PRIVACY POLICY
Effective Date: September 8, 2025
This Privacy Policy ("Policy") describes how Pacific Data Pty Ltd ("Pacific Data," "we," "us," or "our") collects, uses, processes, and discloses personal information in connection with our AI-powered recruitment platform and related services (collectively, the "Services"). This Policy applies to all users of our Services, including employers, hiring managers, candidates, and visitors to our website.
BY ACCESSING OR USING OUR SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY THIS PRIVACY POLICY. IF YOU DO NOT AGREE WITH THIS POLICY, YOU MUST NOT USE OUR SERVICES.
1. INFORMATION WE COLLECT
1.1 Personal Information
We collect the following categories of personal information:
(a) Identity and Contact Information: Full name, email address, telephone number, postal address, job title, company name, and professional affiliations;
(b) Account Information: Username, password, account preferences, and security credentials;
(c) Professional Information: Resume, curriculum vitae, work history, educational background, skills, qualifications, certifications, references, and employment status;
(d) Interview Data: Video recordings, audio recordings, transcripts, responses to interview questions, behavioral assessments, and performance metrics;
(e) Biometric Information: Facial recognition data, voice patterns, and other biometric identifiers derived from interview recordings;
(f) Financial Information: Payment method details, billing address, and transaction history for subscription services;
(g) Communication Data: Messages, feedback, support inquiries, and other communications with us or through our platform.
1.2 Technical Information
(a) Device Information: IP address, browser type and version, operating system, device type, unique device identifiers, and mobile network information;
(b) Usage Data: Log files, access times, pages viewed, time spent on pages, click-through rates, and other usage statistics;
(c) Location Data: General geographic location based on IP address;
(d) Cookies and Tracking Technologies: Information collected through cookies, web beacons, pixel tags, and similar technologies.
1.3 Sensitive Personal Information
We may collect sensitive personal information including:
(a) Protected characteristics under applicable employment laws (collected only with explicit consent and for legitimate business purposes);
(b) Health information related to accommodation requests;
(c) Criminal history information where permitted by law and relevant to the position.
2. HOW WE COLLECT INFORMATION
2.1 Directly from you when you create an account, complete your profile, upload documents, participate in interviews, or communicate with us;
2.2 Automatically through your use of our Services via cookies, log files, and other tracking technologies;
2.3 From third parties, including employers who use our platform, recruitment agencies, background check providers, and publicly available sources;
2.4 Through integrations with third-party services such as LinkedIn, Google, or other professional networking platforms;
2.5 From our AI systems during interview analysis and candidate assessment processes.
3. USE OF PERSONAL INFORMATION
We use personal information for the following purposes:
3.1 Service Provision and Core Business Operations
(a) Providing, maintaining, and improving our AI-powered recruitment platform;
(b) Processing and facilitating job applications and interview processes;
(c) Conducting automated screening, ranking, and assessment of candidates;
(d) Generating interview transcripts, summaries, and analytical reports;
(e) Facilitating communication between employers and candidates;
(f) Processing payments and managing subscriptions;
(g) Providing customer support and responding to inquiries.
3.2 Marketing and Communications
(a) Sending promotional materials, newsletters, product updates, and marketing communications;
(b) Conducting market research, surveys, and customer satisfaction studies;
(c) Personalizing content, recommendations, and user experience;
(d) Creating anonymized case studies, testimonials, and success stories for marketing purposes;
(e) Analyzing user behavior and preferences to improve our marketing strategies;
(f) Conducting targeted advertising campaigns across various platforms and channels.
3.3 Product Development and Improvement
(a) Analyzing usage patterns and user feedback to enhance our Services;
(b) Developing new features, functionalities, and service offerings;
(c) Training, testing, and improving our artificial intelligence models and algorithms;
(d) Conducting research and development activities;
(e) Benchmarking and performance analysis;
(f) Quality assurance and testing procedures.
3.4 Legal Compliance and Security
(a) Complying with applicable laws, regulations, and legal obligations;
(b) Preventing, detecting, and investigating fraud, security incidents, and other illegal activities;
(c) Protecting the rights, property, and safety of Pacific Data, our users, and the public;
(d) Enforcing our terms of service and other agreements;
(e) Responding to legal requests, court orders, and regulatory inquiries;
(f) Maintaining records for audit and compliance purposes.
4. DISCLOSURE AND SHARING OF PERSONAL INFORMATION
4.1 Service Providers and Business Partners
We may share personal information with carefully vetted third-party service providers and business partners, including:
(a) Cloud hosting and data storage providers
(b) AI and machine learning service providers
(c) Payment processing companies and financial institutions;
(d) Customer support and communication platforms;
(e) Marketing automation and email service providers;
(f) Analytics and business intelligence providers;
(g) Legal, accounting, and professional service firms;
(i) Integration partners for third-party software and platforms.
4.2 Employers and Recruitment Partners
We share candidate information with employers and recruitment partners in accordance with the purpose of our Services, including:
(a) Companies and organizations that post job opportunities on our platform;
(b) Recruitment agencies and staffing firms;
(c) Human resources consultants and talent acquisition specialists;
(d) Educational institutions and training providers for student placement programs.
4.3 Marketing and Lead Generation Partners
We may share information with marketing partners for:
(a) Joint marketing campaigns and co-branded initiatives;
(b) Lead generation and customer acquisition activities;
(c) Industry research and market analysis;
(d) Conference and event partnerships;
(e) Content creation and thought leadership initiatives.
4.4 Legal and Regulatory Disclosures
(a) To comply with applicable laws, regulations, legal processes, or governmental requests;
(b) In response to subpoenas, court orders, or other legal proceedings;
(c) To protect our rights, property, and safety, or that of our users or the public;
(d) In connection with investigations of fraud, intellectual property infringement, or other illegal activities;
(e) To enforce our terms of service and other legal agreements.
4.5 Business Transfers
In the event of a merger, acquisition, sale of assets, bankruptcy, or other business transaction, personal information may be transferred to the acquiring or surviving entity, subject to appropriate confidentiality protections.
5. DATA SECURITY AND PROTECTION MEASURES
We implement comprehensive security measures to protect personal information, including:
5.1 Technical Security Measures
(a) End-to-end encryption for all data transmission using TLS 1.3 protocols;
(b) AES-256 encryption for data at rest in our databases and storage systems;
(c) Multi-factor authentication for all administrative and user accounts;
(d) Row-Level Security (RLS) implementation in our database architecture;
(e) Regular security audits, penetration testing, and vulnerability assessments;
(f) Automated security monitoring and threat detection systems;
(g) Secure backup and disaster recovery procedures;
(h) Network segmentation and access controls.
5.2 Organizational Security Measures
(a) Mandatory security training for all employees and contractors;
(b) Background checks for personnel with access to personal information;
(c) Confidentiality agreements and data protection clauses in employment contracts;
(d) Incident response procedures and data breach notification protocols;
(e) Regular security policy reviews and updates;
(f) Third-party security assessments and compliance audits.
5.3 Compliance and Certifications
(a) Australian Privacy Principles (APP) compliance;
(b) General Data Protection Regulation (GDPR) compliance for European users;
(c) California Consumer Privacy Act (CCPA) compliance for California residents;
(d) ISO 27001 information security management system certification (in progress);
(e) SOC 2 Type II compliance reporting (in progress).
6. DATA RETENTION AND DELETION
6.1 Retention Periods
Account Information: Retained for the duration of your account plus seven (7) years after account closure for legal and business purposes;
Interview Recordings and Transcripts: Retained for seven (7) years from the date of the interview for legal compliance, quality assurance, and AI model improvement;
Marketing and Communication Data: Retained until you opt-out of marketing communications or request deletion, whichever occurs first;
Technical and Usage Data: Retained for two (2) years from collection date for security monitoring and service improvement;
Financial and Transaction Data: Retained for seven (7) years from the transaction date for accounting and tax compliance purposes;
Legal and Compliance Records: Retained for periods required by applicable laws and regulations, typically seven (7) to ten (10) years.
6.2 Secure Deletion Procedures
Upon expiration of retention periods or valid deletion requests, we implement secure deletion procedures including:
(a) Cryptographic erasure of encrypted data by destroying encryption keys;
(b) Multi-pass overwriting of storage media containing personal information;
(c) Physical destruction of decommissioned hardware and storage devices;
(d) Verification of deletion completion through audit trails and certifications;
(e) Notification to relevant third parties to delete shared personal information.
7. YOUR PRIVACY RIGHTS
7.1 Access and Correction Rights
(a) Right to access personal information we hold about you;
(b) Right to request correction of inaccurate or incomplete personal information;
(c) Right to receive information about how we collect, use, and disclose personal information;
(d) Right to request information about third parties with whom we share personal information.
7.2 Deletion and Portability Rights
(a) Right to request deletion of personal information, subject to legal retention requirements;
(b) Right to data portability in commonly used, machine-readable formats;
(c) Right to withdraw consent for processing based on consent;
(d) Right to object to processing for direct marketing purposes.
7.3 Communication and Marketing Preferences
(a) Right to opt-out of marketing emails and promotional communications;
(b) Right to control notification settings and communication preferences;
(c) Right to manage data sharing preferences with marketing partners;
(d) Right to limit use of personal information for analytics and research purposes.
7.4 Exercising Your Rights
To exercise your privacy rights, please contact us using the information provided in Section 9. We will:
(a) Respond to your request within thirty (30) days of receipt;
(b) Verify your identity before processing requests involving personal information;
(c) Provide clear information about any fees associated with fulfilling your request;
(d) Explain any limitations or restrictions that may apply to your request under applicable law.
8. INTERNATIONAL DATA TRANSFERS
Personal information may be transferred to, stored, and processed in countries other than your country of residence, including the United States, where our servers and service providers are located. We ensure that international transfers are conducted in accordance with applicable data protection laws through appropriate safeguards, including:
(a) Standard contractual clauses approved by relevant data protection authorities;
(b) Adequacy decisions recognizing equivalent data protection standards;
(c) Binding corporate rules for intra-group transfers;
(d) Explicit consent from data subjects where required by law;
(e) Derogations for specific situations as permitted under applicable privacy laws.
9. CONTACT INFORMATION AND COMPLAINTS
9.1 Data Protection Officer
Email: contact@pacificdata.com.au
Phone: 1300 954 503
9.2 Regulatory Complaints
If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with the relevant data protection authority:
Australia: Office of the Australian Information Commissioner (OAIC) - www.oaic.gov.au
European Union: Your local Data Protection Authority
United Kingdom: Information Commissioner's Office (ICO) - www.ico.org.uk
California: California Attorney General's Office
10. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our business practices, legal requirements, or regulatory guidance. Material changes will be communicated through:
(a) Email notification to registered users at least thirty (30) days prior to the effective date;
(b) Prominent notice on our website and platform;
(c) In-app notifications for mobile and web application users;
(d) Updates to the "Effective Date" at the top of this Policy.
Your continued use of our Services after the effective date of any changes constitutes acceptance of the updated Privacy Policy. If you do not agree with the changes, you must discontinue use of our Services and may request deletion of your personal information.
END OF PRIVACY POLICY
Document Version: 2.0 | Approval Date: September 8, 2025 | Next Review: September 8, 2026
