Privacy Policy

IYOVThreshing Floor Group Pvt Limited

Effective: January 1, 2025Last Updated: June 24, 2026

Summary

  • We collect data needed to run background checks, manage recruitment, and operate HR tools.
  • We never sell your personal data to third parties.
  • Candidates receive email notifications at every stage of the interview process.
  • You can request access, correction, or deletion of your data at any time.
  • Data is encrypted in transit and at rest; we are hosted on AWS (India region).

1. Introduction

Threshing Floor Group Pvt Limited ("we", "our", or "us") operates the IYOV platform — a suite of enterprise HR, background verification, learning, and recruitment tools accessible at https://iyov.ai (also at tfgverify.com) and the following sub-domains: hrms.iyov.ai, employee.iyov.ai, portal.iyov.ai, lms.iyov.ai, crm.iyov.ai (collectively, the "Platform"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights you have over your data. It applies to all users of the Platform including HR professionals, employers (Organisations), job seekers, candidates undergoing background verification, employees accessing HRMS features, and learners using the LMS. By accessing or using the Platform you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue use immediately.

2. Who We Are & Controller Details

Data Controller: Threshing Floor Group Pvt Limited India Office: T-Hub, Plot No 1/C, Sy No 83/1, Raidurgam, Knowledge City Rd, Panmaktha, Hyderabad, Telangana 500032, India Delivery Centre: STPI, DivyaSree Solitaire Building, 15, Inorbit Mall Road, Madhapur, Hyderabad, Telangana 500081, India USA Office: 2245 Texas Drive Suite 300, Sugar Land, TX 77479, USA Phone: +91 888 60 99002 | +91 888 69 19192 Email: connect@tfgroup.ai Website: https://iyov.ai For Indian users, we comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000. For users in other jurisdictions, we adhere to applicable local privacy laws.

3. Personal Data We Collect

3.1 Data You Provide Directly

  • Identity data: Full name, date of birth, gender, nationality, government-issued ID numbers (Aadhaar, PAN, Passport, driving licence)
  • Contact data: Email address, phone number, residential and postal address
  • Professional data: Current and previous employment history, job titles, employer names, dates of employment, reason for leaving
  • Educational data: Degrees, institutions, graduation years, roll numbers, marks/grades
  • Resume/CV: Uploaded documents, skills, work samples, portfolio links
  • Interview data: Responses during AI screening, written answers, video/audio recordings (if enabled), ratings and HR feedback
  • Account credentials: Username, hashed password, security questions
  • Payment data: Billing name, address, GST number — payment card details are never stored and are handled by PCI-DSS compliant processors
  • Communication data: Messages sent via the platform's chat or ticketing system, HR notes, BGV consent responses

3.2 Data We Collect Automatically

  • Device & browser data: IP address, browser type and version, operating system, device identifiers
  • Usage data: Pages visited, features used, time on page, click paths, session duration, search queries within the Platform
  • Log data: Server logs, error reports, API request/response metadata (excluding payload content)
  • Cookie data: Session tokens, preference cookies, analytics identifiers (see Section 9 — Cookies)
  • Location data: Approximate location derived from IP address; precise GPS location is only collected with explicit consent for offline interview check-in

3.3 Data Received from Third Parties

  • Employer-provided data: When an organisation initiates a background verification (BGV), they may upload candidate details on the candidate's behalf after obtaining consent
  • Reference data: Names and contact information of professional references provided by the candidate or HR
  • Third-party verification sources: Public records, educational institution databases, previous employer confirmations, court record databases, credit bureaus (where legally permitted and with consent)
  • Google Calendar: If you connect Google Calendar via OAuth 2.0, we receive access tokens and basic calendar event data solely to schedule interviews on your behalf
  • Job boards: If you apply via an integrated job board, we receive the application data submitted to that board

3.4 Special Category Data

We process special category data (sensitive personal data) only where necessary and with explicit consent or as required by law. This may include criminal record checks (for BGV), disability accommodations (for interview scheduling), and similar sensitive information. You may withdraw consent at any time, subject to legal obligations.

4. How We Use Your Data

4.1 Core Platform Services

  • Creating and managing your account
  • Conducting background verification checks across employment, education, address, criminal, and credit categories
  • Managing the full recruitment lifecycle — job posting, AI screening, interview scheduling, offer management, hiring
  • Operating the HRMS — employee records, attendance, leave management, payroll inputs, letter generation
  • Delivering LMS courses, tracking progress, issuing certificates
  • Operating the CRM — lead management, contact data, deal pipeline
  • Sending transactional emails — interview invitations, round results, offer letters, credentials, BGV consent requests
  • Authenticating users and maintaining session security

4.2 Communication & Notifications

  • Interview schedule confirmations and reminders
  • Round result notifications (Passed / Not Selected) sent to candidates
  • BGV status updates and consent requests
  • Platform announcements, product updates, and maintenance notices
  • Promotional communications about new features or partner services (only with your explicit opt-in consent)

4.3 Analytics & Improvement

  • Understanding how users interact with the Platform to improve UX and fix bugs
  • Generating aggregated, anonymised analytics dashboards for internal reporting
  • Training AI models used for resume screening, interview feedback parsing, and role-matching — only where you have explicitly consented under the 'AI Training' option in your Privacy Settings
  • Fraud detection and prevention

4.4 Legal & Compliance

  • Complying with applicable laws, regulations, and court orders
  • Responding to lawful requests from government and regulatory authorities
  • Enforcing our Terms of Service and other agreements
  • Investigating suspected violations, fraud, or security incidents

6. Data Sharing & Third Parties

We do not sell your personal data. We share it only as described below: Organisations (Employers): Candidate data is shared with the employing organisation that initiated the recruitment or BGV process, strictly for that purpose. Verification Partners: For BGV, we share the minimum necessary data with accredited verification agencies, court record providers, credit bureaus, and educational institution verification services. Cloud Infrastructure: We use AWS (Amazon Web Services) to host the Platform. Data may be processed in AWS data centres located in India (ap-south-1) and, where necessary, in the US or EU with appropriate safeguards. Email & Communication Services: We use third-party email delivery services (e.g., SendGrid / AWS SES) to send transactional emails. These providers act as Data Processors and are contractually bound to process data only on our instructions. Payment Processors: Billing is handled by PCI-DSS compliant processors. We do not receive or store full card details. Analytics Tools: We use anonymised/aggregated usage data with analytics tools. No individually identifiable data is shared. Legal Disclosures: We may disclose data to law enforcement, regulators, or courts where required by law or to protect the rights, property, or safety of the Platform, our users, or the public. Business Transfers: In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity, subject to equivalent privacy protections.

7. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy or as required by applicable law. Account data: Retained for the duration of the active account plus 3 years after account closure, unless deletion is requested. BGV records: Retained for 7 years as required under Indian labour and archival regulations, or longer where mandated by specific sector regulations. Interview records (schedules, round results, feedback): Retained for 2 years from the date of the last activity on the application. Employee HRMS records: Retained for the duration of employment plus 5 years, in accordance with the Shops and Establishments Act and related statutes. LMS data (course progress, certificates): Retained for 5 years; certificates are maintained indefinitely for verification purposes. Usage logs and analytics: Anonymised after 90 days; raw logs deleted after 12 months. Upon expiry of the applicable retention period, data is securely deleted or anonymised so that it can no longer identify an individual.

8. Security

We implement technical and organisational measures appropriate to the risk level of data processing: Encryption: All data is encrypted in transit using TLS 1.2+. Sensitive data at rest is encrypted using AES-256. Access control: Role-based access control (RBAC) ensures users can only access data relevant to their role and organisation. Multi-factor authentication (MFA) is available for all accounts. Infrastructure security: Our cloud infrastructure is protected by VPCs, security groups, WAF, and regular penetration testing. Employee access: Access to production systems is restricted to authorised personnel on a need-to-know basis. Incident response: We maintain an incident response plan. In the event of a data breach, we will notify affected users and regulators within the timeframes required by applicable law (72 hours under GDPR; promptly under DPDP Act 2023). Audit logs: All access to sensitive data is logged and periodically audited. No method of transmission or storage is 100% secure. If you suspect unauthorised access to your account, contact us immediately at connect@tfgroup.ai.

9. Cookies & Tracking Technologies

You can manage cookie preferences at any time via your browser settings or the Privacy Settings panel in your account. Note that disabling essential cookies will prevent you from logging in. We do not use third-party advertising networks or sell cookie data to data brokers.

Types of Cookies We Use

  • Essential cookies: Required for authentication (session token), CSRF protection, and core Platform functionality. Cannot be disabled.
  • Preference cookies: Remember your UI preferences (language, theme, sidebar state). Can be disabled.
  • Analytics cookies: Collect anonymised data on page visits and feature usage to help us improve the Platform. Can be disabled.
  • Marketing cookies: Only set if you have opted into marketing communications. Can be disabled at any time.

10. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data: Right of Access: Request a copy of the personal data we hold about you. Right to Rectification: Ask us to correct inaccurate or incomplete data. Right to Erasure ('Right to be Forgotten'): Request deletion of your data, subject to our legal retention obligations. Right to Restriction: Ask us to restrict processing of your data in certain circumstances. Right to Data Portability: Receive your data in a machine-readable format. Right to Object: Object to processing based on legitimate interests or for direct marketing. Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing. Right not to be subject to automated decisions: Request human review of decisions made solely by automated means that significantly affect you. Indian users: Under the DPDP Act 2023, you have the right to access information, correct inaccuracies, nominate a nominee, and seek grievance redressal. To exercise any of these rights, email us at connect@tfgroup.ai with the subject "Privacy Rights Request". We will respond within 30 days (or within the statutory timeframe required by your jurisdiction). We may ask for proof of identity before processing the request.

11. Children's Privacy

The Platform is not directed at children under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at connect@tfgroup.ai and we will delete it promptly.

12. International Data Transfers

Our primary data centre is in India (AWS ap-south-1). Where data is transferred outside India or the EEA, we ensure appropriate safeguards are in place, including: • Standard Contractual Clauses (SCCs) approved by the European Commission • Data Processing Agreements with sub-processors • Adequacy decisions where applicable By using the Platform, you acknowledge that your data may be transferred to and processed in countries other than your country of residence.

13. Grievance Redressal (India)

In accordance with the Information Technology Act, 2000, and the DPDP Act 2023, the name and contact details of our Grievance Officer are: Name: Privacy & Compliance Team Email: grievance@tfgroup.ai Response time: Within 30 days of receipt of complaint You may also lodge a complaint with the Data Protection Board of India once it is constituted under the DPDP Act 2023, or with your local supervisory authority (for EEA users, the relevant EU Data Protection Authority).

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email and/or a prominent notice on the Platform at least 14 days before the changes take effect. The "Last Updated" date at the top of this page reflects the most recent revision. Your continued use of the Platform after the effective date of any changes constitutes acceptance of the updated policy.

15. Contact Us

For any questions, concerns, or requests related to this Privacy Policy or the processing of your personal data, please reach out to: Threshing Floor Group Pvt Limited Email: connect@tfgroup.ai Phone: +91 888 60 99002 | +91 888 69 19192 India Office: T-Hub, Hyderabad, Telangana 500032, India USA Office: 2245 Texas Drive Suite 300, Sugar Land, TX 77479, USA Website: https://iyov.ai We are committed to resolving privacy concerns promptly and transparently.

© 2026 Threshing Floor Group Pvt Limited. All rights reserved.