Privacy Policy

Last updated: 25 August 2026

1. Who we are

This notice is issued by OTOMEYT AI (INDIA) PRIVATE LIMITED (CIN: U74900KA2015FTC083041), a company incorporated in India and registered with the Registrar of Companies, Bangalore, trading as Otomeyt AI (“Otomeyt”, “we”, “us”).

Registered office: HM Vibha Towers, No.66/5-25, Hosur Rd, 7th Block, Koramangala, Bengaluru, Karnataka 560030.

We provide AI-native talent technology and services, including assessments (MeritEdge), candidate engagement (TalentEdge), hire-a-thons, staffing, recruitment process outsourcing (RPO), and related workforce solutions.

2. Scope of this notice

This notice applies to personal data we process in connection with:

  • this website, otomeyt.ai (and related marketing pages such as staging.otomeytai.com);
  • contact, demo, and hire-a-thon enquiry forms;
  • on-site chat and similar communications tools;
  • our role as a technology and services provider to employers and as an operator of candidate-facing products, including gethired.otomeyt.ai, where no more specific product notice applies.

Product workspaces configured for a client, and data processed only on that client’s instructions, are also governed by the client’s privacy notice and by our contract with that client, including our Data Processing Addendum. If those documents conflict with this notice for processor activity, the contract and DPA control.

3. When we are a controller and when we are a processor

We are a controller when we decide why and how personal data is used. That includes website visitors; people who submit contact, demo, or hire-a-thon forms; chat users; marketing recipients we contact on our own behalf; and candidate accounts we operate for our own platform (for example, creating a gethired.otomeyt.ai profile that is not solely a client assignment).

We are a processor when an employer, staffing client, or other business customer (“client”) instructs us to process candidate or employee data in our products or services — for example assessments, matching, engagement, interviewing support, RPO delivery, or hire-a-thons run for that client. In that case the client is the controller. We process that data only on documented instructions, as described in the client contract and DPA.

We are not a joint controller with a client unless a written agreement says so.

4. Information we collect

a. Information you provide
Name, work or personal email, phone number, company, job title, message content, openness to a job change, CVs and job applications, assessment responses, and similar hiring information. This website’s forms are for business enquiries; they do not collect payment card data. Billing for paid services, if any, is handled under the relevant contract or product flow, not on this marketing site.

b. Information collected automatically
IP address, browser and device data, pages viewed, timestamps, referrer, approximate location derived from IP, and similar usage data — for analytics, only if you allow analytics cookies (Section 12).

c. Information from clients and other sources
Clients may upload or invite candidates and share role requirements. We may also receive information from publicly available professional sources or service providers, where lawful, to operate hiring workflows.

5. Sensitive / special-category data

This marketing website is not designed to collect sensitive personal data (for example health, disability, race or ethnicity, religion, biometric identifiers, or sexual orientation). Please do not include that information in a contact or demo form. If you do, we will use it only to handle your enquiry and then delete it where we can.

CVs, assessments, video interviews, and psychometric or behavioural exercises on our platforms can include sensitive data or allow inferences about it. We do not require that data unless a client’s process or applicable law requires it. Where we act as processor, we handle it on the client’s instructions and with the safeguards in our contract. Where we act as controller, we process it only where a lawful basis applies (including explicit consent where required) and only for the hiring or platform purpose concerned.

6. How we use information and lawful bases

We use personal data to:

  • operate this website and respond to enquiries and demo requests;
  • provide assessments, reports, matching, engagement, and hiring workflows;
  • provide customer support, including chat if you allow it;
  • send service and, where permitted, marketing communications (you may opt out);
  • secure our systems, prevent fraud and abuse, and debug;
  • analyse usage so we can improve products and this website, if you allow analytics;
  • comply with law and enforce our agreements.

Where GDPR or similar laws apply and we are controller, our bases are: performance of a contract or steps at your request (enquiries, accounts); legitimate interests (running a B2B website, securing it, relevant B2B outreach), balanced against your rights; consent (non-essential cookies, certain marketing); and legal obligation.

Where India’s Digital Personal Data Protection Act, 2023 (DPDP Act) applies, we process digital personal data for the purposes described in this notice, based on consent where required, or for the legitimate uses recognised by that Act (including employment-related purposes and compliance with law).

7. AI and automated decision-making

Our products use machine learning and similar techniques to score or rank skills, match candidates to roles, summarise or structure assessment performance, and support engagement (for example reminders or recommended next steps). Those outputs are decision-support for recruiters and hiring managers. The employer or client remains responsible for hiring decisions unless a written contract says otherwise.

We do not use contact-form, demo-form, or website-chat submissions to train assessment or matching models. Whether platform or client-supplied candidate data is used to improve models is set out in the applicable product terms or customer DPA and follows the client’s instructions when we are a processor.

If a jurisdiction gives you rights regarding automated decision-making (including GDPR Article 22 or equivalent DPDP rules), you may ask for information about the logic involved, request human review of a decision that produces legal or similarly significant effects, and contest that decision. For hiring run by a client, make that request to the client as well as, or instead of, us. You can also contact compliance@otomeyt.ai.

8. How we share information

We share personal data only as follows:

  • Service providers (processors) who host, analyse, communicate, or support our operations, listed in Section 9;
  • Affiliates in our corporate group, for the same purposes as we use the data, under appropriate safeguards;
  • Clients / employers when you apply, take an assessment, or are presented as part of a hiring process they control;
  • Professional advisers and authorities where required by law or to protect rights, safety, or security;
  • A buyer or successor if we are involved in a merger, acquisition, or similar corporate transaction.

We do not sell personal data for money. We do not license your data to unrelated third parties so they can market to you without your consent. Sharing with named processors and with a client in a hiring process is not a “sale”. Some analytics cookies may be “sharing” under California law; you can opt out at Do Not Sell or Share.

9. Subprocessors we use on this website

As of 25 August 2026, the following providers process personal data for this website and related marketing communications. Platform products may use additional processors disclosed in the DPA or on request.

ProviderRoleTypical location
Amazon Web ServicesHosting and content delivery for this site (AWS Amplify / CloudFront)India (ap-south-1) and AWS edge locations
GoogleGoogle Analytics 4 and Google Tag Manager (only if you allow analytics)United States and other Google regions
MicrosoftMicrosoft Clarity session replay (only if you allow analytics)United States and other Microsoft regions
FreshworksCRM web forms (contact / demo / hire-a-thon); chat only if you allow communications cookiesUnited States, India, and other Freshworks regions

We will update this section when we add or replace a material website processor. Customers who have a DPA with us receive subprocessor notice as that agreement requires.

10. International transfers

Our primary hosting region for this website is AWS Asia Pacific (Mumbai), ap-south-1, in India. Some providers in Section 9 process data in other countries, including the United States.

If we transfer personal data out of the EEA, UK, or another region that restricts exports, we use a lawful mechanism — typically the provider’s data processing terms, including standard contractual clauses or an equivalent transfer tool where the provider offers one. Transfers from India are made in line with the DPDP Act and any government rules on cross-border processing then in force.

You may request more detail on transfer safeguards from compliance@otomeyt.ai.

11. Notice at collection

We collect enquiry data when you submit a form on this site or message us via chat. At those points we tell you (including via a link to this notice) that we will use your details to respond to you and, where relevant, to follow up about our products. Analytics and session-replay data are collected only after you accept analytics cookies, or if you later change cookie settings to allow them.

If a client invites you to an assessment or hiring workflow, that client should also provide its own notice. This page is the notice for processing we control.

12. Cookies, analytics, and session replay

We use a cookie banner so you can accept all, reject non-essential cookies, or customise. Necessary cookies (hosting, security, and storing your choice) always run. You can reopen the banner from Cookie settings in the footer.

  • Necessary: hosting and security cookies set by AWS / Amplify / CloudFront, and the consent cookie that stores your choice (12 months).
  • Analytics (opt-in): Google Analytics 4 and Google Tag Manager (pages viewed, approximate location, device). Microsoft Clarity (clicks, scrolling, session replay). Clarity is designed to mask many form fields; do not type secrets into non-password fields.
  • Communications (opt-in): Freshworks chat. Contact, demo, and hire-a-thon forms still load on those pages so you can send an enquiry; they are not used as site-wide tracking.

California residents can also opt out of analytics “sharing” on the Do Not Sell or Share page. We honour a Global Privacy Control (GPC) signal by defaulting analytics off. You may still use browser settings to block cookies.

13. Data retention

Unless a longer period is required by law, a dispute, or a written client contract, we apply these periods:

RecordRetention
Website enquiry, demo, and hire-a-thon leads24 months from last meaningful contact
Marketing opt-out / suppressionUntil you ask us to remove the suppression record, and no longer than 7 years for proving we honoured the opt-out
Website chat transcripts12 months
Google Analytics14 months
Microsoft Clarity session replay13 months
Security and access logs12 months
Candidate / client platform data (we are processor)Per client instructions; after the services end, 90 days then delete unless law or a dispute requires longer
Candidate accounts we controlLife of the account, then 24 months after last login, then delete or anonymise unless law requires longer
BackupsUp to 90 days after deletion from live systems

You may request earlier deletion at compliance@otomeyt.ai where the law allows.

14. How to exercise your rights (DSR)

Email compliance@otomeyt.ai with “Privacy request” in the subject and say what you want (access, correction, deletion, restriction, portability, objection, or withdrawal of consent). If we act only as a processor for a client, we will point you to that client where appropriate.

  • We will acknowledge your request within 7 days of receipt.
  • We will complete it within 30 days (GDPR / UK GDPR and DPDP grievances) or 45 days (CCPA/CPRA), starting when we receive a verifiable request.
  • We may extend once, for as long as the applicable law allows, and we will tell you why.
  • We may ask for information reasonably needed to verify you (and any authorized agent). We will not fulfil a request until we can verify it, except opt-out of sale/sharing, which we will honour on this browser immediately via Cookie settings or the Do Not Sell page.
  • Portable copies, where required, are provided in a commonly used electronic format (typically CSV or JSON).

15. Security

We use encryption in transit, access control, and organisational measures appropriate to the risk. We maintain an information security management system and are ISO 9001 and ISO 27001 compliant. No method of transmission or storage is completely secure.

16. Personal data breach

If we become aware of a personal data breach, we will investigate, contain, and remediate it. Where we are the controller, we will notify the competent supervisory authority without undue delay and, where required, within 72 hours of becoming aware, and we will notify affected individuals when the law requires it (including under the DPDP Act in the prescribed manner).

Where we are a processor, we will notify the client without undue delay and in any event within 48 hours of becoming aware, as set out in the DPA, unless law prohibits the notice. The client decides how to notify regulators and individuals unless the law requires us to do so directly.

17. Your rights (including DPDP, GDPR, and California)

Depending on where you live, you may have the right to access, correct, update, or delete personal data; withdraw consent; nominate another person to exercise rights on your behalf (DPDP); restrict or object to certain processing; receive a portable copy; opt out of sale or sharing; and complain to a supervisory authority or, in India, to the Data Protection Board of India.

EEA/UK users may also have rights related to automated decision-making (Section 7). California residents may request to know, delete, and correct personal information, and to opt out of sale or sharing. We do not sell personal information for money. Analytics cookies, if you allow them, may be “sharing”. Opt out here: Do Not Sell or Share My Personal Information. We will not discriminate against you for exercising these rights. You may use an authorized agent as described on that page. We do not have actual knowledge of selling or sharing personal information of consumers under 16.

18. Grievance Officer (DPDP Act)

For grievances under the DPDP Act, contact our Grievance Officer:

Grievance Officer
OTOMEYT AI (INDIA) PRIVATE LIMITED
Email: compliance@otomeyt.ai
Address: HM Vibha Towers, No.66/5-25, Hosur Rd, 7th Block, Koramangala, Bengaluru, Karnataka 560030

We will acknowledge grievances within 7 days and aim to resolve them within 30 days, or sooner if a shorter statutory period applies.

19. Children’s privacy

Our services are not directed to children under 18. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact us and we will delete it.

20. Third-party links

Our website may link to third-party sites, including client career pages and gethired.otomeyt.ai. Their privacy practices are their own.

21. Changes

We may update this notice. We will change the “Last updated” date above. Material changes will be highlighted on this page or communicated by email where appropriate.

22. Contact us

Privacy questions, requests, and complaints:

OTOMEYT AI (INDIA) PRIVATE LIMITED
Email: compliance@otomeyt.ai
Registered office: HM Vibha Towers, No.66/5-25, Hosur Rd, 7th Block, Koramangala, Bengaluru, Karnataka 560030