GDPR Compliance
Legal basis, data subject rights, and the automated deletion process behind our 24-month retention window.
For candidates and recruiters in the EU/EEA/UK, this page explains how Expertini ATS meets GDPR obligations specifically — legal basis for processing, data subject rights, and the mechanics behind the retention window mentioned in our Privacy Policy.
On this page
01Legal basis for processing
Candidate application data is processed under consent (given explicitly at the point of applying) and legitimate interest (a hiring organisation's interest in evaluating applicants for a role they applied to). Recruiter/employer account data is processed under contract — it's necessary to provide the ATS service itself.
02Data subject rights
Access, rectification, erasure, restriction of processing, data portability, and the right to object — all available on request. Where an automated scoring step (CMS) contributes to a hiring decision, you have the right to request human review of that decision rather than have it stand solely on an automated score.
03Automated deletion, not just a policy statement
The 24-month retention window is enforced by a scheduled cleanup process that runs against the live database, not a policy that only takes effect when someone remembers to act on it — expired candidate records and their CV files are identified and removed automatically.
04Analytics and the ePrivacy consent requirement
Site analytics (Google Analytics, described in the Cookie Policy) is not covered by the legal bases above. Under the ePrivacy Directive it needs its own opt-in consent from EU/EEA/UK visitors before the cookie is set, because it is a convenience to us rather than a necessity for you — and consent given can be withdrawn at any time without any effect on your use of the product. Analytics is measured on public pages and inside the signed-in recruiter interface; it is never given candidate records, CV contents, or interview notes.
05International transfers
Data is processed on Expertini's own infrastructure; where any sub-processor (e.g. Stripe, Google's Gemini API, or Google Analytics for site measurement) is located outside the EU/EEA/UK, standard contractual clauses or equivalent safeguards apply as required.
06Who to contact, and where to complain
For any GDPR request or complaint, contact dpo@mail.expertini.com. It reaches the people who actually decide how data is handled here, not a ticket queue. If we don't resolve it, you have the right to lodge a complaint with your local supervisory authority, and you can do that without going through us first.
To be precise about what that address is: it is a monitored routing inbox for data-protection matters, not the mailbox of a formally appointed officer. We do not currently designate a statutory Data Protection Officer — that role is required where an organisation's core activity is large-scale behavioural monitoring or large-scale processing of special-category data, and recruitment processing of the kind described on this page falls outside those tests. We would rather tell you exactly what the address is than imply an office nobody independently holds. If that assessment changes, this page changes with it.
Frequently asked questions
Can I request that a human, not just the CMS score, review my application?⌄
Is the 24-month deletion automatic or do I need to ask?⌄
At a glance
- 24-month deletion enforced by an automated process, not a manual policy
- Right to human review of an automated CMS-influenced decision
- Consent + legitimate interest as legal basis for candidate data
- Contract as legal basis for recruiter/employer account data
- Standard contractual clauses for any non-EU sub-processor
- Right to lodge a complaint with your local supervisory authority
See gdpr compliance on your own hiring.
Bring a real job description to a 30-minute demo — free trial included.
Book a demo