Security & privacy
Recruiting involves large amounts of personal data, so security and privacy are central to administering X0PA AI. This page summarises the controls available to administrators.
Account security
- Passwords — users set their own strong passwords; encourage a password manager.
- Single Sign-On (SSO) — where your organisation uses SSO, users authenticate with corporate credentials.
- Automatic sign-out — inactive sessions are ended automatically to protect unattended screens.
:::note Never share or collect passwords Users always set their own passwords. Administrators and colleagues should never ask for, set, or store another person's password. :::
Access control
The most important privacy control is limiting who can see and do what:
- Assign each user the least-privilege role for their job. See Roles & permissions.
- Restrict exports of personal data to the roles that need it, and limit exported fields. See Export configuration.
- Give external vendors and reviewers only the access required. See Vendors.
Candidate data & consent
- Consent — application forms can capture the data-processing consent your jurisdiction requires. Configure this in AI & portal settings.
- Unsubscribes — the platform respects candidate unsubscribes; opted-out candidates aren't contacted by campaigns. See Templates.
- Data minimisation — collect and retain only what you need (see Custom fields — avoid unnecessary required fields).
Deleting & retaining data
Candidates and other records can be deleted when they should no longer be retained — for example on a data-erasure request. See Deleting records. For people who have left, prefer deactivating their user account over deleting it to preserve audit history.
:::caution Follow your data-protection obligations Depending on your region (GDPR and similar), you may have obligations around consent, access, and erasure of candidate data. Configure the platform to support your organisation's policies, and consult your data-protection lead where needed. :::