How candidate data is handled in Vouch (template to share with your clients)
Last updated: October 6, 2026
This is a template you can copy and send to your own clients. Replace the text in [brackets] with your details, and remove the paragraphs marked "include if" when they do not apply to your workspace.
Summary
[Agency name] uses Vouch as its recruitment platform. [Agency name] is the data controller for the candidate records in its Vouch workspace, and Vouch is the data processor under a Data Processing Agreement.
This note explains what is stored, how long it is kept, how candidates exercise their rights, and how AI is used. The linked documents at the end are the formal versions.
What candidate data is stored
A candidate record holds what the candidate or recruiter has provided for the recruitment process:
Name and contact details
CV and other uploaded files
Application answers and referrals
Recruiter notes, evaluations and interview feedback
Messages sent to and received from the candidate
Each record carries its source (for example application, referral, manually added, imported) and a documented legal basis: pre-contractual assessment for applicants, consent, or legitimate interest.
Candidates are shown a privacy notice when they apply. It is published at a public link and states who is responsible for their data, the legal basis, the retention periods and their rights: [link to your privacy notice].
How long data is kept
Retention periods are set per source and enforced by the platform every day. Our current periods:
How the candidate entered the system | Kept for |
|---|---|
Applied to a job or via the career page | [24] months |
Referred by someone | [24] months |
Added manually by a recruiter | [12] months |
Imported in bulk | [12] months |
Sourced from external providers | [18] months |
Migrated from a previous system | [6] months |
The period counts from the last real contact with the candidate (a message in either direction). Editing a profile does not extend it.
When the period ends, the record is archived and hidden from recruiters, then permanently deleted after 30 days. Keeping a candidate longer requires a recruiter to record a reason, or the candidate to confirm they want to stay in the talent pool.
Candidate rights
Candidates can submit a request at any time through a public data rights page: [link to your data rights page]. It covers access, rectification, erasure, objection, restriction and portability.
The candidate receives an email confirmation with a reference and can check the status of the request with it.
The request lands in a queue that our administrators are notified about. We respond within 30 days.
Erasure removes the candidate record with its files, evaluations, communications and AI-generated data. Once the request is closed, the candidate gets an email with the outcome.
After an erasure or objection, the platform blocks that candidate from being added again by manual entry or import. Only a one-way hash of the email address is kept for this purpose.
Requests that reach us by email or phone are logged in the same queue, so every request has the same record.
Use of AI
AI assists recruiters by summarising and reviewing applications against the job requirements. A recruiter always makes the decision. No candidate is rejected or advanced by AI alone.
[Include if you have enabled the opt-out:] Candidates can decline AI review when they apply, and can change that choice later. When a candidate declines, their application is reviewed manually, no AI processing runs on it, and any AI data already generated for it is deleted.
Candidate-facing explanation: How AI reviews your application.
Access control and audit trail
Role-based access. Users are owners, administrators, or have access to specific jobs only. Per job, a user is an editor, an observer (view and comment) or an interviewer (limited to the candidates they evaluate).
Client access. If you are given access to the portal, you see only the jobs and candidates shared with you.
Two-factor authentication. [Include if enabled:] Two-factor authentication is required for all users in our workspace.
Audit log. Every retention, consent and data rights action is logged with who did it and when, and the log can be exported.
Documents and contact
Our privacy notice for candidates: [link to your privacy notice]
Our data rights page: [link to your data rights page]
Questions about data protection: [name, email].