Privacy Policy

Last updated: July 31, 2026

1. Who we are

This Privacy Policy is issued by SequelOne Solutions Private Limited, trading as HONO ("HONO", "we", "us", "our"), a company incorporated in India with its registered office at 12th Floor, BPTP Centra One, Golf Course Extension Road, Gurugram - 122098, Haryana, India.

It covers our websites at https://www.hono.ai and https://hono.ai, including all subdomains, and applies to all HONO brands, products and services, and to our mobile applications, unless a separate notice is provided for a specific product.

For any question, request or complaint about your personal data, contact our Data Protection Officer at dpo@hono.ai. This is our single point of contact for all privacy matters, including the exercise of your rights and any grievance under Indian law. You can write to us at our registered office above.

HONO has no establishment in the European Union or the United Kingdom.

2. Which laws this policy is built around

This policy is designed to meet the requirements of:

  • The EU General Data Protection Regulation (Regulation (EU) 2016/679) and the ePrivacy Directive
  • The UK GDPR, the Data Protection Act 2018 and PECR
  • The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (India)
  • The Personal Data Protection Law, Royal Decree M/19 of 2021 as amended, and its Implementing Regulations (Kingdom of Saudi Arabia)
  • Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (United Arab Emirates)
  • The Personal Data Protection Act B.E. 2562 (2019) and its sub-regulations (Thailand)
  • Other national and regional data protection laws applicable to our operations

Region-specific rights and disclosures are set out in the Annexes at the end of this policy. Where an Annex conflicts with the main body, the Annex prevails for individuals in that region.

3. Our two roles: controller and processor

The distinction below determines who you should contact and which rights apply.

Where HONO is the controller (this policy governs):

  • Visitors to our websites
  • Prospects, leads and marketing contacts
  • Users of our free online tools
  • Job applicants applying to HONO
  • Contacts at our clients, partners and suppliers

Where HONO is a processor (this policy does not govern):

  • Employee and workforce data processed inside the HONO HRMS platform on behalf of a client organisation
  • Facial recognition data processed through HONO Gatetrack on behalf of an employer

In processor scenarios, your employer or the organisation that engaged us is the controller (in India, the Data Fiduciary). They determine what is collected and why. Our processing is governed by our written agreement with them, not by this policy.

If you are an employee of a HONO client and want to exercise your rights, contact your employer's HR or privacy team. If you contact us directly, we will forward your request to them and support them in responding, but we cannot act on it independently.

4. What personal data we collect

4.1 Information you give us

CategoryExamplesWhere from
Contact and business detailsName, work email, phone number, job title, company name, countryDemo request, contact, download and event forms
Enquiry contentThe message, requirements or questions you submitForms, email, chat
Marketing preferencesYour subscription choices and consent recordsForms, preference centre
Free tool inputsDocuments and text you upload to the Resume Analyzer, Offer Letter Generator, Payroll Error Hunt or Agent PlaygroundTool interfaces
Recruitment dataCV, work history, education, references, right-to-work informationCareers applications
Commercial and billing dataContracting entity details, purchase order and invoicing informationContract process

4.2 Information we collect automatically

Device and connection data (IP address, device and browser type and settings, operating system, language, mobile network and carrier information where applicable); usage data (pages viewed, referring URL, time zone, date, time and duration of visit, search terms, content and links interacted with); and cookie and similar identifiers.

Details of every cookie and similar technology we use, its purpose and its duration, are in our Cookie Policy. Non-essential cookies are set only where you have given consent, and you can change or withdraw that consent at any time via the Cookie Settings link in our website footer.

4.3 Information from other sources

We may receive personal data from: your employer or colleagues (where they submit your details); our clients and partners; publicly available professional sources such as company websites and professional networking platforms; event organisers where you attended a HONO event or visited our stand; and business information providers. Where we obtain your data indirectly, we will tell you the source on request, and we provide this notice within one month of obtaining it or at first contact, whichever is earlier.

4.4 What we do not collect

We do not knowingly collect special category or sensitive personal data through our website or free tools, and you should not submit it. See section 12 on our free AI tools.

PurposeData usedLegal basis (EU/UK GDPR)Basis under DPDP / PDPL
Responding to demo requests, enquiries and quotesContact details, enquiry contentArt. 6(1)(b) — steps at your request before entering a contractDPDP s. 7(a) specified purpose voluntarily provided; PDPL — contract performance
Operating and securing our websites and appsDevice data, logs, essential cookiesArt. 6(1)(f) — legitimate interest in a secure, functioning serviceLegitimate use / legitimate interest
Providing our free online toolsInputs you submit, account dataArt. 6(1)(b) — provision of the service you requestedConsent / service provision
Sending marketing emails and newslettersContact details, preferencesArt. 6(1)(a) — your consent, or Art. 6(1)(f) soft opt-in for existing customers where permittedDPDP s. 6 consent; PDPL consent
Website analytics and performance measurementUsage data, analytics cookiesArt. 6(1)(a) — your cookie consentConsent
Advertising, retargeting and campaign measurementUsage data, advertising cookiesArt. 6(1)(a) — your cookie consentConsent
Managing our client, partner and supplier relationshipsContact and commercial dataArt. 6(1)(b) and Art. 6(1)(f)Contract performance
RecruitmentApplication dataArt. 6(1)(b) pre-contractual steps; Art. 6(1)(f) for talent pool retention with noticeConsent / employment purposes
Fraud prevention, abuse detection and security monitoringDevice, usage and account dataArt. 6(1)(f) — legitimate interest in protecting our service and usersLegitimate use s. 7; PDPL security
Complying with legal, tax, regulatory and audit obligationsAs requiredArt. 6(1)(c) — legal obligationLegal compliance
Establishing, exercising or defending legal claimsAs requiredArt. 6(1)(f) — legitimate interestLegal claims

Where we rely on legitimate interests, we have carried out a balancing assessment and you can request a summary of it at dpo@hono.ai.

Where we rely on consent, you may withdraw it at any time. Withdrawal is as easy as giving consent, and does not affect the lawfulness of processing carried out before withdrawal.

Is providing your data mandatory? No. Providing data through our forms is voluntary. However, if you do not provide the fields marked as required, we may be unable to respond to your enquiry, provide a demo, or process your application.

6. Marketing communications

We send marketing communications only where you have given us specific consent through an unbundled opt-in, or where you are an existing customer and applicable law permits a soft opt-in for similar products and services.

Consenting to marketing is always separate from submitting a form. Agreeing to this Privacy Policy is not consent to marketing.

You can opt out at any time by using the unsubscribe link in any marketing email, updating your preferences in our preference centre, or emailing dpo@hono.ai. We action opt-outs promptly and in any event within the period required by applicable law.

7. Who we share your data with

We do not sell your personal data. We do not share it with third parties for their own independent marketing purposes.

Recipient categoryPurposeLocationTransfer safeguard
HubSpot, Inc. — CRM, forms, marketing automationStoring form submissions, managing contacts, sending communicationsEEA, USA and IndiaArt. 28 DPA with EU Standard Contractual Clauses; EU–US Data Privacy Framework where applicable
Website hosting and infrastructure providersWebsite hosting, delivery and server logsEEA, USA and IndiaArt. 28 DPA and Standard Contractual Clauses where required
Cloud infrastructure providers for the HONO platformHosting the HRMS and mobile applicationsEEA, USA and IndiaArt. 28 DPA and SCCs
Analytics providersWebsite performance and usage measurementEEA, USA and IndiaConsent-based; DPA and SCCs
Advertising and social platforms (LinkedIn, Meta, Google, X, YouTube)Advertising, retargeting and campaign measurementGlobalConsent-based; controller or joint controller terms as applicable
Email delivery and communications providersSending transactional and marketing emailEEA, USA and IndiaArt. 28 DPA
Support and ticketing providersHandling support requestsEEA, USA and IndiaArt. 28 DPA
Professional advisers — lawyers, auditors, accountantsLegal and regulatory advice, auditIndia / as engagedConfidentiality obligations
Regulators, courts and law enforcementWhere legally required, or to establish or defend legal claimsAs applicableLegal obligation
Acquirers in a corporate transactionMerger, acquisition, financing or asset saleAs applicableConfidentiality and successor obligations

A current list of our sub-processors is available on request at dpo@hono.ai.

8. International data transfers

HONO operates in India, the Middle East, South East Asia and Africa, and uses service providers established outside your country. Your personal data may therefore be transferred to and processed in countries other than your own, including the United States and India.

Where we transfer personal data out of the EEA or the UK, we rely on one or more of: an adequacy decision by the European Commission or the UK government; the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), supported by a transfer impact assessment; or the EU–US Data Privacy Framework where the recipient is certified.

For transfers of personal data out of the Kingdom of Saudi Arabia, we comply with Article 29 of the PDPL and the Data Transfer Regulations, including risk assessment and, where required, SDAIA approval.

For transfers out of the United Arab Emirates, we comply with Articles 22 and 23 of the UAE PDPL.

For transfers from India, we comply with section 16 of the DPDP Act and will not transfer personal data to any country restricted by the Central Government.

For transfers out of Thailand, we comply with sections 28 and 29 of the PDPA and the PDPC sub-regulations on cross-border transfers and Binding Corporate Rules.

You can request a copy of the relevant safeguards by emailing dpo@hono.ai. Commercially confidential terms may be redacted.

9. How long we keep your data

We keep personal data only for as long as necessary for the purpose it was collected for, or as required by law. Our retention periods are:

DataRetention period
Marketing contacts and leadsUntil you unsubscribe or withdraw consent, or after 24 months of no engagement, whichever is earlier
Form submissions and enquiries not converting to a contract24 months from last contact
Client contact and contract recordsDuration of the contract plus 8 years, to meet Indian statutory and tax retention requirements
Free tool uploads (CVs, documents, text inputs)Deleted within 30 days of upload
Unsuccessful job applications12 months, or longer with your consent for our talent pool
Website and security logs12 months
Cookie consent records12 months from the consent or its withdrawal
Correspondence and support tickets36 months from resolution
Records required for legal claimsUntil the applicable limitation period expires

At the end of the retention period we securely delete or irreversibly anonymise the data.

10. How we protect your data

We implement appropriate technical and organisational measures, including: encryption of data in transit (TLS) and at rest; role-based access controls on a least-privilege basis; multi-factor authentication for administrative access; network segregation and monitoring; regular vulnerability scanning and periodic penetration testing; logging and log retention; secure development practices; vendor security due diligence and written processing agreements; documented incident response procedures; confidentiality obligations on all personnel; and regular data protection and security training.

11. Personal data breaches

If a personal data breach occurs, we will:

  • Notify the competent supervisory authority within 72 hours of becoming aware of it, where the breach is likely to result in a risk to individuals' rights and freedoms (GDPR Art. 33);
  • Notify each affected Data Principal without delay, and provide the Data Protection Board of India with the prescribed information within 72 hours, in accordance with section 8(6) of the DPDP Act and Rule 7 of the DPDP Rules 2025 — this applies to all breaches, regardless of risk level;
  • Notify SDAIA and affected individuals as required by the KSA PDPL, the UAE Data Office as required by the UAE PDPL, and the Personal Data Protection Committee (PDPC) as required by section 37(4) of the Thailand PDPA;
  • Notify you directly without undue delay where the breach is likely to result in a high risk to your rights and freedoms (GDPR Art. 34), describing the nature of the breach, the likely consequences and the measures taken.

12. Our free online tools

Our free tools (Resume Analyzer, Offer Letter Generator, Payroll Error Hunt, Agent Playground and HONO Consultant) may allow you to upload documents or enter text.

  • These tools are for business use only and are not intended for consumers.
  • You must not upload special category or sensitive personal data — including health data, biometric data, government identifiers, financial account details, or data revealing racial or ethnic origin, religious beliefs, political opinions, trade union membership or sexual orientation.
  • If you upload documents containing another person's personal data (such as a candidate's CV), you are the controller of that data and you must have a lawful basis and, where required, that person's consent to do so. HONO acts as your processor for that content.
  • We do not use content you upload to these tools to train our AI models.
  • Uploaded content is deleted within 30 days.
  • Outputs are generated automatically and may be inaccurate or incomplete. They are informational only. You must not rely on them as the sole basis for any decision affecting an individual, including hiring, promotion, discipline or termination. Meaningful human review is required.

13. Automated decision-making, profiling and AI

On our website: we use analytics and, where you consent, advertising technologies that profile your browsing behaviour to measure campaign performance and show you relevant content and advertising. This does not produce legal or similarly significant effects for you. You have an unconditional right to object to profiling for direct marketing purposes at any time — email dpo@hono.ai or withdraw consent via Cookie Settings.

Our AI features: where you interact with an AI chatbot or AI assistant on our website, you are interacting with an artificial intelligence system, not a human. This disclosure is made in accordance with Article 50 of the EU AI Act.

In the HONO platform: our products include AI features that support recruitment, screening, attendance and workforce decisions. Where these are deployed by a client organisation, that client is the controller and is responsible for how decisions are made and for any required human oversight, transparency and impact assessment. HONO designs these features to support, not replace, human decision-making.

We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. If that ever changes, we will tell you, explain the logic involved and the significance and consequences, and give you the right to obtain human intervention, express your point of view and contest the decision.

14. HONO Gatetrack — facial recognition

HONO Gatetrack is deployed by employer organisations. In respect of Gatetrack, HONO acts as a processor and the employer is the controller (Data Fiduciary). The employer is responsible for establishing a lawful basis, providing notice to its workforce, and carrying out any required impact assessment. Employees should direct requests to their employer.

Facial data is biometric data used for the purpose of uniquely identifying an individual. It is special category data under Article 9 of the GDPR, sensitive data under the KSA PDPL, and sensitive personal data under the UAE PDPL. It requires an Article 9(2) condition — in practice the individual's explicit consent, or a basis in employment law — which the deploying employer must establish. A Data Protection Impact Assessment is mandatory under Article 35(3)(b) of the GDPR before deployment, and HONO will support its client in completing one.

Our processing of facial data on behalf of employers is subject to the following commitments:

  • Purpose limitation. Facial data is used solely to verify identity and record attendance. It is not used for any other purpose, including surveillance, emotion recognition, performance monitoring, marketing or model training.
  • Storage. Facial templates are held for the duration of the individual's association with the deploying organisation and are deleted automatically when that association ends. They are stored in encrypted form.
  • Disclosure. We do not disclose facial data to any third party for that party's own purposes. We do not sell, share or distribute it. It is accessible only to our vetted infrastructure and cloud service providers acting as our sub-processors under written agreements containing confidentiality and security obligations, and to authorised HONO personnel on a strict need-to-know basis.
  • Legal disclosure. We may disclose facial data where compelled by law, regulation or legal process, such as a court order or a lawful government request. Where permitted, we will notify the controller before disclosing and will limit disclosure to what is legally required.

15. Children

Our websites, products and services are not directed at children and are intended for individuals aged 18 or over. We do not knowingly collect personal data from children.

Consistent with section 9 of the DPDP Act, we do not undertake tracking, behavioural monitoring or targeted advertising directed at children, and we do not process children's personal data in a way likely to cause any detrimental effect on their wellbeing.

If you believe a child has provided us with personal data, contact dpo@hono.ai and we will delete it promptly.

16. Your rights

Subject to the conditions and exemptions in the law that applies to you, you have the following rights:

RightWhat it means
AccessObtain confirmation of whether we process your data, a copy of it, and information about how it is processed
CorrectionHave inaccurate or incomplete data corrected or completed
ErasureHave your data deleted where there is no continuing lawful reason to keep it
RestrictionAsk us to limit processing while a dispute over accuracy or lawfulness is resolved
PortabilityReceive data you provided in a structured, commonly used, machine-readable format and have it transmitted to another controller
ObjectionObject to processing based on legitimate interests, and object to direct marketing at any time — this second right is absolute
Withdraw consentWithdraw consent at any time, as easily as you gave it, without affecting prior lawfulness
Automated decisionsNot be subject to a solely automated decision with legal or similarly significant effects, and to obtain human intervention
Nomination (India)Nominate another individual to exercise your rights on your behalf in the event of death or incapacity — DPDP s. 14
Grievance redressal (India)Have your grievance addressed by our Grievance Officer before approaching the Data Protection Board — DPDP s. 13
ComplainLodge a complaint with your data protection authority — see section 17

How to exercise your rights

Email our Data Protection Officer at dpo@hono.ai to exercise any of these rights, to ask a privacy question, or to raise a grievance.

Tell us which right you want to exercise and give us enough detail to find your records. We may ask you to verify your identity before acting, to make sure we do not disclose your data to someone else. We will not ask for more information than is necessary to do so.

Our timelines:

  • We acknowledge every request within 48 hours.
  • We respond substantively within one month. If your request is complex or you have made several, we may extend this by up to two further months and will tell you within the first month, with reasons.
  • Grievances raised under the DPDP Act are resolved within the period prescribed by the DPDP Rules.
  • Exercising your rights is free. We may charge a reasonable fee or refuse to act only where a request is manifestly unfounded or excessive, and we will explain why.

If we process your data on behalf of an employer or client (see section 3), we will forward your request to them and support their response, but we cannot act on it independently.

17. Complaints

We would like the chance to resolve your concern first, so please contact dpo@hono.ai. You also have the right to complain directly to a supervisory authority:

RegionAuthority
IndiaData Protection Board of India
EUThe data protection authority of your Member State of residence, place of work or where the alleged infringement occurred
UKInformation Commissioner's Office — ico.org.uk
Saudi ArabiaSaudi Data and Artificial Intelligence Authority (SDAIA)
UAEUAE Data Office
ThailandPersonal Data Protection Committee (PDPC)

18. Third-party websites

Our website contains links to third-party sites, including social media platforms and app stores. We do not control them and are not responsible for their privacy practices. Read their policies before providing personal data.

19. Changes to this policy

We may update this policy to reflect changes in our practices, services or applicable law. Where changes are material, we will give notice by a prominent notice on our website, and by email where we hold your address, at least 30 days before they take effect. The date at the top of this policy shows when it was last changed. Previous versions are available on request.

20. Contact us

For any question, request or complaint about your personal data, contact our Data Protection Officer at dpo@hono.ai.

You can write to us at SequelOne Solutions Private Limited, 12th Floor, BPTP Centra One, Golf Course Extension Road, Gurugram - 122098, Haryana, India.

For general commercial or product enquiries unrelated to privacy, please use connect@hono.ai.

Annex A — Additional information for individuals in the EU and UK

Controller: SequelOne Solutions Private Limited, 12th Floor, BPTP Centra One, Golf Course Extension Road, Gurugram - 122098, Haryana, India.

HONO has no establishment in the European Union or the United Kingdom.

Data Protection Officer: dpo@hono.ai.

Our legal bases are set out in section 5 and our transfer safeguards in section 8. You may request a copy of our Standard Contractual Clauses and transfer impact assessments at dpo@hono.ai.

You have the right to lodge a complaint with the supervisory authority in your Member State of residence, place of work, or the place of the alleged infringement. In the UK, that is the Information Commissioner's Office.

Annex B — Additional information for Data Principals in India

HONO is a Data Fiduciary under the Digital Personal Data Protection Act, 2023 in respect of the processing described in section 3 as controller processing.

Data Protection Officer and Grievance Officer: dpo@hono.ai.

This notice is available in English. On request to dpo@hono.ai we will provide it in any language specified in the Eighth Schedule to the Constitution of India.

You may withdraw consent at any time at dpo@hono.ai, with the same ease with which it was given. You may nominate another individual to exercise your rights under section 14. You may raise a grievance with our Grievance Officer under section 13, and if unresolved, complain to the Data Protection Board of India.

Section 15 of the DPDP Act places duties on Data Principals, including not raising false or frivolous grievances and furnishing only authentic information.

Annex C — Additional information for individuals in Saudi Arabia

HONO processes personal data of individuals in the Kingdom in accordance with the Personal Data Protection Law (Royal Decree M/19 of 2021 as amended) and its Implementing Regulations, supervised by SDAIA.

You have the right to be informed, to access your personal data, to obtain a copy of it in a readable format, to request correction, and to request destruction. You may also withdraw consent at any time.

Biometric data, health data and financial data are treated as Sensitive Data and are subject to enhanced safeguards. Transfers outside the Kingdom are made only in accordance with Article 29 and the Data Transfer Regulations.

Contact: dpo@hono.ai. Complaints may be made to SDAIA.

Annex D — Additional information for individuals in the UAE

HONO processes personal data of individuals in the UAE in accordance with Federal Decree-Law No. 45 of 2021.

You have the right to receive information, to request the transfer of your data, to access, correct or erase your data, to restrict or stop processing, and to object to automated processing.

Note that entities established in the Dubai International Financial Centre (DIFC) and the Abu Dhabi Global Market (ADGM) are subject to their own data protection regimes and regulators.

Contact: dpo@hono.ai. Complaints may be made to the UAE Data Office.

Annex E — Additional information for individuals in Thailand

HONO processes personal data of individuals in Thailand in accordance with the Personal Data Protection Act B.E. 2562 (2019) ("PDPA"), published in the Royal Thai Government Gazette on 28 May 2019 and in full force from 1 June 2022, together with its sub-regulations. The PDPA is supervised by the Personal Data Protection Committee (PDPC).

This policy applies to you where HONO offers goods or services to persons in Thailand or monitors behaviour taking place in Thailand, consistent with the extraterritorial scope of the PDPA.

Legal bases we rely on under the PDPA include: performance of a contract, compliance with a legal obligation, legitimate interests, vital interests, public interest, and — where required — your consent. For sensitive personal data (including biometric data, health data and other categories listed in section 26 of the PDPA), we rely on explicit consent or another lawful ground provided under the PDPA.

Your rights as a Data Subject under the PDPA include the right to be informed; to access your personal data and obtain a copy; to request correction; to request erasure, destruction or anonymisation; to restrict or object to processing; to data portability; and to withdraw consent at any time. Requests are handled within the timelines prescribed by the PDPA.

Cross-border transfers of personal data from Thailand are made only in accordance with sections 28 and 29 of the PDPA and the PDPC's sub-regulations on cross-border transfers and Binding Corporate Rules issued through March 2024, including where the destination country provides an adequate level of protection or where appropriate safeguards (such as Binding Corporate Rules or standard contractual clauses recognised by the PDPC) are in place.

Data breach notification: where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, HONO notifies the PDPC without undue delay and, where the breach is likely to result in a high risk, notifies affected Data Subjects in accordance with section 37(4) of the PDPA and the PDPC's breach notification guidance.

Contact: dpo@hono.ai. Complaints may be made to the Personal Data Protection Committee (PDPC).