Legal
Privacy Notice
Last updated August 26, 2026 · Version 1.5
This notice is issued by Blucollarz Technologies Private Limited under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. It is standalone: you do not need any other document to understand what we collect, why, and how to withdraw consent or exercise your rights. Where the EU/UK GDPR applies to you, the same notice describes that processing. We have not appointed an EU Article 27 representative.
1. Who we are
Blucollarz Technologies Private Limited (“Blucollarz”, “we”, “us”) operates a verification and hiring platform for skilled workers heading abroad. For the personal data in this notice, Blucollarz is the Data Fiduciary (and the controller if GDPR applies). The person able to answer questions about processing is published on /grievance (grievance desk: support@blucollarz.com, Hyderabad, Telangana, India). This notice is in English. Hindi and other Eighth Schedule languages are available on request via that desk.
2. Itemised personal data, purpose, and service
We process the following personal data for the specified purposes. The service enabled is access to Blucollarz accounts, identity verification, job matching, and interviews. Blucollarz is not a Recruiting Agent and does not file emigration clearance.
- DigiLocker user id — unique candidate account id used to sign in and to identify you on the platform (contract).
- Google account name and email — recruiter and admin sign-in via Google sign-in on the recruiter or admin app (contract).
- Mobile number — account, OTP-style communication, and matching DigiLocker identity (consent: contact).
- PAN, Aadhaar (masked where required), name, date of birth, gender, address/location from DigiLocker / MeriPehchaan — verify identity, confirm you are 18 or older, and generate verification conclusions. Collected when you sign in with DigiLocker (consent: identity). Email and username are not collected from DigiLocker.
- Profile, skills, education, work history, languages — match you to roles using allowlisted resume fields collected during onboarding (consent / contract).
- Applications, AI interview transcripts, scores, answers, and recordings — evaluate you for a role when you grant evaluation consent. Scores assist a human employer; they do not hire you automatically (consent: evaluation).
- Medical fitness appointments and report files — booked only after an employer selects you, and only while medical consent is live. Employers never see the report files (consent: medical; health data).
- Hire company onboarding documents (establishment card, immigration file, licences) — verify the employer (contract).
- Support tickets and Help chats — resolve product issues.
- Device, browser, IP, and security logs — operate, secure, and debug the service. Processing logs are kept for one year.
- Optional analytics (Google Analytics): page usage after you allow analytics cookies. Off until you allow them.
Employers see allowlisted resume fields and interview evidence — not your raw DigiLocker documents, PAN, Aadhaar, DigiLocker user id, phone, date of birth, or address.
3. Consent
Verification and interview data are processed on consent. Signing in with DigiLocker is identity verification. You grant each purpose we use — identity, contact, interview evaluation, and medical fitness. Interview scores, transcripts, and recordings are shared with a hirer only while evaluation consent is live. Medical fitness data is processed only while medical consent is live, and only after an employer selects you. Consent must be free, specific, informed, unconditional, and unambiguous. You can withdraw it as easily as you gave it: Settings → Data rights → Withdraw, or email the grievance desk. Withdrawal does not undo processing already completed lawfully. Account operation also relies on using the service (contract).
5. What we never do
- Charge workers — employers pay platform fees
- Sell personal data, or share raw DigiLocker documents / PAN / Aadhaar / passport numbers with employers
- Use data beyond the purposes you consented to
- Track children or offer this service to anyone under 18
- Let an AI score be the sole decision that hires you
6. Who we share data with
- Vetted employers — allowlisted resume fields. Interview scores, transcripts, recordings, and answers only if you granted evaluation consent
- Licensed Recruiting Agent bound to a role (optional RC number) — hire-safe profile and evaluation data they need for that placement. We are not that agent and we do not file eMigrate.
- Verification sources (DigiLocker / MeriPehchaan) — the request needed to verify identity
- Processors under contract: MongoDB (database), Vercel (hosting / Blob), AI providers via Vercel AI Gateway, Sarvam (voice), Resend (email), DigiLocker / MeriPehchaan (candidate sign-in), Google (recruiter/admin OAuth; Analytics only if you allow)
- Authorities where required by law
7. How long we keep it
We keep data only as long as needed for the purposes above and for periods required by applicable law, then delete or anonymise it. Security and processing logs are retained for one year. When you delete your account from Settings, we remove your profile, applications, interviews, recordings, medical reports, hire company documents, consent events, and rights requests, then delete the stored files from private Blob (subject to any legal hold we must honour, which we will explain if it applies). If we later erase data because we no longer need it, DPDP Rules require 48 hours’ notice before that erasure; that countdown is not yet an automated worker-facing timer.
8. Your rights and how to use them
Under DPDP you may seek access, correction/completion, erasure, withdrawal of consent, nomination of another person, and grievance redressal. If GDPR applies to you, you may also seek restriction of processing, objection, and data portability through the same Settings queue.
- Signed-in: Settings → Data rights. Candidates are identified by DigiLocker user id; recruiters and admins by the Google email on the account. After you submit, use the request ID in any follow-up.
- Access and portability download a JSON package. Recording and medical-report files are linked as authorised same-origin downloads (`/api/blob/file`), not as raw cloud URLs.
- Correction is completed by updating your profile. Erasure is completed with Delete account after we verify it is you — submitting an erasure request does not wipe the account by itself.
- Restriction and objection are logged for the grievance desk to action. They do not automatically freeze every system.
- Not signed in, or you prefer email: write to support@blucollarz.com with the email on a recruiter/admin account, or the DigiLocker user id on a candidate account.
- We acknowledge promptly (target 72 hours) and resolve grievances within a reasonable period not exceeding 90 days.
- You may complain to the Data Protection Board of India if unresolved. If GDPR applies, you may also complain to your local supervisory authority. See /grievance.
9. Security and personal data breach
We apply reasonable security safeguards, including access control, encryption in transit, and processing logs. Private files have no shareable URL; they are streamed only after we re-check who you are. If a personal data breach occurs, we will inform affected people without delay (nature, extent, timing, likely consequences, what we did, what you can do, and who to contact). We will inform the Data Protection Board of India without delay and send a detailed report within 72 hours of becoming aware, or such further time as the Board permits. That filing is an operations action, not an automated product feature. If GDPR Art. 33 applies, we will also notify the competent supervisory authority within 72 hours where required.
10. International processing
Processors may store or process data outside India (for example cloud hosting in the United States). Those transfers happen under contract with our processors. India is not an EU adequacy country. We have not published Standard Contractual Clauses in this product. If GDPR applies to you and you object to those transfers, contact the grievance desk.
11. Children
Blucollarz is for persons 18 years or older. Before you create an account you must confirm you are 18 or older. We then confirm age from DigiLocker date of birth. We do not knowingly collect personal data from children. Accounts under 18 are refused. We do not offer parental-consent onboarding.
12. Automated scoring
AI interview scores and summaries are stored on the interview and shown to the hirer for that role while evaluation consent is live. A human employer decides whether to proceed. You can ask for the scores in an access export and raise a grievance if you contest them.
13. Marketing imagery
Photos on the public homepage are decorative marketing stills. They are not photos of your account and are not used to identify you.
14. Changes
We may update this notice and will post the new version with its effective date. A version bump re-prompts the site agreement before you can keep using the signed-in product. Contact the grievance desk via /grievance.