Data Protection

GDPR at CandiDesk.

CandiDesk processes candidate personal data on behalf of recruitment agencies and talent teams across Europe. That is a responsibility we designed for from the first line of code. This page explains, in plain language, how the General Data Protection Regulation applies to CandiDesk, what we do to honor it, and what rights you can exercise right now.

Last updated July 2026

CandiDesk GDPR and audit view with data subject requests, consent records, and a full audit log

The data subject request queue and audit log, live in the product.

CandiDesk dashboard overview with screening, conversation, call, and outreach activity

Candidate data flows through screening, conversations, and drafts under the agency's retention settings.

Our commitment to GDPR

CandiDesk is built and operated with GDPR compliance as a core requirement, not an afterthought. Recruitment is one of the most personal categories of software there is: the platform touches CVs, career histories, salary expectations, phone conversations, and the private hopes of people looking for their next job. We think a product that handles that kind of information has to treat data protection as part of the product itself, visible in the interface, enforced in the code, and auditable at any time.

In practice that means data subject requests are a working feature inside CandiDesk rather than a support ticket. Export and deletion run from a queue that agencies can act on in one click. Consent is recorded per candidate and per channel. Retention windows sweep old data automatically, with a grace period warning before anything is removed. Every screening decision, draft, send, and deletion lands in an audit log that a customer can hand to a client or a regulator without embarrassment.

We also keep a simple promise about scope: we collect the minimum we need, we use it only for the purpose it was given for, and we never sell personal data. Where this page and any signed agreement differ, the signed agreement governs, but our intent is that nothing here should surprise a lawyer or a candidate.

Data controller and data processor roles

The GDPR distinguishes between the party that decides why and how personal data is processed, called the data controller, and the party that processes data on that party's instructions, called the data processor. CandiDesk wears both hats, for different data, and it matters which one applies to you.

When a recruitment agency or talent team uploads candidate data to CandiDesk, or connects systems that contain candidate data, that customer is the data controller for the candidate data. The customer decides which roles to open, which candidates to screen, what to send, and how long to keep records. CandiDesk acts as the data processor for that candidate data: we process it only to provide the service the customer configured, under a data processing agreement, and we do not use it for our own purposes.

For the data that customers give us about themselves, such as account names, work email addresses, login records, and billing details, CandiDesk is the data controller. We decide how that account data is used, and we are directly responsible to the people it describes.

If you are a candidate whose data was processed through CandiDesk, the agency that engaged with you is your first point of contact for exercising your rights, because the agency is the controller of your data. That said, we never leave candidates stranded: if you contact us directly at nikon.mazur@candidesk.io, we will forward your request to the responsible agency and support its execution inside the platform.

Legal basis for processing

Under the GDPR, every use of personal data needs a legal basis. These are the ones that carry CandiDesk, explained with recruitment examples rather than statute numbers.

Performance of contract. When an agency signs up for CandiDesk, we process its account and billing data because that is what delivering the contracted service requires. Similarly, when an agency uses the platform to manage a candidate through a hiring process the candidate is participating in, processing happens in the context of taking steps toward a possible employment relationship.

Legitimate interest. Some processing rests on legitimate interests that are carefully weighed against the rights of the people involved. Keeping security logs to detect abuse, maintaining an audit trail of actions taken in the platform, and improving the reliability of the service are examples. We only rely on legitimate interest where a reasonable person would expect the processing and where it does not override individual rights.

Consent. Where consent is the right basis, for example when a candidate agrees that an agency may store a CV for future opportunities rather than one specific role, CandiDesk records that consent per candidate, per purpose, and per channel, and makes it just as easy to withdraw as it was to give. Withdrawing consent stops the related processing going forward.

Legal obligation. Sometimes the law itself requires processing, for example retaining certain billing records for tax purposes. Where that applies, the obligation defines both the processing and how long it lasts.

Your rights as a data subject

The GDPR gives every person whose data is processed a set of enforceable rights. Here is what each one means in normal language, and how it works around CandiDesk. To exercise any of them, contact the agency you dealt with, or write to nikon.mazur@candidesk.io and we will route your request.

Access

You can ask for confirmation of whether data about you is being processed, and receive a copy of that data along with an explanation of why it is held. In CandiDesk, an export request produces a complete, readable copy of a candidate's records.

Rectification

If data about you is wrong or incomplete, you can require it to be corrected. A wrong notice period, an outdated location, or a misparsed CV entry gets fixed, not argued about.

Erasure

You can ask for your data to be deleted, sometimes called the right to be forgotten. Inside CandiDesk, deletion requests run from the data subject request queue and remove candidate records across the platform, with the action itself recorded in the audit log.

Restriction of processing

You can require that your data is kept but not actively used, for example while a dispute about its accuracy is being resolved. Restricted records stay stored yet are excluded from active screening and outreach.

Objection

You can object to processing that rests on legitimate interest, and to any processing for direct marketing. After an objection, the processing stops unless there are compelling legitimate grounds that override it, which in recruitment is rare.

Portability

You can receive the data you provided in a structured, commonly used, machine readable format, and take it to another provider. CandiDesk exports produce exactly that.

Complaint to a supervisory authority

You always have the right to lodge a complaint with a data protection authority, regardless of anything written here. For Austria, that is the Datenschutzbehörde in Vienna. You can also complain to the authority of the country where you live or work.

International data transfers

CandiDesk runs on infrastructure in the European Union, and keeping candidate data in Europe is the default, not an option buried in settings. Some service providers we rely on may process limited data outside the European Economic Area, for example when providing global support or communications infrastructure.

Whenever personal data leaves the EEA, we use the safeguards the GDPR provides for exactly this situation. Where the destination country has an adequacy decision from the European Commission, meaning the Commission has formally found its protections comparable to European law, we can rely on that decision. Where there is no adequacy decision, we put Standard Contractual Clauses in place: contract terms published by the European Commission that bind the recipient to European standards of data protection, backed by an assessment of whether the destination's laws undermine those commitments in practice. We do not transfer candidate data to providers who cannot meet these requirements.

Sub processors

Like every modern software company, CandiDesk relies on a small number of carefully chosen providers, for example for hosting and communications infrastructure. The GDPR calls these sub processors. Each one is bound by a written agreement that holds it to data protection standards equivalent to the ones we commit to ourselves, and each one is reviewed before any personal data reaches it.

A current list of sub processors is available on request at nikon.mazur@candidesk.io. Customers with a data processing agreement are informed of intended changes to that list and can object to a new sub processor before it touches their data.

Data retention

Candidate data in CandiDesk is retained according to each customer's own retention settings. Agencies choose their retention window, and the platform enforces it automatically: when a record reaches the end of its window, it is flagged with a grace period warning and then swept. Nothing depends on someone remembering to clean up.

At the end of a customer relationship, candidate data is deleted or returned to the customer, at the customer's choice, unless a legal obligation requires a specific record to be kept longer, such as invoicing data kept for tax law. Backups roll off on a fixed schedule so that deleted data leaves them as well.

Security measures

Data protection collapses without security, so CandiDesk is built on a small set of unglamorous, effective practices. Data is encrypted in transit. Access to production systems is limited to the few people who need it to operate the service, protected by strong authentication, and every administrative action is logged. Customer workspaces are strictly separated, and the human approval gate on outbound messages is enforced at the API layer, which means no configuration mistake can bypass it.

We review our security posture regularly and treat findings as engineering work with deadlines, not as reports to file away. We intentionally do not publish infrastructure specifics on a marketing page; genuine security questions from customers and auditors are answered directly and in depth under agreement. If you believe you have found a vulnerability, write to nikon.mazur@candidesk.io and you will reach the people who can fix it.

Automated decision making and AI features

CandiDesk includes features that use artificial intelligence, such as Smart Intake, which turns a client brief into a job description and screening questionnaire, and candidate scoring, which reads profiles against the requirements of a role and shows the evidence behind every score. These features are designed to support human decision makers, not to replace them.

No candidate is rejected, advanced, or contacted by the system on its own authority. Scores come with the reasoning that produced them so a recruiter can disagree with the machine, and outbound messages wait for explicit human approval before anything sends. Customers remain responsible for their hiring processes and for final decisions about candidates. In GDPR terms, CandiDesk is built so that decisions with legal or similarly significant effect on a person are made by people, with the software supplying evidence, drafts, and speed rather than verdicts.

Data protection contact

For any question, request, or concern about data protection at CandiDesk, contact nikon.mazur@candidesk.io. Whether you are a customer, a candidate, or a regulator, your message reaches people who know the product and can act, not a mailbox that feeds a queue.