Security & Compliance

Built for India's DPDP Act — before the compliance deadline forces the issue.

The DPDP Rules 2025 were notified on 13 November 2025. The substantive obligations — consent notices, security safeguards, breach reporting, erasure timelines — come into force on 13 May 2027. Most HR tech vendors haven't started. Shynsa already has, and we can show you exactly how.

Shynsa is built ground-up for India's DPDP Act 2023 and its 2025 Rules. Every interview collects explicit candidate consent with timestamp, stores all data on servers located in India (Mumbai region), and supports right-to-erasure requests ahead of the Rules' 13 May 2027 compliance deadline. We do not process biometric data — no facial analysis, no emotion scoring.

The regulatory context

Why the DPDP Act matters for recruitment software

The Digital Personal Data Protection Act 2023 classifies candidate PII collected during recruitment — name, phone, email, location, and audio recordings — as personal data requiring explicit, informed consent before collection. Its 2025 Rules (notified 13 November 2025) roll out in stages: consent-manager registration opens 13 November 2026, and the substantive fiduciary obligations — notice requirements, security safeguards, breach reporting, and erasure timelines — become enforceable on 13 May 2027. Penalties for non-compliance run from ₹50 crore up to ₹250 crore per contravention under the Act's schedule. Building consent and data-residency practices in now, rather than in 2027, avoids a scramble later.

Read the MeitY DPDP Rules →

Implemented

Explicit candidate consent checkbox before every interview

Candidates read and accept T&C before the interview begins. Consent timestamp and T&C version stored per application.

Data minimisation

Only name, age, gender, phone, email, location, and voice interview data collected. No social profiles, no document uploads, no biometrics.

Right-to-erasure workflow

Admins can permanently delete any application and associated audio/video. Deletion is irreversible and logged.

Data stored in India

All candidate data processed and stored on servers located in the Mumbai region. No cross-border data transfer.

No facial or biometric analysis

Video is recorded optionally for recruiter review only — never processed for emotion, expression, or biometric data. Under DPDP, facial data is sensitive personal data requiring higher consent.

Audit logs

All data access, deletion, and score events are logged with timestamp and actor.

Roadmap

·

Data Principal notifications

Proactive notifications to candidates when their data is accessed or scored.

·

Data Protection Officer appointment

Formal DPO role and contact mechanism for data-related requests.

Our policy

Why we don't do facial analysis — and you should care

Under India's DPDP Act 2023, facial data is classified as sensitive personal data. Using AI tools that analyse facial expressions or emotion requires a higher consent standard and creates regulatory exposure for your organisation as the data fiduciary — not just for the vendor. Shynsa evaluates voice content and delivery only. Your candidates' video recordings are stored for your manual review — never processed for scores.

  • Facial analysis = sensitive personal data under DPDP — higher consent requirement
  • A systematic review of 1,000+ psychology studies (Association for Psychological Science, 2019) found no reliable scientific basis for inferring emotion from facial expressions — the EU's AI Act now bans emotion-recognition AI in the workplace outright
  • Voice-based scoring (communication, relevance, fluency) is defensible and explainable
  • Camera can be disabled entirely per position — maximising candidate completion rates

Technical security

Security by design — not by compliance checkbox

Transport security

HTTPS everywhere with HSTS. All candidate audio uploads use secure, time-limited signed URLs over TLS. No data transmitted in plain text.

Authentication & session security

httpOnly JWT cookies — no localStorage token storage. Admin sessions expire automatically. Rate limiting on all authentication endpoints.

Data isolation

All candidate audio/video stored in secure cloud storage with org-isolated paths (`orgs/{orgId}/...`). One organisation cannot access another's data. Access URLs expire after a short window.

Email infrastructure

All transactional emails sent via secure, authenticated email infrastructure with SPF and DKIM signing. Candidate confirmation emails include the organisation name — not Shynsa's — to prevent impersonation confusion.

Rate limiting

All public endpoints (candidate registration, interview start, audio submission) are rate-limited per IP and device to prevent abuse.

SOC2 Type II (in progress)

We are working toward SOC2 Type II certification. Expected target date: 2026. Contact us for current security documentation.

FAQ

Data & security questions

Download our security brief

Detailed documentation of our DPDP implementation, sub-processors, and data flows — ready for your compliance team.

Request security documentation