
The updated policy will be published on the website with a revised “Last Updated” date.
Where applicable law requires specific notice or consent regarding a material change, the LLP will adopt the appropriate procedure.
52. RELATIONSHIP WITH OTHER NOTICES
This Privacy Policy should be read together with:
- candidate application forms;
- worker registration forms;
- employee documents;
- employment contracts;
- client agreements;
- data-processing agreements;
- consent forms;
- website notices;
- cookie notices; and
- other privacy or data-protection notices issued by the LLP.
Where a specific notice applies to a particular processing activity, that notice may provide additional details relevant to the activity.
53. SEVERABILITY
If any provision of this Privacy Policy is held to be invalid, unlawful or unenforceable, the remaining provisions shall continue to operate to the extent permitted by law.
54. NO WAIVER
Failure by the LLP to enforce any provision of this Privacy Policy at any particular time shall not constitute a waiver of its right to enforce that provision subsequently.
55. GOVERNING LAW AND JURISDICTION
This Privacy Policy shall be governed by the laws applicable in India.
Subject to mandatory provisions of applicable law, disputes concerning this Privacy Policy shall be subject to the jurisdiction of the competent courts and authorities having jurisdiction over the relevant matter.
56. CONTACT INFORMATION
Please use the contact details on our Contact page.
57. WEBSITE USER ACKNOWLEDGEMENT
By accessing or using the LLP's website, submitting an enquiry, registering for work, requesting manpower services or voluntarily providing personal data, you acknowledge that you have had an opportunity to review this Privacy Policy.
Where applicable law requires consent, the LLP will seek such consent through an appropriate consent mechanism rather than relying solely upon the existence of this Policy.
58. IMPORTANT SECURITY NOTICE
Siddhanath Resources LLP will not intentionally request your:
- OTP;
- UPI PIN;
- ATM PIN;
- debit/credit card PIN;
- internet banking password;
- account password; or
- CVV/security authentication credential
through ordinary email, WhatsApp, SMS or telephone communication.
If you receive a suspicious communication claiming to be from Siddhanath Resources LLP, please contact the LLP using the official contact details published on its website.
59. FINAL STATEMENT
Siddhanath Resources LLP is committed to handling personal data responsibly and to maintaining reasonable safeguards appropriate to the nature and purpose of the information processed.
The LLP will continue to review its privacy, security, consent, retention and grievance-management practices to respond to applicable legal and regulatory developments, including the phased implementation of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
