Nurszon does not collect, process, or store your card number, CVV, UPI PIN, net-banking credentials, or bank account details. All payments are handled entirely by our PCI-DSS-compliant payment gateway partner (Razorpay). We receive only a payment reference, the amount, the status, and the plan purchased. Your payment credentials are entered directly into the gateway's environment and are governed by the gateway's own privacy policy.
Applies to the Nurszon mobile application (iOS and Android), the Nurszon web portal, and all related services.
1Introduction
This Privacy Policy explains how Nurszon (CIN: [CIN]), a company incorporated under the Companies Act, 2013 and having its registered office at Bangalore, India ("Nurszon", "we", "us", "our"), collects, uses, stores, shares, and protects your personal data when you use the Nurszon platform (the "Platform").
Nurszon is a healthcare staffing marketplace. It connects nursing and paramedical professionals ("Candidates" or "Job Seekers") with hospitals, clinics, diagnostic centres, and other healthcare institutions ("Employers" or "Recruiters"). Because our users are licensed healthcare professionals, the information we handle includes professional registration numbers, qualification certificates, and identity documents. We treat this category of information with heightened care, and this policy sets out exactly how.
This policy is published in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
By creating an account, uploading information, or otherwise using the Platform, you consent to the practices described here. If you do not agree with this policy, please do not use the Platform.
This Privacy Policy should be read together with the Nurszon Terms and Conditions, which govern your use of the Platform.
2Definitions
| Term | Meaning |
|---|---|
| Personal Data | Any data about an individual who is identifiable by or in relation to such data. |
| Sensitive Personal Data | Data such as passwords, financial information, health information, biometric information, and official identifiers, as classified under the SPDI Rules. |
| Data Principal | The individual to whom the personal data relates — i.e. you. |
| Data Fiduciary | The entity that determines the purpose and means of processing personal data. For data you provide to Nurszon, Nurszon is the Data Fiduciary. |
| Data Processor | An entity that processes personal data on behalf of a Data Fiduciary — for example, our hosting and communications vendors. |
| Candidate / Job Seeker | A registered nurse, nursing professional, or paramedical/allied-health professional using the Platform to find work. |
| Employer / Recruiter | A hospital, healthcare institution, or its authorised recruiting personnel using the Platform to post roles and evaluate Candidates. |
| Platform | The Nurszon mobile applications, web portal, APIs, and associated services. |
3Information We Collect
3.1 Information you provide directly
All users, at registration:
- Full name
- Email address
- Mobile number (with country dial code)
- Password (stored only as a salted cryptographic hash — we never store or have access to your plaintext password)
- Account role (Nurse, Hospital Personnel/Paramedical Staff, or Employer)
Candidates, during profile setup and thereafter:
- Personal details — date of birth, gender, current city and state, preferred work locations, profile photograph
- Professional experience — job titles held, hospitals or institutions worked at, start and end dates, current employment status, role descriptions, total experience
- Qualifications — degrees and diplomas, awarding institution, year of graduation, academic percentage, specialisation, certification type
- Council Registration Number (CRN) — your registration number with the Indian Nursing Council, the relevant State Nursing Council, or the applicable paramedical/allied-health council
- Skills relevant to your practice area
- Documents — resume/CV, council registration certificate, educational certificates, government-issued identity proof, and any other credential documents you choose to upload
Employers, during onboarding and thereafter:
- Hospital or institution name, description, and location
- Branch and head-office addresses, including map links
- Hospital logo and banner imagery
- Compliance and verification documents — PAN, GST registration, certificate of incorporation, and any further documentation we reasonably require to verify that you are a genuine healthcare institution
- Details of authorised recruiting personnel
All users, on an ongoing basis:
- Job postings, job applications, saved jobs, and messages or notes created on the Platform
- Interview schedules, locations, and outcomes
- Support tickets, feedback, and any correspondence you send us
- Survey responses, where you choose to participate
3.2 Information collected automatically
- Device and technical data — device model, operating system and version, application version, device language, time zone, and a device push-notification token
- Usage data — screens visited, jobs viewed, searches run, filters applied, features used, session timestamps, and your last-active time
- Log data — IP address, request timestamps, and error/diagnostic data
- Approximate location, only where you grant the permission, and only to filter jobs near you. We do not track your continuous or background location.
- Profile-view and document-access records — see Section 6.
3.3 Information from third parties
- Google Sign-In — if you register or log in using Google, we receive your name, email address, and profile picture from Google, as permitted by the consent you give Google at sign-in. We do not receive your Google password.
- Payment processor — where you purchase a subscription, our payment gateway returns a transaction reference, payment status, and limited billing metadata. See Section 3.4.
- Verification sources— where we verify a council registration or an employer's corporate registration, we may receive confirmation data from the relevant registry or verification partner.
3.4 Payment information
3.5 What we ask you never to upload
The Platform is a recruitment service, not a clinical system. You must not upload, enter, or transmit any patient information, patient records, clinical images, or any other protected health information relating to a third party. If you upload a document containing such information, please contact us immediately so we can remove it. Nurszon does not seek this data and has no lawful basis to hold it.
4How We Use Your Information
We use your personal data for the following purposes:
To provide the core service
- Create, authenticate, and secure your account, including one-time-password (OTP) verification and login-time two-factor authentication
- Build and display your professional profile
- Match you with relevant job opportunities and surface recommended roles
- Enable you to search, save, and apply for jobs
- Allow verified Employers to discover, evaluate, and contact you, subject to your visibility settings
- Enable Employers to post roles, review applicants, shortlist, and schedule interviews
- Track and display application status through its lifecycle
- Calculate and display your profile-completeness score
To communicate with you
- Send transactional messages — OTPs, application status updates, interview invitations, document-verification outcomes, employer approval decisions, payment receipts, and account/security alerts — by push notification, email, and SMS
- Send job alerts and recommendations matched to your profile
- Send product announcements, offers, and promotional material, where you have not opted out
- Respond to your support requests and grievances
To verify and protect
- Verify your identity, professional credentials, and (for Employers) institutional legitimacy
- Detect, investigate, and prevent fraud, impersonation, credential forgery, spam, scraping, and other misuse
- Enforce our Terms and Conditions and apply account restrictions where warranted
- Maintain audit trails of access to sensitive documents
To improve and analyse
- Understand how the Platform is used, diagnose faults, and monitor performance and stability
- Develop new features and improve matching and search quality
- Produce aggregated and de-identified statistics and research. Aggregated data that cannot identify you is not treated as personal data under this policy.
To meet legal obligations
- Comply with applicable law, tax and accounting requirements, and lawful directions of courts, regulators, and law-enforcement agencies
- Establish, exercise, or defend legal claims
We do not sell your personal data. We do not make automated decisions that produce legal or similarly significant effects on you without a route to human review — job matching and recommendations are ranking aids only, and every hiring decision on the Platform is made by a human Employer.
5Legal Basis for Processing
Under the DPDP Act, we process your personal data on the following bases:
- Your consent, given at registration and at the point of each specific optional feature — for example marketing communications, discoverability in Employer talent search, and device permissions such as camera, photo library, notifications, and location. Consent is sought in clear terms, is specific to a stated purpose, and may be withdrawn at any time (see Section 11).
- Certain legitimate uses as permitted by the DPDP Act, including where you voluntarily provide data for a specified purpose, for security and fraud prevention, and to comply with a legal obligation or a judgment or order.
- Performance of our contract with you, being the Terms and Conditions you accept when you register.
Where you withdraw consent, we will stop the relevant processing, but this does not affect the lawfulness of processing carried out before withdrawal, and it may mean we can no longer provide part or all of the service.
6Special Protections for Healthcare Credentials
Because Nurszon handles professional licences, certificates, and identity documents, we apply controls beyond those of a general job board:
- Private, non-public storage. Credential documents are stored in a private storage bucket that is not publicly accessible. We never store or hand out a permanent public URL for a credential document.
- Short-lived, single-purpose access links. When an authorised viewer opens a document, the system issues a signed link that expires within sixty seconds. The link cannot be forwarded, reused, or indexed.
- Full access logging. Every single generation of a document link is recorded in an immutable access log capturing who accessed which document and when. This log exists so that access to your credentials is auditable.
- Resume contact masking. Before your resume is shown or downloaded by a Recruiter, it is automatically processed to redact email addresses and phone numbers — both visually and within the underlying file, so they cannot be extracted from the file's text layer. This protects you from off-platform solicitation and recruitment fraud. Contact details become available to an Employer only in the course of a genuine hiring interaction on the Platform.
- Download limits. Recruiter access to candidate documents is capped by the download entitlement attached to their subscription, and consumption against that cap is metered.
- Profile-view transparency. When an Employer views your profile through talent search, that view is logged and may be surfaced to you.
A note on terminology: some parts of the Platform's interface and internal codebase use the term "HIPAA" when referring to these document-protection controls. HIPAA is a United States federal statute that does not apply to Nurszon's operations in India, and Nurszon does not claim to be a HIPAA covered entity or business associate. The term is used loosely in that context as a shorthand for the encrypted, access-logged handling described above. Your data-protection rights on this Platform arise under Indian law — principally the DPDP Act, the IT Act, and the SPDI Rules.
7How We Share Your Information
We share personal data only as described below. We do not sell or rent it.
7.1 With Employers
- When you apply to a job, the Employer that posted it receives your profile — name, contact details, experience, qualifications, council registration number, specialisation, and the documents relevant to that application.
- When you are discoverable in talent search, verified and approved Employers can view your profile and, subject to their entitlement, your masked resume. You can control this in Settings → Privacy.
- Employers receive interview-related and status-related information necessary to progress your application.
Important: once an Employer has lawfully received your data, that Employer acts as an independent Data Fiduciary in respect of it. Nurszon requires Employers, under the Terms and Conditions, to process candidate data lawfully, to keep it secure, to use it only for genuine recruitment, and not to transfer it onward without a lawful basis. However, Nurszon cannot fully control an Employer's subsequent handling of data, and is not responsible for it. If you believe an Employer has misused your information, report it to us using the details in Section 14 and we will investigate.
7.2 With Candidates
Employers' institutional details, job postings, branch locations, and interview arrangements are shared with Candidates as necessary to operate the marketplace. Individual recruiter contact details are not published to Candidates by default.
7.3 With service providers
We engage vendors who process data strictly on our instructions and under contractual confidentiality and security obligations:
| Purpose | Category of provider |
|---|---|
| Cloud hosting, database, authentication, file storage | Managed backend and cloud infrastructure provider |
| SMS and OTP delivery | Indian DLT-registered SMS gateway |
| Transactional and notification email | Email delivery provider |
| Push notifications | Mobile push notification service |
| Payment processing | PCI-DSS-compliant payment gateway |
| Crash reporting and performance monitoring | Application monitoring provider |
| Product analytics | Analytics provider |
We do not authorise any of these providers to use your data for their own purposes.
7.4 With authorities and for legal reasons
We may disclose personal data where we believe in good faith that it is required to: comply with applicable law or a binding order of a court, tribunal, regulator, or law-enforcement agency; respond to a lawful request under the IT Act or the Code of Criminal Procedure; enforce our Terms and Conditions; or protect the rights, safety, or property of Nurszon, our users, or the public — including in investigations of credential fraud or recruitment scams.
7.5 Corporate transactions
If Nurszon is involved in a merger, acquisition, restructuring, financing, or sale of assets, personal data may be transferred as part of that transaction. We will require the recipient to honour commitments materially equivalent to those in this policy, and we will notify you of any change in the identity of your Data Fiduciary.
7.6 With your direction
We share data with any other party where you specifically ask or authorise us to.
8Cookies and Similar Technologies
The Nurszon mobile application does not use browser cookies. It uses on-device storage (including encrypted secure storage) to hold your session token, preferences, and cached content so the app works quickly and keeps you logged in. Clearing app data or logging out removes this.
The Nurszon web portal, where you use it, uses:
- Strictly necessary cookies — session, authentication, load balancing, and security. These cannot be disabled without breaking the service.
- Preference cookies — remember your settings and choices.
- Analytics cookies — help us understand aggregate usage and improve the product.
You can control cookies through your browser settings, though disabling non-essential cookies may reduce functionality. We do not use cookies to build advertising profiles about you, and we do not run third-party advertising networks on the Platform.
The Platform also uses standard mobile identifiers for crash reporting and analytics. You can limit ad tracking through your device's operating-system privacy settings.
9Data Storage, Location, and Cross-Border Transfer
Your data is stored on managed cloud infrastructure. Our primary database and file storage are currently hosted in a data-centre region outside India (Asia-Pacific — Seoul, South Korea). Some of our service providers — for example email, analytics, crash reporting, and push notification services — may also process data on servers located outside India.
The DPDP Act permits transfer of personal data outside India except to territories restricted by notification of the Central Government. We monitor these notifications and will relocate processing if required. Wherever your data is processed, we apply the same security standards and contractual protections described in this policy.
10Data Retention
We retain personal data only for as long as necessary for the purposes it was collected for, or as required by law.
| Data | Retention |
|---|---|
| Active account profile, experience, qualifications, documents | For as long as your account is active |
| Data after you delete your account | Deleted or irreversibly anonymised within 30 days, subject to the exceptions below |
| Application records and status history | Retained for the duration of the hiring process and for 12 months thereafter, so both parties have a record |
| Document access logs and security/audit logs | 24 months, for security and accountability |
| Payment and invoice records | 8 years, as required under Indian tax and companies legislation |
| Support tickets and grievance records | 24 months from resolution |
| Aggregated, de-identified analytics | Indefinitely — this data cannot identify you |
We may retain data longer where required to comply with a legal obligation, to resolve a dispute, to enforce our agreements, or where a lawful preservation request applies.
Data already shared with Employers: deleting your Nurszon account removes your profile from the Platform and from Employer search. It does not, and cannot, retrieve copies of your profile or resume that an Employer lawfully downloaded before deletion. Those copies are held by the Employer as an independent Data Fiduciary, and you may exercise your rights directly against that Employer.
11Your Rights
As a Data Principal under the DPDP Act, you have the following rights:
- Right to access — obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of other Data Fiduciaries and Processors with whom it has been shared. You can request a data export from within the app.
- Right to correction and completion — correct inaccurate or misleading data, complete incomplete data, and update outdated data. Most of this you can do yourself, at any time, from your profile screens.
- Right to erasure — request deletion of your personal data where it is no longer required for the purpose it was collected for, subject to our legal retention obligations. Account deletion is available in-app under Settings → Account.
- Right to withdraw consent — withdraw consent for any processing based on consent, as easily as you gave it. Marketing communications, job alerts, and talent-search discoverability can each be turned off independently under Settings → Notifications and Settings → Privacy. Device permissions can be revoked at any time in your operating-system settings.
- Right to grievance redressal — raise a grievance with us about our handling of your data (Section 14). You must ordinarily exhaust this route before approaching the Data Protection Board of India.
- Right to nominate — nominate another individual to exercise your rights on your behalf in the event of your death or incapacity. Contact us to record a nomination.
How to exercise your rights. Use the in-app controls where available, or write to our Grievance Officer (Section 14). We will respond within the timelines set out in Section 14. To protect your account, we may need to verify your identity before acting on a request — we will ask only for what is necessary for that purpose. We do not charge a fee for exercising your rights, unless a request is manifestly unfounded or repetitive, in which case we may charge a reasonable fee or decline, giving reasons.
Your duties. The DPDP Act also places duties on you: to provide authentic information, not to impersonate another person, not to suppress material information when providing personal data for any document or identifier, and not to register false or frivolous grievances. Furnishing forged credentials on the Platform may attract penalties under the DPDP Act and other applicable law, in addition to termination of your account.
12Security
We implement reasonable security practices and procedures as required under Section 43A of the IT Act and Rule 8 of the SPDI Rules, including:
- Encryption of data in transit using TLS
- Encryption of data at rest for stored files and database contents
- Passwords stored only as salted cryptographic hashes
- Row-level access controls in the database, so users can only reach records they are entitled to
- Private storage buckets with expiring, single-use signed links for credential documents
- Immutable audit logging of document access and administrative actions
- Mandatory OTP-based two-factor authentication on password logins
- Session tokens held in the device's hardware-backed secure storage
- Rate limiting on login and OTP endpoints
- Role-based access restrictions for our own personnel, granted on a need-to-know basis
- Exclusion of personal data from crash and error reports
No system is perfectly secure. While we work hard to protect your information, we cannot guarantee absolute security of data transmitted over the internet. You are responsible for keeping your password and device secure and for not sharing your credentials. If you suspect unauthorised access to your account, notify us immediately.
Breach notification. In the event of a personal data breach, we will notify the Data Protection Board of India and each affected Data Principal, in the form and within the timelines prescribed under the DPDP Act and its rules, and will comply with applicable CERT-In directions.
13Additional Information
13.1 Children
The Platform is intended solely for persons aged 18 years or above, and, where relevant, for persons qualified to practise as healthcare professionals. We do not knowingly collect personal data from children or from persons with a disability who have a lawful guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If we learn that we have collected a child's data, we will delete it promptly. If you believe a minor has registered, contact our Grievance Officer.
13.2 Third-party links and services
The Platform may contain links to third-party websites and services — for example an Employer's own website, a map provider, or a payment page. We do not control these, and this policy does not apply to them. Review their privacy policies before providing information.
13.3 Publicly visible information
Some information you provide — such as your professional headline, specialisation, and experience summary — is visible to Employers using the Platform, and may be visible more broadly depending on your privacy settings. Do not place information in free-text fields that you would not want a prospective Employer to see. Never place identity numbers, financial details, or patient information in free-text fields.
13.4 Social media
If you interact with Nurszon on social media, those platforms' own privacy policies govern that interaction. Please do not send us sensitive personal data — identity numbers, financial details, health information, or credential documents — over social media or any unencrypted public channel. Use in-app support instead.
13.5 Communications preferences and DND
Transactional messages relating to your account, security, applications, and payments are integral to the service and cannot be switched off while your account is active. Promotional messages can be switched off at any time. SMS is sent through a DLT-registered route in compliance with TRAI's Telecom Commercial Communications Customer Preference Regulations. By providing your mobile number and requesting service, you agree to receive service-related calls and SMS from us and our agents, including where your number is registered under the DND/NCPR framework. Standard message and data rates set by your carrier may apply.
14Grievance Officer and Contact
If you have a question, concern, or complaint about this policy or about how we handle your data — including a request to exercise your rights under Section 11 — contact our Grievance Officer, appointed under the IT Act, the Intermediary Guidelines 2021, and the DPDP Act:
General privacy queries: support@nurszon.com
Support: in-app under Help & Support, or support@nurszon.com
Our timelines:
- We acknowledge every grievance within 24 hours of receipt.
- We resolve grievances within 15 days, as required under the Intermediary Guidelines 2021.
- Requests to remove content that is unlawful under Rule 3(1)(d) of those Rules are actioned within 36 hours of a valid order.
- Complaints regarding non-consensual or impersonating imagery are actioned within 24 hours.
Escalation. If you are not satisfied with our response, you may escalate to the Data Protection Board of India in the manner prescribed under the DPDP Act, or to the Grievance Appellate Committee constituted under the Intermediary Guidelines 2021, within 30 days of our decision.
15Disclaimer
Nurszon operates as an intermediary connecting Candidates and Employers. We are not the employer of any Candidate, we are not a party to any employment contract formed through the Platform, and we do not guarantee employment, interviews, response quality, or the accuracy of any job posting or profile. We do not warrant the credentials or bona fides of any Employer or Candidate, and both parties must carry out their own verification before acting. Nurszon is not liable for the acts or omissions of Employers, Candidates, or third parties, or for losses arising from events beyond our reasonable control.
Nurszon does not store your payment card or bank credentials and accepts no liability for their disclosure by a third party or by you. Nurszon does not provide medical, clinical, immigration, or legal advice.
16Changes to This Policy
We may update this Privacy Policy to reflect changes in our services, technology, or legal obligations. The "Last updated" date at the top will always show the current version.
Where a change is material — for example a new purpose of processing, a new category of recipient, or a change of Data Fiduciary — we will give you notice through the app, by email, or both, before the change takes effect, and where the law requires it we will seek your fresh consent. Continued use of the Platform after a change takes effect constitutes acceptance of the updated policy.
We maintain a version history of this policy and will provide an earlier version on request.
© 2026 Nurszon. All rights reserved.

