Privacy Policy

Last Updated on - 16 January 2026

Version - 1.7

Legal Framework & Compliance

This Privacy Policy is governed by and aligned with:

    • Digital Personal Data Protection (DPDP) Act, 2023 (Primary)
    • Information Technology Act, 2000
    • IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
    • ISO 27001:2022 and ISO 27701:2019 frameworks

iLeads acts as a Data Fiduciary under the DPDP Act and processes personal data lawfully, fairly, and only for legitimate, specified purposes.

Definitions

Term Definition
Data Principal The individual to whom personal data relates
Data Fiduciary Entity that determines the purpose and means of processing (iLeads)
Data Processor Entity processing data on behalf of Data Fiduciary
Personal Data Any data about an individual who is identifiable
Consent Free, specific, informed, unconditional, and unambiguous agreement

Role of iLeads

iLeads acts as:

    • Data Fiduciary: For personal data collected through website, recruitment, and internal operations
    • Data Processor: When processing personal data on behalf of clients under contractual instructions

All processing activities are performed strictly within India.

Categories of Personal Data Collected

  • Business and Contact Information
    • Name, email address, phone number
    • Company name and job title
    • Business correspondence
  • Client Data
    • Customer names and contact details
    • Inquiry and transaction information
    • Identity or verification data (as instructed by clients)
  • Website and Technical Data
    • IP address, browser and device information
    • Log files, cookie and usage data
  • Recruitment and Employment Data
    • Resume, qualification, and employment history
    • Contact and identity information

Lawful Basis for Processing

Personal data is processed only when one of the following bases applies:

Lawful Basis Description
Consent Free, specific, informed consent obtained before processing
Contractual necessity Processing necessary for contract performance
Legal obligation Processing required by Indian law
Legitimate use Specified legitimate purposes under DPDP Act (employment, emergency, etc.)

Consent Management

  • Consent Requirements

    Where consent is the lawful basis, iLeads ensures consent is:

    • Free: Not conditional on unrelated services
    • Specific: Clearly stating purpose of processing
    • Informed: Provided with clear notice in plain language
    • Unconditional: No bundled consent
    • Unambiguous: Clear affirmative action required
  • Consent Notice Contents

    Before obtaining consent, Data Principals are informed of:

    • Personal data to be collected
    • Purpose of processing
    • How to withdraw consent
    • How to file grievances
  • Consent Withdrawal

    Data Principals may withdraw consent at any time via:

Withdrawal is effective within 7 days. Withdrawal does not affect lawfulness of prior processing.

Purpose of Processing

Personal data is processed for the following purposes:

    • Providing BPO, KPO, IT-enabled, and lead management services
    • Client onboarding, communication, and support
    • Fulfilling contractual obligations
    • Recruitment and workforce management
    • Compliance with legal and regulatory requirements
    • Security monitoring and fraud prevention
    • Website operations and improvements

We do not process personal data for purposes incompatible with the original purpose without fresh consent.

Data Sharing and Disclosure

  • Categories of Recipients

    Personal data may be shared only with:

    • Authorized iLeads employees and contractors (need-to-know basis)
    • Domestic IT and infrastructure service providers
    • Clients, strictly as part of contracted service delivery
    • Government authorities, courts, or regulators when legally required
  • Third-Party Controls

    All third parties must:

    • Sign data processing agreements with equivalent security obligations
    • Process data only on documented instructions
    • Implement appropriate technical and organizational measures
    • Return or delete data upon engagement completion
    • Submit to audits upon request
    • Report breaches within 24 hours
  • Third-Party Register

    iLeads maintains a register of all third parties processing personal data, including:

    • Entity name and contact details
    • Purpose of processing
    • Data categories shared
    • Contract reference and review date

Data Localization

iLeads processes and stores ALL personal data within India only. No personal data is transferred or accessed from outside India.

Data Retention

  • Retention Principles

    Personal data is retained only as long as necessary for:

    • Fulfilling the specified purpose
    • Contractual obligations
    • Legal and regulatory compliance
  • Retention Schedule
Data Category Retention Period
Client service data Contract duration + 90 days
Marketing/consent data Until consent withdrawn + 30 days
Employment records Employment + 7 years
Financial/tax records 7 years (statutory)
Security logs 180 days
Failed recruitment applications 12 months

After the retention period, data is securely deleted or anonymized per the Data Deletion Policy.

Information Security Measures

  • iLeads implements reasonable security practices and controls including:

    • Role-based access controls (principle of least privilege)
    • Multi-factor authentication for all sensitive systems
    • Network and endpoint security (firewalls, EDR, encryption)
    • Encrypted communication channels (TLS 1.2+)
    • Comprehensive logging and monitoring
    • Physical security at facilities
    • Periodic access reviews and penetration testing
    • Employee security awareness training

Rights of Data Principals

Under the DPDP Act 2023, Data Principals have the following rights:

Right Description
Right to Access Obtain summary of personal data being processed and processing activities
Right to Correction Request correction of inaccurate or incomplete personal data
Right to Erasure Request deletion of personal data (subject to legal retention requirements)
Right to Withdraw Consent Withdraw consent with same ease as it was given
Right to Grievance Redressal File complaint with iLeads and escalate to Data Protection Board if unresolved
Right to Nominate Nominate an individual to exercise rights in case of death/incapacity

Grievance Handling

  • Internal Grievance Mechanism

    Data Principals may file grievances regarding processing of their personal data:

    • Email: [email protected]
    • Online: https://www.ileads.co.in/grievance
    • Written: Registered office address
  • Response Timeline
    • Acknowledgment: Within 48 hours
    • Resolution: Within 30 days
    • If extension needed: Notification with reasons within 30 days
  • Escalation

    If the grievance is not resolved satisfactorily, Data Principals may escalate to the Data Protection Board of India as established under the DPDP Act.

Data Breach Notification

  • In the event of a personal data breach:

    • iLeads will notify the Data Protection Board as required by law
    • Affected Data Principals will be notified where required
    • Notification will include nature of breach, data affected, and remediation steps
    • All breaches are logged in the Breach Register

Contact Information

  • For privacy-related queries, requests, or grievances:

    • Email: [email protected]
    • Website: https://www.ileads.co.in
    • Address: Commercial Complex, Behind Kailash Tower, New Road, Dehradun, Uttarakhand-248003, India
  • For Grievance:

Policy Updates

This policy may be updated periodically. Material changes will be communicated via website and, where required, direct notification to affected Data Principals.

Uttarakhand

Head Office

Commercial Complex, Behind Kailash Tower, E.C Road, Dehradun, Uttarakhand

Branch 2 :

3rd Floor, HM Tower, New Road, Opp MKP College, Dehradun, Uttarakhand

Haryana

Gurugram :

3rd Floor, 24C, Phase IV, Udyog Vihar, Sector 1C Gurugram – 122022, Haryana

Panchkula :

SCO 112 Midtown Business Park, Peer Muchalla Near Sector 20 Panchkula, Haryana

Uttar Pradesh

Noida :

A22 Sector 16, Near Sector 16 Metro Station, Noida - 201301, Uttar Pradesh


Karnataka

Bengaluru :

Maruthi Chambers, Ground Floor, Silk Board Junction, Bommanahalli, Bengaluru, Karnataka

Kerala

Trivandrum :

2nd floor, New Bharath Towers, Chakkai Bypass, Trivandrum, Kerela - Tc no : 86/1424(3)

Tamil Nadu

Puducherry :

Government of Puducherry Electricity Department 137, Nethaji Subhash Chandra Bose Salai, Puducherry-605001

Maharashtra

Mumbai :

3rd Floor, Allied Digital House, A4, Millennium Business Park, Navi Mumbai - 400710, Maharashtra