GDPR Article 14 is specific. When personal data is collected from anywhere other than the person themselves, that person must be told what is held, by whom, and why.
Most enrichment and sourcing platforms don't do this. Profiles are compiled, sold, and contacted without the candidate ever knowing they sit in a database.
That liability doesn't stay with the vendor. A company sourcing candidates through non-compliant data is processing that data — and is exposed accordingly.
Every candidate in hei-dingo's private signal layer opted in. They know they're on the platform. They control their data and their availability signal. When one replies to your outreach, you never have to explain where their data came from — they gave it to you.