Gensact

Privacy Policy

Last updated 24 August 2026

1. Two roles, stated plainly

For the account details you give us - your name, email, phone, company, billing records - we are the data fiduciary under India's Digital Personal Data Protection Act, 2023. For the data you bring into your workspace - your clients, leads, invoices, candidates, employees, correspondence - you are the fiduciary and we process it on your instructions as the platform operator.

2. What we collect

  • Account data: name, email, phone, company details, plan and payment records (card/UPI details are held by our payment providers, never by us).
  • Workspace data: whatever your business puts in - CRM records, documents, books, candidate applications and resumes, mailbox connections. Mail read through the inbox stays on your mail server; we store the connection, not the messages.
  • Usage data: product events and AI usage counts per workspace (used for allowances and billing), and standard technical logs.
  • Marketing attribution: the /start funnel and tenant sites record campaign parameters (UTM, click IDs) in a first-party cookie - marketing parameters only, no personal profile.

3. How data is protected

  • Every workspace's data is isolated per tenant and verified by an automated scoping audit on every release.
  • Credentials - mailbox passwords, API keys, payment secrets - live in an encrypted vault reachable only by the service layer, never through public APIs, and are write-only in the interface (never shown back).
  • Client-facing pages carry no data of any other customer; access is decided by account membership and role.

4. AI processing

AI features send the relevant workspace content (for example, the figures behind a daily brief, a candidate's resume for screening, a report digest) to our AI provider (Anthropic) to generate the output you asked for, metered per workspace. If you connect your own AI key, that processing runs on your own provider account instead. We do not use your workspace data to train models.

5. Retention and erasure

  • Workspace data is retained while your subscription is active and for a reasonable export window after termination, then deleted. Non-payment never deletes data - it only makes the workspace read-only.
  • Recruitment data has its own rule: candidates who are not hired are anonymised after a configurable window (default 365 days) - identity redacted, answers cleared, files deleted. Hired candidates' records persist as employment records.
  • Deleting a workspace removes its records - including tasks, filings, candidates, usage and history - through cascading deletion.

6. Sharing

We share personal data only with the processors that make the Service work - hosting and database infrastructure, payment providers (Razorpay, Cashfree), our AI provider, and email delivery - each bound to process it for us, and with authorities where the law requires. We do not sell personal data.

7. Your rights

For account data, you may access, correct, or ask us to erase your personal data, and may complain to the Data Protection Board of India. Write to privacy@gensact.com - we respond within the timelines the DPDP Act prescribes. For data inside a customer's workspace, direct your request to that business; we support them in honouring it.

8. Changes

We will notify workspace owners of material changes to this policy by email and in the product before they take effect.