Skip to main content
Consents let you manage compliance requirements, GDPR being the common one but not the only one. They are stored directly on the record, on candidates and contacts alike, and include the purpose, type, source, lawful basis, and validity period. Consent tracking is available when it is enabled for your workspace under Settings → Features.

Where consents live

Open a candidate or contact and go to the Consent subtab on the Overview tab. It has two sections:
  • Consent: that person’s consent records.
  • Marketing Opt-out: opt-outs that exclude the candidate from marketing emails.
The Consent subtab with consents and marketing opt-outs
The consent purposes candidates can be tracked against are managed from Settings → Data Model → Candidates → Consents. Spott ships with system purposes such as Recruiting, Marketing Email, Marketing SMS, and WhatsApp Business Marketing, each with a default expiry time. Use Create your own consent purpose to add custom purposes for your workspace.
Candidate consent purposes with default expiry times
Consent records are created manually. Spott does not write one for you, not even when someone accepts your terms through the Request updated CV link. Your terms and privacy policy are configured under Settings → General.
  1. Open the candidate and go to Overview → Consent.
  2. Click Add Consent.
  3. Fill in the fields:
    • Purpose, for example Recruiting, Marketing Email, or a custom purpose
    • Type and Source
    • Lawful basis, for example Consent, Legitimate Interest, or Contract
    • Valid until
  4. Save.
The consent appears in a table with its purpose, type, lawful basis, source, collection date, and expiry date. From there you can add more consents or delete existing ones. Each consent has a Framework field, set to GDPR by default and extendable to other frameworks if you work under different rules.

Stay compliant

Spott gives you the tracking and the triggers; you stay in charge of what happens to a record. In practice that is a routine:
  • Track expiry dates so you renew consent before it lapses rather than after.
  • Use the compliance filters on the Candidates and Contacts views to pull up everyone whose consent is about to expire, or has already.
  • Reach out and record the renewal. A campaign or an automated email handles the outreach; the new consent goes on the record when they answer.
  • Act on what has lapsed, by deleting or anonymizing those records once you have decided they should go.
Expiry flags a record, it does not act on it. Spott never deletes or anonymizes a candidate, a contact, or their CV on its own. Retention is a judgement call with legal consequences, and it stays yours: nothing disappears from your database because a date passed.

Automate part of it

Some of this routine can be taken off your hands. The clearest example: an automation can send the consent email itself when a candidate reaches the stage where you ask for it, so collecting consent stops depending on someone remembering. Renewal and clean-up are still hands-on today: you use the compliance filters to find what is lapsing, and you decide what happens to each record. Which parts are worth automating depends on the frameworks you work under and how your team is set up. Talk to your Customer Success contact before you build it: they can tell you what fits your workflow and what is better kept manual.