Candidate privacy & consent

Candidates can see what you hold. And say no.

Every sourced candidate gets a privacy notice and a personal page that says what you hold, why, and how to have it deleted. Consent is captured where it happens, sensitive questions are flagged, and files clean themselves up on schedule.

What’s built in

Privacy that runs itself, not a checklist you run once a year.

Six pieces, each attached to the moment the data is collected.

A notice on every source

Add someone by hand, parse a CV or import a spreadsheet and a privacy notice goes out with a personal link. Nothing sits in the pool unannounced.

A page the candidate owns

What you hold and why you hold it, in plain words, on a link that needs no login. One button to object, and the record is anonymised on the spot.

Consent where it happens

The apply form asks whether to keep the profile for future roles. The answer and its timestamp live on the application.

Legal texts on your career page

Privacy notice, KVKK disclosure and user agreement publish under your subdomain and are linked from every apply form.

Files that expire

Video answers are deleted at the end of the retention window; check documents are purged after theirs. The outcome stays, the file does not.

Every look, logged

Reveals, exports and deletions are written to the audit log with user and time. Filter it, export it, done.

Collection

Consent is captured where the data is, not in a drawer.

Each touchpoint has its own control: a checkbox on the apply form, a notice on import, a lock on a sensitive question, a legal basis before a document request. You never reconstruct consent after the fact.

Talent-pool consent with a timestamp
Notice with a personal link on import and sourcing
Sensitive-data flag the candidate can see
Legal basis required on document requests
Lifecycle

Data comes in with a reason and leaves on a schedule.

Collected for a purpose, seen by the roles that need it, cleaned up when the window closes, gone when the candidate asks. Each step leaves a line in the audit log.

Access follows role and job scope
Video and documents purge automatically
An objection anonymises the record
Deletions and reveals in the audit log
Where it matters

Three teams that stopped dreading the question.

Passive sourcing, campus pools and regulated hiring each have their own privacy trap.

Passive candidates

People who never applied

You met them at an event or found them on LinkedIn. They deserve to know they are in your system.

  • Notice sent the moment they are added
  • Personal page, no login
  • Objection handled without a ticket
Campus

Pools that outlive the season

Hundreds of graduates, one intake. Some you want to keep for next year, but only the ones who said yes.

  • Consent checkbox on the apply form
  • Filter the pool by consent
  • Video answers gone after retention
Regulated

When legal asks who saw this

Finance, healthcare, public sector: the answer has to be a list, not a memory.

  • Legal basis on every document request
  • Reveals and exports in the audit log
  • Purge dates on the record
Privacy FAQ

What legal and people teams ask first

How Hireall handles candidate data.

No. The privacy notice carries a personal, token-based link that opens their page directly. They see what is held and why, and can ask for deletion from there.

The record is anonymised immediately: identifying fields are removed, and the objection and its time are logged. History stays attached to an anonymous record so your reports still add up.

Video answers and background-check documents are purged automatically when their retention window ends. Candidate records follow a soft-delete policy; company-wide retention timers for whole profiles are not automated today.

The apply form asks whether the candidate agrees to be kept for future roles. The answer and its timestamp are stored on the application and can be used as a filter in the pool.

In the EU, encrypted in transit and at rest. A GDPR and KVKK aligned DPA is available on request; see the security overview page for the infrastructure summary.

See it on your data

Show legal the page, not a policy.

Walk through the candidate privacy page, consent capture and the audit log in a 30-minute demo. Bring your own legal texts if you like.

Talk to our team

Tell us about your roles and team size — we'll map Hireall to your hiring process and the plan that fits.

Contact sales Priced per company, not per seat