# Privacy Policy.

> How Scrini AI collects, uses, shares and protects personal data, our role for candidate data and how to exercise your privacy rights in every region.

URL: https://landing.qa.scrini.ai/privacy-policy  
Breadcrumb: Home > Privacy Policy

Last updated: October 2, 2026. This policy explains what personal data Scrini AI collects, why we use it, who we share it with and the rights you have, wherever you live.

## Summary

- Scrini AI runs an AI hiring platform. When we process candidate data for an employer (our customer), the employer decides how it is used and we follow its instructions.
- For our website, marketing, customer accounts and our own recruiting, Scrini AI decides how data is used and this policy applies directly.
- We do not sell personal data. Customer candidate data is never used to train or fine-tune shared AI models.
- You can ask to access, correct, delete or export your data and object to some uses. Email hello@scrini.ai (subject: Privacy) or support@scrini.ai to make a request.
- Candidates assessed through Scrini should also read our Candidate Privacy Notice and AI Transparency Notice.

## 1. Who we are

Scrini AI is operated by Scrini AI Private Limited (CIN U62099UP2025PTC236974), with its registered office at 537 BHA / 588, Bharat Nagar Mohibullapur, Sitapur Road, Lucknow, Uttar Pradesh 226021, India and its office at 5110, Mahagun Mywoods, Sector 16C, Gaur City 2, Greater Noida, Ghaziabad, Uttar Pradesh 201309, India ("Scrini", "we", "us"). For privacy questions or requests, email our privacy team at hello@scrini.ai (subject: Privacy) or support@scrini.ai, or call +91 9116489709.

## 2. What this policy covers and our roles

This policy covers scrini.ai, app.scrini.ai, our APIs and the services we provide to customers (the "Service"). We play two roles. We are a controller (under India's DPDP Act, a data fiduciary) for personal data we collect for our own purposes: website visitors, people who contact us, customer account users, marketing contacts, partners and people who apply for jobs at Scrini. We are a processor (a service provider under US state laws) for candidate data we process on behalf of customers. For candidate data, the customer is the controller and its own privacy notice applies, together with our data processing addendum with that customer.

## 3. Other Scrini products

Workor, HiringWiring and ViberOS are separate products with their own sign-up flows and terms. When you use one of them, the privacy notice shown on that product's site applies. Where a product does not show its own notice, this policy applies.

## 4. Personal data we collect as a controller

What we collect depends on how you interact with us.

| Who you are | What we collect | Where it comes from |
| --- | --- | --- |
| Website visitor | Device and browser data, IP address, approximate location derived from IP, pages viewed and your cookie choices | Automatically, using cookies and similar technologies |
| Contact or demo request | Name, work email, phone number, company, job title and your message | You |
| Customer account user | Name, work email, role, sign-in and SSO identifiers, activity logs and support requests | You or your employer |
| Billing contact | Name, billing address, invoices and payment status. Card payments are collected and processed by our payment processors | You, your employer and our payment processor |
| Marketing contact | Name, email, company, email engagement, event attendance and consent records | You, events and other business contact sources |
| Applicant to Scrini | Resume, proposal, links to your work and correspondence | You |
| Partner | Name, company, contact details and partnership details | You |

## 5. Candidate data we process for customers

When an employer uses Scrini, we process candidate data on its behalf. This can include contact details, resumes and work history, outreach messages and replies, call recordings and transcripts, video interview recordings and transcripts, assessment answers and results, scores with the evidence behind them, scheduling details and identity verification signals. Each customer decides which features it uses and how long data is kept. We do not require special category or sensitive data unless a customer instructs us to process it lawfully. Our Candidate Privacy Notice explains this processing in plain language.

## 6. How we use personal data and our lawful bases

Lawful bases apply under GDPR, UK GDPR and similar laws. Where a law requires consent, we ask for it.

| Purpose | Lawful basis |
| --- | --- |
| Provide the Service, create and manage accounts and give support | Performance of a contract |
| Keep the Service secure, prevent fraud and abuse and debug problems | Legitimate interests in a safe and reliable service |
| Measure and improve our website and product using analytics | Consent for analytics cookies where required, otherwise legitimate interests |
| Send product updates and marketing emails | Consent where required, otherwise legitimate interests with an easy opt-out |
| Respond to demo requests, partnership enquiries and questions | Steps before a contract and legitimate interests |
| Bill customers and keep financial records | Performance of a contract and legal obligation |
| Comply with law, respond to lawful requests and enforce our terms | Legal obligation and legitimate interests |
| Review applications to work at Scrini | Steps before a contract and legitimate interests |

## 7. AI and model improvement

Customer candidate data is used only to provide the Service to that customer. It is never used to train or fine-tune shared AI models.

## 8. Automated decision-making

We do not make decisions with legal or similarly significant effects about website visitors, customers or partners based solely on automated processing. For candidates, our AI agents produce scores, rankings and summaries that support the employer's hiring team, and the employer makes the hiring decision. How this works, and the rights candidates have under GDPR Article 22, the UK Data (Use and Access) Act 2025, Quebec Law 25, Brazil's LGPD and other laws, is explained in our AI Transparency Notice.

## 9. How we share personal data

We share personal data only as described here: with service providers and subprocessors that help us run the Service, under contracts that protect the data (see our Subprocessors page); within a customer's own workspace and with the integrations a customer chooses to connect, such as its ATS or calendar; with professional advisers under confidentiality duties; with authorities when the law requires it or to protect rights and safety; and with a buyer or successor if Scrini is involved in a merger or acquisition, subject to this policy. We never share one customer's candidate data with another customer.

## 10. Sale and sharing of personal data

We do not sell personal data for money and we do not use candidate data for advertising. On our website, Marketing cookies help us measure campaigns and show relevant ads on other sites, which some US state laws treat as sharing for cross-context behavioral advertising or targeted advertising. In the EU, EEA, UK and Switzerland, Marketing cookies run only with your consent. Everywhere else, you can opt out at any time with the Cookie settings link in the footer, and we honor Global Privacy Control signals as an opt-out. Our Cookie Policy has the details.

## 11. International transfers

We host data on Amazon Web Services in the Mumbai (India) and Frankfurt (Germany) regions, and customers can choose EU-only hosting. Some service providers process data in other countries. When personal data leaves the EEA, the UK or Switzerland, we use the EU Standard Contractual Clauses (with the UK Addendum and the Swiss amendments) where required, plus supplementary measures where needed.

## 12. How long we keep data

Customer account data is kept for the subscription term plus 90 days. Candidate data is kept according to each customer's settings and is deleted or anonymized within 30 days of a customer's request or the end of its contract. Backups are deleted on a 35-day cycle. Marketing data is kept until you opt out or it is no longer needed. Consent records from our cookie banner are kept for about 13 months. Applications to work at Scrini, website analytics and server logs are kept for as long as needed for the purpose described in this policy, then deleted or anonymized. We keep some records longer when the law requires it.

## 13. How we protect data

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Access is controlled with SSO, MFA and role-based permissions, activity is logged centrally with 24/7 alerting and independent third parties test our security at least once a year. Our security controls are mapped to SOC 2 and ISO 27001. Our Data Security Policy has the details.

## 14. Your rights

Depending on where you live, you can ask to access your personal data, correct it, delete it, receive a portable copy, restrict or object to its use, withdraw consent at any time and not be subject to solely automated decisions with significant effects. You can also opt out of marketing using the link in any email. You will not be treated differently for using your rights.

## 15. How to make a request

Email our privacy team at hello@scrini.ai (subject: Privacy) or support@scrini.ai. We will confirm we received your request, may ask for information to verify your identity and will respond within 30 days, or within 45 days under California and other US state laws. Where the law allows, we may extend that period for complex requests and will tell you if we do. You can use an authorized agent where the law allows. If we decline a request, we will explain why and how to appeal. If you are a candidate, contact the employer first, because it controls your data. If you contact us, we will pass your request to the employer within 5 business days and help it respond. You also have the right to complain to your data protection authority.

## 16. Cookies

We use necessary cookies to run the site. Analytics, marketing and preference cookies run only with your consent in the EU, EEA, UK and Switzerland, and elsewhere you can turn them off at any time. You can change your choices with the Cookie settings link in the footer. Our Cookie Policy lists the categories and explains how consent, Google Consent Mode and Global Privacy Control signals are handled.

## 17. Children

Our website and Service are not directed to children. We do not knowingly collect personal data from anyone under 16, or under 18 where local law requires it (for example in India), without the consent the law requires. Customers must not use Scrini to assess anyone under 16, or under 18 where local law requires it, or anyone below the minimum working age where they hire.

## 18. Third-party services

Our Service connects to tools customers choose, such as applicant tracking systems, calendars, job boards and communication providers. Those providers handle data under their own terms and privacy notices.

## 19. Security incidents

If a security incident affects personal data, we notify affected customers without undue delay and within 72 hours of confirming it, with what we know about the scope, impact and the steps we are taking. Where we are the controller, we notify regulators and affected people as the law requires.

## 20. Region-specific information: EEA, UK and Switzerland

Scrini is the controller for the data described in section 4. If you are in the EEA or the UK, you can contact our privacy team at hello@scrini.ai (subject: Privacy) about any privacy matter. You can also lodge a complaint with your local supervisory authority, for example your national data protection authority in the EU, the UK Information Commissioner's Office or the Swiss FDPIC.

## 21. Region-specific information: California

This section is our notice at collection under the CCPA as amended by the CPRA, and it covers job applicants as well as other California residents. In the last 12 months we collected identifiers (such as name, email and IP address), commercial information (such as plans and invoices), internet activity (such as pages viewed), approximate location derived from IP, professional and employment information (for Scrini job applicants and customer users) and account login credentials, which are sensitive personal information used only to provide secure access. We collect it from the sources and for the purposes in sections 4 and 6, keep it for the periods in section 12 and disclose it only as described in sections 9 and 10. We do not sell personal information for money or use sensitive personal information to infer characteristics. Marketing cookies on our website may count as sharing for cross-context behavioral advertising; you can opt out with the Cookie settings link in the footer, and we honor Global Privacy Control signals as an opt-out of sale or sharing. You have the rights to know, delete, correct, opt out of sale or sharing and limit the use of sensitive personal information, and we will not discriminate against you for using them. Candidate data we process for employers is handled as their service provider.

## 22. Region-specific information: other US states

Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Texas, Oregon, Utah, Montana, Iowa, Delaware, New Jersey, New Hampshire, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and Nebraska, can ask to access, correct, delete and port their data and opt out of targeted advertising, sale and certain profiling. You can opt out of targeted advertising with Cookie settings, and we honor Global Privacy Control signals as an opt-out. If we deny your request, reply to our decision to appeal, and if you disagree with the outcome you can contact your state attorney general.

## 23. Region-specific information: Canada

We handle personal information under PIPEDA and applicable provincial laws. Questions and complaints about how we handle personal information can be sent to our privacy team at hello@scrini.ai (subject: Privacy), which is accountable for our compliance. Under Quebec Law 25, if a decision about you is based exclusively on automated processing, you can ask about the information used, the main reasons and factors behind it, have the information corrected and submit observations to a person who can review the decision. You can complain to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.

## 24. Region-specific information: Brazil

Under the LGPD you can confirm whether we process your data, access, correct, anonymize, block, delete and port it, learn who we share it with, withdraw consent and request review of decisions based solely on automated processing. To exercise these rights or ask a question, contact our privacy team at hello@scrini.ai (subject: Privacy), which acts as our point of contact for data subjects and the ANPD. You can complain to the ANPD.

## 25. Region-specific information: India

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, you can access information about your data, correct, complete, update and erase it, nominate someone to exercise your rights and seek redress for grievances. Questions and grievances can be sent to our privacy team at hello@scrini.ai (subject: Privacy) or by phone on +91 9116489709, and we will respond within the period the DPDP Rules set. If you are not satisfied, you can complain to the Data Protection Board of India.

## 26. Region-specific information: Singapore

Under the PDPA you can request access to and correction of your personal data and withdraw consent. Contact our privacy team at hello@scrini.ai (subject: Privacy). We aim to respond to access requests within 30 days.

## 27. Region-specific information: Australia

We handle personal information under the Australian Privacy Principles. Some service providers may process it outside Australia, including in India, Germany and the United States, under contracts that require it to be protected. You can access and correct your information and complain to us first, then to the Office of the Australian Information Commissioner. Information about automated decisions that significantly affect people is in section 8 and our AI Transparency Notice.

## 28. Changes to this policy

We will give at least 30 days' notice of material changes, by email or a notice in the product, before they take effect. The date at the top shows when this policy last changed. Previous versions are available on request.

## 29. Contact us

Email our privacy team at hello@scrini.ai (subject: Privacy) or support@scrini.ai, call +91 9116489709 or write to Scrini AI Private Limited, 5110, Mahagun Mywoods, Sector 16C, Gaur City 2, Greater Noida, Ghaziabad, Uttar Pradesh 201309, India.

## Related policies.

### Candidate Privacy Notice

For people assessed through Scrini by an employer.

[Read](https://landing.qa.scrini.ai/candidate-privacy-notice)

### AI Transparency Notice

How our AI agents work and the choices candidates have.

[Read](https://landing.qa.scrini.ai/ai-transparency)

### Cookie Policy

Cookies, consent and how to change your choices.

[Read](https://landing.qa.scrini.ai/cookie-policy)

### Terms of Service

The agreement for using the Scrini platform.

[Read](https://landing.qa.scrini.ai/terms-of-service)

### Acceptable Use Policy

What customers may and may not do with Scrini.

[Read](https://landing.qa.scrini.ai/acceptable-use-policy)

### Data Processing Addendum

Key terms for processing personal data on your behalf.

[Read](https://landing.qa.scrini.ai/dpa)

### Subprocessors

Third parties that process data for Scrini.

[Read](https://landing.qa.scrini.ai/subprocessors)

### Data Security Policy

How we protect data and respond to incidents.

[Read](https://landing.qa.scrini.ai/data-security-policy)

### Refund Policy

Credits, billing disputes and refunds.

[Read](https://landing.qa.scrini.ai/refund-policy)

### Accessibility Statement

Our accessibility commitment and accommodations.

[Read](https://landing.qa.scrini.ai/accessibility)

### Vulnerability Disclosure

How to report a security issue.

[Read](https://landing.qa.scrini.ai/vulnerability-disclosure)
