Version 1.0 · Effective 1 October 2026
To put this in place
Write to contactus@insiderone.in with your company's legal name and a signatory, and we send a countersigned copy. If your organisation uses its own agreement, send it and we will review it.
This agreement is between the organisation using insiderOne for Employers (the "Customer") and Aurist Private Limited, North Lakhimpur, Assam, India ("insiderOne"), which operates the service in India. It forms part of the Terms of Service between them and applies whenever insiderOne processes Candidate Personal Data on the Customer's behalf.
"Candidate Personal Data" means personal data about job applicants and candidates that the Customer collects, uploads or asks insiderOne to verify through the service. Under the Digital Personal Data Protection Act 2023 ("DPDP Act") the Customer is the Data Fiduciary and insiderOne its Data Processor; under the GDPR and UK GDPR, where they apply, the Customer is the controller and insiderOne the processor.
It does not cover the profiles of insiderOne members that SCOUT shows a Customer. Those belong to people who joined insiderOne themselves, and insiderOne controls them under its own privacy notice until a member applies to the Customer or agrees to be contacted.
insiderOne processes Candidate Personal Data only to provide the service and on the Customer's documented instructions, which are these Terms, this agreement, and what the Customer does in the service. It will tell the Customer if it believes an instruction breaks the law, and will not process the data for any purpose of its own.
insiderOne does not sell Candidate Personal Data, and does not use it to train any language model or other machine-learning model.
The Customer is responsible for having a lawful basis for the data it brings into the service, for the notices it gives candidates, and for every background check it requests. Each check runs only after the named candidate agrees on a page of their own; a request nobody answers lapses after 14 days and nothing is run. Regulated checks require the Customer to state its purpose, which is recorded.
Everyone at insiderOne who can reach Candidate Personal Data is bound by confidentiality, and access is limited to the people who operate and support the service. Staff look at a Customer's data only to support the Customer when asked, or to investigate abuse or a security problem.
insiderOne keeps the measures in Annex 2 in place for as long as it processes the data and may improve them, but will not reduce the overall protection they give. The security page describes each in plain words.
The Customer authorises the sub-processors in Annex 3. insiderOne binds each to data protection terms no less protective than these, and remains responsible for them.
Before a new sub-processor starts receiving Candidate Personal Data, insiderOne will email the Customer's account owner at least 30 days ahead and update the security page. The Customer may object on reasonable data protection grounds; if the parties cannot resolve it, the Customer may end the affected part of the service and receive a pro-rata refund of fees paid for the remaining term.
The database is in Mumbai, India. Some sub-processors in Annex 3 process data in other countries, which each entry states. insiderOne will not transfer Candidate Personal Data to a country the Government of India has restricted under section 16 of the DPDP Act. Where the GDPR or UK GDPR applies to a transfer, it is made under the European Commission's Standard Contractual Clauses or the UK addendum, as the case requires.
insiderOne will help the Customer answer requests from candidates to access, correct or erase their data, or to withdraw consent, using the tools in the service, and will pass on to the Customer within five working days any such request it receives directly rather than answering it itself.
insiderOne will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a breach affecting the Customer's Candidate Personal Data. The notice will say what is known of what happened, the data and people affected, and what is being done, and insiderOne will add to it as it learns more. It will give the Customer what it needs to inform the Data Protection Board of India and the people affected, as the DPDP Act requires of a Data Fiduciary.
insiderOne will answer a Customer's written security questionnaire, and make available the information reasonably needed to show it meets this agreement. Once in any twelve months, on thirty days' notice, the Customer or an independent auditor bound by confidentiality may audit that compliance at the Customer's cost, in a way that does not expose other customers' data.
Every hiring decision step the Customer takes in the service is logged with its time and actor, and the Customer can download an audit pack for any role at any time.
insiderOne will give reasonable help with any data protection impact assessment or prior consultation the Customer is required to carry out about the service.
The Customer can export its data at any time on every plan. When the agreement ends, insiderOne will delete or anonymise the Customer's Candidate Personal Data within 30 days, except where the law requires it to be kept, in which case it is kept only for that purpose and remains protected by this agreement.
On data protection, this agreement takes precedence over the Terms of Service. Liability under it is subject to the limits in the Terms. It lasts as long as insiderOne processes Candidate Personal Data for the Customer.
Aurist Private Limited · North Lakhimpur, Assam, India
Email: contactus@insiderone.in