Data Processing Register

Public summary · Last updated 17 May 2026 · Security policy · Privacy policy

This page summarises the categories of personal data Srida IT processes as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDPA) and provides the equivalent of an Article 30 record for stakeholders. The full internal register — including precise retention periods, cross-border transfer details, sub-processors, and DPIA links — is available on request to regulators and accredited auditors at dpo@sridait.com.

CategoryFieldsPurposeRetentionLegal basis
Candidate identityFull name, email, mobile (encrypted at rest), LinkedIn / GitHub URLAccount creation, programme eligibility, AI screening, contactFor lifetime of account; auto-purged 18 months after last login (with 30-day warning) or immediately on user requestDPDPA: consent (Section 6) — captured at registration with version, timestamp, IP
Application contentResume file, education history, work experience, certifications, professional summary, skills, applied programmeAI screening, human review, programme selectionFor lifetime of account; resumes on rejected applications auto-purged 6 months after rejectionDPDPA: consent — same as identity above
Authentication metadataPassword hash (bcrypt cost 12), session tokens (sha256 hash only), 2FA setting, OTP hashes (HMAC), IP + user-agent of loginAccount security, fraud detection, login throttlingSession rows deleted on logout / expiry; OTPs deleted 10 minutes after issuance; login audit retained 12 monthsDPDPA: legitimate interests (security)
Payment evidenceUPI reference number, screenshot upload (filename, MIME, hash), amount, status, admin review notesProgramme administration fee accounting, audit7 years (statutory financial-records retention under Indian Income Tax Act)DPDPA: legal obligation
Assessment artefactsTrust Engineer Phase 1–4 answers, scores, integrity events (tab-switch, paste, typing rhythm)Candidate evaluation, selectionTied to application lifetime; aggregated metrics retained 3 yearsDPDPA: consent (assessment specifically disclosed in AI screening notice)
Audit loguser_id, action, IP, timestamp, hash-chained for tamper-evidenceSecurity, DPDPA accountability, dispute resolution5 yearsDPDPA: legal obligation + legitimate interests
Email queueRecipient address, subject, body, send statusTransactional email delivery (welcome, status updates, OTP, password reset)Successful sends purged after 30 days; failures kept indefinitely for forensic reviewDPDPA: consent + legitimate interests

Sub-processors

  • Hostinger — hosting infrastructure (web, MySQL, mail relay). Data location: EU / Asia (Hostinger SOC 2 Type II report on file).
  • Email delivery — via Hostinger SMTP or PHP mail() fallback.

Cross-border transfers

None of the data described above is transferred outside India in the ordinary course. Hostinger data centre region is configured to keep processing within Asia-Pacific. Any future change will be disclosed here and in our privacy policy with at least 30 days' notice.

Your rights

You can exercise your access, rectification, erasure, and portability rights from your dashboard at /dashboard/account or by emailing dpo@sridait.com from the registered address. We respond within 5 working days.