Privacy Policy
1. About SourceIT and This Policy
UNH Management Services Pvt. Ltd. ("SourceIT", "we", "us", or "our") is a general staffing, payroll management, statutory compliance management, and facilities management company operating across Navi Mumbai, Thane, Pune, Delhi, and Bengaluru.
This Privacy Policy ("Policy") governs the collection, use, disclosure, retention, and protection of personal data processed by SourceIT through:
- Our website at www.sourceitt.com (the "Website")
- Our mobile application available on Google Play and the Apple App Store (the "App")
- Our staffing, payroll, statutory compliance, and facilities management operations
- Our employer self-service portal at self.staffinggo.in
By using our Website or App, or by engaging us for staffing or related services, you acknowledge that you have read and understood this Policy and consent to the practices described herein.
SourceIT may update this Policy from time to time to reflect changes in applicable law, regulatory guidance, or operational practice. Material changes will be published on the Website with an updated effective date. For changes that materially affect individual rights, SourceIT will notify affected persons directly. Continued use of the Website, App, or services following publication of any revision constitutes acceptance of the revised Policy.
2. Scope of This Policy
Candidates
Individuals who submit their personal details to SourceIT for job placement, whether through the Website, App, walk-in registration, third-party job portals, or referral — including individuals whose profiles are held for future placement opportunities.
Placed Employees
Individuals engaged through SourceIT and deployed to a client organisation. Source IT continues to process personal data for the duration of the engagement and thereafter, as required for payroll, statutory compliance, and legal obligations.
Apprentices
Individuals registered under the National Apprenticeship Promotion Scheme (NAPS) through SourceIT, who meet the minimum working age prescribed under the Apprentices Act, 1961 and applicable regulations. SourceIT processes apprentice data for registration, stipend disbursement, and statutory reporting.
Client Contacts
Named representatives of employer organisations who interact with SourceIT for procurement, workforce management, service administration, or self-service portal access — including HR managers, procurement officers, and accounts contacts.
This Policy also applies to placed employees whose personal data was originally provided to SourceIT by a client organisation.
3. Personal Data We Collect
3.1 Candidate and Placed Employee Data
SourceIT collects the following categories of personal data from candidates and placed employees. The specific categories collected depend on the nature of the role, the requirements of the deploying client, and applicable law.
Identity and Contact Data
- Full legal name, date of birth, gender, and nationality
- Current and permanent residential address
- Personal email address and mobile number
- Photograph, where required by a client organisation for access badge or identification purposes
Professional and Qualification Data
- Curriculum vitae, resume, and cover letters
- Employment history, including previous employers, designations, dates of employment, and reasons for separation
- Educational qualifications, degrees, certificates, and transcripts
- Professional licences, trade certifications, and results of skills assessments
- Reference details and referee contact information
- Interview records, screening notes, and psychometric assessment results, where applicable
Government-Issued Identifiers
The following identifiers are collected to the extent required for statutory onboarding, compliance filings, and identity verification:
- Aadhaar number, collected in accordance with the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and applicable UIDAI guidelines. Aadhaar numbers are not stored in plain text. Any Aadhaar-based verification is conducted exclusively through UIDAI-authorised channels.
- Permanent Account Number (PAN)
- Passport number and/or Voter ID
- Universal Account Number (UAN) for Provident Fund
- ESIC Insurance Number
Financial Data
- Bank account number and IFSC code, for salary disbursement
- Compensation details, including CTC and applicable allowances
- Tax deduction information, including Form 16 data and TDS records
- Provident Fund and ESIC contribution records
- Expense reimbursement claims and supporting documentation
Background Verification Data
The following data is collected and processed only upon receipt of prior written consent from the individual:
- Criminal record check results
- Employment and educational credential verification outcomes
- Reference check responses
- Address verification reports
Background verification checks are initiated only after explicit written consent has been obtained. The scope of any check will be disclosed to the individual before it is initiated. Adverse findings will be communicated to the individual prior to any employment decision being made on that basis.
Health and Fitness Data
Health and fitness data is collected only where required by the specific role or client, and only with the individual's prior written consent. Such data is classified as sensitive personal data and is processed to the minimum extent necessary for the stated purpose. Specific categories include:
- Medical fitness certificates, for field, industrial, or safety-critical roles
- Occupational health assessment records, where mandated by client requirements or applicable health and safety regulations
Attendance and Performance Data
- Daily attendance records, check-in and check-out times
- Leave applications and approval records
- Performance feedback submitted by client supervisors, where shared with Source IT for payroll or compliance purposes
Location Data
GPS-based location data is collected through the App only where the individual has explicitly granted location permission through their device's native permission controls. Location data is used solely to verify attendance at designated deployment sites. SourceIT does not conduct continuous or background location tracking. Location permission may be revoked at any time through device settings.
3.2 Client Contact Data
For representatives of client organisations, SourceIT collects:
- Full name, designation, and organisation name
- Work email address and business phone number
- Login credentials for the employer self-service portal
- Communication records relating to staffing requirements and service delivery
- Contract, purchase order, and invoicing details
3.3 Website and App Usage Data
SourceIT automatically collects the following data when you visit the Website or use the App:
- IP address, browser type, device type, operating system, and screen resolution
- Pages visited, time spent, navigation paths, and exit pages
- Referring URLs and search terms used to access the Website
- App feature interactions, session duration, and crash reports
- Device identifiers, where applicable
- Data collected through cookies and similar technologies, as described in Section 10
4. Purposes of Processing
4.1 Candidate and Placed Employee Data
Recruitment and Placement
- Evaluating candidate suitability for available positions based on skills, qualifications, and experience
- Matching candidate profiles to client vacancy requirements and preparing candidate submissions
- Communicating placement opportunities, interview arrangements, and offer terms
- Maintaining a searchable candidate database for current and future placement purposes
Onboarding and Contract Management
- Collecting and verifying documentation required for statutory registration and client onboarding
- Registering individuals for Provident Fund, ESIC, Professional Tax, and other applicable statutory schemes
- Issuing appointment letters, offer letters, and service agreements
- Conducting background verification checks where required and consented to
Payroll and Benefits Administration
- Processing monthly salary and statutory deductions
- Filing TDS returns and issuing Form 16
- Managing PF and ESIC contributions and filing returns with EPFO and ESIC
- Processing leave encashment, reimbursements, and full and final settlements
Statutory and Regulatory Compliance
- Maintaining statutory registers and records as required under the Contract Labour (Regulation and Abolition) Act, 1970 and applicable state rules
- Filing returns and reports with labour departments, EPFO, ESIC, and other regulatory authorities
- Responding to inspections, audits, and lawful information requests from statutory authorities
- Retaining records for dispute resolution and litigation purposes, where applicable
Communication and Employee Relations
- Issuing deployment instructions, policy communications, and service updates
- Responding to grievances, queries, and exit-related requests
- Notifying individuals of changes to engagement terms, statutory entitlements, or applicable policies
4.2 Client Contact Data
- Managing the commercial relationship, contracts, and delivery of services
- Providing access to and support for the employer self-service portal
- Processing staffing requests, managing deployed workforce data, and issuing invoices
- Communicating service updates, compliance notices, and relationship management correspondence
4.3 Website and App Data
- Ensuring the correct and secure functioning of the Website and App
- Identifying and resolving technical errors and platform issues
- Analysing aggregated usage patterns to improve platform performance and user experience
- Detecting and preventing fraudulent or unauthorised activity
SourceIT does not use personal data for direct marketing communications without prior opt-in consent. SourceIT does not sell personal data to any third party. SourceIT does not employ automated decision-making that produces legal or similarly significant effects without human review.
5. Sharing of Candidate Profiles with Client Employers
The disclosure of candidate profiles to prospective and confirmed employer clients is a core and disclosed function of SourceIT's staffing operations. Candidates registering with SourceIT acknowledge and consent to this disclosure as a condition of using the placement service.
5.1 Categories of Data Shared
- Curriculum vitae and professional summary
- Skills, qualifications, and relevant employment history
- Availability and salary expectations
- Background verification results, where completed and applicable to the role
- Skills assessment or test scores, where applicable
SourceIT does not share government-issued identifiers (Aadhaar, PAN), bank account details, or health and fitness data with client employers unless the role specifically requires it and the individual has provided explicit written consent for that disclosure.
5.2 Conditions of Disclosure
- Profiles are shared only with clients with a legitimate, active vacancy that corresponds to the candidate's profile
- The individual will be informed of the client organisation's identity or sector prior to profile submission
- Consent to profile sharing is obtained at the point of candidate registration or at the time of specific client submission
- An individual may withdraw consent to future profile sharing at any time by written request to SourceIT. Withdrawal of consent does not affect placements already made or ongoing engagements
5.3 Client Obligations
Client organisations receiving candidate data from SourceIT are contractually required to:
- Use the data solely for the purpose of evaluating the candidate for the specific role for which the profile was submitted
- Maintain appropriate technical and organisational measures to protect the data received
- Not disclose the data to any third party without SourceIT's prior written consent
- Delete or return candidate data within 30 days where the candidate is not progressed or placed
- Comply with applicable data protection legislation in their use of the data
SourceIT is not liable for a client organisation's independent misuse of candidate data after it has been lawfully disclosed. Where SourceIT becomes aware of a material breach of client data obligations, it will take appropriate steps including termination of data sharing arrangements with that client.
6. Data Controller and Data Processor Roles
SourceIT operates in two legally distinct capacities depending on the context of processing.
6.1 SourceIT as Data Controller
SourceIT acts as the Data Controller when it independently determines the purpose and means of processing personal data. This includes the operation of the candidate database, the Website and App, client contact records, and SourceIT's own business development and compliance activities. This Policy governs SourceIT's obligations in its capacity as Data Controller.
6.2 SourceIT as Data Processor
SourceIT acts as a Data Processor when it processes personal data on behalf of a client organisation that is itself the Data Controller. This includes payroll processing, attendance management, statutory filings (PF, ESIC), and workforce data management conducted on behalf of a client. In these cases, processing is governed by the data processing terms of the applicable service agreement with that client organisation.
Where SourceIT processes personal data as a Data Processor on behalf of a deploying employer, placed employees who wish to exercise data rights over such data may be required to direct their request to the relevant employer as the Data Controller. SourceIT will cooperate with such requests and coordinate with the relevant client as appropriate.
7. Third-Party Disclosure
In addition to client employers (Section 5), SourceIT may disclose personal data to the following categories of third parties, strictly to the extent necessary for the stated purpose:
Statutory and Regulatory Authorities
- Employees' Provident Fund Organisation (EPFO): for PF registration, contribution filings, and KYC compliance
- Employees' State Insurance Corporation (ESIC): for insurance registration and contribution filings
- Income Tax Department: for TDS filings and reconciliation
- State Labour Departments: for contract labour licence filings and inspection compliance
- Directorate General of Training / NAPS portal: for apprenticeship registration and statutory reporting
- Any other authority issuing a lawful direction or statutory requirement for disclosure
Technology and Service Providers
- StaffingGo (self.staffinggo.in): SourceIT's primary payroll and workforce management platform, which processes personal data as a data processor under a written confidentiality and data processing agreement
- Cloud hosting and infrastructure providers, operating under confidentiality obligations
- Communication and document delivery platforms, for payslips, appointment letters, and compliance correspondence
- Background verification agencies, for conducting checks with individual consent
- Web analytics providers (e.g., Google Analytics), which receive anonymised and aggregated usage data only
Financial Institutions
- Banks and financial institutions through which salary disbursements and reimbursements are processed
Professional Advisers
- Legal counsel, statutory auditors, and tax advisers, operating under professional confidentiality obligations
Group Companies
- Other entities within the Fornax Corporate group, where services are delivered jointly, shared infrastructure is used, or group-level reporting is required. Inter-company data sharing is governed by internal data sharing agreements and is limited to what is necessary for the stated purpose.
Business Transfers
In the event of a merger, acquisition, restructuring, or transfer of business assets, personal data may be transferred to a successor entity. Affected individuals will be notified, and equivalent data protection obligations will be required of the acquirer as a condition of the transfer.
SourceIT does not sell personal data. SourceIT does not disclose personal data to advertisers or unaffiliated third parties for their own marketing or commercial purposes.
Cross-Border Data Transfers
Personal data may be processed or stored outside India through approved service providers where necessary for business operations. SourceIT shall take reasonable measures to ensure that such data remains protected and is handled in accordance with applicable legal requirements.
8. Legal Basis for Processing
SourceIT processes personal data on the following legal grounds under the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable Indian legislation:
Consent
SourceIT relies on consent for the following processing activities:
- Background verification checks
- Collection and disclosure of health and fitness data
- Sharing of candidate profiles with named client employers
- Collection of location data through the App
- Any direct marketing or promotional communications
Consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal. Withdrawal of consent for profile sharing does not affect placements already made or engagements in progress.
Contractual Necessity
Processing is necessary to fulfil SourceIT's obligations under the staffing engagement or service agreement, including candidate placement, payroll processing, and employment contract management.
Legal Obligation
Processing is required to comply with applicable Indian legislation, including:
- Contract Labour (Regulation and Abolition) Act, 1970
- Employees' Provident Funds and Miscellaneous Provisions Act, 1952
- Employees' State Insurance Act, 1948
- Income Tax Act, 1961
- Payment of Wages Act, 1936 and Minimum Wages Act, 1948
- Apprentices Act, 1961
- Shops and Establishments Acts (applicable state legislation)
Legitimate Interests
SourceIT processes certain data on the basis of legitimate interests, where such interests are not overridden by the rights of the data subject. This includes maintaining and improving the candidate database, operating and securing the Website and App, fraud prevention, and client relationship management.
9. Consent: Obtaining, Recording, and Withdrawal
9.1 How Consent Is Obtained
- At the point of candidate registration — through the Website, App, or in-person — individuals are presented with this Policy and asked to confirm their acceptance
- Separate, specific written consent is obtained prior to initiating a background verification check
- Separate written consent is obtained prior to collecting or disclosing health or fitness data
- App location permissions are requested through the device's native permission system. SourceIT does not access location data unless permission is actively granted by the user
9.2 Consent Records
SourceIT maintains records of consent obtained, including the date, method, and scope of consent. These records are retained for the duration of the data subject relationship and for 3 years thereafter, to demonstrate compliance with applicable law.
9.3 Withdrawal of Consent
Consent may be withdrawn at any time by:
- Submitting a written withdrawal request to privacy@sourceitt.com
- Submitting a written withdrawal request to: UNH Management Services Pvt. Ltd., Registered Office, Navi Mumbai, Maharashtra, India
- Revoking App location permissions through device settings
Where withdrawal of consent means that SourceIT can no longer provide a specific service, the individual will be informed of that consequence prior to confirming the withdrawal.
10. Cookies and Tracking Technologies
10.1 Categories of Cookies Used
- Strictly Necessary Cookies: required for the Website and portal to function correctly. These cookies cannot be disabled and do not require consent under applicable law.
- Performance and Analytics Cookies: collect anonymised data on visitor behaviour, including pages viewed and errors encountered, used solely to improve platform performance. SourceIT uses Google Analytics or equivalent services for this purpose.
- Functionality Cookies: enable the Website to retain user preferences, such as language settings and login state, to enhance usability.
SourceIT does not use targeting, advertising, or third-party retargeting cookies.
10.2 Managing Cookie Preferences
Cookie preferences may be managed through browser settings or through the consent banner displayed on first access to the Website. Disabling strictly necessary cookies will impair Website functionality. Disabling analytics or functionality cookies will not affect access to content.
10.3 Third-Party Cookies
Third-party services integrated into the Website (including Google Analytics) may set their own cookies, governed by their respective privacy and cookie policies. SourceIT does not transmit personally identifiable information to analytics providers. Data collected through such tools is aggregated and anonymised.
11. Data Security
11.1 Technical and Organisational Measures
- Encryption of personal data in transit via TLS/HTTPS and at rest where technically feasible
- Role-based access controls, limiting data access to authorised personnel only
- Additional access restrictions for sensitive data categories, including financial data, health data, and government identifiers
- Regular security assessments of SourceIT's platform and third-party service providers
- Contractual confidentiality and data protection obligations imposed on all staff and service providers with access to personal data
- Secure deletion procedures for personal data that has reached the end of its applicable retention period
11.2 Data Breach Response
In the event of a personal data breach that is likely to result in risk to the rights of affected individuals, SourceIT will:
- Assess and contain the breach without undue delay
- Notify the relevant authority in accordance with applicable law
- Notify affected individuals where the breach is likely to result in significant risk to their rights, without undue delay
- Maintain an internal breach register and document all response actions
Individuals who believe their account or personal data may have been compromised should contact SourceIT immediately at privacy@sourceitt.com.
12. Data Retention
SourceIT retains personal data only for as long as necessary for the purpose for which it was collected, or as required by applicable law. The following retention periods apply:
Candidate Data — Not Placed
- Active candidate profiles are retained for 3 years from the date of last interaction or last profile update
- Upon expiry of this period, SourceIT will contact the individual to confirm whether continued retention is desired
- Where no response is received within 30 days of that notice, the data will be securely deleted
Placed Employee Records
- Retained for the duration of the engagement and for a minimum of 8 years from the date of final separation
- This period reflects statutory obligations under the Contract Labour Act, EPFO regulations, ESIC regulations, and the Income Tax Act
Payroll and Statutory Records
- Retained for a minimum of 8 years, in compliance with applicable tax and labour law record-keeping requirements
Apprentice Records (NAPS)
- Retained for the duration of the apprenticeship and for a minimum of 5 years thereafter, as required under applicable apprenticeship regulations
Background Verification Data
- For placed individuals: retained as part of the employee record for the statutory minimum period applicable to that record
- For unplaced candidates: deleted within 6 months of the placement decision, unless retention is required for dispute resolution
Client Contact Data
- Retained for the duration of the commercial relationship and for 3 years thereafter, for dispute resolution and audit purposes
Website and App Usage Data
- Aggregated and anonymised analytics data: retained indefinitely
- Identified server logs and usage records: retained for 12 months
Where an individual submits a request for erasure of personal data during an active placement or ongoing employment engagement, SourceIT will retain the data necessary to fulfil its contractual and statutory obligations for the duration of that engagement. Upon conclusion of the engagement, the applicable retention period set out above will govern. SourceIT will inform the individual of this position in its response to the erasure request.
All other requests for deletion will be assessed against applicable statutory retention obligations. Where legal or contractual requirements prevent deletion, SourceIT will inform the individual of the applicable basis and the expected retention period.
Personal data will, upon the expiry of the retention period pertaining to the data concerned, be either deleted, anonymized, or destroyed, save for cases where retention is required due to statutory requirements or legal proceedings.
13. Rights of Data Subjects
Subject to the Digital Personal Data Protection Act, 2023 and other applicable Indian law, individuals whose personal data is processed by SourceIT have the following rights:
- Right to Access: The right to request a copy of the personal data held by SourceIT, along with information on how it is processed
- Right to Correction: The right to request correction of inaccurate, incomplete, or outdated personal data
- Right to Correction of Personal Data: SourceIT will make every effort to ensure that data provided is correct, complete, and up to date. Individuals may request that any incorrect or out-of-date data they hold be amended in accordance with the procedure outlined herein.
- Right to Erasure: The right to request deletion of personal data, subject to statutory retention obligations and any active placement or engagement in progress
- Right to Restriction: The right to request that SourceIT limit processing of personal data in specified circumstances
- Right to Object: The right to object to processing carried out on the basis of legitimate interests
- Right to Data Portability: The right to receive personal data in a structured, commonly used, machine-readable format
- Right to Withdraw Consent: The right to withdraw any consent previously given, without affecting the lawfulness of prior processing
- Right to Grievance Redressal: The right to lodge a complaint with SourceIT's Data Protection Officer, and to escalate unresolved complaints to the Data Protection Board of India
13.1 Submitting a Rights Request
Data rights requests should be submitted in writing to:
- Email: privacy@sourceitt.com
- Subject line: Data Rights Request — [Full Name]
- Include: full name, contact details, nature of the request, and any relevant reference numbers such as an employee ID or placement reference
SourceIT will acknowledge all requests within 5 business days and will aim to resolve standard requests within 30 days. Where a request is complex or involves multiple rights, this period may be extended by a further 30 days, with written notice to the individual. SourceIT may require identity verification before processing a request.
Where a request for erasure or restriction conflicts with a statutory retention obligation or an active engagement, SourceIT will communicate the applicable legal basis and the expected retention period in its response.
14. Minors
SourceIT's Website, App, and staffing services are not directed at individuals under the age of 18 or below the minimum working age prescribed under applicable Indian labour legislation, whichever is higher.
For NAPS apprenticeship engagements, SourceIT processes data only for individuals who meet the minimum age requirements prescribed under the Apprentices Act, 1961. Client organisations deploying apprentices through SourceIT are contractually required to confirm that all apprentices meet applicable age requirements prior to deployment.
If SourceIT becomes aware that personal data has been collected from a minor without appropriate consent or authority, the data will be deleted promptly. Concerns regarding the collection of a minor's data may be directed to privacy@sourceitt.com.
15. Grievance Redressal
SourceIT is committed to resolving data protection concerns in a timely and transparent manner. The following escalation process applies:
Step 1 — Data Protection Officer
All concerns should first be directed in writing to the Data Protection Officer at privacy@sourceitt.com. SourceIT will acknowledge receipt within 5 business days and resolve the concern within 30 days.
Step 2 — Senior Management Escalation
If the concern is not resolved to the individual's satisfaction within 30 days, the individual may escalate in writing to senior management at the same email address, marked "Escalation — Data Protection". Senior management will review and respond within 15 additional business days.
Step 3 — Data Protection Board of India
Where a concern remains unresolved following internal escalation, individuals have the right to file a complaint with the Data Protection Board of India, once operational under the DPDPA, 2023. SourceIT will cooperate fully with any inquiry initiated by the Board.
16. Third-Party Links
The Website and App may contain links to third-party websites and platforms, including social media platforms (LinkedIn, Facebook, Instagram), group company websites, government authority portals, and the StaffingGo employer portal. Source IT is not responsible for the privacy practices of third-party sites and does not endorse those practices by virtue of providing a link. Individuals are encouraged to review the privacy policies of any third-party platform before submitting personal data to it.
17. Amendments to This Policy
SourceIT reviews this Policy at least annually and updates it as required by changes in applicable law, regulatory guidance, or operational practice. Revisions will be published on the Website with an updated effective date. Where material changes affect individual rights, SourceIT will notify affected individuals directly. The current version of this Policy supersedes all prior versions.
18. Contact
Data Protection Officer
UNH Management Services Pvt. Ltd.
A Subsidiary of Fornax Corporate Services Pvt. Ltd.
Offices across Navi Mumbai, Thane, Pune, Delhi, and Bengaluru
Email: privacy@sourceitt.com
Website: www.sourceitt.com
SourceIT will acknowledge all privacy-related correspondence within 5 business days and resolve standard requests within 30 days. Complex or multi-issue requests will be resolved within 60 days, with written explanation of any extension.