Use case
Encrypted Notes for HR and Recruiting Teams
HR teams handle some of the most sensitive personal data in an organisation, usually through the least controlled channel available: email. The compliance exposure is rarely the moment of sending — it is the copy that sits in a mailbox for the next seven years.
What HR actually sends
- Offer details — salary, equity, start dates — often to a personal email address before the candidate has a company account.
- Payroll and bank details collected during onboarding.
- Identity documents for right-to-work and background checks.
- Portal credentials for benefits, payroll and pension systems.
- Investigation notes and performance documentation with real consequences if they circulate.
Nearly all of it travels by email, and nearly all of it stays in at least two mailboxes indefinitely — the sender's and the recipient's, plus whatever archiving and e-discovery systems sit behind them.
Why the retention is the risk
Data-protection regimes including the GDPR are built around data minimisation and storage limitation: hold personal data only as long as you genuinely need it. An email archive is the direct opposite — it retains everything by default, forever, and its access list grows quietly as people change roles.
An expiring encrypted note inverts that default. The sensitive content lives for a window you choose, then stops existing in retrievable form. The email that remains contains a dead link and no personal data.
This is a risk-reduction measure, not compliance advice
Practical patterns
Send the sensitive part separately from the friendly part
The welcome email can be an ordinary email. The salary figure, bank details or document goes in the note. Keep personal data out of the email body and the subject line entirely.Never put identifying detail in the note name
The name becomes the URL.onboarding-jane-smith-salaryis visible in browser history and link previews before anyone enters a password.Give a realistic expiry
Candidates read email on their own schedule. Two to seven days is usually right; an hour will simply generate a support request.Send the password by phone
You are almost always already speaking to the person. Reading a four-word password aloud takes ten seconds and puts nothing in writing.Explain what the link is
An unexplained link to a site the recipient does not recognise looks exactly like phishing. Say what it is and that a password will follow by phone — otherwise you are training people to click unexplained links.
Where this is the wrong tool
- Anything requiring a signature. Use a proper e-signature platform with an audit trail.
- Records you are legally required to retain. An expiring note is the opposite of a retention system.
- Bulk personal data. Spreadsheets of employee records belong in an access-controlled HR system, not a note.
- Anything needing proof of receipt. There are no accounts and no identities, so a view count cannot tell you *who* opened it.
A note on candidate experience
Candidates notice this. Being asked to open a password-protected note for a salary figure reads as an organisation that takes personal data seriously — provided it is explained. Unexplained, it reads as friction, or worse, as a phishing attempt. The explanation is not optional politeness; it is the difference between the two interpretations.
Frequently asked questions
Is this GDPR compliant?
Can we prove a candidate received the note?
What if a candidate loses the password?
Can we attach documents?
Related reading
For personal use
The same tools, for your own records and family logistics.
Read morePrivacy policy
What we collect, what we do not, and how long we keep it.
Read moreSelf-destructing notes
How expiry works and what it genuinely achieves.
Read moreSelf-destructing notes vs encrypted email
Which one fits which problem.
Read moreWrite your first encrypted note
No account, no email address, no download. Type a note, set a password, share the link.
Open the notepad