Slate

Privacy

Privacy policy

This is how Slate handles personal information passing through it: who is responsible for it, what is collected, where it is processed, how long it is kept, and how you ask for it. It applies to every candidate whose information reaches Slate through a recruiter’s campaign, to every recruiter using the product, and to the client contacts a recruiter adds to a campaign.

Who is responsible for your information

The recruiting agency or independent recruiter you are dealing with holds your information and decides what happens to it. Under South Africa’s Protection of Personal Information Act (POPIA), that makes them the responsible party.

Slate is the software they use to do the administration around a placement, and processes information on their instructions only. That is what POPIA calls an operator: Slate does not decide what a recruiter’s candidate information is used for, and does not use it for any purpose of its own.

Your own information, if you are a recruiter

Your account is different from a candidate’s: for your own name, email address, agency details and the mailbox and calendar you connect, Slate decides why that is collected, to run the account you signed up for, which makes Slate itself the responsible party under POPIA rather than the operator.

A connected mailbox is authorised through an encrypted token rather than a stored password, is never returned to a browser, and is used to send on your behalf; Slate does not read your inbox. A connected calendar is stored the same way, ready for the booking feature once it is built.

This is kept for as long as your account is active. There is no self-service way to close an account and remove it yet.

What is collected, and why

What is held is what a candidate has already sent or entered: their name, contact details, CV, and their response to a document such as a Permission to Represent, whether they sign it or decline it. Either way that response includes the date and time, the device used and the network address it came from, and a decline also keeps the reason given. That record is what makes a signed document stand up later, or explains why one was not signed.

This is used to run the administration around one placement. The advert and interview guide are built from the role and the campaign, not from a candidate’s own details: Slate keeps those separate on purpose. A candidate’s own information is what the first email and Permission to Represent are built from, and what a signed document has to reproduce. Booking and recording the interview, and assembling the pack sent to a client, are the same administration and are being built next rather than live today. Nothing here is used to score, rank or compare a candidate against anyone else, and no candidate is filtered out by Slate. Every decision to progress or stop a candidate is the recruiter’s, made by them and recorded as theirs.

A client contact’s information

When a recruiter sets up a campaign, they enter the name and email address of the person at their client a candidate is ultimately submitted to. The same split as a candidate’s information applies: the recruiter decides to collect it and is the responsible party, and Slate processes it on their instructions as the operator. Sending anything to that contact is part of the client submission pack, which is being built next rather than live today.

It is kept for as long as the campaign it belongs to, under the same retention period described below. Automatic deletion once that period passes is not live for this either, the same qualification the retention section below makes for candidate information, and the same request path applies: ask the recruiter running that campaign.

Where it is processed

Some of that processing happens on servers outside South Africa: Slate’s database, file storage and sign-in are run by Supabase, the application itself runs on Vercel, and the background work behind each step, sending an email, filing a signature, reading a CV, is queued and tracked by Inngest, which can hold the result of that work, including a CV’s extracted text, for as long as the step needs it. Anthropic, an artificial intelligence provider, reads a CV to extract a candidate’s details, is used again to draft the first email from those details, and separately drafts the advert and interview guide from the job description, supporting role documents and the recruiter’s own name or agency name. An email itself is sent through the recruiter’s own connected mailbox, today always Google (Gmail), since the recruiter is the sender and never Slate. Any transfer outside the country is carried out under contractual safeguards, in line with POPIA section 72.

How long it is kept

Candidate information is meant to be kept until 12 months after the role a candidate was being considered for closes, unless the recruiter has set a different period for their agency. The exact period a candidate’s recruiter uses is stated on the privacy notice attached to every link Slate sends that candidate.

Once that period passes, Slate deletes the interview recording, the transcript made from it and the submission pack built for the client, automatically and overnight. The rest of what is held, a candidate’s own details, their CV and the record of a document they signed or declined, is not removed automatically yet, so until it is, a candidate or recruiter who wants any of that removed, or wants it removed sooner, should ask, using the request process below. A record that information was deleted is kept after the information itself has gone, so a recruiter can show what happened to it.

Security

Information is encrypted in transit and at rest. A recruiter’s connected mailbox and calendar credentials are encrypted before they are stored and are never returned to a browser. Every link sent to a candidate is scoped to one purpose, stored as a hash rather than as a plain token, and expires. Repeated attempts against an opened link are rate-limited.

Every meaningful action on a candidate’s information that is live today, an email or document sent, a signature recorded, is written to an audit log the recruiter can review. Booking an interview and sending a submission will be added to that log once those steps are built.

Asking to see or delete your information

Every candidate email Slate sends on a recruiter’s behalf carries a link to your own request page, where you can ask for a copy of what is held about you or ask for it to be deleted. The recruiter is told either way and will answer within 30 days.

If you no longer have that email, or the link in it has expired, email them directly at the address on the privacy notice it carried, and ask the same way.

That path is for a candidate’s own information, held by the recruiter. For a recruiter’s own account information, held by Slate directly, there is no dedicated request address yet.

Slate’s undertakings as operator

These are the terms Slate operates on for candidate information passing through a recruiter’s account, as the operator described above. Slate:

  • processes information only for the recruiting administration a recruiter uses it for, and never for a purpose of its own;
  • keeps it secure with the measures described above, and does not sell it;
  • tells the recruiter without undue delay if a security incident affects their information, so they can meet their own obligations to their candidates;
  • deletes the interview recording, its transcript and the submission pack automatically once the retention period above passes, and is still building the same for the rest; until that is done, a request to delete anything else, or to delete sooner, goes through the recruiter, using the process above.