Privacy Policy

How Swiftcruit collects, uses, discloses, and protects personal data across our recruitment and technical-assessment platform.

Effective 07 August 2026 · Version 1.0

Summary

This Privacy Policy ("Policy") explains how Bitbillion Technologies OPC Pvt. Ltd. ("Swiftcruit," "Company," "we," "us," or "our"), a company registered in India with its office at WeWork Cinnabar Hills, HD-023, Embassy Golf Links Business Park, Bangalore, Karnataka, India, collects, uses, discloses, and protects personal data in connection with the Swiftcruit platform available at www.swiftcruit.ai and any related applications, features, or services that link to this Policy (collectively, the "Services").

Swiftcruit operates a dual-sided recruitment and technical-assessment platform used by both candidates and recruiters/employers. This Policy applies to both audiences and clearly marks where obligations differ. It is supplemented by our Terms of Use, Candidate Assessment & Proctoring Notice, AI & Automated Hiring Notice, and Cookies Policy, each of which is incorporated by reference where referenced below.

  • We act as controller for direct candidate services (accounts, public profiles, platform security) and as processor for recruiter-instructed hiring decisions and proctoring.
  • Proctoring, where enabled, is minimized by default and governed by a separate notice.
  • AI-assisted scores and flags are advisory only - no adverse hiring outcome is based solely on automated processing without human review.

See Sections 4, 9, and 10 for full detail.

1. Introduction and Scope

1.1 This Policy applies to all users of the Services, including candidates who create profiles or take assessments, and recruiters or employers who post jobs, source candidates, or administer assessments.

1.2 This Policy is designed to comply with the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), India's Digital Personal Data Protection Act, 2023 and its 2025 Rules ("DPDP Act"), Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA"), the Australian Privacy Act 1988 ("Australia Privacy Act"), and applicable U.S. state, UK, and EU employment-technology and AI regulation, including the EU AI Act.

1.3 Where a specific feature involves elevated risk - in particular proctoring and AI-assisted evaluation - this Policy is supplemented by a stand-alone notice referenced in the relevant section. Those stand-alone notices control over this Policy for the specific feature they describe, to the extent of any conflict.

2. Definitions

  • "Candidate" means an individual who creates an account to search for jobs, build a profile, or complete assessments.
  • "Recruiter" or "Customer" means an employer, staffing organization, or hiring team that uses Swiftcruit to post jobs, source candidates, or administer assessments.
  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Proctoring Data" means webcam snapshots or video, microphone audio, screen capture, and integrity-event logs captured during a monitored assessment.
  • "AI-Assisted Feature" means any function that uses machine-learning or generative-AI models to generate, score, rank, summarize, or flag content or candidates, including AI Match scoring, JD-to-assessment generation, and integrity detection.
  • "Controller" and "Processor" have the meanings given under GDPR Article 4.
  • "Recipient" means a third party to whom Personal Data is disclosed, including Customers and Service Providers.

3. Who We Are

3.1 For users in the EEA and UK where we do not have an establishment, we will appoint an EU/UK representative under Article 27 GDPR and UK GDPR as required, and will publish that representative's details here upon appointment.

Company (Data Fiduciary/Controller)Bitbillion Technologies OPC Pvt. Ltd.
Trading NameSwiftcruit
Registered AddressWeWork Cinnabar Hills, HD-023, Embassy Golf Links Business Park, Bangalore, Karnataka, India
Websitewww.swiftcruit.ai
Privacy / Compliance Contactcompliance@swiftcruit.ai
Data Protection OfficerSobiya Ameen - compliance@swiftcruit.ai

4. Our Role: Controller and Processor

4.1 Swiftcruit acts as an independent controller for: candidate account creation and authentication; public candidate profiles and job-browsing features; platform security and fraud prevention; product analytics and service improvement; marketing communications where you have opted in; and billing and subscription administration.

4.2 Swiftcruit acts as a processor or service provider, processing data on the instructions of the relevant Recruiter Customer, for: recruiter-managed assessments and scoring; candidate evaluation and shortlisting; proctoring enabled by a Customer for a specific role; and final hiring, rejection, or promotion decisions made by that Customer.

4.3 Where Swiftcruit independently determines the purpose or means of processing - for example, if assessment or proctoring data were used to improve Swiftcruit's own general-purpose models beyond narrowly-scoped quality assurance - Swiftcruit acts as an independent controller (or, where applicable, a joint controller) for that specific use, and will provide additional notice and, where required, obtain separate consent before doing so.

4.4 Recruiter Customers remain independently responsible for the lawfulness of their own hiring decisions, job postings, and jurisdiction-specific employment-law obligations. Our Terms of Use set out this allocation of responsibility in full.

5. Information We Collect

5.1 Information Candidates Provide

  • Account and contact data: name, email address, username, password or authentication token (Google/GitHub/LinkedIn sign-in).
  • Profile data: bio, skills, work history, education, links to external profiles (e.g., GitHub, LinkedIn), and profile photo, where provided.
  • Resume and portfolio data: uploaded resume files, extracted text, and inferred skills used for matching.
  • Assessment data: code submissions, written answers, execution logs, and, where AI-assisted tools are permitted within an assessment, prompts and tool-use logs.
  • Proctoring data (only where enabled for a specific assessment): webcam snapshots or video, microphone audio, screen-focus and tab-change events, and integrity-event logs, as described in our Candidate Assessment & Proctoring Notice.
  • Communications: messages sent to support, accommodation requests, or dispute submissions.

5.2 Information Recruiters Provide

  • Account and company data: work email, company name, billing administrator contact details.
  • Job posting data: job descriptions, requirements, location, and salary information.
  • Candidate-review data: shortlist actions, scorecards, notes, and messages entered while evaluating candidates.

5.3 Information Collected Automatically

  • Device and log data: IP address, browser type, device identifiers, operating system, and access timestamps.
  • Cookies and similar technologies: as described in our Cookies Policy, including essential, analytics, and (where consented) advertising technologies.
  • Usage data: pages visited, features used, session duration, and error/crash reports.

5.4 Information From Other Sources

  • Third-party ATS and job-source integrations (e.g., Ashby, Workday), which supply job listings displayed on the platform.
  • Identity or login providers (Google, GitHub, LinkedIn), where you choose to sign in using those services.
  • Recruiter Customers, where they upload or submit candidate information directly (for example, importing a candidate into their workspace).

5.5 Payment Data

Where subscriptions or paid credits are enabled, payments are processed by our third-party payment processor. We receive limited billing metadata (plan, invoice records, transaction status) but do not store full card details where a hosted or tokenized checkout is used.

6. How We Use Personal Data and Our Legal Bases

The table below sets out our principal processing purposes and the legal basis relied upon under GDPR/UK GDPR. Where we act as a processor for a Recruiter Customer (Section 4.2), the underlying legal basis is determined by that Customer; Swiftcruit processes strictly on their documented instructions.

PurposeExample ActivitiesLegal Basis (GDPR/UK GDPR)
Account creation & authenticationCreating and securing candidate/recruiter accountsContract
Job matching & practice recommendationsResume parsing, AI Match score generationContract; Legitimate interests
Assessment delivery & scoringHosting assessments, generating AI scorecardsContract (Customer); Processor instruction
Proctoring / integrity verificationWebcam snapshots, integrity flagsConsent; Customer instruction (Processor)
Public profile hostingDisplaying candidate profile to recruiters/webConsent (opt-in to public visibility)
Platform security & fraud preventionLog monitoring, abuse detectionLegitimate interests
Product analytics & improvementAggregated usage analysisLegitimate interests; Consent (cookies)
Marketing communicationsOpt-in newsletters, product updatesConsent
Billing & subscription managementInvoicing, renewal processingContract; Legal obligation (tax)
Legal compliance & dispute defenseResponding to regulators, legal holdsLegal obligation

7. Public Candidate Profiles

7.1 Depending on your visibility settings, your candidate profile may be public, private, or limited-visibility. Public profiles may be indexed by search engines and viewed by recruiters or other users without a Swiftcruit account.

7.2 If you make your profile public, profile fields, linked accounts, portfolio information, and resume-derived data may become visible beyond the Swiftcruit platform. You may change your visibility settings at any time; changes take effect promptly but we cannot guarantee immediate removal from third-party caches or search engine indexes already generated before the change.

7.3 We recommend reviewing your visibility settings before publishing sensitive information (such as current employer, if you are passively job-seeking) in a public profile.

8. AI-Assisted Features and Automated Decision-Making

8.1 Swiftcruit offers AI-assisted features to both candidates and recruiters, including: generating assessments from job descriptions; computing AI job-match scores; summarizing candidate submissions; generating reviewer scorecards; and detecting integrity events during assessments. These features are described in full in our AI & Automated Hiring Notice.

8.2 AI outputs are probabilistic, may be incomplete or incorrect, and are treated as advisory decision-support only. Recruiter Customers are contractually prohibited from relying solely on an AI-generated score, match, or integrity flag as the sole basis for a materially adverse employment decision where applicable law requires meaningful human review, including under GDPR Article 22, and we build our review workflows accordingly.

8.3 You may request an explanation of an AI-influenced outcome that materially affects you, and may contest that outcome, by contacting compliance@swiftcruit.ai. A human reviewer will assess contested outcomes where required by law or our own policy.

8.4 We do not perform emotion recognition on candidates in connection with hiring or evaluation. Where the Services process facial or vocal data for identity-verification purposes (see Section 9), we do not infer emotional state, and we do not use this data to profile candidates beyond the stated integrity-verification purpose.

9. Proctoring and Assessment Monitoring

9.1 Where a Recruiter Customer enables proctoring for a specific assessment, we and that Customer may process Proctoring Data - by default, periodic webcam snapshots rather than continuous recording, wherever feasible - to verify identity, deter impersonation, and investigate suspected integrity violations.

9.2 We do not create biometric templates or facial-geometry scans from Proctoring Data, and we do not perform emotion recognition, unless a specific, separately-consented, jurisdiction-cleared feature is introduced in the future, in which case this Policy and the Candidate Assessment & Proctoring Notice will be updated in advance.

9.3 You will always receive a separate, just-in-time Candidate Assessment & Proctoring Notice before any webcam, microphone, or screen access begins, describing exactly what is captured, how long it is kept, who can access it, and how to request an accommodation or contest a flag.

9.4 Default retention for unflagged Proctoring Data is short (see Section 13). Flagged, disputed, or legally-held sessions are retained longer, as described in the Proctoring Notice and Section 13 below. We do not retain Proctoring Data on a blanket multi-year basis.

9.5 Access to Proctoring Data is limited to trained reviewers, authorized Customer personnel, and a limited number of Swiftcruit support, security, or legal personnel on a need-to-know basis.

10. Cookies, Analytics, and Advertising Technologies

10.1 We use essential technologies necessary to operate the Services (login, security, load balancing, consent storage), and, where you consent, analytics technologies (to measure usage and improve the Services) and advertising technologies (for marketing attribution).

10.2 Non-essential cookies and trackers do not fire until you provide consent through our cookie-consent tool, where required by law. You may manage your preferences at any time from the Cookies Policy page or the Cookie Settings link in our footer.

10.3 We do not run advertising or session-replay technologies inside assessment or proctoring environments, or on pages displaying candidate resumes, scorecards, or recordings.

10.4 A current, accurate list of the specific cookies and trackers in use, including provider, purpose, duration, and data-transfer destination, is maintained in our Cookies Policy.

10.5 Where required by law, we recognize recognized opt-out preference signals, including the Global Privacy Control (GPC), for users in jurisdictions such as California.

11. How We Share Personal Data

11.1 We may disclose Personal Data to the following categories of recipients:

  • Recruiter Customers - candidate application, profile, assessment, and (where enabled) proctoring data relevant to roles you apply for or are sourced for.
  • Service Providers - hosting, infrastructure, authentication (e.g., Firebase), analytics, security, and customer support vendors, acting on our instructions under written data processing terms.
  • Payment processors - for subscription and billing administration.
  • ATS and job-source integration partners - to synchronize job listings and, where applicable, application routing.
  • Professional advisers and regulators - where necessary for legal compliance, audits, or to establish, exercise, or defend legal claims.
  • An acquirer or successor - in connection with a merger, financing, reorganization, or sale of assets, subject to confidentiality safeguards.

We do not sell Personal Data for money. If our use of analytics or advertising technologies is treated as a "sale," "sharing," or targeted-advertising activity under applicable law (such as the CCPA/CPRA), we provide the required opt-out mechanisms described in Section 10 and Section 15.2.

12. International Data Transfers

12.1 Swiftcruit is based in India and may process Personal Data in India and other countries where our Service Providers operate infrastructure, including the United States.

12.2 Where we transfer Personal Data originating from the EEA or UK to a country not recognized as providing an adequate level of protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable.

12.3 Cross-border transfers of Personal Data governed by India's DPDP Act are made in accordance with any conditions or country-specific restrictions notified by the Indian government from time to time.

12.4 We take reasonable steps to ensure recipients of Personal Data, wherever located, provide a standard of protection consistent with this Policy and applicable law.

13. Data Retention

We retain Personal Data only for as long as necessary for the purpose it was collected, taking into account contractual commitments, fraud prevention, legal defense, and statutory obligations. The table below summarizes our standard retention periods. A full internally-maintained retention schedule governs day-to-day deletion operations, and is summarized for reference on our Data Retention Schedule page.

We do not create biometric templates from Proctoring Data (Section 9.2); accordingly no separate biometric-template retention period applies unless and until such a feature is introduced with prior notice and consent.

Data CategoryStandard Retention
Candidate account dataActive account + 30-90 days after deletion request
Recruiter/employer account dataActive contract + legal/tax tail (up to 7 years)
Public candidate profileUntil visibility changed or account deleted
Resume & parsed profile dataTied to account; unused uploads purged on a short cycle
Job aggregation data (ATS-sourced)Removed promptly upon expiry or source removal
Application & redirect data30-90 days, operational period only
Assessment content & code logsPer Customer contract term; short default if none specified
Proctoring - unflagged snapshots/video30-90 days
Proctoring - flagged/disputed sessions180-365 days, or longer under legal hold
AI scorecards & AI match-score reportsAligned with assessment content retention
Analytics & marketing cookiesShortest period the tool allows; session-level where possible
Subscription, billing & invoicesPer applicable tax/accounting law (typically 6-10 years)
Customer support communications1-3 years
Security & authentication logs6-12 months
DSAR / rights-request records2-3 years after closure
Consent recordsDuration of processing plus applicable limitation period

14. Data Security

14.1 We implement technical and organizational measures designed to protect Personal Data, including encryption in transit and, where appropriate, at rest; access controls limiting internal access on a need-to-know basis; logging and monitoring; environment isolation; and incident-response procedures. Further detail is set out in our Security Policy.

14.2 We state compliance, certification, or audit claims (such as GDPR/CCPA alignment, ISO 27001, or SOC 2) only where current and evidenced. Where a certification is in progress or planned rather than achieved, we will describe it accurately as such rather than as an achieved status. Current certification status is available on request at compliance@swiftcruit.ai.

14.3 Proctoring Data and other sensitive evidence are encrypted, access-controlled, and access-logged. Integrity flags are recorded separately from final human review decisions, so that an automated flag is never indistinguishable from an adverse outcome.

14.4 No method of transmission or storage is completely secure. While we use commercially reasonable measures, we cannot guarantee absolute security, and we encourage you to use strong, unique passwords and enable available account security features.

15. Your Privacy Rights

Depending on your location, you have some or all of the following rights regarding your Personal Data. To exercise any right, contact us at compliance@swiftcruit.ai or our Data Protection Officer, Sobiya Ameen, at the same address, or use our Data Request process. We will verify your identity before fulfilling certain requests and will respond within the timeframe required by applicable law.

15.1 European Economic Area and United Kingdom (GDPR / UK GDPR)

You have the right to: access your Personal Data; request correction of inaccurate data; request erasure; withdraw consent at any time; receive a portable copy of data you provided; object to processing based on legitimate interests; request restriction of processing; and lodge a complaint with your local supervisory authority (or the UK Information Commissioner's Office).

15.2 California (CCPA/CPRA)

California residents have the right to: know what Personal Information we collect, use, and disclose; access and receive a copy of that information; request correction; request deletion; opt out of the sale or sharing of Personal Information (we do not sell Personal Information, and we honor recognized opt-out signals such as GPC for any sharing that may occur through analytics/advertising technologies); limit use of sensitive Personal Information; and not be discriminated against for exercising these rights.

15.3 India (DPDP Act, 2023)

As a Data Principal, you have the right to: obtain a summary of the Personal Data we process about you; request correction, completion, and updating of your Personal Data; request erasure once the purpose of processing is no longer being served; withdraw consent at any time, as easily as it was given; nominate another individual to exercise your rights in the event of death or incapacity; and file a complaint with the Data Protection Board of India.

15.4 Canada (PIPEDA)

You have the right to access your Personal Information, request correction, withdraw consent (subject to legal or contractual restrictions), and file a complaint with the Office of the Privacy Commissioner of Canada.

15.5 Australia (Privacy Act 1988)

You have the right to access your Personal Information, request correction, and lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the Australian Privacy Principles.

15.6 U.S. State-Specific Notes

Residents of Illinois should note that we do not create biometric templates or scans of face geometry from Proctoring Data (Section 9.2); if this changes, a separate BIPA-compliant notice and consent process will apply before launch.

Residents of New York City should note that if any Swiftcruit scoring tool is used by a Customer as an Automated Employment Decision Tool under NYC law for a role based in New York City, the relevant Customer is responsible for obtaining any required independent bias audit and providing candidate notice, and Swiftcruit will support that process on request.

16. Account Deletion

16.1 You may delete your candidate or recruiter account at any time via account settings or by contacting compliance@swiftcruit.ai.

16.2 Upon deletion, we delete or anonymize your account data, subject to the retention exceptions in Section 13 (for example, billing records retained for tax compliance, or data subject to an active legal hold).

16.3 Deleting your account does not automatically delete data already shared with, or exported by, a Recruiter Customer as part of a hiring process you participated in. Such data is governed by that Customer's own retention practices; our Terms of Use require Customers to handle exported data responsibly, and we will pass along deletion requests to the relevant Customer where required by law.

17. Children's Privacy

The Services are a professional recruitment and hiring platform, not directed at children, and are not intended for use by individuals below the applicable working or data-consent age in their jurisdiction. We do not knowingly collect Personal Data from children. If we become aware that we have inadvertently done so, we will take reasonable steps to delete that data.

18. Third-Party Job Sources and Integrations

18.1 Swiftcruit aggregates job listings from third-party sources, including Applicant Tracking Systems such as Ashby and Workday, to display on the platform and support AI Match scoring and practice features.

18.2 We maintain removal service levels for expired or withdrawn listings and rely on source-provided validity data to keep listings current. If you believe a listing is inaccurate or expired, contact compliance@swiftcruit.ai.

18.3 Applying to a role through an external company site, after being routed from Swiftcruit, is governed by that employer's own privacy practices for the application itself; Swiftcruit's role is limited to the routing and match-scoring activity described in this Policy.

19. Subscriptions and Payment Data

19.1 Payments are processed by a PCI DSS-compliant third-party payment processor. Full card details are not stored by Swiftcruit where a hosted or tokenized checkout is used. A current list of our payment and subprocessor partners is available on request at compliance@swiftcruit.ai.

19.2 Billing metadata (plan, invoice history, transaction status, tax information) is retained as required by applicable tax and accounting law, as set out in Section 13.

19.3 Auto-renewal, cancellation, and refund mechanics are governed by Section 8 of our Terms of Use, which this Policy incorporates by reference for data-handling purposes.

20. Contesting an AI-Influenced or Proctoring-Related Outcome

20.1 If you believe an assessment score, integrity flag, or AI-generated match score materially and adversely affected you, you may request a human review by contacting compliance@swiftcruit.ai within a reasonable time after the outcome. We will investigate and provide a response consistent with our obligations under GDPR Article 22 and equivalent local law.

20.2 Requests for accommodation relating to an assessment or proctoring session should be directed to compliance@swiftcruit.ai, ideally before the session, or as soon as practicable afterward.

21. Changes to This Policy

21.1 We may update this Policy to reflect changes in our practices, technology, legal requirements, or product features. Material changes will be notified via the "Effective" date above and, where required by law, by email or in-product notice.

21.2 Each version of this Policy is assigned a version number, and prior versions are retained internally for audit purposes and can be produced on request where relevant to a specific rights request.

21.3 Continued use of the Services after an update takes effect constitutes acknowledgment of the updated Policy.

22. Relationship to Our Terms of Use

22.1 This Policy is incorporated into, and should be read together with, our Terms of Use. Disputes concerning this Policy are governed by the law and dispute resolution mechanism set out in those Terms.

22.2 Nothing in our Terms of Use, including any arbitration or dispute resolution clause, limits or waives your right to lodge a complaint with a competent data protection authority or regulator, including the Data Protection Board of India, the UK ICO, an EU supervisory authority, the OPC (Canada), or the OAIC (Australia).

23. Contact Us

For any question, concern, or rights request regarding this Policy or our data practices, please contact:

Company NameBitbillion Technologies OPC Pvt. Ltd. (Swiftcruit)
Registered AddressWeWork Cinnabar Hills, HD-023, Embassy Golf Links Business Park, Bangalore, Karnataka, India
Compliance / Privacy Emailcompliance@swiftcruit.ai
Data Protection OfficerSobiya Ameen - compliance@swiftcruit.ai
Websitewww.swiftcruit.ai