GDPR & Data Protection

Your data. Yours to control.

GDPR isn't a policy page here, it's how the platform is built. Consent, retention, deletion and candidate rights all run automatically, and you stay in control of every rule.

UK & EU GDPR ISO 27001 hosting UK / EU data centres
Hosted to suit where your business is registered and trading.
Locked to everyone but you
Your own private platform and data store, encrypted in transit and at rest. A dedicated database that's exclusively yours.
Encrypted at rest & in transit Private & Yours only Full audit trail Daily backups Multi-factor authentication on your Talent Hub
Compliance, automated

The platform handles compliance, so nobody forgets.

Every candidate record moves through the same automatic cycle. You set the rules once, the platform applies them forever.

1 · Consent
Captured & timestamped
Plain-language consent at registration, recorded and version-tracked.
2 · Retention
Your rules, applied
You set how long each type of data is kept. The platform keeps count.
3 · Notify
Candidates prompted
After a set period of inactivity, candidates hear from you before anything is removed.
4 · Erase
Deleted properly
Personal data removed across the platform. Reporting stays intact, anonymously.
Candidate rights

Their rights, built into the portal.

Every right a candidate has under GDPR is a real control in their portal: their profile, preferences and applications, in their hands. No forms, no waiting, no chasing.

{{ r.n }} {{ r.title }} {{ r.how }}
A
Your data & privacy
Candidate portal · Settings
Request my dataRequest
Update my detailsEdit
Email & push notifications
Delete my account & dataDelete
Deletion removes your personal details everywhere. Anonymous application counts are kept so reporting stays accurate. Who to contact for data requests is set out in your privacy policy.
Your privacy policy stays yours. As data controller you'll publish your own. We provide a template, but you complete it with your details, including where candidates send data requests.
Deletion, done fairly

A 30-day safety net, not an instant wipe.

30 days from request

Deletion isn't instant. From the moment a candidate asks, a 30-day window runs before their personal details are removed for good.

Changed their mind? Just log in

Their confirmation email spells it out: log back in within 30 days and the request is cancelled, do nothing and deletion goes ahead. No forms, no support tickets.

Live applications protected

If they have an active application for a live role, their email says so: the 30 days start from the job's closure, so an application is never lost mid-process.

And the door is always open. After full deletion, coming back is as simple as registering again as a new candidate.
Security

Protected at every layer.

01
Encryption

Encrypted in transit and at rest

All traffic and stored data encrypted to modern standards. Keys rotated on schedule.

02
Isolation

Your own private platform

Every client runs separately. No shared database, no crossover with anyone else.

03
Access

Your team only, at the right level

Recruiter access is protected with multi-factor authentication, each person with their own level of access, from admin to read-only.

04
Audit

Every change recorded

Every recruiter action, candidate edit and system event is timestamped in the audit log.

05
Backups

Backed up daily

Automatic daily backups held in a separate location, restore-tested.

06
Incidents

Prepared, just in case

Best-practice controls make incidents unlikely. If one ever occurs, we tell you promptly, keep you informed and handle it within statutory timescales.

07
File screening

Every upload scanned before it lands

Every CV, certificate and document is screened for malware before it's accepted onto the platform. Anything suspicious is blocked at the door, before it reaches your team.

08
AI & automated decisions

Human in the loop, by design

AI scores and explains every candidate, but it never rejects anyone on its own. Nothing is declined until someone on your team reviews and confirms, with safeguards against accidental bulk declines, time to undo, and every confirmation logged in the audit trail. This is how the platform meets the rules on automated decision-making in the UK (UK GDPR Article 22), Isle of Man (Applied GDPR Article 22), Jersey (DPJL Article 38) and Guernsey (Data Protection Law 2017). Candidates can always ask for a human review.

Hosted on ISO 27001-certified infrastructure in UK and EU data centres, governed by UK and EU law.
Compliance questions

Speak to us directly.

We'll walk through how the platform is secured and answer specifics about how your data is handled. A direct conversation, not a sales call.

Contact us Browse the FAQs
Read our privacy policy for how we handle your data as an enquirer.