Privacy First

Candidate Privacy &
Consent Framework

Visage is built on a foundation of informed consent. Every candidate we engage has explicitly opted in before any contact information is shared with an employer. This page explains exactly how that works — for candidates, for recruiters, and for your compliance team.

SOC 2 Type II
GDPR Compliant
CCPA Ready
Consent-First by Design

End-to-End Process

How Visage Sources and Engages Candidates

Every role follows a structured, auditable workflow. Human judgment is embedded at every critical decision point — AI scales the search, humans validate the fit.

Process Diagram — End-to-End Candidate Consent Flow

Visage Candidate Privacy & Consent Process Diagram — BPMN Style
Scroll to zoom · Drag to explore
1
Employer

Role Submission

A role enters the Visage system in one of two ways: submitted directly by a recruiter through the Visage platform, or pushed automatically via an ATS integration (Workday, Greenhouse, iCIMS, Taleo, SuccessFactors, and others). The role brief — including required skills, seniority, location, and any geographic exclusions — is validated before sourcing begins.
2
Visage

Human-Led AI Sourcing

Visage's AI scans across 35–45 professional datasets to identify candidates who match the role criteria. The AI generates a shortlist based on skills, seniority, location eligibility, and role fit. Expert human sourcers then review and validate every slate before any outreach is sent — ensuring quality and judgment that AI alone cannot provide.
3
Visage + Candidate

Candidate Outreach & Consent Gate

Visage sends an outreach email to each candidate. Depending on account configuration, the email may be sent from Visage on behalf of the employer, or directly from the employer using Visage's outreach platform. A link to the employer's Applicant Privacy Policy may be included if the account is configured to do so. Replying to the email constitutes explicit consent. If a candidate does not respond or opts out, no contact information is ever shared with the employer.
4
Visage + Employer

Data Sharing & Hiring Pipeline

Only after a candidate has consented does Visage share their contact details and full profile with the employer via the platform. The employer then reviews the candidate in their Visage dashboard and advances them through the hiring pipeline. All status updates are tracked in real time.

Candidate Experience

What Candidates See and Control

Candidates are never contacted without their knowledge. Every touchpoint is transparent, opt-in, and includes a clear path to opt out.

Candidate Outreach Email — Visage.jobs
Example candidate outreach email from Visage.jobs

Example outreach email sent to a candidate via Visage.jobs

Transparent Outreach Email

Outreach emails are sent either from Visage on behalf of the employer, or directly from the employer using Visage's platform — depending on how the account is configured. In both cases, the email describes the opportunity and identifies the employer. A link to the employer's Applicant Privacy Policy is included when the account is set up to do so.

Reply = Explicit Consent

Consent is captured through a direct reply to the outreach email. The email states clearly: "If you choose to connect directly, you consent to Visage.jobs sharing your contact information with [Employer]." There is no hidden opt-in. Replying is an affirmative action.

Clear Opt-Out at Every Step

Every email includes a direct opt-out link: "If you no longer want to hear about future career opportunities, click here." Candidates who do not respond or who opt out are removed from consideration immediately. No contact data is shared with the employer under any circumstances.

Privacy Policy Access

Candidates can access Visage's full privacy policy directly from the outreach email. The email also explains how their contact information was originally collected, providing full transparency about data sourcing.

Recruiter Experience

What Recruiters See in the Platform

Recruiters interact only with candidates who have already consented. The platform provides full visibility into outreach status, consent state, and pipeline progression.

1Consent-Gated Candidate Profiles

Recruiters only see full candidate profiles — including contact details — after the candidate has replied to the Visage outreach email. Pre-consent, only publicly available information is visible. This is enforced at the platform level, not just by policy.

2Real-Time Outreach Status

The platform shows the exact status of every outreach touchpoint: First Email sent, Follow-Up 1, Follow-Up 2. Recruiters can see at a glance whether a candidate has been contacted, has responded, or has not yet engaged — without needing to manage the outreach themselves.

3Structured Hiring Pipeline

Once a candidate consents and is marked "Interested," the recruiter advances them through a structured pipeline: New → Contacted → Interested → Interviewed → Hired. Every stage transition is logged with a timestamp, creating a complete audit trail.

Visage Platform — Recruiter View
Visage platform recruiter view showing candidate consent status and pipeline

Recruiter view: candidate consent status, outreach tracking, and pipeline management

Data Handling

What Data Is Shared and When

Visage enforces a strict data minimization principle. The type of data shared with an employer is directly tied to the candidate's consent status.

Data TypeBefore ConsentAfter ConsentSource
NamePublicly available
Current job titlePublicly available
Current employerPublicly available
Location / time zonePublicly available
LinkedIn / social media URLPublicly available
Seniority levelPublicly available
Email addressShared post-consent only
Contact detailsShared post-consent only
CV / resumeShared post-consent only
Consent timestamp & recordLogged by Visage
0
Contact details shared pre-consent
Email addresses and contact information are never shared before a candidate explicitly opts in.
100%
Candidates are email-notified
Every candidate receives a clear, branded outreach email before any employer sees their profile.
Auditable
Consent records retained
Timestamp, channel, role ID, and candidate ID are logged for every consent event.

Compliance & Standards

Built for Enterprise Privacy Requirements

Visage's consent framework is designed to satisfy the requirements of enterprise privacy teams, legal counsel, and data protection regulators.

GDPR Compliance

Visage operates as a data controller for candidate data collected from public sources, and as a data processor when handling employer-provided data. Candidates in the EU and UK have full rights under GDPR, including the right to access, rectify, and erase their data. Consent is obtained in accordance with Article 6 lawful basis requirements.

CCPA Readiness

California residents have the right to know what personal information is collected, to request deletion, and to opt out of data sharing. Visage's opt-out mechanism is present in every outreach email and honored immediately upon request.

SOC 2 Type II

Visage has completed SOC 2 Type II certification, covering security, availability, and confidentiality controls. The full report is available to enterprise customers upon request through the Trust Center.

Data Processing Agreement

Visage provides a standard Data Processing Agreement (DPA) that governs how candidate data is processed on behalf of employers. The DPA is available immediately from the Trust Center and can be executed as part of the enterprise onboarding process.

Have privacy or compliance questions?

Our security and compliance team is available to answer specific questions, complete vendor security questionnaires, or provide additional documentation.