Security & Compliance
Built for India's DPDP Act — before the compliance deadline forces the issue.
The DPDP Rules 2025 were notified on 13 November 2025. The substantive obligations — consent notices, security safeguards, breach reporting, erasure timelines — come into force on 13 May 2027. Most HR tech vendors haven't started. Shynsa already has, and we can show you exactly how.
Shynsa is built ground-up for India's DPDP Act 2023 and its 2025 Rules. Every interview collects explicit candidate consent with timestamp, stores all data on servers located in India (Mumbai region), and supports right-to-erasure requests ahead of the Rules' 13 May 2027 compliance deadline. We do not process biometric data — no facial analysis, no emotion scoring.
The regulatory context
Why the DPDP Act matters for recruitment software
The Digital Personal Data Protection Act 2023 classifies candidate PII collected during recruitment — name, phone, email, location, and audio recordings — as personal data requiring explicit, informed consent before collection. Its 2025 Rules (notified 13 November 2025) roll out in stages: consent-manager registration opens 13 November 2026, and the substantive fiduciary obligations — notice requirements, security safeguards, breach reporting, and erasure timelines — become enforceable on 13 May 2027. Penalties for non-compliance run from ₹50 crore up to ₹250 crore per contravention under the Act's schedule. Building consent and data-residency practices in now, rather than in 2027, avoids a scramble later.
Read the MeitY DPDP Rules →Implemented
Explicit candidate consent checkbox before every interview
Candidates read and accept T&C before the interview begins. Consent timestamp and T&C version stored per application.
Data minimisation
Only name, age, gender, phone, email, location, and voice interview data collected. No social profiles, no document uploads, no biometrics.
Right-to-erasure workflow
Admins can permanently delete any application and associated audio/video. Deletion is irreversible and logged.
Data stored in India
All candidate data processed and stored on servers located in the Mumbai region. No cross-border data transfer.
No facial or biometric analysis
Video is recorded optionally for recruiter review only — never processed for emotion, expression, or biometric data. Under DPDP, facial data is sensitive personal data requiring higher consent.
Audit logs
All data access, deletion, and score events are logged with timestamp and actor.
Roadmap
Data Principal notifications
Proactive notifications to candidates when their data is accessed or scored.
Data Protection Officer appointment
Formal DPO role and contact mechanism for data-related requests.
Our policy
Why we don't do facial analysis — and you should care
Under India's DPDP Act 2023, facial data is classified as sensitive personal data. Using AI tools that analyse facial expressions or emotion requires a higher consent standard and creates regulatory exposure for your organisation as the data fiduciary — not just for the vendor. Shynsa evaluates voice content and delivery only. Your candidates' video recordings are stored for your manual review — never processed for scores.
- ✓Facial analysis = sensitive personal data under DPDP — higher consent requirement
- ✓A systematic review of 1,000+ psychology studies (Association for Psychological Science, 2019) found no reliable scientific basis for inferring emotion from facial expressions — the EU's AI Act now bans emotion-recognition AI in the workplace outright
- ✓Voice-based scoring (communication, relevance, fluency) is defensible and explainable
- ✓Camera can be disabled entirely per position — maximising candidate completion rates
Technical security
Security by design — not by compliance checkbox
Transport security
HTTPS everywhere with HSTS. All candidate audio uploads use secure, time-limited signed URLs over TLS. No data transmitted in plain text.
Authentication & session security
httpOnly JWT cookies — no localStorage token storage. Admin sessions expire automatically. Rate limiting on all authentication endpoints.
Data isolation
All candidate audio/video stored in secure cloud storage with org-isolated paths (`orgs/{orgId}/...`). One organisation cannot access another's data. Access URLs expire after a short window.
Email infrastructure
All transactional emails sent via secure, authenticated email infrastructure with SPF and DKIM signing. Candidate confirmation emails include the organisation name — not Shynsa's — to prevent impersonation confusion.
Rate limiting
All public endpoints (candidate registration, interview start, audio submission) are rate-limited per IP and device to prevent abuse.
SOC2 Type II (in progress)
We are working toward SOC2 Type II certification. Expected target date: 2026. Contact us for current security documentation.
FAQ
Data & security questions
Download our security brief
Detailed documentation of our DPDP implementation, sub-processors, and data flows — ready for your compliance team.
Request security documentation