Data privacy (GDPR/CCPA): Candidate viewing and managing profile information
Table of Contents
The General Data Protection Regulation (GDPR) applies to all candidates based in the EU. The California Consumer Privacy act (CCPA) applies to all candidates in California. If a candidate's IP address or country code in their phone number is based in the EU/California, they will later have the option to view, edit, and/or delete their personal information in the CEM.
Updates made to a candidate’s data will send an email request to the Data Privacy Contact saved in the system where they can confirm the changes or message the candidate directly.
Configuration
Configure Terms & Conditions by following this process.
View personal information
To view personal information, the candidate will need to complete the following:
- Ask your AI Assistant if you can view your data.
- Click the link sent by your AI Assistant.
- Click on the link to access the Secure Login page.
- Select the preferred communication method to receive the verification code.
- Note: Depending on the communication preferences, they may see options for email, SMS, or WhatsApp (if enabled).
- From the verification page, enter in the one-time code sent to your preferred communication preference.
The candidate will successfully log in to the portal.
Candidate Information portal

This portal will include:
- The Terms and Conditions agreed upon.
- Personal Data
- Activity Log
- A footer (if enabled in the account)
Personal data
This section stores the candidate’s name, phone number (if provided), and email address(if provided). Candidates can edit, export, and/or delete their information from the Personal Data’s action menu, or the ellipses.
- Note: The below processes are written for a candidate audience.
Edit personal information
- Click the Personal Data’s action menu.
- Select Edit from its drop-down menu.

- Changes can be made to the Candidate name, Phone Number, and Email Address fields.
- Click Save changes in the top right corner.
Notification sent to admin

The Data Privacy Contact will receive an email notification about the candidate’s modification request and can either:
- Message the candidate directly to further elaborate on the changes.
- Allow the modifications.
Once the request is approved, the changes will be officially made in the system.
This contact is configured on the backend by your CS Representative during implementation. If this contact does not make a selection, then they will receive the same email 7 days later to remind them to take action.
Approved modification requests
Once the modification request is approved:
- All data in the system will be modified.
- All sub-process data on the candidate will be modified (Twilio, etc.).
- Paradox’s Compliance Team will be notified.
Important Note: If the client never approves the candidate request, no data will be modified.
Delete personal information
- Click the Personal Data’s action menu.
- Select Delete from its drop-down menu.

- (Optional) Click the Export My Data Before Deleting button to download your data to your device, if preferred.
- Select the I understand my data cannot be recovered once deleted box.
- Click Delete All.
Notification sent to admin

Once a candidate submits a request for their data to be modified or deleted, the admin user email that is configured on your account will receive the following:
- A non-actionable email that lets them know that a request has been submitted.
- An actionable email with two options:
- Allow Deletion – When clicked, this will approve the candidate’s deletion/modification request.
- Message Candidate – When clicked, this will open the CEM where the user can respond to the request.
If the admin user does not make a selection, then they will receive the same email 7 days later to remind them to take action.
Approved deletion requests
Once the deletion request is approved:
- All data in the system will be deleted.
- All sub-process data on the candidate will be deleted (Twilio, etc.).
- Paradox’s Compliance Team will be notified.
Important Note: If the client never approves the candidate request, no data will be deleted.
Export personal information

If the candidate would like to save the data for their records, then they can click the Personal Data’s action menu, or the three dot icon, and then select Export All from its drop-down menu. This will then download all of the candidate’s data, including their conversation with your AI Assistant, to their desktop computer.
Activity log
The Activity Log is listed under the Personal Data section and includes the following information:
- When the terms were accepted.
- The messages sent to the candidate.
- The messages received from the candidate.
- The group and/or location selection(s).
- Personal information edits by the candidate.
- Candidate Profile edits by user ID.
- The user’s IP address and timestamp of the edits made.
Milestones (status updates, profile views, interview requests, etc.) and usernames will not be included in this log.