Legal

Acceptable Use Policy

Version: 3 September 2026

This mandatory customer compliance policy applies to every organisation using HirePortal and forms part of the account terms.

Draft pending final legal review

This is a high-quality contractual and compliance draft, not a substitute for final advice from HirePortal's Dutch privacy and IT lawyer. Mandatory statutory duties of HirePortal cannot be excluded by contract. Text between square brackets is still to be completed.

The English version is a faithful operational version of the Dutch text. In case of conflict, the Dutch version prevails unless expressly agreed otherwise.

Customer obligations

  • The Customer must identify itself accurately and may not conceal the recruitment company behind the call.
  • The AI disclosure may not be suppressed.
  • No call may be started without recorded lawful-basis or contact-authority status.
  • No call may be made to a suppressed, withdrawn or objected number.
  • No repeated calling after refusal or lack of interest beyond the Customer's documented and reasonable contact policy.
  • No scraping or enrichment of private, restricted-access or unlawfully obtained data.
  • No special-category inference from photos, names, memberships, posts or other indirect signals.
  • No emotion recognition or biometric categorisation in recruitment calls.
  • No automated rejection or hiring solely by HirePortal without a separately approved legal configuration.
  • The Customer must have a candidate privacy notice and a process for rights requests.
  • The Customer must perform a DPIA where processing is likely to result in high risk, particularly at scale, with systematic monitoring or profiling, or novel AI use.
  • The Customer must train users and ensure only authorised staff can activate enrichment or calling.
  • HirePortal may suspend access in case of credible complaints or regulatory risk.

Consent controls built into the product

  • Manual import: before the final “Import candidates” action, a blocking modal with non-pre-checked checkboxes appears. Import cannot proceed until accepted.
  • ATS connection: an organisation-level attestation is required during setup, followed by mapping of a Candidate-level consent or contact-permission field. If mapping is absent or the value is unknown, candidate status is set to UNKNOWN / NO CALL.
  • Voice AI execution: a second server-side hard check is performed immediately before placing the call. UI confirmation alone is insufficient.
  • Audit log: actor user ID, organisation ID, timestamp, session where appropriate, declaration version, source/import/integration ID, candidate ID and consent evidence metadata are stored.
  • Withdrawal or block: communication is blocked immediately across phone, email and automation. Active candidate data is removed or anonymised where applicable, retaining only a minimal suppression record needed to prevent re-contact.
  • Re-import prevention: a blocked candidate stays blocked even if later re-imported from the ATS or a CSV. Bulk import cannot overwrite suppression status.
  • Admin override: no ordinary recruiter override. Any exceptional unblock requires a new, documented consent event and elevated permission with an audit trail.
  • False attestation: treated as a material breach and flagged for compliance review or suspension.