Privacy Policy

Effective Date: January 1, 2025  |  Last Updated: August 2025

Gensar IT Solution Private Limited ("Gensar," "we," "our," or "us")

1. Introduction & Scope

Gensar IT Solution Private Limited is committed to protecting the privacy, confidentiality, and integrity of all personal data entrusted to us. This Privacy Policy applies to all individuals who interact with our website, digital platforms, recruitment portals, and professional service engagements across our global operations in India, the United States, and the UAE.

Our services span IT consulting, software development, staffing solutions, corporate training, healthcare operations (including medical billing, medical coding, and clinical data management), BPO/KPO services, and internship programs. This policy governs how personal data is handled across all these business verticals.

By using our website or engaging with our services, you consent to the practices described herein. If you do not agree with any part of this policy, please discontinue use of our website and services immediately.

2. Information We Collect

We collect information through various touchpoints depending on the nature of your engagement with us:

2.1 Directly Provided Information
  • Full legal name, date of birth, gender, email address, phone number, and residential address
  • Resume/CV, portfolio links, professional certifications, employment history, and educational qualifications
  • Government-issued identification documents for employment verification, background screening, and regulatory compliance
  • Bank account details, PAN card, Aadhaar number, tax identification, and payroll information for staffing and contract engagements
  • Healthcare professional credentials, medical coding certifications (CPC, CCS, RHIA), and HIPAA compliance training records
  • Client feedback, survey responses, and communication records
2.2 Automatically Collected Information
  • IP address, browser type and version, operating system, device identifiers, and screen resolution
  • Pages visited, time spent on each page, navigation paths, referral sources, and exit points
  • Cookie identifiers, session tokens, and authentication state
  • Location data derived from IP address (country and city level only)
2.3 Third-Party Sourced Information
  • Employment verification data from previous employers and professional references
  • Background check results from authorized screening agencies (with your explicit consent)
  • Publicly available professional profile information from LinkedIn, job boards, and professional directories
  • Client-provided data for staffing engagements (candidate shortlists, project requirements, performance evaluations)

3. Legal Basis for Data Processing

We process personal data under one or more of the following lawful bases:

  • Contractual Necessity: Processing required to fulfill staffing agreements, employment contracts, service delivery obligations, and recruitment mandates
  • Legal Obligation: Compliance with Indian IT Act 2000, GDPR (for EU-based candidates), HIPAA (for healthcare operations), labor laws, tax regulations, and anti-money laundering requirements
  • Legitimate Interest: Business analytics, service improvement, fraud prevention, security monitoring, and direct marketing to existing clients
  • Explicit Consent: Newsletter subscriptions, marketing communications, cookie preferences, and processing of sensitive personal data (health information, financial data)

4. How We Use Your Information

Personal data collected is used exclusively for the following business purposes:

  • Recruitment & Staffing: Candidate screening, skill-matching with client requirements, interview scheduling, offer management, onboarding, payroll processing, and performance tracking
  • Service Delivery: Executing IT consulting engagements, software development projects, medical billing/coding assignments, BPO operations, and corporate training programs
  • Client Management: Project communication, deliverable tracking, invoice processing, and relationship management
  • Marketing & Outreach: Sending service updates, industry insights, event invitations, and thought leadership content (with opt-out capability)
  • Regulatory Compliance: Maintaining records as required by labor laws, tax authorities, healthcare regulations, and data protection legislation
  • Security & Fraud Prevention: Detecting unauthorized access, preventing fraudulent applications, protecting intellectual property, and maintaining system integrity

5. Data Security & Safeguards

We implement a comprehensive, multi-layered security framework to protect personal data against unauthorized access, alteration, disclosure, or destruction:

  • Industry-standard AES-256 encryption for data at rest and TLS 1.3 encryption for data in transit
  • SOC 2 Type II compliant infrastructure with role-based access controls and multi-factor authentication
  • Annual third-party penetration testing, vulnerability assessments, and security audits
  • Employee training on data protection, confidentiality obligations, and incident response procedures
  • HIPAA-compliant handling of Protected Health Information (PHI) for medical billing and coding operations, including Business Associate Agreements (BAAs) with all healthcare clients
  • Incident response team with documented breach notification procedures (72-hour notification to affected parties and regulatory authorities)

6. Data Sharing & Third-Party Disclosure

We do not sell, rent, or trade personal data. Information is shared only under the following circumstances:

  • Client Engagements: Candidate profiles, resumes, and relevant professional information are shared with prospective clients for staffing placements (with prior candidate consent)
  • Service Providers: Trusted third-party vendors (cloud hosting, payment processing, background verification, HR management platforms) who operate under strict Data Processing Agreements (DPAs)
  • Legal Requirements: Disclosure to government authorities, courts, or regulatory bodies when legally mandated, or to protect Gensar's legal rights, property, or safety
  • Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, with appropriate notice provided to affected individuals

7. Data Retention

Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected:

  • Recruitment Data: Active candidate profiles retained for 24 months from last interaction; unsuccessful candidates' data deleted after 12 months unless explicit consent for longer retention is provided
  • Employment Records: Retained for the duration of employment plus 7 years as mandated by Indian labor laws and tax regulations
  • Client Records: Retained for the duration of the business relationship plus 5 years for audit and compliance purposes
  • Healthcare Data (PHI): Handled per HIPAA requirements — minimum 6-year retention for medical billing/coding records; specific retention periods as per client BAA terms
  • Marketing Data: Retained until the individual exercises opt-out rights or withdraws consent

8. Your Data Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of all personal data we hold about you in a structured, machine-readable format
  • Right to Rectification: Request correction of inaccurate or incomplete personal data
  • Right to Erasure: Request deletion of your personal data where there is no compelling legal or business reason for continued retention
  • Right to Restrict Processing: Request limitation of processing activities in specific circumstances
  • Right to Data Portability: Receive your personal data in a commonly used, machine-readable format for transfer to another organization
  • Right to Object: Object to processing based on legitimate interests, including direct marketing
  • Right to Withdraw Consent: Withdraw previously given consent at any time, without affecting the lawfulness of processing prior to withdrawal

To exercise any of these rights, please submit a written request to privacy@gensargroup.com. We will respond within 30 days of receiving your verified request.

9. International Data Transfers

As a global organization operating across India, the United States, and the UAE, personal data may be transferred between our offices and to authorized service providers in other jurisdictions. Such transfers are protected by:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (for EU-origin data)
  • Adequate contractual protections with recipients in jurisdictions without equivalent data protection laws
  • Compliance with the Indian Digital Personal Data Protection Act (DPDPA) 2023 cross-border transfer provisions

10. Cookie Policy

Our website uses cookies and similar tracking technologies to enhance user experience and gather analytical data. For detailed information, please refer to our Cookie Policy.

11. Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that personal data of a child has been collected without appropriate parental consent, we will take immediate steps to delete such information.

12. Changes to This Policy

We reserve the right to update this Privacy Policy at any time to reflect changes in our practices, legal requirements, or business operations. Material changes will be communicated via email notification to registered users and prominently displayed on our website. The "Last Updated" date at the top of this page indicates the most recent revision.

13. Contact Us

For questions, concerns, or requests related to this Privacy Policy or our data practices, please contact:

Data Protection Officer

Gensar IT Solution Private Limited

privacy@gensargroup.com

+91 91219 12138

Manjeera Trinity, 402, 4th Floor, KPHB, Hyderabad – 500072, India