Skip to content

Procedure guide

How is KVKK applied in recruitment?

The first thing an audit asks for is not the policy document but the record itself: when was this candidate informed, when did they consent, who saw their data, when was the record deleted. This guide shows where those four answers land in the panel. It does not explain what the law says, it explains which setting produces which outcome.

pii:view

Seeing personal data unmasked is a separate permission that is switched on and off on its own

4 stock roles

Of the four roles that come with setup, only CompanyAdmin sees data unmasked

30 days

How long a file deleted in storage waits before it is deleted for good

12 minute readUpdated: 2 August 2026

Quick answer

KVKK in recruitment means informing candidates while their data is collected, taking explicit consent, limiting access with permissions, recording what was done and deleting the data once the purpose is gone. The data controller is the company that opens the posting, the software vendor is a data processor. There are five jobs in the panel: putting the texts in place, limiting the fields you collect, setting up the roles, keeping the records, running the deletion schedule.

Who holds the responsibility, and what the software solves

For candidate data the data controller is the company that opens the posting. The software vendor is a data processor, meaning it stores and processes the data on the company instructions. This distinction is not cosmetic: whose name the privacy notice is issued under, who answers a candidate request and who accounts for it in an audit all follow from it. That is also why the text shown to the candidate is issued under your company name, not the name of the product.

The problem the software solves is this: most of what KVKK asks for is a record, not a document. The moment consent was taken, who saw the data, which field changed to what, when the record was deleted. Kept by hand in a spreadsheet, those fall apart in the first audit, because nobody writes down every single view.

The five steps below are jobs to be done in the panel. Two of them are done once at setup, three run continuously. The sections after that cover the records an audit will ask for, the places the data travels to and how candidate requests are met, one at a time.

  • Once at setup: the privacy notice and consent texts, the role and permission matrix.
  • Continuously: the limit on what you collect, checking the records, the deletion schedule.
  • There is one thing the software never does on its own: deleting data whose period has expired.
Two colleagues sitting on the same side of a desk, leaning together over a single printout.
Responsibility is not handed over to the software: the company that opens the posting accounts for the candidate data.

Step 1

Put the privacy notice and the explicit consent text in place

The candidate sees two separate checkboxes. The text is issued under your company name, and your own text replaces the default one word for word.

Two separate checkboxes sit at the bottom of the application form: one confirms that the candidate has read and approved the KVKK privacy notice, the other that they have read and approved the explicit consent text on the processing of their personal data. The form is not submitted until both are ticked. Keeping them apart is a deliberate decision: the notice informs, while explicit consent is a separate declaration of will. Merged into a single box, what the candidate agreed to becomes unclear.

The full texts open from the link in the form and are assembled on the server. The data controller named inside them is always the company that opened the posting. Both approvals are written to the application record with a timestamp, so the answer to "when did this candidate consent" is the record itself, not an estimate produced after the fact.

If you have a text approved by your own lawyer, it replaces the default one word for word. There is no screen in the panel where you write it: the text is read from the company settings record, and none of the sections on the company settings screen show that field. Changing the text is work done on the setup side, so do not attempt it yourself, ask for it.

Two separate paper strips with a gap left between them on an off white background, the right one cobalt blue.
The privacy notice and explicit consent are two separate boxes; merged into one, what the candidate agreed to is lost.

Step 2

Limit what the form collects

You never have to protect or delete data you did not ask for. Neither a national ID number nor an IBAN is requested at the application stage.

Purpose limitation is applied most cheaply on the application form. The stock form takes personal details, education, the CV file, the salary expectation and the start date. For a pre evaluation that is enough; if you add nothing, the form keeps working exactly as it is.

There is no national ID number and no IBAN anywhere on the application form. Those two fields are asked for only in the information step that follows the hiring decision, and they are written to the database encrypted with AES-256-GCM. The order is no accident: a form that asks for an ID number at application time has to store the ID numbers of rejected candidates too.

To add a question specific to one posting you use the Custom Application Fields section, at most 20 fields per posting. Every field you add is an item of personal data and falls under the storage, masking and deletion obligations. Before you add a question, do not ask whether it is useful, ask whether it is necessary to make this decision.

  • A candidate CV is accepted only as a PDF, with a 5 MB file limit.
  • Custom field answers appear in the application detail and in the context of the evaluation, which means they fall under masking as well.
  • Candidates open no account to upload documents: a unique, time limited link is produced for each request, and the candidate can reach neither the panel nor the data of another record.

Step 3

Decide who sees the data unmasked

Seeing data unmasked is the pii:view permission, and out of the four stock roles only CompanyAdmin carries it. The closed default is deliberate.

Seeing personal data unmasked is a permission of its own: pii:view. Every user without it gets the candidate name, email and phone masked. The permission belongs to the role, not to the user; you cannot say "let this person see just this candidate unmasked". If you want an evaluation done with identities kept hidden, you open a separate role for that person.

Setup brings four roles: CompanyAdmin (every permission), HRManager, Recruiter and Viewer. The last three carry no pii:view. So if you do nothing after setup, your HR manager sees candidate names masked. This is not a fault but a closed default, and if it goes unnoticed it gets read as a broken panel. You have to open the permission deliberately from the role screen.

Do not look for the permission under a KVKK or Privacy heading. Permissions are grouped module by module, and because this module has no display name defined, the group is listed with the raw code, that is as "pii". The single permission inside that group is named PII Görüntüle, described as unmasked viewing of personal data covered by KVKK.

Four paper folders lined up at equal spacing; the second from the left is cobalt blue and slightly open, the other three are closed.
Of the four roles that come out of setup only one sees personal data unmasked; the rest you open yourself.

Step 4

Verify that the mask really works

Masking happens on the server. A masked user cannot open the CV file, cannot see the quotes, cannot read the values in the audit trail.

Masking is not a blur on the screen but a cut made on the server. The list, the detail, candidate comparison, the pool summary, natural language search and the export endpoints all return the data masked. The blur on screen is a presentation layer on top of that, not the only defence. The difference matters: a user who opens the developer tools sees masked data too.

File access goes through the same gate. A masked user cannot open the CV or the transcript; the interface shows that the file is hidden instead of the file itself, and the server cuts access off on the grounds of the personal data restriction. Links issued for candidate files are signed and time limited: one hour by default, five minutes for the short path. An expired link works for nobody.

In AI evaluation the quotes taken verbatim from the CV count as personal data as well and drop for a masked user: semantic evidence, free text reasoning and item quotes come back empty, while the call and the score of the item remain. The audit trail is not lost, its content is hidden: which field changed, who changed it and when it changed stay visible, the old and the new value are hidden.

Step 5

Run the retention and destruction schedule

Data past its retention period is not deleted on its own. You set the period, you build the schedule, and you carry out the deletion from Settings > Trash.

The most important limit in this guide sits here: the system does not delete candidate data on its own because a period expired, it does not anonymise it and it does not remind you. You set the retention period, you build the schedule into your own processes, you carry out the deletion from the panel by hand. A policy that is not tied to a calendar reminder stays on paper.

Deletion happens in two stages. An application deleted from the panel first drops into the trash; the record shows who deleted it and when, and it can be restored from there. Permanent deletion from the trash cannot be undone and takes the files with it: the CV and portfolio files, the document request files, the AI profile and the record itself go together.

On the storage side a deleted file does not disappear outright either: it is moved to the trash together with its reason and permanently deleted 30 days later. For files with no counterpart left in the database there is an orphaned files scan under Settings > Storage; the scan moves whatever it finds into the same trash.

Three stops from left to right on an off white background: a single paper card, a shallow tray holding a cobalt blue card, and an empty slot.
Deleting is not one move; the record travels a chain that runs from the trash all the way to permanent deletion.

The records an audit asks for and where they sit

What a data controller is asked is usually not "do you have a policy" but "what did you do about this person". The table below shows which record in the panel answers those questions, and what a masked user can see in that same record.

The last row is deliberate: the consent timestamp is written to the database, but no screen or export column in the panel shows it. The record is there, it just cannot be read from a screen. If an audit is going to ask for it, the setup side has to extract it; arrange that beforehand, not when the request arrives.

The question, the record and what a masked user sees
QuestionWhere it sitsWhat a masked user sees
Who created, changed or exported this recordSettings > Activity Log, filtered by module and date rangeThe screen asks for the activity_log:view permission
Which field changed and to whatThe Changes tab in candidate detail: field, old value, new value, who, whenThe row and the person stay, the old and the new value are hidden
Why did this candidate get this scoreThe audit trail of the evaluation: version, model, the basis of the hard criterion gate, re-evaluation and manual override eventsQuotes come back empty, the call and the score of the item stay
Was the data really deletedSettings > Trash and Settings > StorageThe screens ask for the trash:view and storage:view permissions
When did the candidate consentThe two separate approval timestamps on the application recordNo screen in the panel shows it

Where candidate data goes

The most skipped part of a privacy notice is the list of sub processors. The answer is short: candidate CV files are stored with a cloud storage provider based abroad and sent to an AI provider based abroad for analysis. Beyond that, candidate data is not transferred to any third party.

The reason it is not transferred is an absence rather than a promise: the product has no LinkedIn, Indeed, HR information system or Slack integration. Because there is no channel to carry the data out, "we send it to nobody" is a sentence that can be verified. The day an integration is added, this section changes with it.

There are two more boundaries on the inside. The company boundary is enforced on the server, not in the interface: every read and write asks for the company identity as a parameter, and the service never guesses it. Candidates open no account to upload documents; a unique, time limited link is produced for each request and that link opens only the items of its own request.

  • File links are signed and time limited: one hour by default, five minutes for the short path.
  • For candidate data you are the data controller; the platform own privacy notice states that split of roles in writing.
  • Evaluation does not learn from the past: who was invited or hired never enters the scoring, the data of one candidate never affects the score of another.
An employee handing a closed folder to a single colleague across the desk.
The data stops at two outside points and stays there; no third channel was built to carry it further.

How candidate rights are met in the panel

Once a candidate has applied, four kinds of request can reach you: asking what data you hold, asking for a correction, asking for deletion, and objecting to automated evaluation. All four have a counterpart in the panel, but three of them are run by hand.

If they ask what data you hold

You prepare the answer from the Settings > Export screen. Columns are picked one by one in groups: personal, contact, education, work, documents, links. You decide which personal data ends up in the file, there is no ready made "everything" button.

There is no page where a candidate views their own record. A person answers the request. Because there is no automated endpoint it is slow, and in exchange you control what the answer contains.

If they say their information is wrong

The correction is made by HR editing the record by hand. Every correction lands in the audit log field by field: which field, its old value, its new value, who and when. That the request was met can be proved afterwards.

There is an information update flow in the panel as well, but that one is for employees, not for candidates. Do not route a correction request from a candidate there.

If they ask to be deleted

You delete the record from the panel and it drops into the trash. To meet the request for good, permanent deletion from the trash is needed. Permanent deletion also takes the CV and portfolio files, the document request files and the AI profile.

Before deleting, check two things: is the posting the record belongs to still open, and do you have another legal ground that requires you to keep that data. Permanent deletion cannot be undone, a wrong call cannot be repaired.

If they object to the automated evaluation

The right to object is used against being analysed solely by automated systems with an adverse outcome. The answer in the product is clear: AI never changes the status of an application by itself. Every status change passes through a single service, asks for a user identity and is recorded field by field. The system produces the suggestion, HR makes the decision.

You also hold the reasoning you need to answer the objection. The model does not give a score; item by item it answers whether the CV evidences it and leaves a verbatim quote, and the arithmetic is done in code. Because every score record keeps the version, the model and the reason behind the gate, the item a candidate fell short on can be shown retrospectively.

Frequently asked questions

The data controller is the company that opens the posting, and the software vendor works as a data processor. What that means in practice: the privacy notice shown to the candidate is issued under your company name, you answer candidate requests, you decide the retention period. The platform's own privacy notice states this split of roles in writing.

Seeing personal data unmasked is a separate permission called pii:view, and out of the four roles that ship with setup only CompanyAdmin carries it. HRManager, Recruiter and Viewer do not. This is not a fault, it is a closed default: you have to grant the permission deliberately from the role screen. Because this module has no display name defined, it is listed under a group headed with the raw code "pii", where the single permission is named PII Görüntüle.

No. Data that is past its retention period is not deleted on its own, it is not anonymised and no reminder appears. You set the retention period, you build the schedule into your own processes, and you carry out the deletion by hand from Settings > Trash. Writing a policy without tying it to a calendar reminder produces a policy nobody applies.

No. The application form asks for neither a national ID number nor an IBAN. Those two fields are collected only in the information step that follows the hiring decision, and they are written to the database encrypted with AES-256-GCM. The order is deliberate: a form that asks for an ID number at application time ends up storing the ID numbers of rejected candidates as well.

Candidate CV files are stored with a cloud storage provider based abroad and sent to an AI provider based abroad for analysis. Beyond that, candidate data is not transferred to any third party. The reason is structural rather than a promise: the product has no LinkedIn, Indeed, HR information system or Slack integration, so there is no channel that could carry the data out.

Delete the record from the panel; it drops into the trash, where who deleted it and when is written on the record. To meet the request for good, you also have to run the permanent deletion from the trash. Permanent deletion removes the CV and portfolio files, the document request files, the AI profile and the record itself together, and it cannot be undone. For files left behind in storage there is an orphaned files scan, and a file moved from there into the trash is permanently deleted after 30 days.

Setup is done, running it comes next

The texts and the roles are set up once; the real work is running the deletion schedule and checking the records from time to time. Why the evaluation stays explainable is covered in the AI guide below.

Contact Us