Data processing agreement
Version 1.0 · In force from 6 October 2026
This agreement sets out how Navigent processes candidate data on the customer's behalf. It forms part of Navigent's terms of service and is accepted when the organisation is created.
1. Parties and background
1.1 This agreement is made between the customer, as controller, and Navigent.io ApS, CVR 46285395, Nørre Voldgade 70, 4., 1358 København K, Denmark ("Navigent"), as processor.
1.2 This agreement forms part of Navigent's terms of service at navigent.io/en/terms. The organisation's owner accepts it on the customer's behalf when the organisation is created, and the acceptance is recorded with the version of the agreement.
1.3 The purpose of this agreement is to ensure that Navigent processes personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), in particular Article 28(3), and the Danish Data Protection Act.
1.4 The annexes form part of this agreement:
- Annex A: The processing
- Annex B: Security measures
- Annex C: Sub-processors
- Annex D: Retention and deletion
- Annex E: Remove me from Navigent and the suppression list
2. Definitions
2.1 Terms such as "personal data", "processing", "controller", "processor", "data subject", "pseudonymisation" and "personal data breach" have the meanings given in the GDPR. Other terms have the meanings given in the terms of service. In addition:
- Candidate data: the personal data Navigent processes on the customer's behalf, as described in Annex A.
- Sub-processor: another processor that Navigent engages to process candidate data.
- The removal page: the page "Remove me from Navigent" at navigent.io/en/remove-me, in Danish "Fjern mig fra Navigent" at navigent.io/fjern-mig, where anyone can ask to be removed from Navigent.
- The suppression list: Navigent's list of people removed following a request on the removal page, as described in Annex E.
3. Scope
3.1 This agreement covers Navigent's processing of candidate data on the customer's behalf, as described in Annex A.
3.2 This agreement does not cover the processing Navigent carries out as a controller in its own right: account data about the customer's users and about the customer as a customer, navigent.io, the removal requests and the suppression list. These are described in the privacy policy at navigent.io/en/privacy.
3.3 When Navigent deletes candidate data from the customer's workspaces following a confirmed request on the removal page, it does so as processor under the customer's standing instruction in clause 6.
4. The customer's obligations
4.1 The customer is responsible for the lawfulness of the processing of candidate data, including having a legal basis for finding, assessing, storing and contacting candidates, and for its instructions being lawful.
4.2 The customer informs data subjects about the processing under Articles 13 and 14. Navigent adds no data protection information to campaign messages and does not give the information on the customer's behalf. Navigent's privacy policy and the removal page describe the service to candidates but do not fulfil the customer's duty.
4.3 The customer carries out the legitimate interests assessments and impact assessments it is required to. Navigent provides a template for the legitimate interests assessment and its description of the processing, and assists under clause 12.
4.4 In the service, the customer decides among other things who is on its list of people and companies not to be contacted and, for each workspace under Settings → Workspaces, whether photos are fetched (the "Show photos" setting) and how long candidates marked as hired are kept. These choices form part of the customer's instructions.
4.5 The customer is responsible for candidate data exported from the service, including deleting exported copies and fulfilling data subjects' requests for them too.
4.6 As controller, the customer answers every request from candidates, using the tools described in clause 12. The only exception is removal from Navigent under Annex E.
5. Navigent's obligations
5.1 Navigent processes candidate data only on the customer's documented instructions, including with regard to transfers to third countries. The instructions consist of this agreement and its annexes, the terms of service, and the choices the customer and its users make in the service, such as roles, searches, decisions, campaigns and settings.
5.2 If EU or Danish law requires Navigent to process candidate data otherwise, Navigent informs the customer before the processing begins, unless the law prohibits it.
5.3 Navigent informs the customer immediately if, in its opinion, an instruction infringes data protection law.
5.4 Navigent does not use candidate data for its own purposes, does not use it to train AI models, and does not share it between customers. Candidate data is included in Navigent's evaluation set only under a separate written agreement with the customer, and only in pseudonymised form.
5.5 Navigent keeps a record of processing activities under Article 30(2).
6. Standing instructions
6.1 The customer gives Navigent the following standing instructions, which apply for as long as this agreement applies:
a) to delete and pseudonymise candidate data under the rules in Annex D;
b) to delete a person who has confirmed a request on the removal page from the customer's workspaces under Annex E;
c) to keep that person on the suppression list, so that they are not fetched or assessed in the customer's workspaces and messages to them are stopped;
d) to enforce the customer's list of people and companies not to be contacted when searching and when sending, and to add anyone who replies that they do not want to be contacted;
e) to give Navigent's support staff time-limited access to candidate data under clause 8.
6.2 The instructions in b) and c) cover only the deletion and the suppression. They apply in the same way to all of Navigent's customers and cannot be opted out of by an individual customer for as long as this agreement applies. A removal takes place without notice to the customer, and Navigent does not tell the person which customers held data about them.
7. Confidentiality
7.1 Navigent gives access to candidate data only to people who need it to provide the service and who are bound by confidentiality by agreement or by law. Access is removed when it is no longer needed.
8. Support access
8.1 Navigent's staff have no access to candidate data by default. Without a grant, support sees only a role's shape, counts and status; names, photos and profile data are hidden.
8.2 Access requires a reason, which the customer can see, and expires after 8 hours at the latest. It is read-only unless a superadmin approves write access, which is logged separately. Staff must use two-factor authentication.
8.3 The customer's owners can see every grant and every action under Settings → Security and receive an e-mail when access is granted. An owner can revoke an active grant at once.
8.4 Access does not require the customer's prior approval, so that support can help quickly, for example during an incident. By this agreement, the customer instructs Navigent to grant access on these terms.
8.5 Removals happen automatically under Annex E and not through support access. Staff see only the request, not candidate data.
9. Security
9.1 Navigent implements the technical and organisational measures required under Article 32, including those in Annex B, taking into account the nature of the processing and the risk to data subjects.
9.2 Navigent may change the measures, provided the level of security is not reduced.
10. Sub-processors
10.1 The customer gives Navigent general authorisation to engage sub-processors. When this agreement is made, the list in Annex C applies.
10.2 Navigent gives the customer 30 days' notice before a new sub-processor is engaged or replaces another, by e-mail to the organisation's owners and at navigent.io/en/sub-processors.
10.3 The customer may object on reasonable grounds within those 30 days. If the parties cannot find a solution, the customer may terminate the agreement with effect before the change takes effect and be refunded amounts paid in advance for the period after termination.
10.4 Navigent imposes the same data protection obligations as in this agreement on each sub-processor in a written agreement, and remains fully liable to the customer for the sub-processor's performance of them.
11. Transfers to third countries
11.1 The service's database and files are in the EU (Frankfurt).
11.2 Navigent transfers candidate data to countries outside the EU/EEA only where there is a valid transfer mechanism under Chapter V of the GDPR, such as an adequacy decision or the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914) with any supplementary measures needed. The location and transfer mechanism for each sub-processor are in Annex C.
12. Assistance
12.1 The service gives the customer these tools to answer data subjects' requests:
- Access and portability: everything held about a candidate in a workspace is on the candidate's card and in the organisation's full export under clause 15.2.
- Erasure: deleting a candidate removes the candidate, the photo and everything linked to the candidate, except the AI log, which is pseudonymised under Annex D.
- Objection: the candidate is added to the customer's list of people not to be contacted, which the retention rules never touch.
12.2 If the customer cannot answer a request with the tools, Navigent helps at the customer's request, as far as possible.
12.3 Requests for removal from Navigent are handled under Annex E. If a data subject contacts Navigent about anything else, Navigent refers them to the organisation that contacted them. Navigent does not answer on the customer's behalf and does not say which customers hold data about the person.
12.4 Navigent helps the customer comply with Articles 32 to 36 on security, personal data breaches, impact assessments and prior consultation, taking into account the nature of the processing and the information available to Navigent.
13. Personal data breaches
13.1 Navigent notifies the customer without undue delay after becoming aware of a personal data breach involving the customer's candidate data. The aim is that the customer is told within 48 hours, so that the customer can notify the Danish Data Protection Agency within 72 hours.
13.2 The notification contains, to the extent known: what has happened, the categories and approximate number of data subjects and records concerned, the likely consequences, what Navigent has done and proposes, and whom the customer can contact at Navigent. What is not yet known is provided as it becomes known.
13.3 Navigent contains the breach, preserves logs and records, and writes a timeline. Navigent does not notify the Danish Data Protection Agency or data subjects on the customer's behalf unless the customer asks it to.
13.4 If a breach concerns only removal requests or the suppression list, Navigent handles it itself as controller.
14. Audits and inspections
14.1 Navigent makes available the information needed to demonstrate compliance with Article 28 and this agreement, including a description of the security measures, the list of sub-processors, and answers to reasonable questions, such as a security questionnaire.
14.2 The customer may have an independent auditor bound by confidentiality carry out audits, including inspections, with at least 30 days' notice, during normal working hours and at most once a year, unless a breach or a supervisory authority gives reason for more. An audit must not give access to other customers' data or weaken security. The customer bears its own and the auditor's costs.
14.3 Navigent obtains relevant information from its sub-processors, such as audit reports, and passes it to the customer on request, to the extent it may be shared.
14.4 A supervisory authority's access under the law takes precedence over this clause.
15. Termination, return and deletion
15.1 This agreement applies for as long as Navigent processes candidate data for the customer.
15.2 The customer can take all its data at any time. An owner chooses "Export all data" under Settings → Security, at most once a day. Navigent builds a ZIP file with everything the organisation holds in Navigent: JSON for each table, the candidates' photos, and each role's shortlist as CSV. The owner receives a signed link by e-mail, and the file is deleted after 7 days. The export is available for as long as the organisation exists, including when it is read-only after a cancellation, and it is offered before the organisation is deleted. Longlists, shortlists and campaign results can also be exported one at a time as CSV. An export never looks up e-mail addresses and contains only those that have been unlocked; see Annex A.
15.3 Once the organisation is deleted, Navigent deletes the customer's candidate data within 30 days. Backups are deleted when they expire under the database provider's backup period, which is at most 30 days. Pseudonymised entries in the AI log are deleted when they are 6 months old.
15.4 Navigent may keep candidate data longer only where EU or Danish law requires it, and only for that purpose. The suppression list and the removal requests are Navigent's own and follow Annex E.
16. Liability
16.1 The parties' liability under this agreement follows the terms of service, including the limitation of liability, unless mandatory rules, including Article 82 of the GDPR, provide otherwise.
17. Precedence, changes, governing law and language
17.1 If this agreement and the terms of service conflict, this agreement prevails on matters of processing personal data.
17.2 Changes follow clause 18 of the terms of service. Changes to Annex C follow clause 10.
17.3 This agreement is governed by Danish law, and disputes are decided as set out in clause 22 of the terms of service.
17.4 This agreement exists in Danish and English. If the versions differ, the Danish version prevails.
Annex A: The processing
A.1 Purpose
Navigent processes candidate data to provide the service for the customer's recruitment: finding, ranking and assessing candidates for specific roles, showing them to the customer's users, who make the decisions, and contacting the candidates the customer has said yes to from the customer's own accounts.
A.2 Nature of the processing
| Activity | What happens | Sub-processors |
|---|---|---|
| Input | A job ad, a link, a file, a LinkedIn profile or a description is read, and requirements and filters are derived. Files are not stored, only the extracted text. A LinkedIn profile used as input is not stored | OpenAI, Prospeo |
| Fetching | About 1,000 unique candidates per search are fetched and normalised. Duplicates, people on the suppression list and people on the customer's list of people not to be contacted are removed before they are stored. Raw responses from Prospeo are never stored | Prospeo |
| Ranking and assessment | Filters with tolerances for function, seniority, location and years, scoring, and written assessments citing the career history. The model sees no names, photos, e-mail addresses or phone numbers, and protected characteristics are not used | OpenAI |
| Photos and "About" text | Fetched for candidates who have passed the filters, and photos only with "Show photos" on. The photo is copied to private storage and re-encoded | Bright Data |
| Full profile | Read from the open profile when a user clicks the Chrome extension | Supabase, Vercel |
| E-mail addresses | Looked up only when an e-mail step is due for a candidate in an active campaign, never in advance and never by hand. A found address is unlocked on the candidate and in the inbox and verified before the first e-mail. If no address is found, the candidate's e-mail step is skipped | Prospeo, MillionVerifier |
| Campaigns | Invitations, messages and e-mails are sent from the customer's connected accounts, and replies are received. Where a message asks AI for a line, it is written for each candidate from the assessment and the job ad. Only conversations with candidates in campaigns are stored; other messages the account receives are discarded unread | Unipile, OpenAI |
| Replies | Replies are labelled interested, not interested or auto-reply. The label only sorts the inbox | OpenAI |
| LinkedIn posts | A post about the role is written from the job ad, the role's requirements and the company, and is posted from a user's own LinkedIn account or a company page once the account's owner has approved the text. Reactions and comments are read and shown, but only their count is stored | OpenAI, Unipile |
| Collaboration | Decisions, notes with @mentions, role owners and an activity feed | |
| Export and statistics | CSV exports, streamed to the user and not stored, the organisation's full export, stored for 7 days, and statistics per role, campaign and team member from Navigent's own database | |
| Operations | Storage, background jobs, error reports without personal data, support under clause 8, e-mails to users, which may name a candidate, and the info@navigent.io mailbox, where the customer may send candidate data | Supabase, Vercel, Inngest, Sentry, Resend, Google (Google Workspace) |
| Deletion | Under Annex D and Annex E |
A.3 Categories of data subjects
- Candidates: people the customer finds through the service or adds with the Chrome extension.
- People on the customer's list of people not to be contacted.
- People named in job ads the customer pastes, such as a contact person.
- People who react to or comment on a post the customer has published through the service.
- The customer's users, to the extent they appear in the customer's data in the service, for example as the person who made a decision, wrote a note, sent a message or made an export, and in statistics per team member.
A.4 Categories of personal data
- Profile: name, headline, current title and employer, city, region and country, career history with titles, employers, periods, seniority and department, LinkedIn URL and Prospeo ID.
- Photo and "About" text.
- Full profile: education, skills, languages, certifications and descriptions of positions.
- E-mail address, and whether it has been verified.
- Derived data: career length, tenures, promotions, types of employer, functions and distance to the role's location.
- Assessments: scores, levels per requirement, reasons citing the career history, strengths and concerns.
- Decisions, reasons and notes.
- Messages, their status, replies and labels.
- Posts, their approvals, and the number of reactions and comments. The comments are shown but not stored.
- The list of people not to be contacted: name, LinkedIn URL and e-mail address.
- AI log: model, prompt version, which fields were used, assessments and reasoning.
- About users: user ID, name and actions in the service.
A.5 Special categories of data
The service is not intended for special categories of personal data under Article 9 or data about criminal offences under Article 10, and the ranking does not use them. Photos are not used to identify anyone biometrically and are never sent to an AI model. Free text, such as an "About" text or a note, may incidentally contain special categories of data, and the customer does not enter them without reason.
A.6 Duration
For as long as this agreement applies, and under the rules in Annex D.
A.7 Location
Database and files in the EU (Frankfurt). Sub-processors under Annex C.
Annex B: Security measures
Hosting and encryption
- Database, sign-in and files at Supabase in the EU (Frankfurt), and the application at Vercel, whose functions run in the EU (Frankfurt).
- Encrypted connections (TLS) for all traffic, with HSTS. The database accepts only encrypted connections.
- Data is encrypted at rest.
Separation of customers
- Row-level security on every table. It is tested automatically with every new version of the code, and a table cannot be created without it.
- Candidates are never shared between workspaces. The same person in two workspaces is two separate records.
- Keys with full access to the database are used only on the server, never in code a browser can reach.
Access control
- Sign-in with Google or a one-time link sent by e-mail. No passwords.
- Member roles: owner, admin and member, with access to all or selected workspaces.
- Invitation links and Chrome extension tokens are stored as hashes, expire and can be revoked.
- Staff: two-factor authentication, no access to candidate data without a justified, time-limited grant under clause 8, and an audit log that the customer's owners can see and that is kept for 2 years.
Data minimisation
- Only the fields the ranking needs are sent to AI: never names, photos, e-mail addresses or phone numbers. Protected characteristics are neither inferred nor used.
- Raw responses from Prospeo are not stored. Files are read in memory and not stored. A LinkedIn profile used as input is not stored.
- Messages that do not belong to a campaign are discarded unread.
- Logs, error reports and usage data contain only IDs, counts and durations, never names, photos, e-mail addresses or profile text, and they are scrubbed before they are sent.
- No open or click tracking in messages.
- CSV exports are not stored by Navigent. The organisation's full export is stored for 7 days in private storage and can be fetched only through a signed link e-mailed to the owner. Every export is recorded, visible to owners and admins, and rate limited.
Photos
- Fetched only with "Show photos" on, and only for candidates who have passed the filters.
- Copied to private storage per workspace and re-encoded, so that metadata and embedded content are removed. Shown only through signed links that expire quickly.
Safe fetching and input
- HTTPS only. Addresses on internal networks are refused, including after a redirect. Limits on size and time, and the content type is checked.
- Job ads, pages, files and profiles are treated as data, never as instructions. AI calls use structured output with no tools, the response is validated, and citations are checked in code.
- Files: PDF and Word only, at most 10 MB and 40 pages, checked on their content and read without network access.
- CSV exports are protected against formulas that could run in a spreadsheet.
Operations
- Rate limits per user, per organisation and, on the public forms, per IP address.
- Security headers, including a strict content security policy (CSP) and HSTS.
- Webhooks: the signature is verified, and each event is processed only once.
- Dependencies are updated automatically, a known serious vulnerability blocks a new version, and the code is scanned for secrets.
- Secrets are kept in a password vault and with the hosting provider, never in the code.
- Daily backups and, from when the first customer pays, point-in-time recovery as well. Restores are rehearsed twice a year, and a restore never overwrites production in place.
- Kill switches can stop searches, fetching, AI, photos, sending and new sign-ups within one minute, without losing data.
- If a breach is suspected, keys are rotated, logs are preserved, and customers are notified under clause 13.
- Automated monitoring with alerts, and a public status page at status.navigent.io.
Pseudonymisation
- The AI log uses a pseudonym, a hash computed with a secret key, and loses the link to the candidate when the candidate is deleted.
- The suppression list contains only hashes computed with a secret key.
The Chrome extension and connected accounts
- The extension has the fewest permissions possible. It has no standing access to LinkedIn, reads the active tab only when the user clicks and only LinkedIn profiles, talks only to Navigent's own server, and loads no remote code.
- The extension's token is stored as a hash, lasts 180 days, can be revoked, and gives access only to the extension's own functions.
- Accounts are connected through Unipile's sign-in. Navigent never sees passwords and stores neither sessions nor access tokens.
- Sending limits per account.
Annex C: Sub-processors
C.1 Navigent uses the sub-processors listed at navigent.io/en/sub-processors, with their purpose, the data, the location and the transfer mechanism. The list is also shown here from the same source, so that the two cannot differ.
| Provider | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Supabase | Database, sign-in and file storage for the service | All candidate and account data | EU (Frankfurt) | The European Commission's standard contractual clauses (2021/914) with Supabase Pte. Ltd., Singapore, in Supabase's data processing agreement |
| Vercel | Hosting of navigent.io and app.navigent.io | Requests and logs, including IP addresses | The service's functions run in the EU (Frankfurt). Vercel's primary facilities are in the United States | The EU-U.S. Data Privacy Framework |
| Inngest | Background jobs | IDs and counts in events, never personal data | United States (Amazon Web Services in Ohio and Inngest's own servers in Virginia) | Not applicable: Inngest receives no personal data |
| OpenAI | AI to read job ads, rank and assess candidates, write text for messages and posts, and label replies. For Navigent itself, also the requirements profile tool on navigent.io and the help in the app | Candidates' career data and assessments without names, photos, e-mail addresses or phone numbers, job ads, and the text of candidates' replies. For Navigent itself, the text pasted into the requirements profile tool and questions to the help in the app | OpenAI Ireland Ltd., Ireland | Outside the EEA: the European Commission's standard contractual clauses or an adequacy decision, under OpenAI's data processing agreement |
| Prospeo | Candidate search and e-mail address lookups | Search filters and the profiles and e-mail addresses Prospeo returns, as well as the LinkedIn URL of each removal from the "Remove me from Navigent" page, which is forwarded | United States (Amazon Web Services, us-east-1). Prospeo is Defastra Tech Inc., Canada | The European Commission's adequacy decision for Canada. Onward to Prospeo's providers in the United States: the EU-U.S. Data Privacy Framework where they are certified, otherwise the European Commission's standard contractual clauses |
| Bright Data | Profile photo and "About" text from LinkedIn, for candidates on a role's longlist in workspaces where "Show photos" is on. The photo is copied into Navigent's own storage without its metadata and is never sent to AI | The LinkedIn URLs of those candidates, and the photos and texts fetched | Israel (Bright Data Ltd.). Its systems are hosted at Amazon Web Services, with a disaster recovery site in AWS in the EU and backups at Microsoft Azure | The European Commission's adequacy decision for Israel. Outside the EEA and countries with such a decision: the European Commission's standard contractual clauses under Bright Data's data processing agreement |
| Unipile | Campaigns through the customer's own LinkedIn accounts and Gmail and Outlook mailboxes, the latter two through Unipile's own apps, which Google and Microsoft have verified, and posts about roles on LinkedIn | Access to the connected accounts, messages to and from candidates, the profile information used to contact them, and posts with their reactions and comments, which are read but not stored | France (Scaleway and OVH) | Hosting in the EU. Unipile's providers outside the EU/EEA: an adequacy decision, the EU-U.S. Data Privacy Framework or the European Commission's standard contractual clauses, as Unipile's privacy policy sets them out |
| Resend | E-mail from Navigent: sign-in, invitations and service messages to users, the confirmation of a removal request, and the e-mails of a demo request. Never campaigns | The recipient's e-mail address, their name where we have it, and the e-mail's content, which may name a candidate the user can already see | United States (Plus Five Five, Inc.) | The European Commission's standard contractual clauses and the EU-U.S. Data Privacy Framework, under Resend's data processing agreement |
| Google (Google Workspace) | The info@navigent.io mailbox | Enquiries and demo requests, which can carry candidate data a customer sends | The countries where Google and Google's sub-processors have facilities | The EU-U.S. Data Privacy Framework and the European Commission's standard contractual clauses in Google's data processing terms |
| Stripe | Payments, subscriptions and invoices. Navigent's own data only | Billing contact, company details, VAT number and payment details | United States (Stripe, LLC). The agreement is with Stripe Payments Europe, Limited, Ireland | The EU-U.S. Data Privacy Framework, otherwise the European Commission's standard contractual clauses |
| Sentry | Errors and logs | Technical data, without personal data | EU (Frankfurt) for errors and logs. Account and organisation details may be kept in the United States | The EU-U.S. Data Privacy Framework, otherwise the European Commission's standard contractual clauses |
| Better Stack | Uptime monitoring and the status page at status.navigent.io | No personal data | EU | The European Commission's standard contractual clauses in Better Stack's data processing agreement |
| Vercel Web Analytics | Visitor statistics for navigent.io. Navigent's own data only | Visits, without cookies and without a cross-site identifier | As for Vercel | As for Vercel |
| MillionVerifier | Verifying candidates' e-mail addresses before sending | Candidates' e-mail addresses | Hungary (GBD Software as a Service Private Limited Company), with providers in the United States, Canada, Germany, France and Sweden, among others | No transfer to MillionVerifier, which is in the EU. Onward to providers outside the EU/EEA: the safeguards MillionVerifier's privacy policy names, such as an adequacy decision, the European Commission's standard contractual clauses or the EU-U.S. Data Privacy Framework |
The location and transfer mechanism are as each provider states them in its own data processing agreement and documentation, read on 6 October 2026. Where a provider does not say where it processes the data, the table names the provider's company and country, and the transfer mechanism covers processing outside the EU/EEA.
C.2 The list in force when the customer accepted this agreement is approved. Changes are notified under clause 10.
C.3 Some providers on the list process only Navigent's own data, such as Stripe and Vercel Web Analytics, and are not sub-processors of candidate data. The list says so.
C.4 LinkedIn is not a sub-processor, and nor are Google and Microsoft as the providers of the customer's own mailboxes. Campaigns are sent from the customer's own accounts with them, under the customer's own agreements with them. Unipile connects the accounts, and Gmail and Outlook are connected through Unipile's own apps, which Google and Microsoft have verified. Google is on the list only as the host of Navigent's own mailbox, info@navigent.io.
Annex D: Retention and deletion
D.1 Navigent deletes candidate data according to this table. Deletion runs automatically every day.
| Data | Kept | Deleted |
|---|---|---|
| Candidates who are not held | 90 days from the last fetch, or from when they stop being held | Automatically |
| Candidates who are held | While on the shortlist for an active role or further along in the process (contacted, replied, interested, not interested or hired). Rejected and excluded candidates are not held | 90 days after the role is closed |
| Candidates marked as hired, after the role is closed | The number of months the customer chooses for the workspace, from 0 to 24 and 12 by default, counted from when the role is closed. Applies when later than the 90 days | Automatically |
| Photos | With the candidate | The photo is deleted before the candidate |
| Assessments, decisions, calibration, notes, campaign enrolments and messages | With the candidate | Together with the candidate |
| AI log | 6 months. Pseudonymised when the candidate is deleted | Automatically after 6 months |
| The list of people and companies not to be contacted | Until the customer deletes the entry | Only by the customer |
| Roles with their thread and requirements | Until the customer deletes the role. Drafts for which no search was ever started, 30 days | By the customer, and drafts automatically |
| Activity feed | 12 months | Automatically |
| Log of exports | 2 years | Automatically |
| The organisation's full export | 7 days, the ZIP file only | Automatically |
| Notifications in the app | 90 days | Automatically |
| Backups | The database provider's backup period, at most 30 days | By the provider |
| All of the above, when the organisation is deleted | Within 30 days |
D.2 The AI log exception. When a candidate is deleted, including by a removal under Annex E, the candidate's entries in the AI log are not deleted at once. The link to the candidate is removed and the free-text reasoning is deleted. What remains is a pseudonym, a hash of the candidate's internal ID computed with a secret key, together with the model, the prompt version, which fields were used, and the assessments. The entries are deleted when they are 6 months old. The exception exists because the AI Act requires the logging of a high-risk AI system to be documented.
D.3 Hired candidates. A candidate is hired when a user has chosen "Mark as hired". How long candidates marked as hired are kept after the role is closed is the customer's decision as controller. The customer makes it for each workspace under Settings → Workspaces, from 0 to 24 months and 12 by default, so that it can document a hire through a guarantee period. If the customer chooses 0, there is no exception, and the ordinary rules in D.1 apply.
D.4 Exports. Data the customer has exported is outside Navigent and follows the customer's own rules; see clause 4.5.
D.5 Evaluation sets. Candidate data is included in Navigent's evaluation set only under a separate written agreement; see clause 5.4. Rows are pseudonymised before they enter the set: name, photo, e-mail address, phone number, employer name and identifying free text are removed, and there is no route back to the candidate.
Annex E: Remove me from Navigent and the suppression list
E.1 Roles
Navigent is the controller of the removal requests and of the suppression list, on the basis of its legitimate interest in keeping a person who has asked to be removed out of the whole service rather than out of one customer only. When Navigent deletes candidate data from the customer's workspaces following a confirmed request, it does so as processor under the customer's standing instruction in clause 6. The instruction covers only the deletion and the suppression.
E.2 The request
- The person gives the link to their LinkedIn profile and an e-mail address on the removal page.
- Navigent sends an e-mail with a link that is valid for 24 hours. Nothing happens until the link is used, and a request that is not confirmed is deleted after 7 days.
- The confirmation shows that the person controls the e-mail address, but not that the LinkedIn profile is their own. This is accepted because a removal only removes.
E.3 The removal
- Once the request is confirmed, Navigent deletes at once, with no manual review, the candidates in every customer's workspaces that match the normalised LinkedIn URL, and the e-mail address where it has been looked up, with their photos and everything linked to them. The AI log is pseudonymised under Annex D.
- The LinkedIn URL, the e-mail address and the Prospeo ID of each candidate found go on the suppression list, so that the person is never fetched, assessed or contacted again.
- Navigent forwards the LinkedIn URL to Prospeo, where the data comes from, and records the date.
- The customer is not told about the removal. Navigent does not tell the person which customers held data about them, and does not forward the request to the customers.
- A removal cannot be undone, and deleted data is not restored from backup.
E.4 The suppression list
- The list contains only HMAC-SHA256 hashes of the normalised LinkedIn URL, e-mail address and Prospeo ID, computed with a secret key. Nothing on the list can be read back into a name.
- The list is checked when a search fetches candidates, where a match is dropped before it is stored or counted, and at every send, where a message to a person on the list is stopped. If the check fails, the fetch or the send stops.
- When a user opens a profile with the Chrome extension, the list is checked first. A match is not stored, not assessed and not sent to an AI model.
- The list applies to all customers. The customer can neither see the list nor remove anyone from it.
- The list is permanent. A superadmin can remove entries only when it has been shown that someone other than the person made the removal, and the reason is written to the audit log.
- The list is separate from the customer's own list of people not to be contacted.
E.5 Records
- A completed request is kept for 3 years as the record that it was carried out. The suppression list is kept.
Navigent.io ApS · CVR 46285395 · Nørre Voldgade 70, 4., 1358 København K, Denmark · info@navigent.io