What Machanx Technologies Pvt Ltd ("Machanx", "RecruitMX", "we", "us") collects, why, and the consent you give us when you create a RecruitMX account — written to meet India's Digital Personal Data Protection Act, 2023 (DPDP Act), the EU/UK General Data Protection Regulation (GDPR), and other applicable data protection laws.
Effective & last updated: 18 July 2026
RecruitMX is a recruitment CRM: our customers ("Organisations", "you", account holders) use it to manage jobs, candidates, employees and interviews. On sign-up, the Organisation acts as the Data Fiduciary / Data Controller for the personal data of the candidates and employees it uploads, and Machanx acts as the Data Processor processing that data solely on the Organisation's instructions. See §2 for what this means and what the Organisation is responsible for.
This policy applies to app.recruitmx and the RecruitMX marketing site (together, the "Service"), operated by Machanx Technologies Pvt Ltd ("Machanx"), a company incorporated in India. It explains what personal data we process, on what legal basis, and the rights available to you under:
Where a term in this policy is defined differently across these laws (e.g. "Data Principal" under the DPDP Act vs. "Data Subject" under the GDPR), we use the terms interchangeably to mean the natural person the personal data is about.
| Data | Who is the Fiduciary / Controller | What that means |
|---|---|---|
| The Organisation's own account data — the signing-up admin's name, work email, password, and the organisation's name | Machanx | We determine why and how this data is processed (running your account) and are directly answerable to you for it under this policy. |
| Candidate, employee, interview and document data your team uploads or enters into RecruitMX | Your Organisation | Your Organisation decides what candidate/employee data to collect and why. Machanx processes it only to provide the Service, per your instructions and our Data Processing Terms — never for our own purposes. Your Organisation is responsible for having a lawful basis (including, where required, the individual's own consent) before uploading someone's personal data to RecruitMX. |
If you are a candidate, employee, or interviewee whose data was added to RecruitMX by an Organisation you applied to or work for, please direct data rights requests to that Organisation first — they control the data. If they're unresponsive, you may also contact us at tech@machanx.com and we'll assist in routing your request.
pdf-parse, mammoth and, where AI-assisted CV parsing is enabled, an OpenAI API integration — see §7)rmx_token) — see §12Under the GDPR (Art. 6(1)), we rely on one or more of:
Under the DPDP Act, our primary basis is your consent (Section 6), given freely, specifically and unambiguously at sign-up (§6 below), supplemented where applicable by the "legitimate uses" permitted under Section 7 (e.g. for a specified purpose you voluntarily provided data for, or to comply with a legal obligation), without needing a separate consent request.
When you create a RecruitMX account, you actively tick a consent checkbox confirming that:
This consent is granular and revocable: you may withdraw it at any time by writing to tech@machanx.com or deleting your account from Settings. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and — as with any SaaS product — may mean we can no longer provide the Service to you (Section 6(4), DPDP Act; Art. 7(3), GDPR).
Where the Act requires it, notices seeking consent are given in clear, plain language, separately from other terms, specifying exactly what personal data is collected and for what purpose (Section 5, DPDP Act), and are also available in English on this page at all times.
We do not sell personal data. We share it only with:
Our infrastructure may process or store data outside your (or your Organisation's) home country. Where personal data originating in the EU/UK is transferred outside the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. The DPDP Act currently permits cross-border transfer of personal data except to countries restricted by the Central Government by notification; we do not transfer data to any such restricted country.
We retain account and candidate/employee data for as long as your Organisation's account is active, plus a reasonable period afterward to allow account recovery and to meet legal, accounting or reporting obligations. Password-reset tokens and OTPs are short-lived (expire ~30 minutes after issue — see our reset-password flow) and are stored only as one-way hashes. You or your Organisation admin may request deletion at any time (see §11); we will erase or anonymise the data unless we're legally required to keep it.
No method of transmission or storage is 100% secure; we work to industry standard practices and will notify affected users as described in §14 if a breach occurs.
To exercise any of these rights, email tech@machanx.com. We will verify your identity and respond within the time limits required by applicable law.
We use a strictly-necessary session cookie (rmx_token) to keep you signed in — this
isn't used for advertising or cross-site tracking, and doesn't require consent under most cookie
laws as it's essential to the Service. If we add optional analytics or marketing cookies in future,
we will ask for your consent first via a cookie banner and update this section.
RecruitMX is a B2B workplace tool and is not directed at, or knowingly used to collect data from, children (under 18, per the DPDP Act's definition, or under 16/13 under other applicable laws). If you believe a child's personal data has been provided to us, contact us at tech@machanx.com and we will delete it.
If we become aware of a personal data breach that's likely to result in risk to you, we will notify affected Organisations and, where legally required, the relevant supervisory authority (e.g. the Data Protection Board of India, or your EU/UK supervisory authority) without undue delay, describing the nature of the breach and the steps taken in response.
We may update this policy as our Service or applicable law evolves. Material changes will be notified by email and/or an in-app notice before they take effect, and, where required, we will seek fresh consent. The "last updated" date at the top of this page always reflects the current version.
Per Section 8(9) of the DPDP Act and Art. 27 GDPR (where applicable), you can reach our data protection point of contact / Grievance Officer here:
We aim to acknowledge grievances within 7 days and resolve them within the timelines prescribed by applicable law.