PlacementFlow is designed with GDPR compliance in mind. This guide covers how data retention works, how to handle candidate requests, and where to find privacy settings.
Candidate data is retained based on activity:
| Status | Retention |
|---|---|
| Active candidates | Kept while in your pipeline — never auto-deleted |
| Inactive candidates | Automatically scheduled for deletion after your configured retention period (default: 3 years — the platform maximum) |
| Placed candidates | Placement records are anonymised rather than deleted, preserving your financial records |
The default retention period is 3 years — the platform maximum, chosen so your talent pool keeps its value for as long as reasonably defensible under GDPR's storage-limitation principle. You can configure a shorter period in Settings → Compliance. Passive talent-pool candidates have their own extended 24-month inactivity window that applies even when your configured period is shorter.
PlacementFlow runs a daily retention job (3 AM UTC) that works in two phases:
Active candidates are never auto-deleted — only inactive records past the retention period.
If a candidate requests deletion of their data:
This permanently removes all their data immediately. The action is logged with your user ID and timestamp for compliance records.
Note: If the candidate has placements, their record is anonymised in place rather than deleted — placement and financial records must legally be retained, but all identifying data is scrubbed.
Candidates don't have to email you: every candidate-facing page links to a Request data deletion form, and the candidate portal includes it too. A submitted request notifies your agency admins — you then have 30 days to process it (using GDPR Delete above). Candidates can also view their AI decision history in the candidate portal and download it as a PDF report.
PlacementFlow can generate a Legitimate Interest Assessment (LIA) document for your outreach activities:
The generated document covers UK GDPR Article 6(1)(f) and PECR requirements. Have your solicitor review it before relying on it — it's a draft, not legal advice.
PlacementFlow operates under Legitimate Interest for:
This is documented in the LIA generator and on your Data & Privacy settings page.
| Setting | Location |
|---|---|
| Data & Privacy info | Settings → Data & Privacy |
| LIA document generator | Settings → Compliance |
| GDPR delete button | Candidate record → Actions menu |
Under GDPR, candidates can request:
Respond to requests within 30 days to remain compliant.
You're responsible for responding to individual requests and ensuring your outreach practices align with your LIA.
Review your Data & Privacy settings to ensure they reflect your actual practices. Generate an LIA document and have it reviewed. The automatic retention job handles cleanup — you focus on active candidates.