EU hosting with encryption in transit and at rest, tenant isolation, role-based access, a three-year audit log and candidate privacy controls — documented here and in our published DPA, so IT and legal can review before they have to ask.
Two-step verification
Authenticator app or e-mailed code at every sign-in
On
Role-based access
Hiring managers see only their assigned jobs
6 roles
Audit log
Sign-ins, exports and permission changes
3-yr retention
Retention & deletion
Video answers deleted on schedule
Nightly
Audit log export requested
Enter the one-time code sent to your inbox.
Verify
Security capabilities
What we put in writing
Nine controls you can hand to IT, legal or a DPO. Where a control is also a product feature, the card links to the page that shows it in detail.
Infrastructure
Hosted in the EU, encrypted in transit (TLS) and at rest. Each customer is a separate tenant — every query is scoped to your company — and integration secrets such as Slack tokens or service-account keys are stored encrypted at field level.
Two-step verification
Each person turns on a second step for their own sign-in: a time-based code from Google Authenticator, Microsoft Authenticator or any other authenticator app, or a one-time code by e-mail. Switching the app on issues ten single-use recovery codes, and the secret is held encrypted. Codes sent, passed, refused and locked out all land in the audit log.
Role-based access
Six roles — super admin, admin, hiring manager, recruiter, reviewer, assistant — plus job-level scoping. Hiring managers and reviewers only see the jobs and candidates they are assigned to.
Sign-ins, candidate and pipeline changes, exports, permission and settings changes, e-mails, integrations and billing events are logged with actor, IP and severity. Admins filter and search in the dashboard; exports to CSV or XLSX require an e-mailed one-time code and are logged themselves.
Retention & deletion
Retention is enforced by the product, not by policy alone: a nightly job deletes video interview answers after 60, 90 or 365 days according to the subscription, and candidate data follows the KVKK soft-delete schedule.
Candidate privacy
Every sourced or imported candidate receives a privacy notice with a personal privacy page; one click objects and the record is anonymized on the spot, and anyone still uninformed after 30 days is flagged to you. Our DPA and sub-processor list are published — no need to ask.
Admins choose which candidate fields count as sensitive — contact details, salary expectation, gender, birth date, address and GPA by default — and reviewers and assistants never see them. Talent-pool consent is captured on the apply form where you require it.
Switch it on per job and evaluators see applications without name, photo or gender until identity is revealed on purpose — and every reveal is written to the audit log.
Ask a candidate for an official document, verify it and record the outcome. Criminal-record and health documents are stored only if the candidate explicitly consents while uploading; otherwise only the verdict is kept, and a file can never be required of them. Other documents the candidate attaches sit in private storage, visible to authorised users alone, and are erased on the date set for that item. The legal basis is always declared by a named person, and no automatic check ever moves or rejects a candidate.
Leaving is a documented process, not a negotiation: on request we export your whole tenant — jobs, candidates, notes, scorecards, offers, audit records — as JSON with a file manifest. What is exportable and in which format is published in the Data Export Register.
When a sub-processor changes, every active customer's privacy contact is e-mailed 30 days in advance, as the DPA requires.
Compliance made simple
GDPR, KVKK and CCPA, handled inside the product
The apply form picks the right privacy notice from the job's location and fills in your legal details. Candidates get their own privacy page; you get the paperwork already published.
EU · UK · EEA
GDPR
For jobs located in the EU, UK or EEA, the GDPR privacy notice is added to the apply form automatically.
Notice pre-filled with your legal entity and privacy contact
Art. 28 processing covered by our published DPA and sub-processor list
Personal privacy page for every candidate; one click to object
Türkiye
KVKK
For jobs located in Türkiye, the KVKK disclosure text (aydınlatma metni) is generated for you.
Legal name, address, MERSIS and KEP details filled in from your settings
Talent-pool consent captured and time-stamped on the apply form
Sourced candidates informed with a personal privacy link
United States
CCPA
For jobs located in the US, the CCPA notice is added to the apply form with your legal entity and contact.
Sensitive fields hidden from reviewers and assistants by default
Candidate objection anonymizes the record on the spot
Full tenant export available on request, in documented formats
Security reviews & questionnaires
Send your vendor questionnaire or third-party assessment to sales. We answer it in writing with the DPA, sub-processor list, Data Export Register and an infrastructure summary.
Write to our security inbox with steps to reproduce. We acknowledge reports, keep you informed while we fix, and credit you if you want to be credited.
The apply form selects the right privacy notice from the job's location — GDPR for the EU, UK and EEA, KVKK for Türkiye, CCPA for the US — and fills in your legal entity and contact details. Every candidate gets a personal privacy page and can object in one click; talent-pool consent is captured with a timestamp. Our DPA, sub-processor list and Data Export Register are published on the legal pages, and sub-processor changes are announced 30 days in advance.
Yes. Sign-ins, candidate and pipeline changes, exports, permission and settings changes, e-mails, integrations and billing events are recorded with actor, IP address and severity, kept for three years and purged on a schedule. Admins filter and search it in the dashboard; CSV or XLSX export is available on plans that include it and requires a one-time e-mail code.
Yes. Send the questionnaire or assessment to sales@hireall.com or through the contact sales form. We answer in writing and attach the DPA, the sub-processor list, the Data Export Register and an infrastructure summary covering hosting, encryption, tenant isolation, access control and retention.
Data is hosted in the EU, encrypted in transit and at rest. The infrastructure jurisdiction and the safeguards against unlawful government access are described in the Data Export Register. For other data-residency questions, email sales@hireall.com or use the contact sales form.
Candidates can object from their personal privacy page and the record is anonymized at once. Records deleted in the product are hidden immediately and permanently deleted by a scheduled job 30 days later; only records a legal obligation or a live dispute requires are kept longer, for that purpose alone. Timers run per data type — audit records after three years, video answers after 30 to 365 days according to the subscription, finished document checks on their own schedule, security logs after 12 months — and every deletion is written to the audit log. Application logs carry record identifiers, not names or contact details.
Talk to us
Need a security pack?
Send us your vendor questionnaire — we answer it with the DPA, sub-processor list and an infrastructure summary.