Data Processing Addendum
Effective 3 October 2026 · Last updated 3 October 2026
Version v1.0. When your organization uses Roleora’s employer features, Roleora processes candidate personal data, applications and directory profiles, on your instructions and for your purpose, hiring. Under India’s Digital Personal Data Protection Act 2023, section 8(2), you are the Data Fiduciary for that candidate data and Roleora is a Data Processor acting on your behalf. This is the reverse of our main Privacy Policy, where Roleora is the Fiduciary and the providers below are its processors. This Addendum is between KNETT IT INFRASTRUCTURE AND SOLUTIONS PRIVATE LIMITED ("Roleora", "we", "us") as Processor and your organization as Fiduciary, and forms part of the Terms of Service.
1. Scope and purpose
We process candidate personal data only to operate the opening a candidate applied to, or the directory invitation flow your organization uses, and for no other purpose. "Candidate Personal Data" means the data in an application share pack and any opted-in directory profile your organization accesses.
2. Our obligations as processor
- We process Candidate Personal Data only on your documented instructions, which for a product like Roleora are the actions your own users take in the Roleora console;
- recruiter notes your users write about a candidate are never shown to the candidate and stay within your organization’s own account;
- we do not use Candidate Personal Data to train AI models, and we do not resell it, the same three commitments that already apply to every Roleora account;
- we do not add a new subprocessor for employer data without updating the versioned list in Section 4 below.
3. Security measures
The same measures described in our Privacy Policy, Section 11, apply to Candidate Personal Data: encryption in transit and at rest, tenant isolation enforced on every database query, short-lived signed URLs for file access, rate limiting, and audit logging.
4. Subprocessors
The same infrastructure that already handles all Roleora data also handles employer and candidate data. Every subprocessor below is real and in current use, confirmed against our own configuration:
| Subprocessor | What it processes | Region |
|---|---|---|
| Microsoft Azure — Cosmos DB for MongoDB | All application data, including employer and candidate data | Central India |
| Microsoft Azure — Container Apps | Hosts the Roleora API | Central India |
| Microsoft Azure — Static Web Apps | Hosts the marketing site | East Asia |
| Microsoft Azure — Blob Storage | Uploaded documents (resumes, certificates) | Central India |
| Microsoft Azure OpenAI | AI document generation for candidates. Not used in any employer-facing route: no employer-side AI ranking or screening | Sweden Central |
| Microsoft Azure AI Speech | Voice interview transcription and practice interviewer (candidate-side only) | Central India |
| Microsoft Azure AI Vision | OCR for scanned PDF uploads | East US |
| Microsoft Azure Communication Services | OTP and service emails, including employer-side notifications such as claim OTP and application stage changes | Central India |
| Microsoft Azure Key Vault | Holds signing keys and secrets; no data at rest | Central India |
| Microsoft Azure Application Insights | Operational logs and diagnostics | Central India |
| Razorpay | Payment processing. Employer features are free at v1, so Razorpay does not process employer or candidate data unless a paid employer tier ships | India |
| OAuth login only. Receives only what a standard login handshake requires, no candidate data | N/A | |
| GitHub | OAuth login, and a separate opt-in integration that syncs a user’s own GitHub activity | N/A |
| Connector sources a member turns on | Credly, Open Badges issuers, DEV.to, Hashnode, Medium, Substack, Codeforces, HackerRank, Stack Overflow, ORCID with OpenAlex and Crossref, YouTube, WakaTime, Toggl and Clockify. Only the handle, link or key the member supplies is sent, to read that member’s own public work. No employer or application data is sent | N/A |
We keep a visible "last updated" date at the top of this page and update the version number whenever a subprocessor is added, removed, or changed.
5. Candidate rights assistance
A candidate withdrawing an application revokes your organization’s access to that application’s shared data immediately and automatically. Access, correction, and erasure of the underlying Roleora account data are covered by Privacy Policy Section 6. Stage history and recruiter notes you have recorded remain your own responsibility as Data Fiduciary for that data.
6. Data breach notification
If a breach affects Candidate Personal Data your organization has accessed, we will notify you without undue delay, separately from the DPDP-mandated notification to affected individuals and the Data Protection Board of India described in Privacy Policy Section 10.
7. Acceptance
This Addendum is accepted by your organization’s admin when claiming your organization’s page on Roleora, by checking:
I have read and accept the Data Processing Addendum on behalf of [organization].
8. Governing law
This Addendum is governed by the laws of India, matching Terms of Service Section 12, unless your organization has separately negotiated a signed agreement stating otherwise.