Retention settings
Set retention periods before you start collecting candidate data. Once a retention period expires, the scheduler’sretention-enforcement job marks the
affected records for deletion.
1
Open retention settings
Go to Settings → Legal → Retention.
2
Set periods for each purpose
Configure a retention period for each data category:
These are starting points. Your legal or HR team must confirm the correct
periods for your jurisdiction and sector.
3
Test with a sample record
After setting periods, find an old test candidate, manually set their record
to expired, and confirm the retention job removes it in the next scheduler
cycle (runs every minute).
Data-subject requests (DSARs)
Candidates have the right to request a copy of their data or request deletion. The candidate portal surfaces both controls to candidates directly. When a request comes in:1
Verify identity
Confirm the requester is the data subject. Do not process a deletion request
without identity verification: deleting the wrong record has no undo.
2
Check for legal holds
Check whether any legal hold, ongoing litigation, or regulatory obligation
prevents immediate deletion. If so, document the hold and communicate the
delay to the requester with a reason.
3
Export or delete
Export: From the candidate record, use Export data. Send the export
to the requester through a secure channel, not unencrypted email.Delete: From the candidate record, use Delete candidate. This
removes the record, applications, files, and personal data. It cannot be
undone. Confirm the candidate has no active legal hold before proceeding.
4
Record the outcome
Log the request, the action taken, the date, and the member who processed
it in your DSAR register. Harly’s audit log captures the deletion event, but
maintain your own register for regulatory response.
Consent records
Harly tracks consent with timestamps and withdrawal events. Consent records are available in Settings → Legal and through the API (activity:read scope).
Do not rely solely on Harly’s consent records. Maintain your own canonical
register if your regulatory context requires one.
AI features and data
Automatic candidate evaluation without AI
Workspaces without an AI provider can use the governedrules-v2 evaluator.
It only evaluates criteria explicitly configured in a published job rubric; it
does not infer requirements from arbitrary job-description text. Each criterion
stores its status (met, not_met, or unknown), evidence source, evidence
coverage, confidence, rubric version, and reproducibility hashes.
An unknown result is not a rejection. Low coverage, low confidence, or a
missing required criterion marks the evaluation for human review. Automated
workflow conditions cannot reject an applicant from this result.
When a candidate is deleted or anonymized, evaluations, criterion evidence,
embeddings, and queued evaluation jobs are removed with the candidate. Configure
retention and legal holds before enabling automatic processing.
When AI features are enabled, candidate data is sent to your configured
provider. Before enabling:
1
Choose a provider with a DPA
Confirm your AI provider has a data processing agreement that covers your
jurisdiction and sector. Store a copy.
2
Document each feature
For each enabled AI feature, document: purpose, provider, model, what data
is sent, who reviews the output, and what the human override path is.
3
Notify candidates
If your jurisdiction or sector requires it, disclose AI use in your candidate
privacy notice before collecting applications.
4
Review the usage log
Open Settings → AI → Usage periodically to confirm only expected data
is being sent and no unexpected features are active.
AI output is advisory. Every hiring decision must have a documented human
reviewer. Never auto-advance, auto-reject, or send a message based on an AI
suggestion without human review.