Legal

Privacy Policy

Last updated: May 11, 2026Always Rise Enterprises LLP

Privacy

Candidate data

Security

Tenant controls

AI data

No shared training

1. Introduction

UpStella is owned and operated by Always Rise Enterprises LLP.

UpStella ("we", "our", or "us") operates the UpStella platform at https://upstella.ai — an AI-powered Applicant Tracking System (ATS) for hiring teams. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our recruitment management platform and related services (the "Service").

By accessing or using the Service, you agree to this Privacy Policy and to our Terms of Service. If you do not agree, please do not use the Service.

2. Roles: Controller and Processor

UpStella is the data controller for information about our direct customers (account holders, admins, team members) and information we collect about visitors to our website.

For candidate data (resumes, applications, interview notes, scorecards, AI evaluation outputs) that you upload or generate through your hiring workspace, your organisation is the data controller and UpStella acts as a data processor. You are responsible for ensuring you have a lawful basis to collect and process that candidate data. We process it only on your documented instructions.

3. Information We Collect

3.1 Information You Provide

  • Account Information: Name, email, profile picture, and authentication details.
  • Company Information: Company name, logo, website, description, team member roster.
  • Billing Information: Billing contact, GST/tax ID, country, and payment method tokens. We do not store full card numbers — payment instruments are tokenised by our payment processor (Razorpay).
  • Hiring Data: Job descriptions, hiring criteria, scoring weights, interview stages, scorecard templates, and offer letters.
  • Candidate Data: Names, contact details, resumes, cover letters, application responses, assessment answers, interview notes, recordings (where you enable it), and AI-generated evaluations of candidates who apply to your roles.
  • Communications: Support tickets, in-app messages, and emails you send us.

3.2 Information Collected Automatically

  • Usage Data: Pages visited, actions taken, feature usage, timestamps.
  • Device & Network Data: Browser type, OS, device identifiers, IP address, approximate location (from IP), and referring URLs.
  • Cookies & Similar Technologies: See Section 9.

3.3 Information from Third-Party Services

When you connect third-party services (Google Workspace, Microsoft 365, Zoom, LinkedIn, Zoho), we receive OAuth access tokens, refresh tokens, and the minimum profile information required to operate the integration you authorised. Tokens are stored encrypted at rest and used only to provide the features you enabled. You can revoke access at any time from your account settings.

4. How We Use Information

We use information to:

  • Provide, operate, secure, and improve the Service.
  • Process job applications, run AI-powered resume screening, generate scorecards, and manage recruitment pipelines.
  • Schedule interviews and facilitate Google Meet / Microsoft Teams / Zoom sessions.
  • Send transactional emails (interview invites, assessment links, scorecard reminders, billing receipts, security notices).
  • Bill you for paid subscriptions and one-time top-up purchases.
  • Provide customer support and respond to inquiries.
  • Detect, investigate, and prevent fraud, abuse, and security incidents.
  • Comply with legal, tax, and regulatory obligations.

We do not use your candidate data to train shared or third-party AI models. AI screening runs per-tenant against your own configuration.

5. Legal Bases (EEA / UK users)

Where GDPR or UK GDPR applies, we rely on:

  • Contract: to deliver the Service you signed up for.
  • Legitimate interests: to secure the Service, prevent abuse, and improve features.
  • Legal obligation: for tax, accounting, and lawful requests.
  • Consent: where required (e.g., optional analytics cookies, certain marketing communications). You can withdraw consent at any time.

6. Sub-processors and Sharing

We do not sell your personal information. We share information only with sub-processors and partners that help us operate the Service, all under written contracts that require appropriate confidentiality and security commitments.

Categories of sub-processors include:

  • Cloud hosting & infrastructure — Base44 / underlying cloud providers.
  • AI/LLM providers — OpenAI (and equivalent providers) for resume screening, assessment evaluation, scorecard summarisation, and other AI features. We send only the minimum data required for the task and configure providers to not retain prompts for training where supported.
  • Payments — Razorpay for subscription billing, top-up purchases, and refunds (where applicable). Card data is handled directly by Razorpay; we receive only tokenised references.
  • Email delivery — Transactional email providers for notifications and ticket replies.
  • Conferencing integrations — Google Workspace, Microsoft 365, Zoom (only when you enable them).
  • Analytics & error monitoring — to keep the Service reliable.

We will also disclose information when required by law, valid legal process, or to protect the rights, property, and safety of UpStella, our customers, or the public.

A current list of sub-processors and our Data Processing Addendum (DPA) is available on request at contact@upstella.ai.

7. International Data Transfers

We are headquartered in India and our primary data location is India. Some of our sub-processors (e.g. AI/LLM providers, email infrastructure) may process data in the United States, the European Union, or other jurisdictions. Where required by law, we rely on Standard Contractual Clauses or other approved transfer mechanisms.

8. Data Security

We implement industry-standard safeguards including TLS in transit, encryption at rest for OAuth tokens and sensitive credentials, role-based access controls, tenant-level data isolation, audit logging of billing-sensitive events, and HMAC verification of payment webhooks. No system is 100% secure; we cannot guarantee absolute security but we work continuously to reduce risk.

Breach notification. If we become aware of a personal-data breach that is likely to result in risk to affected individuals or organisations, we will notify affected customers without undue delay and, where applicable, within statutory deadlines (e.g. 72 hours under GDPR).

9. Cookies and Similar Technologies

We use a minimal set of cookies and similar technologies:

  • Strictly necessary — required for sign-in, session management, and security. Cannot be disabled.
  • Functional — remember preferences such as the last workspace you used.
  • Analytics — measure feature usage to improve the product. Aggregated and de-identified where possible.

We do not use third-party advertising or cross-site tracking cookies. You can control cookies through your browser settings; disabling strictly-necessary cookies will break sign-in.

10. Data Retention

We retain account, billing, and hiring data for as long as your subscription is active. After cancellation:

  • Account & hiring data — retained for 30 days in a recoverable state, then deleted or irreversibly anonymised, except where longer retention is required by law (e.g. tax records).
  • Billing records — retained for the period required by applicable tax / accounting law (typically 7 years in India).
  • Security & audit logs — retained for up to 24 months to support incident investigation.
  • Backups — encrypted backups are rotated on a rolling window and overwritten over time.

You may request earlier deletion at any time by emailing contact@upstella.ai. We will honour deletion requests within 30 days, subject to legal retention requirements.

11. Your Rights

Depending on your location, you may have the following rights:

  • Access — request a copy of personal data we hold about you.
  • Correction — correct inaccurate data.
  • Deletion — request deletion of your personal data.
  • Portability — request an export in a machine-readable format.
  • Restriction / Objection — restrict or object to certain processing.
  • Withdraw consent — disconnect integrations or opt-out of optional communications at any time.
  • Lodge a complaint — with your local data protection authority.

For candidate-data rights (resumes, applications, AI evaluations), please contact the organisation that invited you to apply — they are the data controller. We will assist them in fulfilling your request.

To exercise any of these rights, email contact@upstella.ai. We may need to verify your identity before responding.

12. AI-Powered Features

The Service uses AI to screen resumes, generate evaluation summaries, draft questions, and rank candidates. AI outputs are decision-support, not decisions. Final hiring decisions are your organisation's responsibility. Where possible we display the signals that contributed to a score so outputs are explainable.

We do not use your candidate data to train shared AI models. Where third-party LLM providers are used as sub-processors, we use API endpoints configured to exclude prompts from training where the provider offers that option.

13. Billing, Refunds, and Subscriptions

Subscription pricing, billing cycles (monthly, quarterly, yearly), and one-time top-ups are governed by the plan you select at checkout and by our Terms of Service. Subscriptions auto-renew at the end of each billing cycle until you cancel. You can cancel at any time from your Billing settings; access continues through the end of the paid period.

All sales are final and non-refundable. UpStella does not provide refunds, partial refunds, or pro-rated credits for unused subscription time, downgrades, plan changes, top-up purchases, or accidental renewals, except where required by applicable law. See our Terms of Service for the complete refund policy.

14. Children's Privacy

The Service is not intended for individuals under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact contact@upstella.ai and we will delete it.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or email at least 14 days before they take effect, where feasible. The "Last updated" date at the top of this page reflects the current version. Continued use of the Service after changes constitutes acceptance.

16. Contact Us

For any privacy questions, requests, or complaints: