# GDPR Compliance & Data Privacy
## HireBee & GDPR
HireBee is designed with GDPR compliance in mind. Here's how we help you stay compliant:
## Candidate Consent
### Consent Tracking
- Each candidate's consent status is tracked (consented, withdrawn, pending).
- Consent timestamps are recorded for audit purposes.
- Candidates can update their preferences at any time.
### Privacy Notice
Your career page can include a privacy notice that candidates must accept before applying. Customize the text in Settings → GDPR.
## Data Rights
### Right to Access (Data Export)
Candidates can request a copy of all data you hold about them:
1. A candidate contacts you requesting their data.
2. Go to their profile → **GDPR Actions → Export Data**.
3. A JSON/CSV export is generated with all their data.
4. Send it to the candidate.
### Right to Erasure (Data Deletion)
Candidates can request their data be deleted:
1. A candidate contacts you requesting deletion.
2. Go to their profile → **GDPR Actions → Request Deletion**.
3. A deletion request is created with a scheduled deletion date.
4. After the grace period, all candidate data is permanently deleted.
5. Applications, notes, scorecards, and files are removed.
### Right to Rectification
Candidates can request corrections to their data. Update their profile directly in HireBee.
## Data Retention
Configure automatic data retention policies:
- Set how long candidate data is kept after last activity.
- Expired data is flagged for review and deletion.
- Retention policies are configurable per organization.
## Account Deletion
Users (team members) can request their own account deletion from **Profile → Account → Delete Account**:
- A grace period (typically 30 days) allows cancellation.
- After the grace period, the account and associated data are permanently deleted.
## Audit Trail
All GDPR-related actions are logged in the audit trail:
- Data exports, deletion requests, consent changes.
- Who performed the action and when.