How candidate data is handled in Vouch (template to share with your clients)

Last updated: October 6, 2026

This is a template you can copy and send to your own clients. Replace the text in [brackets] with your details, and remove the paragraphs marked "include if" when they do not apply to your workspace.

Summary

[Agency name] uses Vouch as its recruitment platform. [Agency name] is the data controller for the candidate records in its Vouch workspace, and Vouch is the data processor under a Data Processing Agreement.

This note explains what is stored, how long it is kept, how candidates exercise their rights, and how AI is used. The linked documents at the end are the formal versions.

What candidate data is stored

A candidate record holds what the candidate or recruiter has provided for the recruitment process:

  • Name and contact details

  • CV and other uploaded files

  • Application answers and referrals

  • Recruiter notes, evaluations and interview feedback

  • Messages sent to and received from the candidate

Each record carries its source (for example application, referral, manually added, imported) and a documented legal basis: pre-contractual assessment for applicants, consent, or legitimate interest.

Candidates are shown a privacy notice when they apply. It is published at a public link and states who is responsible for their data, the legal basis, the retention periods and their rights: [link to your privacy notice].

How long data is kept

Retention periods are set per source and enforced by the platform every day. Our current periods:

How the candidate entered the system

Kept for

Applied to a job or via the career page

[24] months

Referred by someone

[24] months

Added manually by a recruiter

[12] months

Imported in bulk

[12] months

Sourced from external providers

[18] months

Migrated from a previous system

[6] months

The period counts from the last real contact with the candidate (a message in either direction). Editing a profile does not extend it.

When the period ends, the record is archived and hidden from recruiters, then permanently deleted after 30 days. Keeping a candidate longer requires a recruiter to record a reason, or the candidate to confirm they want to stay in the talent pool.

Candidate rights

Candidates can submit a request at any time through a public data rights page: [link to your data rights page]. It covers access, rectification, erasure, objection, restriction and portability.

  • The candidate receives an email confirmation with a reference and can check the status of the request with it.

  • The request lands in a queue that our administrators are notified about. We respond within 30 days.

  • Erasure removes the candidate record with its files, evaluations, communications and AI-generated data. Once the request is closed, the candidate gets an email with the outcome.

  • After an erasure or objection, the platform blocks that candidate from being added again by manual entry or import. Only a one-way hash of the email address is kept for this purpose.

Requests that reach us by email or phone are logged in the same queue, so every request has the same record.

Use of AI

AI assists recruiters by summarising and reviewing applications against the job requirements. A recruiter always makes the decision. No candidate is rejected or advanced by AI alone.

[Include if you have enabled the opt-out:] Candidates can decline AI review when they apply, and can change that choice later. When a candidate declines, their application is reviewed manually, no AI processing runs on it, and any AI data already generated for it is deleted.

Candidate-facing explanation: How AI reviews your application.

Access control and audit trail

  • Role-based access. Users are owners, administrators, or have access to specific jobs only. Per job, a user is an editor, an observer (view and comment) or an interviewer (limited to the candidates they evaluate).

  • Client access. If you are given access to the portal, you see only the jobs and candidates shared with you.

  • Two-factor authentication. [Include if enabled:] Two-factor authentication is required for all users in our workspace.

  • Audit log. Every retention, consent and data rights action is logged with who did it and when, and the log can be exported.

Documents and contact

Questions about data protection: [name, email].