/

/

Privacy Policy

Privacy Policy

Privacy Policy

Privacy Policy

1. Introduction

1. Introduction

Space Inventive Private Limited (“Company,” “Space Inventive,” “we,” “us,” or “our”) develops and operates Talliant, an AI-powered talent engagement and recruitment automation platform made available through https://talliant.com (the “Website”) and https://app.talliant.ai (the “Application,” and together with the Website, the “Platform”). 


This Privacy Policy explains how we collect, use, disclose, and safeguard Personal Data in connection with the Platform, and describes the rights available to individuals whose Personal Data we process. 


This Privacy Policy is incorporated by reference into, and should be read together with, our Cookie Policy and our Terms of Use, each of which forms part of the overall terms governing use of the Platform. Where this Privacy Policy and the Terms of Use address the same subject matter, this Privacy Policy governs with respect to the processing of Personal Data. Capitalized terms used but not otherwise defined in this Privacy Policy have the meaning given to them in Appendix A (Definitions) to this Privacy Policy, which serves as the consolidated glossary for this Privacy Policy, our Cookie Policy, and our Terms of Use. 

Candidates: this Privacy Policy describes our processing activities at the platform level. A dedicated Candidate Privacy Policy, written specifically for individuals applying for jobs through Talliant, is also available and should be read if you are a Candidate.

2. Scope

2. Scope

This Privacy Policy applies to Personal Data processed through the Website, the Application, related demonstration and onboarding forms, customer support interactions, and any AI-enabled feature of the Platform. 


This Privacy Policy applies to four categories of individuals: (a) Candidates who are assessed, screened, engaged, or interviewed using the Platform; (b) Recruiters and other authorized users acting on behalf of a Customer; (c) Customers, meaning the organizations that have entered into an agreement with us to use the Platform, together with their authorized personnel; and (d) Website Visitors who browse our public Website without creating an account. 


Where a Customer deploys the Platform to process Candidate or Recruiter Personal Data, the Customer generally acts as the data controller (or “Data Fiduciary” under the DPDP Act) for that Personal Data, and Space Inventive acts as a data processor providing the Platform under the applicable customer agreement and any Data Processing Addendum (“DPA”). This Privacy Policy describes our processing activities in that capacity, as well as in our own capacity as controller for Website Visitor and direct Customer account data. 

3. Information We Collect

3. Information We Collect

3.1 Information from Candidates 

  • Name, contact details (email and phone number), resume or CV content, work history, education, skills, and certifications. 

  • Responses provided during AI-assisted pre-screening conversations, structured interview answers, and any video, audio, or transcript generated during an AI-led or AI-proctored interview, where such a feature is enabled by the relevant Customer. 

  • Assessment outputs generated by the Platform, including fit scores, ranking indicators, and screening notes. 

  • Technical and integrity-related signals reasonably necessary to support interview-proctoring features, where enabled by the Customer, and only to the extent disclosed to the Candidate by that Customer prior to the interview. 

  • We do not intentionally collect government identification numbers, financial account details, or other special-category or sensitive personal data through the Platform, unless voluntarily provided by a Candidate as part of an application (for example, a disability accommodation request), in which case such data is processed only for the disclosed purpose and in accordance with applicable law. 

3.2 Information from Recruiters

  • Name, business contact details, role or title, and account credentials. 

  • Actions taken within the Platform, including pipeline configuration, notes, feedback, and approvals. 

  • Communications with our support team. 

3.3 Information from Customers

  • Company name, billing and contact details, industry, and headcount or hiring-volume information provided during onboarding or through the Contact Us and Book a Demo forms. 

  • Configuration data, integration credentials for connected human-resources systems, and usage and analytics data associated with the Customer's account. 

3.4 Website Visitors

  • Information submitted through the Contact Us and Book a Demo forms, including first and last name, business email, phone number, company name, job role, industry, hiring volume, and stated hiring goals. 

  • Device and usage information collected automatically, including IP address, browser type, pages viewed, and referring URL. 

  • Information collected through cookies and similar technologies, as described in our Cookie Policy. 

4. How We Use Information

4. How We Use Information

  • To provide, operate, secure, and improve the Platform, including resume parsing, candidate matching, scheduling, interview facilitation, and reporting. 

  • To respond to inquiries submitted through the Website and to schedule and deliver product demonstrations. 

  • To communicate with Candidates on behalf of a Customer regarding application status, scheduling, and interview logistics, through channels enabled by that Customer, which may include email, telephone, and WhatsApp Business messaging. 

  • To maintain security, detect and prevent fraud or misuse, and enforce our Terms of Use. 

  • To comply with applicable legal, regulatory, and contractual obligations. 

  • For internal analytics, product development, and aggregated or de-identified benchmarking, provided that such analytics do not identify a specific Candidate to a Customer other than the one that submitted the underlying data, except where reasonably necessary for platform-wide safety or fraud prevention. 

AI Processing 

The Platform uses artificial intelligence and machine-learning models to support resume screening, candidate matching, fit scoring, AI-assisted pre-screening conversations, and interview analytics (collectively, “AI Processing”). 


AI Processing is designed to surface structured, explainable recommendations and insights that assist Customers and their Recruiters. It is not designed, and must not be used, as the sole basis for a final hiring decision; see “Human Oversight” below and the “No Employment Decision Guarantee” section of our Terms of Use. 


Where AI Processing produces an output that could have a legal or similarly significant effect on a Candidate, the Platform is configured, and Customers are contractually required, to ensure a qualified human reviewer is involved before such a decision is finalized, consistent with Article 22 of the GDPR and analogous requirements under other applicable law. 


We maintain internal documentation describing the intended purpose, inputs, and known limitations of AI features used in the Platform, made available to Customers and, on reasonable request and subject to confidentiality obligations, to regulators. . 

Responsible AI Principles 

Our approach to AI Processing is designed to operationalize recognized AI governance principles as follows: 

  • Transparency — Candidates and Customers are told when AI Processing is used, and internal documentation of each AI feature's purpose and known limitations is maintained. 

  • Human Oversight — no employment decision having a legal or similarly significant effect is made without an opportunity for qualified human review. 

  • Fairness — AI features used for candidate screening and scoring are developed and periodically evaluated with the objective of reducing unlawful bias. 

  • Security — AI Processing is subject to the same access controls, encryption, and monitoring safeguards described under “Information Security” below. 

  • Privacy by Design — AI features are built to use the minimum Personal Data reasonably necessary for their stated purpose. 

  • Accountability — we maintain internal ownership for AI governance decisions and make relevant documentation available to Customers and, where legally required, to regulators. 

See also our standalone Responsible AI Principles and AI Transparency Statement (Phase 2), which expand on this section in candidate-friendly and public-facing form. 

Human Oversight 

Human oversight is a core design principle of the Platform. Recruiters and hiring managers retain the ability to review, override, or disregard any AI-generated recommendation, score, or ranking. 


We provide Customers with tools to configure human-in-the-loop checkpoints at key stages of the hiring workflow, including prior to rejection or advancement decisions. 


A Candidate may request human review of an AI-assisted decision that materially affects them by contacting the Customer that administered the relevant hiring process, or, where that Customer is unable to respond, by contacting us at privacy@spaceinventive.com. 

Multiple AI Providers 

Depending on the specific feature, Customer configuration, and service requirements, the Platform may use AI models developed by Space Inventive and, in certain cases, models developed by third-party AI model providers (“AI Subprocessors”). 


We select AI Subprocessors based on their security posture, data-handling commitments, and suitability for the relevant task. Our contractual terms with each AI Subprocessor are designed to prohibit use of Customer or Candidate Personal Data to train the AI Subprocessor's general-purpose models, unless appropriate consent has been obtained or the relevant Customer has separately agreed otherwise. 


A current list of categories of AI Subprocessors is maintained as part of our Subprocessor disclosures described in Section 9, and is available on request. 

6. DPDP Compliance (India)

6. DPDP Compliance (India)

Where we act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), we process Personal Data on the basis of consent or another ground permitted under the DPDP Act, provide a clear and itemized notice at or before collection, and limit processing to the purpose for which consent was given.

Where we act as a Data Processor on behalf of a Customer that is a Data Fiduciary, we process Candidate and Recruiter Personal Data solely under a valid contract with that Customer and in accordance with its instructions.

We implement reasonable security safeguards designed to prevent personal data breaches and maintain a process to notify the Data Protection Board of India and affected Data Principals of any personal data breach in the manner and timeframe prescribed by applicable rules.

Data Principals may exercise the rights described in Section 12 (DPDP Rights) below and may raise grievances with our Grievance Officer identified in Section 15 prior to approaching the Data Protection Board. 


If we are notified as a Significant Data Fiduciary under the DPDP Act, we will comply with the additional obligations that designation entails, including any applicable requirements to conduct data protection impact assessments, undertake periodic independent audits, and appoint a Data Protection Officer based in India. 

7. International Data Transfers

7. International Data Transfers

Our infrastructure is hosted in the AWS Mumbai (ap-south-1) region in India. Certain AI Subprocessors, support tools, or Customers may be located outside India, which may result in cross-border transfer of Personal Data.

Where Personal Data originating in the European Economic Area or the United Kingdom is transferred outside those territories, we rely on recognized transfer mechanisms, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, supplemented where appropriate by additional technical and organizational safeguards.

Cross-border transfers of Personal Data subject to the DPDP Act are made in accordance with Section 16 of the DPDP Act. As of the effective date of this Privacy Policy, no restriction on transfers to specific countries has been notified under that section; we will comply with any such restriction if and when notified. 


Customers requiring a specific transfer-impact assessment or executed transfer clauses for their own compliance program may request these at privacy@spaceinventive.com. See also our Data Residency Statement (Phase 2). 

8. Data Sharing

8. Data Sharing

  • With the Customer on whose behalf a Candidate's or Recruiter's Personal Data is processed. 

  • With Subprocessors described in Section 9, under written contractual terms requiring confidentiality and appropriate security measures. 

  • With professional advisers, auditors, and insurers, where necessary and subject to confidentiality obligations. 

  • With regulators, law enforcement, or other third parties where required by applicable law, legal process, or to protect the rights, safety, or property of Space Inventive, our Customers, or others. 

  • In connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality commitments consistent with this Privacy Policy. 

We do not sell Personal Data, and we do not share Personal Data with third parties for their own independent marketing purposes.

9. Subprocessors

9. Subprocessors

  • Cloud infrastructure and hosting: Amazon Web Services (AWS), Mumbai (ap-south-1) region. 

  • Database hosting: MongoDB Atlas. 

  • AI model providers: One or more third-party AI Subprocessors, selected as described under “Multiple AI Providers” above, depending on feature and Customer configuration. 

  • Communications: Email-delivery providers and, where enabled by a Customer, the WhatsApp Business Platform operated by Meta Platforms, Inc., used to deliver candidate scheduling and status communications. 

  • Analytics and marketing tools used on the public Website, as described in our Cookie Policy. 

  • Customer relationship management, scheduling, and support-ticketing tools used to operate our business. 

A current, itemized Subprocessor list, including the identity and location of each Subprocessor, is maintained and made available to Customers under their applicable DPA and on request to privacy@spaceinventive.com. See also our Authorized Subprocessors page (Phase 2). 

10. Data Retention

10. Data Retention

Candidate Personal Data is retained for the period instructed by the relevant Customer, consistent with that Customer’s record-keeping obligations, and is deleted or anonymized thereafter in accordance with the Customer’s instructions or, absent instructions, our standard retention schedule.

Recruiter and Customer account data is retained for the duration of the applicable customer agreement and for a limited period thereafter to address billing, legal, audit, or dispute-resolution needs.

Website Visitor form submissions are retained as long as reasonably necessary to respond to the inquiry and for a limited period thereafter, unless earlier deletion is requested. Cookie-related data is retained in accordance with the durations set out in our Cookie Policy.

11. Information Security

11. Information Security

AWS Hosting

The Application is hosted on Amazon Web Services infrastructure in the Mumbai (ap-south-1) region, which provides physical, environmental, and network-level security controls independently maintained by AWS.

MongoDB

Atlas provides network isolation, encrypted storage, and audit-logging capabilities that we configure and monitor.

Encryption

We implement encryption of Personal Data in transit using industry-standard protocols, such as TLS, and encryption of Personal Data at rest within our hosting and database environments.

Access Controls

Access is restricted on a role-based, least-privilege basis, with authentication controls, periodic access reviews, and logging of administrative actions.

Access Reviews

We conduct periodic reviews of user access to Personal Data and Platform infrastructure to confirm that access remains limited to personnel who require it for their role, and to promptly revoke access that is no longer needed. 

Secure Development Lifecycle (Secure SDLC) 

We maintain a secure development lifecycle intended to incorporate security requirements, code review, and testing at each stage of the software development process, including for AI-enabled features, prior to production release. 

Vulnerability Management 
We operate a vulnerability management process that includes regular scanning, risk-based prioritization, and defined remediation timeframes, supplemented by periodic third-party security testing. See also our Vulnerability Disclosure Policy (Phase 2). 

Security Monitoring 
We maintain monitoring and alerting over production systems designed to help detect anomalous activity, unauthorized access attempts, and potential security events in a timely manner. 

Audit Logging
We maintain audit logs of significant administrative and access events, retained for a period sufficient to support security investigations and applicable regulatory requirements. 

Backup & Disaster Recovery 
We maintain backup procedures and a disaster recovery approach intended to support restoration of service and data within a reasonable timeframe, consistent with any specific recovery objectives agreed with a Customer under its MSA. 

Incident Response 
We maintain an incident-response process designed to detect, contain, and remediate security incidents, and to notify affected Customers, individuals, and regulators as required by applicable law, including, where applicable, within seventy-two (72) hours of becoming aware of a qualifying personal data breach under the GDPR, and within the timeframe prescribed under the DPDP Act. 


Our security program is designed and maintained in a manner intended to align with recognized frameworks, including ISO/IEC 27001 and SOC 2, and to support ISO/IEC 27701 privacy-information-management practices, as part of our roadmap toward formal certification. No certification is claimed as of the effective date of this Privacy Policy unless separately confirmed to a Customer in writing. See also our Security Overview and Compliance Overview (Phase 2). 

No method of transmission or storage is completely secure. While we work to protect Personal Data using the measures described above, we cannot guarantee absolute security. 

12. Your Rights

12. Your Rights

GDPR Rights
Individuals in the European Economic Area or the United Kingdom whose Personal Data is subject to the GDPR have rights to access, rectification, erasure, restriction, portability, objection, consent withdrawal, protection from solely automated decisions producing legal or similarly significant effects, and complaint to a competent supervisory authority.

DPDP Rights
Data Principals whose Personal Data is subject to the DPDP Act have rights to obtain a summary of Personal Data being processed; request correction, completion, updating, or erasure; have grievances addressed by our Grievance Officer; nominate another individual to exercise rights in the event of death or incapacity; and withdraw consent where consent is the basis for processing.

California Rights (Where Applicable)
Residents of California whose Personal Information is subject to the CCPA/CPRA have rights to know, delete, correct, opt out of sale or sharing, limit use of sensitive Personal Information, and not receive discriminatory treatment for exercising rights.

To exercise rights, Candidates and Recruiters should first contact the Customer that administers the relevant hiring process. Where we are the appropriate party to respond, requests may be submitted to privacy@spaceinventive.com.

13. Children’s Privacy

13. Children’s Privacy

The Platform is intended for use by working professionals and organizations and is not directed to children. We do not knowingly collect Personal Data from individuals under the minimum age required for consent in their jurisdiction, including under eighteen (18) years of age for purposes of the DPDP Act, or under sixteen (16) years, or such other age as applicable, under the GDPR.

14. Updates to This Privacy Policy

14. Updates to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated Privacy Policy on the Website with a revised “Last Updated” date and, where changes are material, will provide additional notice to Customers as required under the applicable customer agreement.

15. Contact Information

15. Contact Information

  • Privacy inquiries and rights requests: privacy@spaceinventive.com

  • Security inquiries and vulnerability reports: security@spaceinventive.com

  • Grievance Officer (DPDP Act): [to be designated prior to publication — name and designation], reachable at privacy@spaceinventive.com

  • Registered Office: Space Inventive Private Limited, 2nd Floor, Tower-B, Phoenix Primea, Plot No. 40 & 41, Road No. 2, Near US Embassy, Financial District, Nanakramguda, Hyderabad, Telangana – 500032, India

Appendix A — Definitions

Appendix A — Definitions

  • “Application” means the Talliant web application available at https://app.talliant.ai.

  • “Website” means the public marketing website available at https://talliant.com.

  • “Platform” means the Website and the Application together.

  • “Company,” “Space Inventive,” “we,” “us,” or “our” means Space Inventive Private Limited.

  • “Candidate” means an individual who is assessed, screened, engaged, or interviewed using the Platform in connection with a hiring process administered by a Customer.

  • “Recruiter” means an individual authorized by a Customer to use the Application on the Customer’s behalf.

  • “Customer” means the organization that has entered into an agreement with us to use the Platform, together with its authorized personnel, including Recruiters.

  • “Website Visitor” means an individual who browses the Website without an Application account.

  • “Personal Data” or “Personal Information” means information relating to an identified or identifiable individual.

  • “Customer Data” has the meaning given in our Terms of Use and includes Personal Data and other business data submitted by a Customer to the Platform.

  • “Controller” / “Data Fiduciary” means the party that determines the purpose and means of processing Personal Data. “Processor” / “Data Processor” means the party that processes Personal Data on behalf of, and under the instructions of, a Controller or Data Fiduciary.

  • “Subprocessor” means a third party engaged by us to support delivery of the Platform.

  • “AI Subprocessor” means a Subprocessor that provides an AI model used in connection with AI Processing.

  • “MSA” means a master subscription agreement or other signed order form entered into between Space Inventive and a Customer.

  • “DPA” means a Data Processing Addendum entered into between Space Inventive and a Customer governing the processing of Personal Data under the applicable MSA.

  • “Grievance Officer” means the individual designated under Section 15 to receive and address grievances under the DPDP Act.