How Swiftcruit collects, uses, discloses, and protects personal data across our recruitment and technical-assessment platform.
Effective 07 August 2026 · Version 1.0
This Privacy Policy ("Policy") explains how Bitbillion Technologies OPC Pvt. Ltd. ("Swiftcruit," "Company," "we," "us," or "our"), a company registered in India with its office at WeWork Cinnabar Hills, HD-023, Embassy Golf Links Business Park, Bangalore, Karnataka, India, collects, uses, discloses, and protects personal data in connection with the Swiftcruit platform available at www.swiftcruit.ai and any related applications, features, or services that link to this Policy (collectively, the "Services").
Swiftcruit operates a dual-sided recruitment and technical-assessment platform used by both candidates and recruiters/employers. This Policy applies to both audiences and clearly marks where obligations differ. It is supplemented by our Terms of Use, Candidate Assessment & Proctoring Notice, AI & Automated Hiring Notice, and Cookies Policy, each of which is incorporated by reference where referenced below.
See Sections 4, 9, and 10 for full detail.
1.1 This Policy applies to all users of the Services, including candidates who create profiles or take assessments, and recruiters or employers who post jobs, source candidates, or administer assessments.
1.2 This Policy is designed to comply with the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), India's Digital Personal Data Protection Act, 2023 and its 2025 Rules ("DPDP Act"), Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA"), the Australian Privacy Act 1988 ("Australia Privacy Act"), and applicable U.S. state, UK, and EU employment-technology and AI regulation, including the EU AI Act.
1.3 Where a specific feature involves elevated risk - in particular proctoring and AI-assisted evaluation - this Policy is supplemented by a stand-alone notice referenced in the relevant section. Those stand-alone notices control over this Policy for the specific feature they describe, to the extent of any conflict.
3.1 For users in the EEA and UK where we do not have an establishment, we will appoint an EU/UK representative under Article 27 GDPR and UK GDPR as required, and will publish that representative's details here upon appointment.
| Company (Data Fiduciary/Controller) | Bitbillion Technologies OPC Pvt. Ltd. |
| Trading Name | Swiftcruit |
| Registered Address | WeWork Cinnabar Hills, HD-023, Embassy Golf Links Business Park, Bangalore, Karnataka, India |
| Website | www.swiftcruit.ai |
| Privacy / Compliance Contact | compliance@swiftcruit.ai |
| Data Protection Officer | Sobiya Ameen - compliance@swiftcruit.ai |
4.1 Swiftcruit acts as an independent controller for: candidate account creation and authentication; public candidate profiles and job-browsing features; platform security and fraud prevention; product analytics and service improvement; marketing communications where you have opted in; and billing and subscription administration.
4.2 Swiftcruit acts as a processor or service provider, processing data on the instructions of the relevant Recruiter Customer, for: recruiter-managed assessments and scoring; candidate evaluation and shortlisting; proctoring enabled by a Customer for a specific role; and final hiring, rejection, or promotion decisions made by that Customer.
4.3 Where Swiftcruit independently determines the purpose or means of processing - for example, if assessment or proctoring data were used to improve Swiftcruit's own general-purpose models beyond narrowly-scoped quality assurance - Swiftcruit acts as an independent controller (or, where applicable, a joint controller) for that specific use, and will provide additional notice and, where required, obtain separate consent before doing so.
4.4 Recruiter Customers remain independently responsible for the lawfulness of their own hiring decisions, job postings, and jurisdiction-specific employment-law obligations. Our Terms of Use set out this allocation of responsibility in full.
Where subscriptions or paid credits are enabled, payments are processed by our third-party payment processor. We receive limited billing metadata (plan, invoice records, transaction status) but do not store full card details where a hosted or tokenized checkout is used.
The table below sets out our principal processing purposes and the legal basis relied upon under GDPR/UK GDPR. Where we act as a processor for a Recruiter Customer (Section 4.2), the underlying legal basis is determined by that Customer; Swiftcruit processes strictly on their documented instructions.
| Purpose | Example Activities | Legal Basis (GDPR/UK GDPR) |
|---|---|---|
| Account creation & authentication | Creating and securing candidate/recruiter accounts | Contract |
| Job matching & practice recommendations | Resume parsing, AI Match score generation | Contract; Legitimate interests |
| Assessment delivery & scoring | Hosting assessments, generating AI scorecards | Contract (Customer); Processor instruction |
| Proctoring / integrity verification | Webcam snapshots, integrity flags | Consent; Customer instruction (Processor) |
| Public profile hosting | Displaying candidate profile to recruiters/web | Consent (opt-in to public visibility) |
| Platform security & fraud prevention | Log monitoring, abuse detection | Legitimate interests |
| Product analytics & improvement | Aggregated usage analysis | Legitimate interests; Consent (cookies) |
| Marketing communications | Opt-in newsletters, product updates | Consent |
| Billing & subscription management | Invoicing, renewal processing | Contract; Legal obligation (tax) |
| Legal compliance & dispute defense | Responding to regulators, legal holds | Legal obligation |
7.1 Depending on your visibility settings, your candidate profile may be public, private, or limited-visibility. Public profiles may be indexed by search engines and viewed by recruiters or other users without a Swiftcruit account.
7.2 If you make your profile public, profile fields, linked accounts, portfolio information, and resume-derived data may become visible beyond the Swiftcruit platform. You may change your visibility settings at any time; changes take effect promptly but we cannot guarantee immediate removal from third-party caches or search engine indexes already generated before the change.
7.3 We recommend reviewing your visibility settings before publishing sensitive information (such as current employer, if you are passively job-seeking) in a public profile.
8.1 Swiftcruit offers AI-assisted features to both candidates and recruiters, including: generating assessments from job descriptions; computing AI job-match scores; summarizing candidate submissions; generating reviewer scorecards; and detecting integrity events during assessments. These features are described in full in our AI & Automated Hiring Notice.
8.2 AI outputs are probabilistic, may be incomplete or incorrect, and are treated as advisory decision-support only. Recruiter Customers are contractually prohibited from relying solely on an AI-generated score, match, or integrity flag as the sole basis for a materially adverse employment decision where applicable law requires meaningful human review, including under GDPR Article 22, and we build our review workflows accordingly.
8.3 You may request an explanation of an AI-influenced outcome that materially affects you, and may contest that outcome, by contacting compliance@swiftcruit.ai. A human reviewer will assess contested outcomes where required by law or our own policy.
8.4 We do not perform emotion recognition on candidates in connection with hiring or evaluation. Where the Services process facial or vocal data for identity-verification purposes (see Section 9), we do not infer emotional state, and we do not use this data to profile candidates beyond the stated integrity-verification purpose.
9.1 Where a Recruiter Customer enables proctoring for a specific assessment, we and that Customer may process Proctoring Data - by default, periodic webcam snapshots rather than continuous recording, wherever feasible - to verify identity, deter impersonation, and investigate suspected integrity violations.
9.2 We do not create biometric templates or facial-geometry scans from Proctoring Data, and we do not perform emotion recognition, unless a specific, separately-consented, jurisdiction-cleared feature is introduced in the future, in which case this Policy and the Candidate Assessment & Proctoring Notice will be updated in advance.
9.3 You will always receive a separate, just-in-time Candidate Assessment & Proctoring Notice before any webcam, microphone, or screen access begins, describing exactly what is captured, how long it is kept, who can access it, and how to request an accommodation or contest a flag.
9.4 Default retention for unflagged Proctoring Data is short (see Section 13). Flagged, disputed, or legally-held sessions are retained longer, as described in the Proctoring Notice and Section 13 below. We do not retain Proctoring Data on a blanket multi-year basis.
9.5 Access to Proctoring Data is limited to trained reviewers, authorized Customer personnel, and a limited number of Swiftcruit support, security, or legal personnel on a need-to-know basis.
10.1 We use essential technologies necessary to operate the Services (login, security, load balancing, consent storage), and, where you consent, analytics technologies (to measure usage and improve the Services) and advertising technologies (for marketing attribution).
10.2 Non-essential cookies and trackers do not fire until you provide consent through our cookie-consent tool, where required by law. You may manage your preferences at any time from the Cookies Policy page or the Cookie Settings link in our footer.
10.3 We do not run advertising or session-replay technologies inside assessment or proctoring environments, or on pages displaying candidate resumes, scorecards, or recordings.
10.4 A current, accurate list of the specific cookies and trackers in use, including provider, purpose, duration, and data-transfer destination, is maintained in our Cookies Policy.
10.5 Where required by law, we recognize recognized opt-out preference signals, including the Global Privacy Control (GPC), for users in jurisdictions such as California.
11.1 We may disclose Personal Data to the following categories of recipients:
We do not sell Personal Data for money. If our use of analytics or advertising technologies is treated as a "sale," "sharing," or targeted-advertising activity under applicable law (such as the CCPA/CPRA), we provide the required opt-out mechanisms described in Section 10 and Section 15.2.
12.1 Swiftcruit is based in India and may process Personal Data in India and other countries where our Service Providers operate infrastructure, including the United States.
12.2 Where we transfer Personal Data originating from the EEA or UK to a country not recognized as providing an adequate level of protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable.
12.3 Cross-border transfers of Personal Data governed by India's DPDP Act are made in accordance with any conditions or country-specific restrictions notified by the Indian government from time to time.
12.4 We take reasonable steps to ensure recipients of Personal Data, wherever located, provide a standard of protection consistent with this Policy and applicable law.
We retain Personal Data only for as long as necessary for the purpose it was collected, taking into account contractual commitments, fraud prevention, legal defense, and statutory obligations. The table below summarizes our standard retention periods. A full internally-maintained retention schedule governs day-to-day deletion operations, and is summarized for reference on our Data Retention Schedule page.
We do not create biometric templates from Proctoring Data (Section 9.2); accordingly no separate biometric-template retention period applies unless and until such a feature is introduced with prior notice and consent.
| Data Category | Standard Retention |
|---|---|
| Candidate account data | Active account + 30-90 days after deletion request |
| Recruiter/employer account data | Active contract + legal/tax tail (up to 7 years) |
| Public candidate profile | Until visibility changed or account deleted |
| Resume & parsed profile data | Tied to account; unused uploads purged on a short cycle |
| Job aggregation data (ATS-sourced) | Removed promptly upon expiry or source removal |
| Application & redirect data | 30-90 days, operational period only |
| Assessment content & code logs | Per Customer contract term; short default if none specified |
| Proctoring - unflagged snapshots/video | 30-90 days |
| Proctoring - flagged/disputed sessions | 180-365 days, or longer under legal hold |
| AI scorecards & AI match-score reports | Aligned with assessment content retention |
| Analytics & marketing cookies | Shortest period the tool allows; session-level where possible |
| Subscription, billing & invoices | Per applicable tax/accounting law (typically 6-10 years) |
| Customer support communications | 1-3 years |
| Security & authentication logs | 6-12 months |
| DSAR / rights-request records | 2-3 years after closure |
| Consent records | Duration of processing plus applicable limitation period |
14.1 We implement technical and organizational measures designed to protect Personal Data, including encryption in transit and, where appropriate, at rest; access controls limiting internal access on a need-to-know basis; logging and monitoring; environment isolation; and incident-response procedures. Further detail is set out in our Security Policy.
14.2 We state compliance, certification, or audit claims (such as GDPR/CCPA alignment, ISO 27001, or SOC 2) only where current and evidenced. Where a certification is in progress or planned rather than achieved, we will describe it accurately as such rather than as an achieved status. Current certification status is available on request at compliance@swiftcruit.ai.
14.3 Proctoring Data and other sensitive evidence are encrypted, access-controlled, and access-logged. Integrity flags are recorded separately from final human review decisions, so that an automated flag is never indistinguishable from an adverse outcome.
14.4 No method of transmission or storage is completely secure. While we use commercially reasonable measures, we cannot guarantee absolute security, and we encourage you to use strong, unique passwords and enable available account security features.
Depending on your location, you have some or all of the following rights regarding your Personal Data. To exercise any right, contact us at compliance@swiftcruit.ai or our Data Protection Officer, Sobiya Ameen, at the same address, or use our Data Request process. We will verify your identity before fulfilling certain requests and will respond within the timeframe required by applicable law.
You have the right to: access your Personal Data; request correction of inaccurate data; request erasure; withdraw consent at any time; receive a portable copy of data you provided; object to processing based on legitimate interests; request restriction of processing; and lodge a complaint with your local supervisory authority (or the UK Information Commissioner's Office).
California residents have the right to: know what Personal Information we collect, use, and disclose; access and receive a copy of that information; request correction; request deletion; opt out of the sale or sharing of Personal Information (we do not sell Personal Information, and we honor recognized opt-out signals such as GPC for any sharing that may occur through analytics/advertising technologies); limit use of sensitive Personal Information; and not be discriminated against for exercising these rights.
As a Data Principal, you have the right to: obtain a summary of the Personal Data we process about you; request correction, completion, and updating of your Personal Data; request erasure once the purpose of processing is no longer being served; withdraw consent at any time, as easily as it was given; nominate another individual to exercise your rights in the event of death or incapacity; and file a complaint with the Data Protection Board of India.
You have the right to access your Personal Information, request correction, withdraw consent (subject to legal or contractual restrictions), and file a complaint with the Office of the Privacy Commissioner of Canada.
You have the right to access your Personal Information, request correction, and lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the Australian Privacy Principles.
Residents of Illinois should note that we do not create biometric templates or scans of face geometry from Proctoring Data (Section 9.2); if this changes, a separate BIPA-compliant notice and consent process will apply before launch.
Residents of New York City should note that if any Swiftcruit scoring tool is used by a Customer as an Automated Employment Decision Tool under NYC law for a role based in New York City, the relevant Customer is responsible for obtaining any required independent bias audit and providing candidate notice, and Swiftcruit will support that process on request.
16.1 You may delete your candidate or recruiter account at any time via account settings or by contacting compliance@swiftcruit.ai.
16.2 Upon deletion, we delete or anonymize your account data, subject to the retention exceptions in Section 13 (for example, billing records retained for tax compliance, or data subject to an active legal hold).
16.3 Deleting your account does not automatically delete data already shared with, or exported by, a Recruiter Customer as part of a hiring process you participated in. Such data is governed by that Customer's own retention practices; our Terms of Use require Customers to handle exported data responsibly, and we will pass along deletion requests to the relevant Customer where required by law.
The Services are a professional recruitment and hiring platform, not directed at children, and are not intended for use by individuals below the applicable working or data-consent age in their jurisdiction. We do not knowingly collect Personal Data from children. If we become aware that we have inadvertently done so, we will take reasonable steps to delete that data.
18.1 Swiftcruit aggregates job listings from third-party sources, including Applicant Tracking Systems such as Ashby and Workday, to display on the platform and support AI Match scoring and practice features.
18.2 We maintain removal service levels for expired or withdrawn listings and rely on source-provided validity data to keep listings current. If you believe a listing is inaccurate or expired, contact compliance@swiftcruit.ai.
18.3 Applying to a role through an external company site, after being routed from Swiftcruit, is governed by that employer's own privacy practices for the application itself; Swiftcruit's role is limited to the routing and match-scoring activity described in this Policy.
19.1 Payments are processed by a PCI DSS-compliant third-party payment processor. Full card details are not stored by Swiftcruit where a hosted or tokenized checkout is used. A current list of our payment and subprocessor partners is available on request at compliance@swiftcruit.ai.
19.2 Billing metadata (plan, invoice history, transaction status, tax information) is retained as required by applicable tax and accounting law, as set out in Section 13.
19.3 Auto-renewal, cancellation, and refund mechanics are governed by Section 8 of our Terms of Use, which this Policy incorporates by reference for data-handling purposes.
20.1 If you believe an assessment score, integrity flag, or AI-generated match score materially and adversely affected you, you may request a human review by contacting compliance@swiftcruit.ai within a reasonable time after the outcome. We will investigate and provide a response consistent with our obligations under GDPR Article 22 and equivalent local law.
20.2 Requests for accommodation relating to an assessment or proctoring session should be directed to compliance@swiftcruit.ai, ideally before the session, or as soon as practicable afterward.
21.1 We may update this Policy to reflect changes in our practices, technology, legal requirements, or product features. Material changes will be notified via the "Effective" date above and, where required by law, by email or in-product notice.
21.2 Each version of this Policy is assigned a version number, and prior versions are retained internally for audit purposes and can be produced on request where relevant to a specific rights request.
21.3 Continued use of the Services after an update takes effect constitutes acknowledgment of the updated Policy.
22.1 This Policy is incorporated into, and should be read together with, our Terms of Use. Disputes concerning this Policy are governed by the law and dispute resolution mechanism set out in those Terms.
22.2 Nothing in our Terms of Use, including any arbitration or dispute resolution clause, limits or waives your right to lodge a complaint with a competent data protection authority or regulator, including the Data Protection Board of India, the UK ICO, an EU supervisory authority, the OPC (Canada), or the OAIC (Australia).
For any question, concern, or rights request regarding this Policy or our data practices, please contact:
| Company Name | Bitbillion Technologies OPC Pvt. Ltd. (Swiftcruit) |
| Registered Address | WeWork Cinnabar Hills, HD-023, Embassy Golf Links Business Park, Bangalore, Karnataka, India |
| Compliance / Privacy Email | compliance@swiftcruit.ai |
| Data Protection Officer | Sobiya Ameen - compliance@swiftcruit.ai |
| Website | www.swiftcruit.ai |