Data & Resume Handling Policy

This page sets out, in operational detail, how Udhyogii handles institution rosters, student resumes and company access. It should be read together with the Privacy Policy, which it supplements rather than replaces.

For institutions

TopicHow it works
Student consentCollected once per student by the institution before that student's profile leaves the institution and becomes visible on the Platform.
Who can see a profileOnly a company the institution has explicitly shared it with, and only for the specific job description it was shared against.
Withdrawing accessThe institution can revoke a shared profile at any time; the company's access is removed immediately. Every share also expires automatically 30 days after it was sent, whether or not it is revoked.
RetentionProfiles are deleted 18 months after the student's batch graduates, or immediately on request.
Exporting your dataFull roster, resumes and share history can be exported as a ZIP file, ready within an hour of request.
Deleting the institution accountRemoves everything. This is irreversible and requires the institution's principal to confirm by email.

For companies

TopicHow it works
What you receiveOnly profiles a placement cell has chosen to share, against one specific job description of yours. There is no open, searchable resume database — you cannot search for students who were not shared with you.
Permitted useOnly for the job description the profile was shared against. Not for any other role, and never resold or passed to a client, subject to the consultancy provisions in the Terms.
WithdrawalAn institution can revoke a shared profile at any time. If it does, any downloaded copy must be deleted — this is a binding condition of the Terms you accepted on registration.
30-day access windowEvery shared profile and resume leaves your console 30 days after it was shared and moves to cold storage. Any downloaded copy must be deleted at the same time.
Download loggingEvery resume download is logged with the recruiter's name and is visible to the institution that shared it, as an audit trail.
Deleting your accountRemoves your job descriptions and console access. Institutions retain their own record of what your account downloaded.

Resume file standards

To keep resumes searchable and safe to open in a browser, Udhyogii rejects, at upload: scanned images with no underlying text layer, password-protected files, exports carrying a design-tool watermark (for example, an unremoved Canva watermark), and any file over 2 MB. Institutions may upload up to 500 files in a single batch; files are matched to students automatically by roll number or file name, and any file that cannot be matched is queued for manual review rather than silently discarded or attached to the wrong student.

Roster sync via spreadsheet

An institution may instead keep maintaining the roster spreadsheet its department already uses, and share it with Udhyogii's service account (roster-sync@udhyogii-in.iam.gserviceaccount.com) at Viewer-only access. Udhyogii re-reads that sheet nightly; edits made in the institution's own sheet are reflected on the Platform, and nothing is ever written back to the institution's sheet. Viewer access means Udhyogii cannot edit, delete or share the institution's source file — only read it.

Legal basis for this clause

This page operationalises Udhyogii's obligations as, in relation to student data, principally a data processor acting on the instructions of the institution (which is the data fiduciary that collects consent and determines purpose), and, in relation to its own account and verification records, a data fiduciary in its own right, both within the meaning of the DPDP Act, 2023. The purpose-limitation, storage-limitation and security safeguards described above are designed to satisfy Sections 5 to 9 of the DPDP Act and the applicable provisions of the IT Act, 2000 and the SPDI Rules, 2011 for any sensitive personal data (such as identity documents) that may appear within an uploaded resume.