GDPR isn't a policy page here, it's how the platform is built. Consent, retention, deletion and candidate rights all run automatically, and you stay in control of every rule.
Every candidate record moves through the same automatic cycle. You set the rules once, the platform applies them forever.
Every right a candidate has under GDPR is a real control in their portal: their profile, preferences and applications, in their hands. No forms, no waiting, no chasing.
Deletion isn't instant. From the moment a candidate asks, a 30-day window runs before their personal details are removed for good.
Their confirmation email spells it out: log back in within 30 days and the request is cancelled, do nothing and deletion goes ahead. No forms, no support tickets.
If they have an active application for a live role, their email says so: the 30 days start from the job's closure, so an application is never lost mid-process.
All traffic and stored data encrypted to modern standards. Keys rotated on schedule.
Every client runs separately. No shared database, no crossover with anyone else.
Recruiter access is protected with multi-factor authentication, each person with their own level of access, from admin to read-only.
Every recruiter action, candidate edit and system event is timestamped in the audit log.
Automatic daily backups held in a separate location, restore-tested.
Best-practice controls make incidents unlikely. If one ever occurs, we tell you promptly, keep you informed and handle it within statutory timescales.
Every CV, certificate and document is screened for malware before it's accepted onto the platform. Anything suspicious is blocked at the door, before it reaches your team.
AI scores and explains every candidate, but it never rejects anyone on its own. Nothing is declined until someone on your team reviews and confirms, with safeguards against accidental bulk declines, time to undo, and every confirmation logged in the audit trail. This is how the platform meets the rules on automated decision-making in the UK (UK GDPR Article 22), Isle of Man (Applied GDPR Article 22), Jersey (DPJL Article 38) and Guernsey (Data Protection Law 2017). Candidates can always ask for a human review.
We'll walk through how the platform is secured and answer specifics about how your data is handled. A direct conversation, not a sales call.