Legal
Privacy policy
Draft. Not legally approved, and not binding. This document is with Australian legal counsel for review and is published as a working draft so you can see what we intend to commit to.
If you need a binding answer before it is approved, email privacy@recruited.com.au and a person will answer you in writing.
Written to be read against the Australian Privacy Principles, in the same order, so you can check it rather than take it on trust.
What this policy covers
Recruited.com.au provides recruitment software to Australian recruitment agencies, and public routes for employers and candidates to interact with those agencies. This policy explains what we do with personal information.
It covers this website, the Recruited application, and the enquiries and support conversations that surround them. It is written to be read against the Australian Privacy Principles in Schedule 1 of the Privacy Act 1988 (Cth), and it is organised in the same order.
Two different relationships, and why the distinction matters
Almost every question about this platform has a different answer depending on which of two relationships it concerns, and conflating them is the most common mistake in a document like this one.
- Information about you as a Recruited customer, enquirer or website visitor. We decide what happens to it, we are accountable for it, and this policy governs it directly.
- Information a recruitment agency holds inside its own Recruited workspace: its candidates, its client contacts, its communications. The agency decides what happens to that information. We hold and process it on that agency’s instruction, to provide the service to them, and for no purpose of our own.
If you are a candidate or a client contact and you want to know what is held about you, the agency you dealt with is usually the right place to start, and they are the ones who can act on most requests. We will help you reach them, and we will act directly on any request that properly belongs to us.
Australian privacy law does not use the “controller and processor” language you may have seen in European policies. We describe the split functionally instead, because that is what actually governs who does what.
To confirm Confirmation of how the agency/Recruited relationship is characterised for candidate data.
APP 1 · Open and transparent management
We maintain internal practices, procedures and systems for handling personal information, including access controls, an audit trail of high-risk actions, and a defined route for privacy enquiries and complaints.
This policy is available at recruited.com.au/privacy without needing an account, and a copy can be provided in another format on request at no charge.
APP 2 · Anonymity and pseudonymity
You can read this entire website without identifying yourself and without an account. We do not require you to identify yourself to browse it.
Where you ask us to do something that requires identification (reply to an enquiry, provide support on a workspace, or act on a privacy request) we cannot do it anonymously, and the reason is that the request itself requires knowing who is asking.
APP 3 · What we collect, and why
We collect only what we need for the purpose we are collecting it for.
- Enquiries through this website: your name, work email, business name, and optionally your team size, current system, primary interest and any note you add. We ask you not to include candidate names, client names or confidential role details, and the form says so where you would type them.
- Account information: the name, work email and role of each person with a login to a workspace.
- Support conversations: what you tell us when you ask for help.
- Billing information: the details needed to invoice a subscription. Card details, where used, are handled by our payment provider and are not stored by us.
- Technical information: the request information any web server necessarily handles in order to serve a page.
- Information inside a workspace: the records an agency creates or imports: candidates, contacts, opportunities, communications, documents. Collected by the agency, held by us on their instruction.
We do not collect sensitive information as defined in the Privacy Act for our own purposes. Where an agency records sensitive information inside its own workspace, it is responsible for having a lawful basis to do so, and our product does not require it.
APP 4 · Unsolicited personal information
If we receive personal information we did not ask for and could not have collected under APP 3, we destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
In practice this most often means a candidate CV pasted into a marketing enquiry form. We remove it and tell the sender where it should have gone.
APP 5 · Telling you at the time
A collection notice sits next to every form on this website that collects personal information, rather than only in this policy. It says who is collecting, what for, and how to reach us.
Where an agency collects information from a candidate through a Recruited job page, the agency’s own collection notice applies, and the agency is responsible for providing it.
APP 6 · Use and disclosure
We use personal information for the purpose we collected it for, and for directly related purposes you would reasonably expect. We do not sell personal information, and we do not disclose it for another organisation’s marketing.
We disclose personal information only:
- to service providers who help us run the platform, under contract, and only as needed to provide their service;
- where you have asked us to, or would reasonably expect us to in the circumstances;
- where required or authorised by law, or to a court or regulator;
- to protect the safety of a person, or to investigate suspected unlawful activity, where the Privacy Act permits it;
- to a purchaser, in connection with a sale of the business, subject to the purchaser assuming the obligations in this policy.
We do not use one customer’s information for the benefit of another. There is no shared candidate database, no cross-workspace analysis, and no privileged access for any customer including LINK, which operates an ordinary workspace on the same terms as everybody else.
APP 7 · Direct marketing
If you enquire through this website, we reply to your enquiry. We do not add you to a marketing list you did not ask to join.
Where we do send marketing, every message contains a working unsubscribe, we act on it promptly, and we will tell you where we got your address if you ask. This is also a requirement of the Spam Act 2003 (Cth), which applies to us independently of the Privacy Act.
Candidate outreach sent by an agency through Recruited is the agency’s marketing, sent under the agency’s own consents. The product carries consent and preference controls and honours an unsubscribe across the workspace.
APP 8 · Sending information overseas
To confirm The hosting region for customer data, and whether any of it is stored or accessed outside Australia. This section must state accurately where customer data is stored, whether any service provider accesses it from outside Australia, and which countries are involved. Until that is confirmed in writing, we describe the position on request during a technical review rather than asserting it here.
Where we do disclose personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, and we remain accountable for it under APP 8.1.
APP 9 · Government related identifiers
We do not adopt a government related identifier as our own identifier for an individual, and we do not use or disclose one except where the Privacy Act permits.
An ABN is a business identifier rather than a government related identifier for an individual, and we use ABNs to verify businesses. Where a sole trader’s ABN also identifies them personally, we use it only for that verification.
APP 10 · Keeping it accurate
We take reasonable steps to keep the personal information we hold accurate, up to date and complete.
Inside a workspace, accuracy is largely in the agency’s hands, and the product supports it: records carry the date and source of what they assert, imported records keep their source system and identifier, and search results show when a fact was last confirmed rather than presenting stale information as current.
APP 11 · Security, and destruction
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. In practice:
- each agency’s workspace is a tenant boundary enforced on the server, in one place in the code, and covered by tests;
- passwords are hashed, sessions are signed and carry an audience claim, and two-factor authentication is available on every plan;
- the database refuses anonymous access entirely, so a browser never holds a database credential;
- documents are stored privately and reached through short-lived signed links rather than public URLs;
- an append-only activity record captures high-risk actions, and staff access to a workspace for support is an auditable event rather than an open door;
- access to customer data is limited to what is needed to operate and support the service.
The security page describes this in more detail, including what we do not claim: we hold no security certification, and no badge on this site suggests otherwise.
To confirm Default retention periods for candidate records, communications and audit logs after a workspace closes. We destroy or de-identify personal information when it is no longer needed for any purpose for which it may be used or disclosed and we are not required to retain it. The default periods after a workspace closes need to be stated here.
If something goes wrong: the notifiable data breaches scheme
If we suspect an eligible data breach we assess it promptly, and where required we notify the affected individuals and the Office of the Australian Information Commissioner within the timeframes in Part IIIC of the Privacy Act.
Where a breach concerns information inside a customer’s workspace, we notify that customer without undue delay and give them the information they need to meet their own obligations, because the notification duty to affected individuals may be theirs rather than ours.
Report a suspected security issue to security@recruited.com.au. We will not pursue anyone who reports a genuine issue in good faith and does not access or alter another customer’s data.
Artificial intelligence
Where the product uses AI, four rules apply and each is implemented rather than promised:
- retrieval is scoped to what the person asking could already read by hand; there is no privileged retrieval path and no query that crosses a workspace;
- output cites its sources, so a summary or a ranking can be checked rather than believed;
- no decision about a person is made automatically; AI ranks, drafts and summarises, and a person decides;
- customer data is not used to train models shared across customers. Doing so would require a separate, explicit decision, and it has not been made.
We do not infer, score, filter on or display sensitive information or protected characteristics.
APP 12 · Getting a copy of what we hold
You can ask for a copy of the personal information we hold about you, and we will provide it within a reasonable period. We aim for 30 days.
We may need to verify who you are first, which is a protection for you rather than an obstacle. If we refuse access, in whole or in part, we will tell you why in writing and how to complain about it.
We do not charge for making a request. If responding involves substantial work we may charge a reasonable cost-based fee, and we will tell you what it is before we incur it.
Customers can export their entire workspace at any time on every plan, without asking us.
APP 13 · Correcting it
If information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, ask us and we will correct it.
If we disagree, we will tell you why, and you can ask us to attach a statement noting your view, which we will do, and which we will make apparent to anyone who later accesses the record.
Where we have disclosed the information to someone else and you ask us to, we will take reasonable steps to notify them of the correction.
Complaints
Email privacy@recruited.com.au. We will acknowledge within one Australian business day and respond substantively within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5288, Sydney NSW 2001. You do not need our permission and it costs nothing.
Changes to this policy
When this policy changes materially we will say so on this page and date it. We will not quietly update it and rely on you noticing.
Where a change would affect how we handle information we already hold about you, we will tell you before it takes effect.
What counsel needs to decide
Every open question in this document, in one list. Each appears in place above as well.
- The contracting entity and its ACN or ABN. Every document has to name who the agreement is with. Currently written as “Recruited.com.au”, which is a product name rather than a legal person.
- A registered address for notices. A notices clause without an address does not work, and the website deliberately publishes no address until one is approved.
- The hosting region for customer data, and whether any of it is stored or accessed outside Australia. APP 8 governs cross-border disclosure and it is the question every agency evaluator asks first. The answer must be accurate before it is published.
- The subprocessor list to publish, and how changes to it are notified. Currently provided in writing on request. Publishing a list creates an obligation to keep it current.
- Default retention periods for candidate records, communications and audit logs after a workspace closes. APP 11.2 requires destruction or de-identification once information is no longer needed. “When you tell us to” is not a policy on its own.
- Confirmation of how the agency/Recruited relationship is characterised for candidate data. Australian privacy law does not use the controller/processor split, so the policy describes it functionally. Counsel should confirm the characterisation and whether a separate data processing schedule is needed.
Marking this document approved in site/content/legal.js removes this list, the drafting notes and the banner together, and the build then refuses to publish a document with an unresolved marker still in it.
Questions
Ask us anything in here.
Whether you are evaluating Recruited for an agency, posting a Brief as an employer, or a candidate whose information an agency holds. If something in this document would stop you, say so.
We reply within one Australian business day.