Legal

Privacy Policy

Learn how Bear Systems HRT collects, processes, stores, and protects personal information to deliver secure and compliant HR technology services.

Last Updated: October 27, 2025Effective: October 27, 2025

1. Introduction and Scope

Bear Systems LLC ("Bear Systems," "Company," "we," "us," or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Human Resource Technology platform, AI-powered recruitment tools, and related services (collectively, the "Services").

This Privacy Policy applies to all users of our Services, including job seekers, employers, HR professionals, and visitors to our website. It covers all personal information we collect through our Services, regardless of how you access or use them.

By using our Services, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your personal information as described herein.

2. Information We Collect

2.1 Personal Information You Provide

We collect information you voluntarily provide to us, including:

  • Account Information: Name, email address, password, phone number, job title, company name
  • Professional Profile: Resume, work experience, education, skills, certifications, portfolio
  • Communication Data: Messages, feedback, support requests, survey responses
  • Payment Information: Billing address, payment method details (processed by secure third parties)
  • Identity Verification: Government-issued ID, tax identification numbers (when required)
  • Background Information: Employment history, references, criminal background checks (with consent)

2.2 Information Collected Automatically

Technical Information

  • IP address and geolocation data
  • Device identifiers and characteristics
  • Browser type, version, and language settings
  • Operating system information
  • Screen resolution and device type
  • Network connection information

Usage Information

  • Pages viewed and content accessed
  • Time spent on different sections
  • Click patterns and navigation paths
  • Search queries and filters used
  • Feature usage and interaction data
  • Error logs and performance metrics

2.3 Information from Third Parties

  • Social media profiles and professional networks (LinkedIn, etc.)
  • Public databases and professional directories
  • Background check providers and verification services
  • Recruitment partners and job boards
  • Analytics and advertising partners
  • Government and regulatory databases

3. How We Collect Information

Direct Collection Methods

  • Account registration and profile creation
  • Form submissions and applications
  • Customer support interactions
  • Survey participation and feedback
  • Email and phone communications
  • Event registrations and webinars
  • File uploads and document submissions

Automated Collection Methods

  • Cookies and similar tracking technologies
  • Web beacons and pixel tags
  • Server logs and analytics tools
  • Mobile app usage tracking
  • API integrations and data feeds
  • Social media plugins
  • Third-party analytics services

4. How We Use Information

4.1 Primary Service Purposes

  • Provide and operate our HR technology platform and AI services
  • Match candidates with job opportunities using our algorithms
  • Analyze and score resumes, profiles, and applications
  • Generate recruitment insights and analytics
  • Facilitate communication between employers and candidates
  • Process payments and manage subscriptions
  • Provide customer support and technical assistance

4.2 Service Improvement and Development

  • Improve our AI models and machine learning algorithms
  • Develop new features and services
  • Conduct research and analysis on HR trends
  • Test and optimize user experience
  • Monitor service performance and reliability
  • Debug errors and troubleshoot technical issues

4.3 Legal and Compliance Purposes

  • Comply with applicable laws and regulations
  • Respond to legal requests and court orders
  • Prevent fraud, abuse, and security threats
  • Enforce our Terms of Service and policies
  • Protect our rights and interests
  • Conduct audits and regulatory reporting

4.4 Communication and Marketing

  • Send service updates and notifications
  • Provide customer support and technical assistance
  • Send marketing communications (with consent)
  • Conduct surveys and gather feedback
  • Announce new features and product updates
  • Share industry insights and thought leadership

5. Information Sharing and Disclosure

Our Commitment: We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We only share your information in the limited circumstances described below.

5.1 Authorized Sharing

  • With Your Consent: When you explicitly authorize us to share your information
  • Job Applications: With employers when you apply for positions or express interest
  • Profile Visibility: With recruiters and employers based on your privacy settings
  • Service Integration: With third-party services you choose to connect

5.2 Service Providers and Partners

We may share information with trusted service providers who assist us in:

  • Cloud hosting and data storage services
  • Payment processing and billing
  • Email delivery and communication platforms
  • Analytics and business intelligence
  • Customer support and help desk services
  • Background verification and screening
  • Marketing automation and CRM systems

All service providers are contractually bound to protect your information and use it only for the specified purposes.

5.3 Legal Requirements

We may disclose your information when required to:

  • Comply with applicable laws, regulations, or legal processes
  • Respond to valid government requests or court orders
  • Protect against fraud, security threats, or illegal activities
  • Defend our rights and interests in legal proceedings
  • Protect the safety of our users or the public
  • Enforce our Terms of Service and policies

5.4 Business Transactions

In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred as part of the transaction. We will provide notice and ensure continued protection under this Privacy Policy or a similar policy.

6. Data Retention and Deletion

6.1 Retention Principles

We retain your personal information only as long as necessary to fulfill the purposes for which it was collected, including:

  • Providing and improving our Services
  • Complying with legal obligations
  • Resolving disputes and enforcing agreements
  • Protecting against fraud and abuse

6.2 Specific Retention Periods

Data CategoryRetention PeriodLegal Basis
Account InformationDuration of account + 3 yearsContract, Legal Obligation
Profile and Resume DataDuration of account + 5 yearsConsent, Legitimate Interest
Communication Records7 yearsLegal Obligation
Usage and Analytics3 yearsLegitimate Interest
Financial Records10 yearsLegal Obligation

6.3 Secure Deletion

When personal information is no longer needed, we securely delete or anonymize it using industry-standard methods to ensure it cannot be reconstructed or identified.

7. Data Security Measures

7.1 Technical Safeguards

Encryption and Protection

  • AES-256 encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • End-to-end encryption for sensitive communications
  • Encrypted database storage and backups
  • Secure key management systems

Access Controls

  • Multi-factor authentication (MFA)
  • Role-based access controls (RBAC)
  • Principle of least privilege
  • Regular access reviews and audits
  • Secure session management

7.2 Operational Security

  • 24/7 security monitoring and incident response
  • Regular security audits and penetration testing
  • Vulnerability assessments and patch management
  • Employee security training and background checks
  • Secure development lifecycle (SDLC) practices
  • Business continuity and disaster recovery plans

7.3 Compliance Certifications

  • SOC 2 Type II certification
  • ISO 27001 information security management
  • GDPR compliance program
  • CCPA compliance framework
  • Regular third-party security assessments

8. Your Privacy Rights and Choices

8.1 Universal Rights

Regardless of your location, you have the right to:

  • Access: Request copies of your personal information
  • Rectification: Correct inaccurate or incomplete information
  • Deletion: Request removal of your personal information
  • Portability: Receive your data in a portable format
  • Object: Opt out of certain types of processing
  • Restrict: Limit how we use your information

8.2 Regional Rights

GDPR Rights (EU/UK)

  • Right to withdraw consent at any time
  • Right not to be subject to automated decision-making
  • Right to lodge complaints with supervisory authorities
  • Right to appoint a representative in the EU

CCPA Rights (California)

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to opt out of the sale of personal information
  • Right to non-discrimination for exercising privacy rights

8.3 How to Exercise Your Rights

To exercise any of your privacy rights, you can:

  • Use our privacy portal at privacy.bearsystems.com
  • Email us at privacy@bearsystems.com
  • Access settings in your account dashboard
  • Contact our Data Protection Officer

We will respond to valid requests within 30 days (or as required by applicable law).

9. Cookies and Tracking Technologies

9.1 Types of Technologies We Use

TechnologyPurposeDuration
Essential CookiesAuthentication, security, basic functionalitySession / 1 year
Analytics CookiesUsage statistics, performance monitoring2 years
Functional CookiesPreferences, personalization1 year
Marketing CookiesTargeted advertising, conversion tracking1–2 years

9.2 Managing Your Cookie Preferences

You can control cookies through:

  • Our cookie consent banner and preference center
  • Your browser settings and privacy controls
  • Industry opt-out tools (NAI, DAA, EDAA)
  • Platform-specific privacy settings (Google, Facebook)

10. International Data Transfers

10.1 Global Operations

As a global service, we may transfer your personal information to countries other than your own, including the United States, where our primary servers and operations are located.

10.2 Transfer Safeguards

When transferring data internationally, we ensure adequate protection through:

  • European Commission adequacy decisions
  • Standard Contractual Clauses (SCCs)
  • Binding Corporate Rules (BCRs)
  • Certification programs and codes of conduct
  • Explicit consent when required

10.3 Data Localization

Where required by local laws, we maintain data processing facilities and comply with data localization requirements in specific jurisdictions.

11. Children's Privacy Protection

Our Services are not intended for children under the age of 16 (or the minimum age for data processing in your jurisdiction). We do not knowingly collect personal information from children under this age.

If you are a parent or guardian and believe we have collected information about your child, please contact us immediately. We will take steps to delete such information from our systems.

For users aged 16–18, we may require parental or guardian consent in certain jurisdictions before providing our Services.

12. Third-Party Services and Links

12.1 Integrated Services

Our Services may integrate with third-party platforms and services, including:

  • Professional networking sites (LinkedIn, etc.)
  • Cloud storage providers
  • Background verification services
  • Payment processors
  • Analytics and marketing tools
  • Social media platforms

12.2 Third-Party Privacy Policies

This Privacy Policy does not apply to third-party services. We encourage you to review the privacy policies of any third-party services you use in connection with our platform.

12.3 External Links

Our Services may contain links to external websites. We are not responsible for the privacy practices or content of these external sites.

13. Legal Compliance Framework

13.1 Applicable Regulations

Our privacy practices comply with:

  • General Data Protection Regulation (GDPR) – EU/UK
  • California Consumer Privacy Act (CCPA) – California
  • Virginia Consumer Data Protection Act (VCDPA) – Virginia
  • Personal Information Protection and Electronic Documents Act (PIPEDA) – Canada
  • Lei Geral de Proteção de Dados (LGPD) – Brazil
  • Other applicable regional data protection laws

13.2 Legal Basis for Processing

We process your personal information based on:

  • Contract: To provide our Services and fulfill our agreement with you
  • Consent: When you explicitly agree to specific processing activities
  • Legitimate Interest: To improve our Services and operate our business
  • Legal Obligation: To comply with applicable laws and regulations
  • Vital Interest: To protect your safety or the safety of others

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable laws. When we make material changes, we will:

  • Provide at least 30 days' advance notice via email or platform notification
  • Update the "Last Updated" date at the top of this policy
  • Highlight significant changes in our notification
  • Obtain consent where required by applicable law
  • Maintain previous versions for your reference

Your continued use of our Services after the effective date of changes constitutes acceptance of the updated Privacy Policy.

15. Contact Information

For any privacy-related questions, concerns, or requests, please contact us through the following channels:

Data Protection Officer

Email: support@bearsystems.co.in

Phone: +91 852 718 6615

Response Time: One week

Legal Department

Email: admin@bearsystems.co.in

Phone: +91 851 718 6615

Address: Gold Course Road, Gurgaon, Haryana, India

EU Representative

For EU/UK users: EU Privacy Services Ltd.

Phone: +33 678 751 112

Email: admin@bearsystems.co.in

Privacy Commitment

At Bear Systems, we are committed to transparency, accountability, and respect for your privacy rights. This Privacy Policy reflects our dedication to protecting your personal information while providing innovative HR technology solutions. We continuously monitor and update our privacy practices to meet the highest standards of data protection and to comply with evolving privacy regulations worldwide.

Your trust is essential to our mission. If you have any concerns about how we handle your personal information, please reach out to our privacy team.