India's Leading Executive Search & Leadership Advisory Firm

Zenith HR Solutions

Privacy Policy

At Zenith HR Solutions, your data is handled with the highest standards of confidentiality, transparency, and legal rigour — aligned to India's Digital Personal Data Protection Act 2023, DPDP Rules 2025, and international best practice.

DPDP Act 2023DPDP Rules 2025GDPR HygieneIT Act 2000
Effective Date: July 2026  ·  Version: 2.0Supersedes all prior privacy statements. Governed by DPDP Act 2023 and DPDP Rules 2025.

↓ Sections auto-expand as you scroll

Zenith HR Solutions Private Limited (“Zenith,” “Company,” “we,” or “us”) is the Data Fiduciary as defined under Section 2(i) of the Digital Personal Data Protection Act, 2023 (“DPDP Act”). We determine the purpose and means of processing your personal data in connection with our website and leadership advisory services.

Your PrivacyOur Priority
ConfidentialityAlways
Data SecurityBy Design

This Privacy Policy applies to:

  • All visitors to www.zenithhr.co.in and any associated subdomains.
  • Candidates and professionals who submit personal data through our contact, careers, or inquiry forms.
  • Corporate clients, hiring organisations, and their representatives.
  • Any third party whose Personal Data Zenith receives in connection with providing its leadership advisory services.
This policy does not apply to third-party websites linked from our site. Following an external link exits our privacy jurisdiction; we encourage you to read the privacy policies of any external websites you visit.

Under Rule 3 of the DPDP Rules 2025, notice must itemise the categories of data collected. Zenith collects the following personal data, limited to what is necessary for each purpose:

Data CategoryExamplesSource
IdentificationName, age, genderDirectly from you
ContactEmail, phone, addressDirectly from you
Professional profileResume, work history, remuneration, skillsDirectly from you
Organisation detailsEmployer name, designation, industryDirectly from you
Usage / log dataIP address, browser type, page visitsAutomatic collection
Communication dataEmails, messages, meeting notesDirectly from you
Referral dataNames/contacts of persons you refer to usDirectly from you
Special category*Disability status (only if volunteered)Directly from you
*Special category data (e.g. disability status) is collected only where voluntarily disclosed and is subject to heightened safeguards including restricted access and separate storage.

In accordance with GDPR-standard transparency and DPDP Act Section 6, we process personal data only for specified, explicit purposes on a documented lawful basis:

PurposeLegal Basis
Executive search & candidate assessmentConsent (DPDP §6)
Client relationship managementContract performance
Talent pipeline & market researchLegitimate interest
Website analytics and improvementLegitimate interest
Legal, regulatory or contractual complianceLegal obligation
Sending insights, thought-leadership communicationsConsent (DPDP §6)
Candidate-to-client matching / referralConsent (DPDP §6)
Zenith does not use automated decision-making or profiling that produces legal or similarly significant effects on individuals without human review.

Under Rule 3 of the DPDP Rules 2025, Zenith provides this itemised notice at or before the point of personal data collection. Consent is obtained separately and in an unambiguous, freely given manner.

  • Consent is obtained at or before the time of data collection via explicit opt-in checkboxes on all forms.
  • Where processing relies on legitimate interest, a Legitimate Interests Assessment (LIA) is conducted and documented.
  • You may withdraw consent at any time. Withdrawal does not affect the lawfulness of prior processing.
  • Zenith will work with registered Consent Managers (where applicable under the First Schedule of DPDP Rules 2025) to facilitate consent withdrawal.

Your Consent Preferences

Manage how Zenith uses cookies and analytics on this site.

Essential Cookies

Required for the site to function correctly. Cannot be disabled.

Always On

Analytics & Performance

Helps us understand how visitors interact with the site.

Functional

Enables enhanced features like live chat and form auto-fill.

Marketing & Retargeting

Allows us to personalise communications based on your interactions.

Preferences are stored in your browser. Update any time by revisiting this page.

Under Chapter III of the DPDP Act 2023, you hold the following rights as a Data Principal. To exercise any right, contact us at Updates Soon.

Right to Access (§11)

Obtain confirmation of and access to the personal data Zenith holds about you.

Right to Correction (§12)

Request correction or update of inaccurate or outdated personal data.

Right to Erasure (§12)

Request deletion of your personal data when no longer required for its original purpose.

Right to Grievance Redressal (§13)

Lodge a grievance with the Grievance Officer within 48 hours of an incident.

Right to Nomination (§14)

DPDP-specific: nominate another person to exercise your rights in case of death or incapacity.

Right to Withdraw Consent

Withdraw consent for any processing based on consent, at any time.

Zenith will respond to rights requests within 30 days. Complex or multiple requests may take up to 90 days, with notice provided within the initial 30-day window.

Zenith does not sell personal data. Data may be disclosed only in the following strictly controlled circumstances:

  • To prospective hiring organisations or clients, solely in connection with a specific live search mandate and with the candidate's awareness.
  • To affiliated business partners for employment-related search purposes under matching confidentiality obligations.
  • To judicial, governmental, or regulatory authorities when legally mandated.
  • To acquirers or successors in the event of a merger, acquisition, or sale of business assets — each bound by equivalent data protection terms.
  • To third-party service providers (e.g. CRM, analytics, IT vendors) under data processing agreements that contractually require adequate protection.

Where Zenith transfers personal data outside India — for instance, to international clients, global executive search partners, or cloud service providers — such transfers are conducted:

  • Only to countries or entities notified as permissible by the Central Government under Rule 15 of the DPDP Rules 2025.
  • Subject to contractual data protection obligations at least equivalent to those under the DPDP Act.
  • With your prior consent where the transfer relates to your personal profile or candidacy.
At the time of this policy, the Central Government has not yet published a definitive negative list under Rule 15. Zenith will update this clause promptly upon publication of any transfer restrictions.

Personal data is retained only for the period necessary for its purpose or as mandated by law:

Data CategoryRetention PeriodBasis
Candidate profile & resume data5 years from last active engagementLegitimate interest / Consent
Client engagement records7 years from mandate closureContract / Legal obligation
Website analytics & log data13 months rollingLegitimate interest
Email / inquiry correspondence3 yearsLegitimate interest
Consent recordsLife of consent + 3 yearsLegal obligation (DPDP Rule 7)
Financial / billing records8 years (GST / IT Act requirements)Legal obligation

Upon expiry, personal data is securely deleted, anonymised, or archived in accordance with the Third Schedule of the DPDP Rules 2025.

Zenith implements the following specific technical and organisational safeguards, as required under Rule 6 of the DPDP Rules 2025:

  • Encryption of personal data at rest (AES-256) and in transit (TLS 1.2+).
  • Role-based access controls (RBAC) limiting personal data access to authorised staff only.
  • Structured audit logging of all access to personal data records.
  • Regular automated and manual security testing of web infrastructure.
  • Secure offsite and cloud backups with versioned recovery capability.
  • Annual staff awareness training on data protection responsibilities.

Breach Notification (Rule 7)

In the event of a personal data breach, Zenith will notify affected Data Principals and the Data Protection Board of India in the form, manner, and within the timeframe specified under Rule 7 of the DPDP Rules 2025.

This website and Zenith's services are intended for users aged 18 years and above.

  • If you are under 18, you must obtain verifiable consent from a parent or lawful guardian before submitting any personal data, in accordance with Rules 10–12 of the DPDP Rules 2025.
  • Zenith does not knowingly collect personal data from minors. If we become aware that data has been collected from a person under 18 without appropriate guardian consent, it will be promptly deleted.
  • For persons with disabilities, a lawful guardian may exercise Data Principal rights on their behalf. Supporting documentation may be required.

You may raise a grievance regarding this Policy by contacting our designated Grievance Officer. We will acknowledge your grievance within 48 hours and resolve it within 30 days.

Data Fiduciary / Grievance Officer

Zenith HR Solutions Pvt. Ltd.

Sachdeva Business Park, Mumbai, Maharashtra 400062

Data Protection Board (DPB) Escalation

If your grievance is not resolved to your satisfaction within 30 days, you have the right to escalate the matter to the Data Protection Board of India under Section 27 of the DPDP Act 2023.

This Policy may be updated periodically to reflect changes in law, our services, or processing practices. Material changes will be communicated via email or a prominent notice on the website.

Version History

v2.0July 2026

Full DPDP Act 2023 + DPDP Rules 2025 rewrite. Added Data Principal Rights, breach notification, cross-border transfer clause, consent manager panel, and DPB escalation path.

v1.0January 2024

Initial Privacy Policy published, aligned to IT Act 2000 and SPDI Rules 2011.

Last Updated:July 2026  · Version:2.0  · Effective Date: July 2026