Interview scheduling software built for GDPR
Interview scheduling designed around GDPR: candidate data encrypted at rest, consent recorded before contact, automated retention, and one-click erasure.
Why interview scheduling is a GDPR problem
Scheduling an interview scatters personal data further than most teams realize. A candidate's name and email land in calendar events on every interviewer's account, in confirmation and reminder emails, in the ATS, and often in a spreadsheet or two. Each copy is personal data you are accountable for under GDPR — subject to storage limitation, purpose limitation, and the right to erasure. When a candidate asks "delete my data", every one of those copies is in scope, and a scheduler that only knows about calendar events cannot help you find them.
What "built for GDPR" means in practice
Cadence treats data protection as an architectural constraint, not a settings page. Concretely:
- Encryption at rest: candidate personal data — names, emails, notes, interview locations, scorecard content — is encrypted at rest, not stored as plain text.
- Consent recorded before contact: a lawful contact basis is recorded per candidate, and every outgoing email is checked against it at send time. No recorded basis, no email — the gate is enforced by the system, not by whoever clicks send.
- Data minimization: candidate-facing pages need no account and no login; the booking and status links carry no personal data in the URL. Availability checks read busy/free time only, never other people's event contents.
- Automated retention: you set a retention period per workspace; candidates who pass it are flagged and processed automatically instead of accumulating forever. See our guide to candidate data retention periods.
- One-click erasure: an erasure request wipes the candidate record, unsent email, scheduling artifacts, and synced ATS fields together, and leaves a PII-free audit entry proving it happened. Candidates can raise the request themselves from their private status page. The workflow is described in the right to erasure in recruiting.
What a tool cannot do for you
Honesty matters here: no software makes an organization GDPR compliant. Choosing a lawful basis, writing your privacy notice, deciding retention periods, and answering subject-access requests are your decisions, usually with your legal counsel. What Cadence changes is whether those decisions are cheap to execute. A retention policy that requires a quarterly manual purge will be skipped in a busy quarter; one that runs automatically will not. A consent check that lives in a wiki gets forgotten; one enforced at send time cannot be.
Where to start
If you are building a privacy-conscious recruiting practice, start with our practical guide to privacy-safe and GDPR-conscious recruiting, then decide your retention periods and your erasure workflow. When you want the operational side handled for you, see the full feature overview and pricing — Cadence is free during early access — or start from the Cadence home page. It is built for small recruiting teams that have GDPR duties but no compliance department.