1. Introduction & Scope
This Privacy Policy applies to all products, services, and websites offered by Akasha Inc. (collectively, the "Services"). We respect the privacy of our enterprise clients, their authorized users ("Recruiters", "Hiring Managers"), and the individuals applying for positions through our Applicant Tracking System ("Candidates").
Our core mission is to provide rigorous, unbiased AI-driven candidate evaluation without compromising data sovereignty. This document outlines exactly how we collect, process, transfer, and delete your data.
2. Information Collection
2.1 Information from Enterprise Users
When you register for an Akasha Workspace, we collect your name, corporate email address, and cryptographic authentication credentials (JWT sessions). We may also collect payment and billing metadata via our authorized third-party payment processors.
2.2 Information from Candidates
Candidates interacting with public campaign forms submit personal data directly to the Workspace Owner's isolated environment. This data may include:
- Contact information (Name, Email, Phone number).
- Professional documentation (Resumes, CVs, Portfolios) hosted securely via our Cloudinary integration.
- Public repository URLs (e.g., GitHub, GitLab) for code evaluation purposes.
3. AI Processing & Data Sovereignty
Given the sensitive nature of source code and proprietary architectures, Akasha implements a strict Zero-Training Policy:
- Local Processing: Structural audits are performed using localized models. Code structural trees are analyzed in-memory and discarded post-evaluation.
- Cloud Processing: When domain-driven design is evaluated using cloud LLMs (such as Gemini or Groq), the transmission is strictly encrypted via TLS 1.3. We enforce zero-data-retention agreements with these providers, ensuring your candidates' source code is never used to train foundational models.
4. Data Retention and Deletion Lifecycle
Workspace Owners act as the Data Controller under GDPR, while Akasha acts as the Data Processor.
When a candidate record is flagged for deletion by a Workspace Owner, a cascading hard-delete is triggered across our infrastructure. This includes the removal of the candidate's MongoDB document and the execution of the Cloudinary Admin API to permanently destroy any attached resumes or PDFs. Backups are purged on a rolling 30-day basis.
5. International Data Transfers
Akasha complies with the EU-U.S. Data Privacy Framework (DPF) and the UK Extension to the EU-U.S. DPF. When candidate data is transferred from the European Economic Area (EEA) to the United States, we rely on Standard Contractual Clauses (SCCs) to ensure the data is protected with an equivalent level of security.
6. Contact & Data Protection Officer
For any inquiries regarding this Privacy Policy, to exercise your data subject rights, or to contact our Data Protection Officer, please reach out via email: