Privacy controls that show their work.
Privacy work is not a hidden setting. Talon surfaces consent state, retention windows, requests, exports, and audit events in the workspaces where people need to act on them.
Information handled in Talon
The information present in Talon depends on the workspace in use. It can include account and contact details; professional profiles; CV or resume information; roles and applications; interview, feedback, offer, and hiring records; recruiter candidate and client records; programme and learner information; privacy-request history; and messages submitted through the public contact form.
Contact submissions are stored so Talon can route and follow up on the enquiry, including whether its internal notification was delivered. Do not use the general contact form for credentials, identity documents, full CVs, or other sensitive personal information.
Talon does not turn every record into the same data set. The fields available depend on the workflow and the information a customer or individual chooses to enter, import, or connect.
What applicants can control
Signed-in applicants have a Privacy Center for reviewing recruiter-held records linked to them. From that workspace, they can see consent status, the date consent was captured or expires, applicable retention information, and available privacy exports.
An applicant can update a linked recruiter record to pending, consented, or withdrawn; choose a retention window; and submit an export or deletion request. A deletion request is submitted to the recruiter team for processing—it is not presented as an immediate self-service deletion.
Consent and retention for recruiter records
Recruiter privacy operations expose the current consent state for candidate records, including pending, consented, and withdrawn states. Recruiters can configure default retention days, export-link expiry days, audit-retention days, and whether records should be automatically deleted after consent expires.
The workspace also shows operational queues and metrics for open requests, scheduled deletions, expired consents, and available exports, so privacy work can be reviewed alongside normal recruiting activity.
What an export contains
Completed privacy exports package the relevant recruiter-held candidate record with the applicable consent state, retention and deletion policy, linked-applicant information where available, and the privacy audit trail included in that package. Exports can be downloaded as JSON for a portable copy.
Export views show when a package was generated, when access expires, and access activity where available. Treat an export link as sensitive: it is intended for the person or team handling that request, not for broad sharing.
What Talon does not decide for you
Product controls cannot determine whether an organisation has a lawful basis for processing, what information it should collect, or how it must respond under employment and data-protection law. Customers remain responsible for their own notices, legal basis, retention policy, and request handling.
Before using Talon with personal data, customers should review the applicable service and data-processing terms. See the security overview for the web-application controls documented separately.
Making a privacy request
If you have an applicant account, use the Privacy Center first: it keeps the request connected to the correct recruiter-held record. If you cannot access the relevant workspace, use the dedicated data deletion request form.
State the account or organisation the request concerns, but do not send credentials, full CVs, identity documents, access tokens, or unrelated sensitive information.
