Legal
GDPR at Recruitifly
How Recruitifly supports GDPR compliance, who is controller and who is processor, retention automation, security measures, sub-processors, and data subject rights.
On this page
- Controller and processor
- Data processing agreement
- Lawful bases for recruitment data
- Storage limitation, retention, and erasure
- Data subject rights support
- Security measures
- Hosting and sub-processors
- International transfers
- Automated processing and Article 22
- Passive sourcing
- Breach notification
- Your responsibilities as a customer
- Questions
Recruitifly is built in the Netherlands for European recruitment, and the GDPR is a design constraint, not an afterthought. This page explains how responsibilities are divided, what the platform does automatically, and what remains your job as an employer or agency. It is informational; the binding commitments live in the Terms of Service, the data processing agreement, and the Privacy Policy.
Controller and processor
Recruitment data in a Recruitifly workspace (candidates, CVs, notes, interview feedback, messages) is determined by you, the customer: you decide what is collected and why. That makes you the data controller for that data, and Recruitifly the data processor under GDPR Article 28. We process workspace data only to provide the Service and on your documented instructions.
For our own websites, accounts, billing, and support, Recruitifly is the controller; that processing is covered by the Privacy Policy.
Data processing agreement
A DPA meeting the Article 28(3) requirements is available to every customer and covers, among other things: processing only on instructions, confidentiality obligations for our staff, security measures, sub-processor authorization and notice, assistance with data subject requests and breach notification, and deletion or return of data at the end of the contract. Email hello@recruitifly.com to receive a copy for countersignature.
Lawful bases for recruitment data
As controller you choose the lawful basis for processing candidate data, typically legitimate interest for handling applications and consent for talent-pool retention beyond the original vacancy. Recruitifly supports both: the platform records consent and objection events, and processing-objection details are visible on the candidate record so your team can act on them.
Storage limitation, retention, and erasure
The GDPR requires that candidate data is not kept longer than necessary. Recruitifly enforces this automatically:
- Per-workspace retention policy. Candidate data has a default retention period of 18 months, which each workspace can adjust to match its own policy and local guidance.
- Automated retention sweeps. A daily job finds candidates past the retention horizon and anonymizes them: personal fields are overwritten with placeholders while aggregate, non-identifying statistics remain for reporting.
- Erasure on request. An explicit erasure request can be executed immediately from the product. A standard delete first moves the record to a recycle bin that is hidden from all views, with a 24-hour grace window before the irreversible anonymization runs; immediate erasure bypasses the grace window.
- Short-lived media. Raw interview audio is deleted within 30 days; transcripts and structured notes follow the regular candidate retention lifecycle.
- Market and competitor signals. Time-sensitive labour-market data is scrubbed on fixed horizons (raw postings within 90 days, derived signals within 180 days).
- Conversation data. Assistant conversations are stored encrypted and purged on an automated schedule.
Data subject rights support
You answer to your candidates; the platform makes that workable in practice:
- Access and portability. Candidate records and documents can be exported in structured formats.
- Rectification. All candidate fields are editable by your team.
- Erasure. One-click erasure with the anonymization model described above.
- Objection and restriction. Objections can be recorded against a candidate and are surfaced to your team where the data is used.
- Consent records. Consent events, including talent-pool and representation consent, are stored with timestamps.
If a candidate contacts Recruitifly directly, we refer them to the responsible controller and assist with executing the request.
Security measures
- Encryption in transit (TLS) for all connections.
- Encryption at rest on all managed databases and storage.
- Application-layer AES-GCM encryption for sensitive payloads, including assistant conversations and generated documents, before they are stored.
- Strict tenant isolation: every record is scoped to a workspace and every query filters on that scope.
- Role-based access control with fine-grained capabilities, so your administrators decide who sees and changes what.
- Audit logging of security-relevant events.
- Authentication designed to fail closed: if session-revocation infrastructure is unavailable, access is denied rather than allowed.
Hosting and sub-processors
The platform runs on managed Microsoft Azure infrastructure in European Union regions, including databases, file storage, and transactional email. Our core sub-processors are:
- Microsoft Azure (Netherlands/EU regions): hosting, databases, storage, transactional email.
- LLM provider: processing of content for assistant and analysis features. Paid usage is not used to train the provider’s models, and an EU-based processing option is available under enterprise agreements.
- Payment provider: subscription billing for customers.
Integrations you choose to enable (job boards, calendars, messaging channels, HRIS systems) receive only the data needed for that integration and act under their own terms; you control whether they are connected. We notify customers of sub-processor changes in advance as set out in the DPA.
International transfers
Primary data storage is in the EU. Where a sub-processor processes data outside the EEA, transfers rely on adequacy decisions or Standard Contractual Clauses with supplementary measures such as encryption.
Automated processing and Article 22
Recruitifly produces rankings, summaries, and suggestions to support recruiters. The platform is deliberately designed so that no decision with legal or similarly significant effect on a candidate is taken solely by automated means:
- Assistant actions that change data are proposals that a human must explicitly confirm before execution.
- Match scores and comparisons are decision support, presented with their reasoning and caveats, and recruiters make the final call.
- Customers must not use the Service to make fully automated rejection decisions; this is part of the acceptable use terms.
Passive sourcing
Where customers use sourcing features based on professional, publicly available signals, candidates can read how this works on the sourcing and your data page and can exclude their identifiers from matching via a one-way hashed opt-out form. We do not sell personal data.
Breach notification
We notify affected customers without undue delay after becoming aware of a personal data breach affecting their workspace data, with the information controllers need to meet their own 72-hour notification duty to supervisory authorities, and we assist with the follow-up.
Your responsibilities as a customer
Recruitifly gives you the tooling, but as controller you remain responsible for: informing candidates about your processing (your own privacy notice), choosing lawful bases, setting a retention period appropriate to your jurisdiction, honoring data subject requests, and configuring access roles within your team.
Questions
For the DPA, our current sub-processor list, security documentation, or anything else on this page: hello@recruitifly.com. Complaints can also be addressed to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
Other legal documents
Questions about this page?
We answer privacy and legal questions on business days, usually within one day.
Contact us