UK candidates
A CV database you can still rely on in three years
A UK agency database is both the firm's biggest asset and its largest pile of personal data, and those two facts pull in opposite directions.
A candidate management system holds the people you have met as structured records rather than a folder of CVs. Surhires stores normalised skills, availability, notice period and salary expectation, records the lawful basis for holding each record, applies configurable retention windows, and supports export and erasure as product workflows under UK GDPR.
By Surhires Editorial · Published · Reviewed
The database decays in a predictable way
The pattern is the same in almost every agency. A consultant receives a CV, saves it, types three lines into a notes box and moves on. The record is technically captured. Two years later somebody searches for a management accountant in Bristol and gets six hundred results with no way to tell which of them answered the phone, which are still in the same job, and which asked to be removed eighteen months ago.
The data was there. The structure was not, and neither was the maintenance. A database with no structure cannot be searched against a brief, and a database with no retention discipline is a liability that grows quietly until somebody asks a question about it.
Surhires writes structure at capture time. Parsing a CV produces normalised fields rather than a blob: current title, years in discipline, tools and frameworks separately from languages, certifications as their own list, notice period, salary expectation and the currency it was quoted in. The free text is still there and still searchable; it simply is not carrying the whole record.
Lawful basis is a field, not a policy document
Under UK GDPR you need a lawful basis for holding a candidate record and you need to be able to say what it is. Most agencies have a policy that says this and a database that does not record it. Surhires puts it on the record: the basis relied on, the date it was established, the channel through which the candidate came, and what they were told at that point.
That turns a policy claim into something reportable. You can ask how many records in the database have no recorded basis, or which came from a particular source in a particular year, and get an answer rather than an estimate. Cleaning a database is only possible once you can see which parts of it are the problem.
This is a capability statement rather than a compliance declaration. The product supports consent capture, configurable retention, export and erasure. You remain the controller for the candidate data you hold, and whether your processing is lawful depends on decisions you make, not on the software.
- Lawful basis, capture date, capture channel and notice text stored per candidate record
- Source of record retained through import, so migrated data is not laundered of its origin
- Reportable across the database, so gaps are visible rather than assumed
- Change history on consent fields, so a later question has an answer with a date on it
Retention windows that actually fire
A retention policy that lives in a document and not in the system is a policy nobody follows. Retention windows here are configurable per record type and per source, and a record that reaches the end of its window without meaningful activity is flagged for review rather than silently deleted or silently kept.
Review before erasure is deliberate. A candidate placed twice in five years and quiet for eighteen months is not the same as a speculative CV from a job board that nobody ever called. The system surfaces both and lets a human decide, then records the decision.
Erasure, when it happens, is complete: profile, parsed text, uploaded files and message history. Financial records tied to a completed placement are retained where law requires it, and the workflow says so rather than implying that everything disappeared.
Keeping a record current is a workflow, not a wish
Candidate data goes stale faster than any other data an agency holds. A notice period is accurate for a month. A salary expectation is accurate for a year. A phone number is accurate until somebody changes jobs.
Re-engagement cadences let you run a scheduled, opt-out-respecting check-in across a segment of the database and update records from the replies. Reply Handler classifies what comes back and moves the record or raises a task, so an update does not depend on a consultant remembering to type it. Bulk actions from the list view let you tag, pool, message or re-stage hundreds of records at once rather than visiting each one.
The candidate-facing self-service portal, where a candidate confirms availability and uploads a newer CV themselves, is in build for the Wave 1 release rather than shipping today. Until it lands, updates come through the cadence and the recruiter.
Search that answers a brief
Search runs across the structured fields and the parsed CV text at the same time. You can ask for a qualified accountant within an hour of Bristol, available inside six weeks, with practice experience, and get an answer that respects all three constraints instead of everyone whose CV contains the word accountant.
Saved searches become working lists that repopulate as new candidates arrive, which is what turns a database from something you query occasionally into something that feeds the desk every morning. Talent pools hold the lists you work every week; tags handle lighter triage.
- Structured facets and full CV text queried together in a single request
- Saved searches that repopulate as candidates are added
- Talent pools for standing lists, tags for lightweight triage
- Duplicate detection during import rather than a cleanup job afterwards
Permissions on the fields that need them
Not every seat needs to see everything. Compensation history is permissioned per role. Demographic data captured for equal-opportunity monitoring is stored separately from the hiring record and is not visible to recruiters at all, so it cannot influence the decision it exists to measure.
Field-level permissions also matter on a database that several desks share. A contract desk and an executive search desk in the same firm often should not see each other's notes, and a permission model that only works at the record level cannot express that.
Where the boundary sits
Surhires holds candidate records, relationships and the hiring pipeline. It is not an HRIS, so once a candidate becomes your client's employee, their employment record lives with the employer. It is not a background-check provider or a right-to-work verification service; it captures the documents and the expiry dates, and the check itself is yours to run.
The reason to state that is that a candidate management system with an ambiguous boundary tends to accumulate personal data it has no business holding. Knowing what the database is for is part of keeping it lawfully held.
What you get
Structured candidate records
Normalised skills, seniority, location, notice period and salary expectation on every profile.
CV parsing
Incoming CVs written to typed fields, with the original file preserved alongside the parsed text.
Bulk CV import
A folder of CVs parsed into records with duplicate detection running during the import.
Lawful basis field
Basis, capture date, channel and notice text recorded per candidate and reportable in bulk.
Retention windows
Configurable per record type and source, flagging dormant records for review before erasure.
Erasure workflow
Profile, parsed text, files and messages removed, with the fulfilled request recorded and dated.
Subject access export
A candidate's full held record exported as CSV or JSON without a support ticket.
Combined search
Structured facets and CV full text queried together, so a brief becomes one query.
Saved searches
A brief saved as a live list that repopulates as new candidates are added.
Talent pools and tags
Standing lists for the segments you work weekly, tags for lighter triage.
Duplicate detection
Matches on contact details and CV content, catching duplicates at the point of entry.
Field permissions
Compensation restricted by role; demographic data held apart from the hiring record entirely.
Re-engagement cadences
Scheduled check-ins across a segment, with replies classified and filed automatically.
Activity stream
Every call, message, submittal, stage change and outcome in one chronological view.
Questions recruiters ask
Does this make us UK GDPR compliant?
No software can do that. The product supports consent capture, configurable retention, export and erasure, and records the lawful basis on each candidate. You remain the controller and the decisions about what you hold and why are yours. We publish that split explicitly rather than selling a compliance badge we cannot honestly issue.
What happens when a candidate asks to be deleted?
The erasure workflow removes the profile, the parsed CV text, the uploaded files and the message history, and records that the request was fulfilled and on what date. Financial records attached to a completed placement are retained where law requires it, and the workflow states that rather than quietly keeping everything else too.
Can candidates update their own details?
Not yet. The candidate-facing self-service portal is in build for the Wave 1 release rather than shipping today. Until it lands, records are updated through re-engagement cadences and by recruiters, with inbound replies classified and filed against the record automatically so an update does not depend on somebody remembering.
How large a database can this hold?
Starter is capped at five hundred candidates, which suits a desk coming off spreadsheets. Professional and Enterprise are not capped on candidate count. Search performance at very large database sizes is something we test rather than assume, and Enterprise accounts are sized during onboarding rather than promised in a marketing page.
Can we import a database that has no consent records?
You can import it, and the import will show you exactly how much of it has no recorded basis. That visibility is usually uncomfortable and usually useful. What we will not do is invent a basis during import or default every migrated record to consent, because that would make the field worthless.
Who can see salary and demographic data?
Compensation fields are permissioned per role, so not every seat sees them. Demographic data captured for equal-opportunity monitoring is stored separately from the hiring record and is not visible to recruiters at all. Keeping it out of the recruiter's view is the point; data that influences a decision cannot also measure it.
Keep reading
- Recruitment software that fits a UK desk
- One system for a mixed perm and contract desk
- The front office half of a UK staffing stack
- One candidate record that actually stays current
- Know why you hold every candidate record, and for how long
- Resumes become records, not attachments
- Stop paying twice for the same candidate
See it against your own reqs
Bring one live role and three resumes. In twenty minutes you will see the match scores, the shortlist and the placement invoice that comes out the other end.