GDPR in Vouch: where to find and adjust everything

Last updated: October 6, 2026

Quick map

Almost everything sits under Talent pool → Data retention. Paths below come after /profile/business/{your workspace id}/ in the portal address.

Topic

Where in the portal

Path

Retention periods, expiry behaviour, LIA

Talent pool → Data retention → Settings

candidates/retention?section=settings

Candidates near or past their period

Talent pool → Data retention → Review

candidates/retention?section=review

Data rights requests from candidates

Talent pool → Data retention → Requests

candidates/retention?section=requests

Compliance audit log

Data retention → Settings → View compliance audit log

candidates/retention?section=settings

AI review opt-out

Settings → Rejection categories & AI review

settings/advanced-settings

Users and roles

Settings → Members & access

settings/access

Two-factor requirement

Settings → Members & access → Security

settings/access/security

Re-opt-in email template

Settings → Communications → System messages

settings/communications

Notifications about requests and expiry

Your settings → Notifications

settings/notifications

Legal documents

Settings, Legal links in the footer

settings/terms

Two public pages are generated for your workspace, and these are the links to give clients and candidates:

  • Privacy notice: /p/{your workspace id}/privacy

  • Data rights page: /p/{your workspace id}/data-rights

The exact links are shown in Data retention → Settings, under Public candidate pages.

Retention settings

You set one retention period per candidate source, in months (1 to 120). Owners and admins can save changes.

Setting

Default

Covers

Applicants / Career-page

24 months

Applications and career page sign-ups

Vouches / Referrals

24 months

Referred candidates

Manually added / Chrome extension / Sourcing inbox

12 months

Candidates a recruiter added

Bulk-imported

12 months

CSV imports

Sourced from external providers

18 months

Lookout sourcing

Migrated from another system / ATS

6 months

Imported records with no documented legal basis

Retention behavior

  • Retention countdown starts from: Date of last engagement (default) or Date added to pool. Engagement means a message in either direction or a manual engagement mark. Profile edits do not count.

  • When retention expires: Notify admins only, or Archive (recoverable for 30 days), which is the default. Archived candidates are permanently deleted after the 30 days. Delete immediately is shown but not available.

  • Recruiters can extend retention on individual candidates with a documented reason: on by default. Turn it off to limit extensions, archiving and restoring to owners and admins.

Legitimate Interests Assessment (LIA)

Setting any period above its default requires an uploaded LIA (PDF or Word). The save button stays disabled until one is on file. A template is linked from the same section (View template). Shortening a period never needs one.

Saving

If candidates are already past the new periods, you get a confirmation with the count before saving. The change applies straight away and is written to the audit log.

Client workspaces

Retention policy is set once, on your main workspace. Client workspaces under it inherit the periods and show a read-only note. Review queues and requests stay separate per workspace.

Being in an active process does not pause the period. Those candidates are marked In process in the review list, so extend them if needed.

Reviewing candidates near their limit

Data retention → Review lists the candidates who need a decision, in four buckets.

Bucket

What is in it

Expiring soon

Retention period ends within 30 days

Past window

Already past. The expiry action applies on the next daily run

Needs justification

Imported without a documented legal basis

Archived

Hidden from the pool, deleted permanently after 30 days unless restored

Select one or more candidates to get the actions:

  • Justify holding. Record the legal basis (applied for a role, consent, or legitimate interest) with a reason.

  • Set engagement date. Record a contact that happened outside Vouch, which restarts the countdown.

  • Extend retention. Pick a keep-until date (up to 5 years ahead) and give a reason.

  • Ask to stay in pool. Sends the re-opt-in email described below.

  • Archive. Hides the candidate now and deletes after 30 days.

  • Restore (Archived bucket). Requires a new keep-until date and a reason.

  • Delete now (Archived bucket, owners and admins). Permanent, with a minimal deletion record kept in the audit log.

The re-opt-in email

The candidate gets an email with two buttons. Yes keeps them in the pool, records consent as the legal basis and restarts the period. No deletes their record and applications and blocks them from being added again. No reply changes nothing. The same candidate is not emailed more than once in 30 days.

You edit the text under Settings → Communications → System messages → Talent pool re-opt-in email.

On a single candidate

Every candidate profile has a Data retention section showing source, legal basis, last engaged and retained until. Click a row to change it. The history icon shows that candidate's compliance trail.

Data rights requests

The public page

Candidates submit requests at /p/{your workspace id}/data-rights: erasure, access, rectification, objection, restriction or portability. They get a confirmation email with a reference and can check status on the same page. The page promises a response within 30 days.

You can switch the page on or off, set the data protection contact email and add your own notice text in Data retention → Settings → Public candidate pages.

To put the link in a message to a candidate, insert the variable Data-rights page link in any message composer or template.

Handling a request

Requests appear under Data retention → Requests, and owners and admins get a notification. Each request shows whether it matched a candidate in your pool. Click Review to act on it (owners and admins):

  1. Mark in progress while you work on it.

  2. For erasure and objection, use the Delete box. The default archives the candidate (recoverable for 30 days). Tick the box to delete permanently right away.

  3. Write a resolution note and choose Mark resolved or Reject with reason. The note is emailed to the candidate.

Access, portability, rectification and restriction requests are fulfilled by you outside the queue, then closed with a note. For access requests, Download profile on an application gives a PDF of the candidate's data for that job.

If a request shows no matching record, verify the person's identity and search the pool before responding.

Requests received by email or phone

Open the candidate's profile in the talent pool, then the … menu → Log data-rights request. It goes into the same queue, and you can choose to email the candidate a confirmation.

Deleting a candidate yourself

Delete in the profile … menu removes the candidate, their applications, files and AI data immediately. This route has no 30-day recovery and does not block the candidate from being re-added. When the candidate has asked for erasure, log it as a request instead, so it is recorded and they stay blocked from re-import.

AI review opt-out

The opt-out is off by default. An owner or admin turns it on under Settings → Rejection categories & AI review → AI review opt-out: Offer candidates the option to decline AI review.

When it is on:

  • The application form shows a short line about AI review with a Decline AI review option. Candidates can change their choice later from their application page.

  • A candidate who declines is reviewed manually. No AI summary, evaluation or search indexing runs on that application, and AI data already created for it is deleted.

  • Recruiters see a Manual review banner on the evaluation tab and an AI-off icon on the candidate card.

The opt-out applies to the application. If you later enable candidate assistance for that person's talent pool profile, Vouch warns you first, and it only ever uses profile-level data, never the opted-out application.

Privacy notice and what candidates see

Vouch generates a privacy notice for your workspace at /p/{your workspace id}/privacy. It is built from your settings, so the retention periods in it always match what you have configured. It covers who is responsible, what is processed and on what legal basis, how long data is kept, and the candidate's rights.

You control three things, all in Data retention → Settings → Public candidate pages:

  • Whether the notice is published

  • The data protection contact email. Fill this in. If it is empty, the privacy notice shows no contact line

  • An optional addendum with your own text

For listings in client workspaces, candidates are sent to your (the agency's) notice.

On the application form, candidates see a notice under the submit button with links to the terms and to this privacy notice. There is no separate consent checkbox. The talent pool table has a consent column showing where pool consent is recorded.

Access and security

Users and roles are managed under Settings → Members & access.

Role

Scope

Can do

Owner

Whole workspace

Everything

Admin

Whole workspace

Manage job posts and users

Job level

Specific jobs only

Depends on the job role below

Editor

One job

Edit and manage candidates and settings

Observer

One job

View and comment

Interviewer

One job

Evaluate specific candidates

Per-job access is set on the job itself under Manage → Access (listings/{job id}/manage/access). Observers and interviewers can be limited to certain stages or to named candidates. This is the right way to give a client access to their own process.

Two-factor authentication. Settings → Members & access → Security → Require TOTP for all workspace members. Off by default, and only owners and admins see the tab. When it is on, share links to jobs are disabled, so invite people by email instead.

Audit log

Data retention → Settings → View compliance audit log opens a log of every retention, consent and data rights action: who did it, which candidate, and when. Settings changes and LIA uploads are in it too.

  • Export CSV (owners and admins) downloads the newest 10,000 events. This is what to hand over if a client or auditor asks for evidence.

  • The button is on your main workspace. Client workspaces that inherit the policy do not show it.

  • For one candidate, use the history icon in the Data retention section of their profile.

Notifications about new requests, candidates near their limit and candidates scheduled for deletion go to owners and admins. Each person sets channels (in-app, email, Slack or Teams) under Your settings → Notifications.

Legal documents and your responsibilities

The same links are in the footer of the Settings page under Legal.

Vouch is the processor and gives you the tools. As controller, these remain yours:

  • Choosing retention periods and the legal basis you rely on, and writing the LIA if you go beyond the defaults

  • Informing candidates you source or add yourself. Vouch does not add a privacy notice to your outreach automatically (except a short footer on the first message to Lookout-sourced candidates), so include the data rights link in your templates

  • Answering access, rectification, restriction and portability requests

  • Your agreements with your own clients about who is controller once candidates are presented to them

Setup checklist

  • Review the six retention periods and the expiry action

  • Set the data protection contact email

  • Open your public privacy notice and data rights page and read them as a candidate would

  • Decide whether to offer the AI review opt-out

  • Decide whether to require two-factor authentication

  • Add the data rights link to your outreach templates