Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

    English (US)
    MX Spanish (Mexico)
    CA French (Canada)
    US English (US)
    • Home
    • Management Tools
    • Client Setup

    Client Setup: Data Privacy

    Written by Lindsey Stanifer

    Updated at August 20th, 2026

    Contact Us

    If you still have questions or prefer to get help directly from an agent, please submit a request.
    We’ll get back to you as soon as possible.

    Please fill out the contact form below and we will reply as soon as possible.

    • Getting Started
      Setting up your calendar Managing your alerts Additional Settings
    • Daily Processes
      Candidate Inbox Candidate Profile My Calendar/Calendars Browser Extension My Jobs Approvals Engine Manual and Common Scheduling Practices Form I-9 processes Troubleshooting Forms & Offers
    • Candidate and User Engagement
      Campaigns Conversation Builder Surveys Channels Talent Community Voice Web Management Analytics & Reporting Data Privacy Career Sites
    • Management Tools
      Job Management Scheduling Security Journeys Content Management System (CMS) Multiple Brands Workflows Users, Roles and Permissions Data Feeds Location Management Lookup Tables Assistant Messaging Company Information Client Setup System Attributes Integration Center
    • Contextual AI
      Knowledge Training Library
    • Conversational Events and Campus
      Conversational Events Campus Events
    • Employee Communications
      Communications App Employee Management
    • Release Notes
      2025 2026
    • Workday Feature Descriptions
    + More

    Parent toggles can only be enabled by your CS Representative/Paradox Admin.

     

    The Data Privacy section of Client Setup includes all system settings around data security. These include the following:

    • Login Method – This selector allows you to determine whether users will log into the system with their phone number or email address.
    • Will your employees use their phone number or email address for 2-Factor Authentication? – This selector allows you to select the contact method that will be used in  two factor authentication, if you want to use it. The default selection will be Do not use 2FA.
    • Enhanced Security: By default, all passwords must contain at least one upper and lower case characters, one number, and one special character. However, you can set additional password requirements here. 
      • Enable reCAPTCHA – This setting adds an extra layer of security to protect widgets from spam and automated abuse. This setting is enabled by default. Learn more about reCAPTCHA protection on widgets.  
      • Password Requirements:
        • Minimum Password Length – This will allow you to set the minimum password length required for the account. Options include:
          • 8 characters in length (default)
          • 9 characters in length
          • 10 characters in length
          • 11 characters in length
          • Up to 100 characters in length
        • Limit Password Reuse – This will allow you to set the number of times a user can reuse the same password. Options include:
          • None (default)
          • Last Password
          • Last 2 Passwords
          • Last 3 Passwords
        • Password Reset Interval – This will allow you to set how often team members should be required to reset their passwords. Options include:
          • Never (default)
          • 30 days
          • 45 days
          • 90 days
          • 120 days
          • 180 days
          • 1 year
    • Do not send a welcome message to your employees – This will disable the welcome message that is sent to a new user or when a user's role changes from Basic User to Full User.
    •  Only allow your employees to log in with SSO – This setting requires users with Login Access enabled to log in through Single Sign-On (SSO).
      • Note: When this setting is enabled, Basic/Limited Users are not required to use SSO. They can log in via MFA if they have Login Access enabled.
    • Allow duplicate location ID's – This setting allows the account to use the same location ID across multiple locations.

    Logic for the Allow duplicate location ID's setting:

    To ensure accurate job matching, Paradox requires unique Location IDs to map Job Feed requisitions to Location Management. Because of this, the Allow duplicate location IDs setting is unavailable under the following conditions:

    • If Map Locations in My Jobs with Location ID from Feed is enabled: These two settings have conflicting logic and cannot be used together.
    • If using External ATS Job Management (Integrated Jobs): Unique IDs are strictly required to support Master Feed and Journey Targeting configurations.
     
    • Automatically log employees out after this amount of idle time – This setting determines a user’s CEM session length so that once that timeframe is met, the user is logged out of the system. Options include:
      • 20 minutes
      • 30 minutes
      • 1 hour
      • 2 hours
      • 8 hours (default)
      • 12 hours
      • 24 hours

    The recommended option for this setting is an 8 hour or less session length.

     
    • Default Candidate Data Retention Period – The period of time in which candidate data is retained in the system. The default selection will be Forever, but additional options are available for selection. This selection is typically made during implementation and shouldn’t be changed, unless warranted.

    Default Candidate Data Retention Period Notes:

    • When the period of time that candidate data can be stored in the system is reached, then it will be deleted on the following Saturday at 10:00AM UTC.
    • Paradox executes a configured Data Retention Period based on candidate activity.
      • For example, a Data Retention Period of 6 months would delete a candidate's profile if the profile remains inactive for 6 months. Data retention is applied separately to candidates' multi-application profiles.
    • At any time, candidates can request to have their personal information updated and/or deleted.

    Candidates Not Impacted By Data Retention: Candidates created via Public API who have not engaged in a conversation or accepted Terms & Conditions (i.e., do not have GDPR enabled on their profile) are not subject to the Data Retention Policy deletion process. Only candidates who have accepted Terms & Conditions (GDPR enabled) will be deleted after the configured inactivity period. If you require API-created candidates to be included in data retention enforcement, please submit an enhancement request.

     
    • API Whitelist – Selecting + Add IP Address allows you to whitelist relevant IP addresses for API access within an account for an additional layer of security. Whitelisted IP addresses will have the Public API access and Custom Inbound Access for the account only.
    • Global Candidate Data Retention – This will allow you to set a period of time for data retention on a per country basis. Countries that aren’t added here will follow the Default Candidate Data Retention Period value set for the account.
      • Provide country data retention policy and specify data retention period. – When Global Candidate Data Retention is enabled, then this field will display where you can add counties by completing the below steps:
        1. Click into this field.
        2. Search for the preferred country.
        3. Select that country from the list that opens.
        4. The country will then display under this field. Select the data period retention selector and select the preferred data retention period for that country.
        5. Repeat these steps for all necessary countries with a different data retention period.
        6. Save the page.

    Changes to a Data Retention Period: Once you make any change to a policy, it will take a minimum of seven days to process. If a change was made by mistake, simply revert the change back to the desired data retention period. After being processed, this data retention period will be locked in.

    Delete a Country’s Data Retention Policy: If you need to delete a policy, you can click the trash icon next to the retention policy time selection and confirm deletion.

    • Note: Our data retention feature deletes the candidate from the CEM. It does so by storing the candidate messages in MongoDB. We anonymize by deleting PII data like their phone number, email, name, IP address, then soft-delete in the CEM setting the status = 10 (which removes it from the view in the CEM).

    ⭐ Paradox executes a configured Data Retention Period based on candidate activity.

    • For example, a Data Retention Period of 6 months would delete a candidate's profile if the profile remains inactive for 6 months. Data retention is applied separately to candidates' Multi-Application profiles.

    Candidates Not Impacted By Data Retention: Candidates created via Public API who have not engaged in a conversation or accepted Terms & Conditions (i.e., do not have GDPR enabled on their profile) are not subject to the Data Retention Policy deletion process. Only candidates who have accepted Terms & Conditions (GDPR enabled) will be deleted after the configured inactivity period. If you require API-created candidates to be included in data retention enforcement, please submit an enhancement request.

     
    • Equal Employment Opportunity – This will allow your company to be in compliance with federal laws that prohibit unfair treatment by employers based on race, sex, color, national origin, religion, disability, age (40 or over), genetic information and retaliation of complaints or witnesses to illegal activity. When enabled, then the below settings will display.
      • Helper Text – This will include helper text for Race and Veteran Status questions within a form. This is enabled by default.
      • Disability Status – This will display Disability Status in a conversation modal. 
        • Disability Statement – This will include a disability statement within a conversation. When the Disability Status is enabled, then this setting will display.
          • Require Disability Statement – When the Disability Statement is enabled, then this setting will display. This will require a candidate to respond to this statement. 
          • Disability Statement – When the Disability Statement is enabled, then this setting will display. This will allow you to configure the client's disability statement in a slide-out drawer. Select + Configure to enter in these details.
      • Require Answers – This will require the candidate to complete the EEO Statement in a conversation modal.
      • EEO Statement – This will allow you to customize the default EEO statement, header, and title of the modal that opens within a conversation. Select Edit to do this if you already have EEO configured, and Configure to first configure the EEO statement. You can learn more about this process in Equal Employment Opportunity (EEO).
      • EEO Question Customization: This allows you to customize the EEO questions and add any additional EEO questions. You can customize the labels, system attributes, display text, stored value, and helper text for the following questions:  
        • Ethnicity 
        • Race 
        • Gender 
        • Veteran Status 
          • Note: You can learn more about this process in Equal Employment Opportunity (EEO).
    • PII Masking – This will mask all personal identifiable information that a candidate provides. PII data types include:
      • Email Addresses:  s******@p******.ai
      • Phone Numbers:  (480) *** - ****
      • U.S. Social Security numbers:  *** - ** - ****
      • MasterCard numbers:  ************3590
      • Visa card numbers:  ****-****-****-4587
      • American Express card numbers:  *************2157
      • IPV4 addresses:  ***.**.*.*
    • Advanced Data Privacy – This toggle supports the GDPR/CCPA regulations needed for current candidates to edit and/or delete their information. By default, this toggle will be enabled.
      • Select where to display terms – This allows you to select where to display these terms. Options include:
        • EU (default selection) –Terms will display for EU candidates.
        • Global – Terms will display for all candidates.
        • California – Terms will display for Californian candidates.
      • Deliver Data Privacy message as – This allows you to select how this message will be delivered to the selected candidates. Options include:
        • Web Link
        • SMS Text
      • Display Terms and Conditions Based on Job Location – Terms and Conditions display based on a job’s location rather the candidate’s location. This feature will only apply for jobs with single locations. Jobs with more than one location will show Terms and Conditions based on candidate location.
        • Note: If you try to enable Display Terms and Conditions based on Job Location when Display Terms in Candidate Q&A and Display Terms in Job Search are enabled in the account, the Conflicting Settings modal displays. You must disable these settings first if you want to enable Display Terms and Conditions based on Job Location.
      • Display terms in Candidate Q&A – This allows the AI Assistant to send the Terms & Conditions messaging 500 milliseconds after they send the first message to the candidate.
      • Display terms in Job Search – Terms & Conditions messaging will display when a candidate begins the job search interaction with the AI assistant.
      • Display Data Portal Footer – This setting controls whether a Contact Us section displays in the footer of the Candidate Information portal. When enabled, candidates can select Contact Us to view your organization's contact information while accessing the Candidate Information portal to view or manage their data. Learn more about the Candidate Information portal.
      • Contact Information Button – This setting displays once the Display Data Portal Footer is enabled. To configure:
        • Select + Configure
        • Under Contact Information Button, select + Configure.
        • Customize Button Text as needed.
        • Enter at least one field:
          • Company Website
          • Address
          • Phone Number
          • Contact Email
        • In the lower-right corner of the drawer, select Confirm.
      • Send an email notification when a candidate requests to delete/modify their data. – When toggled on, a field will display where you can enter the person who will be contacted when a candidate wants to edit or delete their data. This person(s) will then approve or deny the request to update/remove the candidate's data.
      • Send an email notification to an external ATS and CRM when a candidate requests to delete/modify their data. – When toggled on, a field will display where you can enter the preferred contact's email address who will be contacted when a candidate wants to edit or delete their data. The person(s) tied to this email address will then approve or deny the request to update/remove the candidate's data.
      • Use custom data privacy process – This will allow you to create a custom response for the modification/deletion of data. By default, the AI Assistant will send the following message to the candidate: "To review your personal information, please visit [LINK]."
        • Set a response to candidate inquiry for SMS/WhatsApp – This will allow you to set the preferred response for SMS/WhatsApp.
        • Set a response to candidate data inquiry for web – This will allow you to set the preferred response for web.
    • Language Detection Service:
      • Which language detection service provider will this account use? – This allows you to select the language detection service providers for the account. By default, both Google Translate and Yandex will be selected as the providers, with Yandex being the primary and Google Translate being the secondary.
    • Override Roles For Sensitive Information – This allows you to select the user roles, if any, that will be able to view sensitive and masked information in reporting. Otherwise, users will see asterisks in place of data values. 
    • Use communication Preference for Workflows – This will be toggled on by default and ensures that communications are only sent to the candidates' preferred communication methods.
      • Time period to set abandoned workflows – When a candidate is sent a communication opt-in to a select channel, this is the time period before workflows are canceled. Options include:
        • 2 days
        • 3 days
        • 4 days
        • 5 days
        • 6 days
        • 7 days
    • Turn OFF Opt-In CTA Message – This setting prevents the standard welcome message from being sent to new users added to the account.
    • Shortcode Terms of Use – This will create a separate Terms Of Use link for teams who request to have a short code.
      • Terms of Use URL – When Shortcode Terms of Use is enabled, an auto-generated link will be created. Select Copy to share this with the team, if preferred.
      • Customize Shortcode Terms of use – When Shortcode Terms of Use is enabled, this setting will display and allow you to customize the default template based on your team's needs when you select Customize.

    When building out this page, it is recommended to BLOCK the indexing of the Google Search. You can prevent a page or other resource from appearing in Google Search by including a noindex meta tag or header in the HTTP response. When Googlebot next crawls that page and sees the tag or header, Googlebot will drop that page entirely from Google Search results, regardless of whether other sites link to it. 

     
    • Idle timeout in Olivia Chat – This will have the Olivia Chat experience timeout after the selected period of time when a candidate is idle. 
      • Timeout At – When the Idle timeout in Olivia Chat setting is enabled, this will display and allow you to select the idle time period. Options include:
        • 3 minutes
        • 10 minutes
        • 20 minutes
        • 30 minutes
        • 45 minutes
        • 1 hour
    • Terms & Conditions:
      • Region – This is where you can set Terms & Conditions by region or country. The regions of Global, EU, and California will be listed in this dropdown in addition to values saved for a specific country. The regions will display based on the selections made in the Advanced Data Privacy subsection.

    You can also update Terms & Conditions based on a combination of both region and language (English will be required for all regions). To do this, update the region selector and then the language selector before updating the Terms & Conditions. Ensure to save each entry before updating either the region or language.

    • Note: Auto-translation will not occur for Terms & Conditions. Terms & Conditions will only display based on the regions and languages that are set for them.
     
    • Terms & Conditions (continued):
      • Title – The title presented to the candidate around these Terms & Conditions.
      • Web Intro – The message the AI Assistant sends to the candidate before sending the Terms & Conditions.
      • Terms – The Terms & Conditions provided to candidates. These can be adjusted based on your team's needs.
      • Decline Button – The copy of the Decline button.
      • Accept Button – The copy of the Accept button.
      • Accepted Message (SMS) – The message the AI Assistant will send to the candidate after they accept the Terms & Conditions.
      • Declined Message – The message the AI Assistant will send to the candidate after they decline the Terms & Conditions.
    • BCC emails:
      • Manage your BCC address for all emails – This is an optional field where you can enter in the email addresses that should be listed in the BCC field of all emails sent out. These email addresses will not display to the recipients of these emails. 
    • Authorized Email Domains – This setting allows users to add email address domains to ensure users have valid email addresses within the account. If no email address domains are added, any email address domain is accepted.
    conversational ats integrated ats

    Was this article helpful?

    Yes
    No
    Give feedback about this article

    Related Articles

    • Create an employee (user) form
    • Employee/user file requirements
    • Employee/user feed processing status

    Copyright 2026 – Paradox.

    Knowledge Base Software powered by Helpjuice

    Expand