↓ Sections auto-expand as you scroll
Zenith HR Solutions Private Limited (“Zenith,” “Company,” “we,” or “us”) is the Data Fiduciary as defined under Section 2(i) of the Digital Personal Data Protection Act, 2023 (“DPDP Act”). We determine the purpose and means of processing your personal data in connection with our website and leadership advisory services.
This Privacy Policy applies to:
- All visitors to www.zenithhr.co.in and any associated subdomains.
- Candidates and professionals who submit personal data through our contact, careers, or inquiry forms.
- Corporate clients, hiring organisations, and their representatives.
- Any third party whose Personal Data Zenith receives in connection with providing its leadership advisory services.
Under Rule 3 of the DPDP Rules 2025, notice must itemise the categories of data collected. Zenith collects the following personal data, limited to what is necessary for each purpose:
| Data Category | Examples | Source |
|---|---|---|
| Identification | Name, age, gender | Directly from you |
| Contact | Email, phone, address | Directly from you |
| Professional profile | Resume, work history, remuneration, skills | Directly from you |
| Organisation details | Employer name, designation, industry | Directly from you |
| Usage / log data | IP address, browser type, page visits | Automatic collection |
| Communication data | Emails, messages, meeting notes | Directly from you |
| Referral data | Names/contacts of persons you refer to us | Directly from you |
| Special category* | Disability status (only if volunteered) | Directly from you |
In accordance with GDPR-standard transparency and DPDP Act Section 6, we process personal data only for specified, explicit purposes on a documented lawful basis:
| Purpose | Legal Basis |
|---|---|
| Executive search & candidate assessment | Consent (DPDP §6) |
| Client relationship management | Contract performance |
| Talent pipeline & market research | Legitimate interest |
| Website analytics and improvement | Legitimate interest |
| Legal, regulatory or contractual compliance | Legal obligation |
| Sending insights, thought-leadership communications | Consent (DPDP §6) |
| Candidate-to-client matching / referral | Consent (DPDP §6) |
Under Rule 3 of the DPDP Rules 2025, Zenith provides this itemised notice at or before the point of personal data collection. Consent is obtained separately and in an unambiguous, freely given manner.
- Consent is obtained at or before the time of data collection via explicit opt-in checkboxes on all forms.
- Where processing relies on legitimate interest, a Legitimate Interests Assessment (LIA) is conducted and documented.
- You may withdraw consent at any time. Withdrawal does not affect the lawfulness of prior processing.
- Zenith will work with registered Consent Managers (where applicable under the First Schedule of DPDP Rules 2025) to facilitate consent withdrawal.
Your Consent Preferences
Manage how Zenith uses cookies and analytics on this site.
Essential Cookies
Required for the site to function correctly. Cannot be disabled.
Analytics & Performance
Helps us understand how visitors interact with the site.
Functional
Enables enhanced features like live chat and form auto-fill.
Marketing & Retargeting
Allows us to personalise communications based on your interactions.
Preferences are stored in your browser. Update any time by revisiting this page.
Under Chapter III of the DPDP Act 2023, you hold the following rights as a Data Principal. To exercise any right, contact us at Updates Soon.
Right to Access (§11)
Obtain confirmation of and access to the personal data Zenith holds about you.
Right to Correction (§12)
Request correction or update of inaccurate or outdated personal data.
Right to Erasure (§12)
Request deletion of your personal data when no longer required for its original purpose.
Right to Grievance Redressal (§13)
Lodge a grievance with the Grievance Officer within 48 hours of an incident.
Right to Nomination (§14)
DPDP-specific: nominate another person to exercise your rights in case of death or incapacity.
Right to Withdraw Consent
Withdraw consent for any processing based on consent, at any time.
Zenith does not sell personal data. Data may be disclosed only in the following strictly controlled circumstances:
- To prospective hiring organisations or clients, solely in connection with a specific live search mandate and with the candidate's awareness.
- To affiliated business partners for employment-related search purposes under matching confidentiality obligations.
- To judicial, governmental, or regulatory authorities when legally mandated.
- To acquirers or successors in the event of a merger, acquisition, or sale of business assets — each bound by equivalent data protection terms.
- To third-party service providers (e.g. CRM, analytics, IT vendors) under data processing agreements that contractually require adequate protection.
Where Zenith transfers personal data outside India — for instance, to international clients, global executive search partners, or cloud service providers — such transfers are conducted:
- Only to countries or entities notified as permissible by the Central Government under Rule 15 of the DPDP Rules 2025.
- Subject to contractual data protection obligations at least equivalent to those under the DPDP Act.
- With your prior consent where the transfer relates to your personal profile or candidacy.
Personal data is retained only for the period necessary for its purpose or as mandated by law:
| Data Category | Retention Period | Basis |
|---|---|---|
| Candidate profile & resume data | 5 years from last active engagement | Legitimate interest / Consent |
| Client engagement records | 7 years from mandate closure | Contract / Legal obligation |
| Website analytics & log data | 13 months rolling | Legitimate interest |
| Email / inquiry correspondence | 3 years | Legitimate interest |
| Consent records | Life of consent + 3 years | Legal obligation (DPDP Rule 7) |
| Financial / billing records | 8 years (GST / IT Act requirements) | Legal obligation |
Upon expiry, personal data is securely deleted, anonymised, or archived in accordance with the Third Schedule of the DPDP Rules 2025.
Zenith implements the following specific technical and organisational safeguards, as required under Rule 6 of the DPDP Rules 2025:
- Encryption of personal data at rest (AES-256) and in transit (TLS 1.2+).
- Role-based access controls (RBAC) limiting personal data access to authorised staff only.
- Structured audit logging of all access to personal data records.
- Regular automated and manual security testing of web infrastructure.
- Secure offsite and cloud backups with versioned recovery capability.
- Annual staff awareness training on data protection responsibilities.
Breach Notification (Rule 7)
In the event of a personal data breach, Zenith will notify affected Data Principals and the Data Protection Board of India in the form, manner, and within the timeframe specified under Rule 7 of the DPDP Rules 2025.
This website and Zenith's services are intended for users aged 18 years and above.
- If you are under 18, you must obtain verifiable consent from a parent or lawful guardian before submitting any personal data, in accordance with Rules 10–12 of the DPDP Rules 2025.
- Zenith does not knowingly collect personal data from minors. If we become aware that data has been collected from a person under 18 without appropriate guardian consent, it will be promptly deleted.
- For persons with disabilities, a lawful guardian may exercise Data Principal rights on their behalf. Supporting documentation may be required.
You may raise a grievance regarding this Policy by contacting our designated Grievance Officer. We will acknowledge your grievance within 48 hours and resolve it within 30 days.
Data Fiduciary / Grievance Officer
Zenith HR Solutions Pvt. Ltd.
Data Protection Board (DPB) Escalation
If your grievance is not resolved to your satisfaction within 30 days, you have the right to escalate the matter to the Data Protection Board of India under Section 27 of the DPDP Act 2023.
This Policy may be updated periodically to reflect changes in law, our services, or processing practices. Material changes will be communicated via email or a prominent notice on the website.
Version History
Full DPDP Act 2023 + DPDP Rules 2025 rewrite. Added Data Principal Rights, breach notification, cross-border transfer clause, consent manager panel, and DPB escalation path.
Initial Privacy Policy published, aligned to IT Act 2000 and SPDI Rules 2011.
Last Updated:July 2026 · Version:2.0 · Effective Date: July 2026