creit.
LEGALPrivacy Policy

Privacy Policy

Last Updated: September 30, 2026•Harel Infotech Private Limited

This Privacy Policy explains how CREIT collects, uses, stores, shares and protects your personal information, including data received from Google APIs, when you use creitlab.com and CREIT applications.

01

Who We Are

This Privacy Policy applies to creitlab.com and to the applications, tools and services offered under the CREIT brand (together, the “Services”).

The data controller responsible for your personal information is:

Harel Infotech Private Limited

CIN: U72200HR2022PTC101523

Registered Office: FF, U 24 A/3 1, S.F D.L.F, Phase III, Gurgaon, Haryana – 122002, India

Privacy contact: hello@creitlab.com

References to “CREIT”, “we”, “us” or “our” mean Harel Infotech Private Limited acting under the CREIT brand.

02

Information We Collect

We collect only the information needed to operate the Services:

  • Information you give us — name, email address, company, role, years of experience, portfolio or profile links, resumes, job descriptions and any message you send through our forms or by email;
  • Account information — where you sign in to a CREIT application, the identifiers and profile details needed to create and manage your account;
  • Google user data — where you choose to connect a Google account, the data described in Section 03;
  • Usage information — pages visited, referring pages, approximate location derived from IP address, browser and device type, collected through cookies and analytics tools (see Section 08); and
  • Client engagement information — information shared with us in the course of a client project, handled under the applicable written agreement.
03

Google User Data

Some CREIT applications let you sign in with or connect a Google account. When you do, Google shows you the specific permissions requested and you choose whether to grant them.

What we access

  • your name, email address and profile picture, through Google Sign-In (the openid, email and profile scopes); and
  • any additional Google data only where a feature requires it and you have explicitly granted that permission on Google’s consent screen.

How we use it

  • to authenticate you and create or maintain your account;
  • to provide the user-facing features you have requested; and
  • to communicate with you about your account or the Services.

How we store it

Google user data is stored on access-controlled, encrypted infrastructure. OAuth access and refresh tokens are stored encrypted and used only to perform actions you have requested. We keep Google user data only for as long as your account is active or as needed to provide the feature, and delete it as described in Section 07.

How we share it

We do not sell Google user data. We do not share it with third parties except:

  • with service providers who host or operate the Services on our behalf, under confidentiality and data-protection obligations;
  • where you have given explicit consent;
  • where required by applicable law or to protect against fraud, abuse or security threats; or
  • as part of a merger, acquisition or sale of assets, with notice to you.

What we never do

  • use Google user data to serve advertising, including personalised or retargeted ads;
  • use Google user data to develop, improve or train generalised artificial intelligence or machine learning models;
  • allow humans to read Google user data, except with your affirmative consent for specific content, where necessary for security purposes, to comply with law, or where the data has been aggregated and anonymised for internal operations; or
  • transfer Google user data to data brokers or information resellers.

CREIT’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke CREIT’s access to your Google account at any time from your Google Account permissions page. Revoking access stops further collection; to have data we already hold deleted, see Section 07.

04

How We Use Information

We use personal information to:

  • respond to enquiries and hiring briefs;
  • evaluate job applications and match candidates with roles;
  • provide, operate, secure and improve the Services;
  • perform client engagements under the applicable agreement;
  • understand how the website is used, in aggregate;
  • send service-related communications; and
  • comply with legal obligations and enforce our terms.

We process information on the basis of your consent, the performance of a contract with you, our legitimate interests in running our business, or a legal obligation, as applicable.

05

How We Share Information

We do not sell personal information. We share it only:

  • with prospective employers or clients — where you are a candidate, we share your profile with a client only for roles relevant to you;
  • with service providers — such as hosting, email and analytics providers who process data on our behalf;
  • for legal reasons — where required by law, court order or a government authority, or to protect rights, safety and security; and
  • in a business transfer — as part of a merger, acquisition or sale of assets.

Google user data is shared only as described in Section 03.

06

Storage & Security

We use reasonable technical and organisational safeguards, including encryption in transit (HTTPS/TLS), encryption at rest for stored credentials and tokens, role-based access controls and limiting access to personnel who need it.

Our service providers may store or process information outside India. Where they do, we take steps to ensure the information remains protected in line with this Policy and applicable law.

No method of transmission or storage is completely secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.

07

Retention & Deletion

We keep personal information only as long as needed for the purpose it was collected for:

  • enquiries — for as long as needed to respond and follow up;
  • candidate information — for up to 24 months after your last interaction, unless you ask us to delete it sooner;
  • account and Google user data — while your account is active, and deleted within 30 days of account deletion or a deletion request; and
  • client engagement data — as set out in the applicable agreement.

To request deletion of your data, including Google user data, email hello@creitlab.com from the address associated with your account. We will confirm once deletion is complete. We may retain limited information where required by law.

08

Cookies & Analytics

The website uses Google Analytics to understand how visitors use the site. Google Analytics sets cookies and collects information such as pages viewed, time on site, device and browser type and approximate location. This information is used in aggregate and is not combined with Google user data obtained through Google Sign-In.

The website also loads fonts from Google Fonts, which receives your IP address when fonts are fetched.

You can block or delete cookies in your browser settings, or opt out of Google Analytics using the Google Analytics opt-out add-on. See also how Google uses data from sites that use its services.

09

Your Rights

Subject to applicable law, including India’s Digital Personal Data Protection Act, 2023, you may:

  • access the personal information we hold about you;
  • correct inaccurate or incomplete information;
  • request deletion of your information;
  • withdraw consent at any time, without affecting processing already carried out;
  • nominate another person to exercise your rights in the event of death or incapacity; and
  • raise a grievance with us, and escalate it to the Data Protection Board of India if unresolved.

To exercise any of these rights, email hello@creitlab.com. We will respond within 30 days.

10

Children

The Services are not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us and we will delete it.

11

Third-Party Links

The Services may link to third-party websites or services. Their privacy practices are governed by their own policies, and we are not responsible for them.

12

Changes to This Policy

We may update this Policy from time to time. The revised Policy will be published on this page with an updated “Last Updated” date.

If we change how we access, use, store or share Google user data, or make any other material change, we will notify affected users by email or through the Services before the change takes effect and, where required, ask for your consent again.

13

Contact & Grievances

For questions about this Policy or our handling of your information, email hello@creitlab.com or use our Contact page.

Harel Infotech Private Limited

Operating under the brand and trademark CREIT

FF, U 24 A/3 1, S.F D.L.F, Phase III, Gurgaon, Haryana – 122002, India

hello@creitlab.com — creitlab.com