← All legal documents

DATA RETENTION & DELETION POLICY

Brand: Hireinst Operated by: The Hiring Planet (a partnership firm) Website: https://www.hireinst.com/

Effective Date: 14 July 2026 Last Updated: 21 July 2026


1. PURPOSE AND PRINCIPLES

1.1. This Data Retention & Deletion Policy explains how long Hireinst ("we", "us", "our") keeps personal data, when and how we delete it, and how you can request deletion. It puts into practice the storage-limitation and purpose-limitation principles under the Digital Personal Data Protection Act, 2023 ("DPDP Law").

1.2. Our core principle: we keep personal data only for as long as it is needed for the purpose it was collected, to provide the Services, to meet our legal obligations, to resolve disputes, and to enforce our agreements. When it is no longer needed, we delete, anonymise, or de-identify it, subject to the exceptions in Clause 6.

1.3. This Policy is part of our Terms of Service and should be read with our Privacy Policy and Verification Policy. Capitalised terms not defined here have the meaning given in the Terms of Service.


2. RETENTION SCHEDULE

The table below sets out our general retention approach by category. Actual periods may vary where a longer or shorter period is required by law or is genuinely necessary for a legitimate purpose.

Data categoryWhat it includesRetention approach
Account dataName, mobile, email, credentials, role, settingsKept while your Account is active; deleted or anonymised within 30 days after Account closure, subject to legal-hold exceptions (Clause 6).
Worker profile dataProfile details, skills, experience, photo, resume/CVKept while your Account is active; deleted on Account deletion, subject to residual backups (Clause 5) and content already shared (e.g. an application already sent).
Restaurant/Employer dataListing, logo, business details, job posts, applicant notesKept while the Account/listing is active; deleted on Account deletion or listing removal, subject to backups and legal holds.
Identity / KYC documentsAadhaar card, PAN card, or similar identity documentsMaximum 30 (thirty) days. Deleted once Verification is complete or 30 days elapse, whichever is earlier, unless a specific law requires longer. Only a minimal "verified" status/date may remain.
CommunicationsMessages between Users; support/grievance correspondenceKept while relevant to provide the Services and for safety/legal purposes; then deleted or anonymised. Retained where needed for an investigation, dispute, or legal obligation.
Transaction & billing recordsInvoices, payment status, GST recordsRetained for up to 8 years from the transaction date, even after Account closure. This follows Section 36 of the Central Goods and Services Tax Act, 2017, which requires retention for 72 months (6 years) from the due date of filing that year's annual return — and since that due date falls roughly one to two years after the transaction itself, the 6-year clock effectively runs for up to 8 years from the transaction date.
Verification statusFlag that Verification occurred, and dateMinimal record retained as needed for trust-and-safety and audit; the underlying documents are not retained (see KYC row).
Moderation & grievance recordsReports, flags, decisions, appealsRetained for the periods required by Applicable Law (including the intermediary record-retention period, currently a minimum of 180 days in specified circumstances, or longer where required).
Technical & log dataIP address, device info, access logs, security logsRetained for a limited period for security, fraud-prevention, and operational purposes, then deleted or aggregated.
Cookies & similarAs described in the Cookie PolicyPer the retention periods in the Cookie Policy.
Legal-hold dataAny data subject to a legal holdRetained for as long as required (Clause 6), then deleted.

3. ACCOUNT DELETION — HOW TO REQUEST

3.1. You may request deletion of your Account and associated personal data at any time by:

3.2. We may verify your identity before acting on a deletion request, to protect your Account and others' data. Where you delete the Account yourself while signed in, being signed in is that verification.

3.3. What we do on a valid deletion request:

3.4. Consequences of deletion. Deletion is irreversible once it has been finalised, and you will lose access to your Account, history, and any content associated with it. There is a short window between your request and final erasure (see Clause 3.3) during which we may be able to stop the deletion if you contact us — after that we cannot. Content already shared with other Users (such as a message already delivered, or an application already sent to a Restaurant) may persist with those Users or in their records.

3.5. Deleting some data without closing your Account. You do not have to delete your entire Account to have personal data removed. You may edit or remove your profile details, photo, and résumé yourself at any time in the app, or ask us to delete specific data (for example a particular application, conversation, or your Verification documents) by emailing us at the addresses in Clause 3.1. We will action or respond to such a request within 30 days, free of charge, except where we are required or permitted to retain the data under Clause 6.


4. DELETION ON WITHDRAWAL OF CONSENT

4.1. Where our processing of certain personal data relies on your consent and you withdraw it, we will stop that processing and delete or anonymise the relevant data, unless we have another lawful basis to retain it (for example, a legal obligation) as described in the Privacy Policy. Withdrawing consent necessary to provide the Services may require closure of your Account.


5. BACKUPS

5.1. We keep secure backups for disaster-recovery, security, and integrity purposes. When personal data is deleted from our active systems, it may persist in encrypted backups for a limited period until those backups are cycled and overwritten. We aim to purge deleted data from backups within 90 days. During that window, backup data is not used for ordinary processing and is restored only if genuinely required for recovery.


6. EXCEPTIONS — WHEN WE RETAIN DATA LONGER

Notwithstanding the above, we may retain personal data for as long as necessary where:

6.1. Legal obligation — retention is required by Applicable Law (for example, tax, GST, accounting, or intermediary record-keeping requirements);

6.2. Legal claims / disputes — the data is needed to establish, exercise, or defend legal claims, or to resolve a dispute;

6.3. Legal hold / lawful requests — the data is subject to a court order, government or law-enforcement request, or an ongoing investigation;

6.4. Safety and fraud prevention — retention is necessary to prevent fraud, abuse, or harm, or to enforce our Terms (for example, to prevent a banned User from re-registering).

In these cases, we retain only the data necessary for the specific purpose, and delete it once the purpose is fulfilled or the retention period ends.


7. ANONYMISATION AND AGGREGATION

7.1. Instead of deletion, we may anonymise or aggregate data so that it no longer identifies you. Anonymised and aggregated data (which is not personal data) may be retained and used for analytics, research, and improving the Services.


8. YOUR RIGHTS

8.1. You have rights in relation to your personal data — including access, correction, and erasure — as set out in the Privacy Policy. This Policy describes how we implement deletion; the Privacy Policy describes the full set of rights and how to exercise them.


9. CHANGES

9.1. We may update this Policy from time to time. The "Last Updated" date reflects the current version, and material changes will be notified where appropriate.


10. CONTACT


This Policy reflects our commitment to keeping personal data only as long as necessary and deleting it responsibly.